The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyber Leaders
Cyber Leaders artwork

The Rise and Fall of Conti with Geoff White

Cyber Leaders · 2026-06-19 · 49 min

0:00--:--

Key moments - from our scoring

Substance score

77 / 100

Five dimensions, 20 points each

Insight Density16 / 20
Originality14 / 20
Guest Caliber18 / 20
Specificity & Evidence17 / 20
Conversational Craft12 / 20

Cyber journalist Geoff White returns to discuss the rise and catastrophic fall of Conti, the Russian ransomware group that dominated 2020-2021 extortion campaigns. White traces Conti's origins back through Evgeny Bogachev's Zeus banking malware operation and the Dyre Gang, revealing how money laundering infrastructure and Russian criminal networks enabled their evolution. The episode draws heavily from 350,000 leaked internal Conti messages - written in Russian hacker slang - which White has been analyzing to reconstruct the gang's operations, internal dynamics, and eventual implosion. This is the basis for the fourth season of BBC's Cyberhack podcast (launching July 6), which examines ransomware through unprecedented access to criminal communications. Valuable for security leaders, incident responders, and threat intelligence professionals seeking to understand how major ransomware operations function, their organizational structure, and the human vulnerabilities that led to Conti's public meltdown after the Ukraine invasion.

Key takeaways

  • →Conti's internal leak of 350,000 messages in Russian provides unprecedented insight into criminal operations and psychology that most journalists haven't leveraged effectively due to language and hacker slang barriers.
  • →The modern Conti operation evolved from a lineage of Russian cybercrime groups including Zeus (developed by Evgeny Bogachev) and the Dyer Gang, showing how criminal enterprises adapt and rebrand after law enforcement pressure.
  • →Money laundering infrastructure through front companies like 25th Floor Film in Moscow was essential to Conti's ability to operate, demonstrating that successful cybercrime requires sophisticated financial operations beyond technical hacking.
  • →Internal messages reveal the criminals' mindset and sentiment in real-time during active crimes, before they knew the communications would be leaked, providing authentic perspective into adversary thinking and behavior.

In this episode

  1. 1Introduction and Show Format
  2. 2Quiz: What is Conti?
  3. 3Introducing Guest Geoff White and BBC Cyberhack Series
  4. 4Conti Ransomware Gang Overview and Leaked Messages
  5. 5Origins: Evgeny Bogachev and the Zeus Virus
  6. 6The Dyer Gang and Money Laundering Through 25th Floor Film

Mentioned

Geoff WhiteJames LymeKieran MartinSANSContiBBCCyberhackLazarus GroupUK National Cybersecurity CenterEvgeny BogachevUK National Crime AgencyBrian Krebs

Guests

Geoff White

Topics in this episode

Conti ransomware gangEvgeny BogachevZeus botnetDyer Gang25th Floor FilmCyberhack BBC podcast seriesLazarus GroupChannel 4 NewsUK National Crime AgencyNational Cybersecurity Center

Questions this episode answers

Who was Evgeny Bogachev and why is he important to understanding Conti's origins?

Evgeny Bogachev developed the Zeus virus, which intercepted online banking traffic and generated over $500 million in stolen funds. He's considered a pivotal figure and "godfather of modern cybercrime" whose operation and its spinoffs, including the Dyre Gang, directly evolved into the later Conti ransomware gang.

How much money did Conti make and what evidence exists about their operations?

The US government accused Conti of making north of $150 million in ransom in one year alone, though Geoff White notes this is a vast underestimate. A 350,000-message leak of Conti's internal communications in Russian hacker slang provides unprecedented insight into their actual operations and organizational dynamics.

What role did the money laundering infrastructure play in Russian cybercrime groups like Zeus and Conti?

Money laundering was pivotal to these criminal campaigns. A deputy nicknamed "Bentley" (Benny) provided US-based money laundering facilities for Zeus victims' stolen bank account funds, and this infrastructure pattern continued through successor groups like the Dyre Gang and eventually Conti.

How did Geoff White access and analyze the leaked Conti internal messages?

White obtained the 350,000 leaked internal Conti messages and has been analyzing them to extract insights, data, and sentiment. He's currently 47,000 messages into the analysis, working through Russian hacker slang to understand the criminals' communications during their actual operations before the messages were later leaked.

What is the BBC's Cyberhack podcast series and how does Conti fit into it?

Cyberhack is a BBC podcast series that started with two seasons on the Lazarus Group, expanded with a third season on Russian cyber criminals, and now features a fourth season dedicated entirely to Conti, launching July 6. White produced the original Lazarus Heist podcast which became the foundation for the broader Cyberhack series.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

16 / 20

The episode densely packs specific operational details about Conti's business model evolution, internal dynamics from leaked messages, and concrete examples (Graph Diamonds, RedCar Cleveland, Irish HSE, Costa Rica). However, roughly 8-10 minutes of the 49-minute runtime consists of intro banter, tangential jokes, and host setup that dilutes insight delivery.

Accused by the US government of making north of$150 million worth of ransom in one year. And that, by the way, is a vast underestimate.
I'm currently 47,000 messages into those messages, trying to sort of pull out insight and trying to pull out data, but also trying to pull out sentiment from those messages.

Originality

14 / 20

The episode's core originality lies in Geoff White's access to and analysis of 350,000 leaked Conti internal messages - a genuinely rare primary source that yields fresh insights into criminal psychology and operational mechanics. The framing of ransomware as competitive business rather than crime is thoughtful, though the frameworks themselves (state of nature, business model evolution) are not entirely novel.

What was useful about Conti was that for reasons we can go into, there was a huge leak of Conti's internal messages. Something like 350,000 internal messages from inside Conti came out.
They describe themselves as post-paid penetration testers... the idea that you would normally pay for a penetration test to expose your vulnerabilities. Well, we've done one of those tests, we just didn't tell you we were doing it, and you failed, so now you have to pay us.

Guest Caliber

18 / 20

Geoff White is an exceptional guest for this topic: he's a published cyber-crime journalist (three books), BBC podcast creator/producer, has direct access to unique primary sources (leaked messages), conducted original fieldwork including interviews with victims and identifying alleged gang members via open-source investigation. He brings rare expertise that neither host possesses.

he has written the book on cybercrime, or more accurately, three of them. And his expose of another extraordinary group of evil hackers, the Lazarus group, was so popular that BBC turned it into a very successful podcast.
I'm currently 47,000 messages into those messages

Specificity & Evidence

17 / 20

Strong use of named entities, specific dollar amounts, timelines, and documented examples. The episode cites $7.5M ransom for Graph Diamonds, $150M+ annual revenues, 350,000 leaked messages, specific dates (Sept 2021 Graph attack, Feb 2022 Ukraine invasion trigger, April-May 2022 Costa Rica), named individuals (Vitaly Kovalev/Stern), and concrete case studies with verifiable impacts (RedCar Cleveland, Irish HSE). Some claims lack full substantiation but are presented carefully.

They're accused of making upwards of$500 million between them.
we came up with a figure about 400 years.

Conversational Craft

12 / 20

Hosts ask substantive follow-ups and push White on nuance (e.g., questioning whether Kremlin controls gangs, probing why Ireland's HSE received the decryptor key). However, much airtime is lost to extended tangential jokes, host banter about coffee machines and Tom Conti, and self-referential humor that doesn't advance understanding. The quiz opening, while entertaining, is largely filler. Hosts occasionally miss opportunities to press deeper.

Why do you think, or do the messages tell us anything about why they handed over the decryptor key?
I slightly push back on what some people say, which is all, I bet the Kremlin run all of this and all these gangs are actually tracking back to the Russian government. I just don't think that's true.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

speaker67conti58ransomware44gang41russian34back33data28money26gangs23jeff21attack20fascinating19kieran17cyber17world16podcast16

Episode notes

In this episode, Ciaran and James are joined for a second time by investigative journalist and author Geoff White to discuss the extraordinary story of the Conti ransomware gang. Ahead of the latest BBC podcast series Cyber Hack , Geoff shares his expertise on Conti’s emergence as one of the original big game ransomware groups, the catastrophic attacks that brought them global attention, and the dramatic and acrimonious collapse that tore the gang apart. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org

Full transcript

49 min

Transcribed and scored by The B2B Podcast Index.

1 - > SPEAKER_02: Welcome to Cyberleaders. 2 - > I'm James Lyme. 3 - > And I'm Kieran Martin. 4 - > Welcome, or well, welcome back to the show where the geek, 5 - > that's me, and the generalist, that's me, get together to 6 - > discuss a whole range of wacky, weird, wired, wireless, and 7 - > frankly wonderful topics for the cybersecurity leadership 8 - > community.

9 - > SPEAKER_01: Yes, thanks to Sans, where we both toil happily 10 - > mostly, we can bring you the perspectives from across the 11 - > spectrum of tech security. 12 - > A perspective from someone who's been breaking the law. 13 - > Sorry, lawfully breaking into networks. 14 - > That's an important clarification in order to help 15 - > organizations defend themselves and give the baddies more and 16 - > more bad days.

17 - > So that's James, the Uber Geek. 18 - > SPEAKER_02: To the sort of issues around policy and 19 - > operations and posture that organizations need to defend 20 - > themselves from the perspective of someone who used to run cyber 21 - > defense for the UK. 22 - > That's Kieran, a geek in his very own, I suppose, special 23 - > kind of way. 24 - > SPEAKER_01: Yes, I have my own community of, well, me and a few 25 - > others.

26 - > But anyway, we bring to you the perspective of expert guests 27 - > from all over the world on different aspects of 28 - > cybersecurity. 29 - > Indeed we do. 30 - > And loyal listeners, we know there are some, and we love you. 31 - > SPEAKER_02: Yes, and we do love our new listeners too.

32 - > Well, yes, we love all our listeners, I suppose, Kieran. 33 - > Both of them. 34 - > Well, there's probably one or two that we might have an 35 - > argument with. 36 - > SPEAKER_01: But anyway, we're gonna do something new today, 37 - > aren't we, Kieran?

38 - > Yes, an abundance of newness in this season. 39 - > Our capacity to reinvent ourselves is boundless. 40 - > We're just great. 41 - > SPEAKER_02: Well, particularly when we throw in a bit of AI 42 - > suggesting new ideas.

43 - > But anyway, ignore him, listeners. 44 - > It's not from AI. 45 - > How dare you? 46 - > We're gonna start today with a quiz.

47 - > We are. 48 - > It's a one-question quiz brain teaser. 49 - > Einstein levels of challenge. 50 - > We'll come back to him.

51 - > But it is for a specific reason. 52 - > It's to help you, dear listener, work out if this is the right 53 - > podcast for you. 54 - > SPEAKER_01: Yes, now you know our long-running joke, maybe 55 - > it's a joke, maybe it's not, about some of our listeners 56 - > being compelled to listen because of court orders and 57 - > things like that. 58 - > But look, we're experimenting with new ideas for the podcast, 59 - > so we want to give you the listener.

60 - > We want to give you an out in advance. 61 - > So here's our question. 62 - > When you saw this episode and saw the word Conti, did you 63 - > think of option one, the world-leading, market leading, 64 - > handcrafted espresso making machines? 65 - > SPEAKER_02: Option two, the legendary Scottish actor Tom 66 - > Conti, best known to younger viewers as Albert Einstein and 67 - > the recent Hollywood blockbuster Oppenheimer, or to the older 68 - > viewers, such as Kieran and um Kieran, for his Oscar-nominated 69 - > performance in Ruben, Ruben back in 1984.

70 - > SPEAKER_01: Or do you think of option three, the extraordinary 71 - > cyber criminal group, who emerged from the shadows of the 72 - > original big game ransomware hunters? 73 - > And when in their prime, they caused the first declaration of 74 - > a state of emergency as a result of a cyber attack, who crippled 75 - > an entire national healthcare system. 76 - > They forced the UK National Cybersecurity Center when I was 77 - > in charge to dispatch a team of experts to the northeast of 78 - > England to rescue services to vulnerable children, who stole 79 - > the personal details of Donald Trump, David Beckham, and Ophra 80 - > Winfrey, and many others.

81 - > And they seemed master of the criminal world they surveyed 82 - > until their sudden, devastating, acrimonious, and quite frankly 83 - > hilarious collapse. 84 - > SPEAKER_02: So if you went for option one, you know, give us a 85 - > chance. 86 - > Go make some coffee on your posh Conti machine. 87 - > But, you know, maybe keep us on in the background.

88 - > SPEAKER_01: But if you plumped for option two, Tom Conti, just 89 - > switch off, go over to Netflix now. 90 - > Give the great man the homage he deserves. 91 - > I'd recommend the 80s classic Shirley Valentine, or maybe The 92 - > Dark Knight also Rises. 93 - > SPEAKER_02: But if you went for option three, I can tell you 94 - > with certainty, you are in the right place.

95 - > Stay with us for an extraordinary story of the Conti 96 - > Ransomware Gang. 97 - > SPEAKER_01: Yes, today we're going to be talking about the 98 - > Conti Ransomware Gang. 99 - > But there's only one problem, James, with this new approach of 100 - > a really serious deep dive into such a specific topic. 101 - > And that problem is, Kieran?

102 - > Well, James, how much do you know about Conti? 103 - > SPEAKER_02: Uh basically what you've already said. 104 - > So I guess you'll have to say some more, or the episode is 105 - > going to be rather short. 106 - > SPEAKER_01: Well, I do know a bit more than you.

107 - > You're not actually that interested in threat actors, are 108 - > you? 109 - > You know, they're just too human. 110 - > You're just interested in the sort of buggy code that they 111 - > sort of send you and what it looks like and so forth. 112 - > But yeah, so I do know more about it, but I don't know 113 - > enough about how to string out a whole episode.

114 - > SPEAKER_02: Well, yeah, that's fair. 115 - > I and I must admit, you're right. 116 - > I do tend to be rather more obsessed with the digital chaos 117 - > they tend to put out or the artifacts or reversing malware. 118 - > But I do respect there are some actual humans behind it.

119 - > So good job we foresaw this issue coming, Kieran. 120 - > It's a bit of strategic planning has taken place. 121 - > SPEAKER_01: Well, by you, because that's why you're CEO, 122 - > James. 123 - > So what have you got up your sleeve?

124 - > Or who have you got up your sleeve? 125 - > Maybe both. 126 - > SPEAKER_02: Well, back for his second appearance on the 127 - > Cyberleaders podcast is someone who has written the book on 128 - > cybercrime, or more accurately, three of them. 129 - > And his expose of another extraordinary group of evil 130 - > hackers, the Lazarus group, was so popular that BBC turned it 131 - > into a very successful podcast.

132 - > Sorry, Kieran is another very successful cyber podcast, of 133 - > course. 134 - > Yes, that's better. 135 - > That's better. 136 - > To eak their niche, as they say.

137 - > Well, anyway, it was so successful. 138 - > They made two seasons on the Lazarus heist. 139 - > Then colleagues at the BBC made a third series, a really good 140 - > one we've talked about before on the show, about Russian cyber 141 - > criminals. 142 - > They renamed the whole podcast show Cyberhack.

143 - > And now our guest is back with series four, and it's on the 144 - > Conti group. 145 - > It is amazing. 146 - > It's out on the BBC on the 6th of July, but we get a little bit 147 - > of a sneak preview here. 148 - > So to discuss the extraordinary story of the Conti ransomware 149 - > gang, please welcome back the one and only cyber journalist 150 - > extraordinaire, the great explainer.

151 - > It's Jeff White. 152 - > SPEAKER_01: Jeff, welcome back. 153 - > Thank you for coming back to the Cyber Leaders podcast. 154 - > SPEAKER_00: That's really kind of you.

155 - > Thank you. 156 - > That's quite an introduction. 157 - > I'll try and live up to it. 158 - > SPEAKER_01: Now, look, let's get stuck in because we've talked to 159 - > you before about your incredible career in cyber journalism and 160 - > all these baddies you've chased over.

161 - > But today we're doing this deep dive into your new output, 162 - > fantastic new season of Cyberhack on the Conte Group. 163 - > Tell us about how you came to do it. 164 - > I mean, last time we spoke, you were talking about money 165 - > laundering. 166 - > You just knew more about North Korean hackers than anybody on 167 - > the planet.

168 - > But you've gone all Russian on us. 169 - > What's the story about how this came to be? 170 - > SPEAKER_00: Yeah, I've been covering sort of 171 - > Russian-attributed hacking for very, very many years. 172 - > And actually, one of the first stories I did way back when I 173 - > was at Channel 4 News, the big UK news program, was about a guy 174 - > called Evgeny Bogachev, who's is accused of being, you know, kind 175 - > of the godfather of a lot of modern cybercrime, a very 176 - > colourful character.

177 - > So I've always been looking for opportunities to kind of get 178 - > back into that Russian story. 179 - > And yeah, what we wanted to do was really take apart this issue 180 - > of ransomware and look at it in a new way, a fresh way. 181 - > And as I'm sure you're both aware, and the audience probably 182 - > maybe has heard of, one of the biggest ransomware gangs going, 183 - > particularly around 2021, was the Conti ransomware gang. 184 - > Huge operation.

185 - > Accused by the US government of making north of$150 million 186 - > worth of ransom in one year. 187 - > And that, by the way, is a vast underestimate. 188 - > They made a lot more than that. 189 - > Wow.

190 - > What was useful about Conti was that for reasons we can go into, 191 - > there was a huge leak of Conti's internal messages. 192 - > Something like 350,000 internal messages from inside Conti came 193 - > out. 194 - > And I was always intrigued by that and intrigued by the idea 195 - > of being able to just read through their messages. 196 - > And I'd always wondered why nobody had sort of made more of 197 - > that.

198 - > I mean, Brian Krebs, another great cybersecurity journalist, 199 - > that you know did quite a lot of articles about it. 200 - > But it struck me that there was this huge resource out there 201 - > that didn't seem to have been used that effectively. 202 - > But getting hold of the Conti leaks and reading through that, 203 - > I suddenly realized why. 204 - > I mean, yes, it's a vast trove of data, but it's all in Russian 205 - > and it's all in Russian hacker slang.

206 - > So trying to translate it and dig into it has actually been 207 - > really difficult. 208 - > I'm currently 47,000 messages into those messages, trying to 209 - > sort of pull out insight and trying to pull out data, but 210 - > also trying to pull out sentiment from those messages. 211 - > What's brilliant about this is you hear from the criminals 212 - > themselves, in their own words, at the time they were committing 213 - > the crime, and when they didn't even realize that those messages 214 - > were going to be later leaked.

215 - > So you really see into their whole interior world. 216 - > It's absolutely amazing. 217 - > It really is amazing. 218 - > SPEAKER_01: It's a fantastic story, and we will definitely 219 - > come back to what those messages tell us.

220 - > But I think this partly shows we're programmed differently, 221 - > Jeff. 222 - > And it's more useful to have your programming than mine 223 - > because I'm the former civil servant. 224 - > So I was just wondering, did they have a leak inquiry and did 225 - > they find who leaked us? 226 - > Whereas you actually delved into what this amazing drove tells us 227 - > about cybercrime.

228 - > So thank you for doing that, James. 229 - > SPEAKER_02: Yeah, look, I do think this is going to be 230 - > absolutely fascinating. 231 - > We've got to get into some of those messages. 232 - > And these are gifts to the cybersecurity community because 233 - > we spend a lot of time dealing with these faceless adversaries 234 - > that subject us to these incidents and difficult weekends 235 - > and nights.

236 - > And they always seem to choose the right moment to do it for 237 - > security leaders, just as the business is busy with something 238 - > else and it's the worst possible timing. 239 - > And I remember my first example of this, the Cube Face gang back 240 - > in 2009. 241 - > Yeah. 242 - > Where, like this, we managed to dig into their operations.

243 - > We had photos of their office Christmas party. 244 - > And I remember thinking it was fascinating that there was a 245 - > Christmas party for a cybercrime gang. 246 - > Jeff, set this out, I suppose, with a little structure here 247 - > before Kira and I get excited and ask you about all the 248 - > fascinating things you've learned and your Russian 249 - > pronunciation. 250 - > The origin story.

251 - > We probably better start for folks here on who are the Conte 252 - > gang? 253 - > How do we think they got started? 254 - > SPEAKER_00: Let's start there, if you wouldn't mind. 255 - > Yes.

256 - > For me, I would sort of trace this back. 257 - > And we've been informed by some great experts, including at the 258 - > UK National Crime Agency, about this. 259 - > So it's knowledge that I had a bit in my mind, but also has 260 - > been filled in by lots of great experts and at the National 261 - > Cybersecurity Center in the UK as well. 262 - > Basically, this guy, Evgeny Bogachev, I think, was a really 263 - > pivotal figure.

264 - > He developed or was accused of developing a virus called Zeus, 265 - > the Zeus virus, which hacked into bank accounts. 266 - > It effectively intercepted online banking traffic. 267 - > And they made out like bandits those guys. 268 - > They're accused of making upwards of$500 million between 269 - > them.

270 - > It's a vast amount of money. 271 - > Evgeny was working with a couple of deputies, and one of the 272 - > deputies he's accused of working with went by the nickname 273 - > Bentley. 274 - > Bentley or Benny was the name he was using. 275 - > And he was actually over in the US.

276 - > He was a Russian individual based in the US. 277 - > And what he was providing was money laundering facilities. 278 - > And this is why one of the books I wrote was about money 279 - > laundering. 280 - > Laundering is absolutely pivotal to any big money crime campaign 281 - > or illicit campaign.

282 - > And so Benny was helping them out in Russia. 283 - > Once they hacked into Americans' bank accounts using Zeus, Benny 284 - > would help them move the money around. 285 - > Zeus got cracked down on, the money mules got arrested, and 286 - > Benny skipped town and went back to Russia where he's from, and 287 - > then effectively created a sort of spin-off of Zeus, went under 288 - > the nickname the Dyer Gang, who basically had a very similar 289 - > virus used for very sort of similar kinds of things.

290 - > Now, what's fascinating, one of the amazing wrinkles in this 291 - > story, is when they had the money back in Russia, they 292 - > needed some kind of front company to wash the money 293 - > through. 294 - > And so the story emerged that they set up a film company 295 - > called 25th Floor Film, because it was based on the 25th floor 296 - > of a tower block in Moscow. 297 - > And that was being used to wash money through is the accusation. 298 - > Now, some people who work for 25th floor genuinely believed 299 - > they were working for a film company.

300 - > And it did make films, and part of it was a functioning film 301 - > company. 302 - > But according to US investigators, it was also being 303 - > used to wash money through. 304 - > And hilariously, 25th Floor was not only making films, they 305 - > decided they would make a film about cybercrime. 306 - > Wow.

307 - > Perfect. 308 - > And I actually managed to find the screenwriter who was due to 309 - > write this film. 310 - > It's going to be called Botnet. 311 - > And I tracked this guy down and said, Well, you know, what 312 - > happened?

313 - > He said, Well, these Russian guys approached me and they flew 314 - > me across to Moscow, and they knew a lot about cybercrime, 315 - > this film company. 316 - > And I was like, Yeah, I bet they did. 317 - > I imagine they did. 318 - > He actually developed this whole script, and the script was 319 - > effectively a biography of Benny, the guy running the gang.

320 - > It was a life story of his own life. 321 - > Wow. 322 - > Absolutely astonishing. 323 - > However, disaster strikes.

324 - > The Russian government, the Russian authorities, raided 25th 325 - > Floor Film Company and effectively shut it down. 326 - > And the dire gang, the computer hacking group, sort of died a 327 - > bit of a death with that company. 328 - > But Benny rises from the ashes, renames himself Stern, is his 329 - > new hacker name, and effectively doubles down on ransomware. 330 - > Which again, Evgeny Bogachev, the guy I talked about, the sort 331 - > of godfather of cybercrime according to the US government, 332 - > he experimented with ransomware.

333 - > But what Benny, who's now Stern, did was use the ransomware not 334 - > to target individuals and encrypt individuals' computers, 335 - > but encrypt companies' data, organizations' data. 336 - > And with an individual, you might be able to get a few 337 - > thousand dollars out of them for their data on their laptop. 338 - > With a company and organization, you can hit them for maybe. 339 - > SPEAKER_02: That's great.

340 - > Evolution of business model, Jeff, it's just fascinating, 341 - > right? 342 - > Evolving the business model and being really thoughtful on the 343 - > kind of effort you put into cybercrime and how you're going 344 - > to make more dollars by picking your targets, things that 345 - > businesses do. 346 - > Yeah. 347 - > SPEAKER_01: Yeah.

348 - > And just to build on that, Jeff, so these are a bunch of cyber 349 - > criminals who've been in previous groups. 350 - > They've had their ups and downs. 351 - > They get together in various different hacking crime groups. 352 - > They do different things, but then they change the techniques, 353 - > they discover big game ransomware.

354 - > While all this is happening, and I think a lot of people know the 355 - > answer to this, but it's just worth spelling out. 356 - > How are they getting away with it? 357 - > What are the authorities doing or not doing? 358 - > I wouldn't expect James and I and our rural Cotswolds 359 - > backgrounds to be able to do this without Sanford police from 360 - > hot fuzz, at least expressing some interest in what we're 361 - > doing.

362 - > Don't tempt me with a good time, Kieran. 363 - > But these guys, I mean, we've referred to it many times 364 - > before, you know, they have business models and they're 365 - > behaving like, you know, they're having strategy sessions and 366 - > they're just reorganizing themselves, but they're 367 - > committing crime on a global scale and they're planning more 368 - > of it and they're getting better at it. 369 - > What is it with this environment they're working on?

370 - > How does it work? 371 - > SPEAKER_00: Yes, a couple of answers to that question. 372 - > Firstly, I've been told by a well-informed source that in 373 - > Russia it is illegal to hack Russians in Russia, but under 374 - > the Russian criminal code, it's not illegal to hack 375 - > non-Russians. 376 - > So for a start, Russian law enforcement responding to this, 377 - > you want a sticky wicket in terms of what you sort of charge 378 - > these people with.

379 - > An interesting law. 380 - > Yes, yeah, yeah. 381 - > Second thing is obviously, you know, the Russian Federation's 382 - > relationship with the rest of the world has been patchy at 383 - > best and is obviously now completely in the toilet. 384 - > And so, you know, what's the incentive for the Russian 385 - > Federation to sort of go after these gangs?

386 - > There's also a suspicion that there's Russian government 387 - > involvement in some of these gangs. 388 - > Now, I slightly push back on what some people say, which is 389 - > all, I bet the Kremlin run all of this and all these gangs are 390 - > actually tracking back to the Russian government. 391 - > I just don't think that's true. 392 - > I think these gangs are completely money motivated.

393 - > But they know which side their bread's buttered. 394 - > You know, they're working from within side a country. 395 - > And if, you know, the Russian government comes knocking and 396 - > says we'd like you to attack a particular target, we think you 397 - > got into a particular target. 398 - > Some experts have said there's evidence that the Russian 399 - > ransomware gangs will play ball with that.

400 - > Max Smeets wrote a book called Ransom War, in which he talked 401 - > about, you know, some of these ransomware gangs cooperating 402 - > with what he called pioneering exercises. 403 - > Yes. 404 - > And so we do believe that there's connections between 405 - > these gangs and the Russian government, but it is not true, 406 - > I don't think, to say that they are working on behalf of. 407 - > And from what Max Smeets's research dictates, and actually 408 - > some other things that we've got from the leaks, sometimes these 409 - > ransomware gangs do not like the fact that the Russian 410 - > government, you know, wants them to do things.

411 - > Because at that point, they're not making any money out of 412 - > that. 413 - > Yes, indeed. 414 - > So there's various different explanations for why they don't 415 - > sort of get caught in inverted comments. 416 - > But there are takedowns.

417 - > And again, the Russian government, Russian law 418 - > enforcement has done takedowns sometimes of ransomware gangs. 419 - > Has to be said, some of the suspicion is that, you know, one 420 - > ransomware gang will inform on another one and get them taken 421 - > down because obviously then they can take over the market share 422 - > of the other gang. 423 - > And again, crime gangs have done that since time immemorial, you 424 - > know, taking down another crime gang operation so you can expand 425 - > your business.

426 - > So there's multiple sorts of answers as to, you know, why 427 - > aren't they behind bars, these guys? 428 - > SPEAKER_01: No, it's fascinating and it's important. 429 - > And you've referenced another friend of the show, Max Smits, 430 - > who's been on uh talking about these issues. 431 - > And I think that clarity does matter because we're going to go 432 - > on shortly to talk about some of their major operations.

433 - > And if you think in each of these cases, when we're talking 434 - > about them, if you think that was directly ordered by the 435 - > Kremlin, then you've got a slightly different set of 436 - > political and security issues than you have if it's just crime 437 - > harbored by the state rather than controlled by it. 438 - > But let's get on to some of these major bits of history. 439 - > Now, I joked earlier about looking at the world differently 440 - > as an ex-civil servant.

441 - > I also originally studied history, and one of the problems 442 - > when you study history is people get all onto the analysis of why 443 - > something happened and what it tells you, but they forget to 444 - > tell you what actually happened in the first place. 445 - > So we do want to get on to the whole point about their leaks 446 - > and this trove that you're looking into and what that tells 447 - > us. 448 - > But let's just try and remind listeners, because for a while, 449 - > I'm gonna say 2019 to 2022.

450 - > I mean, these guys were on the rampage, they were terrorizing 451 - > the world. 452 - > So let's look at some of these. 453 - > So, James, I think you want to start here with one of the hacks 454 - > you're most interested in. 455 - > SPEAKER_02: Oh, yeah, you know, you're right.

456 - > In that time period, there are a lot of examples we could pick. 457 - > We should probably go through two or three. 458 - > We can ask Jeffy's got a favorite. 459 - > But I know one I do want to touch on, because I thought it 460 - > was fascinating.

461 - > Graph or graph, depending on one's pronunciation 462 - > proclivities. 463 - > A famous kind of luxurious jewellery brand for those who, 464 - > you know, may not be customers and so inclined. 465 - > Yeah, I'd never heard of them until you got hacked. 466 - > I think that's why I learned about them too, if I'm honest.

467 - > I was trying to play that cool, like I'm a regular jewelry goer, 468 - > but everyone knows better. 469 - > More like spend money on a fancy keyboard with magnetic switches, 470 - > which I do have a lovely one in front of me. 471 - > Anyway, fascinating attack here, Jeff. 472 - > Yes.

473 - > And I'm interested in this one because, of course, the victims 474 - > were quite high profile, quite interesting data, quite 475 - > interesting ransom dynamics. 476 - > And also there was something about a pretty bizarre kind of 477 - > semi-apology that happened here as well. 478 - > So, what happened back in September 21 here? 479 - > Give us an outline of the attack.

480 - > SPEAKER_00: Yeah, in a way, the Graph Diamonds attack was a 481 - > fairly typical Conte MO. 482 - > You know, they hacked into the organization, scrambled its 483 - > data, stole a bunch of data, and then threatened Graph and said, 484 - > Look, you pay the ransom to decrypt your data. 485 - > But by the way, even if you refuse to do that, we are going 486 - > to leak this incredibly sensitive data. 487 - > And that's gonna be a big problem for you because this is 488 - > private data of your customers.

489 - > So either way, you pay the ransom. 490 - > And they were hitting them up for in the millions, we think 491 - > about seven, seven and a half million. 492 - > It is fair to say that diamond dealers like Graph, you know, 493 - > they have a hugely famous client list. 494 - > I mean, Graph is known around the world and are 495 - > institutionally secretive about that.

496 - > So we interviewed somebody who, you know, she's a diamond 497 - > historian, jewelry historian for the podcast. 498 - > And I, you know, as a sort of warm-up question at the 499 - > beginning, I said, well, go on, who are Graph's famous 500 - > customers? 501 - > You know, get a bit of sparkle and a bit of celebrity. 502 - > And she said, no, I won't name any of them.

503 - > And I said, Well, come on. 504 - > I'm sure some of them have said themselves in the media that 505 - > they're customers of Graph. 506 - > And she said, nope, nope, Graph will not name any of their 507 - > customers. 508 - > You do not get named, that you get a white glove service.

509 - > I mean, they have a side entrance you can go in as a 510 - > celebrity. 511 - > You will never be spotted going into a graph store. 512 - > The staff never talk about who they deal with. 513 - > It is white glove service.

514 - > So the idea that this ransomware gang had a bunch of this data 515 - > was obviously very worrying. 516 - > Graph presumably was playing quite hardball because Conti, 517 - > the ransomware gang, decided they would start leaking some 518 - > snippets of this information to put the squeeze on Graf. 519 - > So they started on their dark web site leaking out snippets of 520 - > information. 521 - > There was a journalist we interviewed.

522 - > He was actually working on a different story, but he came 523 - > across the Conti dark web site and he spotted these details. 524 - > And so he did, uh I think Chap's name is Kevin O'Sullivan, he did 525 - > an article with some Daily Mail journalists about this. 526 - > And they said, you know, this Graf Diamond jewel has been 527 - > hacked and they've started leaking all this information. 528 - > And it was people like Donald Trump and Oakford Winfrey and 529 - > David Beckham, whose details they claim to have.

530 - > And so obviously, for the Daily Mail, this was a you know a 531 - > celeb-heavy story. 532 - > They can put photographs of Bex and Posh in the article and 533 - > Donald Trump. 534 - > The problem with it was, in amongst the leaks of data, there 535 - > was also data about very powerful people, including the 536 - > Saudi royal family. 537 - > Ooh.

538 - > Which we don't think that Conti actually realized they'd leaked 539 - > out. 540 - > I mean, they probably just took a chunk of this data and stuck 541 - > on the internet. 542 - > So then you've got this bizarre situation where it seems that 543 - > obviously the Saudis are very unhappy about this. 544 - > I imagine all the other celebrities are very unhappy 545 - > about it, but we're not sure what happened in the background.

546 - > What the next thing is, is that the Conti gang comes out with an 547 - > apology, an official apology on their dark web page, saying, 548 - > very sorry this has happened. 549 - > The Daily Mail has alerted us to this. 550 - > Thank you to the Daily Mail. 551 - > They credited the Daily Mail and, you know, credited the 552 - > journalists there and said, um, we apologize to the Saudi royal 553 - > family for this.

554 - > And of course, any inconvenience caused, and we will now delete 555 - > their data and take it offline. 556 - > Now, of course, we have access to the leaks from Conti, and we 557 - > know from those leaks they did no such thing. 558 - > They hung on to the data. 559 - > And in a brilliant exchange, one of them says, you know, you can 560 - > potentially blackmail these people in the future.

561 - > And one of them responds and says, Yes, we can shake and 562 - > shake with the shapes. 563 - > So they're gonna hang on to these people's data. 564 - > So it turns out no honor amongst thieves. 565 - > But so you get this weird sort of reverse ferret, as we call it 566 - > in the UK, from Conti, where they delete the data and get it 567 - > back.

568 - > All of this results, of course, in more headlines for Graf, and 569 - > it got worse and worse. 570 - > Interestingly, we're pretty sure that Graf Diamonds paid, and the 571 - > reason we know that is because they had a dispute with their 572 - > insurance company, Traveller's Insurance, because Graf tried to 573 - > claim it seems on their cyber insurance, and the insurer 574 - > refused to pay. 575 - > And it seems there was a settlement out of court, but 576 - > from that we believe the ransom paid was something in the order 577 - > of$7.

5 million. 578 - > Now, just to put that in context, this entire process 579 - > with Graf would have taken, let's say, a couple of months or 580 - > so. 581 - > We worked out how long it would take the average Russian to earn 582 - > $7.5 million, and we came up with a figure about 400 years.

583 - > SPEAKER_02: Pretty good payday. 584 - > SPEAKER_00: So if you're wondering why a ransomware gang 585 - > bothers doing this, in two years you can earn not just all your 586 - > life's money, but all of your family's money for their entire 587 - > lives as well. 588 - > That's a significant incentive, isn't it, to carry out a 589 - > ransomware attack. 590 - > But just an astonishing attack.

591 - > SPEAKER_01: Wow. 592 - > So, I mean, the sheer bizarre nature of that story is just 593 - > extraordinary. 594 - > I mean, British listeners will enjoy the Daily Mail receiving 595 - > an apology from an international crime syndicate. 596 - > Um I don't know where to go with that one.

597 - > But you mentioned to slightly make the tone more serious, 598 - > because we're about to talk about two very serious hacks 599 - > with real-world consequences. 600 - > You mentioned there was no honour amongst thieves. 601 - > They pretended they deleted the data from the Saudi royal 602 - > family. 603 - > They didn't.

604 - > We have proof of that. 605 - > That's a really fascinating and important learning point. 606 - > And Kieran, a good takeaway for CISOs right there, should you be 607 - > faced with that in the future. 608 - > Yeah, we'll we'll come to your damn takeaway at the end.

609 - > Anyway, um But there were more serious examples of the lack of 610 - > honour amongst thieves in terms of the consequences. 611 - > And let me ask you about two. 612 - > One I know very well, uh know both of them fairly well, but 613 - > one I know very well because I was personally involved, which 614 - > is here in England in Redcurrent, Cleveland, local 615 - > authorities. 616 - > In 2019, where they, as far as they're concerned, they just 617 - > hack a local government, but it's some serious consequences.

618 - > And then two years later, the Irish national healthcare 619 - > fiasco. 620 - > So you've got local services, and then you've got a national 621 - > healthcare system, and they're both conte and they're both 622 - > highly disruptive, arguably, possibly not even arguably, 623 - > dangerous. 624 - > SPEAKER_00: Tell us about those. 625 - > Well, yeah, so the Red Car and Cleveland Boer Council attack, 626 - > as you say, Kieran, this is councillor in the northeast of 627 - > England.

628 - > Very small, like a really small sort of local government area. 629 - > Yeah, so not much money. 630 - > Not much money. 631 - > It's a lovely area.

632 - > It's a beautiful area of the world that I have to say. 633 - > But you know, it's not economically massively wealthy 634 - > by any stretch of the imagination. 635 - > And they get hit with ransomware, all their council 636 - > data is scrambled. 637 - > It's fair to say they did the best that they could.

638 - > And obviously, as Kieran, as you say, you were in the National 639 - > Cybersecurity Center at the time and were dispatching people up 640 - > there to sort of work with them to deal with this, but just came 641 - > completely out of the blue at them. 642 - > This was an interesting point because this was sort of in the 643 - > early days of what became the Conti gang. 644 - > So at the time, I don't think we would have regarded that as, in 645 - > quote, a Conti attack.

646 - > It was done by the sort of precursors or predecessors, but 647 - > the people definitely who became Conti, according to the police 648 - > we've spoken to. 649 - > And it just caused pandemonium. 650 - > I mean, services went under. 651 - > We've spoken to people who didn't want to appear in the 652 - > podcast, but they did tell us their story.

653 - > And they have a lot of health issues and a lot of requirements 654 - > to local council. 655 - > And their support from local council just stopped. 656 - > They couldn't get through on the phone. 657 - > All the things they normally relied on, the carers, the 658 - > helpers, all of that.

659 - > It just dried up. 660 - > And they, you know, it's it's not easy being a couple where 661 - > one person's the other's carer. 662 - > SPEAKER_01: Completely. 663 - > SPEAKER_00: They almost broke up.

664 - > It almost split the relationship. 665 - > And had it done that, both of them would have suffered. 666 - > But also the partner who was in very serious health condition, 667 - > God knows where she would have got help. 668 - > That's the consequence.

669 - > It's not just a ransomware attack and data. 670 - > It's a really traumatic period of their lives. 671 - > It really, really messed with them. 672 - > And that's just one fallout from that attack.

673 - > SPEAKER_01: Completely. 674 - > And let me just interject there, abusing sort of host privilege, 675 - > because, as you said, I was head of the National Cybersecurity 676 - > Centre at the time. 677 - > And it was a really interesting and troubling case about the 678 - > human consequences, but also just from an operational point 679 - > of view, how you have to manage risk. 680 - > So another previous guest on the show, Paul Chichester, still the 681 - > director of operations, he came to see me one day in 2019 and 682 - > said, You need to know this.

683 - > I've just sent a team of some of our best instant responders up 684 - > to Red Current Cleveland. 685 - > And I said, What have you done that for? 686 - > I knew there was a major issue. 687 - > But it turned out there were some things that, whilst 688 - > unpleasant were manageable, you know, the website not working, 689 - > leisure centers struggling to stay open and timetable 690 - > confusion and so forth.

691 - > There were the sort of very difficult issues you talked 692 - > about. 693 - > There's some issues about school transfers at age 11, but the big 694 - > one, structurally, was vulnerable children's services, 695 - > where all of the case data was locked out. 696 - > So there were real issues about child safety. 697 - > If somebody, for example, was getting out of prison and there 698 - > was a case file that said, look, you need to have somebody at the 699 - > family home if they have a history of violent offending or 700 - > whatever.

701 - > None of that was happening. 702 - > So for the first and I think only time, we sent a team, a 703 - > pretty large team. 704 - > And as the council leader was good enough to acknowledge in 705 - > public when all this was investigated in Parliament, they 706 - > slept in camp beds in the office and they just worked flat out 707 - > until they got most of it restored. 708 - > So you had to triage what you cared about most.

709 - > But what you've brought out brilliantly there, Jeff, is just 710 - > the horrible human consequences of this, which brings me to the 711 - > fully formed Conti in 2021 in one of their most infamous 712 - > attacks, which also I think brought them into some tension 713 - > with some parts of the wider sort of Russian criminal and 714 - > probably Russian state ecosystem, because it was so 715 - > brazen and so bad. 716 - > And that's obviously the Irish healthcare system.

717 - > Tell us about that. 718 - > SPEAKER_00: Yeah, yes. 719 - > This was 2021. 720 - > And as you say, Conti'd really hit their stride by this stage.

721 - > And it's worth noting that at this point, Conti were certainly 722 - > experimenting with and may have already sort of fully moved 723 - > into, you know, the affiliate model, basically franchising out 724 - > ransomware. 725 - > So the thing with ransomware is the more victims you hit, the 726 - > more money you get. 727 - > So you want to spread it far and wide. 728 - > But the people who develop the ransomware and they write it, 729 - > they're not necessarily the best at spreading it.

730 - > And so they basically created a franchise operation where anyone 731 - > really around the world could sign up as a Conti affiliate, 732 - > get hold of this ransomware, spread it. 733 - > If the victim paid, 80% would go to the affiliate who spread it, 734 - > and 20% would be kicked back to the ransomware gang. 735 - > Which immediately gives you an indication of sort of where the 736 - > power sits, that 80-20 split. 737 - > You know, these affiliates were very powerful people, but it 738 - > also meant that Conti started to lose control centrally of how 739 - > and where its ransomware was being used.

740 - > And there's debates in the leaks actually about this, you know, 741 - > where the boss Stern sometimes doesn't know what's being 742 - > attacked and is surprised by this. 743 - > One of the affiliates, it seems, or one of the members of Conti 744 - > goes after the Ireland's health service executive, which runs 745 - > basically healthcare in the public of Ireland. 746 - > Again, pandemonium, hospital shutdown. 747 - > You realize there's just this rolling network of stuff in 748 - > healthcare that's just constantly in use, blood tests, 749 - > diagnostics, all that kind of stuff.

750 - > And they just get used to it. 751 - > You know, you go in, they don't know really what's wrong with 752 - > you, but they take some blood, they send it off, and then a few 753 - > hours later, and it's amazing this. 754 - > A few hours later they get back full results. 755 - > Brilliant, we know what's wrong with you, and now we can give 756 - > you the treatment.

757 - > As soon as that grinds to a halt, you just get this backlog 758 - > filling up. 759 - > Your ward is then full of people, and you don't really 760 - > know what's wrong with them. 761 - > And I think we have this idea that doctors, you know, take 762 - > your pulse and your temperature and give you some pills to do 763 - > the wrong thing for a person, not knowing what's wrong with 764 - > them, give them the wrong tablet, give them the wrong 765 - > treatment. 766 - > You could kill them.

767 - > Or simply even delay the process, of course. 768 - > And we spoke to one woman who she fought off cancer and she 769 - > was having radiotherapy for her cancer treatment. 770 - > And this radiotherapy was amazing. 771 - > They had to target the radio waves exactly at the right 772 - > coordinates.

773 - > All those coordinates, of course, stored on a computer, 774 - > which was now inaccessible. 775 - > So they had to write the coordinates down by hand. 776 - > You get some of those coordinates wrong, you've just 777 - > zapped the wrong part of this woman's brain, and that's gonna 778 - > cause a huge problem. 779 - > So she was really worried that this might actually affect her 780 - > life.

781 - > Now, in the end, with HSE in Ireland, the hackers did give 782 - > over the decryption key. 783 - > They actually gave over the key and they managed to unscramble a 784 - > bunch of this data. 785 - > But it wasn't as simple, I didn't realize this, it wasn't 786 - > as simple as like plug in the key, yay, everything's unlocked. 787 - > It takes ages and ages, and you've got to do it system by 788 - > system.

789 - > So even when they got the key, and Ireland's HSE didn't pay, 790 - > the ransomware gang gave them it, it still took ages. 791 - > And it's worth saying that part of what we get from the leaks is 792 - > this really interesting discussion around healthcare. 793 - > And do you hit healthcare? 794 - > There is a range of views in Conte about this.

795 - > Some people say we're not gonna do that. 796 - > Some of them, it is a moral outlook, but others it's like we 797 - > don't want to put a target on our backs. 798 - > You attack healthcare during a COVID pandemic, that's gonna get 799 - > us a lot of unwelcome attention. 800 - > But at the other end of the spectrum, there are people who 801 - > quite literally are saying, well, start off, I'm a criminal, 802 - > I'm a crook.

803 - > Of course we don't care about morality. 804 - > And of course, COVID is exactly the right time to hit a hospital 805 - > because that's when they'll pay. 806 - > So there's this range of opinion going on, this debate going on 807 - > there, which I find interesting. 808 - > SPEAKER_01: So just last question on this, because it's 809 - > so interesting.

810 - > Why do you think, or do the messages tell us anything about 811 - > why they handed over the decryptor key? 812 - > Because so there's a background here. 813 - > This is national level fear and anger. 814 - > The Irish state is actually under some pressure, including 815 - > from some parliamentarians, to pay because health services have 816 - > ground to a halt.

817 - > There are all those disastrous human consequences you're 818 - > talking about. 819 - > There is fear about the wholesale breach of medical 820 - > data, secondary issue relative to the disruption, but it still 821 - > matters. 822 - > People think there's going to be a download of their most 823 - > sensitive information available. 824 - > Is it this moral debate?

825 - > Are they feeling the heat from other cyberattackers because 826 - > this is such a big story and they're seen to have gone too 827 - > far even for criminals? 828 - > Is it pressure from the Kremlin? 829 - > Because you know, Putin doesn't need people thinking he's 830 - > launched an attack on a neutral non-NATO country. 831 - > What's going on?

832 - > SPEAKER_00: Yes, it is murky to say the least. 833 - > And there's various things we got told, which we haven't 834 - > managed to substantiate about this for the podcast. 835 - > But there's a few different dynamics in this. 836 - > I think the Conti gang, and this is my sort of opinion, had got 837 - > used to hitting American hospitals, which are private 838 - > companies, effectively.

839 - > And they got used to the idea that you could hit a hospital 840 - > and it was a private company and they would pay a ransom, and 841 - > that does happen. 842 - > We've seen that happen. 843 - > I think they maybe misunderstood what was happening with 844 - > Ireland's HSE. 845 - > I agree.

846 - > And didn't realise, no, this is the entire country's health 847 - > service. 848 - > This isn't just hitting a private hospital. 849 - > There's a bit of that. 850 - > There's also the fact that the Russian embassy in Ireland came 851 - > out with an amazing statement, which we again we put in the 852 - > podcast, sort of condemning this and saying we don't support 853 - > this.

854 - > Now, as I say, I don't think these ransomware gangs are run 855 - > by the Russian government. 856 - > But a lot of them, certainly Conti is accused of being based 857 - > in the Russian Federation. 858 - > They don't want to piss off the government, for want of a better 859 - > word. 860 - > Pardon my French.

861 - > You know, so that clearly helped them, you know, focus their 862 - > minds. 863 - > But also, HSC from the very beginning said, look, we're not 864 - > going to pay the ransom. 865 - > I think in the end the Conti gang went, look, this is just 866 - > not worth it. 867 - > Give them the key, walk away.

868 - > We don't want any of the consequences to this. 869 - > That's my back-of-the-fag packet maths on that. 870 - > But they're not done with governments yet, are they, 871 - > James? 872 - > SPEAKER_02: They are not.

873 - > And hey, I'd like to highlight two things in there. 874 - > It's just fascinating stuff, Jeff, that it's easy to run 875 - > past. 876 - > But you made a remark there that really matters for practitioners 877 - > who may run into future instances of ransomware with 878 - > decryptors. 879 - > You know, cybercriminal gangs don't spend a lot of time 880 - > working on the quality assurance and kind of speed of decryption 881 - > processes.

882 - > Over the years, I've seen lots of examples of decryptors that 883 - > were broken and, you know, essentially turned into 884 - > inadvertent destruction wear as opposed to ransomware if you 885 - > even get your hands on them. 886 - > And I think that really does underline the importance of the 887 - > kind of preparatory processes and the assumption that one 888 - > can't just pay off the criminals to get your data back. 889 - > That's a remark that is, you know, important to highlight to 890 - > our practitioners here and that we can learn from.

891 - > And the other thing I wanted to highlight, you kind of mentioned 892 - > the targeting and what these tools can be used for. 893 - > You know, back, Jeff, when you and I in the dark ages of 894 - > cybercrime first met and there were dinosaurs romping around, 895 - > I'd just run into one of the first examples of a malware 896 - > gang, including an end-user license agreement stipulating 897 - > that you couldn't use their toolkit for law enforcement or 898 - > hospitals because they didn't want the attention.

899 - > And so, you know, it is interesting. 900 - > There is a whole spectrum of appetites and motives here as 901 - > you notion. 902 - > And of course, they're after money, they're commercially 903 - > motivated here, but creating an international political event 904 - > may not be desirable. 905 - > Which of course brings us to the coup de grass here, Costa Rica.

906 - > SPEAKER_03: Yeah. 907 - > SPEAKER_02: So I mean, 30 odd institutions hit back in April 908 - > 22 a declaration of national emergency on the 8th of May 22. 909 - > SPEAKER_00: Tell us about what happened here, because this is 910 - > stunning, isn't it? 911 - > It's fascinating and it occupies a fascinating place in the sort 912 - > of history of the Conti ransomware gang.

913 - > So put this in context, from the chats, we know that late 2021, 914 - > Conti were riding high. 915 - > There's loads of amazing comments on them saying, oh, 916 - > next year, you know, it's gonna be even better if we can keep 917 - > this rate up. 918 - > And they start talking about buying apartments and they start 919 - > talking about how much money they're making. 920 - > They are just absolutely coining it in and delighted with 921 - > themselves.

922 - > February 2022, we obviously get Russia's full-scale invasion of 923 - > Ukraine. 924 - > Off the back of that, we get this amazing moment where Conti 925 - > at first declares support for the what Putin describes as his 926 - > special operation and then reverses and says, no, we didn't 927 - > mean to say that. 928 - > But in the interim, the Ukrainian side of the Conti 929 - > gang, because it had members in Ukraine, were completely 930 - > incensed by that. 931 - > And you see in the chats, actually the leak chats, you see 932 - > this sort of back and forth between people supporting Russia 933 - > and people supporting Ukraine.

934 - > Off the back of that, someone in the gang decides they're gonna 935 - > leak Conti's entire chat log. 936 - > Every message the gang sent to each other, every second of 937 - > every day for the last something like two and a half years, 938 - > 350,000 messages spill out. 939 - > As you can imagine, it's caused pandemonium in the gang. 940 - > They were already facing stress.

941 - > The boss of the gang, Stern, this character we talked about 942 - > earlier, had basically gone A-WOL by this point. 943 - > Nobody really knew where he was. 944 - > The gang was fracturing, and this was kind of the final nail 945 - > in the coffee. 946 - > They decided they would disband and they would just go their 947 - > separate ways.

948 - > But then we get this so Swan Song attack, if you like, 949 - > attributed to Conti, the attack on Costa Rica. 950 - > Absolutely astonishing. 951 - > I mean, took down multiple entities in the Costa Rican 952 - > government. 953 - > And the Costa Ricans we've spoken to believed that Conti 954 - > was hitting them and responding in real time to what they were 955 - > doing.

956 - > So when they went on TV to talk about the attack, Conti would 957 - > time their next bit of the attack for that TV appearance, 958 - > for example. 959 - > It became a bit of a pylon. 960 - > There were other gangs. 961 - > I think Hive was one of the other gangs attacking Costa 962 - > Rica.

963 - > And so you get this pylon attack that happens. 964 - > The country really suffered. 965 - > I mean, you're talking millions and millions of dollars of cost. 966 - > Import export was one of the things that really got hit in 967 - > Costa Rica, and it makes a lot of its money by import-export.

968 - > That stuff got absolutely hit. 969 - > Ports, you know, forced back to using paper and pen, customs 970 - > declarations having to be done on paper. 971 - > It really cost the country. 972 - > And what's really sad about that is obviously Costa Rica's, it's 973 - > a small country, it's not very rich country, it's a long way 974 - > away.

975 - > A lot of people don't know even where it is on a map. 976 - > The Costa Ricans we've spoken to believe it was used as a test 977 - > case. 978 - > And I think that really got to me because it's like your 979 - > country, it can be sort of pushed around a bit, you know, 980 - > just to prove what we can do and test what we can do. 981 - > Now, in terms of what Conti's motivation for doing this and 982 - > how this feeds into the story, we don't know.

983 - > Because we don't have access to the leaks at this point, because 984 - > the leaks only go up to when they were leaks, you know, 20, 985 - > 22, February, we don't really know what happened here. 986 - > Was this Conti trying to get back on its feet? 987 - > You know, was this Conti doing one long last operation to sort 988 - > of, you know, mic drop, walk away? 989 - > Was this a rogue affiliate who did this?

990 - > Was this somebody within Conti who was trying to market Conti's 991 - > ability as a sort of nation-state weapon? 992 - > To say, look, you know us for ransomware for profit, but look 993 - > what we can do to a country, you know. 994 - > Anybody fancy buying this? 995 - > We don't really know.

996 - > There's lots of different explanations possible for it. 997 - > And again, Max Meets, you know, who wrote Ransom Wars, has 998 - > talked about this, about the possible explanations in it. 999 - > I do find it fascinating, but fundamentally for the Costa 1000 - > Ricans, they declared a state of emergency and it cost them so 1001 - > much money to fix this. 1002 - > Again, they refused to pay.

1003 - > They were not going to pay in the end. 1004 - > SPEAKER_01: Yeah, it's something like 2% of GDP. 1005 - > It's an extraordinary figure. 1006 - > And it's quite a death rattle for the Conti group.

1007 - > I hadn't realized the leaks were before that and it was already 1008 - > on its last legs. 1009 - > So just a quick question, Jeff. 1010 - > Do you we know what's happened to some of these key people, the 1011 - > operators in Conti Group? 1012 - > Are they reforming?

1013 - > Do they have a new badge? 1014 - > Are they living quiet retirements and luxury in some 1015 - > of those nice areas of southern Russia, not so nice at the 1016 - > moment, but you know what I mean? 1017 - > SPEAKER_00: Very good question, yeah. 1018 - > In the final tail end of the leaks, there's always discussion 1019 - > about parts of the gang reforming.

1020 - > There's a member of the gang called Fire who posts this very 1021 - > sort of heart-wending sort of final post and says, you know, 1022 - > we shall meet again. 1023 - > We know that our operation will rise again. 1024 - > So we know there's the aspiration there. 1025 - > Certainly, the members of the gang who were affiliates who are 1026 - > using Conti's ransomware to go and spread it, some of them 1027 - > would inevitably have just joined the next ransomware gang 1028 - > to come along, you know, because all these ransomware gangs are 1029 - > constantly, you know, seeking new affiliates, new and 1030 - > experienced affiliates.

1031 - > So some of them would have moved on. 1032 - > In terms of the people at the heart of the gang, subsequent to 1033 - > the uh Costa Rica attack, we had this remarkable moment where in 1034 - > the end it was the German authorities, the BKA, who outed 1035 - > and named the person they believe is the true identity of 1036 - > Stern, the boss of Conti, this enigmatic character. 1037 - > They claimed he's a guy called Vitaly Kovalev, who's a Russian 1038 - > living in the Russian Federation.

1039 - > They released a photograph of him, a couple of photographs, 1040 - > but there wasn't really much to go on. 1041 - > And obviously, as a journalist, an investigative journalist, I 1042 - > like to see these people. 1043 - > I wanted to understand more about them. 1044 - > I want to sort of, you know, hear from them ideally.

1045 - > And in a remarkable turn of events, there was a telegram 1046 - > account that got set up that was claiming to leak details of the 1047 - > Conti gang, you know, their real identities, etc. 1048 - > Somebody replied to that telegram account with a 1049 - > photograph that appeared to show this man, Vitaly Kovalev, 1050 - > accused of running the Conti gang. 1051 - > And what that led us to was a whole bunch of social media 1052 - > videos with thousands of followers.

1053 - > There's somebody Kovalev's connected to who's quite a big 1054 - > wheel on the internet and actually quite a star, like an 1055 - > internet star. 1056 - > Wow. 1057 - > These videos have thousands of views. 1058 - > And I thought, well, I'll watch all these videos, but I'm pretty 1059 - > sure, I mean, you know, Vitali Kovlev would run a mile from 1060 - > this.

1061 - > He's one of the world's most wanted cyber criminals. 1062 - > Oh no, he's there in the background, waving away, bopping 1063 - > around, dancing. 1064 - > We see him on holiday. 1065 - > We've managed to identify the resort he went to on holiday, 1066 - > and it's sort of a$25,000 a week resort somewhere in southern 1067 - > Russia.

1068 - > So he is still apparently living at large and having a good life. 1069 - > SPEAKER_02: And Jeff, if I'm not mistaken, I he was sanctioned by 1070 - > the US and the UK, but to this date, not arrested, I don't 1071 - > think. 1072 - > SPEAKER_00: Correct. 1073 - > Yes, he's been sanctioned.

1074 - > He was also charged with what he's accused by the US of doing 1075 - > in terms of money laundering way back in 2010. 1076 - > So he's been charged and also sanctioned. 1077 - > We will obviously be as part of the podcast reaching out to him 1078 - > for comment on this, and we sort of welcome his input. 1079 - > Welcome his contribution, yes.

1080 - > SPEAKER_02: Good luck. 1081 - > So if he's listening to the show now, consider that an 1082 - > invitation. 1083 - > Jeff, I do have to say as well, my little bit of background 1084 - > research on this, which will pale in comparison to yours, it 1085 - > is fascinating when you look him up as a character and how he's 1086 - > covered on the Russian side in local language. 1087 - > I mean, he really is presented as an engineer.

1088 - > His certifications are on show, he's a stable system builder, 1089 - > you know, not a cyber criminal, he's kind of portrayed as a bit 1090 - > of an internet genius with connections to influence. 1091 - > It's just fascinating and not what you expect at all, is it? 1092 - > SPEAKER_00: No, absolutely not. 1093 - > And I'm a bit conflicted about this because obviously, having 1094 - > watched, you know, videos in which he appears and sort of 1095 - > heard a little bit of him, it's disconcerting the disconnect 1096 - > between what he's accused of doing, which was a campaign 1097 - > which, you know, as we talked about, threatened in the end 1098 - > people's lives with targeting healthcare.

1099 - > You know, the extent to which he knew that or not, we don't know, 1100 - > but the gang he was accused of running certainly did. 1101 - > But as I look at him, he's just got this very benign face. 1102 - > In the podcast, I describe it as if your car broke down and you 1103 - > were looking around for someone to give you a push, you probably 1104 - > think, oh, he he'd probably help out. 1105 - > It's really difficult to reconcile his demeanor with what 1106 - > he's accused of doing.

1107 - > And perhaps in his own head, he was just a business person. 1108 - > If the accusations against him are correct, maybe he thought, 1109 - > well, Conti was just a business that I ran. 1110 - > SPEAKER_02: Maybe that's how he feels. 1111 - > I don't know.

1112 - > Fascinating, isn't it? 1113 - > Fascinating. 1114 - > And, you know, Jeff, I know that um over years of tracking cyber 1115 - > criminal gangs a bit differently to you. 1116 - > As I say, I do tend to focus on the malware and the data and the 1117 - > attacks and exploits versus the humans.

1118 - > And, you know, you and I talked on the last podcast where you 1119 - > joined us about how we could meet in the middle and you could 1120 - > learn a lot from following the money and thinking beyond the 1121 - > technical parts of it. 1122 - > And it does seem like this gang has dissipated off into other 1123 - > places. 1124 - > And the rumors are some of these folks ended up in kind of Black 1125 - > Bastard, Royal Black, you know, these kind of other follow-on 1126 - > gangs.

1127 - > And that will be hard for us to ever truly know. 1128 - > But I suppose I'd love to give you this opportunity, you know, 1129 - > having now researched all of this for so many years and 1130 - > learned about these different gangs and these individuals, you 1131 - > know, when you look at the leaks you've been pouring through the 1132 - > 47,000 odd messages so far, what do you think overall it tells us 1133 - > about cybercrime? 1134 - > What are your kind of two or three macro conclusions from 1135 - > seeing the inside of the operation in a relatively unique 1136 - > way?

1137 - > SPEAKER_00: Uh the thing that's really come across to me is I've 1138 - > got this theory that these people are bright. 1139 - > You know, you can't do this stuff if you're thick. 1140 - > They're not like hitting people over the head with a hammer. 1141 - > They are, you know, developing computer code, they're extremely 1142 - > smart at what they do.

1143 - > I think if you're a smart person, it's quite difficult to 1144 - > wake up in the morning and extort people. 1145 - > Ransomware is a crime of extortion. 1146 - > You have to threaten your victim, intimidate them, and 1147 - > force them to pay. 1148 - > I don't think many intelligent people wake up in the morning 1149 - > comfortable with doing that, you know?

1150 - > I think what their brain needs is a different way of framing 1151 - > this. 1152 - > You've got to have some psychological lens through which 1153 - > to see it, which makes it okay. 1154 - > And so I think the lens that Conte's members use, and from 1155 - > the chats, this comes to for me loud and clear, is this is a 1156 - > business. 1157 - > We are not attacking a victim, we are in competition with our 1158 - > victim.

1159 - > And you see that in terms of them describing themselves as 1160 - > post-paid penetration testers. 1161 - > You know, the idea that you would normally pay for a 1162 - > penetration test to expose your vulnerabilities. 1163 - > Well, we've done one of those tests, we just didn't tell you 1164 - > we were doing it, and you failed, so now you have to pay 1165 - > us after we've done the test. 1166 - > What they regard this as is not attackers attacking victims.

1167 - > What they regard this as is a competition between two 1168 - > businesses. 1169 - > There's the business that's defending, and there's Conti 1170 - > with its ransomware that's in competition. 1171 - > And when you're ransomed, when you're data encrypted and 1172 - > exfiltrated, you lost the competition. 1173 - > And like in any competitive state, you pay for that.

1174 - > You pay a money amount. 1175 - > I talk about the crime triangle where you have, you know, 1176 - > villains and victims and heroes, you know, the three things you 1177 - > need for crime, really. 1178 - > I just don't think they see the world like that. 1179 - > They see this as just competitors.

1180 - > They're competing between themselves as ransomware gangs. 1181 - > Their victims are competing with them, and they're heroes. 1182 - > I don't think they see the heroes, the FBI and the likes of 1183 - > Sands Institute and stuff as heroic. 1184 - > I think they see them just as competition.

1185 - > This is a state of nature. 1186 - > These people are brought up in a state of nature, and in a state 1187 - > of nature, the person with the biggest fists wins. 1188 - > That's just how it is. 1189 - > It's not criminality, it's just business.

1190 - > I think that's how they see it. 1191 - > And so I think for the defenders, you know, if you're 1192 - > talking to your business in terms of, oh, we need to defend 1193 - > against these attackers, I'm not sure that's the right way to 1194 - > explain it. 1195 - > I think you have to say to your bosses, you realize we have 1196 - > competition out there with these ransomware gangs. 1197 - > This is a hostile takeover.

1198 - > If we don't get it right, we are going to lose this business 1199 - > competition. 1200 - > In the same way you fund your business to be more competitive, 1201 - > you are funding your business in cybersecurity to compete against 1202 - > the ransomware gangs who are competing against you. 1203 - > I don't know where that reframing helps, but that's 1204 - > certainly what I think. 1205 - > SPEAKER_01: Well, it absolutely helps because I want to build on 1206 - > it and ask you, let's take the Conte of 2021 in its pump, 1207 - > causing havoc around the world.

1208 - > There's horrible cases we've talked about. 1209 - > If it were to regroup today, do you think we'd be any better 1210 - > prepared for it? 1211 - > SPEAKER_00: It's a very good question. 1212 - > Oh, Kieran, brutal.

1213 - > One thing that's useful about the big attacks we saw last year 1214 - > on UK high street businesses and also Jaguar Land Rover was it 1215 - > did raise the stakes with this. 1216 - > You know, my mum, for example. 1217 - > Actually, my mum had heard of ransomware before because she's, 1218 - > you know, listened to all my output and read all my books, 1219 - > what you do as a mum. 1220 - > But, you know, lots of mums and dads around the world, around 1221 - > the country in the UK, suddenly heard of ransomware and 1222 - > understood it was a thing.

1223 - > So for a start, there's understanding in communities, 1224 - > there's understanding amongst employees, and also businesses 1225 - > can use that to say, look, we don't want to go there. 1226 - > How do we not become the next Mark Suspensers or co-op or 1227 - > whatever? 1228 - > So I think there is learning there. 1229 - > My worry is attention spans are short.

1230 - > There's lots of pressures in other ways, there's economic 1231 - > pressures in the UK at the moment. 1232 - > It's not just learning the lessons, it's applying them, 1233 - > applying them long term. 1234 - > And so I would argue, yes, we've probably a bit better prepared 1235 - > than we were back in 2020, 21. 1236 - > But it's maintaining that and improving it, I think that's 1237 - > important.

1238 - > SPEAKER_01: Really helpful. 1239 - > Thank you. 1240 - > Well, look, we have kept you far too long because that was just 1241 - > so interesting. 1242 - > But that is all we have time for.

1243 - > SPEAKER_02: Thank you so my words. 1244 - > Sorry, Professor Martin, what about my 30-second takeaway? 1245 - > SPEAKER_01: James, look, this is a new format. 1246 - > It's a really, really cool deep dive into the history and 1247 - > lessons from a major cyber criminal group.

1248 - > Your takeaway, it just doesn't fit anywhere. 1249 - > I mean, what are you gonna ask Jeff to say? 1250 - > Like supposed to takeaway. 1251 - > Cyber criminals are bad.

1252 - > Don't hack hospitals, kids. 1253 - > That does sound like a good takeaway, Franklin, probably a t 1254 - > shirt. 1255 - > SPEAKER_02: But uh, for the audience, just for visual 1256 - > clarity, seeing as you can't see, I now have tears in my 1257 - > eyes. 1258 - > Kieran, I I've got to have my takeaway.

1259 - > We've got to help security leaders with something tangible. 1260 - > SPEAKER_01: Aside from being fascinated, obviously. 1261 - > For goodness sake. 1262 - > Well, you are the boss.

1263 - > Okay, can you figure out a way of shoe hooking? 1264 - > I've got an idea. 1265 - > SPEAKER_02: Okay. 1266 - > It might be good.

1267 - > So, Jeff, as you know, I do want our listeners in the 1268 - > cybersecurity profession to have something that they can learn 1269 - > from this, aside from just being hugely entertained. 1270 - > I mean, you've shared lots of fascinating facts. 1271 - > So, how about this? 1272 - > In 30 seconds or so, have a go at completing this kind of 1273 - > opening statement.

1274 - > I'll lead you in and see what you can come up with. 1275 - > The Conti group showed us that we have to be better at dealing 1276 - > with cyber criminals in the following ways. 1277 - > Can you do something with that? 1278 - > SPEAKER_00: Give it a go.

1279 - > Yeah. 1280 - > Yeah. 1281 - > What are the lessons? 1282 - > The lessons are out there in the world right now, there is a 1283 - > Conti gang or an equivalent who are surveilling your business.

1284 - > It's happening right now to your business. 1285 - > They are looking over your business and they are working 1286 - > out who you are, how much you're worth, and how they get in. 1287 - > So understand that for a start. 1288 - > And they're going around industry by industry.

1289 - > You know, this week it's transport, next week it's 1290 - > pharmaceutical, next week it might be agriculture. 1291 - > So your chances of not getting on their radar are slimming 1292 - > down. 1293 - > So for a start, in the same way that, you know, working out how 1294 - > vulnerable your flat is to being broken into, the best way is to 1295 - > break into it. 1296 - > Start looking at yourselves as a target.

1297 - > If you're not doing it already, how are you vulnerable? 1298 - > What's your public exposure like? 1299 - > How much is out there about you? 1300 - > And, and I think this is what organizations really struggle 1301 - > with, what are the weak bits?

1302 - > And the difficulty with that, approaching that from an IT 1303 - > department point of view is the IT department will always look 1304 - > at the technical weaknesses. 1305 - > That's not what people like Conti look at. 1306 - > They look across the organization. 1307 - > They look at the bits that don't think they're going to attack.

1308 - > You know, somebody in HR or payroll or something that just 1309 - > doesn't think they're a target. 1310 - > So again, looking across your organization, understanding the 1311 - > linkages between bits of the organization, understanding 1312 - > what's valuable and where it is, and understanding who controls 1313 - > that valuable stuff. 1314 - > And taking all your premises and all your prejudices away and 1315 - > really looking at your business. 1316 - > What do we do?

1317 - > What's valuable? 1318 - > Who controls it? 1319 - > That's a good place to start. 1320 - > Because that's what Conti will be doing to you.

1321 - > That's the surveillance exactly the Conti gang uh successes will 1322 - > be doing to you. 1323 - > SPEAKER_01: That was annoyingly excellent, Jeff, because you've 1324 - > defeated my attempts to abolish James's takeaway because you did 1325 - > far too good a job. 1326 - > So, uh Jeff White, thank you so much for coming back on the 1327 - > show. 1328 - > And when is this excellent new series out?

1329 - > We are looking at the 6th of July for broadcast for series 1330 - > four of CyberHack. 1331 - > SPEAKER_02: Excellent, thank you. 1332 - > There you go, folks. 1333 - > Well, Jeff, thank you again.

1334 - > Not just for coming and you know tolerating Kieran and I for a 1335 - > second time. 1336 - > You really are a glutton for punishment, but for the work 1337 - > that you do. 1338 - > You know, I've known you a long time now, and these deep dives 1339 - > into cybercrime, I think, really do offer unique perspective to 1340 - > those of us that bury our heads in code. 1341 - > And I think it's not only fascinating, but incredibly 1342 - > helpful.

1343 - > And a good reminder of why this work matters, the kind of life 1344 - > and limb impact that can come from it. 1345 - > So a personal thanks for your persistence and mastering of 1346 - > Russian where appropriate to read messages, including Russian 1347 - > slang. 1348 - > Oh, thank you. 1349 - > And with that, I think that is all we've got time for today.

1350 - > But again, of course, if you're fascinated in this topic, you 1351 - > can always pick up Jeff's upcoming podcast series. 1352 - > SPEAKER_01: So thank you very much, everyone, for listening. 1353 - > Thank you for listening. 1354 - > Thank you, Jeff.

1355 - > To listeners, do leave us a rating wherever you got this 1356 - > podcast. 1357 - > People who understand modern communications technology tell 1358 - > us that that sort of activity helps, especially if it's a nice 1359 - > rating. 1360 - > And if you have any suggestions or follow-ups on our show, email 1361 - > us at cyberleaderspodcast at sans.org.

1362 - > That's it. 1363 - > And again, thank you everyone for listening. 1364 - > Thank you for listening and keep cybering. 1365 - > SPEAKER_02: From me, Kieran Martin, and me, James Lyne.

1366 - > It's goodbye. 1367 - > And friends, don't let friends use hackerly put together 1368 - > decryptors from cyber criminal gangs.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Following the Money: Cybercrime & Money Laundering Exposed, with Geoff WhiteThe Cyber Insider · features Geoff White70 / 100
  • Ransomware Sanctions, OFAC, and the Lazarus Group: A Real Case StudyThe Backup Wrap-Up · on Lazarus Group88 / 100
  • Cyber is a business problem that needs a business partnerCult Products · on National Cybersecurity Center83 / 100
  • 401 Access Denied Podcast Ep. 120 | Bridging Borders: How INTERPOL Tackles Cybercrime Worldwide with Craig Jones401 Access Denied · on UK National Crime Agency82 / 100

More from Cyber Leaders

All episodes →
  • Defending with the Same AI That’s Coming for You with Chris Cochran80 / 100
  • She Convinced the Pentagon to Let Hackers In. Legally. With Katie Moussouris92 / 100
  • Still Getting Cloud Wrong. Here’s what to Fix. With Simon Vernon89 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin Jones88 / 100
  • Your CISO is Now Your Chief Trust Officer with Jitender Arora82 / 100
Explore the best B2B Ops podcasts →
All Cyber Leaders episodes →