Lye Detector Test
TL;DRA hacker remotely accessed the Oldsmar, Florida water treatment plant via TeamViewer and raised sodium hydroxide levels from 100 to 11,100 parts per million. An operator caught it immediately; no one was harmed.
Jordan Bloemen & Scott Francis Winder discuss that special something they're putting in the water in Oldsmar Florida.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: I'm gonna provide you a little bit of background on how water is provided in Pinellas County.
Speaker 2: So we put sodium hydroxide into our water supply for a couple of different reasons. It's super useful for for controlling how acidic our drinking water is, and it is a very effective tool in preventing pipe corrosion. But importantly, you don't put very much in the water. Typically very, very little, about 100 parts per million. Because sodium hydroxide, which you probably know as lye, is pretty dangerous to humans if you consume more than that very tiny little diluted amount. You remember the scene of Fight Club with Brad Pitt and Edward Norton, and he kisses his hand
Speaker 3: and I do. I do. I know a very basic solution is, not great for the human body, so that would make sense.
Speaker 2: And like everything that we put into our water, there's a dial somewhere on a screen at your water treatment facility that controls, you know, how much sodium hydroxide is in the water that comes out of your tap. On Friday,
Speaker 1: Oldsmar, Florida,
Speaker 2: In Oldsmar, Florida, a city of 15,000 people just outside of Tampa, is no exception. On a computer somewhere in that facility, there's a dial, and it controls how much lie is going into the water supply. And it's kept at about a 100 parts per million, which is a very, very low, very safe concentration. And at 8AM, a couple of Fridays ago, someone reached out from the dark and wrap their hands around that dial in Oldsmar, and they turned it way up. Why they did it, who they probably are, and what we can learn from it is gonna be our subject this episode. Yikes.
Speaker 1: Water systems, like other public utility systems, are part of the nation's critical infrastructure and can be vulnerable targets when someone desires to adversely affect public safety.
Speaker 2: Someone could mess with the water supply or the power grid or the traffic system has kind of long been a cliche in discussions surrounding cybercrime and cyber warfare. We've talked about it a lot on on this show. I think because it's a really easy way to get people to understand the stakes of a cyber attack that, you know, life and death infrastructure is only as secure as the computers that are controlling it. And that like a tech savvy, bad actor could do a lot of harm. And this is kind of about that, but it's also way dumber and way more relevant to most people's day to day lives. This, and I'm pretty proud of this one, is the lie detector test here on Hacked. Nice.
Speaker 1: On Friday morning at about 08:00, a plant operator at the Oldsmar Water Treatment Facility noticed that someone remotely accessed the computer system that he was monitoring. This computer system controls the chemicals and other operations of the water treatment plant.
Speaker 2: You can watch the press conference where Pinellas County Sheriff, Bob Galtieri, stands at a podium next to Oldsmar's mayor and city manager and announces that their water treatment facility was hacked. The clip is on YouTube. It's very interesting to watch. And one of the journalists asks the sheriff closer to the end Arlene, are you are you comfortable, sheriff, calling this an attempted bioterror attack?
Speaker 1: Well, what I'm comfortable it is what it is. You can put whatever label you want on it. What it is is that somebody hacked into the system, not just once but twice, and controlled the system, took control of the mouse, moved it around, opened the program and changed the levels from a 100 to 11,100 parts per million with a caustic substance. So you you label it however you want. I'm telling you those are the facts. And in order to get into the system, somebody had to use some pretty sophisticated ways of doing it.
Speaker 2: So I think, Scott, we should probably start by talking about a piece of software called TeamViewer. Are you familiar with TeamViewer?
Speaker 3: I am very familiar with TeamViewer, actually.
Speaker 2: Broadly speaking, what is TeamViewer?
Speaker 3: TeamViewer is a way to give people access to your local computer from remotely, or remotely give people access to your local computer. I know a ton of IT infrastructures use it as a way to connect to their, you know, remote desktops and laptops and stuff to provide support to staff.
Speaker 1: The computer system was set up with a software program that allows for remote access where authorized users can can troubleshoot system problems from other locations.
Speaker 3: It's installed on boatloads of PCs and is and is and can be wildly vulnerable. So that doesn't surprise me at all.
Speaker 2: According to TeamViewer's website
Speaker 4: What is TeamViewer? A cloud based platform enabling global connectivity. Easy to use whenever and wherever you need it. Designed to provide connectivity across operating systems and devices.
Speaker 2: TeamViewer has 200,000,000 users around the world. And if you've ever used remote access software, you have a pretty good sense of how it kinda works. You can control a computer it's installed in by logging into your TeamViewer account on another device. And in a lot of the discussions I read about software like team viewer, and I guess when and where you should and shouldn't be using it, people brought up the distinction between it and OT a lot. Scott, what what are those? What is that distinction?
Speaker 3: IT and OT. Well, I think the easiest thing to say is that, like, IT is a lot of your basic computer systems. You know, the the ones that the people in the accounting offices use. Where OT is more of the hardware level stuff, you know, the SCADAs and the valve controllers and the PLCs and things like that that actually impact the the physical nature. You know, technology that controls physical things, where IT is more of a, you know, fluffier, softer digital space stuff, I guess, would be the the the layman's way to describe that.
Speaker 2: And as an IT person, if you found TeamViewer or some software like TeamViewer installed on a computer that controlled OT, what would you think about that and why?
Speaker 3: Truthfully, I'd probably just assume that it was put there by the IT department to support the computer that controls the OT stuff.
Speaker 2: Interesting.
Speaker 3: TeamViewer is on so many people's computers and so many people download it. You know, my mother-in-law has it installed on her her laptop, and it's so that her friends can give her remote support. You know? She's probably done nothing to secure it. No. She doesn't disable it when it's not required. And, you know, that probably exists on, as, you know, TeamViewer's website says, 200,000,000 people's computers.
Speaker 2: Yeah. Apparently, it's kind of a meme in the cybersecurity world. Like, I bumped into that a bit when I was reading about this. It's the thing where when cybersecurity people get into a system, they almost flinch a little bit when they see it. Like, it's very common, but is it a great idea at the volume it's used? No. Was sort of the sentiment I bumped into.
Speaker 3: I haven't used it in forever, but if I do recall correctly, the default settings
Speaker 1: for
Speaker 3: it is passwordless. You literally just need this number that's generated to connect to a computer. So, you know, as we talked about in the auto dialers and and, zoom dialers, it's not that hard to generate random numbers and try to connect to them.
Speaker 1: The row remote access at 08:00 on Friday morning was brief, and the operator didn't think much of it because his supervisor and others will remotely access his computer screen to monitor the system at various times.
Speaker 2: So the FBI puts out these things called, private industry notifications or pins, and they're just, like, blog posts the FBI puts up. And the FBI posts a pin a few days ago about the Oldsmar case stating that, quote, beyond its legitimate uses, TeamViewer allows cyber actors to exercise remote control over computer systems and drop files onto victims' computers, making it functionally similar to remote access trojans, which we've talked about before on this show.
Speaker 3: It is entirely it is it is a commercial remote access piece of software. And if, you know, the difference between a piece of software that's sold and a piece of software that's, you know, deployed in a in a bad sense is pretty dissimilar. So, yes. You know, you could use TeamViewer as a remote access Trojan, but no question. Like, as a hacker, if I gained access to a computer, I could just install TeamViewer to use it to come back.
Speaker 2: Sure. It's like the next part of that sentence is what I was about to say which is, quote, TeamViewer's legitimate use, however, makes anomalous activity less suspicious to end users and system administrators compared to typical rats, which is exactly what you said. Compared to a remote access Trojan, TeamViewer might actually be supposed to be there, which might make it harder for someone to notice when it's out of place. Totally. Which is all to say. It seems this is kind of the first half of what happened.
Speaker 1: So nothing else happened, from that initial, intrusion at about 08:00 on Friday morning, until about 01:30. When someone again remotely accessed the computer system and it showed up on the operator screen with a mouse being moved about, to various to open various software functions that control the water being treated in the system.
Speaker 2: The water treatment facility in Oldsmar had TeamViewer installed on a computer. In the press conference from the start of the show, the mayor explained that it wasn't in active use for about six months, but it was still installed on that system. And someone, somehow, found that connection. And luckily for the people of Oldsmar, for whoever, you know, wide open the front door to their water treatment system was, the security system inside was, like, pretty good.
Speaker 1: After the intruder increased the parts per million from 100 to 11,100, the intruder exited the system, and the plant operator immediately reduced the level back to the appropriate amount of 100. Because the operator noticed the increase and lowered it right away, at no time was there a significant adverse effect on the water being treated.
Speaker 2: Alarm bells sort of immediately went off once that lye content went over a certain threshold. There's kind of a, I think, about a twenty four hour delay for the chemicals to actually reach people. And even if somehow all of that failed, there are physical impediments to this much toxic material getting into the water supply that quickly. You know? Because like a little pump meant to disperse 100 parts per million doesn't really know what to do with a command ratcheted up to a cartoon number like 11,000.
Speaker 3: I imagine just having that much base in the water supply probably also caused pop problems in the infrastructure as well, the pipes, you know, any kind of seal.
Speaker 2: If it had made it out. Yeah. If this was a plan, a cyber sabotage attack as that journalist called it, it was like a pretty bad one. The question then is, you know, what was this?
Speaker 1: Our digital forensics unit has been working all weekend, to try and determine exactly how the breach occurred and the identity of the person or persons responsible.
Speaker 2: And in the days following the story breaking, there was a lot of speculation. A couple of the security researchers who have published about this in a little bit of time since it happened brought up something that you and I have talked about here before. Meaning, the answer might lie in our trusted Internet of Things search engine, Shodan. Scott, can you remind everyone what it is we use Shodan for?
Speaker 3: To look for vulnerable IoT devices, notably cameras and other things.
Speaker 2: It's it's it's interesting and weird that it's legal. Like, that's a big thing to unpack, but it is kinda wild to me that something like Shodan is legal.
Speaker 3: Well, the the I think the the reality is is, like, you know, Shodan's doing nothing wrong besides highlighting an issue. So is it Shodan's fault? You know, we're getting into the chicken and the egg and the, you know, is it the IOT devices will the IOT devices ever be more secure if something like Shodan didn't exist to highlight the fact that they're insecure?
Speaker 2: You know? It it That's a fair point.
Speaker 3: It becomes a I don't know. That's a that's an interesting predicament that society deals with in so many different facets. And, this this is just another one of those facets.
Speaker 2: So, Shodan, as you said, is it's a search engine for Internet of Things devices. And this kind of SCADA equipment, these human machine interfaces, whatever you wanna call them, the kind of systems that control water treatment facilities are sometimes indexed on Shodan. So Scott, say you're bumbling around on Shodan and you bump into one of these pieces of equipment that controls the water treatment in this town. Would we expect that this is gonna be locked down in some way? How are you gonna go about taking control of that?
Speaker 3: Oh, it would depend on, you know, what information was available to me. You know, if it was just on Shodan, like, I guess my gut instinct is is like you're not really gonna gain access to the SCADA equipment, DOT stuff. You're gaining access to the PC that's controlling it, and chances are that that PC, had the vulnerability prior to the person finding it. Like, it would be it would be more believable to me that this was a random encounter where somebody randomly ended up on this computer and was digging around looking to see what it was, and and accidentally turned up turned the valve, turned the knob up. Because to me, like to go from, what was it, a 100 or 11 parts per million to 11,000?
Speaker 2: Yeah. It was a 100 parts per million to 11,000 you
Speaker 3: got. Yeah. So, like, those are relatively similar numbers. Like, it wouldn't it wouldn't surprise me if, or like, similar in structure. I either contains ones and zeros. Mhmm. You know, somebody who has no idea what they're doing, stumbling around a computer inside of a SCADA controller, like a a valve control system, accidentally, like, changes an input field.
Speaker 2: Here's the thing. This is still early enough that that might turn out to be what happened. There's a couple more interesting data points that come up, but that is super interesting that it could just be a mistake.
Speaker 3: Yeah. Like, I don't, knowing a bunch of people that operate and exist in this space, you know, trying to poison and kill a bunch of them is just not, I don't think any, like, you know, there's already enough legal punishment for cybercrime as it is. I think once you get into, like, colossal grade militia, like, when you're, like, maliciousness, like trying to impact the lives of thousands or tens or hundreds of thousands of people in a negative, negative way. Like, the criminal penalty for that is astronomical.
Speaker 1: Well, of course, it could be some federal charges. A lot of it would depend upon, there's a lot of things. Of course, there are state felonies, that would absolutely apply and it would be a felony offense.
Speaker 3: Like, you either have to be a bent sociopath looking to, like, destroy the world or, you know, you're just an idiot. It's one of the two.
Speaker 2: I told you the story was pretty dumb. So you used to phrase earlier that what is really relevant here and you said, what inform this all depends on what information is available to you. Right?
Speaker 3: Yep.
Speaker 2: I think it's gonna come up in a second here.
Speaker 1: Here. Obviously, these investigations are very, complicated. Right now, we do not have a suspect identified, but we do have leads that we're following.
Speaker 2: So as the days click on and the FBI investigates further, they make another discovery. And it kind of happens in the second wave of press about the story. And that discovery starts to clarify what this actually might be. You know, when we talk about Shodan, that sort of seemed like a viable explanation early on. It's why people speculated that that's what happened. Someone discovered this. And, it's kinda compatible with the energy of that press event. You know, there's a paranoia in that event of this idea. There's a bad actor out there lurking around and they discovered us, and they were just waiting to strike and they saw the opportunity and they took it.
Speaker 1: Because of this security breach, we are asking that all governmental entities within the Tampa Bay area with critical infrastructure components actively review their computer security protocols, and make any necessary updates that are consistent with the most up to date practices.
Speaker 2: But three days after that initial press event, the FBI and the state of Massachusetts both released their reports on what happened, which I thought was pretty fast. It kind of seemed like someone just sort of stepped inside immediately, saw what was going on, and then just published these reports. And there's a line in the Massachusetts report that I I read twice, quote, all computers used by water plant personnel were connected to the SCADA system and used the 32 bit version of the Windows seven operating system. Further, all computers shared the same password for remote access and appeared to be connected directly to the internet without any type of firewall protection installed without getting into the windows seven thing, which for context, I think Microsoft stopped updating this year and probably shouldn't be on any kind of critical equipment.
Speaker 3: Yeah. That's correct. You know, Windows seven's kind of seen its lifespan and, you know, Windows 10 is a much, much better product. So, if you haven't upgraded, you should.
Speaker 2: Without getting into that, the second half of that quote again. Further, all computers shared the same password for remote access and appear to be connected directly to the Internet, Which means that any employee who knows their own login for remote access also knows the login for remote access to the super sensitive machine that controls what goes into the drinking water.
Speaker 3: Well, it also sounds like every computer had access to the super sensitive control unit that controls how much goes into the drinking water.
Speaker 2: The computer in question had TeamViewer installed, and all computers use the same remote access password. So it kinda paints a pretty clear picture of what happened here.
Speaker 3: Poor cybersecurity infrastructure?
Speaker 2: Unpack that more. You mean that could have prevented it?
Speaker 3: Oh, yeah. Absolutely. Like, a mission critical computer that controls something like that probably should be air gapped. Just saying. Like, you know, when you wanna start fiddling with what goes into the water supply to the citizens of a town or a city, you probably wanna show up and on-site to do that. You know, that's something that requires you to leave your house. It should require you to leave your house. You know, that's not that's not something that I would trust to to to be just wildly open to the Internet. Not having a firewall, also completely reckless. But but I would actually go one step further and say that TeamViewer specializes in bypassing firewalls by using, you know, ports that are typically left open or or different protocols. So I don't even know if that would have blocked it, but still.
Speaker 2: FBI Massachusetts both immediately honed in on the idea that this was a disgruntled employee logging in and mucking around. Verge, summarized it nicely asking, can you really even call this a hack? Which I thought was a super interesting way of summarizing it.
Speaker 3: Yeah. But even then, like, you know, you'd have to be a pretty disgruntled employee to try and, you know, hurt. Like, you'd have to be a pretty messed up person to try and hurt that many citizens. You sure would. And if you were a disgruntled employee, chances are you'd know that there are other mechanical catches and alerts and alarms that are gonna prevent whatever you're doing from actually causing an impact. Or, at least, you know, from immediately causing an impact.
Speaker 2: It's an interesting question you post, Scott, of what kind of person would actually try and do this. And I wanna talk about this right after the break. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify dot com slash hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 5: Have you heard about these kind of attacks happening at other agencies around the country?
Speaker 6: I I think we anticipated that, you know, this day was coming. I I can't tell you that I know a whole lot about those I've that we've confirmed have already happened elsewhere. But, you know, we we talk about it. We think about it. We study it. But as far as the specific, I I'm not aware of one right now.
Speaker 2: So I wanna work backwards in this section, with some case studies about exactly what kind of person we're talking about here. And I wanna start about as far away from this hack as we can go. And to do that, we have to go to the Ukraine. Right around Quinton time, December 23, five years ago, inside the Pyirkar Patio Ablenergo Control Center.
Speaker 3: Haven't heard of that one yet.
Speaker 2: Inside a Western Ukrainian control center. Popular tourist site. If you haven't been to Pyar Kapetaklunurgo, you haven't lived. The operator of the center sits down at their desk and they watch as their mouse, you know, skitters across the screen. But unlike Oldsmar, which was a water treatment facility, the Western Ukrainian Control Center was a power center. But otherwise, exact same thing happens. The hacker wrestles away control of the mouse, grabs control of something on on the screen, in this case, a circuit breaker, and they actually start turning them off, plunging thousands of people into darkness. Do you remember this story, Scott? I do not. It's super fascinating. And what's really interesting about what happened in the Western Ukraine isn't that a hacker took control of the computer. We watched someone in Oldsmart do that quite easily, about as easily as you'd, like, sneak into a garage if you knew where the key was.
Speaker 3: Was it that they were also using TeamViewer?
Speaker 2: I couldn't verify that it was TeamViewer, but the one white paper on it I read did think that it had to do with remote access software that was intentionally installed. Yeah. So who knows? That's a bit ambiguous, but they use the same basic technique. They just can't took control of the mouse. But I think what's really interesting about what happened in the Western Ukraine, is how small a part of how big what was actually going on this moment of taking control actually was. Like, taking control of the mouse was actually just one tiny part of three simultaneous attacks on these centers launching all around the region. It had been planned for months. They'd embarked on a spear phishing campaign to get the right credentials, and the whole thing worked pretty much perfectly. Unlike Oldsmar, it went off without a hitch. Since then, Ukraine has been the victim of what one writer called a digital blitzkrieg of cyber attacks that are almost certainly coming from another nation state.
Speaker 3: I I wonder I wonder who would be attacking the Ukraine.
Speaker 2: Good question. It's thousands documented every year against their energy systems, their financial systems, their transportation, all of it. It is it's an ongoing, like, digital cold war that they're the victim of. But it all started and all came back to someone just taking control of some remote access software and messing with the knob that controlled physical infrastructure, just like Oldsmark.
Speaker 3: Mhmm.
Speaker 2: But a nation state doing something malicious is still different than the the, the individual actor, the person that you asked who would do something like that. Right? Like that's just a different kind of thing.
Speaker 3: Totally.
Speaker 2: So our next stop on our tour of people messing with public utilities of large groups of people for really confusing reasons, brings us pretty far from the Ukraine, all the way to the Australian shire of Maruki. You are Australian. Do you think I'm saying that right? Maruki?
Speaker 3: Yeah. Actually, it's probably pretty close.
Speaker 2: Maruki.
Speaker 1: Maruki.
Speaker 2: So a guy in Maruki named Vitek Boden applies for a job with the Waste Management Authority.
Speaker 3: Wait. His last name was actually Boden?
Speaker 2: Oh, what does Boden mean?
Speaker 3: Well, Bogan is a Aussie slang for, like, essentially redneck. So to have the last name Boden is pretty damn close to Bogan. And if he lives in a a shire called Maruki, well, you know, you can probably put one and one together.
Speaker 2: Bowden the Bogan from Maruki? Yeah. So Wieseck Boden applies for a job with the Waste Management Authority. And he previously worked for an external contractor, it seems like, and he sees this job go up and it seems like a nice place to work from his, you know, experience with them, so he applies for the job. Witek does not get the job with the Waste Management Authority and it would seem this really really pisses VTech off. And based on his old job working with Waste Management he technically has access to some remote desktop access software. So, can you guess what VTech does?
Speaker 3: Messes with the waste management facility?
Speaker 2: Like the Oldsmar culprit, he took control of the system and he flicked a switch. But again, unlike Oldsmar, this all worked. VTech dumped, quote, millions of liters of sewage back into local parks, rivers, and the grounds of a Hyatt Regency hotel. Quote, marine life died, the creek water turned black, and the stench was unbearable for residents. So Janelle Bryant of the Australian EPA.
Speaker 3: What the heck?
Speaker 2: Hang on. Two years in prison for that.
Speaker 3: Only two? That's crazy. These peep these people fascinate me.
Speaker 2: It's such a strange use of that kind of capacity because we talk about this stuff so much that that seems kind of like, yeah, they took access of some remote desktop access software. But for I think a lot of the population, that is a level of, like, sophistication that to use it to dump poop into a creek and like mess up a town's life for a couple months is just such a strange choice.
Speaker 3: Well, the the other thing is too is like, you know, life lesson here. Life is full of rejection. And if you're so poor at accepting it and and dealing with rejection that you have to do something like that to like, you know, feel better about the fact that you've been rejected, then you probably should spend more time in a mental health facility than a jail.
Speaker 2: Yeah. That's an interesting point. So we got the Ukraine. Right? This massive coordinated attack using this this technique. I wanna hone back in on the technique. Ukraine, giant attack using this technique and succeeding. Next story, we have a disgruntled employee using the same technique as the foundation of, like, a still larger hack, kind of this weird revenge campaign, and they still succeed. And now, this month, we have a person sort of casually bumping into this vulnerability and deciding to mess around, maybe trying to do harm. It's hard to tell. Mhmm. All centered around this one technique. When you look at these as a set, like, where does your head go? Do you see any patterns?
Speaker 3: Remote access trojans. You know? Not saying TV viewers a trojan because it isn't. It's usually willfully installed. But remote access trojans are typically, you know, classic Windows pack, and UNIX, too, installing back doors into UNIX systems. But like a remote access trojan is, you know, as old as the book. You know what, we've talked about it before, but I think BO2K was the one that made it super famous. And, you know, you had kids getting their friends to install it so that they could open their CD drive and take control of their computer remotely. And, you know, that was, like, a big thing where people were like, wow, you know, this is super powerful. You can very easily build and deploy a remote access Trojan. And, you know, with things like remote desktop, like, obviously, remote desktop is a little bit more secure, uses the whole, you know, Windows infrastructure for security, things like that. VPNs usually house those infrastructures, so you have to connect to the VPN. A lot of them have multifactor authentication, etcetera, etcetera. TeamViewer is a much more, like, recreational product. Not recreational, but, like, you know, personal, prosumer.
Speaker 2: Sure.
Speaker 3: It's not a full security infrastructure, like something like the Microsoft Suite. Where so you just get TeamViewer showing up on Windows PCs everywhere. And, essentially, TeamViewer is, you know, a remote access trojan, but it's not a trojan in the sense that it wasn't disguised. People willfully install it. And IT infrastructures leverage it because it provides really easy remote access to the all the PCs that they have to manage, you know, etcetera, etcetera, etcetera. So it's it's it's super commonplace. But, yeah, remote access is, I think, one of the oldest parts of, like, network hacking, like hacking network PCs, because usually when you get into something, you want to come back to it. Remote access is, I think, as far as network network computer hacking goes, is probably one of the the staples. So
Speaker 2: I think almost a year ago exactly to this episode, you made a bit of a prediction. And you talked a bit about how the increased reliance on remote access was gonna lead to vulnerabilities. That is we all have to rely on remote work because of what's happening in the world. That increased reliance is gonna up the number of these incidents. And I I think this is kind of seeing that prediction a little bit being realized. When I look for a pattern, I see if not something getting easier, then, like, more common. The more devices this stuff is installed in just sort of law of large numbers, the more we're gonna see these kind of events happen.
Speaker 3: Mhmm. Well, thank you, Jordan.
Speaker 2: And in a sense, the sheriff from that opening cliff kind of had the right point. He was talking about, you know, how we all need to be on blast because there's all these really high level malicious hackers out there. And And, I don't think that's really what happened here, but he was kind of right that, you know, this should be a warning. We're all kind of on blast here a little bit. I think very rarely is the message of this show as simple as keep your cyber security hygiene up. But, like, maybe a year into our collective journey towards this, you know, remote work present future, whatever you wanna call it. It's sort of maybe looking back on all the junky solutions we've cooked up throughout the last year and thinking about, okay, how do we make these these work in the long term? Because I don't think they are.
Speaker 3: Yeah. There's definitely gonna be underfunded IT and IS departments out there that have flaws and vulnerabilities. I I feel bad for them. You know, I think everybody most most senior IT people, experienced ones know, you know, kind of the fundamental rules of Internet security and information security. And, you know, the problem is that it's time intensive, cost intensive, requires perpetual management, can create other headaches to deal with. So, like, something as simple as, you know, a complicated, a multi factor VPN, Mhmm. You know, adds tons of management and support requirements. You know, it's just the more the better job you want to do, the more it requires. And, I think that that's probably a problem too, is people are hitting capacity or, you know, companies are are thinning down on overhead expenses like IT and IS. So yeah. Mhmm. I I 100% agree with putting everybody on blast.
Speaker 5: But, the important thing is to put everybody on notice. And I think that's really the purpose of today is to make sure that everyone realizes this this kind of bad actors are out there. It's happening. So really take a hard look at what you have in place.
Speaker 2: Thanks for listening, everybody. Sorry for the delay in this week's episode. It's been, pretty busy in the old personal life. We usually come out last Tuesday of the month, and you can expect us to be back on that schedule again in March. If you want to support the show, rate, subscribe, and tell folks about it. You find us on Twitter at hacked podcast and you can support the show on Patreon at patreon.com/hackedpodcast. Thank you very much for listening, and we're gonna catch you on the next one.
Speaker 7: Lots of places can expose you to identity theft. Oh, no. That's why LifeLock monitors hundreds of millions of data points a second for threats to your identity, which is way more than anyone can do on their own. If we find anything suspicious, like new loans or changes to your financial accounts, we alert you right away, all through text, phone, email, or the LifeLock app. Get the alerts that could make all the difference. Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 8: Summer weekends are all about family, sunshine, and making memories together. Before everyone arrives, I stop by my local Total Wine and More to pick up a great bottle, maybe a favorite we already love, or something new to enjoy with dinner on the patio. With so many bottles to choose from, it's easy to discover something amazing. And with the lowest prices, it's easy to grab an extra bottle for the table. Not sure what to pick? Their friendly guides are always there to help. Find what you love and love what you find only at Total Wine and more. Curbside pickup and delivery available in most areas. Visit totalwine.com to learn more. Spirits not sold in Virginia, North Carolina. Drink responsibly. Must be 21.