“Hacker ‘NullBulge’ Admits Guilt in Massive 1.1TB Disney Slack Data Heist”

# Disney Data Breach: “NullBulge” Hacker Pleads Guilty to Stealing 1.1TB of Corporate Data

A 25-year-old California man, Ryan Kramer, has pleaded guilty to illegally accessing Disney’s internal systems and stealing over 1.1 terabytes of confidential corporate data. Operating under the alias “NullBulge,” Kramer executed a sophisticated social engineering attack that compromised Disney’s internal communications.

## The Attack Method

In early 2024, Kramer created and distributed malware disguised as an AI image generation tool on GitHub and other platforms. When installed, this malicious program gave Kramer access to users’ computers, allowing him to steal data and stored passwords.

A Disney employee, Matthew Van Andel, downloaded and executed the program on his work computer. This gave Kramer access to Van Andel’s device and the credentials stored in his 1Password manager. Using these stolen credentials, Kramer infiltrated Disney’s internal Slack channels and downloaded approximately 1.1TB of confidential information from thousands of channels.

## The Extortion Attempt

After the data theft, Kramer contacted Van Andel while posing as a Russian hacktivist group called “NullBulge.” He threatened to publish both Van Andel’s personal information and the stolen Disney data unless the employee cooperated. When Van Andel did not respond, Kramer posted on BreachForums on July 12, 2024, announcing the breach and claiming to have leaked the stolen data.

The forum post boasted about the extensive nature of the theft, stating: “1.1TiB of data. almost 10,000 channels, every message and file possible, dumped. Unreleased projects, raw images and code, some logins, links to internal api/web pages, and more!”

## Legal Consequences

Kramer has pleaded guilty to one count of accessing a computer and obtaining information and one count of threatening to damage a protected computer. Each charge carries a maximum sentence of five years in federal prison.

The FBI is currently investigating two additional victims who downloaded Kramer’s malware, giving him unauthorized access to their computers. Kramer’s initial court appearance in Los Angeles federal court is expected in the coming weeks.

Share This Article