Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 8 October 2025 (Cyber Crime Wave)

PassW0rd – 8 October 2025 (Cyber Crime Wave)

Play

Speaker A: This program is brought to you by Resonance FM. If you like what you hear, please support our work by making a donation at resonancefm.com/donate.

Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Warren. In this month’s programme, how cyber attacks are driving up global tension and the increasingly vocal demands for a response to cyber crime. June was a brutal month for cyber attacks as news reports lurched from one disclosure to another, and the list of big names was impressive. Santander Bank, Ticketmaster, the auctioneers Christie’s, and the US telecom giant Frontier Communications were among the ransomware targets making the news. Oh, hang on, that was a year ago. Since April of this year, we’ve seen the Co-op hit for £206 million, Harrods belted, Marks Spencer’s have been knocked for six in an attack estimated to have cost £300 million, and Jaguar Land Rover has been crashed so badly that there is talk of the government having to bail it out and its suppliers to the tune of £1.2 to £1.5 billion. So it’s telling that this month is Cybersecurity Awareness Month. And if you’re not aware of cybersecurity at the moment, then you must have been hiding under a stone on a desert island somewhere. But please pay attention. As it’s Cybersecurity Awareness Month, we thought we would make two programs on cybersecurity. Replaying this one from last year on hitting back at the hackers and putting out another one on how dangerous the situation now is and how much worse it is going to get. We will also be making a TV program on the issue for our sister platform TechTV, which broadcasts on www.techtv.live. We will be repeating that at the end of the program. I was the first journalist in the UK and one of the first in the world to have written and reported on cybercrime in 1989 in the Daily Express and the Sunday Mirror, and it’s really moved on in those 36 years because nothing’s really been done to stop the criminals. Last year, a number of healthcare providers featured prominently in the utterly heartless gangsters’ hit list. This year it was toddlers attending a London daycare nursery chain called Kiddo. In the end, the criminals, two of whom were arrested in Bishop Stortford in Hertfordshire, deleted the data they had stolen, albeit begrudgingly, because let’s be clear about it, these are people without a shred of compassion or care for others. As they have proved. In one ransomware attack, a crime gang called Quillim locked up the data on a number of London hospitals by attacking Synovus, a company that provided computing services to the London Hospital Trust, crippling King’s College Hospital, Guy’s Hospital, St Thomas’s Hospital, the Royal Brompton Hospital, and the Evelina London Children’s Hospital.

Speaker C: System.

Speaker B: That was a year ago, and they demanded $50 million to restore the system. Instead of ransomware attack, I was going to use the word operation because that’s what Quilliam effectively denied to the patients as well as the hospitals, as they could not carry out blood tests and so had to cancel operations, cancer treatments, and transplants. The result was that one person died and others had their health impaired. And it’s not just hospitals. Individuals are now squarely in the criminals’ crosshairs because technologically aided scams, according to the US news agency Associated Press, accounted for $137 billion worth of fraud in the US. It’s a dire situation and one we will explore a little later and in the program that is following this one on Saturday because the sheer scale of the criminal onslaught needs a response from the nations exposed to it. In June of 2024, a congressional committee asked Brad Smith, president of Microsoft, what he believes the federal government can do to protect US infrastructure from nation-state cyber attacks. Attacks and criminal incidents. Smith said the US government needs to draw red lines so it’s clear to the world what they cannot do without accountability. Smith said, we need collective action with the private and public sector and with allied governments so that when those red lines are crossed, there is a public response and people know what has happened. He added, we need to start defining some consequences right now because these threat actors are living in a world where they are not facing consequences. Something the billionaire Finnish entrepreneur and businessman Risto Siilasmaa says is long overdue. Siilasmaa, who as well as restoring Nokia’s fortunes following the company’s implosion, was also responsible for founding the successful cybersecurity company F-Secure. Now known as WithSecure. So it’s a subject close to his heart.

Speaker D: Yeah, and cybersecurity people are investing into securing AI models and coming up with technologies and solutions to identify attempts to influence AI models for nefarious purposes. And it has always been a race between law enforcement and criminals, or terrorists and counterintelligence or intelligence agencies. And that’s how it will be with the world, or in the world of AI as well. And that will never change.. But we can use AI to try to identify those attempts to poison an AI system.

Speaker B: We should also, though, prescribe some of this activity. We should say that in a world that is getting so complex, that to start to interfere with data in this way and the possible consequences of it, we should say that really that should almost become something that the United Nations becomes involved in, saying that you, you mustn’t do this.

Speaker D: I don’t know if United Nations would be the right party, but any country that is the, the victim of another state, nation-state’s attempt to harm the core systems of society should take that very seriously. And it’s, it’s a mystery to me why we are not doing that. Is we know for sure that, for example, Russia has been very diligently trying to make people lose trust in the core societal systems, like the judicial system or the parts of the political system that, that are essential to our societies. And we just, we just watch from the side. We don’t react, we don’t retaliate in any way. If we have a small shooting incident at the border, we are all up in arms and it’s very, very serious. And, and we talk about it in the, the media for days and days.

Speaker B: And that’s, that’s a minor incident. You get an attack in the UK where Hospitals are disabled, appointments are cancelled, people can’t get operations. The ramifications of that are massive. And I mean, apparently the Russian supermarket system came under attack in the last few days. That could possibly have been a retaliation, we don’t know, but it’s very unusual for cyber attacks to occur in Russia. But again, If we’re in this tit-for-tat process, that itself becomes very dangerous if you start attacking people’s infrastructure in return for an attack on your infrastructure.

Speaker D: And we shouldn’t, but we, we should issue sanctions, for example, for cyber attacks or, or attempts to influence elections. For example, we need to take it as serious as it truly is. And we haven’t.

Speaker B: And it’s a, it’s a mystery. The entrepreneur Risto Silasmaa puzzling over why we have such a strange disconnect between technological incidents and those that happen in the real world, given our critical reliance on technology. It’s a situation that’s puzzling a number of people in the US too, because the The attack being coordinated against it to ramp up those figures of $137 billion in fraud is done on an industrial scale, with the criminals organizing themselves into criminal enterprises who use offices and internal company departments identical to those of a modern business. A point Chris Grove, the director of cybersecurity strategy for Nozomi Networks, expands upon. As Grove says, not only are there offices for crime incorporated, but there are also specialist professions within the criminal fraternity and a willingness to adopt new technologies like AI. And without any of the rules used to control AI in business, it could wreak havoc, as the criminals have already proved when a program dubbed NotPetya designed to attack one system accidentally briefly threatened the global shipping giant Maersk.

Speaker F: It’s actually quite a few factors, I think, playing into each other. One is the capabilities of the attackers have gone up. You may have heard for years now about this crime ecosystem, crimeware ecosystem that is put together that enables them to do things easier. Like one guy will specialize in breaking in and he’ll sell that information to the next guy up the chain who specializes in doing the next level of the ransomware attack, and then someone else gets it after him or her, and their job is to launder the money. Someone else gets it, their job is to do the next piece. And then there’s even a double extortion tactic coming into play where someone else may even pick up a piece of this attack chain. But it’s gotten easier for them over the recent couple of years due to the efficacy of the system that they built, their crime infrastructure essentially, has enabled them to do a lot better than it used to be. And the, the speed also in which we’re connecting new systems together, especially when we get close to our critical infrastructure and automated sectors, they’re going through a phenomenal growth right now that different sides of the organizations may have already gone through at one point. So there’s things being connected that weren’t connected before, which results in millions of new devices and new— the threat surface has basically spread out really fast. So that makes for prime ripe playground for these attackers to take advantage of. So they have better tools, they have more things to go after. And then as a society, we have done nothing other than add ourselves into The dependencies. We have become so dependent on these systems, more and more dependent as we go, that we’re just putting ourselves at more of a disadvantage as days go by. We’re not moving in the opposite direction where we’re relying on them less, that’s for sure. So it’s sort of multiple things. The natural progression of technology, how society is growing, and then the capabilities of the attackers. And then now we have multiple world struggles happening at once, conflicts around the world. There’s a lot of governments and organizations that are heavily focused on other areas of things that, that, like national defense, for example, and may not be so focused on crime that is impacting individual people. And one more thing I think that is coming into play is that the attackers have moved on from just— it used to be a while ago someone would write ransomware and the goal was to steal money out of grandma’s savings account. Those days have gone. They’re not even going to waste time on those people anymore. They started to target businesses, and then once they were able to target businesses successfully and they were able to launder their money and hide their identities, then they moved on to whale hunting, essentially, where they’re targeting instead of going for crimes of opportunity, like which business is the weakest and I’m just going to break into them because they’re the easiest. They’re targeting now, picking their target, and then using all these new advanced technologies like AI to help with phishing and using their, the infrastructure that they have available. And they’re able to get much further in much larger and more critical organizations than they were before.. And so now you have an organization that’s able to make a major impact. For example, cost of gas going up in a country because part of their gas distribution infrastructure was attacked, or healthcare systems not able to provide services to its patients because of an attack. In some cases, the skilled high-end attackers are doing the whale hunting methodologies, and they kind of know what they’re doing a little bit more. But just below that surface, you have the ones that that are still just spraying and praying essentially and seeing what they can get. Sometimes they may attack it like it’s a web server at a florist, but it’s actually a very critical piece of healthcare infrastructure, and the result is much bigger than even they understand that they could have caused because it’s not their area of expertise. They didn’t realize when they knocked out a billing server, for example, it was going to take down or cause the organization to turn it down manually, this important infrastructure. So the side effects, the impacts, the ancillary impacts of these attacks can also be much greater than, than they initially thought that they set out to do. And I think all of that comes into play as to why things are getting worse today than they were before.

Speaker B: But this is one of the really dangerous things, isn’t it? We’re talking about wholesale introduction of AI by people. We’re talking about putting AI into the supply chain. We’ve already got this complex situation that you’ve just explained. Now you’re going to get somebody who will do something and it could create a disaster. I’ve been at a lot of meetings recently where people have been talking about the AI accident, which is either caused by cybercriminals And they could either cause an accident because they don’t know what they’re doing, or an accident could happen as a result of poor controls. But this is a very, very, very dangerous situation that we’re in now.

Speaker F: Yes, indeed. And it doesn’t appear to be slowing down. It’s getting some publicity now. We have what’s called the IT/OT convergence, which is the information technology side of the business that most of us talk about most of the time, but there’s also the operational technology side, which handles the robotics and all of the heating and air conditioning and the manufacturing and transportation. And it’s not computing for making graphics and gaming. It is controlling real-world cyber-physical stuff. And those things have become so interconnected over the years that when you hit stuff on the information technology side, it does have an impact sometimes on the OT side that unless they’re an expert in that whole infrastructure, they’re not going they barely know that. And so they’re literally shooting in the dark to see what they hit, and we don’t always know what the impact of that is going to be.

Speaker B: As we have mentioned, the side effects have already been felt in numerous incidents, such as the attack by Russian cyber groups on the Ukrainian infrastructure at the beginning of the war that took out a number of wind turbines across Europe. It’s a world where the edges are now blurring. Frequently, associations have developed between intelligence agencies and crime gangs, with both seeing advantages in that relationship. Intelligence agencies achieving deniability, and the criminals in return seeking protection from their enemies. A dangerous situation when the criminals start to divert the funds from their operations into terrorism and guerrilla warfare, which has recently happened in the Far East. Where Karen warlords based on the Thai border with Myanmar have set up operations in casinos to generate funds from pig sticking, a term used by the crime gangs to describe the romance sextortion and other scams that are now plaguing the US. It’s a trend that, according to Rahul Marna, a partner at EisnerAmper, an accountancy and consulting firm that advises clients on the personal threat to them can only get worse due to the use of deepfake technology.

Speaker G: From my perspective and what we’re seeing on the client side with AI, we’re seeing a lot of, uh, deepfaking starting. And so voice impersonations— I’ve had at least a half a dozen to a dozen clients this year that have come to me with stories of even family members on the true personal side where they thought they were taking a call from a family member that was in need, that needed money because of a surgery or a a banking situation or police involvement. And so they rapidly moved money and found out that it wasn’t the person, but they could swear it was the right person’s voice. And so deepfaking is something that keeps me up at night right now is how do we protect our clients? How do we protect them not only in the office, but their person? You know, Peter, years ago, we used to say we’re protecting the castle. And so when they had an office, we spent a tremendous amount of time building the layers around the castles with the moats and the bridges. And now because of this decentralized work environment, we’re really protecting the person. And so that extends from business. I think AI is facilitating perhaps the next 7-year wave or so, to use that metaphor. And I think AI technologies are being used on the good side. As well as the bad side. And I think this will be the new paradigm that happens in this new shift where you’re seeing, by way of example, nation-state actors doing things at a country level. You’re seeing organized crime much more involved, and you’re seeing entities such as healthcare where there really can be no downtime. And quite sadly, actually, where criminals are taking advantage of those situations.

Speaker H: And so Absolutely.

Speaker G: We’re at a very difficult stage and we see it here in the US tremendously. If you look at— we research different entities and IBM puts out a study, the Ponemon Study, and year on year, the US is the number one targeted and ransomed country in the world. And so we see a lot of that here in the States.

Speaker B: The analogy you can quite easily draw on all of this is that of the Barbary pirates in the 16th century, the Barbary pirates were holding all of the nations in the Mediterranean to ransom. They were breaking ransom agreements that they’d made with various different nation states and saying, you’re not paying us enough, we want more. They kept on going because people kept on paying them the ransoms. Then a new nation suddenly came into the Mediterranean. This was the Americans wanting to trade with Europe, and the Barbary pirates instantly went after the Americans for ransoms, which led to the Americans dropping the Monroe Doctrine, coming out of isolationism, and developing a navy because they wanted to protect it. And then, then the Americans responded by going into a few of the Barbary pirates’ ports and opening fire on them. Are we at that situation now?

Speaker G: Your background in history is poignant and I think a very accurate parallel to what is happening right now. In fact, there’s some ransomware groups that create ransomware products and they rent it out and say, if you want to become a pirate, here are all the tools, you could use them. And when you get the bounty, we’ll split it. And so we’re even reaching that state where you could become a pirate on demand. And it’s quite scary how easy it is to become a pirate on demand.

Speaker B: You point that out. I mean, one of the points that I made in an article about the Russian business network a couple of decades ago was that there is a lot of crossover between the Russian— the people in the Russian business network and people in Russian intelligence. And one of the things, the points that I picked out in a book I wrote about this 2005 was that Tambov, one of the big Russian crime gangs based in Saint Petersburg, was taking advantage of the technology graduates at Saint Petersburg. Turns out we’ve got to start doing something. This is a very, very organized assault.

Speaker G: I couldn’t agree with you more. I see on the US side quite a lot of conversions happening where bad actors are found guilty. You see the SEC and the Department of Justice are really taking a firm stance now starting, I would say, the last 2 years. They’ve gotten much, much stronger and found accountability and liability going all the way up to the CEO and CIO level. And if those executives are not showing what I would say a proper duty of care, they’re personally being found liable. And so with that, I think the heightened sense of awareness is there. And I’ve also seen from the bad actor standpoint When the Department of Justice and the SEC do find some bad actors, they do bring these criminals to justice. Interestingly, I’m seeing them convert some of those bad actors to work for the good guys. And I think that is an interesting parallel shift that has been happening for a few years now in the States.

Speaker B: Rahul Marna of EisnerAmper. As Marna points out, as well as homing in on vulnerable individuals in the community, the criminals are now also cynically homing in on the most vulnerable in our society, the ill, and are increasingly targeting hospitals for both ransoms, personal details, and medical data. Just as with the pirates of old, the criminals acknowledge no moral boundaries in their pursuit of plunder, because not only are the vulnerable in hospitals, so are some of the most vulnerable computer systems, according to Steve McEwen, the head of MacGyver Tech and McNerd. McEwen is a white hacker who specializes in finding the weaknesses in computer systems so they can be patched. Why are hospitals in particular so vulnerable? Why is their cybersecurity so poor? You said that they see security as a cost. Is it because also nobody’s updated any of their systems because, as far as the medical profession is concerned, uh, its priority is looking after people.

Speaker H: Yeah, I mean, you hit the nail on the head. It is because they are not willing to invest in redoing the software applications to make them more resilient for today’s day and age. Some of these systems are decades old, and, you know, even the old way of thinking, if it’s not broke, don’t fix it. But the problem is, in today’s day and age with software, you can’t do that, especially with sensitive information. There’s like applications like Epic and stuff like that that run a lot of the medical billing stuff behind the scenes, and we dealt with it personally. That thing’s super horrible to work with, super archaic, and that’s just the tip of the iceberg. Most of these applications are not being updated and maintained the way they need to be to be resistant against the level of sophistication that’s coming now. Something that was built 10 years ago can’t defend itself against something today.

Speaker B: And as McEwen points out, attacks are now incredibly sophisticated due to investment by the cybercrime gangs.

Speaker H: AI is the great multiplier and it’s accelerating development and also attacks at an unprecedented pace. Two is there’s some new technologies and programming languages that come, come into focus into the software world within the last few years. One of them is called Rust and Golang. What’s really interesting about those languages, they’re extremely fast, extremely performant, and they can run circles around other programming languages. So these, the Quillen and both the Black Hat, are both written in Rust for performance. So they can basically outmaneuver anybody trying to stop them. And they’re, they’re really building software as a service at an enterprise-level scale that even me as an engineer is like, wow, this is really quality work. Like they’re putting serious money into bad software applications that are meant to shake people down for money and cripple their organization. And they’re making a lot of money. So obviously they’re reinvesting into your architecture, which, you know, I guess is a good thing if you’re a good guy, but not so good if you’re a bad guy. So I hope that helps understanding why I think we’re seeing an influx in this area. I personally have dealt with multiple ransomware attacks at the ground floor. So I understand what they’re doing here. And second fold is the healthcare industry in particular is really old, meaning the software, the architecture, infrastructure is really dated. And a lot of them are hard to update. And it’s caused a little bit of a conundrum here where you have, you know, hackers are really accelerating their attacks and their technology ability. And then on the other side, you have the healthcare industry really not stepping up their game at the same level as the hackers are. Which unfortunately I think it’s going to take government oversight for that to happen because most of these companies see security as a cost center, not as something that should be more top of mind, which I kind of think the opposite due to what’s going on there in today’s age.

Speaker B: Steve McKinnon of MacGyver Tech and MacNerd on the spate of attacks on healthcare computing systems that have embraced the NHS. Change Healthcare, and Ascension Healthcare in the US, and the South African National Health Lab Service, amongst others. Of 37 ransomware attacks known, about 5 were on significant health systems. So what should we do about it? According to Chris Grove of Nozomi Networks, we should consider a range of options. After all, It’s what the Chinese government have done, demanding the extradition of 3 Myanmar-backed Chinese warlords who had run pig-sticking operations on Myanmar’s northeastern border with China.

Speaker F: Why can’t we go after the operators of ransomware? Like, we go after— let’s think about this for a second. If a terrorist were to come to our country and do something, whether or not they killed people, let’s just say they blew up a dam and it wiped out power for a city. But no one died. We would still track them down wherever country they were in, and we would kick in doors, and we would either handcuff them or we would throw them off the back of a Navy ship out in the ocean. We would hunt them down. And I think that time has shown the evidence of that with multiple wars that have happened around the world. Ransomware operators have the capability and the risk of having the exact same impact, and we, I think, could treat them the same. Maybe we don’t have to invade a nation for it, but using special forces and using maybe some language and some legislation, some treaties or something, um, I mean, we should be able to treat them differently than just a criminal because they are moving beyond just being a criminal. They’re— yes, they’re trying to get money, but if I blow up a dam for a million dollars, I’m not just going to be treated like a criminal. That’s a terrorist operation where I put millions of people’s lives at stake. If we treat these criminals the same, then I think it opens up a realm of new possibilities of ways to deal with them, from secret black bases where we could lock them up and scan them and infiltrate the entire network and, you know, by force get access to these things. I think, uh, should be on the table.

Speaker B: Chris Grove. But tempting as it is, the response at the moment, according to many experts, must be more nuanced, as was shown by the multinational police operation to take down the notorious Russian ransomware gang LockBit and place its leader Dmitry Koroshev on a sanctions list that is packed with Russian criminals and intelligence regions. Though their extradition is remote— Russia has never extradited one of its citizens to face charges in the West— retribution, according to Troy Hunt, head of the password credential loss alert service Have I Been Pwned, and a Microsoft regional director for Australia, is extremely difficult because of the problem of attribution.

Speaker I: Yeah, I think the kinetic response one is Is interesting that the first question always comes to mind is, well, against who? You know, I mean, it’s one thing if it’s state-sponsored, but of course a lot of these might be state-tolerated, but that’s a different story to state-sponsored. And of course, we’re in an era where on the list of things that, let’s say, Russia has done that might raise the ire of the West, ransomware is probably not right there in the top 1, 2, or 3 either. So in terms of kinetic response, you’d imagine there are many other reasons why that would happen first. I think drawing on examples like everything from LockBitSup to the Myanmar situation recently, I do agree that there’s an escalation, and I do think that the reactions are getting stronger. I mean, certainly here in Australia, we’re seeing our own government much more actively hacking the hackers, as they like to say, which we didn’t see even 3 years ago. So that’s changing very quickly. I haven’t yet seen kinetic response, but I imagine that would be something that might happen in in genuine warfare, in genuine conflict. But in the interim, it’s certainly escalating in other ways, isn’t it?

Speaker B: Some of the people that we’ve interviewed have been saying that what the Americans should be doing is using special forces or perhaps agents to go in and target particular individuals, perhaps extradite them forcefully. There is the beginnings of a loss of patience, isn’t there?

Speaker I: I certainly think patience is waning and responses are getting more severe. I mean, even the naming and shaming of individuals. Yes, it’s quite interesting because some people look at it and they go, well, what’s it going to do sanctioning someone in Russia? What’s it going to do effectively doxing them? Well, yeah, clearly they’re not about to be extradited, but you’d have to imagine life will be much harder for them even in their home country, particularly those who are sitting on tons and tons of Bitcoin. Having your face all over the media, which of course folks there would see. So it’s definitely escalating. There’s definitely more severe responses. Where will it go from here? Well, I don’t think we’re about to have SEAL teams dropping into foreign soil to take out hackers. I think we’re a long way away from that. There’d have to be some sort of serious threat against national interest to get that far.

Speaker B: But then the head of AIG In November, huge insurance company said that as far, far as they were concerned, there were four main existential threats now. Climate change. And these are in order. Cybersecurity, geopolitical tensions, artificial intelligence. All of those are intrinsically linked. Things are actually getting serious. There is this strange inability to make a disconnect, to create this disconnect between the technological world and the real world, which is absolutely stupid because we’re all dependent on this technological world. Now, if somebody had attacked banks in the UK, for example, just to sort of expand the analogy of Lockbit and taken them for a billion dollars, then, and that had been done physically, the British government would have been howling. They would have been screaming about for retribution. In cyberspace, we don’t do this.

Speaker I: Why? Well, I mean, first of all, the technological world is the real world. I agree with that analogy. I think we’ve gone past using this sort of in-real-life analogy. It’s all real life. The first thing that comes to mind in terms of the parallels between a, let’s say, physical bank robbery and a digital bank robbery is clearly the first one involves violence, which is not a factor in the second case. I do think there are some places where it seems that violence is entering into cybercrime, but But again, that requires physical presence. And once we get to physical presence, it’s a fundamentally different set of rules that are played by. Not least of which physical presence means that there is someone to actually capture within your own territory, within your own domain. Even in cases where we see large-scale digital fraud, when that’s mounted from afar, there’s no violence involved. The victims are victims of digital crimes and financial crimes as opposed to physical crimes. And of course, very often they are well beyond the scope of reach of the law enforcement agencies in somewhere like the UK. And then the other factor again is the ability to have anonymity. Very hard to walk into a bank with a gun and have the same degree of confidence of anonymity as when you’re sitting at a PC.

Speaker B: I’ve been using the analogy of the Barbary pirates in all of this. The Barbary pirates in the 16th century went round holding nations to ransom, taking their ships, enslaving their crews, putting them in chains on the oars. Everybody started paying ransoms to them. Quite often the Barbary pirates would break the terms of the ransom because they felt that they could get more, which is a situation that is analogous to now. Then another nation rocked up into the Mediterranean called the Americans, and the Barbary pirates thought, wonderful. We’ve got some other people that we can extract ransoms from, which they started to do, which annoyed the Americans. The Americans didn’t have a navy at the time. As a result of the Barbary pirates’ actions, the Americans broke the Monroe Doctrine, came out of isolation, developed a navy, went into Tunis, Algiers, and Tripoli, and started shooting the place up. That stopped the Barbary pirates. We obviously can’t do that now, but it seems to be the only way to deal with ransoms and to expand that analogy a little more. The Barbary pirates, we are essentially licensing other pirates to operate under their flag and go out from their ports. A situation— affiliates. Yeah, exactly. Very similar to cybercrime.

Speaker I: So what do you do? Well, I think in that case, it’s— we’re back to sort of where we are at the moment as it’s escalating tensions. It’s just looking for responses which are increasingly severe compared to what they have been in the past. I think all of these things do take quite some time as well. We’ve had a bit of press here lately. We’ve had some major data breaches in Australia over the last 18 months that have had a lot of government response and a lot of dedicated government resources. And one of the things that they’re talking about at the moment is we’re not in a position to ban ransoms right now, but we’re on a path to a position where we should be able to do that at some point in the future. So I think it’s really interesting to look at what other levers are available to start trying to tackle this problem and recognising that it is something that happens very gradually over the course of time.

Speaker B: Troy Hunt, head of the credential theft alert organisation Have I Been Pwned? Though there are signs of change. Indeed, Hunt is not alone. Commander Patrick Tyrrell, a former naval officer and intelligence expert who once advocated the installation of borders in cyberspace, is now less sure.

Speaker J: Oh well, I think it’s very important that effective sanctions are placed against those who commit cybercrime. So to do that, you need to be able to track them down within a reasonable timescale, because you’ve got to be able to have good proof that that particular person that was sitting at that particular machine at that particular time is the person who has now benefited from the crime that has occurred. And then making sure that there are international sanctions, which can be applied, and there will be a large number of people who will say, but I’m innocent, it wasn’t me, gov. Um, but there are always lots of people who are apprehended or who were apprehended for bank robberies who said, no, it wasn’t me, I didn’t do it. So you have to make sure you have all the necessary bits of evidence, train of evidence, you know where it’s happened. So we need to get better at it, and banks need to be much more responsive. I mean, I know they’re trying, but you know, when large sums of money suddenly disappear out of somebody’s bank account, particularly if they’re, let’s say, an old lady or an old gentleman who has never ever done anything like that before, Banks need to be— bank systems need to be a lot more aware at doing these things. There was one in the paper today where a lady said that she was telephoned to be told that, you know, large sums of money had been misappropriated from her bank account, and she was then instructed on how to, uh, how to type into her phone a certain code that would make everything better. And of course, the code disabled her phone so that all calls got diverted to presumably the person who was committing the affair. Now, you know, we need to make sure that People are more aware, but even when they’re aware, people tend to be— they want to be helpful. If someone rings them up and says there’s been a problem, your first idea is not to say, ‘I don’t want to talk to you,’ it’s, ‘How can I help you?’ So, and then of course, that’s what the scammers are basing it on.

Speaker B: Intelligence expert Commodore Patrick Tyrrell on the difficulty of attribution and retribution in cyberspace. Yet following the attack on the NHS, a popular Russian discount retail chain with over 1,000 stores nationwide was hit by a cyberattack that disrupted its services for several days. The unknown attackers took down the company’s website and mobile app, Due to the attack, Verney supermarkets couldn’t process bank cards or receive and deliver online orders. In the attack on Verney, no ransom was demanded and no one accepted responsibility, leading speculation that it could have been some form of retribution. But if retribution is difficult, What can we do? As McEwen pointed out, one of the issues with the hospitals is that their tech is outdated because their priorities are treating the sick. But perhaps it should be mandated that the physician should heal himself, to paraphrase Shakespeare. According to Melissa Ventroni, the head of the Chicago law practice Clark Hill cybersecurity team, who specializes in recovering from ransomware attacks, The real problem is a lack of investment in cybersecurity and the use of cybersecurity best practices in the West.

Speaker A: We really have to start looking at cybersecurity from a resiliency perspective, and we have to change the way that we operate. The threat actors know what’s valuable. They know in the US, Social Security numbers are valuable, and in the US, we’ve tied Social Security numbers to everything. And so you get the social and you can get a new loan for your house, for your car, you can get credit cards, you can access potentially healthcare. So until we really stop tying all that information and we devalue what it is they’re getting their hands on, they’re still gonna see value in it. And then on this concept of resiliency, I really think where, yes, we have this idea of locking people out, but if we could come up with a concept that enables or helps, for instance, in the healthcare space, let’s say a hospital gets hit by ransomware, are there facilities that we can set up that they could plug into almost immediately to still continue providing the care? And when they’re stood back up, then it gets transferred back over. I think it’s the resiliency piece we really need to look at because criminals are always gonna find a way to manipulate people or things or technology to try to make money.

Speaker B: So do you think that resilience part should be mandated Some of the people that we’ve interviewed have said that there is a need for the raising of awareness across the board in cybersecurity, that people should have those sorts of backups that you’re talking about, that they should be able to pull those systems back up very, very quickly.

Speaker A: So do you think that should be mandated? Yes, I think it should become— it should come like the seatbelts. Seatbelts are mandated. You’re required to have them. If you have a business, you should be required to have this resiliency concept. So if something does happen, then you can, you can still continue to operate, provide services to consumers, customers, businesses, etc.

Speaker B: I do think it should be mandated. Do you think also then that breaches should be mandated? Some of those we have interviewed have said obviously it’s useful for a hospital to know if another hospital has been hit, and it’s also useful to know what information they were going after. So therefore you can achieve that resiliency you’re talking about.

Speaker A: In some respects, I do think there is validity to sharing information, but we need to find a way to share it so it’s confidential. The thing that drives me nuts is this whole CVE. You look at the publishing of CVEs, and so we’re essentially telling the criminals where, where the vulnerabilities are so that those who maybe aren’t paying as close attention as they should are protected and the criminals can go get access to that information. Until we really find a way that we can share that information in such a manner that it doesn’t create more risk somewhere else, I think we need to be careful about it. What that manner is, I don’t know. I’m not 100% sure and I’ve thought a lot about it, but it certainly shouldn’t be in the manner in which we share CVEs out across the world.

Speaker B: So what should the role of government be in this? Should it be mandating this awareness, this resilience, Should it also be mandating very much like the Securities and Exchange Commission in the, in the US has been saying that you must have somebody on the board who knows about technology because they know what needs to be done?

Speaker A: I do think we need to see mandating the resiliency side of it because that’s really the operational side of it and that’s what’s going to protect people from harm. If you have this resiliency combat for concept for hospitals. You have the resiliency concept for, I mean, look at the cyber attacks on the automobile industry. And so let’s say somebody has an old clunker they were going to turn in. Well, they can’t do it. So now they’re driving in an unsafe vehicle. So really looking at it from the resiliency aspect of it. I do think the government can drive innovation a little bit more, working with the private sector on this concept of how to share information in a way that doesn’t create additional risk.

Speaker B: Ransomware recovery expert Melissa Ventroni of the Chicago law firm Clark Hill on why companies everywhere should improve their cybersecurity to protect against an attack that most businesses say they expect to happen to them. And Ventroni has her supporters. Professor Suckinchetti, director of Old Dominion University’s Center for Secure and Intelligent Critical Systems, is an advisor to the US government, and he is leading a research project into how to stop hackers compromising hospital systems.

Speaker C: When I look at the technology ecosystem in terms of the vendors who they work with, and I notice several weak links in terms of not holding the vendors accountable, and because you don’t have any— at least on the US side, I don’t know how things are crossed upon. There aren’t enough checks and balances. You know, when you say shared accountability, right, how do you hold the vendors accountable who are providing services that they would have the necessary checks and balances to protect the consumers? Usually consumers or the customers or the agents in this case, for lack of training, for lack of technical know-how, are not prepared to properly do the things they’re supposed to do. And so, yes, I definitely see a rise. As a matter of fact, there are so many unreported. That’s the part that’s scary, right? You’re mentioning the ones that we know about, but I know several, at least I’ve heard to the great point, so many unreported. And if you notice, they’re always targeting organization units who don’t have a dedicated cybersecurity staff, and they know that they don’t know. It’s not a technology problem. Problem, right? The technology is there. If you were to ask me, haven’t we solved this problem? Yes. If you ask any cybersecurity expert, state of art, state of practice, it’s all there. It’s just the same thing as health, right? Don’t we know that we need to eat right?

Speaker B: Yeah, those options are there. So what you’re saying then is that you need mandatory reporting. And what you’re saying is that there needs to be some legal structure put in place?

Speaker C: Well, I would say 3 things. I use 3 lenses. So you’re right, mandated reporting for a fact, because hear me out, right? So if let’s say Agency X or let’s say a Hospital X gets attacked, I would like the hospital community to at least know. Imagine, you know, in the hospital IT community, for lack of a better word, right? Are always plugged in. And if one gets attacked, what do we do? Because we are all sharing the same systems. So if they know how to attack one system, we are all connected to the same system. It’s just not a matter of is it probable, are they willing to come to us? So reporting will make sure that we all—

Speaker B: So according to Professor Shetty of Old Dominion University, understanding the technology and the data you use— so you know how to protect it is as much the individual and the business’s responsibility as the government’s. To be in the 21st century, you should understand it. And according to Ari Reitnam, the chief operational officer of CyberXa Technologies, an Estonian cybersecurity company that literally sits on the front line of the conflict, nestling as it does against the Russian border, That does mean making sure you have good cybersecurity, something the Estonians have a deep understanding of. Estonia is the most internet technology developed government in the world and as such plays a significant role in NATO cyber defences.

Speaker E: So there are two types of attribution. One is technical attribution. The second one is the legal attribution. In one sense, we are definitely getting better and better how to detect where are the attacks coming from and how to go back to the original state. The other thing is the legal framework where we are operating. And now we have to distinguish the frameworks where we are operating. One is the Western countries and how we operate in the legal framework. And then there are countries that don’t obey to this kind of legal frameworks and operating in a totally different dimension.

Speaker B: Because that’s another issue about this, isn’t it? Because according to everybody that I’ve spoken to, there are almost a grouping of, you could say, pariah states who are prepared to engage in this activity. Those states, according to the people I’ve spoken to, are China, Russia, North Korea, Iran, a few others. But those are seen as the main offenders. They’re pariah states. How can you have legal retribution on those?

Speaker E: That’s one thing, is that if they don’t come under the same umbrella, then legally we can make decisions on our behalf, but they will not be impacted in any way. So what it means is that we say that it has been an unlawful act, you will be, let’s say, punished by this and that, but actually nothing happens. And now that is the thing why they are becoming more braver and braver. And every single time, like in the school, so you have bullies, until you will go and face the bullies in the same means as they are doing to you, then the bullies will, you know, remain and do the same thing. So, what it comes from, from that angle is that what we have seen is that in the early days in NATO CCDCOE, they investigated how many countries in the world have in their cybersecurity strategy a point where they have this kind of offensive capabilities. When they started, I think that it was, let’s say, 10 countries. And in 2023, I think that it was close to, you know, 70 countries that told that now we have the offensive capability also built in the national cybersecurity fields. If somebody attacks us, we have the capability to push back. It’s very, very dangerous. And I’m just bringing you an example. For example, if somebody’s attacking, there are two dimensions again. One dimension is that they don’t do the cyberattacks as wide that it will have a huge impact across, you know, one nation or in, let’s say, in several nations. So what they’re doing is they are attacking, you know, hospitals, some media houses, transportation companies, and they are halting their activities for a short time. So, they understand what they are doing, and they are doing it in a limited pressure, but they are doing it constantly in different places. And then, the second dimension there is that what happens if you shoot it back and do something? Then, what we have seen is that cybersecurity doesn’t have borders. If you attack some system, and the same system is not only used, for example, in Estonia, but also in Finland, in Germany, then the same thing can happen in different locations. And now, when you have done one mistake, is that how do you then, you know, grab it together and say that I’m sorry, I wanted to attack this unit, but it spread from there to others. And now I have a chain of chaos in different places.

Speaker B: Yeah, I mean, a good example of that is NotPetya, where they hadn’t actually intended to attack the huge shipping company Maersk, but they nearly destroyed it.

Speaker E: Yes. And, you know, NotPetya was one good example. After that, what happened also in Ukraine with the wind turbines, so the same solution happened. So the Russians were attacking the wind turbines in Ukraine, but accidentally the same software was used in some of the NATO countries, and the same impact happened there. So it is overspill effect. So you can’t be sure that while you attack, you will not attack others. And if you attack back, then you have to somehow limit it by geography. But nowadays, all the systems are connected together. So even the systems that are in this kind of states, for example, you know, if we’re talking about Iran or Russia, then they still have, you know, connections outside.

Speaker B: And if we attack it, then it might overspill and go to others as well. So what you’re saying is these aren’t very accurate weapons. And as a result of Firing one of them, you can essentially send something flying off in the direction of somewhere that you didn’t want it to. You want to attack the Ukraine and you destroy a hospital system in Spain.

Speaker E: Yes. And the point there is that at the moment, what we haven’t seen is a proper cyber war. So everything what is done at the moment is a testbed. So we are testing and we are seeing and, you know, trying to understand what we do, what kind of impact it has. But at least it gives us an understanding that if we do that, then what might be the impact in this nation?

Speaker B: CyberX Technologies’ Ari Reitman, a frequent guest at NATO’s cybersecurity headquarters, on why being protected against cyberattacks in an AI and internetted world is a safer strategy than going off half-cocked in a world where you cannot be sure of what will happen. In our metaverse world, we should really work out what we need to put locks on and why. As I said at the beginning of the program, I was the first journalist in the UK to write about cybercrime back in 1989. Since then, I’ve written two books on the subject. In the first, Cyber Alert, written in 2006, I warned that the situation was dangerous and out of control and revealed that Russian hackers had even got into Downing Street. Since then, the situation, if possible, has only got worse, something we will demonstrate in our next password program on Resonance on Saturday and on Tech TV, www.techtv.live. Now, due to the complexity of the world technology infrastructure and the rapid rollout of AI, the world is now in an even more dangerous place according to the leading experts we interviewed. You can find out more on the Tech TV website and from our parent organization Future Intelligence on www.futureintelligence.com. Futureintelligence.co.uk. You’ve been listening to Password on Resonance FM, presented and written by me, Peter Warren, and produced and edited by Blue Buffery.

Speaker A: Thanks for listening and goodbye. This program has been brought to you by Resonance FM. If you like what you heard, please support our work by making a donation at resonancefm.com/donate.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00