Video summary
The podcast features Joe Tidy, a journalist and author of *Control Alt Chaos*, discussing the evolution of cyber crime from teenage exploration to organized financial exploitation, with a specific focus on the "Scattered Spider" collective responsible for recent attacks on major UK retailers like M&S, Co-op, and Harrods. These groups are described as loosely coordinated collectives that operate primarily through platforms like Discord and Telegram rather than traditional criminal organizations. Tidy argues that social media dynamics, particularly Twitter's emphasis on followers and clout, alongside the rise of Bitcoin in 2013, shifted hacker motivations from benevolent curiosity to seeking fame and illicit profit. This shift is exemplified by groups like Lizard Squad, which targeted gaming services during Christmas 2014 for attention rather than money, whereas modern gangs utilize cryptocurrency's anonymity to launder funds and evade law enforcement. The discussion delves into the mechanics of these attacks, highlighting that entry often relies on social engineering—such as impersonating IT staff via phone calls or tricking employees with malicious email attachments—rather than complex code-breaking seen in movies. Once inside a network, attackers deploy ransomware to encrypt data and demand Bitcoin payments, causing significant disruption ranging from empty supermarket shelves to paralyzed hospital systems. Tidy illustrates the human element of cyber security by recounting how hackers often fail due to arrogance or laziness; for instance, Julius Kamaki (also known as Ryan), identified as one of history's most hated hackers, was caught after accidentally uploading his entire home directory and 33,000 patient records from a Finnish psychotherapy clinic. His subsequent disappearance while on bail suggests a sociopathic detachment where causing chaos is the primary goal rather than financial gain or technical mastery. Tidy also explores high-profile state-sponsored operations and their potential impact on critical infrastructure, such as Stuxnet, which targeted Iran's nuclear centrifuges by speeding them up until they broke, and NotPetya, an uncontrollable worm that caused over a billion dollars in damage globally while pretending to be ransomware. The conversation extends to the risks of autonomous vehicles, noting that current self-driving cars face significant security challenges due to their reliance on connected systems; Tidy shares anecdotes about Waymo vehicles being ignored by human drivers and Tesla's aggressive driving styles derived from training data. He references *Robo Apocalypse* as a cautionary tale where AI takes over driverless fleets to eliminate humanity, emphasizing that while current autonomous tech is secure for now, the convergence of physical mobility and digital connectivity creates new vectors for catastrophic cyber warfare. Finally, the episode addresses the broader geopolitical implications of cyber crime, including the difficulty in tracking perpetrators across borders and the limitations of regulation compared to rapid technological evolution. Tidy recounts his dangerous undercover mission to Russia to interview members of Evil Core, a family-run criminal enterprise led by Maxim Yakubets, highlighting how Western accusations often lack direct engagement with the criminals themselves. The segment concludes with advice on personal security, such as using password managers and enabling multi-factor authentication, while acknowledging that even robust software updates can fail catastrophically, as seen in the CrowdStrike incident where a benign update bricked millions of systems worldwide. Ultimately, Tidy stresses that despite emerging threats like quantum computing breaking encryption by 2030, fundamental human behaviors—such as falling for social engineering scams or reusing passwords—remain the primary vulnerabilities exploited today.
Read the full video transcript
What's happening with Scattered Spider?
Well, Scattered Spider is the name of
this very loosely coordinated collective
of hackers that are, we think, currently
causing havoc around the UK and the US
as well. So, I don't know if you've
heard about the news of the M&S cyber
attack and the co-op cyber attack. So,
um there's a really big, if you're not
in the UK, there's a really big uh chain
of of supermarkets called M&S. very much
loved, over a hundred years old, one of
the pillars of the high street. And
around Easter time, there was a cyber
attack which started causing problems
for M&S. And it just got worse and worse
and worse for them because initially
they said, "Actually, we we can't take
orders on the internet, which for a
massive company like M&S is really bad."
Then we started seeing logistics
problems, empty shelves in some stores.
And then around the same time, there was
a very similar attack on the co-op.
Again, another big supermarket chain in
the UK. They also do funeral services
and insurance as well. Um, that attack
wasn't as bad, but again, we're seeing
disruption at stores, empty shelves,
real chaos behind the scenes. And around
the same time, we saw an attack on
Harrods, obviously the uh the luxury
retailer in London. Um, so everyone's
wondering what on earth is going on. And
things have got progressively worse. And
then we hear the last couple of days
there are attacks on US retailers as
well. And everyone is pointing towards
this really infamous group called
Scattered Spider. And they're not a
normal cyber crime gang. They haven't
named themselves that they are uh you
know not very organized. They come
together on Discord and Telegram. A
little bit like have you heard of
Anonymous? Yes. Yeah. So they're a
little bit like that but more out for
cyber crime and money and infamy than
sort of activism. So uh one company
called Crowd Strike started looking at
this activity coming from this sort of
corner of the the cyber crime ecosystem
and they said who are these people?
They're doing the same kind of tricks to
get into into places. So they nicknamed
them scattered spider. Spider is the
name that CrowdStrike gives cyber crime
groups and scattered is is what they um
the term they give for you know because
they're loose and they're all over the
place. And actually I'm looking right
now at the Crowd Strike Scattered Spider
figurine. Um it's very controversial
actually that they've done this but here
you go. So this is the So they sell
these on their merch website and like I
say quite controversial actually because
it kind of glamorizes these these guys
and there are some people who would who
would say we shouldn't really glamorize
cyber criminals because um the the type
of individuals that we think scattered
spider are very young probably teenagers
in the US and UK they will love the
attention of having their own figurine.
Do you think that social media platforms
like Twitter have sort of changed what
hackers motivations are from just
exploration or exploitation to now fame,
cloud chasing, stuff like that?
Absolutely. Yeah. When when I wrote this
book, my publisher on on the first
draft, my publisher said, "Yeah, that's
all great, but can you answer some
questions as to how this has happened
and why this has happened?" And they
really kind of challenged me. and I work
for the BBC. So, normally, you know, we
got to be very careful about giving
opinions and and putting our necks on
the line in terms of theories about
things. But it was quite good cuz I
landed on this. There are two kind of
factors which I think have turned
teenage hackers from largely benevolent
groups of people that are out to, you
know, they're out to to make a name for
themselves, but they're also out to make
the internet a safer place to where we
are now where we've got cyber crime
gangs, teenage gangs that are causing
mayhem and trying to make money. And I
think Twitter is a very that you could
kind of see at that point when Twitter
becomes mainstream this shift starting
to take place because of course before
Twitter social networks were about being
social with your network whereas Twitter
sort of invented the idea of followers
and retweets and likes and you know
clout online and that's when we started
seeing in 2011 when Twitter was really
on the ascendancy we saw Lulc the first
of this conveyor belt of teenage cyber
crime gangs
Yeah, there's no one flexing their
recent uh ransomware exploitation on
their personal Facebook account. That
wouldn't work. But on Twitter, that
would be great. Yeah, absolutely. And
and we know from interviews with
arrested hackers and convicted hackers,
they loved it. They loved the attention
back then. And I think where we are now
is slightly different because I think
what we're seeing is they have come off
Twitter or X, whatever they're calling
it. Um, and now it's more in the kind of
insular communities, but they're still
they're still after that online clout
and that that infamy. It's just they're
in their own channels in Telegram and
Discord. I was going to say, where do
these people live? Yeah, Telegram and
Discord. Yeah. So, if we're talking
about Scattered Spider, which very much
formed the last part of my book because
I talk about the kind of this gradual
shift to where we are now, but Scattered
Spider, they're part of this larger
collective known as the Comm, the
community, which is a group of thousands
of online delinquents, really, largely
boys, obviously, it always is. And
they're causing mayhem and in some cases
doing some really nasty stuff like
sextortion. Do you know what sextorion
is? No. So, sextortion is this horrible
sort of criminal harassment campaign
where you trick someone into sending you
nudes. So, I would I might befriend
someone on the internet and and strike
up a relationship, a romantic
relationship, send them some nudes that
they think are of me, but I'm I'm a
criminal. I'm a I'm a man, not not not
the the young girl they think I was.
Convince them into sending me nudes. and
then you start extorting them saying if
you don't pay me then I'm going to
release all these pictures. So we see
that kind of activity in the com and we
see some really nasty stuff some other
stuff like um there's some uh it's
really nasty but but like cut signs.
Have you heard of cut signs? No. So like
you know a fan sign where if you're a
big fan of someone you will hold a sign
up saying I love them or you hold their
name or their band name. A cut sign is
like that, but you literally cut into
your own skin the names of hackers, the
names of hackers that are extorting you
or or Wow. So, the hackers are saying
that you need to show me that you've
selfharmed my name into your arm. Yeah.
To show devotion or to make them feel
powerful. There's a excuse me there's a
a bit in my book where we we there's a
gang called Lizard Squad that was around
in 20145
and they destroyed someone's online
life. They hacked all of this kid's
accounts and in order to get them back
he had to make a cut sign and say Lizard
Squad made me do this. So although
people are really shocked about what
we're seeing in the com now this kind of
activity has been around for a while. We
know it's there. We've got the history
for it. So, Scattered Spider are part of
this larger online cyber crime
nastiness. They're a very kind of small
niche of this much larger group of
largely unskilled cyber people. You
wouldn't even call them cyber criminals,
but then there are they come together
with a little bit of skill and a lot of
bulls and take on these big hacking
campaigns. It seems I don't know. I I I
have to assume that although M&S is a
100-y old institution, I would like to
think that their cyber security isn't
100 years old. How if you've got to have
someone with talent, I I assume like how
how do they get into a system of any
kind? Is this cyber hacking or is this
social engineering or is this some
combination of the two? It's yeah, it's
a combination of the two. I think the
initial entry is usually through social
engineering. But to be honest with you,
I mean, a lot of hacking is that to get
into a system, it's not really like in
the movies where you kind of hunch over
a laptop typing code furiously to get
in. Normally, it starts with like an
email that you can trick someone into
downloading an attachment or you call
up. This is this is what we think
happened with the the latest um attacks
is that they call up the IT help desk
and they pretend to be a member of staff
and they say you know I've forgot my
password can you let me in please and it
sounds so stupid but it works and then
what that what often happens is once
they are in that's when you would argue
the hacking starts that's when they find
a vulnerability that allows them to
spread themselves throughout the network
deploy ransomware which is this type of
malicious software that scramles a
company or a victim's computer and
systems and servers, makes that data
completely unreadable, useless, brings
computers to their knees, and that is
where they send the the ransom note
saying, "If you want the key, pay us in
Bitcoin certain amount, and we'll give
it back to you." And ransomware is by by
far the number one problem in cyber
right now. Right? So, this is uh social
engineering.
pretend to be Julie from the front
[ __ ] front from reception who's
locked herself out. Find the person who
is sufficiently gullible or doesn't
stick to protocol and actually allows
you in in some ways. Then you've got
access to some internet type system that
means that you can access other bits
maybe some more sort of spreading from
there. I would imagine maybe you as that
person emails someone else an attachment
which gets you more access to a higher
admin level your way up criminal. Well,
look, what can I say? I'm I am a young
British man. Um, but no, I I mean, my
password manager is a [ __ ] mess, so I
I would be bad at that. It's good that
you got one. Yes, you're way you're way
step ahead of most people if you've got
a password manager. I had Who was the
FBI's most wanted guy? That hacker for a
while. [ __ ] Kevin Mitnik. No. Uh maybe
I he was on the show probably about
three years ago or so and you know he'd
gone through all of this stuff that he
done. He broken himself out of jail
twice and all of this [ __ ] And I
got to the end of it and I was like,
"Hey man, I'm I'm
[ __ ] terrified. Like what what what
do I do?" And he's like, "Dude, just use
a use a password manager." Like the the
TLDDR
9010 solution is just get a password
manager and use that. So uh someone once
said to me there are there are buckets
of how difficult you are to hack and
hackers will always go for the easiest
bucket. Who can I hack? Who uses the
same passwords across multiple accounts?
Who uses weak passwords? If you take
yourself out of that easy bucket into
the slightly harder bucket massively
reduce your chance of getting hacked.
Yeah. Why? Like even if you're the
target but you're a difficult target,
there's so many more easy targets. [ __ ]
it. We might as well go for them. Okay.
So um ransomware.
What? This is This can just totally
debilitate computer systems companies.
If M&S can't get eggs on the shelves, it
seems it's pretty comprehensive. Yeah,
absolutely. Ransomware completely
cripples an an organization. It's like
going back to medieval times. Your pen
and paper. You really are. And sometimes
we've had situations where ransomware
has hit hospitals, for example, and they
can't even function in any way you'd
imagine. like some of the systems, some
of the scanning systems they use in
hospitals, for example, they've been
infected by ransomware, so they're down
as well. So yeah, I I would not want to
be in an organization where they've been
hit with ransomware. M&S is going
through a tough time. I wonder whether
or more likely when we will see the
first uh vehicle hack, autonomous
driving vehicles. I was in a I drove
from Palm Springs to Newport Beach last
week. Very nice. And I was in a It was
lovely. I mean, it was way too hot in
Palm Springs, but And I was in a a
rented Nissan Rogue, a new one. And it
had normal run-of-the-mill medium level
trim Nissan Rogue. And it had this radar
guided cruise control and lane assist
that was keeping in lanes and would if
you just knocked the indicator on would
allow you to change. I was like this is
assisted autonomous driving in a [ __ ]
Nissan Rogue, right? Old school petrol 2
L chug chug chug American car like
Japanese American car in America. And uh
I just remember thinking I've been in uh
Whimo. Whimo is now available on Uber
here in Austin. Mhm. And uh I thought,
"Holy [ __ ] like if these ransomware
attacks, you need as as the level of
kinetic importance to people's lives
increases, the level of security around
those systems needs to increase in I
have to assume you've thought about
this, your autonomous driving and and
the potential risks to cyber security."
Yeah. Yeah. We we haven't seen anything
like you're talking about, but I mean,
yeah, it just it does seem almost
inevitable that someone will find a way
to cause havoc with autonomous driving.
It it's uh it's a bleak thought. But of
course, the companies that that are
behind these these cars, they know that
too. And you hope and and you pray that
they are pretty much on top of security.
Christ, we got to we've got to the point
of hope and prayer as a forget your
password manager. just get on your knees
and you know have you read a book called
Robo Apocalypse? No. It's it's so good.
Spielberg brought the rights to it a few
years ago. He never actually did
anything with them, but it would make
and is going to make an awesome movie if
they ever make it one day. So, in that
in that book, it's about how AI kills us
all. And the one of the ways that um
they initially get that first kind of
like 50% of humanity dead is they take
over the driverless cars. And the
description of what can happen is it's
always it's always stuck with me. But
not to scare anyone, that's not going to
happen. It's gonna be fine. It's gonna
be fine. Okay. They are super duper
cyber secure. I'm sure. Yeah. Well,
yeah. Up until up until you're reporting
on it for BBC News, mate, and then and
then I'm going to ring in. I'm going to
say Joe said to me from a from a I'm
locked inside of my Tesla in which I
don't yet own in Austin, Texas. People
from outside are trying to molotov
cocktail it. people from inside are
trying to hack it. I'm [ __ ] Um, okay.
So, on that point, there was there was
very recently, only like 3 weeks ago,
some tech CEO in some American uh
company
uh city. I can't remember which one. It
was a self-driving city. So, whatever,
maybe San Fran or something, something
like that. He was stuck in one of these
cars and it just kept going around the
um the car park and he couldn't get it
to stop. And it was funny, but also like
hm bit worrying. I've got, look, I
you're the guy for me to give this take
to. I've said this before, but I have
switched off uh the autonomous toggle on
Uber in Austin. So, you just it's on on
the back end of the settings. Do you
want to be more likely to be matched
with an autonomous vehicle? And I've
said no. Reason being, every time that
there is a vehicle that's 10 minutes
away, that's a a Whimo, it takes 20
minutes to get to me every single time.
And every single time that we do the
journey, they say it's going to take 15
minutes for me to get home from the east
side of town or whatever. And it always
takes nearly double. And I realized why.
And it's because Whimos outwardly are so
obvious. They're these big like bulbous
clunky things, lidar on top and all, you
know, additional Jaguar [ __ ] And it's
white, right? So it really stands out.
I think there's two reasons why humans
behave on the road. One is because of
fear of retribution, especially in
America with a very heavily armed uh
populace. Uh and the second one is guilt
at sort of uh inconveniencing somebody
else. So safety and and in human [ __ ]
decency, I suppose the two. The problem
is when you see a Whimo, there's no one
in the driver's seat and you can't see
if there's anybody in the back. So they
just get cucked at every single
junction. No one lets them out.
Everybody's like, "Pedestrians will just
I I will too when I go on a walk around
Austin. I'll just happily walk out." I'm
like, "H, it's 100 feet away. It's going
to 30 m. It'll slow down. It'll be
fine." You wouldn't do that if there was
a human driving the car. So, it means
that until you can program in
retributive tailgating and beeping the
horn and flashing the lights from the
Whimo to somebody else or until you end
up with more than 50% of the cars on the
road being autonomous, you don't have
this level of coordinate. It's an arms
race, right? It's an arms It's an arms
race of uh uh like being mean as
drivers. And unfortunately, the Whimo
has come without any ammunition. Uh
Tesla self-driving people got a hold of
this take online and said that that's
different because uh Tesla self-driving
is trained on real drivers. So you do
have more natural merging sort of more
aggressive driving styles are built in
because competent drivers are the
drivers that this has been built on.
Whereas Tesla focused on software, way
more focused on hardware. And yeah, with
Whimo, it's just it's like being in the
back of the car with your mom all the
time. Is that Tesla thing true? Have you
have you done a comparison? No, I've
never been in a Tesla that's got full
self-driving. Uh, but I also know that
the Tesla full self-driving community
online is um like very evangelist. It's
like oddly oddly militant. Uh, so I
don't know. Well, I guess I'll wait and
see until I get into one. But yeah,
that's my that's my current working
thesis on autonomous vehicles. I thought
you were going to say you don't do that
because of like the safety concerns, but
actually yeah, it's I also thought you
were going to say they're slow because
they're slow and like they're very safe,
aren't they? But no, I I I hadn't
appreciated there other other people on
the road intense for me. Going back to
the youth, these youths online, I think
I've heard you say that today's youth
hacking culture has tipped from chaotic
good into chaotic evil, apart from
clout. Is there anything else that's
triggered some moral decline in this
scene? Yeah, so we mentioned earlier
about the rise of Twitter. I would put
that very much as one of the reasons
we've seen this shift. I would also say
the rise of Bitcoin as well because if
you think about when Bitcoin started
becoming valuable and useful as a store
of value or as something you could buy
things with sort of 2011 12 13 that's
when we saw this shift and certainly
looking at some of the people I do in my
book they go from not even thinking
about money just doing it for the for
the lulls um and for the clout to
thinking hang on a minute I can make
some money here and as soon as you start
in introducing Bitcoin coin into the
lives of young teenage boys, you're
looking at trouble.
So without cryptocurrency, would this be
even harder again? Yeah. I think without
cryptocurrency, a lot of cyber crime
that happens these days would be a lot
harder because the great thing about
crypto, of course, if you're a cyber
criminal, is that I can steal crypto or
I can uh extort crypto from someone and
then it goes to my wallet and people
don't know know who I am. No banks can
stop that. And if I can find a way and
it's becoming harder now, but if I can
find a way to launder that Bitcoin, I
can get it out of the system, turn it
into money I can use, happy days. if we
without Bitcoin, you get things like uh
bank card fraud, that kind of thing. And
we did see that in in some of the early
days of of hacking. But of course,
that's easy to trace and track and stop
if you're a bank. And one of the guys in
the in the book, the main hacker that we
follow who started as a as a teenage
cyber criminal, ended up becoming one of
the most wanted criminals in the world.
He started by carding which is a where
you take credit cards and you use the
numbers and the details to spend uh
without the owner knowing and the banks
usually you know reimburse the owner and
and what's interesting about that is
they when they first arrest him and
they're going through all the bank
receipts they work out he spent about
€33,000
which you'd think like that's quite a
lot of money for I think he was like 15
16 and when you look at the things he's
spending the money on. It's of course
what you would do. We've both been 14,
15 year old boys. It's PlayStation
games. It's the latest phone. It's
Netflix subscription. He even went and
bought um some land. He bought like a
little bit of land.
He could call himself a lord like his
Highland titles.
And you know that that's what you would
do if you had unlimited money. But of
course, the problem with that is when
you get arrested, it's all there and the
police have got it all and you know,
it's very hard to hide from. Whereas
cryptocurrency makes that way easier.
The other way that you could do it, I'm
not giving anyone any ideas because this
is how some cyber criminals work, is
through gift cards. So you don't say to
someone, "Send me $200
in a ransom," for example. You say,
"Send me $200 worth of gift cards." And
then you can sell those online for $190.
So then you get, you know, you have to
shave a little bit off each time. Oh,
okay. That's interesting. But they're
untraceable. So
Well, I you've said uh teenage hackers
are sort of a kind of digital cartel.
Should we be thinking about them more
like organized crime than bored kids in
bedrooms? What's the tension there?
Well, I think um
modern ransomware groups, for example,
these really really well-run, highly
organized um moneyoriented gangs like I
don't know uh evil core or lockbit,
there's loads of them. Um Conti was
another one. They are like modern
cartels. They are run with, you know,
there's a there's someone who develops
the malware. There's someone that sends
out the fishing emails. There's someone
that does the extortion negotiations.
There's 247 customer service on the
darknet websites for these things. But
the teenage hacking gangs, they are
slightly different. They're becoming
more organized now with the likes of
Scattered Spider, but it is a different
type of culture. It's more of a hacking
culture than a than a hacking
organization. I wouldn't necessarily put
them in the same bracket, but certainly
if you look at the um the rise of the
teenage hacking gangs, every single step
of the way, they've been under
underestimated. There's a there's a
researcher called Allison Nixon who is
she features quite a lot in my research
and um she came up with this new phrase
for these types of gangs. She calls them
NPTs
which stands for noob persistent
threats. So they're newbies, they're
noobs, but it's play it's a play on this
very famous and wellused term APS which
stands for advanced persistent threat.
So, she's sort of poking fun at them,
but she says, you know, they're not
advanced, but they are persistent and
they are a threat and we should take
them seriously. And to be honest, I've
been doing this job quite a long time
now and and we don't we don't take them
seriously. Every time there's a a case
like we're seeing right now in the UK,
people are shocked. How can this be done
by teenagers from their bedrooms? Well,
we know from history that this is how
they work. They've just rolled the dice
enough times. They just keep on going.
Yeah. And also they they don't really
care about getting caught. This is the
other thing about these these teenage
gangs unlike the cyber crime gangs that
are based in Russia or places where you
know law enforcement in the West can't
really get them. Um these guys are very
grabbable. They're very getable. In the
last about year and a half, there's been
six arrests of of teenagers and sort of
early 20s hackers that are thought to be
from the scattered spider um culture or
community because they're in the UK and
the US and they don't they don't protect
themselves very well. They don't
actually disguise their voices when they
call up IT desks pretending to be
someone else. Stuff like that, you know,
like it's called operational security.
And these groups, these NPTs are
terrible at it because they don't seem
to care.
What are the patterns or dynamics about
how young kids get pulled into these
communities online? What's the typical
trajectory of one of these people? It's
nearly always the same. It's every
single hacker I've ever met has had the
same pathway. It's computer games. So
Minecraft or Runescape or whatever it
is, I probably Fortnite these days,
probably still Minecraft. It's so
popular. So you you get into gaming and
you play with your mates and then you
start wanting to be better. So you buy
some uh extra bits for your character or
you find some shortcuts, some cheats.
Then you find yourself on a hacking
forum and you find ways to become better
at the game and cheat the game. Then you
find yourself sort of drawn away from
the game and drawn towards more fun ways
to have fun on the internet, i.e.
hacking. And it always starts off as
just a bit of fun. See? Well, what
happens if I type that in there? What
happens if I go into this server over
here? Oh, where am I? This is exciting.
And then it's, oh, quick, you escape.
Oh, that was that was wrong. I shouldn't
have been there. And then it's, hang on
a minute. What else can I do? And then
it goes on from there. And then as soon
as you start bringing money into it,
Bitcoin, then it can quite quickly
become serious cyber crime. And that's
that is the path that I have personally
seen speaking to all the hackers I've
interviewed over the years. But also the
NCAA, the National Crime Agency, in 2015
they did a kind of massive research of
all the convicted cyber criminals and it
was exactly the same. It was step one
gaming, step two gaming cheats all the
way down until serious cyber crime. So
it is a cliche but it's true.
Where are most of these people? You
mentioned Russia. I always when I think
hacking group I just think oh it's the
what is it IRA or whatever in in Russia
or some oh G gu GU sorry whatever
there's loads of them loads of acronyms
uh what is it what where where are all
of these you mentioned these two are
notable or at least scattered spiders
notable because they're primarily
English speakaking in the US and the UK
but that that's a rarity I guess it is.
Yeah. Um, that's probably why they're so
interesting as well because we're like,
well, hang on a minute. They could be
upstairs in in in in the bedroom. Um, so
if you're looking at the the kind of if
we take the whole cyber crime ecosystem,
these are the people that are out to
make money, defrauding, stealing money,
extortion, ransomware, all that kind of
stuff. They're they could be anywhere.
But the biggest gangs are organized and
run, we think, from Russia, Eastern
Europe. And we know this because there
are lots of lots of kind of like hints
that you get. So, for example, I spoke
to a guy who deals with um ransomware
negotiations. And I said, "How how can
you be so sure that they're in Russia?"
And he said, "Well, they speak and they
plan in Russian on Russian forums. They
um work in Moscow hours and they don't
ever answer you on um public holidays in
Russia. So, you know,
there's a few hints there. Um but of
course, the actual affiliates, the
people that are carrying out the
everyday attacks, we don't know where
they are. They could be anywhere. And
there was an very famous um arrest of a
an IT expert in Canada who was, you
know, an upstanding citizen of the
Canadian IT scene. and he was working
for a Russian cyber crime gang uh called
Net Walker. Um and I actually on that
one it was really interesting because
someone uh one of my contacts sent me
the negotiation portal for when Net
Walker was extorting this university and
it was during the pandemic and I was
over the course of about 3 weeks I
watched this negotiation this extortion
take place. What what's what what do you
mean by the portal? Like a chat like a
private chat type thing? Yeah. So, if
you um if you get hit with ransomware,
you'll have on your screen on your
computer, it will pop up saying, "Hey,
you've been hit by ransomware. Go to
this darknet website um which is like a
jumble of numbers and letters. Onunion
um and we can start the start the the
negotiation." They always it's really
really kind of like irritating and
frustrating, but they always like frame
themselves as um we are here to help.
Follow this link, we will help you, you
know, we we'll get you through this. And
of course they're the they're the
bastards who are trying to
um but it was fascinating watching this
Net Walker ransomware group extort San
Francisco. Um I think it was it was uh
the Southern California University or
something and they were like this is
during the pandemic. We are working on a
vaccine please we haven't got any money
leave us alone. And they're like how
much you got? And they're like yeah know
$750,000
that's nothing. I can't even buy
McDonald's with that. send more. And it
ended up they paid uh I think it was
$1.2
million to these guys. Anyway, so he
turned out to be in in in Canada. Um but
most we think
if you look at the arrests, they could
be anywhere, but they are normally based
in Russia. Then you've got um North
Korea. They are very very uh big on the
on the hacking scene. But what's really
interesting about North Korea is they're
the only country that that we know of in
the world that as well as doing cyber
spying, which we all do. Every country
does it. UK and US all over it. But
North Korea does that. Plus, they steal
cryptocurrency and they are very very
good at it. They just stole oh my what
was it now? I think it was like I can't
even remember. It was it was it was like
1.5 billion.
The country, the country of North Korea
or the country of North Korea has a
cyber team that they've always denied
this of course, but they have a cyber
team that is dedicated to making money
for the regime by hacking. They used to
do banks, but now they do cryptocurrency
companies, but they're unusual. Most
countries don't have that. Most
countries just have their cyber spies,
and they're out to project power, steal
secrets. In some cases, they'll be used
in military. So Russia we know has
hacked against Ukraine in in the war for
example. Um but most cyber crime is done
by criminals um who could be anywhere
but are yeah largely kind of organized
in Russia and Eastern Europe. Why is
that area of the world such a hot bed?
Have they got lacks internal scrutiny
from the law enforcement? Is it sort of
side eye allowed by the state to try and
[ __ ] up everybody else? What's going on?
Well, yes. So, there's this golden rule
if you're a Russian cyber criminal,
which is you do not hack Russia or
former Soviet states. It's like a kind
of unwritten rule. If you do, you get in
lots and lots of trouble. And there was
a a cyber crime gang called Reval or R
Evil. And um they were they were allowed
to kind of just run a muk for years and
years hacking left, right, and center
western companies causing huge amounts
of problems. Um but then so the story
goes they accidentally hacked Russia and
then suddenly there was some arrests. Uh
so yeah there is that kind of that kind
of um culture in Russia. Obviously the
Russian government denies this every
single time it comes up. Um there was
this uh this summit between Biden and
Putin. Um when was that now? 2021 I
think. It came off the back of some
absolutely horrendous ransomware
attacks. One of which was on against
colonial pipeline which is a really
important part of the US um petrol and
oil uh infrastructure and it meant that
there was shortages at pumps and panic
buying and there was no fuel going up
and down the east coast. So this
conversation between Biden and Putin
according to him was like you've got to
stop your people hacking. This is no
good. And Putin was like it's not us we
get hacked too. But the evidence really
is not really there for that. M how
close are we to seeing cyber attacks
being treated as acts of war? Oh,
well there's this Yeah, there's this
thing called I think it's article 5 in
NATO which means that when you get
attacked and it's a confirmed attack
then everyone else is you know piles in
um and it's one of the founding you know
parts of NATO one of the tenets and some
people have said what we've seen in um
in Ukraine uh sorry in with the attacks
against Colonial Pipeline and others is
oh could this be article 5 There was
another attack on US government solar
winds attack thought to be from Russia.
People are saying maybe that crosses the
threshold. But I think people are very
very scared to bring cyber in the same
anywhere near the same kind of um
seriousness as a as a missile
when in fact sometimes the damage can be
you know can be just as bad. What was
that one that tried to get? Was it
Iranian
nuclear reactors and it waited around
the stuckset? Can you tell me the story
behind that? Oh, just like unbelievable.
You have to take your hats off to them.
So stuckset was a an attack by they've
never admitted it but Israel and the US
against Iran and they were very worried
about the uranium enrichment helping to
create nuclear weapons for Iran. So
according to the the story the the uh
the president at the time said right
well what can we do to slow them down
and someone said let's let's hack them
and the stuckset virus was so
specifically and perfectly targeted that
it only infected that certain system and
I think they spread it through USB
sticks or something. They dropped them
in the car park. Absolutely brilliant.
Um it's dumb but it works. That's what
they always say in cyber. It sounds
dumb, but if it works, it's not dumb.
Um, and it managed to get inside the
system of this very specific machinery
that they were using in the Natance um,
refinery and it sped up the refinery um,
centrifuges so fast that it caused
apparently, we don't know because
obviously Iran would never admit it, but
we think it caused physical damage and
potentially broke some of those
centrifuges and slowed them down. We
don't know how much it slowed them down.
We don't know how much damage was done,
but it's largely been, you know, hailed
as one of the most impressive cyber
attacks of all time, didn't it? It was
infected some insane percentage of
computers around the world as well. Like
loads and loads of machines had it, but
it just it didn't do anything. It was
just is this is this computer attached
to an Iranian nuclear facility? No. All
right, just chill out. Nothing for you
to do. May maybe you'll get maybe you'll
meet someone in future that is and it
just did that over and over again.
That's it. And it it's really targeted
really precise and there have been cases
where a country is blamed for releasing
something like that. You're you know an
uncontrollable worm that's got out of
hand. So there's this one called not
Petra which was 2017
17 I think it was and um it was well
again Russia would uh Russia would never
admit this but it was uh thought to be
from Russia against Ukraine and they
hacked into a really popular accountant
accountancy sort of software that the
Ukrainians used and it was a worm that
spread uncontrollably and it was a fake
ransomware. So normally the thing comes
up and it says pay this and you get your
your files back. But with not Petia it
was it was a shredder. It was fake. Even
if you paid you wouldn't get you
wouldn't get anything back. And that
spread from Ukraine all over the world.
Hundreds of countries affected by this.
And it caused they think the most damage
of any hack ever. I can't remember the
figure now but it was
I know one company lost a billion. MK,
the the logistics company, they were
back to pen and paper. So, they had
ships coming into harbors. They didn't
even know what was on the ships. They
didn't know how to unload it, where it
was going. Absolute carnage. And it cost
them well over a billion. I can't
remember the details of that. This is
like the Wuhan Institute of Veriology
equivalent of a a online
worm. Exactly. And you can't stop it.
The only way to stop it is to inoculate
all the computers so that if you get it,
they don't get ill. It's like a vaccine
around the world. Yeah. What are the
ways that cyber security firms find
these sorts of hackers? Like what is it?
I know TTP's sort of part of this, but I
don't know. I if you're good if you're
good enough to construct a worm that
does ransomware and scrambles and does
all the rest of it, I have to assume
that you're good enough to be able to
hide your tracks. So, it's yeah, how how
do the security companies track down who
caused it? Well, a lot of it is is
follow the money because if you can
follow the trail of of of cryptocurrency
and Bitcoin, then you you might be able
to get them. But thinking about um about
that, there's there's a there's a a part
in my book where Julius Kamaki, this guy
that we follow all the way through, he
gets caught. One of the ways that they
find out it's him, is because he does
the biggest self own in cyber crime
history, an absolute monster of a
blunder. Someone in the book called Anti
Kuritu, who's a cyber expert, he says
that um everyone thinks that cyber
criminals are masterminds when they're
carrying out the hacks, but they're not
masterminds at covering their tracks.
They often get a bit lazy or a bit um
you know, arrogant about that part of it
because operational security is really
really hard. So um this guy Kamaki, he
starts sending out um he's got all these
the the patient data of psychotherapy uh
patients all over Finland, 33,000
people. He's managed to steal all the
notes from the from the therapists. So
he starts extorting the company by
releasing every day 100 new records. Um
and yeah, this is the kind of stuff that
you do not want on the internet. like
this the stuff you say to your therapist
is the most sensitive information
probably that you could ever hope that
you know stays safe. So day one 100
records day two this is on the darknet.
Day two another 100 records. Day three
another 100 records. But then he says to
make it easier for all the people on the
forum here's a bulk download so you can
download all 300 patient data notes um
instead of having to do one after the
other. Um, then he goes to bed. Uh, and
then what he doesn't realize is he's
accidentally uploaded the entire
database of 33,000 patients. So, he's
given away all his bargaining chips, but
also he's accidentally uploaded his
entire home directory for his computer.
So, it's like, for example, I want to
send you an email. I accidentally send
all the emails in my inbox and all the
attachments and every folder on my
desktop as well. Wow. So the police
found this in the morning and they
obviously downloaded it as quick as they
could. He woke up and he realized that
what he'd done and he starts deleting
files from the server. The police find
an IP address which is a internet
protocol which is like tells you where
roughly where the physical computer is.
They find an IP address in that home
directory uh you know accidental dump
for a computer server a cloud server
company which is only half an hour away
from them in Helsinki. So, there's this
race against Ransom Man, that's what
he's called, deleting everything as he's
going because they've got this massive
server that could potentially give them
all the clues they need. They get to the
uh the server farm, pull out the
internet cable, severing Ransom Man from
his server. I put it like this. It's if
you imagine a drug dealer, the cops are
arriving, he's trying to flush all the
cocaine,
but then suddenly, I don't know, they
cut off the water or something. Exactly.
Something like that. So he Yeah. He's
nothing he can do. So then um they had
this they had this massive server
full of all the evidence they needed to
track him down. It was a little bit
harder than that. Um he did he did try
and use aliases and that kind of thing,
but there was just so much there on that
server that led them back to him and
that's what led to ultimately led to his
conviction. So it's that kind of thing,
those mistakes that that can be made.
It's Russell Brick@gmail.com.
Yes. That kind of thing. Yeah. Yeah.
Like if you're going to start the
biggest online drug selling network in
human history, make sure that your old
forum posts aren't linked to your name
atgmail.com.
But that's a really good example, isn't
it, of how someone's online presence can
start, you know, innocently enough.
You're building something. You're you're
a software developer. You're just asking
for advice. You don't know that in five
years time you're a massive mastermind.
You got to future proof yourself. Be
careful what be careful what Runescape
username you use in 2012 because God
knows where you're going to end up 14
years later. Yeah. Okay. So, we're
giving advice now to I'm I'm I'm I uh I
welcome our
internet overlords. I I my operational
security is horrible. Uh okay. So,
another hack that I knew about, one of
the most famous ones, uh, the Christmas
hack of computer games, and it seems
like this sort of kicks off a lot of the
story that you've been following. So,
what what first drew you to this? What
what's the story behind Lizard Squad?
Give me the give me the overview. Yeah.
So, um, 2014, Christmas time, there was
a ginormous DOS attack, which is a very
low-level form of hacking. It's like I
liken it to when Glastonbury tickets go
on sale, everyone lands on the website
and and accidentally the website
crashes. It's like that really in cyber
crime. If you get enough traffic into a
server or a website, you can bring it
down. So the Lizard Squad were part of
this, as I said earlier, this conveyor
belt of these teen hacking gangs, these
NPTs that emerged in 2010s, and they
decided they were going to go after not
just Xbox Live, but PlayStation Network
as well. And I don't I still don't
really know how they did it, but they
managed to bring these services down for
hours and hours on what was, you know,
the busiest time of year, Christmas Eve,
Christmas Day, Boxing Day. So that was
uh coincidentally like that was the
first story I ever covered. And I went
into the Sky I used to work for Sky News
and I walked into the Sky News um
newsroom. I think it was like very early
on Boxing Day or the day after Boxing
Day. And they said to me, "Have you
heard about this massive hack these kids
have done?" I was like, "What are you
talking about?" No. So then I looked
into it and I couldn't believe the power
that that these kids could wield. I I
found it absolutely fascinating. So my
news editor came over to me and he said,
"Um Riley's called who's the head of Sky
News. He says he wants a lizard on air
tonight." So, I was like, "Right, how on
earth am I going to get one of these
anonymous Lizard Squad hackers to do a
TV interview in, you know, 6 hours, 7
hours, whatever it was." So, anyway, I
managed to find one and it turned out to
be um this kid who was, I think he was
16 at the time, 17, uh calling himself
Ryan. And we did an interview and it was
uh Hang on, you jumped ahead. How did
you find him? Oh, just like going after
person who says they're involved and
then it turns out they're not, then
another person, then another. I don't
even know. I couldn't tell you how I got
to him, but in I went through I know one
of the people I went through was this
guy called Vinnie who was part of Lizard
Squad, kind of like an adjacent member.
He didn't he said he didn't really do
anything for them and I believe him and
he was cleared of all wrongdoing. Um,
and he actually lived in Twickenham,
which was like three miles away from the
gang newsroom. So, um, so he he promised
he would get me this this this kid,
Ryan, who was a part of the the gang
that took out these these gaming
services. So, anyway, I did this
interview with, um, with Ryan, who it
turned out was Julius Kamaki. Uh, that's
one of the aliases he used, was Ryan.
Um, and I I that kind of really sparked
off in my mind this this fascination
I've had ever since with cyber crime.
Um, and I've tried to keep tabs on on on
Ryan or Julius ever since. But then the
trail ran cold because he disappeared
for a while. So then when he pops up as
potentially the person behind this
ginormous hack in Finland on the the
psychotherapy centers called Vastamo, I
thought, "Wow, he has had a career." And
my money, Kamaki is the most hated
hacker in history. Not just because of
the Vastamo hack and and the the
PlayStation and uh and Xbox One, but
also there are lots of times in that
that sort of 10 12 year cyber crime
career where he has done some really
hateful nasty stuff to not only you know
people that he wanted to go after but
fellow hackers as well. What leg?
So, there was a Sony um executive called
John Smemedley who um fought back a bit
on Twitter against Lizard Squad. He was
like he wouldn't he was used to be a
prolific tweeter and he he sort of fired
back some tweets against these kids and
they didn't like it. So, they went after
him pretty badly. And um one of the
things that Kamaki did was he found out
that John Smmedley was flying from oh I
think it was from Phoenix to Houston or
somewhere. I can't remember where it
was. Um and he convinced the airline
that there was a bomb on Jordan
Smmedley's uh flight and it had to get
escorted by fighter jet to a different
airport where he was um he was
questioned at gunpoint and all sorts
stuff like that. Um and there there is a
litany of situations uh and incidents
where Kamaki has done some really
horrible things. What he said about um
what he's done to other hackers as well.
What's in that list? Well, there's a
there was a kid called Blair Straater
who um I spoke to in the book and Kamaki
led probably a three-year harassment
campaign against him. Have you heard of
swatting? Not swatting. Yes. Yes. where
you pretend you you call up the police
and you say there's a
kill someone or whatever. Yeah. Um and
and the SWAT team arrive and and it's
really dangerous and and people have
died. Um so they would do that all day,
all night for months against Blair
Straighter. They they've also got this
weird thing which is it's still a thing
now. I don't really understand it, but
it's um when you get doxed your
documents come online. So that means
that everyone knows where you live, your
real name, all that stuff. So for a
hacker, that's a pretty bad situation to
be in if you're doxed cuz you, you know,
the whole point of it is you're
anonymous and you're powerful and
you're, you know, you can disappear at
any moment. So with Blair, they doxed
him and then Kamaki and others would
send him pizzas, Chinese takeaways, all
these kind of deliveries. At one stage,
a lorry load of sand and gravel arrived
at his house. Personally, like if a free
pizza turned up at my house, I'd be
happy about it. But when you talk to
people who have been victims of this for
months, it becomes horrible because you
are on edge the whole time and the
delivery drivers want paying if you
haven't paid them and they get annoyed
with you. So, you know, that kind of
harassment is not nice. There's a there
was an article written by another
journalist called Kevin Roose who um
interviewed the Straighter family around
this time when it was really bad. And
the article was called Haunted by
Hackers. And I've always thought that's
such a good headline because for Blair
Straater and his family, that's what it
was like.
[Music]
Yeah. It's ruthless, man. Okay. So, you
sit down with this guy. You don't know.
I mean, this is what, 2014? 2014. Yeah.
Yeah. The first time you do it. Um, what
stuck with you from that first
interview? Just just complete lack of
remorse, caring,
um, smirking throughout the entire
interview.
a lot of honesty. He didn't sort of make
up uh sort of So, he didn't hide his
face. No, not at all. Not at all. No.
No. He he turned up uh to the Sky News
interview on on Skype fully. Uh didn't
disguise his voice, his face. Didn't
didn't give a damn. Surely that's a bad
idea. This is what I'm saying. OBSE is
terrible. These NP that's that see but
surely that's something different. That
to me seems like operational security is
covering your tracks. That seems more
like a purposeful middle finger.
Absolutely. Oh yeah. And don't and don't
forget Well, you don't know this and I
don't know how far you got in the book,
but at this point Kamaki was already
under investigation. He'd already been
arrested. He was on bail. So
So you got to factor that in. Wow. But
but but you know Kibamaki and there's a
few others like him in the last kind of
1015 years. They're a different breed.
So you've got the MPTs who don't care.
They're out to cause chaos, get some
money, bit of infamy. Then you've got
the kind of Allison Nixon, the
researcher I mentioned earlier, she
calls them the centers of gravity. There
are certain teenage hacking uh hackers
who they are
they they are the center of their gangs
and everyone follows their lead and you
don't necessarily have to be the most
technical to be that center of gravity
but you have to be the most ballsy
anarchistic charismatic charismatic and
and you and you don't care. And the
thing about the that that Christmas Day
hack was he appeared on um on the
interview fully, you know, face and
voice. And yes, like it came it came
very quickly afterwards. There was a
knock on his door by the Finnish police,
but they never they never got him on
anything. All the things he told me
either they didn't find evidence or they
were too busy on his other cases to to
look into it. But uh as far as I'm aware
and as if you look at his at his court
records, none of that was taken into
account with any subsequent convictions.
Do you know what he did in between that
and the mental health hack?
Not really. I know that he traveled a
lot. I know that he was carrying a lot
of Bitcoin. I spoke to one um fellow
Lizard Squad hacker who he went out with
in um in the Netherlands uh on a on a
jolly and he was carrying a a a hardware
crypto wallet and it had something like
$50,000
worth of Bitcoin in and that was
apparently just his holiday spending
money. And of course that Bitcoin now
would be worth something like 12
million, you know. But you're right,
there is this gap in his story which I I
would love um to find out what what
happened. But the the actual hack
happened in 2018.
So he stole the Vastamo database of
psychotherapy patient notes in 2018. So
there wasn't like a huge gap. It
wouldn't go to 2020, but yeah, there was
a gap. There are there is a um
suggestion
by a Finnish journalist which has yet to
be confirmed and it's all alleged and
you know huge pinch of salt with this
cuz I haven't we don't know if this is
true but he thinks that Kamaki might be
involved in a in a uh in a hacking sort
of hacking cyber crime thing that
happened around that time which was
Kamaki aside whoever did this it's like
the perfect crime. So what they did, I'm
not going to say Kevin Macki because we
don't know if it was him. But what they
did was they found a website on the
clear web. So that's the the the
internet that we all know and love that
was advertising darknet drugs
marketplaces. So it had links for the
the darknet links. So like as I say,
jumble of numbers and letters.
He hacked into that and then changed the
links for those darknet websites to his
own fake darknet uh marketplaces which
had all the things you would imagine
like buy your coke here, buy your MDMA
here, but all the money going into that
marketplace was going into his pocket.
And I spoke to the police about this. I
was like, if that is Kamaki,
why aren't you looking into that? Like
why isn't that part of your
investigations now that he's behind
bars? you know, aren't you investigating
this? And the guy, Marco Lepin, the
Finnish police officer, said, "We
haven't got any uh complaints. There are
no victims." Because, of course, no
one's complaining. No one's complaining.
The cocaine that I tried to buy on the
dark web, I didn't receive my order for
that. Exactly. It's the perfect crime.
The perfect crime. But anyway, I don't
know who I don't know who's behind that
one, but there is some vague suggestion
uh that some some journalists have have
made. How did he do the Vastamo hack? Do
you know? Yes, it was uh it took about 4
minutes. It was it was awful. The the
security at Vstamo was terrible. And
there have been convictions. Uh the CEO
has been convicted. He's appealing it.
um the the the cyber security practices
at that company were very very poor. So
he did a scan of um open servers with no
passwords.
He logged in, saw it all there,
downloaded it. It it must have been
Well, no one knows why he did it in
2018, but then he didn't do the
extortion until 2020. But my theory is
he couldn't believe his luck. He
downloaded it and then sort of sat with
it for a while waiting to see if
someone's realized. I think so because
of course at some point we don't know
why in 2020 um he decided to extort the
company run out of Bitcoin to party
with. You know what I mean? I need to I
need a party fund. But that was that's
my other that's the other really
mysterious thing about this character is
that um we don't know why he did it
because apparently he did have enough
money. Apparently he was and is very
wealthy. The court fees alone the
lawyer's fees to try and defend himself
absolutely humongous. And part of his
defense was why would I do this? I've
got loads of money. And then they say
well how much money have you got? And he
says I can't remember.
It's all in Bitcoin.
It fluctuates by the day based on what
the price of Bitcoin is. Um, so why did
that hack hit differently? What was it
about the Vastamo hack that caused such
uproar?
Well, um, data breaches happen all the
time. Data stolen from people all the
time, from companies all the time. And
to be honest, it's a kind of just like a
little bubbling thing that happens in
life all the time. And you know, we we
kind of like uh take it for granted.
There aren't many situations where
people actually are badly affected by
that. But when you've got a group of
people who are already vulnerable
because they're in therapy, some of them
have had horrendous lives, childhoods,
some of them are children. Um and when
you get that kind of im that kind of
like insight into their lives through
the patient through the psychotherapy
notes that the therapist is writing down
like I said earlier that I mean that
kind of data is the most precious of
them all isn't it? So that in itself
is pretty bad. Stealing that data is
pretty bad. But then what happened next
was run-of-the-mill. So he went to the
CEO of StarMo and he said, "Give me
€400,000
worth of Bitcoin and I won't publish the
data on the internet." That didn't work.
So then he started releasing them on the
internet on the darknet as I described
100 a day, which would have carried on
if he hadn't have messed it up. And then
after that, he went the step even
further and he sent out emails to every
single one of the victims he could find
email addresses for, which is about
27,000 people. and they all received an
email in their inbox on Saturday night
after they got out of the sauna in
Finland because everyone has a sauna in
Finland on a Saturday night and they saw
in their inboxes an email from ransom
man saying I have got your notes pay me
now or I will put them on the internet
and if you can imagine the kind of
impact that would have on on you or on
me that's horrendous but you got to put
yourself in the position of people who
are already in the the lowest of low and
um I spoke to lots to the victims and
you know some of these people have still
got PTSD and some of these people are
scared to leave the house and the impact
the long-term impact is absolutely
horrendous. Although the evidence
has never been presented uh the lawyer
that represents about 4,000 of the
victims, she says that two of the
families um have said that people have
taken their lives over this.
Did he send that extortion email after
he accidentally leaked all 33,000? Yep.
Right. Okay. So, he It was the last the
last roll of the dice to see if he could
make some money out of it. Yeah. Yeah.
Yeah. Yeah. Okay. So, he
face plan he Russell brick atgmail.com's
his own computer onto a server. The
police realize it's 30 minutes away.
They get in the car. They run down
there. They unplug the computer, the
internet from the servers. They now have
the servers and they start to do cyber
forensic stuff. Yeah. Took a long time,
but they managed to come up with a name.
The funny thing was, of course, um even
before the servers, people were
wondering, could this be Julius Kamaki?
Cuz he was so infamous in Finland by
that by that stage as all the teenage
stuff he'd done. And then um they in 200
I think it was 2022
they decided they had their man and they
wanted to start finding him but they
couldn't find him. So I think it was
late 2023
that they no it was late 2022 that they
um put out an interpol red notice for
him. So they didn't know where he was.
They had a feeling that he was somewhere
in Europe but they didn't know where. So
they put out that is bit of a nuclear
option actually and a bit controversial
because Kamaki has always said they
could have just asked me and I'd have
come back. Whether or not he would have
done I don't know. Anyway, so this this
um Interpol red notice went out for him
and the detectives in Finland kind of
just got on with other cases. I don't
know what a red notice is. What is that?
Oh sorry. It means that um if you are
found
anywhere in the world, if you've got a
red notice out through your arrest, they
can arrest you like that and then they
send you back to wherever the the
interol red notice came from. Assuming
you're somewhere that's got extradition,
I imagine. Oh, yeah. Yeah. Yeah. Um
should have gone to North Korea. Could
have been around.
That's his mistake. Um so they put this
notice out and then they kind of got on
with other things and then remarkably
there was this uh stroke of luck in
Paris whereby um someone called in a
domestic uh incident disturbance in the
early hours of I think it was February
2024
and the police the French police went to
the house and they were expecting it to
be you know a a woman being abused or
something like that and they opened the
door and everything was fine and there
wasn't any danger.
Um, and this man sort of it was after a
night out, so I think he was a bit hung
over and still asleep. They dragged him
out of his bed and he they just did some
it some ID checks and he was uh
traveling on a passport for someone
called Asan Att um which is a Romanian
passport and they were like, "Well, hang
on a minute. This guy is 6'4, green
eyes, does not look like a Romanian
called Asan Art." So they ran some
checks and somehow they unearthed the
fact that this was Julius Kibamaki. So
they arrested him on on the spot and
took him back to the uh Do you know what
the disturbance was?
Well, the call went out from a woman
who'd been out with uh the the woman and
Kamaki that night and apparently there'd
been a big row and and she hadn't
answered her phone and he was being
abusive and aggressive. But then if you
ask Kamaki, which some journalists did
afterwards, apparently it was someone
who knew that he was hiding and they
they did it deliberately to get to get
police to uh to know where he was.
Again, not a very liked person. Yeah, he
doesn't seem like a good guy. Okay, so
he then
gets extradited from France. Back to
Finland. Yeah, back to Finland. And then
so begins this monthsl long uh time
period where they were putting together
the case against him um in time for the
trial which was in 2014 no 2024 sorry um
and led to his uh conviction. And what
was the court trial process like claims
defenses and and the uh sentence and all
of that? Yeah. So, um, the the police
had a giant folder of evidence against
him, not only for the the hacking, but
also for the blackmail. It took police
ages to get that evidence together for
the for the actual blackmail part of it
because they had to go to um they
wouldn't say which US tech giant, but
they had to go and kind of get some
evidence from them. And it literally
took like 18 months for Google or
Amazon, whoever it was, to send back
some details about it. But that was one
of the crucial pieces of evidence that
they needed. Um and eventually, yeah, he
was convicted. In Finland, they don't
have um juries. They they do it all by
judges. There's three judges that that
decide um and and and they found him
guilty on all counts. But what was
really interesting is that every single
time that it said in the paperwork, um
Kamaki either by himself or with others,
so every charge came with that cuz
they're never quite sure whether or not
he did it on his own or not. They think
he might have had help from somewhere,
but they don't know where. There's some
discussions right now happening in
Finland, like this week, about whether
or not there's a suspect in Estonia that
might have helped in some way, but we
don't know. But the conviction happened,
they said they they didn't have anything
that they said that on in the totality
of of the evidence, he's guilty, but if
you take in each individual one, they
couldn't quite pin him on each
individual one. It's a strange thing,
but the prosecutors are very happy. The
police are very happy. They said that
they took everything kind of
holistically and said, "Right, yes, he
did it." Because of all these bits, none
of them are kind of like um a smoking
gun, but all of them together were
enough to convict him. What was your
reaction to the arrest and the trial and
stuff as you were following this going
on? Because obviously this was, you
know, a decade after you first sat down
with this guy. That must have been a
slightly I don't know out of body
experience for you to see it occurring.
Yeah, it was bizarre because I just had
a feeling all those years ago that this
kid would be worth watching. And there
were rumors at the time that he'd kind
of fled with a a stash of billions of
Bitcoin and stuff. And I've always been
fascinated about what happened after the
Lizard Squad uh takeown at Christmas.
Um, and being in the courtroom, seeing
him as now, I think 26, 27 years old,
still cocky, still smiling, still not
really caring about anything was was
absolutely fascinating. There was this
uh bizarre moment in the in the trial
where um he applied for bail because he
was in prison and he was having to leave
prison each day to go to the courthouse.
And he applied for bail to be released
so he could, you know, be a free man
until until the end of the case. And um
although the police objected because
they were worried he'd be a flight risk,
the judges agreed. So he was let out. Um
and then the police were like, "Whoa,
whoa, whoa, whoa. What are you doing?
this is this this this guy is not going
to be uh we can't pin him down. Why have
you let him go? So, they very quickly
appealed and the judges were like, "Oh,
yeah. Okay, quick. Get him back in." He
wouldn't come in.
He disappeared. They couldn't find him.
Where did he go? Well, um they the
police kept calling him and said, "We
you've got to come back in a court
order." And he's like, "I'll see you on
Tuesday." This was like Saturday. I'll
see you Tuesday when the the case starts
again. They're like, "No, no, come in
now." He's like, "No, no, I'm fine." So,
anyway, they they um found his social
media handles or somehow like some
obscure forum handle that he was using
in the past and he posted a picture of
himself, his hand, holding a bottle of
really expensive champagne. And they saw
from the background that it looked
potentially like a kind of Airbnb. And
then they figured out that there's no
way he could could have got an
apartment. He's not in any hotels, so
he's he's he's he's like there's very
only small places he could be. And they
looked at all the pictures of all the
Airbnbs in Helsinki and then got the
right one, rang the doorbell, and there
he was. Holy [ __ ] They they
geographessed their way to finding him.
Yeah. But all the court cases I have
covered in my in my time as a
journalist, people arrive in a suit and
they're really polite and they try
really hard to make the the jury and the
judges realize they're good guys, but
just it's classic. You know, that's that
character of that teenage cyber criminal
who's just got away with it for so long.
What is it? He doesn't care. Yeah. What
like what is it about his psychology? Is
he completely detached? Is this guy a
psychopath? Does he is he just really
cocky and out for recognition? What do
you think's driving him? Well, one thing
that kept one word that kept coming up
is sociopath.
And it's really difficult and dangerous,
I think, to kind of throw these things
around. Like I'm not a clinical
psychologist. I can't I can't decide on
that kind of thing. But um one of the
guys that used to hack with him back in
the teenage days says that the thing
about him was he just wanted to sort of
see watch the world burn. He just wanted
to cause chaos and and damage. One of
the cops said that um it's like the kind
of guy who likes to get in a fight in a
bar, but he can do it from behind the
computer to protect his bone structure,
which I've always quite liked. But I
don't know. I I don't know. I I I'd like
to sit down with him. I tried to um get
an interview with him during the trial
and and and he said yes and his lawyer
said yes, but the judge blocked it at
the last minute so I wasn't able to. And
then we were talking on text and then he
just stopped talking to me. That was
about when he disappeared actually. So
maybe that's why he stopped talking to
me. Um and I've tried many times to
contact him while he's been in prison,
but he he he won't answer my um my
letters. Dang it. So yeah, he he uh he
remains a bit of an enigma.
How long's the sentence?
Very short. He'll be out in probably a
year and a half from now. You should
have just waited to publish the book.
You didn't need to publish it now. Well,
you can do a follow you like a the
paperback. The paperback paperback can
have a Yeah. a little appendex
additional chapter. That's the usual way
that authors do. Well, with what's
happening right now with M&S Co-op and
Harrods, I think there could be enough
for another chapter when the paperback
comes out. A that's we've just brought
up a we've doubled sales. We've doubled
sales overnight. Um so I'm interested in
this Maxim Yakabets guy as well that you
went and and tried to track down. It
seems like you have a a ponchant for uh
trying to find Eastern European young
men
and not no accusation, but uh you you do
seem to have a skill for it. So what's
the story of him and evil core and stuff
like that?
Yeah. So, Evilcore are um are the kind
of OGs of Russian cyber crime. They were
there from the beginning and they
evolved as the cyber crime ecosystem
evolved. Um and they they've been kind
of run and led by a family, the Yakubets
family. And Maxim Yakobets is was the
most wanted cyber criminal in the world.
There's a 10 thou 10 million uh dollar
reward out for his arrest. him and his
right-hand man um Igor Turv. So we
decided in I think it was just just for
the pandemic, so 2019, that we would try
and go and find him in Russia. Because
one of the things that I became a bit
annoyed about was that the West points
fingers at these people, UK, US, and
says, "H, they're cyber criminals.
They're guilty. They've done this, that,
and the other. They've they've stolen a
hundred million dollars worth of uh of
money from innocent people around the
world." But you never hear from the
actual cyber criminals themselves. you
never actually they never get a chance
to kind of have their say. I know that
sounds silly but as a journalist like
that's kind of like my job and that's
the bit that interests me is like
hearing both sides. So I was I remember
I was sat in the garden there and I was
just like thinking one one afternoon why
don't we go why don't we try and find
these people. So we did and we searched
around Moscow and we got all the
addresses that were known about them and
tracked down their supercars and tried
to take go to the garages that they were
at. Um, and I managed to find an address
that we thought was Makim Yakabet, but
it was actually his dad, but we went
there and his dad opened the door and we
had this absolutely
for me unforgettable interview with um
with uh Yakobet Senior
uh where he was like so angry with the
with the West accusing his son of being
a cyber criminal. And I was saying
things like, you know, speaking through
my producer, reporter, translator, like,
well, how do you explain the
Lamborghinis? He's like, well, they
could be rented. So, how do you explain
the quarter of a million dollar wedding?
Well, we don't know how much it was.
Have you seen the paperwork? It's like,
well, no, but I went there and spoke to
the wedding organizer, you know, and he
had an answer for everything. And what
was fascinating about that and what's
become even more fascinating is we went
there in 2019 and put the documentary
out and I think it was yeah last year
the National Crime Agency gave us loads
more information about Evil Core and
they said it wasn't just these seven or
eight men it was also the dad. He's a
part of it. He's in some way involved
moneyaundering. You met the mastermind
who was in front of you. You could have
snagged him there. Yeah. Yeah. Um, so
yeah, that that was a that was an
amazing trip, but I I didn't enjoy it.
It was the worst assignment I've ever
been on. It was so And I went to Ukraine
as well during the war, but this was
worse. The the Moscow trip was worse.
Well, you're in a what is a there aren't
many countries that you go to that are
kind of like um adversarial countries
that that you know that that are
um they're not friends of the UK. And
the BBC out there is seen as an arm of
the British government, even though of
course we're completely independent. So
like there's that plus I'm going there
to track down cyber criminals who we
know have got links to the Kremlin. Um
and it was really intimidating the
entire time. We thought we were followed
at one stage. We flew out to um this
place called Yoshka, which is about a
thousand kilometers east to try and find
um Igor Turv. and we were convinced
there were guys in the airport who we
saw who we then saw at our hotel. Um so
that that kind of thing, you know, isn't
isn't nice. And I'm here complaining,
but really um the the the one that got
off the worst was my um fellow reporter
on the story with me, Andre Zacharov,
who um was and is a very talented cyber
reporter, but he helped me out with the
whole story and he was there the whole
time. And maybe it was that or maybe it
was something else, but he was very
quickly put on the enemy of the state
list um after shortly after that and he
had to flee the country. No way. Because
of the work that you did together, we
don't know if it was that cuz he's done
a lot of provocative to the criminal.
Right. Okay. Okay. And illustrious
pissing off the
It was after that. He thinks that it was
possibly the the straw that broke the
the camel's back. But before he before
he decided to leave, he was followed
around the entire city by some nasty
looking men for weeks and weeks and
weeks. Horribly intimidating for him. He
is a superb journalist and I'm still
friends with him and I know he's doing
well now. But um yeah, I I I can't
complain about my uh my handling or
treatment when when Andre had a really
tough time. Wow. I got scared in a
hotel. Wow. At least I get to stay in my
country though, you know? At least I'm
in my home country still. That's nice.
Exactly. I'll tell you though, when I
got back, I installed a security camera
system on around my house cuz I was I
just started feeling a little bit
intimidated cuz I once interviewed a guy
who um he decrypt ransomware. So like
when ransomware is deployed in the
system, it scramles your files. You have
to pay them to get the key to unlock it.
This guy uh Fabian Wasa is an anonymous
researcher from a company called Mcoft
and he is so good at building his own
decryptors that the the hackers
absolutely hate him when he's searching
through a piece of malware. He has found
on more than one occasion, [ __ ] you,
Fabian. Stuff like that. They write in
their code in case he's looking in case
he finds it. Yeah. Because they hate him
so much. And he fled his country. He
fled Germany because he was so scared
of, you know, some of these gangs are
are very very rich and it wouldn't be
much to drop, you know, 20 grand to go
and get someone's
uh legs Yeah. broken or whatever. Wow.
What was the fallout from that Crowd
Strike thing? Because you've just held
up a cool toy model thing. So, Crowd
Strike, cyber security organization,
maker of cool figurines, but yeah, also
also subject of a lot of bad press only
at the start of this year. What what
first off, what the [ __ ] happened? And
secondly, is this is that what was the
comeuppance of that? Cuz I kind of heard
about it. It was a huge deal. Loads of
[ __ ] happened and then nothing. Well,
give it time. There are some big court
cases against Crowdstrike right now.
There are companies like um oh, is it
United, the airline in the US? Um they
are they are trying to sue CrowdStrike
for something like 7,000 flight
cancellations across the day that that
the Crowd Strike caused the world to
implode. So, the Crowd Strike problem
was um was it this year? This year has
flown by. Maybe it was this year.
Anyway, um so they they did an they did
an update for their um their CrowdStrike
software and and they're like an
antivirus. Um it was a year ago 19th of
July 2024. Oh, it was okay. Last year.
Um and so Crowdstrike is a kind of like
antivirus company, one of the biggest
and best in the world and uh used by
some ginormous corporations including
United to protect systems from cyber
attacks. They did a really innocuous
update where they sent through some
really like tiny bits of information to
keep the software up to date. It
completely bricked the system. It caused
the blue screen of death on something
like I think it was 2 and a half million
computers around the world. And that's
not just computers like we're talking on
now. That's servers that run airlines,
those kind of computers. So, um yeah,
the the world went mad for I think like
3 days. No computers running, flights
canled, uh online services down, shops
offline,
massive massive problems. It was like uh
some sort of apocalypse was was
unfolding. But, um we bounced back.
We're still here. The best image that I
saw of that was someone's smart fridge,
the front screen of a smart fridge,
which is Yeah. Yeah. You got BSODed on a
on a [ __ ] Samsung American chiller.
Um, yeah. It's just, you know, there is
kind of like uh the uncanny valley, but
the equivalent of that for smart homes.
And I still don't think that we're out
of the other side of it. think that most
houses would benefit from a physical
switch on the wall for most things and
that a nice quite simple up and down you
your fridge does not need an app. No,
your I mean look Echo Water that's a a
hydrogen water company that I love. I
love hydrogen water. I think it's
awesome. This like big revolution in
health. What is what's hydrogen water?
So, it's a special type. I haven't got
it here, but like imagine that this
flask um was able to hydrogenate the
water. So, it's it's actually all
self-contained within the the unit
itself. So, it's a kind of hot thing.
It'll be in the UK in 5 years time. It's
big in America. It's coming big in
America. It'll it'll transport over the
Atlantic in about 5 years time. Hold to
it. They have an app for your [ __ ]
Yeah. You don't need that for your flask
and it allows you to change the color of
the LED and it tracks how much water
you've drank. And I'm like, look, it's
cool. I love the product, but the app to
me and then there's they did a battery
update that you need to overtheair
update your flask from your phone. I'm
like, guys, yeah, yeah, yeah, I know
it's cool, but there is a there is just
a little this and I think, look, if you
know, Crowd Strike issues another update
and I can't get my hydrogen water out of
my echo echo water flask, I'm going to
be pissed. So I think the the way that
you
or the way at least that this seems to
be explained is that the hackers are
always going to be out ahead of
governments of they're going to be
coming up with increasingly
um innovative ways to circumvent
both security systems and and law
enforcement to try and track them down.
Is regulation ever going to catch up
with how fast dark web hackers crypto
economy stuff can evolve? Like is this
is there a a light note at all here or
are we just kind of in it for the long
haul? Make sure that you've got a
password manager downloaded. Yeah, I
think I think there are some things that
we can do right now today that would
make it so much harder for hackers, but
but we don't because there's a thing of
like security versus convenience. So,
reusing passwords, keeping your software
up to date. Um,
actually, you know, when you think about
Crowd Strike, that was one of the things
about CrowdStrike that was so bad was
that the people that kept their software
up to date, which is what we're being
told all the time, they were the ones
that got hit. If you were if you weren't
if you hadn't have done the software
update, then you were fine because it
was that thing that that bricked your
system. But no, generally speaking,
Crowd Strike aside, keep your software
up to date. Do do two factor on your or
multiffactor. Um, good passwords. And it
sounds so obvious and I'm bored saying
it. And I know I can see you falling
asleep, but if we all did this, then the
world would be the cyber world would be
a safer place, but but we don't. And
there's a lot of things at the moment
about, you know, quantum computing and
AI and deep fakes and stuff and how this
is how the hackers are getting in these
days with all these whisbang new things.
They're not. If you look at the list of
how hackers are getting in, it's the
same old stuff. Someone said the other
day that nothing in nothing in cyber has
changed for 20 years. Social
engineering, find a person who's
prepared to let you into the system, go
from there. Yeah. Yeah. But also, you
know, that once you get in, they they're
not using the the latest and greatest
techniques to to to move around a
system. They're going through something
that should have been patched a year ago
or or or two years ago. How much truth
is there to this quantum computing will
be able to make all
um encryption totally obsolete because
it can work out prime numbers in the
split of a second and everyone's [ __ ]
Bitcoin is going to be owned by one guy
and all of our passwords are going to be
released. Yes, they call it Q day. the
day when the quantum computers can break
encryption and there's this thing called
um uh I think it's something like grab
now encrypt later uh or decrypt later.
So the idea being that um if you as it
harvest now and decrypt later so if
you're a spy agency for example China or
the UK or the US you can grab all of
this data that at the moment is
encrypted. So all the most important
vital um communications are done with
really high-grade encryption. So if I'm
uh if I'm uh President Trump talking to
um Prime Minister Starmer, we will talk
on a really really secure line which if
I grab that, it just comes out as
gibberish. But if I grab it now, I might
be able to make it unjibberish when Qday
Oh, [ __ ]
That's that that's the worry is that
Yeah. was that Q day will mean that kind
of thing happens. But um I'm trying to
be positive. It is it is a a concern.
The National Crime Agency recently put
out advice saying like the deadline is
2030. I think they said you need to get
everything um encrypted in a way that is
postquantum encryption safe or
postquantum safe now because of what I
just described.
Uh I'm just having a look here. This is
a friend's um
uh a job advertisement for the new head
of cyber security at his majesty's
treasury in Britain provoked derision
because of its stated pay of £57,000 a
year.
That was the total annual salary around
about $70,000 for the head. The head
of cyber security of his majesty's
treasury in the UK. Yeah. Yeah. There's
a big problem. There's a big problem.
Have we considered
low pay as a vector of risk? Like just
disgruntled workers as a potential, you
know, I mean, you don't they call it an
they call it insider threat.
they call it insider threat because
sometimes there will be people in high
levels of power who could be corrupted
but you know that that's I don't want to
start you know I think that's rare
that's a rare thing that we see um they
think potentially this is all alleged
and all you know um reports have come
out so I'm not saying this is this is
what's happened but there's a big thing
at the moment right now with Coinbase
where lots and lots of people have had
their crypto um stolen or exposed osed
and they think that might be inside a
threat. But um yeah, you you mentioned
the salary there. The problem with with
cyber jobs is that you can get paid a
lot of money but not really in the
public sector. It's all in the private
sector. But of course, we need we need
very good people to be in the public
sector protecting the way more important
stuff.
Yeah, Joe, you're [ __ ] awesome, dude.
You're really great. Books book's
fantastic. You're a wonderful
communicator. Where should people go?
They want to check out all of your
stuff. Oh, it's it's um Yeah. So, my
book is called Control Alt Chaos: How
Teenage Hackers Hijack the Internet. Um
and it's out on the 3rd or the 5th of
June. Um the book launches the 3rd of
June. That's why I got confused. Um and
then it'll be in all the usual places
and on um on audiobook as well. And it's
also coming out in Finland and it'll
come out in the US in January as well.
Hooray, dude. You're brilliant. Uh, good
luck doing more investigations. I look
forward to speaking to you again when
you found some more awful people from
the the Eastern Europe that we can can
talk about stories to do with. Thank
you, mate. Thanks for having me on.
Congratulations, you made it to the end
of the episode. And if you want more,
well, why don't you press right here?
Come on.