The discourse surrounding ransomware takes center stage as we engage with investigative journalist Geoff White, whose extensive research delves into the notorious Conti Ransomware gang. This episode elucidates the profound implications of ransomware attacks, which have escalated beyond mere data encryption to encompass severe extortion tactics that threaten the integrity of personal and organizational data alike. White articulates the critical need for public awareness regarding the mechanisms and repercussions of ransomware, especially in light of recent high-profile attacks that have reverberated across various sectors in the United Kingdom.
Furthermore, we explore the intricate dynamics of cybercrime, including the intersection of state-sponsored hacking and organized crime, revealing how these elements coexist and influence one another. In shedding light on the inner workings of the Conti gang, we aim to equip our listeners with the knowledge necessary to navigate this complex and evolving threat landscape effectively. The exploration of ransomware, particularly through the lens of the Conti Ransomware gang, presents a multifaceted narrative that delves into the complexities of modern cybercrime. Investigative journalist Geoff White, known for his extensive work in exposing organized crime and technology intersections, articulates the profound implications of ransomware on both corporate and individual levels.
This episode sheds light on the alarming trend where ransomware has transitioned from mere data encryption to more sophisticated extortion tactics. The discussion is framed within the context of recent high-profile attacks on major UK entities, illustrating how these breaches have penetrated public awareness and sparked discourse on cybersecurity. White elucidates the significance of the unprecedented leak of 300,000 internal messages from the Conti gang, offering a rare insight into their operational mechanics and ethical considerations. This leak has unveiled not only their technical strategies but also the internal debates regarding the morality of targeting critical sectors such as healthcare. Such discussions prompt critical reflections on the broader ethical landscape of ransomware, as victims often grapple with the decision to pay ransoms to recover vital data, raising questions about the ramifications of empowering criminal enterprises.
The conversation further enriches the understanding of ransomware's intertwining with traditional organized crime, showcasing how the financial flows from ransomware operations can fuel various illicit activities. White and host Joe Carson emphasize the necessity of enhancing public awareness and education on these issues, advocating for proactive measures that would empower individuals and organizations alike to recognize and combat ransomware threats. As ransomware evolves, the episode serves as a crucial reminder of the collective responsibility to foster a more informed society, one that is equipped to navigate the increasingly complex landscape of cyber threats.
Takeaways:
Links referenced in this episode:
Hello, everyone.
Speaker A:Welcome back to another episode of the Security By Default podcast.
Speaker A:I'm the host of show Joe Carson and it's awesome to be here.
Speaker A:Always.
Speaker A:My favorite time of the week is where I get to talk to really cool, awesome people.
Speaker A:That really insightful, you know, brings me knowledge, brings me the curiosity and gets me excited about the passion I have for this industry.
Speaker A:So I'm really excited to bring you a guest who's been on the previous podcast, but now first time on this podcast.
Speaker A:So, Jeff White, welcome to the podcast.
Speaker A:If you can give the audience a little bit about yourself, background, your origin story, how do you got into the industry and where did you really, where did you get started off?
Speaker A:Here.
Speaker B:Sure, yeah.
Speaker B:Thanks.
Speaker B:So, yes, I'm Jeff White and I'm an author and investigative journalist.
Speaker B:And what I basically cover is organized crime and technology.
Speaker B:So ever organized crime and tech crossover, that tends to be where I hang out.
Speaker B:And how I got into that was I was a journalist for Channel 4 News for many years, the big UK news program covering technology.
Speaker B:And the issue we had basically was that technology stories, they were always a kind of nice to have funny story at the end of the program.
Speaker B:You know, particularly back in the day, it's video games and Apple product launches and that kind of thing.
Speaker B:It didn't seem very serious.
Speaker B:And as a result, we kept getting dropped from the end of the program because if something important happens, it goes in at the top of the program and you've got a limited amount of time, so whatever's at the bottom of the program gets dropped.
Speaker B:And I just got really annoyed with that.
Speaker B:And also I didn't get into journalism to cover product launches.
Speaker B:You know, I wanted to do hard news.
Speaker B:So I started doing more investigation.
Speaker B:And then that led me into the sort of cyber security, cyber crime kind of space.
Speaker B:And through that started looking not just at cybercrime, but tech crime, generally, financial crime.
Speaker B:Obviously there's a lot of technology involved in that.
Speaker B:Money laundering, of course, has become increasingly high tech.
Speaker B:So now what I cover is basically all of those types of, if you like, for crime.
Speaker A:Fantastic.
Speaker A:Excellent.
Speaker A:You know, what was kind of what, you know, you're working on some upcoming documentaries and stuff, which should be around the same time we launched this podcast.
Speaker A:Can you tell us a little bit about what have you been working on this last year or six months plus what's the exciting news that you have?
Speaker B:Yes, well, so it's always frustrated me a little bit that ransomware, although in the industry it's accepted as a huge phenomenon still with the general public, it's not been something general public have been hugely aware of.
Speaker B:That's obviously changed now, particularly in the UK with the attacks on Mark Spencers and Co op and Jaguar Land Rover.
Speaker B:We've had this remarkable moment where a cyber attack affected our country's gdp, which hasn't been looking particularly healthy for a few years now.
Speaker B:So we can do without that.
Speaker B:But it frustrated me.
Speaker B:There'd not been really a way for the general public to get into the issue of ransomware and to understand it and to understand how it works.
Speaker B:And so we were kicking that around to try and work out how we would deal with that.
Speaker B: ably Conti, you know, back in: Speaker B:At that point, we had this astonishing leak of information.
Speaker B:I mean, 300,000 messages from inside the gang got leaked for reasons we can go into.
Speaker B:And we did go into the.
Speaker B:The BBC podcast I've been working on.
Speaker B:And so I wanted to try and tackle the issue of ransomware, but also do it in a way that the public could understand and really got into the heart of this and actually really got our arms around the whole subject.
Speaker B:And this leak of data was.
Speaker B:Was really pivotal.
Speaker B:So podcasts have done for the BBC World Service.
Speaker B:It was called the Lazarus Heist because we were covering the Lazarus Group, which was a North Korean group.
Speaker B:It's now been renamed Cyberhack.
Speaker B:Not my favorite name, but there you go.
Speaker B:But it does allow us to cover way more than we used to.
Speaker B:So the Conti Gang and the Story of Ransomware is going to be our new series for that BBC Cyber Hack strand.
Speaker B:And that's going out in on 1st of June this year.
Speaker A:Fantastic.
Speaker A:That's actually really exciting.
Speaker A:I mean, I've kind of, of course, been covering it myself from a researcher perspective for a long time.
Speaker A:And I completely agree with you.
Speaker A:It's really kind of from the, you know, this typical person on the street, you know, or at home, the families in society, they kind of be somewhat.
Speaker A:Be a bit disconnected until it really hits home, until it affects them.
Speaker A:And I remember working on one case a couple of quite a couple of years ago now, maybe four years ago, where it was a small business, but it was a small business where it doesn't impact just the business, but the crossover between the business and their personal life was also impacted.
Speaker A:Yeah, all of the drives were the accounting and stock information was the Same drives where they stored their family photographs and their digital life and history.
Speaker A:And when they got impacted, the attackers were asking for tens of thousands of euros in order to decrypt it.
Speaker A:And that's something that you know, would really harmfully, you know, impact the business.
Speaker A:But also they had to make the decision because it was photographs and videos of grandparents that had, you know, no longer been around, and that's that connection to their past.
Speaker A:And it was a really tough decision.
Speaker A:That's where you also get into the question is, you know, a lot of researchers have always say in the past, don't pay the ransom because you're feeling, you know, crime, which I agree with.
Speaker A:But at the end of the day, you have to think about people's lives as well.
Speaker B:Yeah, yeah.
Speaker A:The decision.
Speaker A:So in that case, I took the effort in helping negotiate down to, you know, just a few hundred euros in order to be able to get that life, that digital life that they had lost back.
Speaker B:It's interesting.
Speaker A:So negotiation does work in a lot of cases, especially when you're using empathy.
Speaker A:But.
Speaker A:And even when we hear about the misinterpretation about how many people's paying actually ransomware itself, I think the Kunti leaks showed us that we'd underestimated a lot because, you know, the assumption was maybe a couple of hundred million.
Speaker A:And that was like, showing that it was actually, I think Conti was.
Speaker A:Was a cyber crime unicorn in many cases because of the amount of kind of money it went through, their kind of systems and ransom demands, possibly.
Speaker B:So, yeah, I mean, we know it's in the hundreds of millions.
Speaker B:The FBI assessment, the US government assessment is 158 million.
Speaker B:That's a vast understatement.
Speaker B:I mean, there are.
Speaker B:As you comb through the Conti leaks, you start to come across examples of companies that were not in the public domain.
Speaker B:And I've come across companies that still, it's not been reported that they were targeted by Conti would almost certainly have paid up.
Speaker B:And so you're looking in the hundreds of millions, and that's Bitcoin prices.
Speaker B:2022 Level.
Speaker B:Bitcoin's price since Donald Trump came into power has roughly doubled.
Speaker A:So, yeah, you might not give you an idea.
Speaker A:Yeah.
Speaker A:So tell me about what was your kind of interest?
Speaker A:You know, one of my favorite.
Speaker A:You know, I've.
Speaker A:Your books over the years have been amazing.
Speaker A:I really enjoyed the Lazarus heist was a fun read.
Speaker A:And then the last time we did the episode was when you were launching Rinsed, which for me was.
Speaker A:It was a big Realization when I went and read the book, because it really kind of where a lot of my skills focuses on the digital forensic side of things.
Speaker A:And you really kind of highlighted to me that there's this convergence between financial investigations and the digital investigations and how important they are together.
Speaker A:What was the findings when you're doing the research?
Speaker A:Did you start finding more that convergence overlap and how both financial investigators and digital investigators.
Speaker B:So what was, what was interesting was looking at, and this is one of my big bugbears, is that I feel we've got this unhealthy separation in our world between financial crime, fraud, money laundering and cyber.
Speaker B:When you meet those people, they come from different backgrounds, usually they inhabit different worlds.
Speaker B:The conferences are generally separate, the companies are generally separate, but often they're dealing with a lot of the same threat.
Speaker B:You know, if you're a cybercriminal and you steal a bunch of money, you have to launder it somehow.
Speaker B:You have to have some laundry facilities somewhere to, to wash that money.
Speaker B:You can't buy your Lamborghini still these days, mostly in bitcoin.
Speaker B:It just doesn't work.
Speaker B:You know, you've got to have, and also, you know, most Lamborghini dealerships, because Lamborghini doesn't want to be involved in, you know, criminal proceeds.
Speaker B:Lamborghini dealerships will sell Lamborghinis to people who can prove where their money came from.
Speaker B:You know, going along with a bag full of bitcoin is not really going to work.
Speaker B:So you need to have these kind of off ramps and on ramps for the money laundering.
Speaker B:Now, one of the things we don't go into in the BBC podcast, which is fascinating, is the work the National Crime Agency's done around what happens to the profits from ransomware.
Speaker B:There's an amazing operation called Operation Destabilize, which the National Crime Agency were originally going to call Operation Accumulatively.
Speaker B:But as I've just illustrated, I think they realized that was just too difficult a word.
Speaker A:Yeah, it could be a.
Speaker A:Could be a quick tongue twister, especially when you're trying to pronounce it.
Speaker A:Yeah.
Speaker B:So destabilized was a lot, a lot easier to say.
Speaker B:Certainly what they discovered was that ransomware profits were washing into what they say is a vast network of money movers around the world.
Speaker B:And those money movers connect ransomware gangs with street level drug dealing in the uk so the people who peddle heroin on our streets in the UK they also connect it with Russian government influence operations.
Speaker B:So the Russian government channeling money into the UK to fund Media, Kremlin Media here to fund spy rings in the uk.
Speaker B:Also sanctioned Russian individuals who want to buy property and pay their school fees.
Speaker B:In the UK there was this nexus of dodgy money and inevitably the ransomware gangs were part of that because they've got dodgy money that they want to get rid of.
Speaker B:There's this sort of underground banking system for people who for various reasons can't be honest about their money.
Speaker B:And ransomware and cybercrime absolutely feeds into that.
Speaker B:So if you're in the cyber space and you think, well, financial crime, fraud, money laundering, doesn't really affect me.
Speaker B:Absolutely it does.
Speaker B:The people who are hitting you and hacking you, they are taking the money they get and they are putting it into these networks.
Speaker A:Absolutely.
Speaker A:It always remind me that was the other thing is that when you do pay ransom demands is that you tend to be fueling, you know, it's an entire criminal ecosystem and as you're, you're pointing out is that it's probably easier for the criminals to exchange services between criminals because it's easier to kind of keep the money off the books.
Speaker B:Yeah.
Speaker A:And you know, when you're doing that, you know, you end up fueling other crimes.
Speaker A:Your software, illegal software, you end up creaming human trafficking, drug trafficking, you know, drug kind of criminals.
Speaker A:So it kind of gets into this whole entire ecosystem.
Speaker A:What's some of the interesting, you know, one of the things we look back, you know, as is the, you know, attribution of criminals still very much, you know, the likes of North Korea, you know, Russia, Iran.
Speaker A:Is it still the usual, you know, state actors and mercenaries?
Speaker A:Are you finding it is expanding beyond all of that?
Speaker B:It's interesting, yes.
Speaker B:We've still got, you know, state level activity.
Speaker B:And so frankly, the uk, the us, every country worth its salt has government hackers.
Speaker B:That is just the game.
Speaker B:It's the modern face of espionage.
Speaker B:That's what happens.
Speaker B:What makes North Korea such an interesting example, the reason I've covered it so much and keep covering it, is because it's, it's this interesting nexus between sort of state level power and criminal power.
Speaker B:You can look at what North Korea does to try and steal money to top up its coffers because of course North Korea is sanctioned it unable to get its hands on legit money a lot of the time.
Speaker B:So it's, it's hacking to steal money.
Speaker B:It's like, well, is that nation state hacking or is that cybercrime?
Speaker B:It's actually a hybrid of both.
Speaker B:That's why North Korea is such a fascinating example to look at.
Speaker B:But what's interesting is as our world starts to fracture, we're going to be in an increasing, increasingly fractured world.
Speaker B:And you can look at Russia as an example of this.
Speaker B:As states start to break away from traditional sort of linkages, their ability to move money around is going to become increasingly part of what the private sector does.
Speaker B:So, for example, you know, the Russian government wants to funnel money into the UK to fund pro Kremlin media.
Speaker B:It's stopped from doing that by sanctions.
Speaker B:The UK government will try and stop Russia from doing that.
Speaker B:So the Russian government, according to National Crime Agency, works with private individuals who are working on the criminal side, but also work on the government side to help funnel money around.
Speaker B:So what we're seeing is this blending of sort of state power with criminal rails on which all of this stuff can happen.
Speaker B:There's a great book, by the way, by a guy called Miles Johnson called Chasing Shadows, which is all about how Hezbollah in Lebanon worked with drug cartels in Colombia and how the two of those came together.
Speaker B:It's a really fascinating book.
Speaker B:And issues like that where you start to this blending of state stuff with criminal stuff.
Speaker B:I think that's going to become more prevalent in the future.
Speaker A:Absolutely.
Speaker A:The mercenary side of things where they're just basically, you know, people fire, you know, to do those activities, whether it be in skill or just people who's looking to, you know, give their space from their homes to, you know, computers that will operate and appear to be coming from those countries.
Speaker A:So, you know, a lot of that disinformation campaigns that we see quite commonly.
Speaker A:One of the things that kind of was interesting was, you know, one country, basically it was when the Russian government appeared to take down Conti.
Speaker A:How, how was.
Speaker A:Do you think that was more of a show entertainment type of thing, you know, on the front?
Speaker A:Or was it, you know, a proof of example to other criminals to get in line.
Speaker A:What was kind of, what was your thoughts around that scenario?
Speaker B:It's very, it's very, very interesting.
Speaker B:And I think people in the UK and outside Russia have this idea that Russia is this wild west where anything goes, you know, that there's no law enforcement, it's all co opt and so on.
Speaker B:That's not altogether true.
Speaker B:I mean, Russia has a criminal code.
Speaker B:They enforce it.
Speaker B:You know, there are police officers in Russia and actually, you know, in the uk, National Crime Agency, people in the FBI who've worked and Secret Service who've worked occasionally with Russian officers do find some commonality there that, you know, there are Russian Officers who want to do a good job and enforce the law.
Speaker B:And you do see this every now and again.
Speaker B:Amazingly, one of the stories we cover in the podcast is the incredible tale of the 25th Floor Film Company, which was a film company.
Speaker B:They made and distributed films.
Speaker B:We actually spoke to a guy who was writing a film for them.
Speaker B:The film was going to be called Botnet, and it was going to be about cybercrime.
Speaker B:So he went across to meet 25th floor and found them remarkably well informed about cybercrime.
Speaker B:And that's because certainly According to the FBI and various others we've spoken to, 25th floor was a front company for laundering money from Russian cybercrime.
Speaker B: th floor gets raided in: Speaker B:So the Russian police came in, they raided the place, they shut the place down.
Speaker B:They didn't, it seems VICT the people behind this, but it was a slap on the wrist.
Speaker B:It was basically like, you can't do this.
Speaker B:And we've seen this in various, various times.
Speaker B:You know, there are arrests, there are raids.
Speaker B:It's difficult to get an absolute steer on why that stuff happens.
Speaker B:It could be that the Russians are enforcing the law.
Speaker B:It could be that someone within the gang hasn't paid off the right police officer or the right, you know, individual in the government.
Speaker B:It could be that a rival gang wants to put that gang out of business.
Speaker B:So they've managed to convince the law enforcement guys to go after them.
Speaker B:It's quite a lot of smoke and mirrors.
Speaker B:But we do know that these.
Speaker B:These things happen.
Speaker B:In fact, one of the key members of the Conti gang, I got told fairly recently was arrested by the Russian security services.
Speaker B:However, can't find any more details on that and any more information.
Speaker B:And so there's these tantalizing moments where something happens, but you're not quite sure why it happens.
Speaker B:What is the dynamic behind that in Russia?
Speaker A:Yeah.
Speaker A:Or what's the outcome?
Speaker A:Where does that individual end up, you know, is a part of, you know, do they become part of the offensive team eventually to pay off their service as well?
Speaker A:So bring it back into the citizen side of things?
Speaker A:Is that how important is it for them to be aware of ransomware and the evolution of ransomware as well?
Speaker A:Because it's no longer just about encrypting data.
Speaker A:It's become more of extortion.
Speaker A:Warriors become threatening to disclose sensitive information.
Speaker A:We've seen it in the Vastamo case in Finland, where it's a very different type of scenario where it was patient records from psychologists.
Speaker A:So how important should citizens be aware of ransomware and what things can they do in order to, you know, what sources can they get better informed about it?
Speaker B:Yeah, yeah, sure.
Speaker B:There's two sort of ways to look at this.
Speaker B:Number one is as just a member of society, citizens in society.
Speaker B:You know, the company that you worked with, gave data to, paid, used their services, could get hit by ransomware, and your information could be leaked out.
Speaker B:And one of the cases we go into in the podcast is the famous hit on Graff Diamonds, the big Juliet jewelry company.
Speaker B: It's: Speaker B:In that case, details of very, very rich and wealthy clients of graph got leaked all over the Internet.
Speaker B:It's turned into a huge story.
Speaker B:There's people like David Beckham and Oprah and Donald Trump, people who shop at Graf got their details sort of smeared all over the Internet.
Speaker B:Now, obviously that's celebrities, but, you know, on a lower level, we are increasingly going to see if these ransomware gangs continue and continue to be successful.
Speaker B:More and more people's information smeared all over the Internet that can be used, obviously to target people with phishing emails, with fraud campaigns, with extortion and blackmail, if it's a particularly sensitive service.
Speaker B:So there's that level on which people have to understand it.
Speaker B:There's also the level that lots of people are company employees.
Speaker B:And when the hacking gangs go after companies, they're going to be sending phishing emails to lots of employees.
Speaker B:So as a citizen, you may get affected by this if your data's leaked.
Speaker B:But also as an employee of a company, which a lot of people are, you have a responsibility to up your game in terms of spotting these phishing emails, these phishing messages, you know, all of us can actually play a part in that and potentially stop the company that you work for being ground to a halt and potentially put out of business because somebody answered a dodgy email.
Speaker A:Absolutely.
Speaker A:I think it really comes down to is that the more data that gets leaked out there that is sensitive, that can be weaponized against us.
Speaker A:And then when you combine it with the acceleration and what AI has been able to do and a lot of GPT engines that can really use that to get it really personalized and really targeted, where it's no longer the generic one from, you know, Africa, the Prince, you know, which is just the same, that everyone gets used to, those messages become very personalized and also translated so well.
Speaker B:Yes.
Speaker A:That there's very little mistakes.
Speaker B:Yes.
Speaker A:It gets even more difficult even for professionals to spot than just citizens on the street.
Speaker B:Yeah, and, and also on the translation point, translated into different languages.
Speaker B:I mean, previously, you know, to send phishing emails, sending them in English made sense because you've got all of the us, which is hundreds of millions of people, you've got the uk, you've got other countries where English is the common language.
Speaker B:You know, targeting Estonia, for example, or Latvia would be more difficult because you've got to learn the local language, get your phishing email.
Speaker B:Right.
Speaker B:You know, translation engines can absolutely help with that.
Speaker B:And I worry that populations that have not been massively targeted with phishing before might see more phishing attempts come their way simply because the language ability is there now for the hackers that wasn't maybe there before.
Speaker A:Absolutely.
Speaker A:We've seen it in Estonia where, you know, the language is no longer a protection for this society and it's meant that the NCSE here in Estonia has had to, you know, send out new educational to the citizens to be that, you know, the ways of spotting fishing in the past is no longer valid today.
Speaker A:Looking for mistakes is just not enough because it's going to be even better than most people's grammar and in the language they speak today.
Speaker A:So sometimes, you know, it's better to look for mistakes because then it's more likely written by a human.
Speaker B:Phishing emails have become too good.
Speaker B:They're actually better than.
Speaker A:Yeah, yeah, absolutely.
Speaker A:So what, what sources.
Speaker A:Where can, you know, for, for people to, you know, I think it really comes down to, is that, you know, people need to be aware, they need to be educated.
Speaker A:This needs also, I think, not just, you know, starting the means that we are, you know, delivering and trying to get the population to prioritize this and, and become aware of the risks.
Speaker A:But also I, you know, find that it needs to also start in schools and to get into even the younger generation because we need them to be more.
Speaker A:Not just digital natives, but we need them be digital secure natives in many cases.
Speaker A:So what's your kind of recommendations?
Speaker A:How to get it even to the next younger generation, next talent that's coming through is the documentary follow any kind of focuses around children and youth who's going to replace us in the years to come?
Speaker B:I think it's an interesting one and obviously saying this is somebody who's well advanced in years now trying to work out what the kids are looking at and what they're interested by.
Speaker B:But, you know, I have done sessions in schools and what I find interesting is the one thing that will get kids attention is if you frame it and phrase it in a way that makes sense and is relevant to their world.
Speaker B:So, for example, you know, I've gone in as a journalist and I've talked about journalism and what I've started by is saying, well, what's the news story today in this school?
Speaker B:You know, if I was going to write a front page about your school, what would it be?
Speaker B:Which teacher's done something really stupid and embarrassing?
Speaker B:Who fell asleep in assembly and dropped off their chair?
Speaker B:Starting at their level and starting in their world.
Speaker B:And their point is absolutely the best way to do, because if you just go in with an adult perspective on it or an outsider perspective, it's just not going to resonate.
Speaker B:I don't know how you sort of translate that at scale, but I do think, and, you know, look, it's interesting, I had a conversation with somebody the other day who was saying that if you look at statistics around who falls for phishing emails and for fraud attempts and so on, we have this idea that it's all older people who, you know, crumbly and don't understand this.
Speaker B:Actually, young people, the statistics this person was quoting was saying, are more likely to fall for these kind of things.
Speaker B:And even if those statistics aren't right, you know, young people do fall for this phishing stuff.
Speaker B:But what's interesting is younger people have less money.
Speaker B:So in terms of the cost per failure, if you like, of people's ability, as you get older, you have more money, so you're more of a target.
Speaker B:But those younger people are getting caught.
Speaker B:They are falling for phishing emails and they are falling for scam campaigns and scam deals on Facebook.
Speaker B:It's just the losses for those people relative to the older people is less.
Speaker B:Although if you're in your 20s and you lose £1,000, that's going to be a lot of money to you.
Speaker B:It's arguably going to be as much of an impact as if you lose 100,000 when you're in your.
Speaker B:Your 70s or 80s.
Speaker B:So I think there's some interesting dynamics around that, around thinking about what the harm on those age groups is going to be.
Speaker B:And again, targeting that and not saying, well, you lost 100 quid on Facebook Marketplace, you know, what's the problem?
Speaker B:That's a big problem for somebody who's only got 100.
Speaker A:Yeah, absolutely.
Speaker A:It makes.
Speaker A:It makes sense.
Speaker A:The impact is very different for the younger generation than it is for older from a financial side of things.
Speaker A:So the question is, what is that real, true impact moving forward?
Speaker A:So tell me a little bit more about documentary, Kenneth.
Speaker A:What does it kind of move through.
Speaker A:What's the storytelling aspect of it?
Speaker A:Where do you start off?
Speaker A:And tell me a little bit about the navigation storytelling side.
Speaker B:So we start off at Conti's sort of first big hit, and it's a really interesting one because it's a hit on a local council.
Speaker B:Ed Carton, Cleveland BOA Council in the northeast of England.
Speaker B:It's a really small local council.
Speaker B:Classic ransomware campaign starts on a Friday night.
Speaker B:Somebody had answered a phishing email.
Speaker B:There's the 3:00am call for the IT security person.
Speaker B:And it literally was a 3:00am, you know, go in, pull out the plugs.
Speaker B:So we sort of start from there and we start to unpack what happened at Redcar Council.
Speaker B:It's a slightly awkward example to use because it takes place at this point where there was a flux between how the ransomware gangs were defining themselves and being defined.
Speaker B:So we'd had this emergence of a gang called Trickbot who had various members and did various things that grew out of sort of bank hacking kind of community, but then discovered ransomware, and the ransomware they were using was the Conti ransomware.
Speaker B:Eventually they became known as the Conti Gang.
Speaker B:But at the time the Redco attack happens, there's this interesting kind of flux point and inflection point.
Speaker B:And then you can just see they just double down on ransomware.
Speaker B:From then on.
Speaker B:The Conti Gang are just doing it and doing it and doing it.
Speaker B:And what's brilliant about the leaks and the reason these leaks of information are so useful and why I spent months going through thousands of these messages.
Speaker B:I'm 45,000 messages into the Conti leaks, and I'm still going, oh, my goodness.
Speaker B:The brilliant thing about that is you can see them talking in real time contemporaneously about the hacks that they're doing.
Speaker B:So one of the issues we hacks, we talk about in the podcast is the health service executive of Ireland, Republic of Ireland.
Speaker B:There's this really interesting debate that takes place in the Conti Gang around that time, but also at other times about attacking healthcare.
Speaker B:Do we attack healthcare?
Speaker B:Is that right?
Speaker B:And that's where you start to realize the Conti Gang is not a homogenous group.
Speaker B:There is leadership, but the leadership struggles to really plant its culture across the organization.
Speaker B:There are people in the Conti Gang who absolutely do not care.
Speaker B:They're like, let's hit as many hospitals as possible.
Speaker B:It's Covid.
Speaker B:They're going to pay up.
Speaker B:We can make millions.
Speaker B:And at the other end, there are people who are saying, no, that's not what we do.
Speaker B:We are trying to be businesslike and hitting healthcare is really not going to make that argument.
Speaker B:And also we're going to get heat from everybody if we attack hospitals.
Speaker B:So you see the visibility rises playing out in real time.
Speaker B:And that's something we go into in the podcast.
Speaker B:The other thing we is, of course, the man who's allegedly behind Conti, Vitaly Kovalev, who went by the name Stern.
Speaker B:We have, for reasons that you'll have to listen to the podcast to understand, discovered a trove of videos of Vitaly Kovalev on the Internet, waving, you know, hanging out with the family, going on holiday.
Speaker B:It's absolutely astonishing that the man who's basically gangster number one, he's one of the world's most wanted cyber criminals, is popping up on YouTube and TikTok in these videos.
Speaker B:It's absolutely astonishing.
Speaker A:Fantastic.
Speaker A:I'm really excited about watching and going through and learning.
Speaker A:For me, it's been a fascinating kind of evolution that ransomware's had over the years.
Speaker A:What has happened to Conti, you know, what is kind of.
Speaker A:Where do you find, you know, have they disbanded into smaller groups?
Speaker A:What kind of.
Speaker A:What had they evolved into?
Speaker B:So what's interesting is there's this point where Russia invades Ukraine.
Speaker B:Some people in the Conti gang backed the Russian Special Operation, as Vladimir Putin called it.
Speaker B:Some members of the gang were clearly in Ukraine or Ukraine supporting.
Speaker B:That's what led to this leak of inside data.
Speaker B:Somebody got so annoyed about this, they were like, f you, we are leaking this stuff on the Internet.
Speaker B:So that's where these leaks come out.
Speaker B:It's caused pandemonium in the Conte gang after that, the gang limps on for a while, and they do actually stage, which we cover in the podcast, an attack on the government of Costa Rica, which, although it was at the tail end of Conti, really shows the evolution.
Speaker B:They went from the beginning of our series attacking a small local council in the UK to taking down an entire country's government.
Speaker B:You know, they really, really put Costa Rica through the wringer for weeks after weeks after weeks, and it became an Internet pile on.
Speaker B:Other groups were getting involved as well.
Speaker B:Conti, after that, disintegrated the National Crime Agency, the FBI, have told us that the members went into other gangs and other groups.
Speaker B:We know obviously where the man accused of being behind it, Vitaly Kovalev, we know where he is.
Speaker B:We can track him on social media.
Speaker B:He's on holiday.
Speaker B:He's clearly, you know, enjoying a Good life.
Speaker B:A lot of the gang ended up in Dubai.
Speaker B:We know that from the leaks.
Speaker B:And my suspicion with that is that they are sitting now on a vast pile of dodgy cryptocurrency, hundreds of millions of dollars worth of crypto.
Speaker B:Where and how do you take that money and transform it into pounds, dollars and then Lamborghinis, apartments and yachts and so on.
Speaker B:There is still in Dubai.
Speaker B:Dubai is quite a forward looking country in terms of crypto, but that also has an underside where that's an area where you can get rid of crypto and start washing it.
Speaker B:So my suspicion is the Conti gang senior members have either ended up in Dubai or have significant links there because that's where they're trying to offload their dodgy crypto.
Speaker B:That's my assumption.
Speaker A:Absolutely.
Speaker A:You do see Dubai and Sabu Dhabi as one of those places where a lot of the cryptocurrency influencers are showing off and showing basically their luxury lifestyle.
Speaker A:But the question is, is that, you know, and I don't think some of the, some of the criminals you covered in the past also ended up in the same location as well.
Speaker B:Exactly.
Speaker B:Yeah, yeah.
Speaker B:Famous hush puppy who laundered money.
Speaker B:North Koreans was, was living in the Palazzo Versace in Dubai.
Speaker B:Look, it's a mixed picture.
Speaker B:You know, on the one hand, as I say, these countries are trying, Abu Dhabi and Dubai trying to be forward looking, you know, financially and in crypto generally they're trying to say, look, we, we're crypto friendly.
Speaker B:The problem with that is people who have dodgy crypto will then turn up in your country because they can see, you know, conduits through which they can wash it.
Speaker B:So it's, it's, it's, it's tricky.
Speaker A:Absolutely, absolutely.
Speaker A:When you can pay for a lot of things in Bitcoin that tends to be, you know, much more acceptable also when regulations a bit more kind of lenient also kind of follows as well.
Speaker A:So always interesting.
Speaker A:But yeah, I always find that, you know, that one of the things for Costa Rica in that scenario was, I think it was also a change in targets as well.
Speaker A:When a lot of countries sanctioned Russia after the war had started, it became more difficult for those gangs to get payment through the, because of the sanctions as well.
Speaker A:So you've seen a rise in Central and South America and also African countries becoming victims following the sanctions as well.
Speaker A:So kind of because those countries didn't have the sanctions against Russia.
Speaker B:Yes.
Speaker A:So it became much easier for them to pay.
Speaker A:So, so it was a switch in Targeting to countries where sanctions were not in place because payments to the gangs could also continue.
Speaker B:Really interesting.
Speaker B:I hadn't.
Speaker B:That's a.
Speaker B:That's an interesting aspect.
Speaker B:I hadn't thought about that.
Speaker B:But, yes, that does make sense.
Speaker B:We also had, of course, the diversification of ransomware gangs because Gang X would get sanctioned, but they would basically rebrand as Gang Y and then just attack the same.
Speaker B:So, oh, we're not Gang X, you can pay us.
Speaker B:We're not sanctioned.
Speaker B:So we had that.
Speaker B:Which was an interesting evolution as well.
Speaker A:Absolutely.
Speaker A:Or they just became into the proxy scenarios where they basically become service providers to other gangs and, you know, become proxies from.
Speaker A:From a lot of.
Speaker A:I think the proxies a lot of was in Southeast Asia where they had to basically, you know, it's like, okay, we're not going to do it direct.
Speaker A:We'll just provide it as a service and now become somebody else's getting the payment and they're just getting the royalties.
Speaker A:So, you know, the ransom as a service became a big popular way to the affiliate program.
Speaker B:Yeah, yeah.
Speaker A:So their channel.
Speaker A:Channel and partners became another.
Speaker A:Another interesting area.
Speaker A:So it's really, really exciting.
Speaker A:What's.
Speaker A:What's.
Speaker A:Where do you see the evolution of ransomware moving to?
Speaker A:What.
Speaker A:What's.
Speaker A:You know, from a lot of the research that you've done for the documentary and what's next for ransomware, where's the direction going?
Speaker B:Yeah, it's interesting.
Speaker B:I think what we're going to see is there's this interesting pendulum effect with ransomware where what you've got to understand about the ransomware gangs is they don't want to get too big.
Speaker B:They don't want to become the headline.
Speaker B:And we saw this in the attack on Colonial Pipeline attributed to the Dark side gang.
Speaker B:That was a big problem for the Dark side gang.
Speaker B:And they kind of rode back from it and said, oh, we didn't want this to happen because you end up in the headlines.
Speaker B:You end up with a target on your back.
Speaker B:You know, what the ransomware gangs want to do is occupy a middle zone.
Speaker B:You obviously want to make enough money that you can buy your Lamborghini, but you don't want to make so much money and cause so many problems that you're then target number one for law enforcement.
Speaker B:So staying within that kind of middle zone is going to be quite important.
Speaker B:I think the evolution of that is going to be targeting not necessarily the biggest companies in the world, but the companies that link together or are important conduits or central connectors.
Speaker B:Between companies, you know, the Collins Aerospace, I would argue, is an example of that.
Speaker B:I'd never heard of Collins Aerospace, you know, but it turns out they're a massive linchpin tying together all these different airports.
Speaker B:So if you ran somewhere Heathrow, that's major critical infrastructure, you know, that's going to get you a lot of attention.
Speaker B:But you ran somewhere, Collins Aerospace, you have the effect on not just Heathrow or Belfast, you know, all these other airports that Collins Aerospace was servicing.
Speaker B:So you effectively, by targeting the linkages between the big companies, you get all of the effect of targeting the big companies, but without the headlines.
Speaker B:So for companies that are in that space, if you're a connector, if you're a service provider that connects all these big companies together and you're the linchpin holding some of that bit together, you're a target because they can hit you and they poison the waterhole and they poison all the beasts.
Speaker B:They don't have to go after the beasts individually.
Speaker B:I think that's the evolution.
Speaker B:If I had to lay a bet, that's why I'd back come.
Speaker A:Yeah, yeah.
Speaker A:And also the extortion war as well, you know, so you're not actually taking down the service, but you've actually stolen the data, threatening it because.
Speaker A:So then that tends to be as.
Speaker A:We as citizens don't tend to see it because the service is still functioning.
Speaker A:It's just that our data has been basically, you know, stolen and being threatened against, I think a lot of ransomware gangs.
Speaker A:They want to kind of move to the extortion where.
Speaker A:And data theft, where it's not bringing too much attention to them in the public space.
Speaker A:But there's still negotiations between the victims going behind the scenes as well.
Speaker A:So sometimes you find that that's a way to stay.
Speaker A:Stay, you know, out of the news.
Speaker B:Yeah, that's really true, isn't it?
Speaker B:Yeah.
Speaker B:With the ransomware, you know, you are really pummeling your victim, but you're also doing it quite publicly.
Speaker B:But interestingly, if we do get back to that stage, slightly depressingly, I feel like we've sort of gone back in time 10, 15 years.
Speaker B:When I first started covering this stuff, when there was data thefts and that was, you know, we just didn't realize that extortion could be part of that.
Speaker B:We're still back at the stage where stealing a chunk of data from a company is the thing that the hackers are after.
Speaker B:It's like.
Speaker B:Yeah, well, they were after that 15 years ago when I started covering this.
Speaker A:You know, Absolutely.
Speaker A:And it's interesting as well.
Speaker A:So especially with AI being able to quickly analyze that data at really fast.
Speaker A:You know, that's one thing I find is that those attackers, where they are really using AI, is to analyze the data train, you know, understand and ask it questions.
Speaker A:Where's the sense of information?
Speaker A:What's the value?
Speaker A:Where's the credit card information, you know, in that data?
Speaker A:Because it used to take them months to analyze it.
Speaker A:You know, they, you know, you've got like 10 terabytes of data.
Speaker A:Yeah, that's a lot of data to go through.
Speaker A:But if you got it, if you put it through an AI algorithm with, you know, proper GPUs and large language models and natural language processing, you can ask it questions and get answers immediately.
Speaker B:Yeah.
Speaker A:So the speed at what the attackers are understanding, what they've stolen is much more accelerated than it has ever been in the past as well.
Speaker A:And that AI gives them a lot of new capabilities.
Speaker B:Yeah.
Speaker B:I was thinking back to the Move it breach, which obviously the software that moved, you know, data around in organizations and was.
Speaker B:Was hacked a few years back.
Speaker B:Part of the issue, as I understand it, for the gang that the Klopp gang, I think I might in saying, was the movie part of the issue Klopp had was they were overwhelmed.
Speaker B:They had so much stuff they couldn't triage it.
Speaker B:A lot of victims were caught up in that.
Speaker B:Never got an extortion demand in the end.
Speaker B:To your point, you know, these days, you'd be getting chatgpt on the case and saying, right, look through this, rank these victims in order of market capitalization, you know, come up with a sense, you know, to use that tool.
Speaker B:Makes perfect sense.
Speaker B:Although I will say I did approach various ransomware gangs because obviously they have channels through which you can talk to them.
Speaker B:And I just asked them, you know, are you using AI?
Speaker B:And the few that responded did sort of say, well, no, you know, we're using it at a low level, but at the stage of negotiation, we wouldn't use it.
Speaker B:You don't want the AI running your negotiation and costing you millions.
Speaker B:But you're right, maybe in the background triaging data, some of them did say target reconnaissance.
Speaker B:AI can be useful for that.
Speaker B:So there were uses around the edges, I think, for this stuff.
Speaker A:Absolutely.
Speaker A:Even the social engineering side is also improving with the phishing heavy use in that initial target side.
Speaker A:So for the documentary, where's the ways that people can access it and where can they learn about it?
Speaker A:Is it going to be on podcasts, platforms, Is it going to be in YouTube?
Speaker A:Where's it going to be available?
Speaker B:Yeah, I think if you search BBC Cyber Hack, that's, that's the best thing.
Speaker B:It will be on BBC Sounds, which is obviously the BBC's own platform, but it'll also be on Spotify, it'll be on Apple Podcasts and wherever you get your podcasts, that's what the Americans say.
Speaker B:Ever you get your podcasts.
Speaker A:Well, I'll make sure that I'll.
Speaker A:I'll add it to the links so the show notes so people can easily find it.
Speaker A:And what ways do you.
Speaker A:How do you stay up to date?
Speaker A:You know, because, you know, for, you know, rather than reading through tons of messages from the Conti leaks, what other ways do you stay up to date?
Speaker A:How do you stay informed?
Speaker B:Well, there's a great quote from, I think, this guy called Richard Knuth, who was a software developer.
Speaker B:People who know this stuff will be ashamed of the fact that I don't.
Speaker B:Will cast shame on me for the fact I don't know which software he developed, but he was a software developer of note.
Speaker B:And he has this great quote that he said, you know, a lot of people stay on top of things.
Speaker B:They want to stay on top of things.
Speaker B:That's not my job.
Speaker B:My job is to get to the bottom of things.
Speaker B:And so famously, if you sent him an email, you get a response that said, I'm working on a project.
Speaker B:I will get back to you in three months.
Speaker B:If it's still important, then like, literally, the guy was there.
Speaker B:You know, I don't want to talk to people for three months.
Speaker B:I've got work to do.
Speaker B:So I try and I try and balance being on top of things.
Speaker B:And that's mainly through LinkedIn and through looking at the feed and following various people.
Speaker B:But I also, there are times when I have to get to the bottom of things.
Speaker B:I have to read through 45,000 Russian hacker messages.
Speaker B:So for that, I think books are really important podcasts.
Speaker B:I love a deep dive that takes you into a world and sort of explains it to you in a story.
Speaker B:And suddenly you.
Speaker B:This world.
Speaker B:There's a great book called Dead in the Water, which is about insurance industry fraud in the maritime sector.
Speaker B:It's about a ship that goes aground, basically, and the insurance stuff that happens.
Speaker B:Fascinating.
Speaker B:I had no idea about any of that.
Speaker B:And it's a brilliantly written book.
Speaker B:It's a great story.
Speaker B:So things like that.
Speaker B:I really love just taking a deep dive through a book or a podcast into world that I didn't know about and just letting a story guide you through.
Speaker B:And at the end of it, you go, I kind of understand how that world works now.
Speaker B:So.
Speaker B:And that's what I'm trying to do, you know, obviously, with things like the cyber hack and Lazarus.
Speaker A:Fantastic.
Speaker A:I mean, again, thanks for, for everything that you do.
Speaker A:So it's really, you know, a lot of the depth and details that you bring out.
Speaker A:You.
Speaker A:You really educate the rest of us into things that sometimes, you know, takes that focus and dedication in order to really analyze and understand large amounts of data.
Speaker A:And it's, it's a, it's a very.
Speaker A:I mean, it's a tough, tough thing to do.
Speaker A:It's, it's a lot of focus, a lot of research, a lot of reading, a lot of kind of just bringing context to something that for many people would not, you know, know, come to light without somebody like yourself and going through that.
Speaker A:That hard work and hard research that, that brings that information to at least the visibility and transparency that it needs.
Speaker B:That's really kind.
Speaker B:Thank you.
Speaker B:Yeah, yeah, it's, it's, it's often fun to do, but can be quite grueling as well.
Speaker A:Yeah, yeah.
Speaker A:It reminds me, I used to, I used to, years ago when I was doing financial, foreign exchange, money markets, I used to go through like, you know, digs of logs, you know, thousands and thousands of log entries looking for two goods that were actually identical to try and find where money was missing.
Speaker A:You know, it didn't do the full transaction.
Speaker A:It's tough to go through and correlate and analyze.
Speaker A:I kind of, you know, while you enjoy it, it's a difficult thing to do, at least correlate things as well.
Speaker A:If the audience has questions afterwards, what's the best way to contact you?
Speaker A:Reach out or, you know, if they want to learn more.
Speaker A:What's the best way to contact you?
Speaker B:I'm on LinkedIn.
Speaker B:If you search for Jeff White, Jeff with a gift and White, like the color.
Speaker B:There's also my website, jeffwhite Tech.
Speaker B:If you want to contact me there, my email address and mobile number is all over the place.
Speaker B:So you have people to contact me as long as they're not North Korean.
Speaker A:Fantastic.
Speaker A:Fantastic.
Speaker A:Well, there's ways to check.
Speaker A:Now, I love to say something bad about North Korea.
Speaker A:Leadership will definitely make them struggle to answer that question.
Speaker A:So there's no ways to check.
Speaker A:I love the Jim hates Scams where it's hold your hand in front of your face.
Speaker A:You, Jeff.
Speaker A:It's always great talking to you.
Speaker A:I always learn a lot.
Speaker A:Hopefully, at some point in time, we'll cross paths in person in the near future, which I'm I'm pretty sure we'll do.
Speaker A:So for everyone, hopefully, this has been educational.
Speaker A:We'll definitely make sure, you know, go watch the documentary.
Speaker A:Go learn.
Speaker A:Go.
Speaker A:Go get educated.
Speaker A:This is a really important topic.
Speaker A:It's something that impacts everybody.
Speaker A:And what myself and Jeff are really here to do is is make the world a safer place, bring information to you, help educate you, and for those in the industry, you know, help shape your career to, you know, really making it very kind of a successful one.
Speaker A:So for everyone, tune in to the Security By Default podcast every two weeks.
Speaker A:New episodes, new guests, new thought leadership.
Speaker A:Take care.
Speaker A:Stay safe until the next time.
Speaker A:Thank you.