Never Let a Good Crisis Go to Waste
TL;DRDuring COVID-19, hackers exploited mass remote work transitions, corporate layoffs, and public fear as cover to breach weakened IT infrastructures and social-engineer overwhelmed help desks—mirroring classic distraction tactics like the…
Jordan Bloemen & Scott Francis Winder discuss coverfire, smokescreens, and how to never let a good crisis go to waste.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: It's summer in Stockholm, and the streets are lined with burning cars. It's the early hours of a foggy morning back in 2010, and a small army of police and firefighters are rushing to the scene of a spontaneous mass arson. Arson. Someone, for some reason, has set a bunch of cars on fire. No one knows who, no one knows why, only that around 02:00 in the morning, the streets of Stockholm suddenly lit up with the crackle of, well, it's Sweden, so presumably a bunch of burning Volvos. Emergency response arrives on-site, they put the fires out, and Stockholm is calm again. During that window of time, just six or so minutes, when the attention of Stockholm's police force was drawn to those burning cars, this whole other story was unfolding. A heist that those cars served as a distraction for. Miles away at the Swedish Royal Residence, windows shattered at the Chinese pavilions, and a crew of bandits raided a permanent collection of art and antiquities. They fled to a nearby lake and vanished by speedboat. They set the cars on fire so no one would notice as they robbed the Royal Palace blind. This isn't really about that heist, which you should look up. It's like one of dozens around the world, whole big thing, very interesting. It's about the cars, the distraction. Because if you want to understand how so much cybercrime, so many hacks go sight unseen, you gotta ask, where's the burning Volvo? Like on Christmas Eve twenty twelve, when the business controller of a Sacramento construction company went to log in to their corporate bank account to find nearly a million bucks missing from their bank, which was conveniently being distracted by a DDoS attack launched by the same hackers. Burning Volvo. Were similar smokescreens employed in hacks against Wells Fargo, Bank of of America, and Citibank burning Volvos? Or right now, as the whole wide world is paying attention to one very specific crisis, and a bunch of people are figuring out how to take advantage of this once in a lifetime burning Volvo. This is smoke screens, cover fire, and how to never let a good crisis go to waste. On this episode of Fact.
Speaker 2: CBS News got exclusive access to this global operation center where the Secret Service is tracking the spike in coronavirus cybercrime.
Speaker 3: Anytime there's a heightened element of fear, such as with the coronavirus, criminals are going to exploit that. The threat actors are going to take advantage of the situation and milk it for all that it's worth.
Speaker 2: With more Americans working from home in the weeks ahead, the Secret Service says the risk will only increase because a personal thematic
Speaker 4: sense to what's going on
Speaker 2: in the world now. You know? We talked
Speaker 4: about the thematic sense to what's going on in the world now. You know? We talked about the Iranian malware, and then in the subsequent episode, we talked about the shutting down of Shadow Server. And I can't help but feel like they're both related to the same thing, what's going on in the world right now with this pandemic. You know, Cisco being a major corporation with major corporate expenses, probably looking at ways to save money and focus more on core operations, you know, completely hypothetically. And that could
Speaker 1: have been what led to the removing of the funding to
Speaker 4: keep shadow server going. Meanwhile, we've got the Iranian government taking advantage of this crisis to jack malware onto the phones of all of their nation's citizens. And this just leads me to the the thing I wanted to talk about today, which is, like, you know, never letting a good crisis go to waste. Essentially talking about, you know, when you're when you're looking to hack something, timing is as important as technique. And when we talk about cover fire, you know, in the DDoS episodes discussing, you know, how you can use them to distract IT infrastructures and IT service departments, away from paying attention to the security infrastructure, that's essentially what's going on today. Like, you can imagine with billions of white collar employees moving to a work from home basis, security infrastructures that have been fine tuned and tweaked for years are literally being dismantled to allow for this new world to operate. So I kinda just wanna talk about, like, if you were gonna be hacking something, now is probably a pretty good time for it.
Speaker 1: You said cover fire. Can you talk to me a little bit about what that means?
Speaker 4: Yeah. Cover fire is just a way to keep people in their holes or to keep people distracted so they don't notice what you're actually doing. You know, in the classic war movie where the guys gotta make a break across the field to get to the hole, everybody starts spraying bullets, you know, wasting ammunition, but, essentially, it's done to keep the opposition in their trenches so that they don't notice this person sprinting across to get to the, you know, target.
Speaker 1: Mhmm. So the idea there is that the whole world right now is covered fire. The whole world is just spraying ammunition, and it's a really, really good time for someone to try and book it across the front line.
Speaker 4: A 100%.
Speaker 1: K. So, in a practical sense, let's talk about that. You talked about this idea that we we have got a whole bunch of companies all around the world, and they've got a very probably well built out IT infrastructure.
Speaker 4: Definitely. And they've probably spent years fine tuning, adding in, you know, separate pieces of of verification, authentication, network security controls, you know, all of this stuff to prevent and detect intrusion, locking down the fort. You know? They've probably been building walls and tightening them and supporting them for years.
Speaker 2: Mhmm. And
Speaker 4: then all of a sudden, they have to send, you know, 27,000 staff home, and they have to just knock the walls down.
Speaker 1: Talk to me about what kind of vulnerabilities having a bunch a huge chunk of our workforce suddenly working from home introduces into otherwise relatively secure IT infrastructure.
Speaker 4: Well, I think the the first thing that I would look to exploit is the social side of it. You know, I don't walk down to the, IT department anymore to ask for things. I have to call down. There's no real way to verify who I am via a phone call. So if I have a staff directory for everyone that works at a company, probably a pretty good chance that I could call enough IT people and convince one of them that I'm somebody I'm not and get things that I shouldn't. Mhmm. Does that make sense?
Speaker 1: Yeah. It does make sense. The basic idea is that when the ways that people work together, those sort of, like, soft security measures, get completely reworked, it creates this sort of, of, this negative space where someone can social engineer their way through, and get into a system they're not supposed to be in.
Speaker 4: Totally. And, like, the you know, from a geographic perspective, when you have local networks, you know, they're pretty locked down. You know? When your access to a network requires geographical, you know, connection, so I have to be here to plug into the port on my desk or on the Wi Fi that's thrown around with my office. You know? When you have to start letting everybody go to working from home, you start talking about massive VPN infrastructures, you start talking about stuff like this. And if these companies didn't have it, you know, they're probably struggling and rushing and, truthfully, probably making some mistakes and leaving vulnerabilities, and not because they're bad at their jobs, but just because of the velocity they have to be operating at.
Speaker 1: As someone who knows, generously nothing about IT and setting up a network for a business, explain to me in, like, broad, broad 10,000 feet, strokes what the difference between my home Wi Fi network and the way I would be working from home. How is that different from a big company with its own network? It from my perspective, I've got a laptop and I'm connecting to a Wi Fi network or I'm sitting at my desktop. It doesn't really seem like it's that different. Talk to me about what's happening behind the scenes that makes that more secure than working from home.
Speaker 4: So the big thing is is, you know, when you're when you're a trusted member of a network. So if you're in the office and you brought your work designated laptop and it's plugged into a work designated Ethernet port and you have access, all of your credentials have been rolled up by major, you know, access control servers. You know, you can see the f drive and the u drive and the etcetera, etcetera. You know? You can boot up your ERP for the company and connect to the database servers.
Speaker 3: All of
Speaker 4: a sudden you go home and you don't have any of that infrastructure. That infrastructure all exists inside of that building. So they need to open up holes in the firewall to let you start to connect to that infrastructure. That's probably where the first big problem begins. There are very good solutions for it. You know, corporate VPNs are a thing for a reason, and that would be one of the main solutions. And I'm sure there's companies that didn't have huge VPN infrastructure do now, and are probably rolling them out actively. But I think that basically answers your question.
Speaker 1: Yeah. I'm a business, and I've just sent everybody home, and we're all working from on Slack or whatever.
Speaker 4: Mhmm.
Speaker 1: What kind of things should they be thinking about for making sure that they're secure during all this?
Speaker 4: I think the like, I trust, like, the VPNs, and I trust that a lot of these major, you know, hardware software service providers, the Microsofts, the Ciscos, will provide solutions that allow these companies to continue to operate in a secure fashion. I think, you know, for me, the number one thing that I'd be looking at targeting would be the social confusion that spins out of this. You know? Has the IT help desk person ever met Darcy from Houston? No. Probably not. Can I be Darcy from Houston? Yes. I probably can. And I you know, that would be probably the first place I would start. So having some form of you know, we talked about two factor authentication when it came to, you know, cell companies and SIM swapping. You know, what is the corporate human version of that? It can't be go to the office anymore. So what is it now?
Speaker 1: There's another side of this that feels like it creates, just as potent a vacuum for social engineers to be able to sneak through. It's people who haven't been sent to work from home. It's just people who've been laid off. Yeah. Just, like, huge unemployment right now, and you've got a bunch of people sitting at home. What kind of, an opportunity does that create for, you know, cyber criminals basically knowing that, okay, we've got a bunch of people who are out of work, who are sitting at home on the Internet. I think of, like, money mules. I think of all these different things that just rely on someone needing money, needing some legitimate way to make bank. What kind of opportunities does that create for the social engineer oriented hacker?
Speaker 4: No. That's that's a great question. But, actually, I think you brought up something that I kinda wanted to hit a bit more, in regulation of what we're just talking about, which is when you have bulk layoffs, which is what we're seeing, you know, there's rumors that, like, nine and a half percent of The US population was laid off last week. And I don't this will be airing the week after. So two weeks ago, 10% of The US population was theoretically laid off. That's an overwhelming amount of people for an IT department. Like, if you imagine disabling access to emails, disabling proximity key access, you know, when we talk about crimes of opportunity as this episode's kind of, you know, themed at, that's a massive crime of opportunity because there's a good chance that a lot of people laid off still have access to their corporate networks.
Speaker 1: K. So before getting to the question that I did ask, which I do wanna get to, what should the top priority for IT professionals be right now? They show up to work on Monday. What is the thing that they should really be thinking about?
Speaker 4: Well, I think, you know, being somebody who spent a decent amount of time in IT, your top priority is whatever the company's top priority is. And that might not be security right now, which is why the crime of opportunity is a thing Because the company is being put into this insane amount of pressure to continue to operate, to continue to deliver, to continue to sustain given what's going on. So, really, your focus is is on facilitating operations,
Speaker 1: not
Speaker 4: security. So I think if I'm an IT person getting to work on Monday, assuming I'm still going to work, figuring out and making sure that as many of the people that I work with can continue to work is probably my top priority. And security will be the b, c, d, e, or f on that list. Hence, the cover fire. You know, there's such chaos going that the cover fire is for free right now. Sure.
Speaker 1: So if
Speaker 4: you were slowly kind of infiltrating a network or doing something or setting up some hack, now's a great time to do it. Mhmm.
Speaker 1: I wanna talk a little bit about how and this is true in terms of the current situation we find ourselves in, but I think it's true, like, all of the time, is that when people are desperate for information about something, that seems like a really good opportunity to, that's a situation you can take advantage of. Right?
Speaker 4: Yeah. Well, I think, you know, that goes back to survival. You know, we're all kind of loosely transitioning into this odd form of survival. We know be that some people are doing different things. Some are fighting over toilet paper. Others are, you know, not spending any money and hoarding cash. Some are, you know, dumping more money into the stock market because they think it's low, and they think that they can make back their losses. You know? Everybody's kind of dealing with this sense of survival that's been kind of imposed on us by what's going on. Mhmm.
Speaker 1: So you present someone with an opportunity, that will make it easier for them to navigate the situation. You might be able to kinda get past their defenses a little bit.
Speaker 4: Totally. Like, you know, we're talking about vulnerable populations growing exponentially. You know? People who are unemployed or out of work, you know, weeks ago was the lowest number in American history, is now going to be probably the highest in American history within the matter of weeks. Mhmm. So when you have an exponential explosion like that, not only in, you know, viruses, but virus cases, but in just vulnerabilities, like, we're gonna have that's there's gonna be a social cost to that. And, you know, whether that's, whether that's exploitation or whether it's, you know, just bad things going on in society, people are just mostly going to be going into survival mode. Some people who, you know, sociopaths, will see opportunity in this and will be taking advantage of it for, you know, their own reasons, hacks, etcetera.
Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all ecommerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 5: Sierra has all the best active and outdoor brands for the super athletic stuff, like running gear for cruising up the trail. Woo. And the super athletic stuff, like fish and gear for chilling by the creek. Nice cast. Fitness apparel to push for higher reps. You got this. And golf balls priced so you could afford to lose one or a few. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.
Speaker 1: Okay. So I wanna talk about cover fire outside the context of COVID. Let's just imagine we live in in the four times.
Speaker 4: I'm sorry. I guess pre pre November.
Speaker 1: Sure. Talk to me about the different types of cover fire. So, like, we've been talking about, a massive news story
Speaker 2: Mhmm. Kind
Speaker 1: of, like, people are hungry for information, opportunity, economic of people who need money
Speaker 2: Mhmm.
Speaker 1: And then this weird outlier situation of, IT networks having to flex to have people work from home. Yep. What other kinds of cover fire exist? Giant distractions, giant things that, you know, people just can't look away from and create opportunities for cybercriminals?
Speaker 4: Well, I think in the in the classic, like, tech hacker sense, cover fire
Speaker 2: will
Speaker 4: be something that just pulls away security resources or causes infosec teams to have to let their guard down. You know, very similarly to, like, what we're talking about now where it's like, hey. The world's different. People aren't coming to the office. We have to let our guards down to facilitate these new operations. Things are things are happening. So any any semblance of that becomes cover fire. So, you know, the classic, hey. Our corporate network's being hit with this massive DDoS attack leads to the technical staff having to deal with, address, mitigate that problem. And they might not notice you squeak, you know, four and a half gigs of data out the back door. So that becomes the essence of cover fire. So in today's sense, you know, lots of things can be cover fire. I'd say you have to be pretty smart about it because if your cover fire leads to new security policies, new lockdowns if the cover fire stimulates a change in the IT and infosec infrastructure that'll actually hurt your actual hack, that's a bad thing. So you have to really kinda think about and plan what you wanna do for cover fire.
Speaker 1: Sort of like, it's kinda like close-up magic. You need to make them look over here while you do something over here.
Speaker 4: That's literally that is the the hacker version of cover fire. Pay attention to this problem over here. Focus on this while you don't notice what's going on over here.
Speaker 1: Right. It's the DDoS attack and the opening story from that Sacramento bank.
Speaker 4: You know, that's the the perfect example of this, you know, dealing with, human level crisis. Because, really, DDoS ing the website, not the end of the world, but it would have thrown the organizational into a crisis, which would have caused people to make, you know, decisions that probably would have been in a higher level of scrutiny if that crisis weren't to be going on. So, you know, they threw a bunch of, EFT requests in, you know, move money here, here, and here. Upon scrutiny, calling the client probably would have been a part of that scrutiny to verify that they were, you know, real transactions. None of that was done because they were dealing with this other crisis. It's perfect cover fire. You know? Create a create chaos, and then in that chaos, leverage people's reduced ability to make sound decisions.
Speaker 1: As a hypothetical, say, I wanna hack a software company. What kind of take me through that. What kind of cover fire would I be looking at to do something like that?
Speaker 4: Sure. So let's think, you know, a couple years ago, I think I mentioned this in one of the first episodes of Hacked, the first season, quote, unquote season, is somebody had hacked into a software company and gotten actually control and was embedded in their development infrastructure. So they were actually playing and tweaking with the source code that would then become the production releases of the software. So, like, let's think of a great beneficial use case for that. Let's assume we had a backdoor into password managers. Tie in another episode of old hacked. So say we want to hack into one of the password manufacturers software code and add our own backdoor. So what would distract everybody inside of the password manager's company, not just the IT staff, but the development staff too to not be as secure. Say we had spent months researching the password manager that we were looking to get access to. Say we tested their network. We had found some vulnerabilities, and we kind of knew when we could punch through. Maybe we release, you know, a hack for their password manager or a security bug to the market, and we showcase it, Defcon, throw a paper up, put it in the dark web, wherever, causes the entire company to go into hysteria because they don't want you know, they make something that's sold on the grounds of security. And if we can come out and say, hey. It's not that secure. The development teams are gonna be hot patching it like crazy. The PR corporate and overhead people will be dealing with the social crisis of it, marketing aspect of it, and the tech people will probably just be looking to, you know, support in any way possible. So that's good cover fire. A social crisis that's kind of spinning the corporation into survival mode, quote, unquote, as well as sending the developers, you know, into a a frenzy to patch and fix this problem. They're probably not gonna be looking at their, commits, their git commits or, like, you know, whatever they're using for versioning control. They're not gonna be paying as close attention to it. So that would be a perfect time to slide in and kind of set yourself up in their development world.
Speaker 1: So the idea is, like, you find you're you're trying to hack someone. You find the vulnerability that you like. You think this is the way into their system that they're never gonna notice. Mhmm. What you then have to do is as you're developing that vulnerability, go find another vulnerability over here, work on that in earnest, and then show yourself in some way, shape, or form, either by leaking it to other cyber criminals, either by publishing something, so that everyone snaps their focus over to that, like, a spotlight, and you've got this this other road in.
Speaker 4: Yeah. Well, imagine the, you know, the YouTube video you referenced in one of the news updates, the Wi Fi, the crack, thing. Imagine what happens to that chip maker the second they see a video like that. You know, that becomes an internal crisis, which becomes beautiful cover fire if you wanted to do anything else. So I would be looking to do something like that. And the beauty is too is, like, I remember the last time this happened, I think it was a firewall manufacturer where somebody had gotten in and had access to their development stack. They didn't find them for years. So you imagine, you know, imagine a firewall or a password manager or some other piece of, you know, secure software that people lean on for their security, having a serious hole in it for years, and having the ability to tweak and play with it as you wanted.
Speaker 1: So amongst IT professionals, like info sec type folk
Speaker 4: Mhmm.
Speaker 1: When they when something goes catastrophically wrong, when everyone is suddenly, okay, there's a giant problem we have to address, is there, like, a school of thought that that's the moment you should be, like
Speaker 4: Stepping back and thinking about it.
Speaker 1: Being really, really critical. Because on one hand, you you do have to address that issue. If there's cover fire, you have to hide behind some something.
Speaker 4: I I think the question you're asking is less about infosec procedure and protocol and more just about human nature. When you throw people into a crisis, you know, people people react totally differently. I remember being in in university, and in one of my org b classes or something, they made us do a test to see how well we dealt with adversity. And it was part of it. You know, apparently, a lot of strong leaders deal with adversity very well. So there was this very calculated test that we took to see when put into stressful situations, how you reacted. And, you know, I think that that's probably more of just the human model. You're hacking the human model. Cover fire is hacking the human model.
Speaker 2: How do
Speaker 1: you keep up your defenses when someone's just blown a hole through them?
Speaker 4: Well, I think that the hole that they blew in our defenses is by just reducing our ability to make, good decisions. And so it's it's you know, once you've impaired that in somebody, you know, you don't really need to do much else. So,
Speaker 2: you
Speaker 4: know, I think that that's a big part of the cover fire thing. It's just impairing people against making their best decisions. So, you know, I think we're seeing that today, and I think we'll see that going forward. And I think, you know, that's just a part of reality. Because, you know, humans are, as I've said before, often one of the most vulnerable parts of a chain. There's only so much securing you can do that a human can't undo very quickly.
Speaker 3: I'm Gwen Washington, host of Snap Judgment, the award winning storytelling podcast from KQED. And every week, Snap deals a new card, like jumping on Rihanna's private plane, or the accidental bank robber, or even the man who was swallowed by a hippo. What? Pick a card, any card. Tap to listen now to Snap Judgment from KQED on Spotify.
Speaker 6: Have no fear. Chosen Foods is here to defend your favorite foods from the forces of seedy oils and sketchy ingredients. With cooking oils, salad dressings, and mayo, all powered by the good fats from 100% pure avocado oil and simple delicious ingredients, chosen foods.