Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

The Disney Slack Leak Was Real—but the “NullBulge” Story Wasn’t What It First Appeared

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In July 2024, a group calling itself NullBulge claimed to have leaked about 1.1 TB of Disney Slack data. Federal prosecutors later said the core event was real: California resident Ryan Mitchell Kramer accessed a Disney employee’s computer and Slack account, downloaded confidential data from thousands of channels, and released files in July 2024. The later case also changed the story: prosecutors described NullBulge as a fake Russia-based hacktivist identity Kramer used, not a verified Russian group.

What happened in the Disney Slack leak?

NullBulge made its claim in July 2024, presenting the release as a protest tied to Disney’s treatment of artists and its use of AI-generated art. Contemporary reports described an archive said to cover nearly 10,000 channels and containing messages, files, code, images, project information and possibly credentials. Those details came from the attackers’ claims and early reporting; they should not be treated as a complete, independently audited inventory. WIRED’s contemporaneous report covered the original claim and its stated rationale.

In May 2025, the U.S. Attorney’s Office for the Central District of California announced that Kramer had agreed to plead guilty. The government said he accessed a Disney employee’s computer and Slack account, downloaded approximately 1.1 TB of confidential data from thousands of Slack channels, and released the files on July 12, 2024. That makes the leak more than an unverified boast, while not proving every claim made about the archive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Justice Department’s announcement is the key source for the later account. The figure is often rendered as 1.1 TB; some early posts used 1.1 TiB. Either way, it describes a very large download, not necessarily 1.1 TB of text messages alone.

Timeline: from an AI-art tool to a public release

  • Early 2024: Prosecutors said Kramer posted software presented as an AI-art application that contained malicious code.
  • April–May 2024: A Disney employee allegedly downloaded the program. Kramer gained access to the employee’s computer and credentials, then entered the employee’s Disney Slack account.
  • May 2024: Prosecutors said Kramer downloaded approximately 1.1 TB of confidential data from thousands of Disney Slack channels.
  • July 8, 2024: According to the plea agreement, Kramer threatened the employee and warned that the data would be released.
  • July 12, 2024: The files and the employee’s personal information were published on online platforms.
  • May 1, 2025: Federal prosecutors announced Kramer’s agreement to plead guilty.

The plea agreement provides detail on the alleged access, threats and release. In the announcement, prosecutors also said at least two other people downloaded the malicious file and that Kramer gained unauthorized access to their computers and accounts. That suggests the Disney incident may have been one target in a broader operation, rather than an attack built solely around Disney.

Who was behind the NullBulge identity?

The original public narrative centered on NullBulge, which described itself as a hacktivist group and framed the leak as opposition to AI-generated art and Disney’s treatment of creative workers. The later federal account identified Kramer as the person responsible for the Disney data theft and said he pretended to belong to a fake Russia-based hacktivist group called NullBulge.

That distinction matters. Early coverage reflected what the claimant said at the time; the later government case attributed the conduct to an individual using that identity. The evidence cited here does not support saying that Russia, or a verified Russian collective, carried out the operation. The purported AI protest was the attacker’s stated justification, not an independently established explanation for the crime.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was Disney Slack itself hacked?

The government’s account points to a compromised employee computer and account, followed by unauthorized use of that employee’s Slack access. It does not establish that Slack’s own servers or infrastructure were breached. Calling this simply “Slack was hacked” can therefore mislead: the described path is malware on an endpoint, access to credentials, account takeover and a large download from the cloud service.

This is a common distinction in cloud incidents. A SaaS service can be operating as designed while an attacker uses a legitimate user account obtained through a compromised device or stolen authentication material. The DOJ account supports describing this as unauthorized access to a Disney employee’s Slack account—not evidence of a platform-level Slack vulnerability.

What data was exposed?

The government described the download as confidential Disney data from thousands of Slack channels. Contemporary coverage and the original claims described a wider mixture of material, including internal messages, attachments, code, images, information about unreleased projects, links to internal resources and possible credentials. The full archive has not been independently inventoried in the cited sources, so those categories should remain attributed rather than presented as a confirmed list of everything exposed.

The human impact is also significant. Prosecutors said the employee’s bank, medical and personal information was released, after Kramer allegedly threatened the employee and demanded cooperation. Those details make this not only a corporate data-theft story but also an employee privacy and safety incident. Do not seek or redistribute leaked files: copies can expose personal information and confidential or copyrighted material, and publication on a forum does not make a file safe or legitimate.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security lessons for organizations using Slack

The case illustrates how several controls must work together. No single Slack setting or security product can reliably stop an attack that begins on a computer and progresses through an employee’s credentials into a cloud account.

  • Protect endpoints and restrict software: Require managed, monitored devices for work accounts; use endpoint detection and response and application controls to reduce the risk of malicious downloads.
  • Harden identity and credentials: Use phishing-resistant multifactor authentication where feasible, keep personal and work credentials separate, and store work passwords and secrets in approved managers rather than plaintext files. After a device compromise, rotate exposed credentials and invalidate active sessions and tokens.
  • Limit access and exports: Review channel membership, guest access, administrative export rights and sensitive project spaces. Monitor for unusual high-volume downloads. The public record does not establish which of these controls Disney had or lacked; they are sensible audit questions raised by the incident.
  • Plan for containment, not just deletion: Isolate the affected endpoint, preserve evidence, revoke sessions, assess legal and privacy notification duties, and watch for secondary misuse. Removing a message or taking down one copy cannot erase files already downloaded or reposted.

The lesson is broader than Slack: when an account can reach thousands of channels, endpoint security, identity controls, least privilege and bulk-export monitoring all matter.

What happened legally—and what remains unclear?

In its May 2025 announcement, the Justice Department said Kramer agreed to plead guilty to accessing a computer and obtaining information, and to threatening to damage a protected computer. Each count carried a statutory maximum of five years in federal prison, according to the announcement. That source describes an agreement to plead guilty; it should not be paraphrased as a conviction or sentence without a later court record confirming that outcome.

The cited public materials establish the broad access path, approximate volume, release date and the defendant prosecutors identified. They do not provide a complete public audit of every file in the archive, every affected Disney account, or Disney’s final internal findings. The attackers’ claim of nearly 10,000 channels remains a reported claim, while the government described data from thousands of channels.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.