Californian Man to Admit Role in Massive Disney Cyber Breach Involving 1.1 Terabytes of Stolen Data
A 25-year-old man from Santa Clarita, California, is set to formally plead guilty to orchestrating a significant cyber intrusion into The Walt Disney Company’s internal communications systems, federal authorities revealed Thursday.
According to the U.S. Department of Justice, Ryan Mitchell Kramer faces two federal charges: illegally accessing a computer to extract data, and making threats to compromise a protected system. Each carries a potential prison sentence of up to five years.
Federal investigators say Kramer engineered a deceptive software package disguised as an AI image generation tool, which he distributed via online developer platforms like GitHub. Embedded within the application was covert malicious code that allowed him to infiltrate computers of unsuspecting users.
One of those victims, a Disney employee, downloaded the software between April and May 2024. The hidden malware granted Kramer access to the employee’s device, enabling him to extract saved login credentials—including those that unlocked Disney’s internal Slack network.
Once inside Disney’s corporate chat system, Kramer allegedly exfiltrated an enormous volume of confidential data—roughly 1.1 terabytes—harvested from private Slack channels involving thousands of employees. The trove is said to have included proprietary information on streaming operations, theme park logistics, and forward-looking business strategies not disclosed to investors.
In July 2024, prosecutors say Kramer escalated the breach by impersonating a member of a fictitious Russian hacktivist group named “NullBulge.” He contacted the Disney employee through email and Discord, demanding cooperation under threat of public data exposure. When his demands were ignored, Kramer released the stolen material on July 12, compromising both corporate and personal information, including sensitive financial and medical data linked to the employee.
Disney has since acknowledged the incident publicly. “We appreciate the swift actions taken by federal law enforcement and are committed to ongoing collaboration to ensure accountability for cyber threats,” the company said in a statement.
Court records also reveal that other individuals downloaded Kramer’s booby-trapped software, though investigations into those intrusions remain active under the FBI’s oversight.
Kramer’s plea hearing is expected to take place in U.S. District Court in Los Angeles in the coming weeks. Assistant U.S. Attorneys Lauren Restrepo and Maxwell Coll are leading the prosecution as part of the DOJ’s Cyber and Intellectual Property Crimes Section.
In response to the breach, Disney reportedly disabled access to its internal Slack channels as a precautionary measure and is evaluating its broader cybersecurity protocols.




