{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy"},"incident":{"title":"Rippling sues Deel over a manager allegedly recruited as a corporate spy","date":"2025-03-17","date_precision":"day","victim_org":"Rippling","sector":"Technology","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was alleged.","outcomes":["Insider Access","Espionage","Data Breach"],"loss_usd":null,"loss_note":"No loss figure has been established. The complaint alleges payment to the employee laundered through an intermediary; the allegations are contested and litigation is ongoing.","records_affected":null,"threat_actor":"Alleged: a Rippling employee acting on behalf of competitor Deel. Deel disputes the allegations; a related DOJ inquiry has been reported.","summary":"On March 17, 2025 Rippling sued rival HR and payroll company Deel in the Northern District of California, alleging Deel cultivated a Rippling employee as a spy. The complaint says the employee searched Rippling systems for 'Deel' an average of 23 times a day over four months and accessed Slack channels more than 6,000 times without business justification, funnelling sales pipeline data, pricing, customer churn lists and employee contact details to Deel. Deel denies wrongdoing and the litigation continues.","how_it_worked":"The alleged access was entirely legitimate on its face. A person in a management role at a Rippling affiliate used their normal credentials to run searches and read Slack channels, activity that generated no security alerts because none of it was unauthorised in a technical sense; the abuse was in volume and purpose. Rippling exposed it with a honeypot rather than a detection rule: it sent a letter to three Deel executives referencing a Slack channel called 'd-defectors' that existed but had never contained a single message. Within hours the employee searched for that never-used channel for the first time, which Rippling argues shows the letter's contents were relayed to him. He was confronted when court-appointed solicitors sought his phone.","lessons":"Insider risk programmes need behavioural baselining on internal search and channel access, since a recruited insider's activity is authorised by definition and only its pattern gives it away.","confidence":"Alleged","sources":[{"title":"Lawsuit Alleges $12 Billion 'Unicorn' Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor","url":"https://www.rippling.com/blog/lawsuit-alleges-12-billion-unicorn-deel-cultivated-spy-orchestrated-long-running-trade-secret-theft-corporate-espionage-against-competitor","publisher":"Rippling"},{"title":"Rippling accuses competitor Deel of corporate espionage","url":"https://www.hr-brew.com/stories/2025/03/20/rippling-deel-corporate-espionage","publisher":"HR Brew"}],"entry_type":"incident","slug":"2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-rippling-sues-deel-over-a-manager-allegedly-recruited-as-a-corporate-spy"}}