https://www.theregister.com/2025/04/29/former_disney_employee_jailed

A former Disney employee has received a 36-month prison sentence and been ordered to pay nearly $688,000 in fines after pleading guilty to sabotaging the entertainment giant’s restaurant menu systems following his termination.

Michael Scheuer, a Winter Garden, Florida resident who previously served as Disney’s Menu Production Manager, was arrested in October and charged with violating the Computer Fraud and Abuse Act (CFAA) and committing aggravated identity theft. He accepted a plea agreement in January, with sentencing finalized last week in federal court in Orlando.

According to court documents, Scheuer’s June 13, 2024 termination from Disney for misconduct was described as “contentious and not amicable.” In July, he retaliated by making unauthorized access to Disney’s Menu Creator application, hosted by a third-party vendor in Minnesota, and implementing various destructive changes.

The attacks included replacing Disney’s themed fonts with Wingdings, rendering menus unreadable, and altering menu images and background files to display as blank white pages. These changes propagated throughout the database, making the Menu Creator system inoperable for one to two weeks. The damage was so severe that Disney has since abandoned the application entirely.

Particularly concerning were Scheuer’s alterations to allergen information, falsely indicating certain menu items were safe for people with specific allergies—changes that “could have had fatal consequences depending on the type and severity of a customer’s allergy,” according to the plea agreement. He also modified wine region labels to reference locations of mass shootings, added swastika graphics, and altered QR codes to direct customers to a website promoting a boycott of Israel.

Scheuer employed multiple methods to conduct his attacks, including using an administrative account via a Mullvad VPN, exploiting a URL-based contractor access mechanism, and targeting SFTP servers that stored menu files. He also conducted denial of service attacks that made over 100,000 incorrect login attempts, locking out fourteen Disney employees from their enterprise accounts.

The FBI executed a search warrant at Scheuer’s residence on September 23, 2024, at which point the attacks immediately ceased. Agents discovered virtual machines used for the attacks and a “doxxing file” containing personal information on five Disney employees and a family member of one worker.

Following his prison term, Scheuer will undergo three years of supervised release with various conditions, including a prohibition on contacting Disney or any of the individual victims.