Hacked - Modified Elephant
Episode Date: July 1, 2022The story of some very incriminating letters and the mission to figure out where they came from. Like Hacked? Subscribe, spread the word, and visit https://www.patreon.com/hackedpodcast to show us s...ome love. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
So this is a story about some very incriminating letters.
Letters discovered on the hard drives of a group of people in India.
And the letters implicate this group of people, many of whom are in jail today,
in a terrorist plot to kill the prime minister and seize power of the government.
They're one of the main pieces of evidence against these people.
The police searched their computers in connection with this deadly incident that happened in 2018.
And these letters are, you know,
publicly at least, what implicates these 16 people as being co-conspirators in this insurgent
plot. The letters are why they say the charges were laid. The letters are why these people are in jail
today. And in 2020, lawyers for one of the accused, an activist named Rona Wilson, were able to get
a cloned copy of his hard drive, the one where the police found those letters, which is where
the trouble starts. Or depending on who you believe where the trouble gets revealed.
because once that cloned hard drive made it into the hands of security researchers,
it started to become clear that the laptop that had this key piece of evidence on it
also had malware on it that had been used to, amongst other things,
place those letters on that computer.
The report made no claims about who placed the files,
only that they definitively had been placed.
And then this past month, a second security firm put out another story, suggesting who was behind the hack.
There's a little bit of history to get through in this one, but really, it is about some very real cyber forensics.
This is the modified elephant conspiracy here on Hacked.
Scott, welcome back. How are you doing?
I am good. Thank you, Jordan. How are you?
I'm doing good. Happy to have you.
Well, thank you. I'm happy to be back.
Got you back just in time for a complicated one.
Let's hear it.
This sounds extra exciting.
If you go back far enough, you end up talking about some in the weeds historical stuff
that is not going to be the focus of this show or this episode or my expertise at all.
I like the weeds.
I live in the weeds.
I know you do.
You're a weedy kind of guy.
But I'm going to try and give enough of like a, I guess a primer on this that you've got your feet under view.
and I'm going to try and refer to some sources
that understand the nuances of Indian
politics better than I do.
But what this ends up being about
is cyber forensics and how we confirm
the genesis of digital evidence
when digital security
can be really hard to maintain.
Very broadly speaking,
there's a few players in this
that you need to know for any of it to make sense.
First is the Bima Corrigan 16.
The 16 people in jail
or under house arrest today.
year, few had heard of the Bima Corregan battle or its sheer importance for the Dalit community,
especially the Mahars.
The Dalit are celebrating this Bima Corriga victory.
Bima Corrigan in this context refers to the 200-year anniversary of the Battle of Bema Corrigan.
It's this battle of historical importance to the Dalit people.
When you hear about the caste system in India, the Dalit were historically kind of the lowest
rung on that caste system.
They're a presently and historically persecuted group.
And in 2018, it was the 200-year anniversary of the Battle of Bima Corgaon,
this big battle where a small Dalit army won against a much bigger one.
And there was this large event organized in the town of the same name.
So you had Dalit people, activists who fight for Dalit rights, political leaders,
all gathered for this 200-year anniversary event, a celebration of this anniversary.
And in some ways, kind of a protest against the current government,
which a lot of folks in this group say continues to disenfranchise
the Dalit.
First day of the anniversary goes great.
There were speeches and music and dancing, all good.
But on the second day of the event, January 1st, first day of 2018, a group of people from a nearby
area marched to the Bima Corr Gown anniversary.
What happens next is a matter of debate in the court.
But what is claimed by the defense is that the mob that was marching on the event was chanting
anti-Dalot slogans as they approached the anniversary.
and they began to attack.
What we know for certain is that violence broke out,
35 people were injured with two deaths.
This sparked Dalit protest around the country,
and over the days that followed,
more than 300 people were arrested by the police in Mumbai alone,
some as young as 14, many still in prison.
This was like a big news story in India.
It was a violent clash over this long-standing political and racial tension.
The next important milestone in the story
takes place a few months later in April.
This is Fay-Desusa, a journalist in India,
who has covered this at length on her series, the whole story.
By April, Pune Police started searches in the residence of eight people.
Now, they searched the homes of activist Rona Wilson, human rights lawyer, Suryendra Guddling,
Dalit rights activist Sudein, Davale.
The computers of Wilson and Guddling were seized.
Now, this is an important point.
This you should remember.
Let's put a pin in that.
The Pune Police, the police from the larger district,
where all of this kind of happened,
started conducting searches in the homes of eight people,
including a guy named Rona Wilson,
whose laptop this is kind of all about,
who are all in attendance at this anniversary event.
Rona Wilson is a Dalit rights activist.
The search in April is when his computer gets seized by the police.
In May, an Indian anti-terrorism law
was used to bring charges against these people
based on the incriminating evidence found on Rona Wilson's laptop.
The police also searched at the workplaces and residences of Mahesh Rao, who was a land rights activist,
and Shoma Sen, who was an English professor.
They were also both arrested.
And in June 2018, the arrest began.
Their main piece of evidence cited to the press, the letters they found on Wilson and several other people's computers.
The question is, what did these letters say?
Now, the police basically said that they found electronic evidence on these computers.
that they had seized that the group was involved in a plot to assassinate the prime minister,
Narendra Modi.
Okay, this is the last bit of history I'm going to go through here.
And then it's all computer stuff.
The next character or kind of group you need to know for this cyber security story to make sense
is the Maoist branch of the Communist Party of India.
Beauty.
The Communist Party of India is like a normal political party.
They are legal to join, legal to vote for.
The Maoist branch is a outlawed guerrilla military insurgency based in the jungles of India.
They have been engaged in like an active, violent conflict with the state for decades.
It is a crime to be a member of this group.
It's a crime to support this group.
They're a nationally designated terrorist organization.
The letters that were found on the hard drive by this investigation tell a very strange and remarkable story.
The Maoist military insurgency, they are deep off the grid.
Rona Wilson and the rest of the academics, politicians, activists that had been arrested,
they are not fighting in the jungle.
They are very much on the grid members of society in India.
These letters found on Wilson's laptop reveal a plot
that these 16 people had been conspiring with the Maoists,
not just sympathizing but actively planning this conspiracy with them.
According to these letters to and from the arrested, using their legal names, which is poor operational security,
Wilson had been corresponding with the Maoist party attempting to coordinate the delivery of arms and munitions to help them in their fight.
And much more than that, he was really laying out the architecture of an assassination attempt against Prime Minister Modi,
whom Wilson is in real life and outspoken critic.
That he and his network were going to be able to assist in funneling resources from Russia and China.
He was suggesting in-person meetings between Wilson and the Maoists.
In no uncertain terms, these letters are outlining a plan to overthrow the state.
Smuggling weapons and funding Maoist activities in an attempt to overthrow the government.
So these are really, really serious accusations.
At this point, being investigated by the Pune police.
When you refer to these as letters, are we talking about emails?
Are we talking about Word documents that were to be printed and mailed?
That's a great question.
So when we refer to them as letters, we're referring to very specifically Microsoft Word documents
that either were to be or had been printed and mailed.
I would have assumed just given today's day that any high functioning terror cell
would be at least having use of cell phones and maybe some basic encrypted emails.
Okay, so these are real letters.
Like we're talking about like 1950 snail mail, print it, sign it, put it in an envelope,
stamp on it, mail it to the jungle letters.
I might be wrong about this, but I think one of them was literally typed in like the old
career typewriter font, which again, in Microsoft Word, like it does have a really old timey
conspiracy aesthetic to it.
I like that.
Except for the fact that they were discovered on computer hard drives.
Sure, they were guerrilla conspiratorial communications that somebody spent the time to
type up in Word and would then print and then.
somehow have delivered to people in the jungle.
I think when it's a conspiracy, you call them communiquees, but otherwise you nailed it.
Okay, okay, okay.
And instead of using, you know, any of the million encrypted messages that you can use these days,
we're going to literally type a letter and word in courier font, print it, put it in an envelope,
somehow figure out a way to get it to somebody who's in the middle of a jungle in some form of timely manner.
You seem to have a really good grasp on the whole situation.
See, a letter is just so much more personal.
Maybe I was there.
Maybe I was there.
So on September 1st, 2018,
the Pune Police hold this press conference,
an important press conference that will come up later,
in which they break protocol and disclosure of evidence,
but in which they, to the nation,
share these letters with journalists and the public,
presenting their primary piece of evidence,
proof of what they, the government,
had been hinting out for some time, that there were now Maoists, not just in the jungles,
but in the cities.
Urban Maoists, as Prime Minister Modi would go on to call them in a speech shortly after,
a term coined in response to this incident.
Three days ahead of elections in Chattisgar.
The Prime Minister shifted BJP's poll campaign in Top Gear, addressing a rally in Jagdalpur.
He launched a no-holds-barred attack on the alleged Maoist sympathizers or urban knuckles.
The Prime Minister said,
the so-called urban Maoists were remote controlling violence and killings in Chattisgad.
While they themselves lived in air-conditioned houses,
they did not let the fruits of development reach the people on ground.
Let's listen in.
The urban Mao-wadi has in the air-conditioned gharoma rethes.
The B. McCorragound 16 had been arrested, and this long multi-year trial commences.
So several years go by.
Some of the 16 are still in prison, others are under house arrest,
but the case is kind of slowly grinding its way through the courts.
But in 2018, Rona Wilson's legal defense finally gets a hold of a cloned copy of the hard drive.
The hard drive of the laptop where they found these letters.
And they reach out to a security firm called Arsenal Consulting
to perform some cyber forensic analysis on this drive.
This case is still ongoing, so Arsenal very politely.
told us they could not talk with us on the record about the report until the trial ends.
But the report speaks for themselves.
And here is what it found.
On an afternoon in June 2016, several years before the violence at the B. McCorrigan
anniversary, Rona Wilson gets a bunch of emails from his friend and fellow activist, a person
named Varvara Rao, another one of the people arrested.
In the emails, his friend Rao was urging him to read this state,
from another civil liberties group to just click on the link.
Yeah, always a good idea on this show to click on links.
Yeah, absolutely.
Instead, Arsenal found.
The link actually deployed something called Netwire.
You heard of Netwire?
I haven't heard a Netwire.
You might not have heard the name, but you know what it is.
I think you taught me about these.
Netwire is a remote access Trojan.
It's consumer level, deployable.
It's pretty easy to get your hands on.
and it does what most remote access Trojans do.
Give you access?
It gave the attacker access and control of Wilson's device.
The malware logged Wilson's keystrokes, his passwords and browsing activity,
but Arsenal kept digging beyond Netwire to try and work out
if the attacker did something beyond just monitoring Wilson's activity.
They ever took control of his computer to do something with it,
which is when they recovered some system file information showing
that the attacker had done something else.
They'd created a hidden folder on Wilson's laptop.
And into that folder, they placed 10 files.
A collection of incredibly incriminating letters
between Comrade Wilson and the Maoist Party.
Actually, the thing I find funny about that,
and this might not make it in,
the thing I find funny about that is that he never goes
by Comrade Wilson anywhere else, like in real life.
But they kind of, they gave him the little,
nom de plume for this. I thought that was fun.
Just for some color, a little color, you know,
just to liven things up.
He's a comrade. The same letters
the Pune police had gone on television and
read for the entire country.
The evidence against the 16
had been planted.
So Arsenal digs deeper.
In their initial report, they confirmed
that the letters had been created in Microsoft
Word. And while Wilson did have
Word installed on his system,
the version that the letters were created with
was newer than the one Wilson had installed.
They were then able to confirm that while the letters were on Wilson's hard drive,
they'd never actually been opened by his computer.
They had, with absolute certainty, been created on another machine
and remote transferred into a hidden folder that Wilson never accessed.
The cyber attacker had planted the alleged letters for that entire plot.
Now, this was reported by the Washington Post.
So this is all pretty damning.
Sort of damning.
It's a little damning.
But Arsenal doesn't make any claims
about who they think placed in the files,
only that his system had been compromised
years prior to his arrest
and the letters had been placed in the folder.
Washington Post breaks this story back in 2021.
And for context,
the prosecution of the case
has since claimed that their cyber forensic analysis
did not find any malware on the system.
They just kind of missed it.
So it's easy to miss this
because of kind of how egregious all of this is starting to seem.
But the timeline here is kind of weird, right?
Like, Wilson's computer was breached in 2016,
years prior to the thing that he was arrested for,
which let's say for a second we're sort of staring at the, you know,
iceberg peak of a little evidence fabrication plot.
It's a pretty lucky one.
Like the odds that the people who would be at this event
where the violence broke out,
were the exact same people
whose machines had been compromised years before,
those odds are pretty slim.
Unless, hypothetically,
whoever had installed that wire on Wilson's computer
was actually spying on a whole bunch of people,
unless they'd compromise the systems of hundreds of folks.
And when this B. McCorrigan violence occurred
and time came to drop files on these 16 people's computers,
they already had their way in.
Because this was actually just part of,
a much faster hacking operation
that targeted not dozens,
but rather hundreds of individuals
across India for nearly a decade.
Unless hypothetically, that is what is going on here.
Hypothetically.
A little state-sponsored monitoring, maybe.
A little hypothetical state-sponsored monitoring
right after the break.
Think about the last time you heard
a breach story on this show.
It always starts the same way.
Someone, somewhere,
saw something too late. An alert buried, a signal missed, an SOC that just couldn't keep up.
Arctic Wolf set out to solve that problem by rebuilding security operations from the ground up for a
world where attackers are already using AI. They created the Aurora superintelligence platform,
a fully agenic system powered by the swarm of experts. Instead of single-purpose bots or lucky-guess
LLMs, this swarm is full of deterministic agents that handle whole entire workflows.
Humans stay in the loop and on the loop to validate the critical decisions and keep everything trustworthy.
And all of this is just off running on their secure operations graph.
A constantly updating intelligence engine fueled by more than 9 trillion telemetry events every week
and over a decade of real-world incident response.
The system reasons on real signals and real context not synthetic training data.
And the result is the new Aurora agent SOC.
It's the first SCC that is agent led by design.
You get agents that coordinate, agents that investigate, agents that respond at machine,
speed and hundreds more that automate the repetitive work that normally buries human analysts.
Arctic Wolf didn't try and bolt AI onto an old model. They rebuilt the model entirely.
What makes it even more effective is how it works with Arctic Wolf's concierge experience.
The team brings customer-specific context directly into the platform so every AI-driven
decision reflects your environment instead of generic assumptions. The automation frees your
concierge security team to focus on higher value strategy and proactive risk reductions.
while the agents handle the grind.
If you want to see what trustworthy, production-ready AI and security operations actually looks like,
go to arcticwolf.com slash hacked.
Never feel like cyber threats are evolving faster than anyone can keep up?
Last year, 2025 was nothing short of a record-breaking year for major breaches,
from sophisticated ransomware operators to AI-enabled attacks that turned defenses on their head.
Organizations around the world saw headlines they never expected,
than cybersecurity teams were tested like never before.
But here's the thing.
These incidents aren't just news headlines.
They're learning opportunities.
And that's why Arctic Wolf is hosting a live webinar on February 5th,
diving to the most impactful breaches of 2025.
Their field CTO and security leaders are going to unpack not just what happened,
but why these attacks succeeded.
And most importantly, what businesses can do to fortify their defenses for it's too late.
You're going to walk away with real insights into how threat actors are evolving,
how defenders are responding,
and what strategies can help you stay ahead of the next big breach.
It's not fearmongering.
It's practical, actionable, intelligence from experts in the trenches.
Register now at arcticwolf.com slash hacked.
And we can't go to India.
Yeah, it was kind of rude of me to go there twice before recording this.
You've been to China, too.
Have you been to Russia?
I haven't been to Russia.
Wow, well, you're never going to be allowed to.
I hadn't really thought about that.
I had thought of it.
about that.
I'll find a way in.
I'm sneaky.
I'm clever.
If I was going to find a way in,
me just saying I'm sneaky,
I'm clever, I'll find a way in
is definitively the reason
I will never get into that country.
So we're talking about this this month
because of what a second
cybersecurity firm discovered
recently.
After the Washington Post story
broke in 2021, this little army
of cyber forensics professionals started looking into this. And the main one for Act 2 of the story
is a company called Sentinel One. Back in February of this year, Sentinel One published a detailed
report on what they are calling Modified Elephant, which is their name for the much larger conspiracy
of hacking that this was allegedly part of. They determined that these 16 people were not the only
people that this campaign has gone after. And their February report outlined how these same hackers
had targeted hundreds of different lawyers, activists, journalists, academics,
with the same tactic, a phishing emails leading to remote access Trojans, starting back in 2012.
And just like Arsenal, their first report didn't say who they thought was behind it,
who was focused on the scale of the operation.
What they did point out, and you got way ahead of this, Scott, is that the activity, quote,
aligns sharply with Indian state interests.
And then this month, they publish article number two.
Sometime between February and the publishing of this report,
an anonymous security researcher reached out to Sentinel One.
This anonymous researcher came with some information in hand.
Scott, you get remote access into someone's system.
You're logging all their passwords and their usernames.
You got access to all their stuff.
Yep.
But you've taught me about this idea of backdoors before.
There would presumably be a temptation to create some kind of backdoor access
into those accounts if say your net wire access to their whole system ever went away, right?
Well, you know, if you wanted to protect your access to all of their information, you know, why not?
Maybe you set up their two-factor authentication or backup reset passwords and emails to go to your stuff.
You know, you could do a bunch of different things.
Well, Scott, these hackers had the same idea.
Shocking.
In 2018 and it was the same idea, but I'm not sure it was as well executed as I think you're imagining it.
In 2018 and 2019, three of the B. McCorragound's 16 email accounts were compromised.
And as a backup mechanism for the attacker to maintain access to that system,
a recovery email and phone number was added to these Gmail and Yahoo accounts.
So if the hacker ever lost access to the machine, they could still get into those accounts.
You see the accounts belonging to Wilson, his friend Rao,
and an activist and professor in Delhi named Hannibaboo.
And the researchers at Sentinel One started looking,
the recovery emails added to the hacked accounts.
And the name on that recovery email belonged to a member of the Punei police.
You got to be kidding me.
The same department that went on TV and read the letters.
So now this anonymous researcher and Sentinel One are working together, and they keep digging.
Amnesty International is now joined in on the fund.
Their security lab, who we've talked to before.
they're all doing their own cyber forensics in concert.
This is clearly some big dodgy nonsense going on here.
But say hypothetically you were bending over backwards
to engineer a little plausible deniability for the Punei police.
You could say that anyone could theoretically add an email
and number as a recovery to an account.
Just because their name was on an email added
to a system that was hacked
doesn't mean it was the hacker who added that recovery email.
Of course.
Of course, right?
Maybe it was the Bema Corrigan 16 who framed the Punei police.
Maybe.
Which is when Cental won an Amnesty International discovered
that the email account had been accessed by an IP address
previously identified as being used by the larger modified elephant hacking campaign.
In Rona Wilson's case in particular, the anonymous analyst figured out
the Wilson's email account got sent another fishing email in 2018
and then appeared to be compromised by the hackers using those same IP addresses
at the exact same moment,
the email and phone number connected to the Pune Police
got added as recovery contacts.
Definitively connecting the Pune Police for the modified elephant IP address.
But let's keep digging further,
because that is what these cyber forensics nerds did.
After that, Wilson's email account was used to send out more phishing email
to other targets in the Corrigan case for about two months before Wilson was arrested in 2018.
His email was used to fish other members of this case the same way his friend Rouse had been used to target him.
For their coverage of this this month, Wired got in touch with a security researcher at Toronto Citizen Lab,
who confirmed that the NSO hacking tool Pegasus, which we've talked about,
had been used to target some of their smartphones.
Then, to eliminate the remote possibility that maybe the Punei police didn't control,
the recovery emails, even if it was the hackers who had added them.
The same researcher at Citizen Lab went digging through this open-source database of a ton of Indian mobile phone numbers and IP addresses,
looking for the punet at ic.in suffix used by the police email addresses,
which is when they found that the number is also linked in a database to the recovery email connected to the hackty accounts for the same punet police official.
Separately, a security researcher named Zashan Aziz
was able to connect the recovery email and phone number
to the Punei police official using the leaked database
using this Indian job recruitment site
which underwent this big data leak.
And when that leak occurred,
it would have forced a two-factor authentication
between the phone number and the email,
which successfully occurred, suggesting that the police controlled both accounts.
This is the last one.
Last piece of evidence.
If you've tuned out at this point because I said the word fishing and email and account one too many times.
Recovery, recovery.
And recovery.
This is where the proof ends and it's the most like, well, there you have a one.
You can call the phone number and the guy picks up.
It says, yes, I did this.
Yes, I did this.
It's actually his voicemail.
I'm guilty of this.
You've reached me at this number.
I am a criminal.
To put a bow on.
You remember the press conference at the beginning of the story where they read out the letters on TV?
The Citizen Lab researcher managed to find a WhatsApp profile associated with the recovery phone number added to the hacked accounts.
And that WhatsApp profile has a profile picture.
It's a selfie.
Drum roll.
And it is the face of the same police officer who went on TV and gave that press conference.
My mind goes somewhere darker, quicker.
Ooh.
And it goes to a identification and targeting of people who are in opposition,
active opposition to the government norms, leadership, government leadership norms.
And then adding them to a dossier or collection of people who receive advanced monitoring, et cetera, et cetera.
You know, I could see that.
That is very dystopian, but it's like,
you know we kind of kind of seems like the modern world's taking a little step towards dystopia
every now and then and you know i could see that being a thing the the thing that makes it that
breaks me from that that feeling is the fact that this is just appears to be a regular detachment
police officer if it was a special branch that handled this stuff they would be probably quite
better at it you know they would have anonymized emails for recovery like the fact that there's
not like a random this doesn't all
landed like a random proton mail, you know, dark web proton mailbox.
Sure, sure.
It's shocking to me.
The fact that it goes to someone's personal cell phone and someone's personal email is a bit
strange, or at least one that's linked to one that's linked to someone's personal email.
Totally.
And that's like that pulls me out of the fact that it's a little bit more state sponsored
and maybe it was a bit more ad hoc.
On the defensive side, this is a tangent, but on the defensive side, you know,
Operational security is the weakest link, right?
It's you can have an incredibly advanced IT department and someone that is locked down almost
every corner of the system and then that system collapses because one person clicks on an email.
Oh.
And it kind of feels like this is, my take on this is that happening but on the offensive
side.
It's that there are people who are quite good at what they do who at a certain point at scale
end up collaborating with people who don't quite have that proton mail level of security.
So the system that you compromised three years prior ends up in the hands of a person
that doesn't know not to use a phone number that can be worked back to them as a recovery email
because they think it's never going to come up.
That's my take on it.
I guess that's the beauty of people like all the security and forensic researchers.
Is there the people that get to hold the people who aren't as qualified accountable?
You know, because in an olden era, you know, planted evidence was just planted evidence.
But now we've got people who are better at detecting the planted evidence
than the people that are planting the evidence.
It's not the same as a bag of weed in the glove box or a gun in your back pocket that you've never seen before.
So it was hard to say what's going to happen next in the case of the Bima Corgan 16.
it's ongoing, but, you know, Arsenal, Sentinel One, and that community of forensics folks
seemed to have unearthed a pretty damning situation, that these people weren't arrested because
the violence that broke out at this event was an intentional plot by Urban Maoist insurgents.
They were arrested for political reasons.
They were targeted by this hacking campaign, and we have no reason to believe that just because
they were the first defense to expose this, that they were the first people charged based on
fabricated evidence as part of the larger modified elephant campaign.
One of those 16 defendants,
84-year-old Jesuit priest, guy named Stan Swamy,
who was a Dalit rights activist, that's why he was there.
He died in jail last year.
Farver Rao, who was 81 years old and reportedly in pretty poor health,
it was recently let out on medical bail,
which expires in about a week's time from the moment we're having this conversation.
Of the other 14, only one has been granted bail.
Despite what we've learned, these folks are still in jail.
So this isn't the first time something like this has happened.
You brought that up.
It's not the first time cyber forensics has been used to reveal evidence fabrication.
To name one example close to this story, Sentinel One, the group that cracked this kind of open,
also unearthed a similar story in Turkey a couple years ago,
a case called egomaniac in which Turkish police targeted a group of journalists with associations to a TV station that was critical of the governing party.
And they did the same thing.
They infiltrated a system using a fishing scheme,
deployed a remote access Trojan to drop files
that would be later cited as evidence.
And it's a really good thing
when cyber forensics can reveal
digitally fabricated evidence.
It's this really kind of cool, collaborative thing
where all these different researchers
come together to dig through the muck
and figure out what happened.
And it's a kind of collaborative forensics
that couldn't have really happened in the past.
But for however many of these cases get tackled in this way,
the question kind of remains, you know, how many don't?
How many cases that hinge on digital evidence get enough attention
or have a defense with enough resources to hire digital forensics?
How many people are out there waiting for someone to crack open that hard drive and start digging?
Thanks for listening, everybody.
This was an interesting story,
and I appreciate it involved waiting in this very sensitive political
stuff that is still active and ongoing. I hope we got everything right. If we didn't, please just
get in touch and let me know. I encourage folks to read more about this one. And a big thank you
to our patrons on Patreon. That's patreon.com slash hacked podcast. Best voice for the show. Steve Wang,
thank you very much, buddy. Appreciate your support. Chuck Davis. Thank you. Janice Newman,
appreciate the heck out of it. DeCis Serennavison. Appreciate the heck out of you. And Jamie Murray,
thank you very much.
That's patreon.com slash hackt podcast.
That's another one in the bucket.
We will catch you in the next one.
