
onSecurity · 2024-01-11 · 30 min
Key moments - from our scoring
Substance score
51 / 100
Five dimensions, 20 points each
Digital Mint operates as a bridge between ransomware victims and threat actors, leveraging cryptocurrency infrastructure and compliance expertise built around understanding illicit crypto flows. Mark Rent explains how ransomware has become a profit-driven business rather than a nation-state operation, with major variants like Lockbit, BlackCat, and Alphv operating affiliate models similar to franchises. The conversation reveals surprising nuances: threat actors enforce internal rules to maintain reputation, insurance companies have evolved to support claims rather than deny them, and negotiations sometimes hinge on personal blackmail rather than pure ransom amounts. Rent discusses the economics of ransomware as a service, where affiliates operate under strict rules enforced by variant leadership, facing consequences like license revocation for poor service delivery. The episode also covers how incident responders navigate OFAC sanctions, business interruption loss modeling, and Digital Mint's role as a regulated money services business coordinating with law enforcement and government entities.
Major variants operate franchise models where affiliates must follow strict protocols for obtaining decryptors and distributing payments. Leadership bans non-compliant affiliates to protect brand reputation and ensure victims continue paying, since word spreads through the incident response community when promises aren't kept.
Yes, one case involved a hacker returning a few hundred thousand dollars to a nonprofit after learning about the organization's mission, recognizing they had moral objections to targeting that type of company, demonstrating that even criminals have selective values.
Insurance carriers have become more supportive than expected, adding forensics teams and threat actor negotiators to their staffs and focusing on thorough due diligence for policy sustainability rather than seeking reasons to deny claims.
Threat actors exfiltrate and analyze personal data mixed with business files, using threats to expose marital affairs or compromising information about key employees to their spouses to force victims into paying after initial refusals.
Yes, as a registered money services business, Digital Mint performs due diligence on every transaction to ensure wallet addresses and threat actor groups aren't OFAC-sanctioned entities and coordinates with government and law enforcement on compliance.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains genuinely useful practitioner insights about ransomware affiliate economics, threat actor honour norms, and personal-data leverage tactics, but these are spread thin across significant rambling, sponsor shout-outs, and platitudes about 'doing the right thing.' The signal-to-noise ratio is low for a 30-minute runtime.
the bitcoin actually rose in price. So the...nonprofit organization who was uninsured at the time, ended up getting a profit out of this
a lot of the rules within these variants, you know, lockbit Alpha black hat...if you're not following the rules, um, within the community they know that folks are going to complain to the leaders
The Taco Bell franchise analogy for ransomware affiliate models and the marital-affairs-as-leverage story are genuinely fresh illustrations, but the underlying thesis - ransomware is financially motivated, threat actors operate like businesses - is well-worn in cybersecurity circles and is not argued from first principles.
I operate Taco Bell and I the franchisor. I want to allow others to be franchisees
there was information in the data leaked...showing marital affairs. And the threat actor was using that to threaten
Mark Rent is a genuine operating practitioner - nine years building a compliance-first Bitcoin payment rail specifically for ransomware incidents - with real back-channel intelligence relationships and regulatory exposure; he is not a thought-leader tourist, though his breadth of strategic insight is limited to his specific niche.
we founded a cash to crypto, uh, money service business operation about nine years ago
we have back channel relationships that that's what makes them valuable, that they know the right people in the dark web
The episode names real entities - Chainalysis, TRM Labs, Elliptic, Merkel Science, LockBit, Conti, the Garantex/Hydra takedowns, Mondelez vs Zurich - and gives rough numbers (10/20/80 affiliate splits), but dollar figures are vague ('a few hundred thousand'), timelines are imprecise, and the Garantex geographic attribution appears garbled, undermining confidence in the data.
you keep 10% or whatever, you keep 20 and then give 80 to the house
groups like Chainalysis, TRM Labs, Elliptic Big, these blockchain forensics companies
The host occasionally surfaces useful follow-up angles - insurance resistance, nation-state safe-harbour pressure, the Mondelez precedent - but questions are consistently loosely phrased, loaded with filler, and almost never push back on or quantify the guest's claims; the episode closes with overt cheerleading rather than synthesis.
Well, what kind of resistance are you seeing if any from insurance are there: Like, let's try to find ways to not pay it
Is there, is there heat, uh, because of optics from their nation state
Computed from the transcript - who did the talking, and the words that came up most.
As the tactics of hackers and threat actors evolve, organizations are finding themselves in unknown, uncomfortable, and unsafe situations. When it becomes necessary to engage or negotiate with hackers, experts can offer their experience and resources to ensure the most positive outcome possible. In this episode of onSecurity, Stel is joined by Marc Grens, Co-Founder and President of DigitalMint. Marc goes into the often unknown details about how companies engage with ransomware attackers and shares some surprising experiences.
Transcribed and scored by The B2B Podcast Index.
Speaker A: The On Security podcast aims to inform and challenge the viewer on all things cybersecurity. Our sponsor, Onshore Security, is a premier provider of full telemetry, cybersecurity detection via its Panoptic cyber defense service and managed security solutions. Hi again everybody, Stell Valavanis from Onshore Security. Here for the next episode of On Security podcast we've got uh, Josh Eckler producing. Hi folks. Thank you Josh. You're awesome Josh. And um, always. And then of course you know, uh, a great guest that I've known for a while. We've played around in the investor circles and in uh, the web three circles and you know, Mark, serial entrepreneur whatnot. So let me just go ahead and introduce you Mark Rent from Digital Mint and he'll tell you a little bit about himself.
Speaker B: Sure. Thanks Stell. Great to catch up as always and I appreciate being on the show. Um, I am a co founder, president of Digital Mint. I uh, have a background in the capital markets as uh, Stell said. I was an active angel investor about 10, 15 years ago in the Chicago scene and learned about this cute little thing called bitcoin, uh, about 11 years ago and saw this system and this protocol as a way to disrupt the settlement and payment system. Uh, so we founded a cash to crypto, uh, money service business operation about nine years ago. And one thing we decided to do differently that a lot of the other cash to crypto operators and instead of kind of turning a sort of quote unquote blind eye to who's actually using it, we decided we really wanted to understand who is using crypto. The good, the bad and the ugly, to understand you know, the, the why and you know, whether. Fortunately, unfortunately we learned pretty quickly that uh, you know, crypto and bitcoin, you know, being an unregulated, especially in the early days, the black markets took a uh, real strong you know, liking uh, to Bitcoin amongst some of the other early protocols. Uh, so we decided to learn about that and we decided to create you know, a compliance first organization to study and understand that and try to defect it and report and communicate to our country and our states and regulatory law enforcement. Um, so what that end up uh, sort of parlaying our infrastructure into um, is building sort of a 10 lane highway for uh, settling the highest risk of the highest risk, uh, transactions is that during a ransomware incident. So when a company is hit by the hacker, uh, and they're holding their systems hostage where they need to buy decryptors to get their systems back up and running or they have to pay for data suppression. Uh, Bitcoin became the preferred choice. Uh, and we were sort of asked to build out the infrastructure and leverage our compliance to be able to support that. So I, uh, assume that's what uh, sell is going to want me to talk about, uh, in some fun stories. Take it back to you. Yeah.
Speaker A: Bitcoin on demand. Right, I know. Um, and I mean, I mean, look, let's face it, it, it sucks that this is among the things we have to do, like why we can't have nice things kind of stuff. But it, but, but you know, that's reality. Um, you know, my whole business, cyber security, is responding to criminals. I mean, it's just, that's just the way it is. So. Okay, but that said, you, you know, that we need to face that reality. Uh, and I have to say, you know, some of it's very telling and very informative and has caused us to operate a lot tighter and smarter and whatnot. So I'm not taking the reaction to it kind of all bad. And you have built a business now, in addition to, you know, the, the bitcoin, you know, ATMs now having that, you know, bitcoin on demand, um, to be able to mitigate against you know, the, hopefully, you know, manage this, you know, this crime. So, but I, I have to admit, I do want to know the stories. I do think there's a lot of nuance and I think that everybody benefits from seeing that and it is kind of, you know, interesting. Uh, so what's your best. Give me your, like, weirdest, like, wow, I didn't think this was like that, or here's a big deal.
Speaker B: Yeah, I, So again, just thinking off the top of my head, it's something that pops in my mind is probably four years ago, um, after we've had, you know, regular cadence within supporting the incident response industry, we've come to realize, you know, and with all the experts in this space that the hackers are, they're not really in the business and all the affiliates that support all the different ransomware variants out there, they're not really in this game because they're trying to really, um, sponsor some nation state to really try to burn down the western world where they maybe used to be 10 plus years ago, they're in this to make money. And the reality is that whether it's good, bad or ugly, with the invention and the establishment and the infrastructure of markets in bitcoin and crypto, they made a lot easier for them to get paid to be able to settle and with a, uh, you know, very low likelihood of them getting caught and. Or those funds seized. So that birth of it, you know, made it a lot easier for them to do that. So we came to realize, you know, also with our threat actor intelligence and communications team, that this is a business for them, and it's for our job to negotiate as, uh, sort of from an economics, game theory standpoint. So about four years ago, you know, sort of knowing that and having that infrastructure and knowledge, um, that there was an organization that was a nonprofit, you know, that got, uh, hit, I think it was a few hundred thousand dollars payment went, um, through the usual protocol, usual communications with the threat actor. Payment was made to the hacker. They gave them the decryptors back. They promised not to delete. They showed, you know, proof of deletion on the mega sites. And within about two, three days later, uh, the incident response firm came back to us and said, um, hey, Mark, can you provide us with, uh, a bitcoin wallet address? And I said, why? He's like, uh. The threat actor decided they had a change of heart. They learned more about the company and realized they were doing good things, and they decided to give all the money back. So we re. We had funds returned back to us from the hacker and this. And turns out the bitcoin actually rose in price. So the, The. The nonprofit organization who was uninsured at the time, ended up getting a profit out of this because of the change in price? No. So, I mean, it's a rare event, but it's. It's interesting just to think about that, you know. You know, there. There are these hacker criminal organizations, you know, that have some sort of honor and, you know, also probably to the testament that they're making a lot of money anyway, a few hundred thousand dollars. Then they decide to say, this is not the type of company I want to hack. You know, I feel like I want to give it back because they're doing something that maybe I believe in.
Speaker A: I mean, do you think they're. They're. They're. I mean, you have some. Inside these organizations, there might be some kind of thing, like, let's say they have to recruit people too, just like we do. They have to keep good employees, and they have to show that we're on a, you know, their mission is, you know, a good mission, that we're doing whatever. Do you think they're. That. That something like that might.
Speaker B: Absolutely. I mean, at the end of the day, they're. They're people, humans like us. They're driven on very similar incentives. They're very tribal in the same way. So they do. They have infrastructure, they have employees, they train, they teach. When some of these affiliates or, you know, hubs of major variants that want to expand. So that could have been something that said, hey, we don't want to be in the business. We want to take money off pure capitalist organizations, maybe not nonprofit. And a lot of times they don't know who they hit. They may hit someone. And, you know, they're just fishing. They're constantly fishing, and they're throwing out thousands of different cast lines and they don't know always that they hit. You know, and don't get me wrong, they're criminals. They're not. I'm not saying, um, just this is the first story. I'm, I'm stating it happens to be good to the top of my head.
Speaker A: But no, it's good because it's completely a twist. It's like completely like you. This is. I want the stories that are unexpected. You, you know, uh, what are the pressures? Do they have. I'm really curious about this. Are there like, optics that they think they have to be concerned about to the world or to a smaller community, the criminal community? I mean, you know, what, what, you know, what are the pressure pressures?
Speaker B: I. I think, uh, just tying into today's environment with ransomware variants. I think over the last 12 to six months, what we've seen in our intelligence shows that there are way more affiliates to ransomware variants than we've ever seen. So just to take a step back, what that means is I operate Taco Bell and I the franchisor. I want to allow others to be franchisees. So a lot of them have opened up their, their playbook and says, if you want to be a franchisee or an affiliate of mine, you got to follow these rules. You got to follow this process. Here's sort of discount, you know, process you can go. Here's how you get paid. You have to follow this. Here's how you obtain the decryptor, and after you receive payment, here's how you go. And basically your buy it, you keep 10% or whatever, you keep 20 and then give 80 to the house or vice versa or whatever the model is. So what's up happening is now you have an insane number of new sort of hackers who are affiliates to these ransomware groups behind the keyboard all over the world. So what the pressure for them is that, you know, a lot of the rules within these variants, you know, lockbit Alpha black hat. You know, two examples that if you're not following the rules, um, within the community they know that folks are going to complain to the leaders. You know, it's well known that all the major DFIRs have back channel relationships that that's what makes them valuable, that they know the right people in the dark web to go and they can talk to you if an affiliate is not doing a good job and they'll listen to them and at times they'll get banned or blocked and removed and says I'm can't, I'm revoking your license to be able to operate under because you're not following the rules, you're giving us a bad name and a bad brand. And that's really important to these major uh, variants that are out there because again if things are not going right, people are not getting their decryptor keys and these affiliates are not able to deliver on their promise, then it hurts their brand and then people want to stop paying. Once you probably hit some tipping point and the word gets out within our community and the instrument response, we all talk to each other, we'll stop saying stop paying blackheads, stop paying black boss, uh, stop paying Lockpit 3.0 affiliates. And that's not what the groups want. So they'll be proactive. So that's what really I think is concerned concerning, is not always knowing who's behind the keyboard and what experience they have. And it's our job to determine the good faith, again, you know, honor among thieves, that if you make the payment in Bitcoin which is irreversible, that they're going to make good on their promise by delivering on it. And that forces us to do more due diligence to get to that, you know, 99% confidence interval that they can deliver.
Speaker A: Is there, is there heat, uh, because of optics from their nation state, uh, safe harbor? I mean I know you're saying hey, nation state and they're the kind of like, let's say political side of it is not as much of an impetus as it used to be, but they still have nation state safe harbor to allow them to operate.
Speaker B: Yeah, they don't, they don't talk about it. They, that's one of those things that I believe that they don't want to talk because they know they're generally familiar with like sanctions. They're familiar with, you know, the, the post Russian invasion in Ukraine and all the sanctions that have happened. They're very careful to not even talk about it. And if you recall Back In February of 22, when the war broke out, um, some of the, uh, those who worked with Conti, you know, were part of the main core group. Leaked messages. I mean, it's old news about a year and a half ago, but it's important still. And it sort of set the tone is, I, uh. Keep your mouth shut. So they don't talk about it, don't say money, don't say, I'm going to support and go after anybody who's not, you know, who's against Russia. That implies, you know, nation, state, actor, which is banned. And again, it really sets the test. It, it tells a story that they're in this for business reasons. They want to get paid. They say it all the time. This is business. You know, we're not going to ruin you. We'll help you. We'll show you proof. After payments made. Again, it really sets the tone to keep your mouth shut because, you know, we're in this to make money, um, know about what goes on behind the scenes in terms of the support of their country, nation, state. I mean, there's still a lot of questions and unknowns, and I think that's the way they want to keep it. Um, they don't want anyone because that can be bad for the industry and bad for them to get paid. Um, so, uh.
Speaker A: Oh, well, well, give me another one. Yeah, we have another one comes to mind. A good one that's gonna, like. I mean, I mean, I mean, I guess a lot of them are kind of boring. Just like, oh, here it is. Here's the, you know, the ransom, here's the month, here's the, you know, the currency we got in time, you know, pay, Pay it out.
Speaker B: Right.
Speaker A: I mean, a lot of them are just.
Speaker B: Yeah, I think, I think what's also interesting, um, is we, we see at times, you know, the, the, the over exuberance of a company that is a victim and that don't want to pay, which is fine. Again, we're not in the business to make a recommendation that you should pay. We're not there. We communicate. We're part of the stakeholders to communicate with the threat actor. And the over exuberance at time to say, we're not going to pay, we don't need to pay, we don't pay terrorists. And we say that that's fine. Whatever your positioning is, we have good enough backups. You know, we're not concerned about the data that's going to leak. Like, let's just go and do a full negotiation. And we find in A lot of instances where, you know, going through the process that the backups are not as strong as they thought it could be, an older version, even two weeks old can really disrupt it. If you're missing two weeks of data, as you're probably aware of, and they'll come back and say, oh, wait, hold on a second. Uh, the data, they're not as good. Maybe we need to change our tune with the threat actor and not, you know, be so off putting with them. And maybe we need to start talking about that financial, you know, and we've had situations where, you know, to a. A, uh, story, you know, with. Without. I'm going to do my best to de. Identify this for confidentiality purposes where there was information in the data leaked and through proof of. Proof of, uh, you know, of exfiltration. Looking at sample files in the, in the file tree, there is some really, you know, heavy stuff, you know, that we're showing marital affairs. And the threat actor was using that to threaten to say one of your key employees was doing something internally with another one of your key employees. And I know the email and phone number for their spouses and, uh, I can go and reach out to them. And we went back and had a sidebar conversation with counsel first. Then we brought the client in and it was amazing. They went from we're not paying to them and say, pay whatever the man is or whatever on a dime. And, you know, it really shows, I think, you know, at the end of the day is, you know, we're like, we're like an ER room. We're kind of numb to this because we do it all the time. But the victim coming in, they're not used to being the room. They're panicky, they're emotion. And sometimes their defense mechanism is like, we don't need to pay. We're fine. We're going to survive this. But then going through the process, you know, these threat actors are good. They know what they're doing, they're trained, they know what to look forward, they know how to use that against them. And a lot of people mix personal and business all the time and things that they don't want to have leaked, and they use that to their advantage. Such as that, you know, they look back and say, oh, they have that, okay, let's pay them right now. You know, and it's egg on their face because there are other executives who are on the call too. And it's not just them, you know, who knows whatever else is going to happen after the payment is made. Um, so, you know, those cases happen quite a bit.
Speaker A: Well, the stuff like that affect insurance. Like you think insurance might have a reason to not pay out a claim maybe under some circumstances?
Speaker B: That's a, that's a good question. Um, I can't imagine that that would, you know, be an exclusion to a payout for the extortion. Um, because I think it's very muddies
Speaker A: and gray like fraud or crime and criminal activity.
Speaker B: Yeah, I mean, obviously fraud is different, but if there are people, you know, meddling business and you know, and personal and pleasure, you know, I think obviously in that situation they're, they have to abide, you know, buy whatever the contract and say, I don't think they have an exclusion to say if you're having an affair and it comes out, we're not paying for that. So.
Speaker A: Well, what kind of resistance are you seeing if any from insurance are there? Like, let's try to find ways to not pay it and kind of push that or support that or they stay on the sideline and just cross their fingers or like what, what, what kind of pressures are you seeing from insurance?
Speaker B: I mean, that's a good question. I think they're, they're more supportive than one, you know, would, would have thought. You know, on the surface you would think carriers and to come up with every reason to say no to a payments, you know, in thinking about some of the general concerns or maybe exclusions that you can't pay something that's, you know, uh, that's an OFAC sanctioned, you know, variant a wallet address or any other information that comes in, even in the IOCs that the forensic firms looking at IP addresses that are pinging in North Korea, you know, for, you know, where part of the malware is, you know, sitting and serving like they, they're, they're very smart and uh, they're, they want us to do a thorough job as an industry. But they're not necessarily looking for reasons to say no. They just want to make sure that people, the group is thorough. You know, we're not playing games. We're not trying to withhold anything that's important because they just want it to be done thoroughly. So surprisingly, they very much. In the last couple years, the insurance companies have upped their game. They're adding their own forensics, you know, professionals or adding their own instant response teams. They're adding the threat actor negotiators. They really are understanding, they're hiring folks who understand the sanctions not because of looking at reasons to pay, like, not pay out. They just want the data they want the information. They want to write better policies, they want to write better claims because their job is to be sustainable. This is not let's write policies. We're in this to make money. In two years, we're out. It's all about sustainability. The more data they have, the better that they can write policies that make it sustainable. Um, because if you, obviously, if you come up with reasons to not pay claims, I mean, there's a lot of console out there that's going to go after them, that are going to sue them and tie them up and you know, make them look bad. They want to be good. Uh, they want to have honor too, within the industry, um, and understand that they're becoming very smart and well equipped.
Speaker A: Well, you know, the Mondelez whatever case. So, you know, that, that, that to me, you know, kind of really scared. Well, me, a lot of people, hey, is insurance going to start? You know, it was the claim. This is like a nation state act. And so our insurance doesn't, you know, cover. And then they lost, you know, uh, Zurich against Mondelez, I think is what it was. But anyways, um, uh, so I do worry about that a bit. And actually this is really positive to hear, you know, not that we really, you know, are happy to make these claims. There's massive damage and disruption. Even if the insurance company makes you, you know, whole, you know, as whole as it can. So it's like nobody wants it. This isn't like, oh, a tree fell on my garage, great, I get a new garage. You know, I mean, this is massively disruptive your business. I don't think you could even really put dollar amount on it. You know, the, you know, it's hard I looking.
Speaker B: I don't know how anybody, me having a. But a finance background, you know, and a fan of modeling, I can't even imagine how they model out, even account forensics, accounting to deem business interruption losses to be able to make a claim. And even in short period of time, within maybe a couple of days of the breach, to say our systems are locked up, our clients can't buy, our vendors are walking away to try to save for every day that goes by, we're losing X dollars. I mean, it's, it's complicated. There's a lot of work that goes in to deem what those losses are, you know, and it's still not an exact science because there's a lot of qualitative information and assumptions that are made, you know, within those models to deem what those losses are. That's a tough job, um, you know, for anybody to, to sustain and even unintended consequences six months, years down the, you know, the road that can have losses that maybe are not accounted for up front.
Speaker A: Yeah, yeah, no. And of course. And you know, like all stuff you can't like sell off to kind of insurance risk, you know. And then of course you can't even pay ransom if it is a, you know, uh, whatever listed entity, whatnot. I hope they kind of help you keep from jumping over that tripwire. Like they don't go ahead and authorize, you know, a claim or payment without making sure it's been verified that this entity is not a, uh, listed the.
Speaker B: Yeah, the industry over the last couple of years have completely swung a pendulum in terms of knowledge and just best practices within cyber insurance claims apartments to do the due diligence for forensics to do their due diligence, have redundancies as well. Use a, uh, registered money service business who's doing all the work and all proprietary due diligence on every transaction. It's very complicated to build a reputation. You can't just knock on the door and say, I'm going to give you money to support. You know, it takes time to build those relationships and be in, in concert with the regulated regulations all the way up a Department of justice as well, to understand what the requirements are, um, and be part of those circles. Because collaborating with all the different stakeholders and officials and government entities is important because, you know, we're at the end of the day as we're all in the same business, we're trying to stop this from happening. I mean it's, it's pro American to, you know, stop what's happening, to limit it. Because we don't want this industry to last forever. It's always going to be here. But to certain extremes that we're seeing right now, we're working together, you know, like conferences like Black Hat and all the groups out there are um, trying to do whatever they can to, you know, create the biggest walls and defenses and onshore as well to make sure this doesn't happen, you know, and then we could figure out, using our skills elsewhere, you know, versus us being in. It's a response team. So, uh, but at the end of the day it's happening. We just got to put out these fires because if we weren't put out the fires, they would burn down companies. These companies would not exist and they would have way more damages. You know, whether it's good, bad or ugly, the payment side is Important, um, you know, whether it's something like it or not.
Speaker A: No, we need you. I mean we need you. Right? I mean, you know, we need you know, whatever doctors and lawyers and everybody to kind of do their jobs and tighten things up and make us healthy and keep us safe and prevent uh, but we be, you know, deceiving ourselves if we think our ecosystem doesn't have a need for you know, this, this, you know, uh, this, this part of that service side, you know, which is to, to make people whole when, when there is damage to, to recover. And that means working with criminals, sadly. I mean it's reality of it. So, um, but tell me like what do you think? Kind of like a closing thing, you know, insurance, uh, companies may be doing more stuff that's a changing landscape. Uh, um, you know, government being a little more kind of, let's say smart and vocal and trying to get policy out there, trying to get, and this is globally, this is not just you know, us, um, uh, you know, everybody getting smarter. Cyber security getting better people. Companies like onshore protecting people better and better. And you know, so tell me what you think the future of your, your business. And I know there's also you know, the, you know, the, the ATM side of the business uh, too but you know, focus on the, you know, the you know, Bitcoin, uh, on demand, you know, business. What do you see?
Speaker B: I, I, I think it's, that's a good question. I'll try to be over philosophical but you know, and I, I think you're, you're, there's always you know, the, the, the angel on one shoulder and the double on the other shoulder in the world of capitalism and in a financial transaction business or any consultants, you know, they're on there to make money, they set up their shop as an incident, happens to make money. And overall when there's enough, there's the incentives continue to increase and margins, you know, are attractive for these companies. They get acquired, they pay themselves big bonuses, all that stuff. Um, there needs to be that balance and continued balance between doing the right thing to support the industry and the companies, you know, while making money at the same time, you know, and I think it's, that's the only way to make this industry sustainable. If you have too many, you know, bottom feeder cowboys that are in this space that are just here to make money, um, I don't think it's going to be good for the industry, it's not going to be good for the government. And I think when in doubt, don't Turn a blind eye, understand who's buying, where was the, where's the money going on the blockchain? What exchanges, what mixers are being used to wash this space? Who are those behind the scene? Uh, is there ways that we can intercept these funds? Because at the end of the day if you figure out ways to cut the supply chain in different ways, you can really slow and limit the industry or add more risk, you know, limit the financial damage. So instead of organizations within our space that may again, I can't speak for others, can only speak for us, but take the approach of collaborating with law enforcement to provide de identified data to help them understand it. You know, the groups like Chainalysis, TRM Labs, Elliptic Big, these blockchain forensics companies are out there and Merkel Science amongst others, they're in the business to provide forensics on the blockchain. They're basically providing transparency on um, attribution of where it's going. And the more information we collaborate with them, the more, the more we collaborate law enforcement, the more we can see who's washing where. Are there other countries around the world that are maybe turning a blind eye that have crypto exchange peer to peer mixers that are happening that maybe we can stop and report on? Uh, maybe they don't know what's happening. And if we don't support the industry for not collaborating, if we're just pure capitalist mindset and say I'm not trying to increase and try to take the theme of limiting and destroying, you know, threat actors, you know, it's, it's, we're losing the chance to provide that intelligence to law enforcement. The shutdown Guarantax exchange, perfect example. You know, I would, I think it was in Czech Republic. It was a front for you know, uh, Russians, uh, ransomware variants to clean their money. They got raided and shut down. Um, Hydro Market was known for, you know, black market marketplace to clear and clean money and used by other ransom that was taken down and seized. You hear about more and more and the reason this happens is because of those that are actually have a little bit of altruism enough to keep the sustainable industry by sharing and collaborating that, that information. If we weren't doing that, none of that would happen. So I think uh, to, to conclude, I would say, you know, when a doubt, just find ways to do the right thing and provide intelligence to make this, you know, a better place in a better corporate ecosystem operating.
Speaker A: No, I love your vision. It's a big vision, it's a hopeful vision. Um, and you're you're totally not wrong that there's, this is an activity that we've seen on the kind of law enforcement side, you know, is way better last couple years than before. I mean, we're really seeing movement. Um, we're getting more sophisticated there. And I think it's people like Digital Mint that are finally doing it professionally, such that we're, you know, gathering information, making some better decisions. I'd like to see that better collaboration with law enforcement. I want to see Digital Mint succeed in that. And hell, man, maybe we're going to be like, scraping some of our money back from, you know, these criminals. Uh, we'll see. Getting, you know, putting them behind bars. You're awesome, Mark. And this is, this is a good fight. It's, it's, it's got an ugliness to it, and you have to navigate these, but, you know, need people like you to do that. Uh, so let's, let's, let's wrap on this. Um, thank you for coming. Love to have you again and continue. Ah, this topic or other awesome topics. You and I have so many things that we share that, you know, we can talk about. Um, and, uh, thanks, Josh, for producing. Thanks, guys. Great conversation.
Speaker B: Great. Thanks for having me. All right.
Speaker A: And, uh, we'll do it again. So long to audience for the Onshore on Security podcast. Uh, Mark Rens from Digital Mint. Awesome guest. Good day.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.