Network equipment maker Ubiquiti on Tuesday filed a lawsuit against infosec journalist Brian Krebs, alleging he defamed the company by falsely accusing the firm of covering up a cyber-attack.
On March 30, 2021, Krebs reported that Ubiquiti had disclosed a January breach involving a third-party cloud provider, later revealed to be AWS, and that an unnamed source within the firm had claimed the company was downplaying a catastrophic compromise.
On December 1, 2021, the US Department of Justice charged former Ubiquiti software engineer Nickolas Sharp, accusing him of attempting to steal data from the company and to exhort $2m from the firm in Bitcoin ransom as part of an effort to reduce the price of Ubiquiti shares. The DoJ said that after Ubiquiti refused Sharp's payment demand, he tried to sink the company's shares by publishing stolen files and engaging in a media campaign to plant damaging stories about the firm.
The publication of these stories, on March 30 and 31, 2021, the DoJ said, coincided with a $4bn decline in Ubiquiti's market capitalization.
Ubiquiti, in its complaint [PDF], alleges that Krebs, after seeing the DoJ announcement, knew that the unidentified source he cited in his March articles – Sharp – had been indicted for involvement in the attack on Ubiquiti.
And the biz contends he published on his Krebs-on-Security website a story on December 2, 2021 that repeated prior claims while misleadingly referring to his source as "a Ubiquiti employee" and to Sharp...
Read Full Story:
https://www.theregister.com/2022/03/30/ubiquiti_brian_krebs/