Go back

#328 Kevin Mandia - The Man Who Exposed China's Military Hackers

197m 54s

#328 Kevin Mandia - The Man Who Exposed China's Military Hackers

Kevin Mandia, a pioneer in cybersecurity incident response, discusses his 31-year career defending against nation-state hackers. Starting as an Air Force officer in 1993, he entered the field when computer security was nascent, eventually founding Mandiant in 2004 to respond to major breaches. He contrasts Chinese and Russian tactics: China historically operated like "a tank through a cornfield," stealing massive data with little stealth, while Russia used precision strikes and better tradecraft. However, China improved sophistication post-2020. Mandia highlights the 2013 APT-1 report, which publicly named China's PLA Unit 61398, exposing widespread espionage against U.S. defense contractors and other industries, leading to a temporary halt in attacks. He also addresses the human impact of cybercrime, including stolen emails and extortion, noting that ransom payments often prevent data leaks due to criminal governance. Mandia recommends iOS for personal security, praises the Glacier app for privacy, and expresses trust in U.S. intelligence institutions. On geopolitics, he suggests China may win Taiwan through demographic and cognitive strategies rather than invasion. The conversation underscores the persistent, evolving threat of cyber attacks and the emotional weight on victims, while Mandia remains committed to protecting national interests through innovation like Armaden.

Transcription

37162 Words, 199742 Characters

English
Most guys will spend money on gear, training, supplements, everything else, and then still wear the same uncomfortable underwear all day. If you're moving, traveling, working out, or sitting for hours, you feel it. That's why I like sheath. What makes sheath different is the dual pouch design. It keeps everything separated, supported, and comfortable, so you're not constantly adjusting or thinking about it. And I like that sheath was originally built by an active duty operator who needed something that could handle long, hot, miserable days. So it was built to solve a real problem, not just look good in packaging. They're soft, breathable, and built for daily wear, travel, training, or long days on set. Feel it to believe it. Go to sheath.com/srs in use code srs for 20% off. Sheath offers a first pair of guarantee. So if it's not for you, you get your money back. That's sh-e-a-t-h.com/srs in use code srs for 20% off. Sheath, the underwear of legends. Thanks to sheath for sponsoring the episode. If you spend any time off road like I do, you already know how easy it is to end up second guessing where you're at, whether you're still on a legal trail or if the route ahead is even worth taking. That's why I've been using on-x off-road. It's an off-road navigation app that shows trails, public and private land boundaries, places to camp, and detailed trail info all in one place. And what makes it really useful is the amount of actual trail data. You can check difficulty ratings, terrain details, trail photos, even recent reports from other riders before you head out there. The other big thing is you can download maps ahead of time because once you lose service out there, your phone is pretty much useless. But with on-x off-road, everything still works offline. And if you're riding with a group, their location sharing feature lets everybody stay on the same map so nobody gets lost or separated. What I like most about it is it gives me a lot more confidence when I'm exploring somewhere new. I'm not wasting time backtracking, accidentally ending up on private land or trying to figure things out once I'm already deep into the trail system. I can plan ahead, know what I'm getting into, and spend more time actually enjoying the ride instead of worrying about navigation the whole time. Search on-x off-road in the app store or Google Play. Again, that's on-x off-road in the app store or Google Play. Kevin Mandio. Welcome to the show. Thank you. Man. Cyber. Cyber security. Got this. You ready? I'm ready. All right. We're going to make it cool. Man, I have been, yeah, I always thought Cyber Security was boring until I started researching you for the center of white holy shit, man. It's what a fucking badass. It's a weird world. I've walked the halls of a lot of the headlines people read in Cyber Security, and the press never really gets it. Nobody really understands what it's like to be a victim of a cyber crime, whether it be someone hacking you to steal all your corporate secrets or extorting you, and hey, you got to serve a higher purpose, mine's always been the phone rings. I answer it, and it's a CEO on the other side saying, "Hey, we're getting ransomed and damn it. We're not paying it." In my response, it's always like, "Hey, man, we're not paying it." Let's show up. But it's a. Sean, let's see if we make this interesting for everybody. Because I remember a judge, I testified once in a case, and a judge was like, "This stuff's so cool. I can't wait till there's like an NCIS show on it," or something like that. I'm like, "Man, if you could see the war room in a cyber case, it's just really quiet. It looks like your back room right there with those guys at it." You know what I mean? Everybody's clicking on a computer, going, "Clickety, clackety." There's nothing to see, but you can see the emotional changes in the victims, you know what I mean? You can see it on the faces. We'll make it real. What is. Let's talk about what is a victim go through? Yeah. They're like a worst-case scenario for everybody here. There's nothing. Here's bad. You're an executive at a company, and somebody breaks in, and your email gets released. It's now Google searchable, every. You know, you're at a. Let's say you got a Fortune 100, Fortune 500 company, or your photos get released, you know, things like that. Your private thoughts get released. I've seen. I've been in the room with executives when their email got posted. Nobody ever should have to go through that. I just. It's just a terrible thing to see. Even I get physiologically like I can't eat, and I'm like, "Man, this is bad." So I think that's the worst thing. It personally impacts people. It gets exaggerated. Press does search your emails. They do write articles about people, and it's happened to actors. You know, their photos get stolen. It happens. Like during our interview today, it's going to happen to some 20-year-old college kid, you know, where their photos get stolen. Nobody should ever go through that stuff. So to me, those are the ones that hurt the most. Companies survive them. You know, you get back up and running. You get your operations running. You get over the reputational hits that happen sometimes. I just feel for the people that, you know, go through losing their email. Yeah. And by the way, it goes and stages. They lose their email. Like, month later, they lose their family. You know what I mean? Some of these things are pretty bad. Is that how they always start? They always start their email? No. The intrusions are all different, right? It depends on who's doing it. You know, you have the modern nations, China and Russia, Iran, North Korea. North Korea hacks for money. Take them out. But China hacks for espionage, you know? So if they break into your company, they'll break into defense, industrial base. They'll break into any company, doing business in China. And they steal emails. They steal things, communications. But they don't post it online, Sean. They don't extort you. They follow rules of engagement that whatever their doctrine is, they follow it. But it's not destructive. They don't change your data. They're kind of like the polite hackers. The criminals, it's gotten hard. I mean, because they want to monetize any breach they've got. So they pull on every thread to monetize it, right? Though, if the Sean Ryan show got compromised, what they would try to do to you is steal your emails, steal things that matter to you and say, we're going to share it with the world unless you pass $5 million, $10 million. And those are the ones that are, you know, you're always making the least bad of 10 decisions, you know? So, short as to answer, people hack for espionage, security, securing a nation. People maybe even hack, you know, espionage to me, supports diplomacy, and then people hack for criminal reasons. And then probably there's a third, they just hack for the game of it, you know, the attractive nuisance of it. And I don't really respond to too many of those, you know. What do you recommend for people that like individuals, not who executives, but just individuals who've had their photos, their emails had, did they pay the ransom? Oh, it depends, meaning it's already happened. It is, I've never said pay the ransom or don't pay the ransom. I've never said that, but I've been in the room when people think about it. And I've sat there and gone, man, I think I'd pay this one. Like if you're a hospital, somebody breaks in and they've encrypted every machine so they're unusable. And they say for $10 million, we're going to hand you back a key to unlock all your machines again. You got two options. You're either getting every doctor in a room saying, what surgeries can we do? Which surgeries can we not do? Or you're evacuating patients or you're diverting ambulances or you're paying a ransom. And that situation, I never opine, but boy, if I said, oh, I'd get it, you know, I'd pay that one and get back online. So I've seen people pay extortions and pay ransoms. And the difference is a ransom is to like get a key to decrypt your things. Like people will ransom and say, I've hacked into your network, I've shut down 10,000 machines for $10 million. I'll turn them back on for you. And that one, you know, if lives are at stake or you want to protect the privacy, the second of the extortion is, I've hacked in, I've stolen emails, I've stolen client data, I've hacked the law firm and I've taken your briefs, those extortions are really painful. So I will release the data unless you pay me. And I see people pay it because you're protecting your customers or you're protecting people in general. So hospitals will pay, law firms would pay, yeah, it's a tough decision. And I'm, luckily, I've never had to make that decision and I hope I never have to. That's brutal. Damn. Yeah. And how do you even know that they're going to stop if you pay them? Well, exactly. Like they're only capable of one bad thing, right? And then they're done. And you don't. The reality, though, is usually that if you're getting extorted, it's highly probable whoever's extorting you is in a safe harbor like Russia. I've not, others have written that they've seen Chinese actors do this. I have personally never seen a Chinese actor extort a company or even ransom a company. So I think culturally the Chinese really don't do this. It comes out of Russia and the good news is this. If somebody in Russia hacks company A in the United States, extorts them and company A pays the extortion. Let's say they pay $20 million in Bitcoin and anonymous currency. And then they still leak the data. The reality is is people just stop paying the ransom. But I actually think there's a governance over in Russia of, oh, if you get paid… You don't post because otherwise people will stop paying and they've got a good racket going So it's been my observation when people pay the vast majority of the time the data does not leak make sense There are exceptions Sean. It's rare. I can count the exceptions on a single hand Wow, and there's probably over a thousand times we've responded to these things. How often is this happening every day? Every single during this call during I mean this interview it'll happen to somebody can we that it during our interview an eight-year-old American Woman will probably lose 200 grand of her life savings during our interview a company will get compromised and probably Extorted for five to ten million dollars. It is happening at a rate and this is not a fear and certainly a doubt thing Nobody knows the rate So then you go to the government say well how much money is getting paid in Bitcoin every year to Russian organized crime It's in the billions of dollars holy billions like the lowest estimates are billions. All we know is the lowest bounds but As I sit here today people I've worked with are Definitely responding to extortion cases and trying to figure out and there will be a new one today a big one Wow, damn and they're handled quietly and discreetly or sometimes they're front page news. You never really know Well, yeah, well, you're the guy to talk to about all this. Yeah, and yeah, exactly. I sit there and say hey, let's yeah By the time we get that phone call Sean like that there's been a breach. There's been an extortion. It's it's It's tough. Yeah, it's not that you can do about it except Work through it. How do you know? How did you meet Joe Lonstyle? He's the one that connects. Oh, yeah, Joe. Thank you So that's a great question. I you know first we haven't well, he's a Texan now Right, so he lives outside Austin, but when he moved to Woodside, California He has a place there and so we met there and in general it's a small community. You know what people are doing and He and I just knew of each other. You know, I knew what he had done with Palantir He knew I was the cyber person and just over time you get you know if something happened and he would give me a call Hey, listen, we got a company that needs this or a company needs that and you know I've been in the cyber security domain for 34 years sooner or later you're either good at it or you're not doing it You know, I like think I'm still pretty good at it. So That's kind of it. You know when people need when people had a computer intrusion. We had a unique My company kind of responded to everybody's that mattered and so I think I'm on speed dial for a lot of these folks And I'm probably Lonstyle. I'm on his speed dial when something bad happens somewhere right on yeah I'm the emergency room doctor for cyber security incidents That's a perfect way to put it. Yeah, let me give you a quick introduction here Kevin Mandia you have 30 years on the front lines of American cyber defense You began your career as a United States Air Force officer serving as a computer security officer at the Pentagon and as a special agent in Air Force counterintelligence and 2004 with no outside funding you founded Mandian and spent the next decade building it into the gold standard for Incident response Author the groundbreaking APT-1 report exposing China's PLA units 61398 in a sweeping cyber espionage campaign targeting over 140 U.S. Companies a revelation that reshaped global cyber security policy Led with transparency during the solar winds breach publicly disclosing the compromise of fire I and helping uncover one of the most significant cyber attacks in U.S. history impacting multiple federal agencies oversaw the fore oversaw the 5.4 billion dollar acquisition of Mandian by Google One of the largest cyber security deals ever and led the company through integration as the CEO Most recently you were the founder of Armaden a pioneering autonomous AI agents designed to identify and exploit vulnerabilities like nation-state Attackers backed by a record 189.9 million dollar raise from top tier investors including Incuteel the CIA's investment arm. That's right. They are in America, how is it working with Incuteel? Why not? You know I when you get in the offensive cyber the cyber domain has been contested my whole life Your whole life Sean literally. I mean it's it's something that People that are faceless nameless and have no risk and repercussions can rob people hack people extort people steal information And they can do it from 10,000 miles away, you know and so When we started you know Armaden the whole thing was We want to support the United States government like the cyber domain is contestive. That's at least when when it is contested during times of peace It's contested imagine during a time of war what it might look like, you know, so Yeah, it getting Incuteel involved to me It just felt like the right thing to do you want to service the intelligence organizations and the military it makes sense I am curious So nobody's really come out and said that they have them as an investor. I don't think we did I know how you knew that Wasn't the first one I would elicit it because now you know, you try to do business in Germany They're gonna be like all the US governments and inside of Armaden. They're not it's just you want to support the word Fuddy you want to support our intelligence agencies and you want to believe you know America can be the beacon on the hell still so do they have any Specific stipulations that they want inside into your company that other that other venture capital firms are not going to Are not going to have access to well, you know, it's funny that we're talking in Q talk to the latest Dan Brown book in Qatar The bad guys in OSHA true story. They're the bad guys somehow. It's been my career like I'm biased. I believe in the institutions of the US government You know, I served in the military people can people in every institution you can have its downsides and upsides But you look at the missions of what we try to do we try to do the right thing, you know, and It's the fastest way to bring capability to the intelligence agencies and to the military is through and could tell sometimes and I believe in what we're doing And I want to make sure the American Warfighter has the advantage in the cyber domain that simple Do they have covenants? I'm sure they do, you know, did I sit here and memorize them for your show? No, I do know they you know they'll tend the board meetings when we have them and as an entrepreneur You'll learn if you haven't yet man board meetings can be long And and I've been the operator at board meetings. I'm trying to push these things off as long as I can You know, let's start them when when finally we will start board meetings That's the problem. I was unfunded the first time so I didn't have board meetings for the first seven years of mandate But now I've done funding and I'm like should I be doing a board meeting yet? And I'm just gonna sit quietly now someone will listen to the show and say okay, Mandy. I have a board meeting I'm not gonna really Schedule until someone's begging for him, you know, but I'm sure you tell show up and and the others will show up, but we are so early on What's the value in a board meeting? Yeah, you know, it's it's they think there's value. What are you doing with their money? For me, it's let us prove ourselves and and let's get some things done first So I'm not sure I need a 90-day cadence yet. Right. Oh, I'd probably just spoke my mind and I'll have one in two weeks now Yeah I've been using Ridge for a while and what I like about them is they take everyday gear and make it cleaner tougher and more functional Wallets power banks luggage travel gear all the stuff you actually carry in use In fact, they're power banks. I just got three charges off one bank at the airport Amazing and now Ridge is back with their annual sweepstakes for the sixth year and this one is insane Two winners get to choose between a Lamborghini Aracan Storato a hennessey velociraptor a custom Ford Bronco or a hundred thousand dollars in cash I'd probably take the velociraptor It's got 558 horsepower twin turbo and it's basically American muscle built into an all terrain truck That's a hard one to pass up even if you don't win Ridge is still worth checking out their power bank is built in cables wireless charging mag safe compatibility and enough power for up to three full phone charges Their wallets are slim durable and built for everyday carry ready to upgrade your wallet and maybe you ride for a limited time only Had to ridge.com and use code srs. It check out for 10% off your order and a chance to win ridges biggest sweepstakes ever a Lamborghini Huracan Storato a hennessey velociraptor a Ford Bronco or a hundred thousand dollars in cash No purchase necessary to enter, but every dollar you spend gets you more entries That's ridge.com in use code srs After you purchase, they'll ask you where you heard about them Please support our show and tell them our show sent you As you guys know once upon a time I was a navy seal and then I contracted for CIA We were hunting ISIS Taliban terrorist organizations China was there Russia was there the Iranians were there and everybody's kind of Collecting on each other one thing I learned is how important Encryption in protecting your data is that experience is just always made me Extremely paranoid about what's being sucked out of my phone what information or people getting. I wanted something that could protect everybody and so we turned it into an application. We call it the Glacier app. We have Secure DNS. Now what's Secure DNS? Well very simply put, Secure DNS keeps your phone from being exploited while you're browsing the internet. Just a couple of buttons, your phone's protected. You got yourself a burner number or more. You hit connect, done. You're protected. This is like the real James Bond ship, MI6 CIA level stuff, made in the U.S. The Glacier app.com or just go on the app store and look up the Glacier app. Take your privacy back. Download Glacier today. Well, before we get tuned to the weeds here, this is going to be a fascinating interview. I don't think anybody can make cyber as exciting as you can in your backstory. Wow, but everybody gets a gift. Oh, thanks. And we got you a couple. Thank you. Those are vigilantly gummy bears made in the U.S.A. legal in all 50 states. Not that you have to worry about that being out in Cali, but and I'm the guy that had true story. It's in South Hall right now in the hotel. There's a little white bag on my table with your gift in it. So I'm going to send you something as well and I apologize that didn't bring it with me. I was so eager to get here. I ran out the car without it. No, sweat. I got you one other thing too. This is the most exciting. Yeah, so there you go. Yes. So that is, that's just an iPhone, but that is, that has our new application in there. So I got really paranoid through some of the interviews that I've been doing. It's for me. This for you, I want, I want your honest feedback on that. So you'll get it. Wow, thank you. So I'll give you the backstory. So I started getting paranoid about a lot of the people that I'm connected with in the U.S., out of the U.S., then we did an interview in Taiwan with Bowshi Kim. Okay. Yeah. You know all about China. We're going to talk about it later. So I started getting really paranoid and I wanted about my email about my text, about, you know, my phone. It's secured. So I started asking a lot of the former buddies or buddies of mine, they were former Intel guys. Hey, what is the latest and greatest black phone? And so I got pointed to this company called Glacier. Okay. Yeah. And so Glacier was started by a handful of former Intel guys over at NSA. And so I got to talk them with them. I got one of their phones and their phones are awesome. They secure VPN, all American VPN, secure DNS. They will upload and take away your footprint. So like when we went to Taiwan, they uploaded a false footprint, got rid of it when we got back home, can re-upload it if we go back. So nothing looks fishy. And then they have also they have virtual numbers. So I talked to them a lot about how to disappear off the internet. And they basically said, Hey, you have to, you need to keep that number. You're real numbers sacred. So what we have here is, that's awesome. You can put in a proxy to it. Any area code you want, it'll give you a list of burner numbers. It's got a great case. Thank you. It's like pull proof, right? Well, so it was hard, but we got it on the iPhone. Nice. And because nobody, nobody wants to use an Android. So that was a challenge. Yeah. The device is extremely expensive. So when I talked about going into business with them, I said, Hey, you know, this is really expensive for the everyday user, not only for the device, but for the subscription right as well, a lot of money. And so I said, what would be greatest if we could, we could dub this down into an application that's a lot more consumer friendly. So we took everything, almost everything that Glacier has put it into an app. And like I said, it's it's it's a full-blown security suite on your privacy app on your phone. But so I'd love your honesty that you'll get it. And it's weird. So now one of the things I had to learn throughout my careers, how to solve the read, write, store, and delete data. What's the app really do? You know, so we'll end up kind of reversing it. You know, we'll kind of try to figure that out. But I think you're right to be paranoid. It is a strange world where, you know, the digital exhaust we leave behind is way high. Way higher than people think. Every time you browse the web, you know, whether you say, hey, I want cookies or don't want cookies, you're get them. You know, we had a company come in and pitch us on a we got a cookie tracker. And I'm like, you know, we didn't invest in it. But we went out and just tested their software during, you know, while the entrepreneur was pitching us on hey, listen, this is this is what happens. And we went to a medical site that everybody uses. And when we connected to a child, of course, we got the prompt, do you want to accept cookies or not? We're like, hell, no, we got a bunch. We got over 900 cookies just by doing one search on one site about a specific disease. And those cookies come on to your hard drive. And then when you go to other sites, you're letting like a marketing company know, or you're letting a PR firm know, or in this case, we looked at all the cookies. And one of them was dot are you like we were sending our IP address in the sites we're visiting to somewhere in Russia. And so this this whole yeah, like everybody, we have a whole generation, by the way, it's probably waving the right to privacy by posting everything on, you know, Facebook, you know, meta. And but I get it, you know, it's right. It's like if I had to give one privacy tip, use iOS devices, use Apple. Really? Yeah, totally. Just it's not, if you look at by the way, simplest metric in the world on hey, what's really secure? Look at the payouts as somebody has a zero click exploit for the iOS phone. It's in some places, it's 20 million dollars, you know, in Apple itself, I think you can get four to six million on the bug bounty program. Like if you find a zero click, someone just like, Hey, that looks interesting. They don't touch anything. iOS is hard to compromise. And they really anyone who's on offense and can compromise it, it'll probably a modern nation and they're really coming after you. But that doesn't mean it's undoable. So I love the fact that you pick the iOS as the platform is right. Thank you. And I think more and more people probably should think, where's my data going? Who's getting it? Well, the other thing that I've actually came up with, I got to mention is there's a there's data blocking. So everything gets sucked out of your phone is no longer getting sucked out with that application. So it's a link in the description for anybody that wants to check it out. But you just mentioned, so when I was researching you and we were talking about the China, that was a section I was in the China. What is the six one six one three nine eight, six nine three nine eight. Yeah. And when I was researching that, you had mentioned that if anybody had done business in China, you're compromised pretty much. Isn't Apple doing a business? Well, they probably work compromised in some way. Interesting thing about Apple, my whole career, Apple's never called and said, hey, man, can you respond to a breach here? So there's a couple like if I went through the whole fortune 100, there might be eight of them that didn't hire us to respond to a breach. And that's it. And Apple's one of them. And they've always there's a couple of places, you know, Goldman's one, you know, they have usually homogenous networks, very similar, lots of tight controls. If anything does happen, they detect it quickly and respond quickly. And Apple's always struck me as one of those companies that's pretty damn good at security. You know, I mean, good. Yeah. Yeah, it's it's just there's something different about them. I mean, think about what they did with the iOS, they closed it. It's not like you can just write an app and do it. You've got to use their libraries, their APIs and publish it their way. You know, no one really jail breaks the iOS phone to put whatever they want on it. So if you for the most part, you almost have to hack yourself to hack your iPhone, you know, a window should pop up. Hey, this software is unsafe. You have to go, I'll take it, you know, and hit it. So except for the the rarest of cases is you're really targeted by like a foreign intelligence service. That's about the only way I think you're going to see a phone get popped. Okay. Yeah. Okay. That's good to know. Yeah. No, it's a good selection. Thank you. Thank you. You nailed it. Right on. Well, let's, so let's, I want to do a full-blown life story. All right. I'm ready. Where'd you grow up? Where'd I grow up? Formative years Pittsburgh, Pennsylvania during like the crappiest decades of living Pittsburgh. Yeah. We're winning super balls. That's about the only thing we're winning. Yeah. Not a bad thing. 70s and 80s. Every steel mill closing down. You know, I still remember probably 1984 coming home from school. My dad, I did, you know, don't of me. My dad never sat at the kitchen table unless he was eating. And I came home from school one day and A, he was home. B, he was sitting at the kitchen table. And then it hit me. Something's different. And he lost his job, you know what I mean? And I remember in an instant, you know, nonverbal communication could say it all sometimes. I instantly thought, man, he'd pick cancer over this. And so Pittsburgh was a rough place to grow up. And I spent, you know, the the late 70s and early 80s there. And then moved away from there and I went back to there. And I still remember when we left to come, man, I don't ever want to go back there. They did three years later. by that as I, "Hey, we're heading back." So anyway, formative years, Pittsburgh, great people, tough town. I think if you lived in Pittsburgh from 1970 to 1985, all you saw is a tough place. I like Detroit, you know what I mean? Sister City Detroit, I feel for that place. Yeah, what we're into is a kid, football, right? It's Pittsburgh, you know, football, baseball, basketball. I was young as the four boys. I think that matters, you know, you got somebody, you got to live in Alice Cooper fan and the older brother, you know, you learn about rock music. You know, I was 10 years younger than my oldest brother. So I got a real education on music early. Everybody played football. Everybody, you know, it didn't matter where, you know, it's a, you go in the backyard and pummel each other. You had to, you know. So it was football, baseball, basketball, and then you go to entertainment. It was like Magnum PI, Quincy. Show as you probably don't know, I mean, oh, no, I know Magnum PI. You got Fresh Prince Bill Air, I got Quincy. But you get it, it was a, you know, Pittsburgh was a black and white city. You know, you move away from that and you get to see color. But in Pittsburgh, when I met by that, it's just, it was gray, it was like it felt like it was always winter. You know, and in hindsight, you don't know it till you leave it and look back on it. It was a depressed state. Like the people were all struggling, you know, period. You know, and I was in one of the nicer towns. But I think I was in the sports, you know, and then I had a father who was old school, right? Old school is, hey, son, get A's. What that meant is get A's are all kick your ass. (laughing) - Get A's are winter, similar. - Life's gonna get real hard for you. I mean, I didn't want to find out what the alternative was. - I found out it wasn't bad. - Yeah, that's what I thought. - Well, you know it, right? I mean, my dad had a set of rules that if you broke them, you did get hit and it was fast. I always was like, "How does this large man move so quickly?" You know, but he was consistent about it, you know? People are like, "Hey, corporal punishment is bad." For me, at the youngest of four boys, I think it was necessary in a way, you know what I mean? Like we were probably gonna be pretty, my dad liked to order, quiet, clean. And I don't think you would get that naturally without some enforcement, you know, and at the edge, as they say, and my dad had that. So, I knew every time when I was gonna be disciplined, it never surprised me other than how fast he could move to do it. (laughs) And by the way, we did no good at the broad 'cause I would have just made it worse. You know, you just gotta stay there and take it. And it wasn't like it beat me. It was just, you know, we had a discipline to it. And so, you know, going back to the original question when I was into, it was probably the same every teenage boy and post-reasoned sports. Except I was a Vikings fan for some damn reason. - Yeah, I figured that one out. - So, how did you, were you into cyber security by the time you joined the Air Force? - No, it didn't even exist. So, I get in the Air Force in '93. But, you know, I graduated college in '92 and back then there was a little bit of a lag. You know, we had the Clinton years, there was a lot of rifts going on and you could do ROTC and never actually get orders. You know, so it was an interesting time for the military. It was time of peace for the most part. We had done Kuwait in the 1990 desert storm. So, I graduated college in '92 but I grew up, you know, I thought Magnum P.I. was cool. You know, he was former military, he was, you know, he saw off cases, I always felt like you, you gotta have a mission bigger than self, you gotta, you know, when you contribute to society. And I grew up a forensic fan. I mentioned Quincy earlier, I used to watch Quincy go, "Hey man, let's solve cases." I did computer science in college from '88 to '92 because I grew up with Pong. I still remember the first Pong game, Nintendo. Wow. In television, the Odyssey by Magnavox. Like I grew up with the whole Atari 2600. You grew up these games and that kind of gets you into computer. So by the time 1980 or 1981, I'm 10 or 11 years old, my Christmas present was the TRS 80 color computer. Like other kids are asking for, I don't know, stretch arms strong and rock 'em, sock 'em robots. And I'm like, "Hey man, can I get a computer?" And my dad, my mom, my grandparents all pitched in and bought me like this $700 Christmas present, which back then is like, "Are you kidding me?" That's like better than a car, Magna then, actually, Sean. So in hindsight, it should probably be more thankful. So in 1981, I got my first computer. And even though I'm playing football, baseball, basketball, running track and out, he's pummeling people, and I'd come in and be like, "Hey man, I like this computer crap," you know? So I kind of grew up with the computer. I got computer science ROTC at a small school in Pennsylvania called Lafayette College, where I went all out. I took a pencil, filled out the common application, planted one school, got in and went there. I was, there was none of this 20 schools, 10 schools, I had like no plan B. As I applied to Lafayette, did ROTC at Lehigh and did computer science. And I got stationed at a Pentagon in 1993. And the way I got into cyber security was, I got a station at Pentagon with six second lieutenants. And we were all waiting in line to go in and see a no-six, a colonel, full bird air force colonel. We were stationed at what was called the seventh communications group. And we're all, you know, chicken shitting out in the hallway who wants to go first, what do people want to do. And I like to tell you there's this elaborate plan for me to go into cyber security, but what would really happen is I went first. I was like, "I'll go meet the colonel. I'll go figure this crap out." So I just get first in line. And I go in and the '06 behind the desk gives me, and literally it's the whole thing. You go in, you know, stand at attention, go to add ease and wait. And he lays out five options for my next couple years. Here's what your assignment can be. So I actually had a choice. And all the choices were bad. And it was the weirdest thing, Sean, right at the end of it, my store remember it. He was like, "Oh, oh, when we have one slot left, "one job left to do computer security." That's what he called it. And I remember thinking all five options prior to that were horrible. Like it would have sent us to me to death. It was like job control language, mainframe programming and the basement of the Pentagon. When he said there was one slot left, I'm a sucker for there's only one left, you know? And so I'm like, "I'll take that." There's only one left, that's valuable. And you know, in hindsight, I backed it into, you know, it ends up playing out very well. I've loved forensics. I ended up getting a master's in forensic science at GW on my own time while serving. And computer security worked. Like immediately I had this job doing computer security. And what it was is who's accessing what? And about a year into me doing that job. It was 1993, the Air Force put eyes on the network for the first time. I mean, for the first time ever, we started watching. What are people doing on the network? So I kind of got to grow up with computer security. You know, we started watching people. The Department of Energy created a tool called the Automated Security Incident Measurement Tool. Interesting. And we deployed it at the Pentagon. And for first time ever, we could see what are people doing? Like what files are they transferring and what commands are they doing and where are they logging into. And when we lit it up right away, we recognized, "Wait, we're not the only ones on this network." You know what I mean? Who are these other people on it? And so by 1995, I cross-trend into the Air Force Office of Special Investigations from Computer Security to do computer intrusion investigations. The military was starting to use the internet, you know, from '93 onwards. So we had to start figuring out who the hell is on our networks and what the hell are they up to? Who was on the networks? First one I ran into was China. Literally. Go all the way back to, I think it was summer '95. Might have been summer '96. One of those summers, we, you know, at that point, we had the Air Force computer emergency response team. The Air Force had one. I don't think the Army had one yet. I don't think the Navy had one yet. And then the government had one called US CERT out of Carnegie Mellon University in Pittsburgh. And so maybe there's something in the water in Pittsburgh to get you into this stuff. But I remember there was a West Coast University. I'm in the Air Force of Special Investigations and our ASIM boxes showed something like 20 Air Force Paces were logged into from one university. What the hell's going on? Like no university should be logging into that many, you know, Wright Patterson Air Force Base, Oak Ridge, Lawrence Livermore, Los Alamos, Wright Patterson, all of them. And they were in, and so I flew out to the university and at that time frame, I'm in the United States military. I go to this university and I'm like, do you mind if I monitor all traffic tune from this machine? Now everybody's listening to us and be like, the government watches everything. We really didn't. Back then I did a brief, the judge advocate general, hey, this is what I want to do. And to the Air Force's credit, if we did what we would call wire tap and there was nothing fruitful in it, oh, it got killed fast. Like you had to have fruitful real results or a jag was going to be like, stop it, get out. There was a great control to not wantonly watch. But the university allowed consent. - Still like that? - Yeah, I don't know. You know, I often wonder if the military is the same as when I grew up, maybe a top of four later, because to me, but then it absolutely was. I remember going, man, I need to tap this because someone's coming from somewhere in the world into this system and then from there to all these military installations. So I got consent to monitor to the colleges or the university's credit, they were like, yeah, go ahead and do it. And then I, the way I did taps back then, I just ran soft on the machine itself. You know, it was a, it was a Unix machine and I watched all incoming traffic. And the first day I'll never forget the Sean summer of '95 or '96 as one of those two. The very first day I did the tap, somebody was logging, this is how you go one hop back every time. Like when some, if somebody hacked you, we'd only know the first, like IP address or first address they came from, but in computers, you can connect, to connect, to connect, to connect. And they're called hop points. And everybody obfuscates where they're really sitting. If you're sitting in Russia and hacking, you know, the Pentagon, you're not going straight from.ru to Pentagon, you're going from.ru to the UK, to China, to wherever you want. How do you pick those? They compromise them first. Like if you're on offense, you have a network that you use to launch your attacks. And for the most part, you almost have a team that maintains that compromised infrastructure for you. So if I'm a foreign intelligence service, I have a team that maintains access on all these intermittent sites, not my real targets, just sites like universities and businesses. And it's called a non attributed network of victim machines. At least this is how other nations do it against the United States. And then they have their operators use that infrastructure. And that's exactly what we ran into in this case. I do this tap out of West Coast University the very first morning I go in and like download the files to look at what happened. Somebody came directly from Beijing into West Coast University using the account of a Chinese foreign national. I went to this college, but I had since graduated and logged into 37 or so military installations. And each login was somewhat haunting. They use a user ID like S Ryan and then a passphrase. And the next one they would go to like right pat and go John's J Smith and the right passphrase. They were validating accounts at all these different places and I had the right choke point to see all the traffic. They came to this one machine logged in the right pat logged out logged into Los Oak Ridge logged out. Logged in alone, you know, Los Alamos logged out right pat it keep going down the list. And they never fat finger to passphrase. They got in every time and I remember thinking, how do we fix this? Like you can't, you call 37 basis, who do you call? They were hit in Army, they were hit in Air Force, they had the Marine Corps, they hit us all. I mean, just just for the viewer context here, those are the most secure, secret military bases that the US has. Yeah, it's just a protocol. Yeah. And it was just it was the defense research and engineering network is essentially what these guys are in and the unfortunate reality in hacking or fortunate in a few of their offense. Like if I break into the Pentagon, it's just about a time before I break into all the other military installations. If you break into an Ivy League school, you're going to be able to hack all the Ivy League's because that's just where the traffic goes. That's where the information is shared and that's what happened here. I don't know where they originally broke into, but it was extensive and that was in the 90s. And I remember there was no one to call, like that case went on for like 10 years. I mean, it had code names and classified names and it just kept going. There was nowhere. I was a firstly tenant at the time. I mean, what do I do call the base? Like hello operator, I need the cyber security guy. There wasn't, there was no way to remediate it. That simple. So instead, what we ended up doing is running an operation largely run by the military jointly with the FBI and we did counterintelligence. We just watched it. And then we found the Russians. For me, every day, let's just shortcut. It is 2026. My first incident response is 1995. So it's been 31 years, I would say every day of my 31 years, we've been responding to an intrusion out of China somewhere on the planet here every single day. And by the way, not just one, way more than that. So they have masks, they have just the scale that they can operate at. That's pretty, pretty high. And then probably the Russian SVR had kind of forensics earlier. So they would go dark on us. And back in my day, Sean, if I responded as an Air Force special agent, what was amazing to me if I responded to Russia, every time we caught them, they just went away. They're like, ah, you got us. We're going to go away for now. And there was almost like rules of engagement. If they got caught spying, they just went away. And you can tell when someone's monitoring what you're doing, you can find the tools we use or you can see that we're starting to remediate and clean up around you or we shut off the account that you're using or we change past phrases. And the Russians never let us observe them. Period. From literally from 1995, 1996, anytime I responded to a Russian based intrusion, they were super stealthy. That did change right around 2015 where they got louder and probably they stretched their mission too much to do counter forensics and counter surveillance stuff. But they had a 20 year run where we'd have them in our sites and lose them. And I went years not finding them. Like literally we're like, we know they're out there because that's their day job, you know what I mean? They're paid to hack us. You know, they show up every day, bad, you know, building and do it. But most of those cases probably got classified and I was on the outside by then. But they were really hard to find. China was more like a tank through a cornfield. I mean, they were just like, they didn't care for you saw them, they didn't do counter forensics, they didn't change the data, they didn't extort, they didn't do anything. They just stole everything, you know. Who do you think is better? It sounds like Russia's better at it. You know, for the vast majority of my 31 years responding, Russia was better, better tradecraft. Yeah, there are operators really didn't like getting caught, you know? And they just, here's an example, like I think China just had so many people, Sean, like I just said the other day, I knew a lot about religion because I took art history. I feel like I know a lot about the Chinese culture just by responding to intrusions. They definitely threw people at it. And here's an example, if a, if a Russian hacked your machine, what they would do is they would bring their own way to search your machine. They would hack your computer, they'd upload a file that would search everything on your machine looking for specific keywords, whatever they're after. Or they'd just grab your email. And even when they grabbed email, they would minimize it. They'd grab like the last month's worth or something like that. They were always very precision strike. If a Chinese operator got on your machine alphabetically file by file and directed by directory, they'd look through your machine because I had, and I thought about it, they have human capital. There's eight hours in the day. There'd be an operator on the keyboard going, I'm on Sean's machine. Let me just look at this file, and literally they almost did it alphabetically. The second thing I noticed is early in my career, the SVR would always steal the front and toe in service out of Russia, the SVR would always steal specific files, respond to what they wanted. They were just really good at that. The Chinese would just compress a whole directory and steal it. Like if you ever use like zip or something like that, they would say, oh, this directory called documents looks interesting. I'm going to take the whole thing. I could actually tell who the operators were just by the data theft. I'd be like, that was Russia. They took 32 files. That was China. They took three terabytes of everything because China would even steal operating system files that were the same on every machine. But it's just that operators that would go, that was an interesting director. I'll take everything in it. That was an interesting director. I'll take everything in there. I'm sure they had a unit that was more precise, more stealthy. Every nation does, but China took front seat in 2020. Every year at the end of, so from 2004 to 2025, I worked at Mandiant, my company. At the end of every year, I'd be like, hey, guys, breathe me on the coolest cases we got. For the most part, I got involved in those during the year. It was in 2020 where I saw the Chinese government break in using what's called a zero-day attack. There's no patch to it. Similar to when we were talking earlier about Stuxnet, zero days are attacks that work against an application, and you can't stop them. They will simply work. The goal of a hacker is to get remote access to your machine. So I'd be 10,000 miles away and get to your phone or 10,000 miles away and get to your server or desktop. Then it's usually, I want your email. I want your files that you've created. I want reports that you're writing about our Supreme Leader or whatever it might be. In 2020, the most expensive offensive attack was done by China. They used multiples of zero days to break into a defense industrial-based company. Everything they did, they were special. Everything they did had to be custom crafted for that environment. That is, in my whole career, that is very, very rare and China did it. So I'd say China is number one now for scale scope and sophistication. China decided to get stealthy in 2020 as well. They weren't prior to that. They decided to, from a friend's standpoint, leave less fingerprints. And Russia went the other way. By the way, Russia is now like we found them. I think Russia with conflict and everything, they're just operating at such a scale and scope that they can't, they don't have enough operators to clean up after themselves. It's very manual to clean up after yourself. It is not, it takes a human intelligence on a keyboard to say, "I don't want to leave a trace on this machine, so I have to edit the log file. Take myself out." So the counter forensics of Russia is down and up. or two right now. I mean, you were tracking nation-state hackers before the majority of people even had an email. Yeah, I think you were the first ones to do it. When you walked into that, what was the program you were at? What was it called? Well, so I made it. I mean, yeah, yeah, yeah, so I had a master's in forensic science, so you can think about all these intrusions I'm responding to are like crime scenes. Like, what are the fingerprints left behind by the intruders? What's the malicious code they run? It's the commands they execute, it's the encryption algorithms they use. It's the type of files they steal, it's the type of targets they even compromise. And so with my forensic science background, I created a thing called an indicator of compromise. I worked enough cases where we're like, we got to call the fingerprints something. So the indicators, and we started just bucketizing them. So we respond to company A and be like, oh, the attack came from here. They use this software and as we bucketize their catalog, catalog the evidence, we started just seeing the same people over and over. They use the same custom code to break in. Like I give you a weird one. Like if you break into the two dominant operating systems or Unix based operating systems, UNIX and Windows and Mac is a Unix derivative, you know, in Windows, if you break in, you do what's called a directory command. I've broken in and I want to see what's on your hard drive. I'll do DIR and just kind of look at what's on there. And the Russians when they break in, they do a directory listing of everything on your drive. And that's all they do. It's really smart. It's a great recon. They don't even poke around sometimes. They break in and go, just show me a map of everything on the machine. They download the map, then five days later, come back and just take what they wanted. The Chinese would break in, show me everything, and then go through it alphabetically with human sitting there 10,000 miles away looking at every single file and doing it. So we even cataloged in Unix that DIR command is called LS for LIST. And we would catalog, did they do an LS-AL option or LS-LA? Different operators typed it differently and we could even get down to the speed at which they typed. I mean, we were tracking on a lot of cases. We had it up to 650 criteria we would track, but only like 10 mattered. Long story made short, we just took the fingerprints of each group. And it turns out that Chinese did great training and the Russians did great trading. So they were actually really consistent, you know, the commands they typed. If you're a kid and you break into a machine, you just get undisciplined. You start going, I'll check out this directory and then randomly this directory and then randomly this. And I'll look over here and I'll do this and they're all over the place. It looks like a monkey's shit fight at the zoo, right? And then you responded, yes, we are, and it's just all economics. They did a directory listing and left. That's it. Gone. Kids don't do that. Foreign intelligence services do that because they're going to come back in after they've looked at the file listing and just by names alone, they know what they want or even the apps they want to steal. And at the time I started responding to intrusions in '95, we didn't export our supercomputers. So all our modeling and simulation of modern weapon systems were done on supercomputers. The crazy 90, the origin 2000. The front notes to all these supercomputers were what we would respond to. The Chinese and Russians would hack these things and literally they would run our modeling and simulation on our systems, but export the output all the way back to China and Russia. And that amazing. So one of the first cases I ever did with Russia, they were literally running, they were stealing stuff and they were running the modeling and simulation of a certain system we were creating unclassified though, but they were exporting the display right to their desktop. So they were just sitting back watching, oh, there's the model and this is how it looks. They were literally stealing it that way in '95. So again, though, those fingerprints, that's just an example of fingerprints, the commands they type, how fast they type, the malware they use, who they target and how they operate. At my company, Mandion, we started creating these dossiers basically and we were boring. We didn't know what the call, we didn't name the groups like, you know, this is fluffy snuggle doc and this group's called, you know, whatever, bad rabbit. We just called them managers, advanced persistent threat one was China. It actually was PL unit 61398 and we just named them managers and now we're up to, I don't know, 50 something. And that's why we have definite attribution, like we can get you to a building they're coming out of, you know. So when we started this, we had maybe 40 groups in the first eight years that we had fingerprinted only 40 different fingerprints for every cybercrime. Now we're in a, I don't know, 6,000. How big was your team back then? Oh, but a time, I mean, it was one meeting and then we grew, it's about five, one person of the whole clock. No, no, no, no, no. I, I started it, right? But we were about, but a time we're labeling groups APT, one, two, three, we're 350, 350 people. All ex-government, like at one point, Mandion was 500 people and I'd say 350 came from the US military. I'm sorry. I meant. Yeah. The Air Force. Oh, and the Air Force. When you were a special agent. When I was doing that, there was 13 of us. I think we doubled it to 26. Yeah. It kept doubling. And, you know, cyber was new in 1995 when I was in the Air Force doing this. And so they kept doubling the teams. Now I bet it's hundreds and hundreds. Like if you're a special agent in the FBI today and you're not digitally, forensically educated, you're not very useful. I mean, you have to know, networks function, how every case has digital evidence now, counter intelligence, crime, estimate, all of it, period. But when I started doing this, there was like the computer aware agent and the non-technical non-computer aware agent, I think that one's almost obsolete at this point, you know, unless you're a great accountant or you speak 20 languages, I don't know how you can be an agent today investigating anything without understanding digital forensics, you know. So small team, 13, 14 of us massively grew even while I was doing it. We were called computer crime investigators and we did the, and the FBI had a thing called the CARP team. I don't remember what that stands for, but it was like computer forensics stuff. And all I can tell you is we're always, no matter what, it was almost like we had a sticking line where we're always six months behind. No matter what the case was, we were six months behind on the forensics, you know, it was like, uh, because it was real hard to keep up with all the digital evidence piled up. So here at Sean Ryan Show, we cover subjects that get complicated fast, intelligence, war, technology. And when you're dealing with topics like that, the hard part isn't just finding information, it's making sense of it all. That's why we use Claude. Claude helps us take a messy topic and start connecting the pieces, timelines, contradictions, different angles, follow up questions, things we may have missed. It helps us slow down the research process and think more clearly before we ever sit down for an interview. And we use it across the show, episode prep, research, strategy, and even our hot question segment. It's become one of those tools that help sharpen the work behind the scenes. Claude is the AI for minds that don't stop it good enough. It's the collaborator that actually understands your entire workflow and thinks with you. Whether you're debugging code at midnight or strategizing your next business move, Claude extends your thinking to tackle the problems that matter. And with features like deep research and connectors, Claude can help pull context together from the tools you already use and turn complicated information into something that you can actually work with. Things like stripe and Shopify trust anthropic with the rollout of AI in their businesses. For problems worth solving, get started with Claude at Claude.ai/srs. That's Claude.ai/srs and check out Claude Pro, which includes access to all the features mentioned in today's episode, Claude.ai/srs. Let's talk about, if we're ready for this, let's talk about exposing China, the APT-1 report. February 2013 released a 76-page report publicly naming PLA Unit 61398, operating from a 12-story building in Shanghai's Pudong District. As the source of espionage against 141 U.S. organizations across 20 industries unprecedented, stole technology, blueprints, manufacturing, processes, test results, business plans, and executives' context list. How did you, I mean, well, this is all you, but I think the government knew. So this was 2013. The backstory on that is, I start Manian 2004 and I had a premise, let's respond to every breach that matters, because in the cyber domain, prior to Manian, here was the intelligence model in cyber. It was McAfee and Smantec Anivirus, you've probably heard of them, right? McAfee and Smantec, you'd run Anivirus on your machine. If Anivirus missed a bad file, a malicious file that was stealing your stuff, the only way Take a Mac, if you got smarter, is you. you would be like, "Hey, man, you missed this malware, so I'm going to submit it to you," so that you can detect it next time. Well, here's the problem. My mother's never going to find malware on her system, and Sean, you're never going to find it either unless you read a 800-page book I wrote that were born a hell out of you. It's hard to find this crap. It's ridiculous. I decided we need a new intelligence model on the cyber. Let's learn from all the red teams out there, the offense from Russia, China, the criminal element, North Korea. Let's respond to every breach that matters, and learn from it, and build the defenses. Because I thought, "Anavirus," and I hate to say it, "Thinking semantic a Macfee was securing you at that time was like believing in the Easter Bunny." I mean, it literally was so easy to evade. I was actually talking to one of your guys earlier, and we were talking about he even experimented with offensive cyber and could evade AV, because all you had to do is encrypt or compress your executable, put it on your machine, and when it executed it would decrypt itself, meaning it had no signature. So AV would miss it. So long as they're made short, we needed a new model in cyber. How do we build better defense? Let's actually get in a ring with the offense. Look at what the hell they're doing. So I think I was the first company ever started with, we're going to respond to every breach that matters. I got to be honest with you. I didn't know if breaches would go on forever, but I had that phrase. I think I made my first website, and you're an entrepreneur, so you know, there is no website team, I had to make my own website back in 2004, and I literally wrote on the website. The first phrase was, "You cannot solely rely on preventive measures," and that was boring, so I went with security breaches are inevitable. No one believed it. I think the only reason mandate was successful is that a premise security breaches are inevitable. We'll respond to everyone that happens, so that we can build a better defense against them. First knowledge, first mover knowledge, and what the bad guys are really doing to circumvent defense. Nobody believed that premise, so we had no competition. So every damn major breach, my phone rang, I still don't know how to help my number got out there, but we had to be good at it, and then everybody recommended us, and breaches took off. In 2004, when I started a company, every election year, both sides have a problem. I can tell you that right now, so in 2004, you get to respond. If you respond to Pepsi, you don't respond to Coke. If you respond to the RNC, you don't respond to the DNC, but those things are heavily targeted. But in 2004, when I started Mandian, right in the summer of 2004, we were only like, I started a company February, by June or July, we're nine people in a basement in Old Town, Alexandria, and we get a phone call from the defense industrial base, and we couldn't respond to it. We're already fully pegged, responding to a breach somewhere else, because it was an election year. But it was Honeywell. And I guess I can say that now, because that was 22 years ago. They were the first ones I saw where the Chinese government that I was responding to in Dot Mill, the military just went, I'm going to shoot the headlight over here and hit Honeywell now. Then they go through the whole dip. They go after Lockheed Martin. They go after Boeing. They go after Rolls-Royce. They go after UTX and Rathia. And it was these are companies where all of us, they are heavily attacked in the cyber domain every day by China. It's fair to me. It's fair to me. I mean, I was contacted. They're coming for you. And these companies have, what's funny, people would be like, man, the banks have great security. Well, in cyber, the best security I ever saw at one point in time was Lockheed Martin. I mean, what they did on defense was, I mean, all the defense contractors trust me. They do everything they can to secure their stuff, but they also have these joint projects that are, you know, a bunch of man professors getting together. But in 2004, 2005, I saw the military of China suddenly expand scope and go after our defense industrial base. And that was right when Mandy had started. So all those companies hired us and we respond. And I remember I would brief, hey, this is a guy in Beijing doing this or, you know, it was the beginning of it. You know, that's when we realized China is all over our networks. I guess I always knew it. Top mill, top mill felt fair game. I think nobody really expected them in China to suddenly say, hey, let's hit.com. And then they went way down.com. Like if you're a law firm, if you were an accounting firm, if you were doing business in China and any capacity, they had guys in uniform, hack you. So they don't separate economic dominance from military dominance in China, probably. You know, they hack. We would hack on offense as a country for security purposes and defense purposes. China hacks for economics. So and then since then, Sean, everything went public. General Alexander and his run in the NSA, largest theft of IP and human history, you know, to the credit, Chinese didn't damage anything. They didn't delete stuff. In my whole career of responding to the Chinese threat actor, I only saw like one operator delete the logs once, you know what I mean? They leave everything there, but they got way more surreptitious lately. So yeah, and since 1995, till now, China's heavily targeted our defense industrial. But what do you think and when you figure out that the CCP is hacking into our defense tech companies are like Lockheed, Ray, these are the first of the companies that hold the keys. Well, I think, you know, a lot of folks think when a nation targets you, you should be able to withstand it. But I've always thought, like they now, well, I'll use this one. You are a seal. If a seal wants to rob the Lego store at the mall, they're going to evade Paul Blart, the mall cop and rob the store. No problem. You have the Chinese government trying to hack you and you're a company. You will lose over time. There is nothing. I don't think it's reasonable for the American people to think any company can withstand a foreign intelligence service trying to break in and cyber to me. It's not. And so I remember early on, every victim company wouldn't tell anybody, you know, but it became because you'd get you'd say it and then you had pundits on the hill go, hey, what are your responsibility to let the Chinese hack you? Are you kidding? It's like your grandmother in an ultimate fighting championship. It's simply an unfair fight. And it still is today. Even for the companies that do everything they can in cybersecurity, you really don't want to come under the lens of the SVR and the MSS when they decide to go in offense. It's a, it's a tough thing to do. So what? Yeah. So we had like eight. That's why we went public in 2013. I mean, I just told you in 2004, the first company I saw China go, hey, we're going after was Honeywell. And I just, I hate saying that out loud. I don't know if I've ever said that publicly, but with this amount of separation, they can live with it. They, uh, and used go man, you know, the thermostat company, but they also made, you know, helicopters and dashboards and they, they're defense contractor. But they all had the Chinese come for them and, and, uh, it's, it's a sucker punch at that time for him. There was no defense for how China was breaking him back down. It didn't exist. We had no software to detect it really. You could just log in. You could just do things. There was no reasonable way to defend yourself in the cyber domain against the nation back down. Shit. Yeah. I mean, that's, yeah, pretty fucking scary. Just don't, I mean, just now you know what I mean? We would bond on your back then when you saw it happening. Back then you're more tacitly, you know, well, that's why we went public. You know, we had Mike Rogers, uh, Congressman from Michigan. We had, uh, Congressman from Maryland. They wanted to do, they wanted to make it so you could share when you've been compromised. Like stop, like hiding the fact that we're all in this together. They wanted to have more of team ball, like team America. Uh, so we decided, let's help the US government with like some information. Sharing that when you're hacked and you know it, you can share that information and not get condemned by the government for doing it. You know, you kind of got a safe harbor. And so we, we recognize two things kind of, there's like eight reasons why we went public with this report. I'll give you three of them. First, Mandian at the time were a bunch of ex-US soldiers and we were like, "Scue China for doing this." You know what I mean? So I wasn't going to be able to stop going public. Our, my team wrote this. I was just a face on it. We knew it was China from 2004 onwards. So it took us nine years before we finally just said, "Hey, man, let's just tell the world what the hell's going on here." Second, you could feel the government, the government knew about this, but they didn't know what to do about it. And at least, you know, the House Intelligence Committee was like, "That's past the law, that allows people to share information so we can defend each other." And then the third thing was the CEOs were like, "What the hell?" You know? Let's sit down with the CEOs of these companies, they were like, "We're doing a joint project with China. Why the hell are they hacking and stealing all this crap?" And, you know, the companies knew, "Hey, it's on us to defend ourselves." But they also, at some point in time, I remember thinking, hopefully, maybe if we just bring it up, the heads of state would actually come up with, "Hey, let's knock this crap off. You can hack us for espionage, but don't hack, you know, Disney because they're trying to open Disney China or don't hack, you know, whatever, a soft drink company or somebody else, because they're trying to do some bottling in China." It was time to have dialogue, so we did go live in 2013 and do that. It just so happens that the day that Obama was going to meet with Xi Jinping to talk about some cyber stuff in optimistic sounding, sunny land, California in 2013, that was when I was not a Snowden leak. And that stole the show. So I've never, you know, I've always believed since 2004, when I first started responding as a private company to these intrusions, that neither China nor the United States really wants a whole cyber conflict. Neither nation really wants it. And at least that's two nations that can come to the table and probably have a dialogue and come up with rules of engagement. I don't know if you can do that with Russia, too much criminal element. I don't think you can do that with North Korea and I don't think you can do it with Iran. But China is the one place where I've seen them follow rules. We have to infer the rules, Sean, when we respond. But China follows rules and etiquette when they act still. Their operators are predictable, interesting. What kind of stuff did they steal? It would be hard to say what they didn't, you know, that's the reality. And that's why General Alexander's read the testimony from the director of the NSA, largest IP theft in history, Admiral Rogers after him, General Nakasoni, all of them kind of allude to China's kind of taken a ton. Now there was a dialogue after that report. Here's what's amazing. And what we were doing is we were kind of monitoring victim networks, meaning we saw traffic coming in and out with consent. And the whole defense industrial base was working together by then. They started a whole consortium where Ray Fion and Lockheed and Boeing, they all worked together to figure out what's China doing and how do we thwart this. So they do play team ball now and it's actually pretty organized. But I remember at the time going, we're seeing over 70 companies a month compromised by China right now, just in our little network of watching what they do. After we went public, that report went down to zero for a while. So I think they noticed we changed behavior or some say, well, maybe just lost vision on them. Because when we wrote that report, one of the things we didn't kind of say in the report is we provided that trace evidence, the fingerprints, we provided over 5,000 fingerprints of this is their infrastructure they're using the hackers. This is the malware they're using. So all the defense companies that make software to stop it, we could just stop them. So we kind of burn their infrastructure. We burn their methods, their TTPs or tools, tactics, and computers were fried. So we fried it. So they had to go away anyway and recreate all that stuff. But again, going from anywhere from 10 to 70 companies hacked a month, just in what we could see, and I could tell we probably saw less than 1% of what they were doing. We'll never know. 80% or 2% was probably closer to two down to zero for a few months and then it starts creeping back up again. Just for the audience, can you elaborate on some of the stuff that you thought was most concerning that they had access and do flag officer's email? I always hated that stuff because you get to see what contracts matter, what weapon systems matter. I'd never read those emails, I didn't want to know, but when you see a communication of a high level official gets stolen, I've always felt, oh man, there's unvarnished truth in that period. No matter what we're trying to posture publicly, you've got the backdoor story in China as to what we're thinking and how we're going to arbitrate. That was the first time I ever saw, and it was in the mid-90s, that China got flag officer's email. Just instinctively, I went, man, that's bad. First off, the good news, most flag officers didn't really use email back then, but what did you put in it? You thought it was private, and I just felt, I didn't like that. Sippernet email? No, no, I've never seen a Sippernet breach, not that it's got to be physical separation. I've heard rumors of it. I've never been involved in one and I don't know, I personally don't think it's happened, but probably a physical security issue if there's a Sippernet breach, someone got to a Sippernet terminal. Did they get blueprints to weapons? Yeah, the problem we've got as a nation is we're so damn open, and academia, everything that becomes classified somewhere was unclassified first for the most part. How it's used, and who's using it, and where they're using it, use these classified, but we have this, you look at University, Illinois, or Bonne, Champagne, LSU, Penn State. All these great American, University, Harvard, MIT, I can name them all. Almost all of them, Berkeley. They're all doing work with the government, and you want to, like, the easiest thing to compromise on offense is a university period. So go do it, and go look at the programs, and you're probably, I mean, I'm given the playbook, but the Chinese already knew the playbook. The students, I mean, we have a bunch of Chinese foreign nationals at the schools. That's the challenge. And you know, somebody once came to me, Sean, and they said, "Hey, man, if you were working at a company in another country," and Uncle Sam came to you and said, "Can you just take this for us? Would you do it?" I'm like, "Yeah." I'll do that for Uncle Sam, I'll do that for you to discover it. You know, it's now I'm unemployable to any foreign company. That's what's happening here, you know, with all the, you know, we went with this global economy and we said, "Come work here, and we'll take your best and brightest." The problem is, where are their families, and who they truly loyal to. Well, I actually felt, man, you know, the compromises occurred because you can do it from 10,000 miles away and there's no risk to it. But I actually felt, and I remember for years working with the defense industrial base, we always thought to ourselves, "If we lock down the cyber door, are we just going to have an HR problem? Are we going to be hiring the scientists that steals everything?" And most people would rather have a cyber problem than personnel working at their company stealing their stuff, you know. So it's a tough, man, when you're heavily targeted, like the debt is, defense and industrial bases, it's a complex place to secure. Wow. It looks like at that time for my IP theft by China was an estimated 300 billion in 1.2 million American jobs per year. Impacted? Yeah. Yeah. I mean, there's no question like, like they want in solar power, right? Do you think they have the solar power coming? Probably. Probably every damn one of them, you know, everybody makes fun of, you know, the space shuttles all look the same. Well, how did I get it, you know? The least risky way to spy, cyber, period, and probably the most comprehensive, because when you spy, you want comms, you want the communication, right? Did they ever China ever confirm that they did it? No, when we went live, certain quotes you remember your whole life, I'll probably get this one wrong. But when we went live, you know, we went live because we did that report in conjunction with the New York Times, by the way, deciding that they were going to go live because they had the reporters compromised. They had a reporter named Mike Barboso from China and the Chinese were stealing his email. And you know, when we wrote that report, by the way, I remember, it was like a movie in a way. I remember getting on the phone with David Sanger, who wrote the article from New York Times. But all of our press were compromised. They were going after Washington Post. They were going after New York Times. They were going at the USA today. They were going after all the press because China wants to see what are you going to publish about us before you publish it? I don't know why, but they do that, especially if you have a bureau in China. And I just remember getting on a call and on the other side, it's like, hey, it's Barbosa, you know, and the New York Times wanted to verify PLA unit 61398. So we gave him an address, and I think Barbosa went and checked it out and went, oh, man, it's like a whole bunch of noodles shops. And then there's this NSA looking thing with antenna everywhere right in the middle of them all. And a bunch of dudes in uniform going in every day. We had it right because we used Google Earth, Sean. We saw the building get built in that insane. We just watched it grow, you know, on Google and we went, okay, that's where they're doing it from. We figured it out in a couple of ways every once in a, and you got to look every day to find it because a lot of evidence will pop up and disappear. We were finding resumes by Chinese students that were transferring schools or going for jobs. We had Mandarin speaking folks who would translate these resumes. This was before you could just use Google Translator and just read everything in English. So we had to hire our own translators and we were translating resumes and we kept hearing about this PLA unit 61398 and what people did there. And when you read the bullets, you know, you transferred from Chinese character set to English, it was basically like, you know, we hack for a living. We get our orders, we hack those companies. That was it. And we had, we knew where they were. But the New York Times went public at the same time frame about their compromise and they were the first ones, really one of the first victims. Google was another first victim. Google's so big when they were hacked by China, they just told everybody. And they actually withdrew doing business in China. They were just like, yeah, this isn't worth it. You know, because China does have to learn about the Chinese dissidents here and what they're doing. So, bottom line, you know, whenever there's ideological conflict, you're going to see cyber activity. We have plenty of that right now. Wow. Wow. You know, speaking of China, are you familiar with Polymarket? Oh, yeah, yeah. Speaking of China, people in Polymarket say there is a 93% chance that China will not evade, invade Taiwan by the end of 2026, only 100% say that they will. What do you think? I'm talking about this. - Yeah, it's Alliance 2027, right? - Yeah, I think that's what people say. You know, to me, and this is Kevin Mandia, anecdotal, you know, dad from California thinking about it, unofficial, I don't think they need to evade it. I think just population growth alone, you never know the will of a nation, like Ukraine surprised me, how hard they're fighting back. You know, I didn't go over to Ukraine, I didn't know the Ukrainian people, I didn't know the will to be independent, I didn't know if they had the leadership for it, and I think like many Americans, when the invasion happened in February of '22, I remember thinking, well, that's gonna take three days and look where we're at, right? I mean, this is unbelievable. But then I apply that, I don't know what Taiwan would do either, but it's, it just feels like we never acknowledged it as a standalone nation. You know, I think no one really recognizes this. - There's only 12 countries on the world that recognize it as its own nation. And so think about it culturally, how tight it is. And then I think population-wise, I've always just guessed, Sean, like, look at Singapore, like I think it's 30 to 40% Chinese foreign nationals. Like how long does it survive? You just look at population growth, and what point is, is there just a majority? So I think China could just win. Everybody says the population in China is going down, I'd be fascinated if we look globally, is the population of the Chinese culture going down. I doubt it. - So I just think that that's a tough one. I don't know, I'm the wrong guy to ask. I just go on God alone. They might be winning without having to fight. - See, that's what I want over there. They have this thing, I mean, cognitive warfare. - Yeah. - It seems to be the thing that the Taiwanese are most concerned about. - Yeah. - I mean, basically in a nutshell, it's a siop to convince the Taiwanese people that they, they still belong to China. - Well, and then I just don't know, throughout his year, they've been offensive, and warlike, you know what I mean? I just, I think they probably win through, if they, everybody says that their culture has a longer term view of things. Okay. Well, the longer term view is over time, we'll just win Taiwan over ideologically. - That's kind of what I'm getting at. - Yeah, that was, I think those 93 votes are way out of it. - They don't, I think they're winning. So it's like, if you're going like this up into the right, why go to war? It's heading in the direction you want. That's just my gut, though. And I haven't read enough on it, and I should. But I even looked at, you know, I was very interested in our war or whatever we're calling it with Iran. You know, what would China's response be? And it just doesn't seem very aggressive. It's almost like, "Hey, whatever's happening has happened." They feel like they're not even in the scene. They're off, they've exited stage left for now. And I just feel like a country that's prepping for war might want to exert a little more muscle than that. - Hmm, you think they're standing off? I mean, what do you think they're standing up? Because I think they're hoping that the petrodollar turns into the petrodun. - You hadn't. - Yeah, maybe. Oh, good point. Well, and I do know, longer this goes on, the more pissed off everybody's going to get at us. - I think the dialogue in DC is, there's never been a ramp up of Navy in history as much as the Chinese have ramped up their Navy. If you look at Taiwan, well, that's a naval battle. That's a naval blockade. That's Navy, Navy, Navy. So there's evidence to shows it. But if you want to be a global power, I still feel like we're one of the only nations that can project force remotely. You know, I've heard we may not, depend on who you listen to, we may not be able to project in two fronts anymore. And I've always felt we were always built to at least do two wars at once. That may not be the case. But China's building for something, right? And you always think back to when we sent our, whatever, beautiful white ships around the world, Teddy Roosevelt or whenever you carry a big stick. And I wonder when China's going to do that, if they're already doing it. I think they're probably already doing it in parts of the world, yeah. But we'll see if they do it globally someday, yeah. You brought up Snowden earlier. - Yeah. - What do you think about that leak? - You know, I'm never a leaker. You know, I get it that the dialogue needed to happen, but I'm, I mean, I'm the wrong guy to ask. I'm a pro. It is a weird sense that I've had my whole life. I got to probably, and maybe as I get older, I'm less trustworthy. But I believed in the institution of the NSA and still doing, I've known the leaders there. Nobody is trying to do the wrong thing. I really don't believe it. And, you know, there's tons of inspection there. I would almost argue, we inspect so much, we almost hamstring ourselves, you know? And so I'm in the, I don't know, I'm probably in a minority camp. I trust the NSA to do the right thing. I really do. And I, but again, I've walked the halls there, and I believe in the people in the mission. And I think you should never, there's, there's, you would like to think there's another path you could have taken if that was his fight. And I, and I still believed in, you know, they looked at the violations done. I can't remember the exact code that came out of the, you know, I think they called it the Patriot Law for one, for a while. But, you know, there was a huge investigation into what were the procedures and who are the people? And they even had people from, I mean, they had left liberals, they had right winged at everybody. And it really came back a nothing burger from the extent, at least from my understanding of it as to what we were really doing. So, I don't know. To me, it's a spies a spy. I still believe that you can whistle blow appropriately, but I could be wrong, Sean. (laughs) I'm as a European, if I were sitting in that building, I'd never have done it. But, you know, maybe I'm a weaker person. Maybe it takes, the dialogue is good to have all the time, right? The checks and balances. That's why we had the press and freedom of the press. You know, to keep the government in check. You know, I still think marketing companies probably know more way more about us than the government ever could. - Like you're probably right. - Yeah, but marketing companies won't break down your door and take your assets. - You know what I mean? - So we don't worry about 'em as much, right? So, I do believe in checks and balances and the government's gotta get called out. Whether appropriately or inappropriately, it's always a good check. - Yeah. - No matter what. I get worried, I see both sides too. I mean, I get worried about it. Obviously, I mean, we're just talking about Glacier. But obviously, I get really worried about it. But I can see both angles. I get concerned about government overreach. - Yeah, I do. - If unchecked over time, doesn't it automatically go there? I mean, that's just the fear I've always had, is that it is a good thing to have healthy debate no matter what spawned it, right? Whether it's, so even my opinion on Snowden, whether positive or negative, it's a great conversation to have all the time, you know? So that was kind of my take at the time. I just wish what I don't know and what probably nobody in the general public knows is what were the downside problems that that created. I'm certain there were certain lives that became real complicated to those leaks, you know? - Yeah. - Yeah. - Well, Kevin, let's take a quick break. We'll come back, we'll get into solar winds. (dramatic music) - This episode is sponsored by BetterHealth. You've heard me talk about BetterHealth for a long time. And one of the things that stands out is how many people have shared real positive experiences with it, therapy is personal. So hearing directly from the people have used the service matters. BetterHealth makes those reviews easy to find at betterHealth.com/reviews, and they update them every day. BetterHealth has an average live therapy session rating of 4.9 out of five. That's based on over 1.7 million client session reviews. That kind of feedback from people who've actually used the service speaks for itself. And getting started is simple. You answer a few questions. BetterHealth matches you with a therapist based on your needs. And if that's not the right fit, you can switch therapists at any time. More than six million people have used BetterHealth globally. And their therapist have at least three years and 1,000 hours of hands-on experience. See the reviews, see what stands out, and see if BetterHealth is right for you. Visit BetterHealth.com/srs. That's betterhelp.com/srs. Looking for another way to support the Sean Ryan Show? Head to SeanRyanShow.com and check out the latest drops from Vigilance Elite. We just released new gear, including this beautiful, moisture-wicking VE performance hat and SRS campfire mugs. And you guessed it. Vigilance Elite gummy bears. Oh shit. Every purchase directly supports the show and helps us continue bringing you independent conversations without compromise. Visit SeanRyanShow.com and grab yours today. All right, Kevin, we're back from the break. You were just telling me a story about-- Oh, yeah. When you exposed a 6-1-- 6-1-398. 6-1-388. You know, even when I went live with that, I didn't know the five digits right away. I remember being on like 60 minutes, I'm like six, two, four, three. It's like, you worry about those damn things. And as I get older, I forget it. But yeah, when we did that story, David Sanger, and Nicole Pearl Roth from New York Times, there's kind of coincided with the New York Times was compromised by a Chinese governance, a little weird. And they decided to go live with it. And we decided, well, let's go with who did it and what they've been doing. That's the PLA Unit 6-1-398 thing. And it was Sanger's idea and Nicole's idea. Let's just put this on the front page. And I remember like the day before. I don't know where, every once in a while, I think, an expert when I don't know shit. So I'm literally on the phone with Sanger and I'm thinking I know his job better than him. He's like, this is going to be a big deal. I'm like, no, it's not. David, you were wrong. Nobody gives a damn about hacking. I've been doing this for 20 years. No one's ever cared and they still don't. I go into work the next morning and I get in. I still remember my lights weren't even on in my office yet. And I go in. It's out, you know, and Alexander Virginia it's about seven 20 in the morning. And it's live. We're on, you know, it was like February 13th of 2013, we're the front page. And I don't even remember what the headline said. And what's weird too, you're an entrepreneur, you know, it's like no matter how good yesterday was, the only thing that matters is tomorrow. I already been dumbed on. We're fine. We're on the front page. You give us a shit. We're off. Let's get our work day done. And all of a sudden, my cell phone rings and I answer it. It's my now ex-wife. And her exact words, exact words were, what the fuck did you do? And I went, and, and immediately because I'm a guy, I'm like, what left field thing in my untrouble for now? Like I didn't know it. Why she was saying it. And I'm like, what are you talking about? You know, I probably got the fence where I like, what the hell are you talking about? I didn't do anything. You know, she's like, turn on your TV. And I have a TV right in my office. I turn it on. And I'm not even getting the very first scene I saw is a, the building, I recognize the building in the background. It's PLA in a Sitchland 398 headquarters. And it was like a dude in a taxi going, drive away, drive away. And I look at the bottom and say, you know, or Mandy report and all that. So I'm like, oh crap, what did I do? Like I didn't even know. We didn't think about people are like, this is a marketing drill. Really? No, it wasn't. It was a bunch of former US soldiers saying, screw this. It's Chinese New Year. Let's get the report out. Let's burn their infrastructure, burn their operation, give our government a tool. So the government doesn't have the point to finger at China. We'll do it for them. And let's just see what happens. And we dialed that report back. We actually had the names of a few of the soldiers. Like we knew who they were. And we pulled, I remember I edited those things out. I'm like, no, we're not going to put that in there because I didn't know what would happen to these guys for getting caught. But anyway, I ended up that day doing about 13 interviews or something like that. And by the way, with no staff, like nobody's handing me power bars, nobody's coordinating. I think, you know, I just ran around trying to get out the truth of it. Because what's weird is if I didn't go out and do those Sean, those interviews, someone would make crap up or say something. And we were on, we were in the ring. Like, you know, we were in the ring. We knew exactly what China was doing. So I just felt let's be the voice of reason on this one and get it out there. Nobody had even heard of 618. 618. I don't know. To be honest, I hadn't either. My team wrote it. We picked, here's what's weird. We had like three groups who could have picked in China. There's like a little naval group we call it APT4. We chose APT1 for a lot of different criteria. But one was they kind of, they weren't, they weren't the Mike Tyson in the rent, you know, in his prime. They were more, you know, Buster Douglas. We knew we could take the upper cut coming back from them. And so we literally picked them. And it was a tool to give, you know, Congressman Rogers, you know, something, the government, like US government, we know, we probably know you know, but we'll let you guys have this work of art from us. So we did it. If you heard of, you know, we were just talking about Snowden. Yeah. Yeah. And have you heard of this Pfizer thing that's going on today? Pfizer court stuff? No, what's happening? This is a tweet from Thomas Massey. The House, the House passed Pfizer section 702 renewal yesterday. I voted now. This was a uniparty vote in favor of unchecked government surveillance without adequate warrants are going to count ability. The vote tali, the vote tali is Republicans have voted yes, 192 42 Democrats voted yes, nay Republicans, 22 Democrats, 169 total, yes, 235, no, 191. Do you know what this means for? You know, what I would tell the viewer, just like in my view, at a time when I was in the US government and in law enforcement, I never, ever saw witnessed or knew about unchecked surveillance period. And I feel that's healthy skepticism for folks to have. I personally never saw it and never executed it. In fact, it was hard for me to get the ability to do it. You really did have to go talk to judges. You really had process. So Pfizer's foreign intelligence kind of taps, right? And to me, US law protects US citizens. And I think a lot of times you forget that. And so, you know, bottom line, it's good for the viewer to know that I'd never, ever witnessed or saw what I would consider unchecked governments. I dug into this a little bit this morning. And I understand why everybody's making a big deal of it. But the way I read it and deciphered it was that in order for the government to actually surveil you under this, you have to be in contact and talking with a foreign state actor. And there's still a Pfizer court. They're watching. Yeah. Not just anybody from any foreigner, a foreign state actor that is that's already under investigation. There's a Pfizer court. And that's all classified stuff. And you go and present to a special Pfizer judge and you get your ability to go do it. I had to get approval for consent monitoring. Like literally people were like, you can monitor. I'd be like, no, I actually can't. I got to ask, you know, my Jag, if I can go do that. So people could have asked us to come in the monitor. We wouldn't have been allowed to do it. You know, and in cyber at the time, some people did, you know, like if the if the government knows more about what the bad guys are doing on offense and anybody else, why not let the government help protect the defense industrial base or why not let them protect the banks or protect a hospital. And we can't do that as a nation because of the separation between the two. So it just I think I would rest assured a fire in this country that I've never seen. And I don't know of and I'm in DC all the time. You know, no, there's nobody. It's not unchecked. You know, it's not not for me. That's good to hear. And it's yeah, that's great to hear. I guess, you know, everybody can innocently make mistakes. And yeah, I've never had the brief of Pfizer court. But I've had to brief, you know, a judge. It's not easy to monitor anybody in this country. I haven't found it to be easy. Maybe it was cyber stuff. Maybe it was me. I'm not compelling. I get in front and be like, we need to do this today. But you know, anyway, I'm not worried about it. I believe in my gut is if we restrict our ability to spy, we're hurting Europe. We're hurting ourselves. We're hurting a lot of people. And so I think I would trust our organizations to do their job. All right. Let's move into solar ones. Thank you. I'll just jump right in then for you. Imagine Sean, you're sitting at work one day. I had about 4,000 employees. I was the CEO of a public company called Fire Eye. And I looked down on my schedule. I'd just done a an all hands with 4,000 employees where I told them and it was fall of 2020. So it's during COVID. And I'm doing weekly calls during COVID because you want to keep the wheels on the bus. And we have 25 year olds in Alexandria, Virginia living by themselves and their parents won't even see them because they're so afraid of the damn, you know, of COVID. So I'm doing weekly all hands guest speakers. I felt like I was doing the Kevin Mania show every Wednesday. I'd do it twice just to keep people in the ring together and entertained almost because I had a lot of a lot of folks struggling during COVID to stay motivated and stay human. Late COVID, you know, so it's November of 2020. I do my all hands where Blackstone did a $400 million invested in my company so I could split it. You know, so I could split my company and sell off the more mature portion of my portfolio and and carve Manian out to be a standalone company. Blackstone gave me the air code to do it. So I do the announcement to the whole company. I hang up, they all hands, you know, mean Zoom call. And I looked out on my calendar and it says that my chief from for main security officer wants to talk to me at one o'clock. And it's a Friday. It's 1257 and I'm not kidding. I'm about to go downstairs and grab beer. You know, I'm like, man, this has been a long week. I just did a $400 million raise. I just wrote my presentation. This pre-AI had the right all my own speeches, you know, no help. And I don't have the company's going to be like, wait, am I going to be in the part of the company he sells or in part of the company he keeps. And we were still kind of figuring out which students go right and left and it was complex and it was something that had to be done in a public market. I see this invite. I get on the phone at one and man, I should have known it was going to be bad news. Chief in for main security officer really wants to talk to the CEO. I get on the call and one of the first and I'm getting a briefing from one of our IT guys who ended up moving into the security operations center. And he's telling me that somebody is logged into our network. And the very next thing they did after they logged in is they dumped all our user accounts and pass phrases from a Microsoft tool called Active Directory. So in other words, that's like somebody broke into the hotel and the first thing they do when they broke into the Marriott is they didn't grab the room key that just opened up room 101. They grabbed the room key that opens up every room. They had the master key. You don't get the master key to first time you break into the hotel. So I lucked Luckily, I'm a CEO that's responded to breaches his whole career because when I get that news, I literally go call board meeting. This is the one I'm worried about. And even my sister was like, "Call board meeting. What the hell are you doing?" And I'm like, "I think this is Russia." They're accessing our network the way we do. That's perfect offense. Access the network that you're targeting, the same way the employees access it, using their accounts. And that's what whoever this was did. So 10 minutes into my briefing, my heart's saying, "Well, I'm not getting that beer today." And honestly, every day, Sean, I remember going, "I got the board together a couple hours later." And I think I gave him the solid speech, landing a plane on the Hudson. I just said, "Brace for impact, man. This is going to go from bad to worse." We're a cybersecurity company, someone's in our network. They got all the keys. They've got all their accounts. Did you know, did you think you were the only company in it? No. At least. Yeah. Over 2019, Russian SVR hackers inject malicious code into the SolarWinds Orion update, used by 300,000 customers. March 2020, the back door goes live, U.S. Treasury, state, homeland security, and the Pentagon compromised for over a year for anyone noticed. December 8, 2020, Mandy discovers Mandy and itself has been hacked. Red team tools stolen goes public, yep, with their company, blog the same day against most legal and PR advice. Yeah, because, well, we found out beforehand. We went live as soon as we could, but here's what held up us going live even faster, is so Friday, I get the brief from Friday afternoon. Sunday, I just already scheduled a board meeting for Sunday afternoon, and luckily I did the job of computer forensics. How did people break in? There was always what happened, what to do about it. That was my job for every day of my career. What happened, what to do about it, and every computer investigation, and then sometimes who did it? On this one, I just felt right away, it was the SVR, just my gut went, okay, this is a problem. On that Sunday, three days or two days after I knew we were probably compromised, I would get an update every day. I just got worse every day. I'm like, man, I hope they don't get to our secret server that has all our past phrases. Like an hour later, a guy called, hey, we just did forensics on the secret server, they've got it. I'd be like, oh, I hope they don't grab some of our email. Day one, I caught our best email investigator and said, hey, I'm pulling off the job and you got to go look at our email that's stored at Microsoft. He called me back exactly 47 minutes later with, we got a problem. So if we didn't know to look, Sean, we'd never looked, but we knew to look. So we did, and we started noticing, why is our backup account backing up our email all the time? It's not backing up our email. They were using our backup account to log in and steal our emails. And so I just went, oh, this is going to get ugly. Sunday night, I call a frontline responder for a pep talk. We're working around the clock. And I can tell you day one, even as an incident response company, I didn't think my team was taking it seriously enough. I'm like, guys, this is the one, this is the one we're worried about. By day three, everything was changing. The team went, yeah, this is the one we got to worry about. And so I call a frontline guy, Sunday night, he's working around the clock, and I just happened to be talking to him. And he goes, yeah, they stole our red team tools. These are tools that we use to be seraptitious and break into our customers, you know, kind of simulate the offense, simulate the bad guys. And the minute we lost them, I was like, well, can we stop them? Can we stop our own red team tools and the answer was we couldn't. We made software to stop bad guys. The unfortunate reality is we had created all this offense stuff that our defense platform couldn't even stop. And I'm like, I can't go live with that, you know, we got to fix this. To the credit of Microsoft, to credit of CrowdStrike, to the credit of power out to networks. We didn't have anywhere for me to go in the government, really. I went to the NSA because it's a damn lonely world when they're compromised. Day one, by the way, I called the NSA and I told them, hey, listen, we're burned. Don't email us. Don't talk to my guys. Don't email my guys. I have no idea how bad this is, but it's going to go from bad to worse than it did. And to their credit, they were a great ally. Second, we immediately started reversing our own red team tools to figure out how to detect them. And then we called, I called the CEOs of these companies. Like, head into cash, could you please have power out to networks help us out? Before we ever went public, Sean, we were working inside the community. And to the credit, these are companies that competed with us. They helped me. Thank God. And I was like, hey, George at CrowdStrike, can you please, we were giving them the rule set to stop our cyber weapons, just in case the Russians used them. They've never used them that we're aware of, but they sure saw learned a lot from it. And boy, it was I scared. Like the whole time I was like, I'm going to be the reason the internet goes down. I'm going to be the reason, you know, all hell breaks loose. So I was in a race to go public no matter what, Catholic guilt, call it the right thing to do. Remember, I got so much unsolicited advice during this intrusion from employees in the board that I remember two things distinctly, one, every time I was advising a CEO during their own intrusion, I would tell them, this is your day job now. You got to get through the crisis. So I remember my own voice in my head of what I told other people. Now I had to live by my own advice was a little weird. And almost was like, you know, bipolar, I was telling myself how to handle my own incident, period, you know, coaching myself the same words I told other people. But we were in a race to go live right away. And I was so worried the Russians would use what they took to their credit and thankfully, they didn't. And I think I didn't think we were alone, because yes, we are always has multiple victims. It's not that one company at once. But I could feel when I went out to the community. It starts NSA to me, I go right to them, Hey, man, we got something new novel. We don't know what the hell we're dealing with. You want to defend the military first. We do have it. And then they go to five eyes with we got something new novel and it kind of percolates through. And it doesn't go good to go public right away because all you're going to do is scare the hell out of everybody. There's nothing they can do about it. So we did get Microsoft's help. Thank God they showed up in a big way. It turns out they were compromised by the same people. CrowdStrike showed up in big way, power out to networks, Fortinet, all the cyber security companies kind of rallied. But it was all informal. And even today, Sean, if we knew a cyber attack was coming, there's no way for the nation to go shields up with coordination. The way you do it, as you call the vendors personally and go, Hey, you know, we got something new and novel and we need help. I had to protect America from the very tools we had made, you know, so we did it. And I'll never forget to my boards credit to I went into a board meeting. This was December 8 when I went public, there was no legal obligation to go public about the breach. We didn't violate anything. We didn't lose any covered data by statute. We in the lawyers, a great guy, an incredible lawyer and he gave the whole board of presentation on you have no legal obligation to go public. And I had like five pages of notes and I was ready to fight my board with I'm going public anyway. God damn it. And here's why. They rolled over in 10 seconds. It was the easiest board meeting I ever had was conveying the news to the public. And by the way, here's what happens when you're hacked and you know it and you tell the world. Marco Capco is down by 20% for us. We get sued right away by shareholders and you're considered negligent and I even had a phone call and then you're calling all your customers and I've lived this with a lot of folks. I called one money center bank and the guy on the other end who I've known for 20 years is like, Mandy, how did you let this happen? How did you let your company get compromised? And I remember saying internally, don't lose your shit and I just went, let this happen and I lost my shit. I didn't let it happen. Nobody lets it happen. We have a modern nation with an incredibly smart people coming after America. We're going to lose. We can't throw a perfect game every day. I was so pissed off because let it happen every day we woke up. I spent every Friday, Sean, downside to my jobs is every Friday. I'd get a threatening email from a ransomware actor and they were real people and they'd say, we're going to have to do this weekend. And the reason why is because we were preventing payouts. We'd respond to an intrusion, bottled it up so fast that companies didn't feel they needed to pay the ransom so they'd threaten us and they did break into us and we'd have to play this whack-a-mole game with them before they could do anything. We made our own security software. We could program it any way we wanted and we can't even stop the criminal element. That's how asymmetric this fight is. So I remember every weekend, anytime my lawyer called, my heart rate would go to 130. No matter what. Yeah, you had the phone ring certain times just like, oh shit. I had it every weekend and then so during soul of the wins, I think part of that side of me came out. I didn't let this happen. Nobody lets this happen. We're getting sucker punched here. We're giving Wayne Gratsky unlimited shots on goal. I mean, the puck's going to get in the net sooner or later for God's sake, you know? And that's what we're doing. So I remember just, you've had those moments where you're like, don't lose your shit, don't lose your shit and then you lose it anyway. I had that one all over the other day. You got it. That was what it was. You know, don't do it. Don't do it. And then I didn't let this happen. But soul of the wins for me was you learn under crisis whether you're gang weight or lose weight, I lose weight. And it's weird because it's not like you're bleeding out in Afghanistan. That's what I kept telling the team. This is a cyber intrusion. We're still healthy, you know? But what I've learned is when your credibility gets attacked or your confidence gets attacked, it is, it's, I personally don't respond well to it. you know, like every time I go to bed, you know? I got a subpoena as a public company CEO. I didn't do anything wrong. But you read the first paragraph, and I just get this energy like, "F this, I didn't do this." You know, I got that during solo ends. A lot of energy to prove, we're not incompetent. We're good people, but I got, you know, just lost that day to a foreign intelligence service that really kicked our ass. What did they get from all the government agencies from Department of State, from Homeland, I mean, what are they getting out of that? - In my experience, the Russians always had an etiquette, where I've never really seen them take the top person's email. It's almost like they're like, "Hey, man, don't take the Secretary's email. Just take all the people that report to him." You know what I mean? True story, I've always felt that. It's always the emails, huh? - Yeah, it is, 'cause everything's there. They took email and they took from us or read team tools. I think it was source code for some of the victims. It was emails for some of the victims. It was methodologies. A lot of it was how do we detect them, find them, and what do we know about them, you know? To their credit, they did a lot of keyword searches. You know, so we could see what they're looking for. That's a gold mine for us. I've never seen China do it, well, that's not true. I have seen the Chinese recently do keyword searches, and that's a gold mine for us, 'cause you know what they're interested in. Keyword search means they hack into the machine and they say, "Find any document "has the word secret in it," or, you know, heggseth in it, or whatever the hell it is. You know, they pick their words and then go. The Russians did that on us. So I could tell you exactly what they were after our red team tools. I mean, they were absolutely after us. - So let me, I'm just curious, let me ask you this, you know, coming from the intelligence world, I mean, you have all signs, you have code names, you have all that kind of shit. - Yeah. - Does the USG use pseudonames and emails? Have we started-- - Not that I'm aware of. - Do you have a tactic like that? - Yeah, no, it's just-- - No, sure. - Yeah, so, you know, there's, here's the reality, we're, there was a whole idea once by a company that started and they'd since pivoted, where they were like, "We're gonna make a bunch of fake stuff." So when the Chinese steal it all, they won't know what's real and what's fake. Even companies don't know the last version of something. We have bad enough document control and email control on our own shit, let alone this fake 'em out, or head fake, or code names. And I did protective services when I was in the Air Force. I'd augment the Seagal service. I can tell you, we did do code names then, 'cause the radios were probably not even encrypted. They were these big bricks we wore. And I remember the very first thing that ever happened, and I don't know if it was for show, just to scare the 27-year-old Air Force guy, but it was like Raven 1 and the Raven 3. And the response was, "I'm Raven 1, you dipshit." No, I'm Raven 1, and we argued about who was Raven 1, or something, you know what I mean? So, you use code names, you gotta change 'em all the time. And I don't think it's gonna work. So, I don't know if any real-obsuscation you encrypt, and you try to keep your communications out of a plain view from the Chinese. So, but SolarWinds was something that, it was a supply chain hack shon, where SolarWinds was a company that we all use for kind of controlling our infrastructure. And I feel bad for 'em in a way. You know, I mean, imagine this, I had to call them. We found an implant in their published code. That's no different than like Microsoft getting hacked, and you get the next updated Microsoft, and it's a back door for the SVR to steal all your email. It's, or you're on your phone, and you download an app, and like, "Whoop, thank God I updated my app." And the update itself, signed by SolarWinds, had a back door in it that the Russians now had a menu of, "Who do we want to hack today?" Well, we have a choice of, at the time, 18,042 companies had downloaded the new version with the back door. - Holy. - So they had a menu of 18,042 companies. And to the Russian SVR's credit, they didn't hit everybody. They could have literally shut us all down, just to lead everything, you know? If it was a destructive attack, well, there's a whole lot of data to lead it right down, that's that. What they did was very precision-based real espionage. You know, they went in and took what they wanted. - You described this as a special operations cyber unit. - Absolutely. Yeah, I remember I went to the Senate Intelligence Committee. I said, "This was a sniper shot, not a spray and prey." They went right at the 50 something, I'm aware of about 50 or so companies that, or US government agencies, it went after. - February, 2021, you testified before the Senate Intelligence Committee was the most credible, you were the most credible voice in the room. - Pushed for management. - You said that. - Pushed for mandatory breach disclosure laws that still don't fully exist. - They still don't fully exist. - Yeah, there's no national level breach disclosure law that I'm aware of. That is useful or helpful in any way, shape or form. The problem we had is the privacy laws, the privacy zealots got there first and said, "If you're hacked and you know it, and you lose like your personal data, Sean, then we got to tell 48 state governments or whatever it is." Now it's probably all 50. And so there was things to protect American citizens when you lost their email or their data birth or the social security number or their bank account number or private bank account number. It's called covered data. And that's great. But what covers the Chinese going in and just stealing all your IP? Nothing. There's no disclosure law required. And the problem with that is no company gets better from it. Like if companies hack today and the Chinese use all new and novel techniques to break in, no one's learning from it. You know, so if they can go to one place and say, listen, we're broken into, even if I hate to say it, I was even a proponent of if it's defense industrial based or criminal infrastructure, hell, let the best in government show up and help. Because then we can go shields up, learn the tools, tactics and procedures that were successful at company A and they should be the only victim of that breach period. And then you just kind of create a better, imagine a line, you have to have a learning system. As a nation, we haven't built a learning system where we learn from everyone's compromise and we all get bolstered from, you know, all the breaches are responded to. Like just I can just pick any of them, hell, it's every single brand you can name. But if you get compromised today, wouldn't you feel good about, well, at least nobody else has to go through this? So I think if we get compromised, I would immediately say, here's the TTPs used against us. Here, it'd better be a new and novel attack. I don't want anything that pre-existed work against us. And we got to get it out there to make sure they only victim if we got to do that. It's no different than neighborhood watch. You see an asshole robbing a house. You better tell everybody in the neighborhood, you know, and they drive this car and they're doing this. We need that as a nation and we could do better there. We're in a neighborhood where people are getting robbed and no one's telling you they're driving a white van and there's our plate numbers and three dudes in the van. We need it. Are we working on this? Yes, the challenge is that every time you go public, no matter what, there's never really a safe harbor for you. So unfortunately, and I can never guess, when you're hacked and you know it and you tell the government, I've never been sure what the government's response would be. And I can never tell the public's response. Example would be like when Target was breached, you know, they lost credit card numbers and they over-communicated. They had great people, great talent, but people also job over that breach. It happened in really 2000, the end of 2013, beginning of 2014. Almost the exact same breach happens at Home Depot and nothing happened. Public wasn't in an upper rear or anything, but there's something about this Target breach that it just got a lot of attention. It was during Christmas time as holidays. It was the front-down page every day. And then Home Depot saying thing happens. Someone hacks steals credit data and does stuff. And Home Depot will say, well, we handled it better. There wasn't that big a difference in handling of it. It's just a public response, a different. You know, and maybe there's a few minor tweaks here and there between those responses, but I never know. And so a lot of times companies get hacked and they do disclose. And then they still have to show up and testify in front of the government. And you'll have a senator from Oregon saying, well, how come you don't have firewalls? And you'd be like, dude, firewalls don't do damn thing. Like are you kidding? That's not even a padlock in cyberspace. You know, it's, you just get held to account at no matter what. - Gotcha. - Damn, damn. Let's talk about the Colonial Pipeline in critical emphasis. - Yeah, sure. - May 2021, dark side ransomware hits Colonial Pipeline. 45% of East Coast fuel supply. Mandying called into response six days of shutdown. $4.4 million ransom. Gas lines across the southeast shut down. - Yep. - I can tell you, I found out. And you know, with a lot of these, you never know how much is still under litigation or not, but the upside for me is you always get to see the leadership. And you get to learn from them. So for me, Sean, kind of like you doing the show. I get to show up and talk to the CEO. And I just feel like Colonial had great leadership. You know, just like unflappable, calm. Yep, here's what we got to do. But whenever there's a cyber attack, like when somebody ransoms you, they break in and they encrypt your hard drive, it's not like you know what's going on. Machines start to just go dark. They just shut down. And some of them shut down after 30 minutes, some three minutes, some 50 minutes. And if you're, imagine being in a control room and all of a sudden, "Hey, my machine doesn't work. Hey, my machine's not working. Hey, I'm going down." You have no idea what the hell is going on. and you don't know if there's a physical threat, you don't know if someone cut an electric wire, it non-siber people have different responses. And I feel like whether it's Sony pictures had to deal with something like this, so many companies have different defense firms had to deal with it and then colonial pipeline. The way that one came to me is, I think we were responding on a Friday and somehow, some way my young frontline responders didn't see this as national security issues. So I never got the update. My phone rings from somebody who works in the government and literally they open up, it's eight in the morning, I'm just waking up to go to the gym, which means that's a late morning. And I get a call from someone I know in the government, they're like, hey, are you responding to colonial pipeline? And I don't want to act like I don't know. So I have to say, well, let me check. You know, I'll get back to you. And actually, it was weirder than that. I think he called and said, is it true the Iranians hacked the pipeline or something like that? And then I was like, let me go check. I call my front, and by the way, I'm thinking colonial pipeline, you make faucets or something. So I don't even know who the hell they are. So I get on the phone with my guys, sure enough, for responding. And then I hear what they do. And I'm lecturing my frontline nerd because these guys are so into cyber security, they're like, all right, you've been breached. What happened, what to do about it? They never thought to escalate. Hey, man, 40 something percent of the US fuel on the East Coast is gonna be not transmitted. I got a call from the government on that first. And that does happen for me every once in a while. I've had that at maybe at least three times in my life. I learned we're responding to a breach 'cause someone from the White House called me, you know? But on this one, I got a call from somebody at a agency and then I looked in and it was definitely not Iranians right out of the gates who knew who it was. And that's based on again, we're cataloging forensic evidence at every breach we respond to. So we can go into like a colonial pipeline, look at the evidence and plus they said who they were, makes a lot easier and they wanted to get paid. So you know who you're paying. You can pull the evidence out and just match it and marry it up. So we're pretty confident with who they were. But on that one, it's just an example of many of them where first it was always a fog of war. You have no idea what's happening. If you're a hospital and stuff starts going down, you just, a lot of hospitals will be like, physically secure the hospital. Like you call security and say guard all the exits 'cause you don't know if there's someone on the inside doing it. It's a weird uncontrollable moment, but I've seen incredible leadership and I did attend a lot of the calls of Clawney where you do your daily briefs and they were just, they did, they show that you plan ahead. Like do the plan that you wrote when you weren't under duress. And that's exactly what they asked you. That's the best way to say it. They had already kind of said, "Hey, if something like this happens, here's what we're gonna do." And they just pulled out that playbook and did it. And it works 'cause it keeps everybody calm. Because there is nothing, it is a weird thing when you're hacked and you know it. You know, I've lived it where I'm like, "Man, I wonder if they're still in my email right now." You know, what the hell's in that? Nobody knows what's in the email. So Colonial Pipeline, again though, it's just all of these, whether it's Colonial Pipeline, Hospital, Cell Company. Every one of them, it's a full sprint the whole time, no matter what. Like you show up and our job is always physically impactful, Sean, like when we show up, we have to figure out what happened, what to do about it. We're not really sleeping. Like you show up and you're just triaging and working around the clock. And it's a clone, it was no different. Like some of these intrusions, we did United Health Care. I mean, do you remember what happened to them? I think it was last year. Somebody hacked United Health Care and ransomed them and people couldn't get their drugs at pharmacies. People literally worked themselves in the hospital visits. I'm not making that up. Where people literally worked around the cocktails. Like one guy didn't show up at a meeting. They had to go find him and he was like, passed out on the ground and hospitalized him. So these things are absolute races. Colonial, the upside they had is, you know, they don't have a competitor. You just gotta get it right. And I think what they had is the constant like it. So everything, like when you, it's a political issue, you gotta get oil and gas. So I think they probably, you know, I'm not aware of it, but my gut is they felt an incredible men's pressure to get back up and running. You know, in most companies, dude, United Health Care did, yeah. I mean, I've got to be honest. - I've got to be honest. - It's way harder than people think. - 4.4 million in ransom for 45% of the East Coast fuel supply seems pretty minimal. You know, to me, yeah. You never opine whether people should pay or not. Obviously, here's what I will tell you. I've never met a CEO who wanted to pay. Not like it was never the default answer, but you certainly see the logic in paying that one, right? I do, 4 million, yeah, I'd have paid it. I've gone through the hypothetical of what would I have paid to keep my legal counsel's email from getting posted. Now I'm advertising to the bad guys, but I would pay to not read. The amount of lawsuit you get as a public company CEO if your general counsel's email is online, it's amazing. I mean, reported to read it. They write articles on this stuff. You know, it's a tough situation. What about texts? Do they ever go after text messaging? Well, do some reading on a, yes. The answer, modern nations do. And, you know, both of all our cell companies have a, there are certain industries that you need to withstand military-grade attacks or modern nations attacking them. Our cell companies, our phone companies are definitely one of them. They are fair game for espionage every day. Last year, there was widely publicized breach in 18 team Verizon, who's in 2024 and 25. And the advice from the FBI was, and it's pretty telling, hey, you signal, are you shitting me? No, meaning texts are in the clear and text can be found and cell companies are fair game. And in reality, they are so valuable to espionage most likely that if you're on offense against us, you're trying to place people there. You're trying to hack 'em. You're trying to do anything you can to make sure you maintain access to the data from those companies. Just signal, legit. I think signal is, like you use it. There's always ways around everything, but you have to have a massive, like in transit, signals legit, like if somebody hacked your phone, my gut is they can get to at least half the equation and maybe be able to decrypt it. That means it's a modern nation targeting you specifically, but signal is infinitely better than not using it, same as cliche or like these things are massively annoying if you're on offense. 'Cause that means I can't just intercept your dialogue and read it and I can't find it stored in plain text. I have to do a lot of work to get to that. - Ben, didn't they just, what was I reading this? I can't remember what it was, but they broke signal and they were able to get the messages through notifications if I break it into the app. Have you heard about this? - Now there's usually workarounds like that. I can tell you, usually, I wouldn't say usually, in the times where we needed to decrypt something and we only had one key, we always were able to decrypt it over time and usually there's two keys, public and private key to something and so there was a time where we could decrypt at my company, remote desktop protocol for Microsoft. And we thought we were the smartest guys on the planet, we're like look what we can do, and if we can do it, China can do it. In reality, none of our customers cared it, we could do it, but what it allowed us to do is whenever the Chinese broke in, they would remote desktop to all these machines, we could see exactly what they were doing 'cause we could tap it. And even though it was encrypted, we could decrypt it. We thought all, we're awesome. Nobody really cared, but the reality is, most stuff today probably can't be decrypted easily until you have quantum compute come out and then realize you have two problems if you're worried about this. One, someone got your traffic or your data somehow and then two, they can decrypt it, right? But quantum, that's the biggest issue with quantum compute and that's gonna come like AI, everything's coming fast when we want. When the Chinese and the Russians and others have quantum, the vast majority of things we've done in the past that they've already intercepted, tapped, stole, that's encrypted will be decrypted. That'll be the risk we run. The secrets that we once kept will no longer be secret. How far are we from that, under 10 years? For the most part, here's the good news. The Chinese really don't have a whole lot to decrypt. They accessed everything with a valid key, meaning a valid user account and passphrase. So everything was presented in plain text anyway. I actually think the threat from quantum is far less than people realize because for the most part, even when the Russians were stealing stuff, it was not encrypted. So the vast majority of the intrusions, I'm speaking with like 5,000 plus intrusions and investigations behind me. Very rarely does an attack raft overcome encryption because they are accessing your data with your keys, your credentials. And so it's just plain text anyway. So I think quantum's not going to be a big issue. It is for some things, but we'll see what comes out then, Sean. You'll have a lot of good shows then. - I'll bet I will. - Yeah. - It scares the shit out of me. - I mean, the way I understand it. - Figure out where Hoff is buried or something. - The way, I mean, it's just, you know, people, people describe it as your banks will be done all your paths. or it's will be gone, financial network will be completely. - I think AI's gonna impact that more than anything, 'cause you have AI doing trades, not humans. So. Imagine a whole system of AI edge and doing all the trades. At some point, the market's gonna be managed by them, the AI edge and not humans. - You've heard me talk about Caldera Lab before. And lately, the product I've been reaching for the most is the good between being a dad, hosting the show, traveling, training, and trying to keep up with everything else. I don't have time for some complicated skincare routine. I don't want 10 steps. I don't want a cabinet full of products and I don't want something that takes a bunch of time every morning and every night. I just want one simple product that actually does something. That's what I like about the good. It's an antioxidant rich facial oil serum made specifically for men's skin. The good is formulated with 27 botanicals and it's designed to help deeply moisturize, support skin recovery, even skin tone, and visibly reduce the appearance of lines and wrinkles. For me, the biggest thing is that my skin doesn't look as dry or worn down. It feels softer, smoother, and just looks healthier. And the results back it up. 96% reported healthier looking skin. 91% reported less dryness in 89% showed improved radiance and luminosity. If you're looking for one simple product that actually makes a difference, that's the good. Visit CalderaLab.com/SRS in UseCodeSRS for 20% off your first order. Again, that's CalderaLab.com/SRS in UseCodeSRS for 20% off your first order. What is the worst case scenario for a cyber attack on US critical infrastructure? What is the worst case? I'll start with this. Nobody knows what would happen when the gloves come off and the couple of reasons why. We're in times of basically at least ostensibly, we're at peace right now with the modern nations like China and Russia. We may be fighting proxy things or ideological differences. But on defense, we don't know if we've seen 99% of their capability on offense or 20%. My gut is it's like 80%. In other words, they have stuff on the shelf shown. They've never deployed. We haven't seen it yet. That you save for the moment of need, right? So the first thing I would tell you, there's a book by Ted Coppel called Lights Out. And I've read enough of that to go, I don't know if that happens. I don't think it's that bad. But genuinely, nobody knows what had happened if all minor nations go all out in cyber. I can tell you our kids probably aren't going to school. I can tell you some regional trains aren't running. But I don't know if it's like the Nero, there's a movie out on Netflix called Zero Day. And it's all about this exact situation, but it's done by Hollywood. And I couldn't make a pass the first 10 minutes, trains were crashing into each other. Some child gets killed or some people get killed in a car accident because the lights aren't changing right, traffic lights. And I was like, man, I don't want to watch this. The problem is, I think you're going to get a situation that there's such a rippling butterfly effect that most of society will come to an absolute, we better go back to the old way. I'll give you an example. Like there was an attack in 2021 and it worked. It shut down software that was used by a lot of restaurants. And I mean, you and I've been ordering food and restaurants from long before the internet, or at least someone wrote down your order. What I was amazed at is when the internet went down at about 800 restaurants, just the app itself that they were using got compromised, the majority of the restaurants couldn't take orders. They didn't know how to run their business off the grid. If you want to do something weird, see how many Fortune 500 companies can actually run their business if they're off the internet. The answer is probably none of them. Some aspect or most of their business might actually falter. And that's unfortunately probably what will happen if the gloves come off in the cyber domain. So much will be unreliable and unpredictable. It'll impact so many weird things. Like you're running app. Hey, how far do I run today? Oh, my running app doesn't work now. Or you're tracking calories, you can't track calories. You schedule blows up. Your organization can't get on the grid, or you can't transact, or you can't sell, or you can't get your money, or you can't believe what you're reading. And there's a lot of different kinds of attacks. Like if I had to privilege a couple of times by teaching a modern warfare class at the Naval Academy, I'd show up and guess lecture. And I'd depress myself. Because first off, the attacks start a year out and you won't even know it's us. Yeah, I won't even give you the playbook. But when the cyber stuff happens, you know, I think we're staying home from work that day. I don't think the grid crashes. I think hospitals function. You don't think the power grid crashes. I think it might crash in the Midwest. The mom and pop utilities, Shawn are gonna have a problem. Maybe some of the water facilities, but it also depends on who's doing the attack and what their goal is. I would like to dive into that a little bit more because that is one of, that's where I thought we were going. Was the grid's going down? Water treatment plans are going down. You better have fault tolerance. I think some will. I mean, the way I understand the way things are going. China manufactures all of our, damn near all of our power infrastructure, the transformers, water treatment. Well, and so if they're manufacturing that shit, they're putting stuff in there to be able to access it. You gotta trust the country you do business with. And you know the former FBI director said that they are in our power grid and our water. Well, they hacked into it. Yeah, they have, and not everywhere. And that we know of, nobody knows what'll happen. That the challenge, here's where I will tell you, the minimum is small municipalities are going to lose electricity. They're going to have their water works probably shut down. Now again, it depends on the attack. And if we go full-monte right away versus gradual incrementalism, most wars gradually increment, it depends on the actor because there's a blunt force way to attack us that might not be as successful as a slow erosion of our capabilities. Does that make sense? Here's why, if I break into a major utility, like conned runs is New York City or PG&E or down in LA or Southern code, these are strong cybersecurity entities. If you broke into any of them and tried to run malware, they probably can detect them out with compensating controls and stop it. Or if you try to just delete everything on a machine, they'll have redundancy. So what you actually have to do is reverse. So how does this utility work? And what commands do I issue that will be unique to every single one of them to get it to perform differently or to impact it negatively? That's lower and slower. You got to read the freaking manuals. On the little or guy, you probably can just delete everything. I call that blunt force trauma. We hacked in and we just said, "Hey, delete everything, go." That might shut down municipalities. It won't shut down the bigs. They're going to keep giving you energy. The bigger problem with the bigs is the load they've got to take if things start to shut down. We saw that happen in Texas, right? They had like an early winter or late winter. And all of a sudden, the whole darn thing ripples across the state. Because if one utility went down, the other tried to bear the load, Nick couldn't do it and it pops down. And we had that cascading in August of whatever it was when a New York went down. You remember that happened in maybe 2003, 2004? It was 2002 maybe. I can't remember. To August of 2003, grid goes down in New York City. And it was all peace and happiness 'cause it got back up in three days. But what's it like after five? I was actually in New York at the time. It was really good. 'Cause people learned after 9/11 how to work together during crises and that was August of 2003. But I also remember walking around the city gone. It's August, it's hot as hell. Aircon's not working. How long before this thing unravels? But I think if I'm on offense against us, you take out energy, you take out everything. That's healthcare, that's finance, that's everything. And I think that's what you got to worry about. And then you're just gonna get this weird ripple effect of regional transit not working. ATMs maybe not working. You know, life will change. So what about water treatment facilities? Hard to defend if they just make minor changes to how they treat it, to what they're putting in it, how they're. - They're all different, Dashon, that's the thing. Like there's, you're gonna have to. - The fucking poison us. - Yeah, I think you got to know more than that. I think they're gonna go for, that's why I said you, they're shut down or alter. Shut down is blunt force. They just, they're gonna delete everything versus we're gonna change the commands being executed. They're unique for utility. They really are. Like you got to read the manual. I mean, that being said, if I ever hack a company, I find the manuals, they're not hard to find. They really aren't. You just look at it, everybody stores them in the same place and it's usually called the name of the system and the user guide. Read the freaking manual. We do a lot of assessments of these utilities. And if I were, you know, my red team, we'd be sitting here and be like, yeah, we usually, if we can get to the OT or operational network, that's a problem. So what you have to do is segment the internet network. is the IT network. We've all heard IT, right? You got to keep that IT separate from the OT. You better have one hell of a wall between the two. The problem is everybody has a cross over somewhere. It's almost like Nippernet, the Sippernet. You know, we can go one way but not the other. You know, you've got to figure it out. I think the small utilities are uniquely disadvantaged at the time of war. So you're from Missouri, hometown? But I'm not going to do great. Yeah. Yeah. I don't really like thinking about it. Well, you've got to think about it all the time. But there's no that the challenge. So here's the, let's try it out. I'm not a pessimist or an optimist. I'm a realist. I do think we can have a future with AI. Everybody's going to say AI on offense is going to create a problem and that is true. I think it's near-term pain with AI on offense and what, you know, and we can probably get more into that. But I do see a future where AI on offense will be uniquely available built by the good guys. That's what Armidin is doing to train your AI on defense. The biggest problem we have in cybersecurity is there's there's a starvation line. The big companies have great expertise, great talent, and great software to defend it. Then you hit a poverty line and all these utilities can't defend themselves and all the smallcomings can't defend themselves. With AI, we're going to get the scale, the expert. The problem is we have to live that transition period, Sean, and the advantage will go to offense during a transition period. And we're in that now. AI is just emerging, it will advantage offense. However, in the long run, it will advantage the defense. But we're going to have an ugly transition. So when you talk about a, like a sl, how did you do just not, not blunt force. Yeah, blunt force promise like a bad hack. Like if I'm on offense, I don't do blunt force because I don't want you to notice. I've hacked you and I've screwed with you till it's too late. So what does that look like? You slowly erode a system. How would you do it? Slowly pollute the water, slowly degrade the utilities. Yeah, but I would have to read the manual because it's unique to different things. I almost hate giving the playbook away because I'd already have, if I were against us, I'd already have people working there. I would already know how to bring down the major utilities because I've one guy on the inside feeding me the manuals, feeding me the access if I needed it as well. So it's real hard to stop that. We have a very international culture and not all loyalties lie in the same place. So, you know, I hate thinking about what, and I instantly shall go, what would I do if I were against us? And I just don't like what the outcome would be. So I'm hoping that our adversaries gradually increment. We have to have a proportionate response. So someone attacks us in cyber. Our best deterrence is not in cyber. It's explosive. It's kinetic. It's you bring the pain. That's the unfortunate reality. We are in the glass house in cyber compared to the rest of the world. You know, I think China might be too because they have such centralized control. We may be the two biggest glass houses. You know, if you're, if North Korea hacks us and we think, you know, we're going to tip for tap by hacking back, they're in a mud hut throwing rocks at a glass house and we're in a glass house on rocks at a mud hut. It's stupid. It's not the right domain to fight the conflict end. And I think unfortunate as to reality, we have to, if somebody starts hacking our utilities, we have to respond very quickly and violently to that. What about the financial markets? I don't even think I started number one. And they like to think they are. You know, you talk to the banks, but to me, I've never ever had a scenario in my head where I targeted a banks. No one gives them about money if they can't go to a hospital. You know, I go after electric first and foremost, probably water, you know, because it's, it's unguarded. It's hard to protect and healthcare. That's it. The financials are so well defended and they're so good at, they can always roll back to one second ago. They have fought tolerance everywhere. They're confidence games, they cover losses. And I would put, if you could wage a war on every front in the cyber domain, yeah, I'd go after every domain, I'd go after every industry, I mean, and let them all have it. And I'd have AR and offense that can have 24/7 total recall. And that's what's common, unfortunately, Sean is a future where all of us, there's an attempt at a hack against all of us all the time. It's almost that bad now, you know, but it will be that way with AI. So it's like a lot of needles coming at the balloon, you know, it takes one to pop it, you know, how do you, I mean, what do you, what would you tell the just the average American to prepare for if that were to happen? Everybody needs to be able to live off the grid. You know, that's actually, in fact, we tell businesses, I call them red lever events. If I'm meeting a CEO at any company, never forget how to be business the way you used to, just in case you're under conflict. Be able to dust off a book and say, okay, man, we're gonna have to do insurance claims with patent paper again. Whatever it is, because you never know what conflict can bring and what you may have to work. Like if you're a restaurant for God's sake, you ought to be able to take an order without the internet. And without a damn iPad, you ought to be able to write it down, walk back to the kitchen and do it. And I saw over 50% of restaurants falter with no internet. Literally couldn't operate the business. In fact, weight staff didn't even know the menu, because they were so used to it. So great companies, spent, and by the way, critical infrastructure or damn sure, you drill the red lever events off the grid, how well do you operate? Every machine becomes inoperable right now, how fast to recover. Those are like, pull the lever. What happens? And most companies, when they do those red lever events, have unique findings. Like, wait, I never thought about it. No one can park in the parking garage. When we come off the internet, when people badge to go in to the parking garage, your badge gets digitized and sent somewhere for authorization to open the gate. No internet, no gate, traffic jams, the whole block of LA. So you got to figure out how do people buy and launch at work? No internet. Can't take visa cards. How do we, you know, I, critical infrastructure needs to operate off the grid, and needs no way to do it. It needs to be able to operate how it used to. I believe that. What about for people, about for businesses? People, you know, there's no way to, unfortunately, you know, for me, for people, it's, when we're talking about the rest moments, I hate to say it. I, and I know you believe this, you have to at least have a family plan for what do we do if the dirty bottom comes off? What do we do if the earthquake hits? What do we do if blank? You know, great idea about technology. I do believe with proper diligence, you can know where your kids are, know where your family is, and do so in a safe way. You could have protocols and pleasure in communicating a safe way. The grid comes down. I don't know how to do that, but you can't really take down the internet in the United States. That's why I was created. Survive nuclear war. That's literally how we went from packet, you know, packet switching from circuit switching. Circuit switching was one line. You sever it, no comms. The internet was created literally, so we could communicate after nuclear fallout. That was one of its reasons. So you're not shutting down the internet here. And there's ways to have redundancy, go satellite and fiber to your house, have backups. But it's, it's virtually impossible for me to say to any individual, you should prepare to withstand an AI-based attack coming from a modern nation. That's going to fall in the hands of, of the companies to protect us at that point. Okay. Yeah. Apple's got to protect us. Google's got to protect us. Amazon and AWS needs protect us. Microsoft protect us. CrowdStrike. Palo Alto Networks. Fordonnet. Cisco. You go through the brands that we all really, you know, like use for infrastructure, use for applications and say, hey, guys, you got to be able to use shields up during conflict. And they know that, you know, they're actually, I would argue, they are critical infrastructure. If we think Google Clouds not critical infrastructure, it is. It's running a lot of businesses. So is AWS and so is Microsoft's Azure. So you got to put them into category of their critical and they should have, I hate to say, at wartime protocol. What do we do? What about the USG? I mean, you're talking about the capabilities of China, Russia. In the next segment after this, we'll talk about China, Russia, Iran, North Korea. But what are our capabilities? Are we? Do we have an offensive hacking arm that is conducting espionage on our behalf? You know, anything we do offensively is going to be classified. And one of the things I will tell you is I started armament into absolutely benefit, the offense for nations that are governed by laws. And those laws are things we aspire to abide to and we do it. I've always felt on gut intuition and to some extent experience we were the best in the world. We probably still are. But China is great. And the problem is, Sean, AI is the equalizer between all of us. AI will enable nations like Saudi Arabia, UAE, other nations to have the same level of offense as us, potentially, over time. Because you can train systems. It only takes one exceptional offensive mind that can do vulnerability discovery, exploitation development. All these skills were going to be automated into AI. And then, and so that highest tranche of talent capability is just going to get more distributed over the next few years. So it used to be, U.S. was in this land of its own, Israel is incredible in offense. I'm starting to realize war makes you innovate faster, and Israel could be the best world on offense. And maybe there are certain platforms, different nations are number one in, like the mobile platform. Got to give some shout outs to the Israeli offense of capability in mobile period, right? And I don't know how, how did you respond when pages exploded and supplied? Right. If you think about when command and control is eroded like that, who to hell wants to be part of that network, huh? The radio explodes, the pages explode. I don't want the next thing you're giving me, you know? Right? Just give you a smoke signal from the mile away now, and hell, that'll probably blow. So there's a lot of nations that the thing about cyber is one smart person is infinitely scalable. So all you need is that one or two great offensive minds at the right time, you know? And the vulnerabilities in cyber change, like today, there might be first time in internet history, no zero days work. But right now, there's 223 year old kids working on an app that everybody's got to have. Do we know who those great minds are or the different types of work like today? It could be that the architecture matters as Siemens tomorrow could be parsing in the next day. It could be Cisco. You don't know what skills you need on offense till the moment, I'm actually talking about a foreign adversary's offense. Do we know who those great minds are? Do we know who to take out if they hit us? I would think it's hard. Yeah, I doubt we know. We probably know some. You always know the lowest bounds, right? Whatever you know, it's the lowest bounds of your knowledge. But now, and I think ours aren't really well known either. I think the best offense I've ever seen, nobody knows who these guys are. Yeah, they're smart. They go home, walk their dog, and they don't blog about it, you know? They don't go to black hat or conferences and really share what the hell they're doing. And the great thing about offense is the government's mission still draws in incredible talent. But at the same time for him, in my lifetime, I remember growing, up going, the best road at physics would be in the US government. The best in the world at offense, a thyroid would be in the US government. The best in the world at big data would be in the US government. And now that I've worked at Google, all right, I'm familiar with Amazon and I see the paid differentials that apply expanded massively in our lives. I'm starting to think that there's more talent on the outside, right? So, but I would put the US will always be excellent on offense. We have the, you know, and I hope we just stay there. It's good to hear. Yeah. Let's take one more break. Got it. All right, Kevin. We're back from the break. We had a really good discussion off camera on what you would do. If you were going to hack into a nation, how would you do that? Yeah, you know, if you were, you always wonder, what would our enemies do to the United States of America? And one of the things that you need to us at that first amendment allows any, you know, there's a, there's no line between, you have to say the truth when you're speaking your mind. You know, what's the difference to, you know, really, really bad opinion and being out and out lying to incite a riot, you know, nobody knows where these bright lines are. With the first amendment in the United States and the freedoms that everybody's afforded for that, I think we're uniquely susceptible to manipulation to the hearts and minds of the American people. And, you know, there are, what I was trying to remember Sean is sometime in, I think, August of 2015, I had one of my intel folks, we built a global intelligence infrastructure at Mandin. So we had hundreds of people that spoke 30, more than 30 languages in over 30 countries. And one of these guys just walked in my room one day and said foreign intelligence from Russia is influenced in the hearts and minds of people through these X handles, these Facebook walls, and he just unloaded, and it was like a hundred page document. And I remember going, this feels wrong. I don't, this is before anybody ever talked about Russia's trying to influence the US elections. We know crap. Every nation is, right? With whatever they've got. I mean, if you're getting funding in your Liberia, wouldn't you maybe try to get a few votes for that side? I think there's no different, there's good people trying to manipulate hearts and minds for good reasons, but what we saw and what I saw in the hundred pages, and we went public as a company about this, with about 90 of those pages, but I remember, I think I literally flew back in and brief Senator Warner, he was, you know, the Senate intelligence community saying, I don't know what to do with this, but here's what's happening, like Facebook walls are being started. And when we went back and we traced it, I don't remember the details now, other than our guys were really good, they had spent their whole time kind of tracing certain Russian actors, and they're like, this is them. This is them using these platforms. And all they did is amplify what already existed, they weren't even really making stuff. They're just like, let's push this issue, let's push that issue and they were just driving things. And people would ask, well, what side did they push? I'm not sure they gave a damn about any of that. I think they more cared about, just push American people this way, put directions. You know, and I apologize, I don't remember the details as well as I did a decade ago, but I mean, that was the cool part of my job. It's literally, a guy just walks in my office, you're going to want to read this. And me read it and go, what the hell do I do with this? You know, and then you just talk to people like, you know, we got Facebook involved. We got Google involved, there was a third, oh, X, and we did talk to their trust people. And all of us were like, yeah, this doesn't feel right, but we didn't know what to do. What it would be, it was the earliest onset, in my opinion, of social media being used. And you can't tell what's artificial amplification versus real amplification. That's a problem, right? You can't tell if this is an issue that matters to Americans or not based on the number of hits and number of volumes. And that stuff's feeding their algorithms and changing things. So we got to figure this one out. And I know a lot of work's been done since I inspected it, so I'm sure today, there's a constant whack a mole at these social media companies say that's a foreign actor kill it, kill that. And yet people don't want that to happen either, because it's censorship. But I can tell you, it's real. And if I were on offense against us, because of the first amendment, and you're right to say anything you want for the most part, you know, Shao Skrim and fire and a crowded movie theater kind of thing, we are susceptible to attacks Iran is not and Russia is not and China is not. Bastions of internet freedom, they control their press and we can't really push back on the buttons there as effectively as you push our buttons. So you even can look at our nation today and many people describe it as divided. I can't tell because I think people are amplifying the edge. And I think we're getting that through our media in such drastic numbers that nobody really knows what's normal anymore. And it's too easy to do, you know. So I think if you go on offense against us, you just get us tear ourselves apart, you know, that's what you do. Psychological work. Absolutely. And you can, you know, and if we've even seen that, you know, no matter what people say about the DNC breach of 2015 and the documents leak in 2016, a lot of people don't like to talk about that. It became a political issue. But somebody hacked these servers and somebody leaked documents, we'll leave it at that. I would say that the, to me, all of the facts did align in my experience to it really was the Russian GRU and SVR that did it. Just all the same tools. And what's interesting about those guys, by the way, they really used their own crap. So if you find their crap, it's them. I don't think they're leaking it out and giving their custom tooling to other people. And I've never seen a modern nation hack and then leak documents before. That was kind of the first. That was a escalation in my domain. China doesn't do that. They're not going to hack Sean Ryan and then take all your email and throw them out on the internet. Russia seems to do that now, you know, it's a little bit different, but that's what I do. And then what would stop you from hacking people like Hillary Clinton or Obama? They lost their emails before to what we would attribute as foreign actors. Leave the emails, make crap up in them. I mean, we are a culture now where I don't even know if you need the evidence to tell someone under the bus, you know. So I think the way I'd go to war with the US is maybe what we're already seeing. You create division. Absolutely. You create this court. It doesn't matter. You don't even pick a side. You pick all sides. Just throw it at us. I would actually pick the two opposite sides and keep pushing both of them. And you see it. It's going to make it tough to lead in our country and it's that freedom of speech. Everybody has the right to say whatever they want and so we got to figure out how to protect that freedom while still showing. I would argue the biggest thing we have to do is find artificial amplification of ideas and quash it. Because you think it's like 5% of America thinks something, but it's like 3% plus amplification. But that's really hard to do. And in reality, the biggest guilty people for amplification are marketing people. You know, you have the foreign intelligence will absolutely amplify certain ideas, but unfortunately so do US organizations. You have to do this or, you know, here's the cure. So it's really, it's a tough battle. And you know, you often study, there's a book out. You have kids now, so you're going to have to read these things. And you look into the anxious generation, the same person that wrote the coddling of the American mind. And when I leave, I'll send you these books. It's a reporter. You don't even need to read the book, Sean, just look at the graphs. Ever since the iPhone came out and people use social media, depression goes skyrocketing, thousands of percent, suicides go skyrocketing, hundreds to thousands of percent, they don't know anything other than, well, it all starts going bad in 2007, the year of the first iPhone. You don't play a maple, but was the species ready for what we're actually developing? The tech finally get out in front of us in a way where we couldn't manage the fallout from it, and to some extent, a social media, I think that's the case. It is a social media in many ways, 'cause of the anonymity behind it, does have the propensity to amplify the minority. It has that possibility. So anyway, it's a tough one. So if I'm on offense against United States, I'm all hearts and minds, fake media, synthetic media. Even if you know it's fake, you won't get it out of your mind, right? We even have an administration that uses it, and I think it's, we're gonna have a future where we won't be able to tell properly between synthetic media and non-synthetic. - I think we're already there. - And I think you're right. And so the hearts and minds, when you have a nation like us with this openness, I mean, we're pulling ourselves apart pretty hardcore right now. Feels that way. - I mean, you would even mention breaching companies. - Total rating riff. - Oh, absolutely companies. - Absolutely. Get the trusty business leaders. I hate seeing these ideas publicly because you can do it. Discredit public leadership in credible ways. I don't even think you need credible ways, but just do it in credible ways. Meaning, say you hacked someone and get their email, leak it. I've seen what that does to people, but leak it, nothing stops you from adding to it, and doing it in a friendsically sound way, or in a way where some, there's always a pun in it that goes, "Oh, it's definitely real. "I'm an expert and that's real." It's just seem, and then you have someone who really knows what to do and going on. This looks fabricated. I've worked cases where all the evidence was fabricated digitally. That was amazing to me. Couldn't believe it. At least my opinion was it was, and people agreed with it. In today's day and age, it's just too easy. We all have digital lives. We all rely on technology more than ever before. You have wearables to tell you how much you sleep. When you should take pills or drugs. You have wearables that might even, you may even have apps that require prescription at some point in time, because you have something on your list that says you need more of something. I'm sure it already exists. We rely on this text so much, but the unfortunate reality is, you can take it. You can take that data. You can skew that data. You can use it against people. We have a whole generation, Sean. I think all their deepest thoughts has already written down. In the text they shared, in the photos they share, maybe we've waived the right to privacy, and maybe that's the transition mankind's going through from the private life, and people didn't need to know our thoughts did. Now everybody knows everything we're thinking. And maybe we cross the chasm and just recognize it's okay to think whatever the hell you want, how dark it is, or how great it is, but we haven't crossed it yet, so damn. Yeah, so that's what I would do on offense. That's what I taught you. When I was at the Naval Academy, we were talking about it. Everybody was coming up with their neutron bomb blow up GPS, and that's what we do before war. I'm like, how about a road confidence in your lawmakers and your business leaders? And how easy that is to do, and it is easy to do. One allegation creates doubt in a lot of people, whether it's founded or not. So we need to have a better system to, they call it a cancel culture. It's tough. Damn. Yeah, sorry. Dark stuff, man. We got to end on a, we need some sunshine. Well, I don't think we're going to get it any time. Absolutely. But the hypothetical is how do you attack us? What do we do about it? Boy, is there ever a time for critical thinking? And how do you teach that? And how do you train that? And honestly, and I've heard you talk about this in your exactly right, and this is a cybersecurity episode, but when studying cybersecurity, it's directly related to ideological conflict, you know? Period, it really is. And people with opposite opinions got to learn to talk and respect each other. The American way is gotta be. You can have a disagreement, still be fans of each other. Yeah, you know? So we kind of, we have definitely lost that. It reflects it in cyberspace too, really does. Like it, it's, we used to be able to. And this is something that happened in my career. If you committed cybercrime in the United States, you got caught. And penalties were stiff. They were, a lot of people would argue they were really stiff 'cause judges and lawmakers didn't like the invisible crime and the anonymity of it, and they wanted to stop it 'cause it was maybe too easy. So you have a severe penalty 'cause of how easy it is. And suddenly in the last few years, we're running the Western hemisphere hackers and they're not getting arrested. And I don't know why, you know what I mean? Like in my career, I had at least a 25-year run. If you had to from LA, oh man, you got caught. If you had to from anywhere in this country, you got caught. If you were doing it in Canada, you got caught. It's seemingly getting harder. And I don't know what's going on, but we do now have in my career where we're responding to intrusions and the threat actors are on our continent. Isn't that weird? Didn't used to be the case. And hopefully we get, you know, we get back to where we were. We push all unauthorized or unlawful internet-based activity for most of all, we gotta get that. We ought to be able to control our backyard. The internet wasn't built with your privacy in mind, but Glacier was open the app, tap connect, done. You're protected. Remember, privacy isn't paranoia, it's protection. Do you ever wonder what it takes to make an episode of the Sean Ryan Show in this exclusive studio tour? I'm taking you behind the scenes for an in-depth look at every part of the operation from the editing room in the main studio to the spaces where we film range day, content, and more. You'll see how the show comes together. Meet some of the people behind it and get a closer look at the work that happens off camera. When you become a paid member of the SRS Patreon community, you get more than just the podcast. Watch new episodes early alongside other members. Join monthly live shows with guest Q&As and submit questions just like you see on the show for upcoming guests on the protector tier. You'll also unlock exclusive range day videos behind the scenes content and premium ambience videos that you're not gonna find anywhere else. Join the Patreon community today and get access to the full experience. Let's move into our four adversaries. Yeah, who are they? In cyber, you got to go with Russia as a two trick pony, criminal and real foreign intelligence services, high capability, when focused, they are Wayne Gratsky on the penalty shot, right? They're real good. China, scale and scope. You can add all the threat groups I tell you up and they do not create the volume of compromise that the Chinese government does. So all of it together, criminal, Russia, North Korea, Iran, all of it together doesn't add up to the steady tsunami of Chinese-based intrusions. And we only know what we know, but we look at my old company, Mania, responds over 1,000 cybersecurity breaches a year, Sean. And these aren't the ones you're five minutes behind. We get hired when the scale and scope of the intrusion requires additional expertise, and that's us. And we're responding with companies that have great talent and great defense, and we're still showing up going, all right, how did they break in? And it is new and novel attacks. It is things that would work 99% of the time or higher. And that's, you know, so we've got to respond to those. And when we look at that, with that a doubt, since 2004, China has led the way, we've always responded way more to breaches coming out of China. They follow rules of engagement that I don't think are written down, but they are polite hackers. They don't delete your data, don't destroy your systems. They steal things. Russia hacks for security reasons. And you know, the SBR, in my opinion, follows probably the same rules our offense does. But their FSB, TRU, a little bit more broad than what we would ever probably allow. And I've heard stories of Russian threat actors that hack for the government during the day and hack, you know, to make money at night, I believe it. Certainly, Russia condones all crime being done in the cyber domain period. But they actually, yeah, from what I've heard, both China and Russia, I mean, they have put on classes, courses, schools, totally. And in the schools, they actually just hack the U.S. as a train. I think with China, they'll hack not to make money, though. You know, not directly Russia they would. And so North Korea only hacks to make money, it seems. I mean, in reality, North Korea is the only people in uniform badging into building every day, or at least showing idea to get in, are hacking to make money because they fund themselves. Is that incredible? And have you heard about the North Korean IT problem? Where it's not hundreds. Thousands of North Koreans have been hired by companies in the United States, because we all started hiring remotely during COVID. We hire IT professionals, they speak English, they know what they're talking about, but they're actually North Koreans. And you hire them. And a couple of days after you hire them, they just steal all your crap and go. And sometimes they keep working for you because you're paying them 130 grand a year. There's a podcast coming out by Nicole Pearl, and maybe you'll meet Nicole. She's a New York Times reporter. She's doing her story on this now. Her last podcast was on the Chinese Cyberassetmanage campaigns, and she can do things I can. Like she'll say things I won't say, or she'll talk to the victims and follow up when I never got to do that. She saw the ramifications of companies losing their IP. I just saw what the attackers did and how to clean it up. She's doing the North Korean thing now. And when I first heard that problem, hey North Korea, you know, has IT workers getting hired, I'm like first out laughing at it. There's no freaking way that this can be a problem. And I was at a conference with a bunch of heads of security from really reputable companies, and as soon as I was like laughing it off, like a five of them came up to me and started to say, hey, no, we have the problem. And when they explained what happened, I went, there's no fix for it. The fix is you've got to get people in the chair across from you and hire them. And the problem is, we literally hire internationally. Many US companies will hire people in Europe through Zoom, Google Meet, you know, or Microsoft Teams. And these are programmers that can answer to questions, right? I mean, and quite frankly, they all even do the damn job for you. It just so happens you're paying someone who's working for a weapons of mass destruction unit. Literally. And so the North Koreans, you may hire them and then they have to steal a big coin. They're hacking to make money. Russia's hacking for spying and crime. China's hacking for spying. And long-term economic gain through theft of IP. And Iran right now, you know, with what's going on the excursion going on right now. The cyber domain was already a crappy neighborhood. Think of it as it's like, Camden, New Jersey, no offense, Camden, tough place. It just got five new gangs to it. It's like cranking it as they say in spinal tap, crank it to 11. The cyber domain, if you can be hacked by an Iranian effort, they'll do so. But the way they break in right now is with user accounts and passphrases that are already on the dark web. Like you lost your use on the passphrase from some prior breach somewhere, maybe your own company, maybe somebody else's. They tend to brute force long in and then they're going to delete everything they get in right now. Whoever they are, the gangs that want to support the Iranian cause. So yeah, these things will see any retaliation from in the cyberspace from what's going on in Iran. I think right now there's probably automated programs running on behalf of the Ministry of Security Intelligence and Security MIRIS over there that if a Ken break in will and then they got to get a human operator to do something with it. It doesn't take a lot of bandwidth if you can get, you know, you don't need a whole lot of satellite dishes to get something working for you there. Yeah, you'll see something and it'll be real hard to tell Sean whether it's really the Iranians or proxy or just somebody who wants to have for the hell of it and make some noise. Which one of these out of Russia, China, Iran, North Korea? Which ones? Who are you most worried about? You worry about them for different reasons. I would say sophistication now goes to China. For how they first break in. How people break in will always change. China seems to be the forerunner of what's called zero day development now. They can find a tax that are going to work. And then but when they break in, they're not leaking your email to the press. They're not extorting you. Those are really complicated. So I would say Russian criminal really hard to go against. There's some now Western hemisphere criminal gangs. There's a group called Shiny Hunters. There's a few others that they break in with social engineering. They'll like call your help desk and help us help people. And they have whole scripts written in the very bold and they get one time authentication into your network and they then go in and once you can get any beach head in the cyber domain, usually that means you take the island. You just need that one boot on the ground and you'll do fine. So you need one way to access the network. You'll spread from that. The Russian criminals really hard to deal with the US. Now we have Western hemisphere criminals. They're really, really hard. Iran's going to delete everything right now, probably if they get in. That's not going to be a fun cleanup. They're all bad. I mean, that's the reality, Sean. But the public humiliation does not come from being hacked by the Chinese. That, you know, those you can handle quietly and discreetly. I think it's the Russian and the North Korean and the Iranians are probably going to go public. And that just adds complexity to your response. Got you. Got you. All right. Are you hanging in there on cyber in there? Scary shit. So we've got to get more optimistic. This will move into your new company. I got to ask you a question. So you know, Clod, I'm sure. Oh, God. Anthropic. Yeah. So we had Clod Anthropics. I scraped the internet to ask you a question. How did it do? And here's what it came up with. In 2010, Stuxnet became widely known as the worst first, the world's first cyber weapon. The US and Israel used it to physically destroy Iran's nuclear center fuges. That was 15 years ago. Now with AGI being reported as achieved, do you think AGI is the new cyber weapon? And why? Fast answer. Yes. You have to use all technology to advance crime, to advance war, to advance societies. It does all of it. It does good. It does bad. The invention of the gun helped the hunter, but it also helped criminals, to some extent, depending on your frame of reference. AGI will make the speed of intrusion take the human out of the loop. That's what it will do. It's too fast at discovering vulnerabilities. So I started armoured in and combined what's called red team consultants, the best red teamers in the world. These are folks that got paid to hack into Fortune 500 companies and see if you can stop the train or corrupt the food or shut down the grid or steal the email from the CFO. We took those guys and we're still hiring a bunch of them and we paired them up with AI native developers and said automate what we humans do. And we started this company September of last year, Sean. Here's what I can tell you happens already. If somebody tells us they hire our red team and says, take a look at this custom application. You build an application that you gave me here. Someone will say, take a look at this application. Can you hack it? Well, you used to take us five days with two smart humans, is five minutes to 10 minutes with AI now. That already exists today. So what you see is the compression down, but it gets unfortunately more daunting. When we go on offense as humans, we only find one way in at one point of time to achieve the goal you've told us to try to achieve, try to shut down the assembly line, try to get to our IP. We find the fastest path in, we prove it, and then you fix that. With AI, we launch a hundred thousand threads coming out. You would find all paths in almost immediately, but it does a few things humans can't do. It has total recall the next time we ask it to do that. So if there's a vulnerability that found that company A two months ago, it instinctively already knows. Look for that again. Just in case you didn't fix it. It's the speed though. The fact that AI can think, learn and has total recall and can be trained, it will be the cyber weapon in the future. Just like no different than drones, if you think you can fight the next war and when you better have software that thinks, learns and is secure, and you better hope it thinks the fastest, learns the fastest and is the most secure to win that war. Or you're going to lose, and that's going to be cyber domain, that's going to be autonomous planes, drones, you name it. So yeah. It's going to be a long time ahead of you, I think it's going to be a long time ahead of you, I think it's going to be a long time ahead of you, I think it's going to be a long time ahead of you, I think it's going to be a long time ahead of you. There's a follow-up. Got it. On a different note, by 2027, every new car in America will have an infrared camera pointed at the driver's face, and that's by federalism. There's a follow-up. Got it. There's a follow-up. On a different note, by 2027, every new car in America will have an infrared camera pointed at the driver's face, and that's by federal law. From cyber security experts perspective, what's your honest take on this? Does this leave vulnerabilities for our adversaries to hack American vehicles? argument inside security since the dawn of time. If we're distributed, it's harder to beat us, but it's harder to defend us. If all our eggs in one basket, it's easier to defend, but easier to beat us. Right now, we're putting data about everything everywhere. I mean, I grew up, there were no cell phones in college. Otherwise, I would never be able to be a Supreme Court justice, right? Evidence would exist. Now there's cameras everywhere for everything. There's just no question, even though it's going to get harder and harder to compromise things, I believe that. The internet was pretty damn open in the 90s, and I've lived that. It was pretty damn open in 2000, really until 2020-2021, and we're in a whole different world. AI's going to help us write more secure code, there'll be less vulnerabilities. But at the same time frame, should someone break in, I think the impact is going to be far more than what it used to be in the past. Early on in this interview, yes, it was worse for each we saw, and I remember going, I always hated it if a flat officer lost his email. That's just weird, because they do important things. Fast forward to now, with wearable devices and our dependency on everything, whole businesses can operate if the internet goes down. AI will be the offensive choice, and unfortunately, because of the speed of compute, AI is going to have to be the answer on defense, and that's why armament didn't exist. We will be the ultimate offense built by the good guys to train and automate the defense, and every company is going to need a different defense. We're all going to write our own apps. We talked about Anthropic and Cloud. Talk about magic. I got a computer science degree. I hate to say it. Don't tell your kids to get a computer science degree, okay? Heck, ask the CEOs of these companies at S. Dario at Anthrop, okay, you want your kid to learn computer science? You'd probably say, it's like learning Latin. No one's going to speak it. The computers are going to do it for us. The whole goal of Anthropics is to have Anthropics Cloud build the next cloud. At Armadin, we want to get our AI attack would be so good. It's building its next AI attacker. They self-propagate. And the unfortunate reality is we have to build it, or the adversary will. And it is the only way to get to autonomy. But back to your original question, yeah, we're going to have cameras in the cars, cameras on the streets, cameras in our homes, data everywhere. I think it'll be harder to break into all that stuff, but should the breaking occur? I think the impact will be more grave than in the past. Now, I'm thinking today, two years from now, you should be driving a car that has something in it that instantiates normal Sean driving. And if anything happens, something very bespoke to you can recognize and say, that's not him. That's not what he wants. That's not what he does. And it may save you, may do the opposite of that. But we are going to have defense that can thwart attacks we've never seen before. And do it in a way that a human's not in the loop for. Something's asking this system to do something's never done before. They automatically get stopped and ask for a human in a loop, say, hey, listen, this has never happened in this car before. Do you really want it to happen? Or this never happened on your computer before or on this camera before or on your HVAC before? Do you really want to allow it? Stuff like that will exist. Interesting. And then you'll pick in your house, you'll say, I want to be prompted every time someone's accessing my camera. Other people will get trained specific to them. It'll get one time human to go ahead and allow it to happen. And after like three times where the user says, go ahead and allow the program to do something, it'll just do it from there on in. We'll have bespoke software trained by you. Your phone will end up being trained by you. The AI on your phone will know you, be personal to you. There's got to be vulnerabilities within that alone. Well, yeah, you often wonder, now we're talking to two AI SkyNet story, right? One brain in the sky doesn't mean we all share one brain over time. And that brain will always reflect the culture of those you built it, to some extent, right? And then all AI models, no matter what anybody says, we had to add armoured and build a way to as soon as they update at the front to your laps their models. We plug them right into our shooting range and see which ones are the best at the things we normally do now. And no flip and flop all the time or they'll be about equitable. And we test them on the range as they say. But these things, you test them day one, you test them day 20. They're already different. They're like, they're like organisms that grow. These models learn and change and sway in ways that are different. Like how we, what we get out of a model today could be totally different tomorrow. Not totally different. It's always, you know, to me, I haven't gotten a hallucination a long time. And I use Gemini a lot and I use Claude a lot. I'm a little less open AI. And I use it for real stuff every day. It's common I'll have like Claude running on something that I want because it's great. I make them PowerPoint slides and I have Gemini making some graphics for me or answering questions. I'm using them both. Interesting. Yeah, interesting. Where do the motivation come from to start armoured and has to exist? Right? It's two things. One, I wanted our, the first motivation is, you know, my company got bought by Google and I'm an entrepreneur. You know, some people would say once you're an entrepreneur, you can't sell your baby. I had no problem being a public company and getting bought. Comedy is no longer mine. I was a face for it. But if you're a great entrepreneur, at some point in time, you're also the owner, but you know, I had no problem letting it go. I was bought by Google and I went in like a lion super like Google can change the world. It really kind of the resources it has. I just didn't fit. You know, so I was a little upset in a way that I didn't fit there because I know the power and capability of that company or Amazon or Microsoft. We have great companies. They can do great things in cybersecurity and you want to be a part of that. But one thing they would never do is offense and I respect that. I get it. I wouldn't fit with a large brand and I thought to myself, the exact thesis I had was the first intel in the internet was terrible. You had to find what semantic mist and give it to them. The second intel in the internet, I feel I created will respond to every breach that matters and people are like, that's not even a that's not even a market. There are no breaches. Oh, there were. We responded to all of them and we learned about the new and novel attacks first so that we could build better defenses against them. Well, the third wave of intel is we're going to create the attacks and we're going to create before the bad guys do and we're going to fix your problem before they come out. It's almost, you know, I guess they call gamification in a way for viruses, but if you can create the viruses that are coming 10 years from now and inoculate today, we're ready. You know, same thing here. But we have to build it because it's going to be what we're up against. And if you want to know if a bulletproof vest works, you got to shoot a bullet at it. We're going to be shooting bullets at networks. And if you can withstand our bullets, the assumption and what we want to become is that seal of approval. If Armadin can't break in, oh, you're good to go. Brief the board, let him know. There's no other way to reduce your cyber risk and I actually believe that. So we started Armadin so that we can dry run and practice what we're up against. And it's common. There are no risk repercussions to the folks stealing from us, hacking us. Just we haven't shown a means to impose risk to these threat actors. So you get you got into it a little bit, but what is the future of cyber warfare with AI coming online? Oh boy. You will have systems dedicated. I think. So the general models are what I call horizontal models. Like Anthropics Cloud is a horizontal model, right? Open AI, horizontal model, X as a model, Gemini for Google. There's going to be very verticalized models where you train them and learn from these huge models that have read every book, every human's ever written or watched every YouTube video of everything. You've contributed to models probably. You don't even know it. And you're going to you're going to have offense against very specific things like we're going to end up creating models that are offense against cell phone offense against drone offense RF against drone offense against windows offense like deep models that are actively working the same way a human did, but at thousands and thousands of times the speed and doing the same tests we did to try to find vulnerable code, vulnerable IP, you know, it'll all be automated and specialized for the targets they go after. It's going to happen. And the sad thing is we had to build armoured in because it's automatically going to happen. Every shift, I live through this, Sean, and in 2000, there was a guy named Alexi Ivanov and a guy named Vasiliy Gorskov. At the time in 2000, Alexi was 18 in Chelyabins, Russia. Vasiliy was 25 in Chelyabins, Russia. These guys extorted hundreds of US companies. They'd break in. And what they did is they scripted everything. They even scripted, we got to do the forensics on their laptops. These two Russians were lured to the United States for jobs. And the jobs they got were with the FBI. The FBI lured them over. They flew into C-TAC airport or Tacoma airport. And they got arrested. And when you look at what they did, it was at a time when PayPal was just coming out. eBay was getting big. These guys had monetized that they could steal credit cards. And they wrote software that would sell fictional items on eBay, buy it with stolen PayPal credit cards. And they were making money, selling fictional stuff. And the whole thing was automated. They could literally hit buttons, script it, and walk off, and come back. With we made $72,000 selling stuff we don't even own and buying it with fake stuff happened so Every shift changes embraced by every personality AI is going to be embraced by the criminal element in this comment And we can't withstand it unless we build it ourselves and figure it out So I always believed the best way to build a safe at a bank is to get the best bank robber to build it for you You know, you got it out of rob banks to investigate a bank robbery and I had the privilege of training Thousands of FBI agents to FBI Academy, so when it came to cyber we taught them how to break it Get a sense of what you're up against the actors why they do it how they do it Now let's investigate what they did and you couldn't really just start with let's just investigate it It just wouldn't work yet to give in that sense of Doing the criminal act and then investigating it It's going to happen in cyber we have to build the offensive cannon So Armin is going to build the cyber cannon We're going to shoot it at the best companies in the world and those companies if they can withstand the blast they're good to go and if they can't were Over time and no human in the loop Building fixes to however we broke in if we find a permeable membrane and we get through you're going to patch it You're going to compensate for it and that is the future and oddly enough that future scalable finally you can once we build The AI on offense or say on defense we can go down to the utility and all equip a Pennsylvania and say the waterworks is not going to be compromised And the small mom and pop Electric company in Missouri will not be compromised because we can now Instantiate a national risk policy through an offensive cyber cannon training to defense and it's just software You're you're not going to be people dependent. It really is going to happen and will it have flaws? Will we get beaten? Yes, they're all but every once in a while be something on offense that gets through But you can literally use the analogy of drone swarm in the cyber domain like you're going to you're going to send 3000 drones out of city And we can only shoot down 2,990, you know We're at the same problem in the cyber domain. We're trying but the best part of it is it will be automated And it's actually going to raise the tide for cyber security for most people And then the big joys have their own team still Doing stuff to help secure. I'm just curious and I'm sure it's very different but On average how many vulnerabilities are you finding per company and how fast do you find them with these AI agents As I sit here today, it's never taken longer to the day to break in Shit yeah with any Yeah, and yeah, and here's and here's what's interesting. So I can tell you this I still think the best findings we had were by humans, but that's going to go away within a year And nobody knows how fast, but AI keeps surprising us But here's how we broke it in the first time a fortune a hundred company He literally said hey Break into us and see if you can break this custom application. We built very important application We have an AI agent they didn't even expect us to do this, but we've done this a lot We had an AI agent go out to the dark web and go to a bunch of password brokers And we found four hundred and forty or so accounts That were the domain of this company and all we did is tried all of them at human speed not AI speed because AI speeds too fast You can rate limit and block it Cisco routers can block fast attacks We just logged in Seven of the accounts actually just logged into the app we just logged in and this is an app you don't really want people logging into and on one of the thing and we did all human speed you saw browser just kind of pop up on our agent screen It was acting like it was a human tried all the accounts it found it gets in seven times, but on one of them The app we broke into prompted you don't have multi-factor authentication turned on would you like to register your phone? So we did so now we literally hacked the company like stuff we found on the internet and but Humans wouldn't have found it because it's really a pain in your arse if you scripted it's too fast and you get blocked Or detected if you have a human log in every time takes days and it's annoying and they're gonna fat finger stuff We just all automated no human intervention hacked the company That was it and that works. I would have bought that when I was a seat Yo, I would have been like I just want that. I don't even need you to try to hack my app and break in the old way of the vulnerability Just tell me if you can log into my damn network because that stuff changes everybody thinks oh we have two-factor authentication Meaning user account passphrase and then you know the digits to your phone or you know your fingerprint and all this other crap I would want to you can't there's no magic wand that says do we have two-factor everywhere it doesn't exist But this would prove it the attacker's view of your network matters and AI can Comprehensive we do that. So I'm not convinced it took just yesterday. I got a text I'll show you when we're off camera of what we do to a company yesterday 100% ownership of every machine Day one God in all of it and here's the secret and cyber so for everybody out there listening the hardest parts getting in From the internet every company does everything they can to while these above the poverty line in the cyber domain The one a enterprise is to about everything they can to not have a breach. They don't want to deal with it And they're truthful about that. They hire good people and they try If we can't get in I would say over nine percent of time we do But once we get in it's easy as health. It's all downhill skating at that point You know so shaw and that's just the problem right now everybody's built their imagino line And they've hardened that as much as they can if we get around it Oh, it's just waltz and in the Paris, you know It's too easy once we break in Everything we need is on the very first machine we get to and and usually the Achilles heel is every company has one account that works everywhere So you can patch things so you can fix things You can't keep that account from us That's just the Achilles heel. So it's funny the very thing you use to make sure you're secure It's probably the very thing that we get every time to make you insecure You know, so anyway, we will get better everything as bad as this whole three hours or so is gone Everyone's getting better at cyber defense. We are in a tough time The offense is still uniquely advantaged. That's the problem. I think it does change in under two years two Equitable I don't think defense is it the only advantage defense has is we should have access to the software we build To make it secure Before the offense can try to hack it. That's our only advantage. We can secure our code before we publish it Get it out the market and the and the anthropics of the world are making that a reality Microsoft and Thropic Google Really are making it so the code we're writing is better today not worse. That is happening So in theory, it'll get better Sean. That's good news It's just we're going through two years now This style. I would be different. I would say you know what we're stopping 99.99999999% of attacks now It's just the best in the world. We never get to stop them. They are they're scoring Wow, yeah Okay, then we'll wrap it up here. Yeah sure. It's been I've learned a ton really. Yeah, so thank you for coming One last question. Yeah, sure If you had three guests to recommend for the show who would they be Well, I love Bruce Springsteen Bruce Springsteen all right Three guests for your background. If you do another one in cyber The best person that can bring this to everyone is Nicole Pearl Roth the New York Times reporter I told you she is exceptional on camera and she tells better stories than I do Yeah, because I came up through computer science and I had to solve the problems I had less of a humanity side to me when I met CEOs. I was always like hey man suck it up deal with crisis She's better at it. She tells better stories as to what China did What and what the North Koreans are doing she's more personable more likable So she's a great one for cyber Those are to you know and I don't know you're doing a great job People like listening like I listen to Kent the guy that you just had okay. Yeah, I thought he was great I'm a political. I want the United States to be successful. I thought he did an incredibly good job Doing the same being a political people probably hate the guy. I'm probably getting trouble saying it I just listened to him thought okay. I learned something You know you listen to you know bottom line you get both sides you get you get people that at least are I think that's important I get a lot of it. Yeah, I mean it's uh it's important. So anyway, I'll give you those two spring scenes. It was good. Perfect. It's getting old Kevin, I really appreciate it. Thank you for focusing No matter where you're watching the Sean Ryan show from If you get anything out of this at all anything please like Comment and subscribe and most importantly Share this everywhere you possibly can and if you're feeling extra generous head to apple podcasts and Spotify and leave us a review I'll see you next time.

Podcast Summary

Key Points:

  1. Kevin Mandia, a 30+ year cybersecurity veteran, shares his journey from USAF officer to founder of Mandiant and later Armaden, an AI cybersecurity firm backed by In-Q-Tel (CIA's investment arm).
  2. The interview covers the evolution of cyber threats, contrasting Chinese and Russian hacking tactics—China historically stealing vast data with less stealth, Russia using precise, stealthy operations.
  3. Mandia details the 2013 APT-1 report exposing China's PLA Unit 61398, which targeted 141 U.S. organizations, leading to public disclosure and a temporary drop in attacks.
  4. He explains the emotional toll on victims, ransom and extortion dilemmas, and the prevalence of cybercrime, noting billions paid in Bitcoin annually.
  5. Mandia recommends iOS devices for better security and discusses the Glacier app, a consumer privacy tool developed by Sean Ryan, which he praises for its approach.
  6. He reflects on China's potential win over Taiwan through population growth and cognitive warfare rather than invasion, and his trust in U.S. institutions like the NSA.

Summary:

Kevin Mandia, a pioneer in cybersecurity incident response, discusses his 31-year career defending against nation-state hackers. Starting as an Air Force officer in 1993, he entered the field when computer security was nascent, eventually founding Mandiant in 2004 to respond to major breaches. He contrasts Chinese and Russian tactics: China historically operated like "a tank through a cornfield," stealing massive data with little stealth, while Russia used precision strikes and better tradecraft.

However, China improved sophistication post-2020. S. defense contractors and other industries, leading to a temporary halt in attacks.

He also addresses the human impact of cybercrime, including stolen emails and extortion, noting that ransom payments often prevent data leaks due to criminal governance. S. intelligence institutions.

On geopolitics, he suggests China may win Taiwan through demographic and cognitive strategies rather than invasion. The conversation underscores the persistent, evolving threat of cyber attacks and the emotional weight on victims, while Mandia remains committed to protecting national interests through innovation like Armaden.

FAQs

Sheath uses a dual pouch design that keeps everything separated, supported, and comfortable, so you don't have to constantly adjust. It was originally built by an active duty operator for long, hot, miserable days.

You can visit sheath.com/srs and use the code srs for 20% off. Sheath also offers a first pair guarantee, so if it's not for you, you get your money back.

onX Offroad is an off-road navigation app that shows trails, public and private land boundaries, campsites, and detailed trail info. It allows you to download maps for offline use and share your location with a group so nobody gets lost.

Go to ridge.com and use the code srs at checkout for 10% off your order. Every dollar you spend gets you more entries into their sweepstakes, where you could win a Lamborghini, a Hennessey VelociRaptor, a Ford Bronco, or $100,000 in cash.

The Glacier app is a privacy and security suite that includes Secure DNS and virtual burner numbers. It protects your phone from exploitation while browsing and helps reduce your digital footprint, with features designed by former Intel professionals.

The advice depends on the situation, but it's important to weigh options carefully. Paying a ransom or extortion is a tough decision that should consider risks like protecting customers or lives, though there's no guarantee the data won't leak.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.