CSIDB logo
Threat actor

Sudhish Kasaba Ramesh

Attribution profile

Type
Insider - Disgruntled
Location
India
Known incidents
1 incident
First seen
2018-09-24
Last seen
2018-09-24
Updated
2026-07-30 23:03
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Sudhish Kasaba Ramesh, also known as Sudhish Ramesh, is an individual whose known location is India and who has been identified as a former engineer at Cisco Systems. He held an H1 visa while residing in the United States and had a pending green card application at the time of the incident. After resigning from Cisco in April 2018, he retained access to certain corporate resources that he later exploited. His actions came to public attention through a guilty plea and related court documents filed in the Northern District of California.

In September 2018, approximately five months after leaving Cisco, Ramesh accessed the company’s Amazon Web Services‑hosted cloud infrastructure without authorization. During this unauthorized session he deployed code from his personal Google Cloud Project account that resulted in the deletion of 456 virtual machines supporting the WebEx Teams collaboration platform. The deletion caused more than 16,000 WebEx Teams accounts to be shut down for roughly two weeks, prompting Cisco to incur over $2.4 million in recovery expenses and customer refunds. Although the disruption was significant, investigators confirmed that no customer data was compromised as a result of his conduct. Ramesh pleaded guilty to intentionally accessing a protected computer without authorization and to recklessly causing damage, acknowledging that he consciously ignored the substantial risk his actions posed.

The only publicly documented tactic associated with Ramesh involves the use of custom code executed from a Google Cloud Project to delete virtual machines; no specific malware families or exploit kits are referenced in the available sources. His initial access appears to have stemmed from credentials or permissions that remained valid after his resignation, rather than from phishing, vulnerability exploitation, or supply‑chain compromise. No evidence links him to a state sponsor, criminal consortium, or any broader affiliations; the incident is treated as an individual act of misconduct. The Cisco WebEx Teams disruption remains the sole notable operation attributed to him, illustrating how insider access combined with cloud‑based scripting can produce substantial service outages and financial harm. Following the legal proceedings, reports indicated that he was no longer employed by Stitch Fix, the company where he had worked after leaving Cisco.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB