Former Cisco engineer gets 2-year prison sentence for Webex hack
Cisco didn't seek restitution for $2.4M in restoration and customer service costs


Northern California District Court has handed former Cisco software engineer Sudhish Kasaba Ramesh a two-year prison sentence for deleting 16,000 Webex collaboration accounts.
From August 2016 to April 2018, Ramesh was part of Cisco's platform team, focusing on automation, access to data, and logging metrics. This gave him access to servers on Amazon Web Services (AWS) that ran Cisco's Webex Teams application, which customers use for video conferencing, video messaging, and file sharing.
The Department of Justice (DOJ) charged Ramesh with intentionally accessing a protected computer without authorization and recklessly causing damage on July 13, 2020. He pleaded guilty in San Jose, California on August 26.
The plea agreement said Ramesh accessed Cisco's cloud infrastructure running on AWS on September 24, 2018. He logged in via a Google Cloud Project account and used his AWS key to delete 456 virtual machines running Webex Teams.
Deleting the virtual machines shut down over 16,000 Webex Teams accounts for up to two weeks, costing around $1.4 million in employee time to restore the damage. According to the DOJ announcement in August, Cisco refunded over $1 million to affected customers de to Ramesh’s actions.
The case leaves two questions unanswered: Why Ramesh did it, and why he left such an obvious trail? He didn't explain his actions in court.
Prosecutors said they were "perplexed" at how Ramesh, who is "a highly intelligent individual," could have left such an obvious trail for the FBI investigators who caught him. He didn't use a proxy to carry out the attack and chose to launch it from his work computer instead, which contained search records querying how to delete Amazon servers. His Google Cloud Project account was also registered under his name and paid for with his credit card.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The District Court sentenced Ramesh to a two-year stint in prison and a $15,000 fine. Cisco didn't seek restitution for the incident, but reports claim he was also fired from his job at personal lifestyle website Stitch Fix. Ramesh will begin his prison sentence on February 10, 2021.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Cisco claims new smart switches provide next-level perimeter defense
News Cisco’s ‘security everywhere’ mantra has just taken on new meaning with the launch of a series of smart network switches.
By Solomon Klappholz
-
Cisco is jailbreaking AI models so you don’t have to worry about it
News Cisco's new AI Defense security solution helps organizations shore up LLM security by identifying potential flaws.
By Solomon Klappholz
-
Cisco dispels Kraken data breach claims, insists stolen data came from old attack
News Cisco has refuted claims it has suffered a data breach after the Kraken threat group posted stolen data online.
By Solomon Klappholz
-
Cisco patches critical flaws in Identity Services Engine
News Cisco has issued patches for a pair of critical vulnerabilities affecting its Identity Service Engine (ISE).
By Nicole Kobie
-
Your office is now absolutely riddled with surveillance equipment
News While workplace monitoring is shown to have a detrimental effect on morale, many firms are still charging ahead
By Nicole Kobie
-
Cisco confirms attackers stole data, shuts down access to compromised DevHub environment
News The tech giant insists that no sensitive customer information has been compromised
By Solomon Klappholz
-
Cisco confirms investigation amid data breach claims
News The networking giant says its probe is ongoing amid claims a threat actors accessed company data
By Nicole Kobie
-
Rubrik partners with Cisco to bolster cyber resilience
News Rubrik now integrates with Cisco XDR and is listed on the connectivity giant’s SolutionsPlus program
By Daniel Todd