
The Defender's Advantage Podcast · 2026-04-27 · 29 min
Key moments - from our scoring
Substance score
59 / 100
Five dimensions, 20 points each
Google's newly formalized Disruption Operations team operates with a distinct mission from traditional security defense: rather than detecting threats or defending products, they focus on imposing costs on threat actors themselves. Snyder explains their four-pronged approach - technical takedowns on Google platforms and partner networks, leveraging legal systems and court orders, strategic disclosure of adversary activity, and driving product hardening - while clarifying what they don't do (offensive hacking or "hack back"). The team's work differs fundamentally from Google's existing counter-abuse and trust and safety teams by targeting the actor behind the malicious activity rather than just the activity itself. Two case studies illustrate their approach: the IP Idea residential proxy network operation, which enabled hundreds of threat actors across APT, crime, and information operations, and UNC2814, a China-nexus APT group targeting telecommunications companies globally using Google Sheets as a command-and-control mechanism. Snyder addresses the inherent tension in disruption work - that aggressive action against adversaries often means losing visibility into their operations - and argues that given the increasing boldness of modern threat actors and the stakes involved (critical infrastructure, ransomware against hospitals, cyber-kinetic effects), the risk-benefit calculus favors active disruption over passive monitoring.
Residential proxy networks mask malicious activity as coming from consumer devices in residential networks rather than data centers, making attacks appear to originate from normal users like "John Doe in Iowa." Threat actors use them to evade detection and conduct abuse ranging from credential stuffing to ransomware campaigns without attribution risk.
Google used Android enforcement to remove malicious SDKs from devices, combined with creative use of court orders to work with domain registrars and other ecosystem partners to take down command-and-control infrastructure and digital storefronts where IP Idea marketed their proxy technologies.
UNC2814 used Google Sheets as a command-and-control channel - the attacker would communicate through sheets to issue commands to compromised machines and exfiltrate data. Google identified all instances of this abuse, worked with partners to identify victim infrastructure, and sinkholes the attacker's infrastructure at scale.
While counter-abuse and trust and safety teams focus on detection and product defense, Disruption Operations specifically targets imposing costs on threat actors themselves, treating adversaries rather than malicious activity as the primary focus.
Google explicitly does not conduct offensive hacking or "hack back" operations; their disruption toolkit is limited to technical takedowns, legal action, disclosure, and product hardening - always within legal and ethical bounds.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a few genuinely substantive concepts - the enabler-targeting logic, the four-pillar disruption taxonomy, and the Google Sheets C2 mechanism - but the density is reduced by PR framing around a newly-public team announcement and several mid-interview recaps. Smart defenders will extract real ideas but will also wade through promotional positioning.
we found hundreds of threat actors using IP ideas, residential proxy networks, specifically everything from you know, apt crime, hacktivism, information operations. Uh, we observed uh, model distillation attacks against our uh, LLMs, uh transiting that infrastructure
building up this capability that the threat actor had of you know, essentially uh, maintaining live connections to 70 plus uh, telecommunications companies worldwide likely took quite a bit of effort for the threat actor to build over time
The enabler-targeting rationale and the tactic of hitting adversary commercial storefronts rather than just C2 infrastructure are modestly fresh angles. Most other framing - intel gain-loss tradeoffs, 'adversaries are bolder now,' sunlight-as-disinfectant - recycles widely circulated industry positions without adding new reasoning.
by going after one, you can potentially impact a wide array of threat actors who are relying on those enablers
sheets is just another mechanism to upload and download arbitrary data. Uh, there's lots of places attackers can misuse uh, products. For C2. It's clearly becoming a common tactic to use the products of popular kind of cloud and all online technologies
Charlie Snyder is the operational head of a newly stood-up disruption unit inside one of the most capable threat intelligence groups in the industry; he speaks from first-hand involvement in specific operations, not from advisory distance. His credibility is grounded in what the transcript reveals he has actually executed, not credential-signalling.
I think we are the first team who's primary focus is on disrupting the actor behind that activity
This started uh, with a Managed Threat Defense investigation. And what that is is you know we have a product that will, on behalf of Google Cloud customers, monitor their uh, security telemetry
The episode is reasonably concrete by B2B podcast standards: named threat actors (UNK 2814, IP Idea, Salt Typhoon, Volt Typhoon, Shiny Hunters), a specific C2 mechanism (Google Sheets), a hard victim count (70+ telcos), and named legal instruments (court orders, domain registrar cooperation). It falls short of exceptional because there are no timelines, dollar figures, or hard before/after metrics on disruption impact.
maintaining live connections to 70 plus uh, telecommunications companies worldwide
the attacker would communicate from an attacker owned server to um, the victim, in this case the customer we were investigating to uh, issue commands to the compromise machine and to uh, upload data from uh, the compromise machine to uh, the attacker all through uh, Google Sheets basically
Luke McNamara asks structurally sound questions - the impact-measurement question and the intel gain-loss framing are the strongest - but he never pushes back on a claim, never asks Charlie to quantify success, and closes with a predictable 'what are you excited about' softball. The interview reads as facilitated storytelling rather than genuine interrogation.
there's also this dynamic where at times the very act of disruption, of taking down infrastructure, of forcing an actor to retool might mean that we lose some visibility into their operation
Where are you kind of excited about in terms of, you know, potential future areas, you know, without getting into specifics, of course
Computed from the transcript - who did the talking, and the words that came up most.
Host Luke McNamara is joined by Charley Snyder, Head of Disruption Operations at Google Threat Intelligence Group, to delve into how Google is crafting a more coordinate approach to disrupting adversary cyber operations. Charley describes how this disruption focus is not hacking back, how it builds on existing work across Google security teams, and some of the recent wins such as the IPIDEA and GRIDTIDE takedowns.
Transcribed and scored by The B2B Podcast Index.
Speaker A: You know, some of these actors we've tracked for a very long time. We want to look at how things have been working, you know, for a threat actor that we've been monitoring for a long time. Do they look substantially similar today as uh, how they looked, you know, two years ago, three years ago, five years ago? Are they able to successfully complete the same types of operations that they were doing a couple years ago? If so, you know, maybe it is time to try something different. You know, if we're seeing them be successful, it's kind of a status quo business as usual for them. They clock in and they, you know, they compromise users. Maybe it is time to try something new and take on a little, little bit of risk that, that we might lose visibility.
Speaker B: Welcome back to another episode of Manian's Defenders Advantage podcast. I'm your host, Luke McNamara. Today I have the pleasure of welcoming on Charlie Snyder, who is the head of the disruption operations here within Google's Threat Intelligence Group. Charlie, great to have you here today.
Speaker A: Thanks so much Luke for having me. I'm, I'm honored, uh, to be on and looking forward to the conversation.
Speaker B: I'm excited to be having this conversation. Uh, we're talking today about, uh, the disruption unit, newly announced, I guess formally uh, announced at RSA release recently. But this is not obviously a new group. It's been around here within GTIG for uh, a little while. For folks who have read some of our blogs, they'll notice references to some of the activity that this organization that you lead has been a part of. Uh, but I thought we could dive a little bit more into sort of the kind of mission and focus and intent behind this group, some of the operations that you've been involved with. Uh, and maybe a great place obviously to start is how do you sort of define the mission of the disruption team?
Speaker A: Yeah, sure. So, you know, we define our mission pretty simply. Um, uh, we exist to degrade and disrupt the capabilities and operations of uh, kind of the most significant threat actors, uh, targeting our users and customers at Google. Um, so we are an adversary agnostic team that partners closely with all of the, you know, adversary aligned teams within Google Threat Intelligence Group, uh, to identify and execute, you know, opportunities to disrupt malicious activity. It's probably worth explaining a little bit, you know, how we do this, like what are our tools. There's been kind of a lot of information out there, a lot of speculation about, you know, not just what Google's doing to disrupt, but, you know, other industry partners. Um, so I think it's helpful to be a little bit more granular about uh, what specifically we're doing versus not doing. Um, so, uh, we have kind of four broad categories of action. Um, so the first, the one that kind of drives uh, maybe most of the headlines is technical takedowns. Uh, this is both kind of on our platform and then enabling uh, other partners uh, to take action on their platforms as well. Uh, but you know, from a Google perspective, uh, we definitely want to be aggressive when we see threat activity on our platforms and services, targeting our users, uh, to be aggressive in kicking them off. So that's one second is using the legal system, uh, to our advantage. Uh, we want to be, you know, actively uh, using um, you know, the laws where we operate, uh, to you know, hold threat actors accountable and using some of these authorities in creative ways. Um, and frankly there's been a lot of kind of trailblazing from um, you know, other teams at Google as well as industry partners here that, that we're seeking to replicate. Um, third is disclosure. I think, um, you know, sunlight can be a disinfectant. Uh, it's not always disinfectant. I think a lot of threat actors are pretty immune to bad publicity. But there can be cases where selectively sharing kind of the misbehavior of actors can be helpful. Um, and then last, and I think this gets overlooked sometimes in the disruption conversation, we're also very focused on using threat intelligence to drive uh, product hardening and remediation. We do not want to be in a place where we're constantly kicking bad actors off our platform just for them to turn right around and come right back in. So those are the tools we're focused on using. I think importantly, there's been some speculation about hacking back and taking offensive action and we're not uh, doing that. And then I think the last thing I would say about our mission and like kind of our tools is kind of a thread running through all of this is, you know, across all of these, uh, you know, I think partners play a big role here. So that's a big part of our job too. Whether it's you know, taking technical action, um, fixing things. You know, we can be more effective and more comprehensive in disrupting adversary behavior when uh, we bring in other partners in the ecosystem who can take action on their end as well.
Speaker B: You referenced this a little bit, but um, I wonder if you could kind of maybe uh, frame this some more, which is, you know, how this differs from what Google has historically done. Obviously we've got, you know, trust and Safety teams, counter abuse teams across, uh, the Alphabet ecosystem. Is it really the thing that you see that sort of defines this is the holistic nature that you're looking at this strategically working with a lot of those teams, or how does this differ from what we have done in the past here at Google?
Speaker A: Great question. Um, I'm always quick to state, like, disruption is by no means new to Google. There are lots of teams, some of which you've mentioned, that disrupts malicious activity, uh, on a daily basis, you know, hundreds, thousands of times per day. What I think is new or a little bit different is that the primary focus of most or all of these teams is, you know, things like detection of threats, defense of our products, defense of our users. And with our team, I think, although Google's a big place, you never know. But I think we are the first team who's primary focus is on disrupting the actor behind that activity. So we're not a detection team, we're not a defense team in the purest sense of how I would think about it. Um, we are a team focused on imposing costs on those bad actors. Importantly, there's obviously a nexus between all of the counter abuse security teams, threat intelligence functions at Google. We benefit immensely from their expertise. In fact, we couldn't really do anything without those teams tracking threats 24 7. And what we try to do is leverage all of that expertise, the tooling, the visibility, to really look at an actor from that other standpoint of um, how can we go study what they're doing, study what they value and uh, try to degrade and disrupt that to try to make them have a bad day. Um, and in that way I really hope that we can be a value add to those, uh, defender teams to those counter abuse teams to make that kind of firefighting a little bit easier.
Speaker B: So I think maybe it would be helpful to get into some of the examples where you guys have been active already. Um, again, this has been around for a little while here at Google, even though we're talking about it more publicly, um, and it's shown up in a few of the blogs within the last several months, within last year, maybe we could dive into a few of those examples because I think that really highlights, uh, highlights some of the ways that you approach this sort of work. So whether it's grid tied or iPadadia, I don't know which one you want to dive into first, but maybe we could talk about some of those examples.
Speaker A: Yeah, sure. And you know, as I mentioned up front, we are kind of, you know, adversary Agnostic in that we don't just look at apts, we don't just look at crime. Uh, we look for good opportunities where a given threat is causing havoc or causing pain to our users and customers and then pair that with the opportunity. There's some cases where we might see malicious activity, but we don't really see a good path to disrupting them in a comprehensive way. And so for better or worse, there's no shortage of different things to look at and focus on. And as you mentioned, a couple of our projects have, uh, been publicized in the last six or seven months that we've been up and running. Um, and I think the two cases, one is kind of a group of, uh, residential proxy networks, all operated by kind of this same group called IP Idea. And the other, uh, was taking down a campaign we called, uh, Grid Tied, that was a China Nexus APT group on 2814. And so that kind of shows like, the breadth of different activity we're looking at. And I think there's some interesting kind of differences between those cases. So, you know, IP Idea, we started looking at kind of this group which I would put in kind of like the enabler category. Um, they're kind of, they kind of sit in the, in the crime bucket. Um, but what they're really doing is enabling a lot of other bad activity. And so when you. The reason we like going after enablers is, um, by going after one, you can potentially impact a wide array of threat actors who are relying on those enablers. Um, you know, residential proxy networks have become a bit of a scourge in the last, uh, several years. What these are, you, you know, they are a proxy network, um, so you can look at them as, you know, a way for a user to make their activity, uh, appear as if it's coming from a different place online. And the difference with residential proxies, as opposed to other forms of technologies that do this, like ISP proxies or VPNs, is residential proxy networks are built upon basically consumer devices in, uh, residential Networks provided by ISPs. And the reason they want to do that, the reason threat actors want to use them, is because they look like they're coming from, you know, John Doe in Iowa or wherever. And the way they build these networks is, you know, in a couple different ways. Um, one, pure malware, um, they will infect those consumer devices and join them to the network, um, also through kind of subterfuge. So what we found in our investigation was they would essentially go to developers of applications in Our Play Store, um, although it wasn't limited to just Android, it was other platforms as well. Say hey developers, this is a totally legit software development kit. If you incorporate this in your app you'll get paid for doing so. Like we'll basically pay you on a per download basis and when, when it was incorporated into that app and when users download and run the app that, that joins the, the device into the network in most cases without that consumer's knowledge or awareness of what was going on. And so essentially the consumer is renting their bandwidth to this proxy network. And because of those advantages of residential proxies, again it's making it look like it's coming from you know, a normal residents somewhere in the world. It is overwhelmingly abused by threat actors. And uh, as we kept pulling the thread um, we found hundreds of threat actors using IP ideas, residential proxy networks, specifically everything from you know, apt crime, hacktivism, information operations. Uh, we observed uh, model distillation attacks against our uh, LLMs, uh transiting that infrastructure. So really enabled a lot of bad behavior. Um and in that case we were able to bring together a couple different tools including enforcement on Android, ripping all of this stuff out of Android devices and also some uh, interesting legal authorities. We were able to kind of repurpose a court order to uh, work with uh, other providers in the ecosystem like domain registrars and the like to take down all of their or a lot of their online infrastructure. And we went after both the command and control, uh, that the devices were uh, communicating with, that were routing proxy payloads through those devices to the end destinations. But we also went after their digital storefronts so um, where they actually marketed uh these proxy technologies. And I think the latter is probably maybe the largest uh effect I think because you know these technologies are in a competitive marketplace. There's lots of proxies out there. They'd spent a lot of time and capital in getting distribution, getting people interested in their product and by taking down all of their websites we've, we kind of, you know we impacted that. Uh, so in that case uh, you know this is a very kind of complex ecosystem. Uh, we're pleased with the initial results but you know there's no shortage of uh, devices out there that can be added to these networks. They've been able to reconstitute to a degree. And that kind of illustrates another kind of important point about our team that um, we don't just launch kind of one off projects. Um, it's very much kind of a journey, a cat and mouse Game, et cetera. We know we have to keep hammering away at the residential proxy issue. The other case you mentioned, kind um of more of a straightforward disruption ah of a APT group's operations. Again this is uh, unk 2814. It's a uh, China Nexus APT group. We had been monitoring this group for a long time well before our team was formed. And there was this kind of untold story I think about global telecommunications uh, targeting. And I think obviously Salt Typhoon gets, you know, has gotten a lot of the headlines and in particular for some of the specific systems they, they were targeting in the United States. But there are other uh, China Nexus APT groups out there that are, that are going after and successfully compromising global telecommunications infrastructure, uh, every bit and having every bit as much success as Salt Typhoon. And uh, so, so this group has been on our radar for a long time and what I think is interesting about this case is how much we benefited from different Google teams coming together uh, in a relatively short amount of time to create a significant impact. So this started uh, with a Managed Threat Defense investigation. And what that is is you know we have a product that will, on behalf of Google Cloud customers, monitor their uh, security telemetry when alerts fire. And in this case, so it all started at a customer where uh, that team, our Managed Threat Defense team, uh quickly uh, saw an alert, uh triaged it and actioned it quickly about a process being initiated from a suspicious uh, location in the system. What we were able to find pretty quickly is uh, the actor was using uh, you know, an interesting uh, malware family that had been on our radar but we didn't have kind of all the pieces of it to piece it together fully, uh, that used you know, Google APIs and Google Sheets uh, specifically as kind of a C2 mechanism. So rather than the way you or I would use spreadsheets, uh, they would communicate, you know, the attacker would communicate from an attacker owned server to um, the victim, in this case the customer we were investigating to uh, issue commands to the compromise machine and to uh, upload data from uh, the compromise machine to uh, the attacker all through uh, Google Sheets basically. And uh, so as soon as we saw that we were obviously uh, very interested in how we could pivot off this and create greater disruptive impact against the threat actor. And so we were able to combine kind of that world class investigative capability, working with customers, uh, with our visibility within Google to identify all the instances, uh, we think where the actor was uh, utilizing this mechanism, um, and uh, through that process as well as working with uh, some key partners we were able to identify quite a bit of infrastructure and identify you know, frankly a large number of victims, almost unanimously in the kind of telco sector and then rip it all out all at once and sinkhole a lot of their infrastructure as well. And you know, as I think we said in the public materials, you know, building up this capability that the threat actor had of you know, essentially uh, maintaining live connections to 70 plus uh, telecommunications companies worldwide likely took quite a bit of effort for the threat actor to build over time and uh, we hope we set them back quite a bit. Um, so that was a really fun, interesting project, uh, working with uh, a lot of really highly capable teams across Google and with partners uh, in a relatively condensed amount of time.
Speaker B: That's an interesting one too when you think about one of those levers, one of those tools that you utilize being disclosure given that even though that actor has been around for a while, we've tracked them for a while, there had not been a lot previously discussed about them out in the open source. Um, and it's also a campaign, a set of activity where as we highlight in the blog, there were a lot more other suspected victims than the ones we are aware of. So I think that's a great example where obviously many different tools kind of applied to that. But even just talking about this publicly and raising awareness about this actor and what they're doing, hopefully it leads to uh, further investigations into um, parts of this that maybe we haven't seen or hasn't been discovered yet.
Speaker A: Yeah, absolutely. I think that was a big goal or reason for releasing some information publicly. Again, you know, wanting to drive the message. It's not just, you know, it's not just salt typhoon, it's not over. This activity is, is continuing, people are at risk and then obviously releasing you know, indicators of compromise uh, to help organizations check if they've been uh, impacted. Um, you know the other piece of it that's kind of a longer term thing is driving you know, kind of more resilience and product hardening. One thing we point out is sheets is just another mechanism to upload and download arbitrary data. Uh, there's lots of places attackers can misuse uh, products. For C2. It's clearly becoming a common tactic to use the products of popular kind of cloud and all online technologies in general for that purpose. And so um, hopefully we can you know, spark additional action you know, both within Google and with, with other operators of online services to try to find more solutions to try to cut down on that, um, and again I think that's a, that's a longer term piece of that.
Speaker B: Let's talk a little bit about measuring impact. I think as you noted at the beginning, you know, some of the ways that adversaries respond to being publicly disclosed, their um, activities being disclosed, um, some of the extent to which their operations are disrupted, that's going to vary. It's going to vary actor to actor, what was actually impacted. Um, there's also this dynamic where at times the very act of disruption, of taking down infrastructure, of forcing an actor to retool might mean that we lose some visibility into their operation. So there's, there's trade offs to even some of this activity. Um, as we've always known, when we release blogs and put the stuff out there publicly, the actors read this stuff. That's not new. But I guess I'm curious, maybe at a high level or even in some of these specific areas, how do you think about measuring the impact from disruptive operations, um, to specific actors? Um, and how do you think about that kind of balance between needing to do more to impose cost, particularly in the private sector, needing to kind of take more of a stance there. But uh, then also meaning that, you know, in some cases we may risk losing visibility into operations.
Speaker A: Yeah, great question. So, first piece of it, you know, measuring impact. It is a, it's a supreme challenge. And I think this is not common to what we're doing. It's common across um, the security field in general. Um, how do you know if things uh, are getting better if you've done your job? Um, and certainly when you're working against highly advanced threat actors, it can be very hard to get accurate assessments of. Again, we set out to make bad actors have bad days. How do we really know that it's a bad day or a bad week? Uh, so it is a challenge. We try our best and we look at different things. First, if we're able to identify potentially impacted organizations and help them, uh, remediate and recover, you know, I think that's, that's always a win. But uh, two, can we identify classes of attacks, things that we can work on to again kind of like harden the products, make it, you know, make the attacker have to expend more resources to do what was previously a little bit easier for them. Um, and so we measure, we have metrics related to that. And then you know, of course just looking at, you know, for whatever we can find. And again this is often a challenge. You know, how has the actor specifically been impacted? Do we see their operations becoming less effective, things like that. And then of course that kind of leads into, you know, the last part of your question, which is, uh, when we do this, we necessarily often lose visibility. And so that gets into that kind of intel gain loss conversation that I think has been an ongoing conversation in this industry for, for decades. You know, there's, there's a couple ways we look at that and like, um, the, you know, what we can gain versus lose by being a little bit more aggressive, having a more kind of disruptive posture versus things, you know, against things we're monitoring. First, first thing, and I try not to throw around kind of too many industry stereotypes, but in my opinion, I think it is true that the, you know, quote unquote threat picture is worse now than it was maybe 10, 15, 20 years ago. For in. And again, in my opinion, this is really for one primary reason and it's that adversaries are bolder now. They're willing to do things that were unthinkable before that, that were not kind of the norm of what we would see in, you know, 2015 or 2010. Um, when you look at kind of the crime sprees of Shiny Hunters, the extortion, the ransomware against hospitals, things like that, when you look at the volts holding critical, I say the volts of Volt Typhoon, the things we're seeing where adversaries are willing to hold critical services at risk for entire nations. Um, when you look at the kind of pairing of cyber and kinetic effects and things that we've seen play out in Ukraine, to me I feel like adversaries have, you know, whether there were ever norms, it seems like the norms, uh, have shifted, if ever there were any. And uh, adversaries are bolder now and against that type of activity versus, you know, espionage, you know, you really have to meet that aggression head on. You know, we don't want to be just, you know, quote unquote, monitoring the situation, uh, when that kind of activity is occurring that, you know, that's not something you're going to be able to explain to, you know, your boss or uh, the government or whatever. You know, we want to take an active posture against, uh, what is increasingly kind of bolder and more disruptive adversarial cyber attacks. We want to be pushing actors kind of off the X, give time for, you know, the defender community to take more kind of, uh, to take action to protect these services that, you know, everyone relies on. And then the other thing that we look at a little bit there is you know, some of these actors we've tracked for a very long time and we want to look at how uh, things have been working, you know, for a threat actor that we've been monitoring for a long time. Do they look substantially similar today as how they looked, you know, two years ago, three years ago, five years ago? Are they able to successfully complete the same types of operations that they were doing a couple years ago? If so, maybe it is time to try something different. If we're seeing them be successful and uh, it's kind of a status quo business as usual for them, they clock in and they compromise users. Maybe it is time to try something new and take on a little bit of risk that we might lose visibility. Um, and of course there's cases where our visibility is too tenuous. We don't have confidence in the effects of some action we want to take. And in those cases, you know, I think caution would, would certainly prevail.
Speaker B: So I guess, you know, looking forward, you know, given the sort of, this is, this is still a relatively new um, kind of area of focus for us and there's going to be some trial and error. Where are you kind of excited about in terms of, you know, potential future areas, you know, without getting into specifics, of course, but when you look at where the utilization of these different tools and levers can be applied, when you look at some of the different problem sets that are out there, do you think we're going to be seeing more of this applied to the infrastructure takedowns? Uh, like with IP idea, is it going to be more around specific actors? Just curious, some general thoughts you have. Kind of looking forward into the future here.
Speaker A: Yeah. Uh, so, um, I'm excited for the future. Um, we are still, we are a small team and uh, we are looking forward to scaling our impact. Um, just, you know, frankly a lot of this work right now is pretty artisanal. You know, we're very interested and I think well positioned, you know, working where we do to leverage AI and automation to scale our impact. You know, we've got amazing tools to leverage amazing, you know, expert teams, uh, to partner with within Google. And we really want to systematize this uh, disruption activity. So we're focused on that. We're also, uh, you know, I think I've been very pleased with uh, some of the partnerships we've developed with other companies, government, uh, organizations and the like. And uh, you know, we really want to build on that and deepen those partnerships, make them, you know, really ingrained into the working model both for us and those partners. And I think we can just accomplish a lot more together. And ultimately, you know what, what I hope is next is bringing more pain to more bad actors.
Speaker B: Excellent. Well, I expect, uh, in the upcoming months there's going to be more blogs where your team, if not the full focus of it, will have a footnote about. Hey, you know, here's a new operation that we didn't just respond to. We also had a role interrupting. So, um, I look forward to seeing those and we'll include a link in the show notes to some of the ones that you mentioned as well. But Charlie, thanks for your time today and I think this is a great, uh, discussion around, uh, the work your team is doing.
Speaker A: Thank you so much Luke. This was a, this was a lot of fun. Let's do it again.
Speaker B: All right, Take care.
Speaker A: You too. Bye. Bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.