/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Brian Krebs apologizes to IoT manufacturer Ubiquiti after posting now-removed articles on a “breach” based on a “sole source” currently under federal indictment

Last year, I posted a series of articles about a purported “breach” at Ubiquiti. Tweets: @quinnypig , @alyssam_infosec , @berendjanwever , @davezatz , @blowdart , @jrozner , and @g_solaria See also Mediagazer Tweets: Corey Quinn / @quinnypig : Okay—so an employee didn't breach the AWS root account and then wipe the CloudTrail logs, @ubiquiti? And then you didn't hide that fact from customers? Because the federal indictment says otherwise. https://twitter.com/... @alyssam_infosec : So he trashed Ubiquiti, costing them $4B in market cap, on the basis of a single source that has since been indicted for charges that include providing false info to the press. Those who blasted Ubiquiti for suing him, where are you now? https://krebsonsecurity.com/ ... @berendjanwever : Providing 100% reliable news is not possible but providing reliable information when and how mistakes are made is. Thank you, @briankrebs, for being open about your mistakes. This openness is greatly needed in a time where fake news is rampant. https://krebsonsecurity.com/ ... Dave Zatz / @davezatz : Krebs apologizes to Ubiquiti and deletes prior coverage of “breach” in quotes. https://t.co/SBXNrNc3de Barry Dorrans / @blowdart : That seems carefully worded. Settlement? https://krebsonsecurity.com/ ... Joe Rozner / @jrozner : Wow Krebs finally apologized to Ubiquiti. His handling of this was the thing that pushed me over the edge on him but honestly, happy to see him doing the right thing here and I hope they reach a settlement and end the lawsuit. https://krebsonsecurity.com/ ... Sol / @g_solaria : Occasional reminder that Krebs is a jerk who has always prioritized page views over accuracy, doxxed security researchers and refused to make updates to stories that are clearly incorrect. https://twitter.com/... See also Mediagazer

Krebs on Security Brian Krebs

Context & Ripple Effects

The apology closes a loop that opened in March 2021, when Krebs reported that Ubiquiti had downplayed a catastrophic breach giving root access to its AWS accounts. Ubiquiti responded by suing Krebs for allegedly false accusations of a cover-up, and the company blamed the coverage for roughly $4B in lost market cap.

What changed is the sourcing: the sole source behind the breach articles is now under federal indictment, prompting Krebs to delete the series and apologize publicly. The case joins a small but growing set of retractions in tech-security coverage, alongside The Wire's apology over its Meta investigation and Keeper's lawsuit against Ars Technica over a vulnerability story.

First-order effects

  • Ubiquiti gains decisive leverage in its lawsuit against Krebs: with the sole source indicted and the coverage deleted, public speculation turns to a settlement to end the dispute.
  • Krebs' own credibility takes the direct hit — two decades of outed cybercriminals now sit alongside a retracted series built on one unverified source.

Second-order effects

  • Security journalists and editors face pressure to require independent technical verification before publishing single-source breach claims, the exact standard The Wire admitted it skipped in its Meta coverage.
  • Companies accused in breach stories now have a proven playbook — sue, wait for the source to unravel, extract a retraction — lowering the bar for the next Keeper-style legal action against security press.

Third-order effects

  • If the pattern holds, defamation litigation becomes a structural counterweight to vulnerability disclosure reporting, raising the cost of publishing aggressive breach claims and pushing outlets toward multi-source verification norms.
  • The episode also sharpens scrutiny of how market-moving security claims are priced by investors: a $4B market-cap swing traced to one source argues for slower confirmation cycles on breach news.

The trend: Single-source cybersecurity scoops are increasingly ending not in follow-ups but in retractions and lawsuits, as companies learn that waiting out an unreliable source can beat disputing the story.

Discussion

  • @g_solaria Sol on x
    Occasional reminder that Krebs is a jerk who has always prioritized page views over accuracy, doxxed security researchers and refused to make updates to stories that are clearly incorrect. https://twitter.com/...
  • @berendjanwever @berendjanwever on x
    Providing 100% reliable news is not possible but providing reliable information when and how mistakes are made is. Thank you, @briankrebs, for being open about your mistakes. This openness is greatly needed in a time where fake news is rampant. https://krebsonsecurity.com/ ...
  • @jrozner Joe Rozner on x
    Wow Krebs finally apologized to Ubiquiti. His handling of this was the thing that pushed me over the edge on him but honestly, happy to see him doing the right thing here and I hope they reach a settlement and end the lawsuit. https://krebsonsecurity.com/ ...
  • @alyssam_infosec @alyssam_infosec on x
    So he trashed Ubiquiti, costing them $4B in market cap, on the basis of a single source that has since been indicted for charges that include providing false info to the press. Those who blasted Ubiquiti for suing him, where are you now? https://krebsonsecurity.com/ ...
  • @blowdart Barry Dorrans on x
    That seems carefully worded. Settlement? https://krebsonsecurity.com/ ...
  • @davezatz Dave Zatz on x
    Krebs apologizes to Ubiquiti and deletes prior coverage of “breach” in quotes. https://t.co/SBXNrNc3de