00:01Well, Joe, I think reached an agreement means paid. I think the company should say that
00:07it paid because reached an agreement is just tricky wording. These hackers, shiny hunters
00:15aren't suddenly becoming nice people and deciding because they've affected 8,800 or so education
00:24institutions around the world and affected millions of students that they might just
00:28give the information back. So it's naive wording, it's improper and it doesn't give people the
00:35right information for them to make their own decisions. There's a few other things. The
00:39company has said it's had the data given back to it. It's not like a car was stolen from
00:44your driveway, Joe, and someone can bring it back and say, sorry for taking it. When someone
00:49steals the digital information, the original stays in the system and criminals steal the
00:54other bits. So to give back a copy of something that they've probably kept a copy of and will
00:59on sell in the criminal black market, giving assurances mean nothing.
01:05Yeah. And so there's no guarantee because it's also said in some kind of statement that the
01:12hackers have destroyed the information, but there is no guarantee that that's happened.
01:17Not at all. I'm extremely sceptical. Police every once in a while actually catch these types of
01:22criminals and execute search warrants and find data that was meant to have been deleted, find records
01:29of where they've onsold that data. These are criminals that stole it in the first place. So they
01:34haven't, as I say, suddenly become good people. So this is where the problem lies. Now I'm not against,
01:41and this might sound controversial, the concept of if computer systems are locked up and people could
01:47die like hospitals or power companies or water companies are locked up. This is what we call
01:53ransomware. I actually think it's a legitimate consideration on the part of a government and of
01:59pieces of critical infrastructure to potentially pay as much as we should avoid it. If there's life
02:04and death situations, this is not a life and death situation. It's a terrible thing that so many
02:10millions of people have been impacted by this hack. But the information is not of such a gravity.
02:17And the situation, as I say, computers aren't locked up and institutions unable to function,
02:23there shouldn't have been a payment in this case. And I think it's a sense of dangerous and bad
02:28precedent. The fact that it's clear there was a payment. And what is that dangerous precedent?
02:33Well, it does, it does fuel the criminal economy. And as I say, I always have a carve out that
02:38says if
02:38someone's going to die, or if it's going to collapse an economy, that you have to consider
02:43occasionally dealing directly with criminals. So don't get me wrong here. And that's even a
02:48controversial thing to a position to have, by the way, some people say you should never pay.
02:52Those people have never dealt with real victims of crime, because every once in a while, you have
02:56to make that concession. But in this case, the companies being cute victims, and there are plenty of
03:03victims in this, the company themselves, the 8,800 plus institutions that were using the services of
03:09this company, and then the millions of students, teachers, professors, and others that are impacted,
03:14whose data has been stolen. So there's an awful lot of victims here for, in structure, the parent
03:21company to say that they've come to an arrangement, and have the data returned is fanciful.
03:26And so what does this highlight about the need for companies to be as cyber secure as possible?
03:32Well, this highlights that we rely on software services that we've never heard of,
03:37from companies that aren't in our jurisdiction, that actually form the fabric that a lot of our
03:43other institutions operate on. So this highlights supply chains, it highlights that there are organisations
03:48that have millions upon millions of records that aren't securing them well enough. It is a wake
03:54up call that there are these massive software, software as a service platforms that we rely upon,
04:00where clearly security can fail, it can always fail. But more needs to be done. This isn't the first of
04:06these types of hacks, and it won't be the last. But it's an indication that as you might tighten some
04:13of
04:13your software type controls, you then need to be ready for these social engineering attacks, which is
04:19what Shiny Hunters, this particular criminal group does. They trick organisations into gaining access,
04:27and then escalate their privileges and commit these types of crimes.
04:30Yeah. And so is it almost impossible to guarantee yourself against hacks now, especially with the
04:35onset of AI enhancing hackers' effectiveness? And to what extent is that happening?
04:41Well, complete computer security has always been a myth. The job of cyber security experts is to reduce
04:50the likelihood of an attack being successful, to detect that hack fast, and to reduce the harm
04:58associated with it. It's a risk reduction exercise, it's not binary secure or insecure. But certainly the
05:04frontier models of AI are making hacking much easier. In this case, it was unlikely to be an AI-based
05:13attack. It was a social engineering attack, where they will trick people out of these credentials,
05:19logins and the like. But yes, AI is making all of the threat environment worse for those of us who
05:27defend systems. So people should be ready, sadly, for a never-ending story of computer crime and losses.
05:37Yeah. And when you link that with an example like this, and the payment of a ransom,
05:42what does that indicate about where this is headed?
05:46Well, there are two big sort of threat actor groups here that we deal with, Joe. There's a vibrant
05:52criminal economy and that relies upon essentially either causing harm in exchange for money or stealing
05:59things that they exchange for money, data and other things. That's this type of incident we're talking
06:03about tonight. Then there's the nation state threat actors who largely steal for strategic reasons,
06:09though we have seen countries like China starting to look at how they can cause actual harm to critical
06:16infrastructure through their cyber means. And AI and the mix of these two lots of threat actors,
06:25there's an increasing blending between them where they'll use fronts for each other's activities,
06:31just makes it more complex. And added on top, of course, Joe, we're using more technologies that
06:37are more complex, including AI. So it just basically makes that risk equation more complex.
06:46The
Comments