Hacked - Wizard Spider

Episode Date: May 2, 2026

Investigative journalist Geoff White has spent a lot of time inside the leaked communications of Conti — the Russian ransomware gang that ran like a corporation, hit Ireland's national health servic...e, extorted the Costa Rican government, and pulled in $180 million in a single year. Geoff joins us to break down how Conti operated, the internal moral debate over hitting hospitals, the jewellery heist that spooked them into apologizing to Saudi royals, and how he tracked down rare video of the gang's elusive alleged boss, a man almost nobody had ever seen. It's a preview of his new BBC series Cyber Hack, dropping June 1st. Learn more about your ad choices. Visit podcastchoices.com/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 The number one thing to understand about the people who run these campaigns is they do not think of themselves as crooks. There's a small part of their brain that must know it, but that is overwhelmed by the bit of their brain that casts this as a business. Jeff White is an investigative journalist, and he's looking into this guy who goes by the online handle, Stern. Stern was, according to the accusations against him, the leader of one of the biggest organized ransomware gangs on. on Earth, a group called Conti. I've heard that name before. You've heard that name before. You've heard that name somewhere before, Jordan.
Starting point is 00:00:38 It's on some cybersecurity show. Conti was a Russian-speaking ransomware operation. They came out of an older Russian crew by 2021 at their peak. They're pulling in something like $180 million US dollars every year. They ran like a network. Affiliates around the world broke into companies, stole copies of the data, deployed Conti's malware to encrypt the originals, and then the demand, often millions, typically in crypto, for the decryption key.
Starting point is 00:01:08 Pay and the stolen data stayed offline. Don't pay. And it didn't. That group's name was Wizard Spider. Shattered Eagle Dome. No, it actually was Wizards Spine. Was it really? I thought that was, I know they had many names.
Starting point is 00:01:26 All of these groups do. That's funny. What wasn't funny? They're victims, hospitals, schools, governments, Ireland's national health service, the government of Costa Rica. We talked about that one here on Hacked. Hundreds. And Conti was famously corporate.
Starting point is 00:01:46 Most ransomware crews pay their affiliates a cut. Conti paid their salary payroll on the first and 15th of the month. Performance reviews, an HR department, an employee of the month. That's what I'm saying, you know. Malware is the service. Malware is an enterprise. And in this LinkedIn post, I'll explain how to synergize them all. Stern allegedly was the boss.
Starting point is 00:02:12 Now, part of the trick of being the boss of an international cybercrime syndicate, as I understand it, don't appear in a lot of photos. Check's out. You've heard the old adage, no press is bad press. Broadly speaking, untrue for the heads of cybercrime gangs. You're going to want to keep a low profile, Scott. And at the time that Jeff was looking into him, there was basically like one known photo of Stern. It's the photo in his Interpol notice.
Starting point is 00:02:40 Until, as part of his reporting, Jeff gets this message. Someone on Telegram put us onto a social media account for someone who is very popular on social media. They're an influencer on social media. It turns out, Stern, this rarely photographed kind of unassuming alleged head of a vast cybercrime network is friends with an influencer. Of course. I was about to say, are they themselves an influencer? Because that would be extra funny. They were not, but she was. And this woman has a pretty significant, like, social media following.
Starting point is 00:03:18 And so there's all these videos, like thousands and thousands of videos with millions of viewers, some of these videos. And I thought, well, surely, you know, the world's most wanted hacker, you know, the internet's gangster number one, according to the accusation. against him. He's not going to appear in these videos. Oh, no, he's there. He's waving at the camera, you know, bopping around to music, seen on holiday, you know, driving around in the car with this other individual. Absolutely amazing. Jeff White has spent like a considerable amount of time researching Conti as part of a new upcoming series for his show, Cyberhack for the BBC. It's the third season. First two are definitely worth a listen. I rarely get to spend months
Starting point is 00:03:56 combing through leaked communications between cybercrime operators. unraveling the tangled corporate bureaucracy of some of the world's most prolific digital criminal operations. But he did. So naturally, I had some questions. Jeff White, author and investigative journalist, was kind enough to chat with me about Conti, about translating Russian hacker slang, about the history of this group, and the future of this kind of crime on this episode.
Starting point is 00:04:24 Without further ado? Without further ado. Of hacked. Jeff White, thank you so much for joining me. Thanks for having me. I'm a big fan of your work. There are a lot of things to pull a reporter to this story. What pulled you to reporting on Conti?
Starting point is 00:04:54 Well, I was looking for a way into the ransomware story, and the BBC World Service and the BBC who make the podcast, a cyber hack podcast, were also very interested in that. Obviously, in the UK, we've had some very, very significant ransomware attacks over the last year or so, there was a point where the ransomware tax actually had an impact on UK's GDP, you know, our national bottom line was affected by ransomware attacks. I heard a stat the other day that the government reckons cyber attacks in UK cost us something like 15 billion pounds a year, you know, it's about a half a percent of our GDP goes on cyber
Starting point is 00:05:30 attacks, and that's absolutely astonishing. So you wanted a way into this, but we also wanted, as we always do with these podcasts, you know, some colorful characters, some thrilling stories. And the most important thing was that, to tell a story for me anyway, you need three things. You need a victim, you need a villain, and you need a hero. You know, it's pretty basic stuff. Often, getting the heroes is actually not, not usually too difficult. You know, the police, you know, talk about how, you know, the great things to do. It's great. Getting victims has always been quite difficult, but has got a little easier over the years, you know, that people wanted to speak out about what's happened has got, it's got easier. Getting the villains is
Starting point is 00:06:08 is pretty hard, as you can imagine, you get stories of cyber criminals who've been in prison and come out, you know, people have gone straight, you know, having broken the law. But what we had in the Conti gang, which is remarkable, is actual contemporaneous conversations that they were having at the time they were doing their hacking, which was subsequently leaked. And so you can hear them talking about the stuff they were doing as they were doing it. And so we've got instances where we sort of line up, you know, what the victim was experiencing, and then we line up what Conti was saying about in the backgrounds. Absolutely astonishing. Yeah. Oh, there's so much to unpack there. Victim, villain, hero, and this debate inside of
Starting point is 00:06:45 Conti, not as to whether or not they want to be the villain or the hero. I don't know if it ever quite gets up to that point, but about what kind of villain we are maybe. Yeah, absolutely. And actually, that's a really astute observation because Conti, I have this theory that if you're going to do, you know, advanced cyber crime, you're bright, you're a smart person. And you've got to wake up every day, and particularly with ransomware, it's quite hard to escape what you're doing. You are basically blackmailing people, threatening people, intimidating people. I don't think as an intelligent person, that's really what you want to wake up and do every day. But that's your job. So you have to have some psychological framing that allows you to do it. And the way that
Starting point is 00:07:27 gangs like Conti and other ransomware gangs do this is they reframe it as a business. You know, we're business. We just have this software, this encryption software, that turns out to be really good. And, well, you know, I guess you've been caught by it, and now you have to pay us some money. You know, they've described themselves some of these gangs to me in chats as post-paid penetration test. So you would normally hire penetration tests to do a test. Well, they've done the test. You just didn't hire them. Well, now you owe them some money because you've got the results. This is the framing that they have. Now, what's interesting about that is the way that breaks down within the actual gang, within Conti, is sometimes you have people who, who, you know, really draw
Starting point is 00:08:06 red lines around what they're going to do. They say, we don't attack hospitals and we have to negotiate, you know, with the victims, we have to give them a fair chance and we have to really be professional. We need to be professional here. And you've got the other extreme, people who say, I'm a computer hacker. I'm going to do what I like. I'll attack a hospital and I'll, you know, drag them through the dirt if I have to get the money. So you get this range of people within this gang from the very, very hardcore criminals to the kind of people who say, no, no, we're a business. It's fascinating, really fascinating. That's so interesting. It is a little bit like likening the classic trope of like the mobster threatening someone. It sure would be terrible
Starting point is 00:08:41 if your business burned down as being like, well, that's pre-fire insurance. It seems a little, I don't say disingenuous, but I have a hard time wrapping my head around that one. Yeah, I mean, they, you know, I think this is one of the big revelations for me is, it's you'll have had this, you know, Jordan, that people describe cyber crime. It's a business, you know, it's a nine to five business. I've heard that so many times, but when you get up close and personal with the Conti gang and you read through their messages, it suddenly dawns on you quite how much of a business this is. It is, they have payroll, they have sick pay, they have holidays, they have a bonus scheme for operatives. I mean, and what was interesting was they've got
Starting point is 00:09:21 two problems of Conti gang. One is recruitment. They've got to get people through the door. They've got to hire people. And of course, they can't be really honest about what they're doing. So they have to subtly suggest to people what they might be doing. And they also have to, when people realize that this is going to be a criminal enterprise, they have to reassure people that they're hiring and say, no, no, no, no, yeah, we're a cybercrime gang, but you know, you can trust us, we're going to pay you, it's going to be professional, we'll teach you, we'll train you. I've seen them talking about, you know, we take good guys and we hire, you know, we bring them up. The second thing they've got, obviously, the ransomway gang is when they go to the victim, they've got a
Starting point is 00:09:56 convince the victim that even though the gang has done something awful to them, you know, they've scrambled all their data, they've stolen all their data, it's okay because if you pay the ransom, you can trust me, I'm going to decrypt the data. And that's where the professionalism comes in again, is, you know, you give us the ransom, we have got the decryption key here, ready to go. You know, we'll send it to you and we'll make sure your files are decrypted. Some of them even offer a sort of report about how they got in so that you can secure your weaknesses. That level of professionalism is core to what these gangs do. and how they are. That's so fascinating. We've been talking about these gangs for a while,
Starting point is 00:10:31 and the corporatization of them is maybe the most interesting thing. Like you brought up, they have HR departments, they have monthly payroll, they have salaried programmers and employees. You learned so much about how this group works based on this moment. And I'm wondering if you can kind of take us back to it. It was like, I think it was 2022. Russia's just invaded Ukraine. Conti's kind of come out publicly in support of that. And within days, an insider there dumps this corpus of text. Take me through that moment and what you learned.
Starting point is 00:11:00 Yeah, yeah. So it's worth noting Conti at this point were riding high. The end of 2021, they were making loads of money. The FBI estimate for Conti's take in 2021 was $158 million. That is a vast underestimate.
Starting point is 00:11:13 That's just the ones they knew about and the sums they've added up. And so you see in the chats, this brilliant moment at the end of 2021, where they're just, they're going to take a month off, they're going to have a party over Christmas. And there's a comment in the,
Starting point is 00:11:26 chats, which is really interesting, which is, you know, 2022. It's going to be as good as 2021, even better. We're going to push this. And then, of course, as you said, the war happens. Now, who leaked these messages? We presume it's an insider from Conti. Certainly somebody who had access to Conti's messages. But from the researchers that I've spoken to and from whom I've heard, a lot of researchers
Starting point is 00:11:47 were sniffing around Conti. A lot of the cyber security companies were trying to access and penetrate this gang, as well as law enforcement in the US, in the UK, and so on. It's feasible that it was law enforcement that leaked them. It's feasible. It was somebody, some intelligence agency. It is also entirely feasible. It was a member of the gang because, as you say, Conti declared support for what Vladimir Putin called his special operation. That was not the uniform view of the gang. There were people in the gang who were based in Ukraine who freaked out when the invasion happened. And so it's possible this was an act of revenge by one of the Ukrainian members of Conti, what we got as a result of that
Starting point is 00:12:26 was actually two leaks. Firstly, the Conti leaks, and then secondly, a thing called the Trick leaks. You start to get into the weeds of these gangs here, but before Conti, there was a gang called Trickbot, which seems to have been servicing members of Conti and then effectively seems to have morphed into Conti. I had to explain to the BBC that these gangs don't have corporate registration documents where we can go and look up, you know, when they were created and who their directors were. Sure. It was not a formal aqua hire where we can trace the owner. Yeah, I got you. No company's house for ransomware, unfortunately. So it's kind of murky, but so what happened was that the Conti leaks came out and I was aware of them, sure you were,
Starting point is 00:13:04 lots of people in industry were, you know, this huge leak of data. The Conti leaks was about 75,000 messages or so. And then we have the trick leaks which comes out, which is about another 200,000 messages. It was fast. This is every message that the members of the gang typed to each other every second of every day for about two years. It's just astonishing. I've been trying to quantify this and work it out, but I really think it must be one of the biggest data dumps of criminal activity that's ever been released. You know, when you put a gang under surveillance with a wire, you might get a few hundred hours of tape, but this is two years. This is 300,000 messages. But there were problems, obviously, with interpreting those messages, which I'm sure we'll go into.
Starting point is 00:13:46 but it's an amazing, amazing resource and one that I really wanted to have in our podcast so we could hear these guys, literally hear them in their own words. It's such an amazing body of information for a reporting project like yours, but I want to talk about what you just brought up. So it's like, what did we learn about this group from this leak and then what were the challenges in interpreting this information? Because it's, it's not a nice, clean, you know, a little zip folder of easily parsable stuff. Unfortunately, it's not. No. I mean, look, we. We learned a huge amount, as I've talked about, about how the gang operated, about their sort of bonuses and incentive schemes, the holiday pay and so on, how they recruited, how they retained staff, what their pay rates were.
Starting point is 00:14:26 We also learned some really interesting things about how the gang proceeded as they went along. So one of their members gets arrested, a woman called Ala Witt. It was fascinating. She's Latvian originally, and she's 55 years old, I think, when all this happens. So she's older and a woman, which is a very unusual demographic for cybercrime. She gets arrested. There's a whole tale which we tell on the podcast about how that happens. So we can see that that arrest happened. And we knew about the Allerwick case. What's fascinating from the leaks is you can see when that happens,
Starting point is 00:14:59 the Conti Gang for start took ages to find out about it. They didn't realize that this person had been arrested. And then when they did, they didn't realize that she was a 50-year-old woman, 55-year-old woman. That came as a huge shock to them. And then they suddenly realized that she's in the US. and she's potentially going to give the US authorities access to the data that she's got. Or they might somehow force her to give access or gain access.
Starting point is 00:15:22 That's bad. So the gang suddenly realized they've got to spring Allah from prison somehow. They've got to get a lawyer to defend her. But then there's this thing of, well, yeah, we have a lawyer, but how do we pay the lawyer? Because we're kind of conti. We can't really send a check. So they try to work at how they can use money that they were going to get from a US victim of ransomware and somehow channel that money through to the lawyer.
Starting point is 00:15:43 in the US, absolutely amazing. And of course, all this is unfolding as, you know, as Allers being arrested. But the other thing that was interesting, you mentioned how the data is presented. There were a number of challenges with this. In addition to the fact it's a huge data dump. The gang were using a thing called Jabber, which would be probably familiar to you. It was a sort of dark web chat service. And in the Jabber software, it would have been done in chat rooms.
Starting point is 00:16:08 So person A talked to person B in one room, person C talks to person D in another room. when the data gets released, it's all in time order. So you're scrolling down, and it's like somebody's taken your WhatsApp and just listed all the messages in order. So you start following a conversation along, and you're trying to get the hang of what they're talking about, and you start following, and then suddenly two completely different people, or more, start timing in and talking about something completely different.
Starting point is 00:16:33 So you've got to remember the conversation you're following along, now follow a new conversation, and when the old conversation comes back, pick up from where you left off. it is the single hardest thing I've done as an investigative journalist in the 10 years or so I've been doing this. It was mind-blowing. I'm 45,000 messages in and I'm still going. It's difficult. Just practically, and I want to stay on Conti, but are you, do you have a team of people working with you?
Starting point is 00:16:59 Or are you just locked in with these documents by yourself? We have a team of people. The BBC has a, we've got a fantastic team, actually, people working on this podcast, and they're doing great stuff. But with this, it's just me. And the reason for that is it would only really work with one person going through it. I suppose you could farm out bits of it. Because it's such an amorphous set of data, you need to go through it and get the hang of it. Once you get the hang of it, you start to realize what you're dealing with and you start
Starting point is 00:17:25 to get an eye for it, if I can put it like that. So, for example, it's all in Cyrillic. The original chats were obviously in Russian, because the vast majority of members of the gang of Russian. As the, they've been translated through LLMs, but the LLMs struggle with Cyrillic characters. So the classic example is they keep talking about the k-ball. You know, who's got the k-ball? And you think it's this snooker or pool, what's going on here, it turns out when you spell Bitcoin in Cyrillic, it's Bitcoin.
Starting point is 00:17:52 But the end at the end looks like a V. And so the LLM's translated as V, which would be Bitkov, which in Russian is kubal. And so whenever you hear about them talking about the kubles, it's like, well, that means Bitcoin. And then there's other things where they drop into slang. I mean, there's a huge amount of hacker slang going on here, of course. They keep talking about the grandmas, you know, who's got the grandmas? And again, you think, why are they obsessed with their grandparents, what's going on? And it turns out in Russian, obviously, grandma is babushka.
Starting point is 00:18:19 And there's some word like babi-a or something, which means cash or money. So when they're saying, you know, who's going to drop the grandmas? It's like who's going to give us the money. So as you get the hang of these things, as you're going through, you just get this sense and this eye for what you're trying to translate. But there were some hilarious mistransations of what the Conti gang said. It's absolutely astonishing. because of the nature of their business, extracting and in some cases like holding on to people's information,
Starting point is 00:18:44 there's this interesting Russian nesting doll of whose information is coming out. You've got their leaks coming out, their chats, their internal business process, but they've been stealing other people's information that presumably is being reflected inside of that larger thing. And some of the information they've stolen over the years, I want to talk with you about, But it's fascinating. There was the September 2021 story involving, it was a London jeweler who had, it was I think, was close to 70,000 client documents with some, what's called large names inside of that leak. Can you tell me a little bit about that part of the story? This was a fascinating case. And in the podcast, we've been trying to reflect the different types of cases attributed to content.
Starting point is 00:19:30 So attacks on local councils, healthcare. And Graf was a really interesting example because it's a, as you say, it's a jewel. It's a commercial company. Graph is one of the world's biggest jewelers, and they sell jewels to incredibly wealthy people. We actually interviewed a historian, a jewelry historian who has written books about Graff. And, you know, as a nice warm-up question, I said to her, you know,
Starting point is 00:19:51 can you tell me some of Graff's famous clients, you know, because I've read in the news, some people say, oh, I got this from Graff, this necklace. And she said, no, no, I cannot tell you a single name. And I said, oh, come on. You know, ancient, you know, people from the past, you know, celebrities are, you know, So no, no, I will.
Starting point is 00:20:06 And this is, this is key to the story, is graph is like a lot of these companies, institutionally private and secret and discrete. You do not, you know, when you go into Graph, you are taken in through the side door, your chauffeur exactly, you know, nobody knows that you've been there. So it would be awful, wouldn't it, for Graph's entire contacts database and customers to be leaked, but that's what Conti were threatening to do. They basically broke into Graph and they do two things. they scramble the data. The problem with that is if the victim's got backups, then the victim can
Starting point is 00:20:38 refuse to pay the ransom and restore from backup. So Conti's solution to this, like a lot of ransom my gangs, was double-dip ransomware. You steal the data, and if the victim refuses to pay, to have it unscramble, you say, well, fine, but I'm going to leak the data that I stole. So you've got a second incentive to pay. That's what they were running with Graf. They started leaking tip bits of the information to put pressure on Graph, because Graf were playing hardball refusing to pay. And one of the things they leaked was customer data. There was a journalist at the Daily Mail, the UK newspaper, who found this. He's actually a freelancer.
Starting point is 00:21:11 He found this, and he wrote a story for the Daily Mail, because what he found was details of Donald Trump and Obama and David Beckham and people like this. Not Obama, sorry, Oprah Winfrey. The two O's in the names confuse me there. Obama may be a customer of graph, I don't know. But, you know, famous customers. And this was a big problem actually for Conti because obviously they're doing this to put pressure on graph. But as soon as people found out that they were in this database that have been leaked, they obviously started getting extremely angry. And it seems that someone in that list contacted Conti and said, you take that down or we will come and find you.
Starting point is 00:21:56 I mean, the way it was explained to me was, if you offend the FBI or the UK national crime agency, they might indict you put you in prison. You offend some of the people at that level in society. They are just going to kill you. And what we got afterwards was an apology specifically to the Saudi royal family. So the presumption from some is that the Saudi royal family contacted Conti and said, take that stuff down. Because Conti apologized to the Saudi royal family and said, so sorry, we leak this information. and, you know,
Starting point is 00:22:25 apologies for any inconvenience cause. We will, of course, delete this. Now, what's interesting because of the leaks, and this is one of the great things about being able to see the leaks happening at the time. The story was happening is, we know Conti did no such thing. They did not delete the data.
Starting point is 00:22:38 In fact, there's a quote from the leaks, which some researchers at a company called Syjax found for us, which says we can shake and shake with the shakes, as in we have the shakes data from Saudi Arabia, and we can potentially blackmail them again. So it just shows you, I can't trust a thief who would have knew. That is fascinating.
Starting point is 00:22:58 And a relatively sinister story, that's one of the more sinister moments. It is. But what's interesting is, again, when people said, oh, well, you know, Conti would have been intimidated or threatened, you know, to make this happen, I did have some skepticism there. And I thought, well, really? I mean, it's quite nasty guys. And who's going to put the squeeze on them?
Starting point is 00:23:17 But in the leaks, they actually say that. They say, you know, this is, they talk about some of the slughey. celebrities and they say, yeah, but these are heavy guys in there. We, you know, we have to sort this out. We can't, you know, we've got to make nice here and apologize. So actually, it is true that when the Conti gang, from what the leaks suggest, that they were worried. They were, they were scared once they realized who was onto them and what stuff they leaked. I thought that was really fascinating. To go back to victim villain hero, uh, this character I want to talk to you about last year, German police publicly named, a character named Stern, 36 year old Russian,
Starting point is 00:23:51 named Vitali Kovalev. I'm sure I'm pronouncing that adjacent to correctly. Now under Interpol, he's now under Interpol Red Notice, and you ended up with a video of the man himself. Take me through this character and what you saw. Yes. Well, Stern, as you say,
Starting point is 00:24:11 the German authorities named the head of the Conti Gang, who he knew went under the alias Stern as Vitali Kovalev, this Russian national, should be said, we haven't heard from Vitali Kovalev. We don't know what his response to all of this is, but the accusations against him are piling up. And according to US authorities, he's got a very, very long history.
Starting point is 00:24:31 He first seems to pop up in the kind of 2010s, as far back as that, being accused of doing money laundering for cybercrime gangs, a really big gang called Zeus, actually he used a virus called Zeus. Kovlev's accused of operating back then as a money launderer for that group, but then seems to have moved into
Starting point is 00:24:49 other viruses and apparently into ransomware ran this gang and in the chats you see stern pop up and he's an interesting character because he's quite tack-a-turned he doesn't say much and there's also this interesting thing where there's a number two in the gang called mango um who is basically the office manager i don't know about you jordan there's always when i've worked in offices there's always been a person in the office who actually makes the place run and everybody knows that but nobody really fully acknowledges it because nobody because then then you know that person would know when they'd are for pay wise mango's like the guy who holds it all together and as the as the contigango are mango's just getting more and more frustrated with stern because stern's got the money
Starting point is 00:25:31 and mango keeps so everybody has to make stern happy but stern is also incredibly distracted just always his mind is always somewhere else he's always doing something else so mango is constantly frustratedly going back saying look we've got to get this project sort of i'm working really hard here Why are you such a soft touch? Why do you keep paying people when they're not doing the work? You know, we have to, you know, really crack down on this. So, Stern's this interesting character. I describe him as a bit like the sort of the guy in the office,
Starting point is 00:25:56 the kind of David Brent character, the chap who runs, you know, who's effectively been promoted above his station doesn't really want to be there. He's risen to the level of his incompetence, I think, is the thing that people say. The Peter principle, I think they call it. Yes, yes. But yeah, so as I say, you know, we've got this name for time. Charlie Kovalev. We await his comment and we welcome any comment from him if he wishes to address the accusations against him. But someone on Telegram put us onto a social media account for someone who is very popular on social media. They're an influence on social media and they're very close to Vitalikov. And so there's all these videos, like thousands and thousands of videos with millions of viewers, some of these videos. And I thought, well, surely, you know, the world's most wanted hacker, you know, the internet's gangster number one. according to the accusations against him, he's not going to appear in these videos.
Starting point is 00:26:47 Oh, no, he's there. He's waving at the camera and, you know, bopping around to music, seen on holiday, you know, driving around in the car with this other individual. Absolutely amazing. And it's just, it was very satisfying to find that because we've got one mugshot of this guy and to find a sort of interior life for them was really interesting. What was disconcerting was we have this image, don't we have cyber criminals with the hoodie, you know, tattoos and, you know, rings on the fingers. He looks, he just looks, he's got this very benign face. And yes, he is apparently behind all these crimes according to the accusations.
Starting point is 00:27:26 But if you, I have this thing that if your car broke down and you needed someone to help you push it, you'd look at him and think, oh, he would probably do that. He's got this bearing that's just really interesting. And so I had real trouble reconciling that with the accusations against him. Sure. The office, David Brent type character versus the body of work call it that you're looking at. Exactly. Precisely. Yeah. That's so interesting. I want to go back to, you brought up Mango and the kind of like intra-office, call it idea guy versus executor type. Yes. Yeah. Dynamic that they have. It sounded like from my reading about it, there were other tensions that emerged too. And I find that so interesting to go back to the moral, the really.
Starting point is 00:28:13 narrow little moral path that you're trying to walk of what will we and won't we do in this fundamentally, you know, pretty tricky business model. Some of the leaks captured an ethical argument between the operators about, say, things like hitting healthcare. And I know Mango comes up in those debates a lot. Tell me about that. I want to zoom back in on that kind of prickly moment post-COVID where do we target healthcare in this moment of all moments. Yeah. It's a really interesting running debate within Conti, and it was not a homogenous gang. And one of the key, drivers for that and the reason that Conti was fractured from within was because of a business decision that Conti made that, again, a lot of other ransomware gangs made to adopt an affiliate
Starting point is 00:28:52 model. Your main problem with ransomware is spreading it. Writing ransomware is hard, is a coding challenge, but once you've written it, you've got to infect some victims. If you are a coder, I think I've got this idea that hackers are just one thing. You're a hacker, you're a hacker, you just hack. I can invent encryption software, but spreading it and writing fishing emails and and then negotiating with victims to pay a ransom. These are separate skills. You might get some people who have all of them, but more likely they're going to be separate people.
Starting point is 00:29:21 So the people who write the ransomware are not necessarily the ones who are good at spreading it. So Conti developed, as other gangs have, and we used an affiliate model. People could sign up to the Conti gang, get a copy of the ransomware, and then distribute it. And when the ransom was paid,
Starting point is 00:29:36 usually 80% would go to the affiliate and 20 to the virus writer to the Conti gang, which immediately also gives you a copy of, a very hard metric about who has power in that situation. You know, without the affiliates, the gang would be nothing. Conti would be nothing. And also there was competition for affiliates. The affiliates could work for multiple different gangs.
Starting point is 00:29:54 So it's a bit like these taxi apps. You know, each taxi driver could have five or six apps. So the app provider has to lure the taxi drivers in. Conti did the same. They offered their affiliates good rates. They offered, again, to support them, to bring them up, to bring them into this gang. Join us with the biggest in the world right now. That's what got said at one point.
Starting point is 00:30:12 The problem with the affiliates was you get scaled, but you lose control. You know, as any organization that scales very quickly knows, it's difficult to keep control. And an affiliate model is particularly hard to control. And so you've got members of the gang who went rogue, went freelance, started attacking targets. Conti didn't even know about. Some of the targets got attacked, Stern claimed he didn't know about, he didn't know that that was going to be attacked. Because that's not his job. He's not choosing the targets.
Starting point is 00:30:41 That's the affiliate's job. So you've got this interesting push-pull between the affiliates and the core gang. And healthcare was absolutely at the heart of that. Some members of the gang were absolutely clear. We do not attack healthcare. Other members of the gang, particularly an individual called Target, who's incredibly aggressive, deliberately targeted hospitals. Apparently several hundred hospitals were on targets list and did not care and absolutely rejoiced,
Starting point is 00:31:07 it seems, in attacking hospitals because they paid up. And then you get this grey area in the middle. where gang members hit a target that doesn't look like a hospital, but then one of the other gang members says, yes, yes, it's a hospital. And then this argument breaks out saying, no, no, it's a physiotherapy place. There's one brilliant moment where they hit.
Starting point is 00:31:26 I think it is a physiotherapy center. And the person who hits it says it's not a hospital, it's physiotherapy. And the person controlling them, their handler within the gang, says, this is healthcare. We said we wouldn't attack healthcare. And then the affiliate says, but we think they're going to pay something like $3 million in ransom. And suddenly the conversation changes.
Starting point is 00:31:46 And the handler says, oh, okay, well, all right, maybe we will keep going with this. But don't do it in future, no hospitals in future. So there's this really interesting debate around what is healthcare when you don't attack healthcare. And when somebody puts some money on the table in front of you, your psychology around that can change pretty quick. Wow. Inside of Conti, do you think that that's a moral thing or an optics thing?
Starting point is 00:32:06 Like I know in Ireland, the HSC attack health service executive there, kind of publicly funded healthcare apparatus, call it, was attacked. And it was 20 million. Like, it was way bigger than even that. Like, is that a, is that a moral thing? Is that an, like, oh, we're just going to get even more heat if we go after these. What do you attribute that to? It's, it's a real mix. I don't doubt there were people in Conti who had ethical concerns about hitting hospitals. There was discussion in the Conti chats about people's relatives dying of COVID. So they knew this was a global pandemic. There are some people in Conti who, um, have concerns about hitting healthcare, as you say, because it will put a target on your back.
Starting point is 00:32:44 You do not want to be during the middle of a pandemic tanking hospitals. There are also people who are prosaically thinking, well, hospitals don't generally pay outside of the US. The HSE example is a perfect example. Ireland's Health Service Executive runs basically the country's hospitals. Immediately when they were attacked said, we're not paying. Don't even think about it. We're just not going to pay. Ireland's HSC was given a decryption key at a certain point
Starting point is 00:33:08 and it's very probable that's a factor in it the gang knew they weren't going to get any money out of them. So there's an interesting sort of mix of motivations in there when they talk about we're not going to hit healthcare from the sort of ethical through to the very, very prosaic through to the kind of very money motivated. If I had to put money on it, this gang are so money motivated.
Starting point is 00:33:30 They are so acquisitive. If you're always in doubt about why Conti do something, something, look at the money. And that will be a few answer. Follow the money. If we follow the money from the 2022 hacks that you spent a lot of time digging into, there were, there have been more recent leaks, maybe not at the same scale. I believe in 2025. In terms of where this goes from when you start reporting to closer to where we are now, what's sort of the long arc of this group? It's interesting. So in terms of the Conti gang specifically, um, after the leaks in 2022, This was an absolute disaster for the Conti gang.
Starting point is 00:34:07 They were already wobbly. There was already these issues internally, as we've talked about, tensions over targeting, tensions between the top leadership team, then tensions over the war, then the leaks. Conti did one sort of final sort of swan song hit, certainly under the Conti name, which was Costa Rica. They attacked the government of Costa Rica. And for a period of several weeks, kind of took Costa Rica's government down. I mean, it's rolling pandemonium in Costa Rica. And again, your listeners might be, you know, reaching for Google Earth and thinking,
Starting point is 00:34:37 where the hell is Costa Rica? Certainly people in Europe, it's quite far away from us, would, and it's a tiny country, and why should we sort of care? Well, the problem with that is Costa Rica starts to look like a bit of a test case, you know, if we wanted to take a government down using encryption software, how would we do that? Well, let's have a go at Costa Rica, you know, a small country that a lot of people don't know about. Let's try it there. That's one of the theories as to why Costa Rica got a time.
Starting point is 00:35:03 attack. Other theories are that it was a rogue member of Conti who wanted to show that the gang was still a force of nature. The problem is the leaks obviously run out at that point because once the leaks are leaked, you know, that's it. They kind of all disperse. So we don't know the story with Costa Rica. All we know is that was their sort of final hit. As to what happens next to the gang members, again, a little difficult to work out. I mean, obviously the person's accused of running this, Stern, Vitali Kovalev. We have some insights to where that individual now, and satisfyingly we've got videos, believe still in the Russian Federation
Starting point is 00:35:37 would be very hard, given the Interpol Red Notice against Vitali Kovalev for him to travel outside Russia without facing justice. Other members of the gang, because they operated under pseudonyms, in some cases, you know, Mango's case, we've got a name and a face for who the German police say he is,
Starting point is 00:35:53 you know, and Interpol say he is. It's very possible that if Mango is this person, he just set up under a fresh pseudonym in a fresh gang. You know, they were all working under pseudonyms. So some of them will have got their fingersburn decided to leave ransomware. Some of them will have joined new ransomware groups. There's also an interesting infrastructure around Dubai. In the messages, we know that Conti started relocating to Dubai. And there's some hilarious chats where some of the hackers are jealous of their colleagues
Starting point is 00:36:23 who go to Dubai, because obviously if you're in Russia, it's really cold. And they're like, oh, you're going to Dubai? I wish I was in the office in Dubai. So we know there's a Dubai next. given the amount of cryptocurrency that Conti accumulated during the course of this, my assumption is that efforts in Dubai and elsewhere to somehow get into crypto in a big way and have some outlet for crypto where they can turn that stash of dodgy crypto into fiat money and eventually yachts and houses and Ferraris and Lamborghinis and Lamborghinis. That's, I think, where the running would be from the senior Conti guys. The UK National Crime Agency, and I think probably the FBI as well,
Starting point is 00:37:02 would say, look, a lot of these guys are just going to pitch up in different gangs. We're going to see them rotate around. Maybe set their own thing up, maybe become an affiliate somewhere else. Who knows? I'm super excited to tell you guys about one of our new sponsors. We got a new sponsor, and they're called Even Realities. And they make AI smart glasses, which sounds crazy, but they're actually real. They showed up last week.
Starting point is 00:37:28 I got a friend that's had these. They had the first version of these, and he uses them for teleprompter when he does presentations. I got these ones to do coding. They have a full terminal integration into AI coding apps. There's also an entire ecosystem of people that have made custom plugins of which you can control AI assistance, sports scores, news, weather. There's a whole pile of uses for these things. Even G2, our productivity smart glass is designed to keep real-time support right in your view. With teleprompting, conversation support, real-time translation,
Starting point is 00:38:03 AI assistance, and more, they help you stay on top of the work and daily life. And unlike most spark glasses, they're designed to look and feel like premium I wear. There's no camera. They have a lightweight, 36 gram design that you can wear all day. The more context you give, the smarter they get. And they adapt to how you work and what you need. If you want to learn more about even G2s, go to even realities.com and see how everyday smart glasses keep helpful information in sight.
Starting point is 00:38:32 So you can stay productive. and hands-free throughout the day. And for our listeners, use promo code hacked at even realities.com to get 10% off the even ring one and or the even clip when you add them to your even G2 order. That's even realities.com promo code hacked. Scott, what do you like about Shopify? Well, there's lots of things to like about Shopify, Jordan. The first thing I like about it is easy to use.
Starting point is 00:38:58 It's totally web-based, has great apps for the phone, integrates with all of the systems, distributions, production partners that we use. It's amazing. It does everything you need. And not only that, now as a consumer, as a mass consumer of online buying, it seems like every single website that I go to is Shopify because it automatically logs me in with my shop account. It knows all my information. It does everything for me. So I love it both as a retailer and as a shopper. It is like a unified sales platform for the internet. And if you, If you want to sell things on the internet, I honestly don't know if there's another platform that I would use because it's just, it's everywhere and that makes it better. If you want to upgrade your business and get the same checkout that we use, use Shopify.
Starting point is 00:39:47 Sign up for your $1 per month trial period at Shopify.com slash hacked. That's all lowercase. Again, go to Shopify.com slash hack to upgrade your selling today. Scott, one more time for the people. Shopify.com slash hacked. Since you brought up governments, both in the context of Costa Rica and Dubai, you mentioned this earlier, the Office for Government topics. As this concept coming up in the chats, operators describing Stern as having connections to FSB, Federal Security Service of the Russian Federation. Oh, yeah. Yeah. Can you take me through the connection between this group of people and states around the world?
Starting point is 00:40:31 Yes. There's a sort of a bit of a pat assumption, which I find slightly frustrating that, oh, these gangs, they're all working for the Russian government. It's not that simple, and I need to push back on that. I don't think that's the case. For a start, the one thing that comes across loud and clear from the ransomware gang leaks that I've looked through is money. It's all about money. It's a business and the bottle line is about everything. Yes, the government might. pay them some money. A government somewhere might pay them some money, but it's going to be nowhere near the millions they're going to get from a victim. The other thing is, if a government comes in, and sometimes this has been reported, sometimes a government would come in and task one of the ransomware gangs and say, well, you've broken into this target. Could you please now hand us over that access? Well, the ransomware gang thinks, well, okay, we might collaborate with you, but now we're not going to make money out of that victim. Max meets a guy called Max. A guy called Max Smeets wrote a book called Ransom War, which is all about ransomware. And one of the things
Starting point is 00:41:35 he covers in that book is what the ransomware gang is called pioneering exercises, which is where a Russian gang would get tasked by the Russian government to go and hack some target of interest to the Russian government. They did it because if you're in Russia and the government asks you to do something, it's in your best interest to do that. But they didn't like it because it meant they got no money out of that victim anymore. So the way I see it and the way it came across to me and others may have better information, I don't know, was it was a sort of grudging, tolerant relationship of, you know, the fact that you don't hack Russians for a start if you're in Russia. And that's, for good reason, it's illegal to hack Russians in Russia. As far as
Starting point is 00:42:17 I'm aware, and I was told this, the Russian law does not prevent you hacking non-Russians. That's not illegal. So immediately, don't hack your own people. If the government comes knocking, you know, do the right thing, kind of, you know. And actually, there are reflections of that in Western and cybersecurity companies, you know, who want to work with government and who, you know, they understand, you know, that it's obviously not the same thing, but you can see, you know, the commonality there of approach. However, in the Conti leaks, there's also a suggestion that FSB members were embedded somehow within Conti. There's gossip among the members of that. That was actually reported in, I think, a wired article. And some of the gang members say,
Starting point is 00:42:57 well, yes, of course, you know, they would have been in here. others were surprised at that. So it's just not as simple as the Russian government runs this ransomware gang. That's not, it's not that simple. Inevitably, there will link, there will be links. But as I say, there will be links from governments into lots of things within their country. So that's how I put it. I know some listeners will think,
Starting point is 00:43:17 you're being a bit woolly and a bit mealy-mouthed there, but you've got to call it how you see it. And that's what I see. It doesn't strike me as, you know, evasive at all to just say, like their primary motivation is money. Think of them like a business. They're trying to get a rate of return. They're trying to pull a profit here.
Starting point is 00:43:36 But if they're operating out of a place with a government that can either like them and leave them to do their business or can have a pretty big negative impact, you're probably going to play ball, even if it's not profitable, even if you don't work for them, even if the simple story isn't the case. You still probably want to play friendly with the cops. There was a slight change, I should say, after the Ukraine war started, we saw multiple ransomware gangs declaring again support for the Russian regime and sort of casting their attacks as patriotic attacks.
Starting point is 00:44:10 So again, you start to see a line between ransomware gangs and governments. But again, there's a money way of seeing that, which is that, well, hey, we can attack these victims and extract a ransom for patriotic reasons. It's like, well, yeah, it's still about money, isn't it, at the end of the day? So, but some of the ransomware gang were, you know, we're casting this as being, we're just going to take Western companies down. So the Ukraine war did start to change things and we did start to see criminal gangs moving into kind of patriotic activity. But my suspicion is that the back of it was still either money or a survival instinct to say, well, if we say that, the Russian government's going to like us and we'll stick around longer. They're less likely to arrest us, et cetera. There's also a game that's played between ransomware gangs, I suspect, of if you want to take your competition,
Starting point is 00:44:55 down because ransomware gangs are in competition, if you can get friendly enough with the government and law enforcement, you can tip them off to where that gang is and they go and they take that gang down, which obviously for the government looks great and for the police looks. Interesting. Actually, the ransomware gang is a win because your competitors went out of business. It's a very grubby world they work in. That's so fascinating. And you still make that patriotic money. You can feel good about that patriotic. Yeah. It's a win-win. Yeah. It's a win-win. Yeah. If it doesn't back fire and they end up wading you, this is the thing. There's all sorts of calculations go on when you're in organized crime, I think.
Starting point is 00:45:29 Yeah, that puts the law enforcement who's potentially working with them in a very fascinating position of like, who do we, whose tip do we take and whose competition do we take out? And actually, I've heard interviews not about cybercrime, but with people investigating, for example, you know, organized crime with terrorism cases. There's one example, particularly in Ireland, where one of the officers said, look, you know, when you work in these shadowy worlds, you take information and tips from people. who are crooks, who are wrongans, who are terrorists. It helps you because you can then shut part of an operation down, but you're always aware that your strings are potentially being pulled by that person. So yeah, it's difficult not for all law enforcement, for law enforcement who work in those shadowy type areas.
Starting point is 00:46:14 There is a challenge, I think there was a challenge there. I want to go back to your victim, villain hero. We've talked about a few of the, I guess they would fit into the second category here-type characters there. Are there any that we haven't talked about? We've talked about Stern. We've talked about Mango. We've talked about their moral disagreements and the inter-office politics. Are there any other big characters inside the gang that you want to point at?
Starting point is 00:46:36 There's a whole cast of characters. And actually, one of the difficult things in the podcast was working out which ones to sort of follow. In my mind, we were always only ever going to concentrate on three. And obviously, you know, the leader, the office manager, the incredibly aggressive guy who just goes off on one all the time. And we obviously need a podcast. We wanted to voice up these chats. So we got a group of actors to come in, you know, Russian accented actors to read out the chats. And they just did fantastically well.
Starting point is 00:47:10 It brought it really to life. The only problem was, I mean, these chats are full of swear words. These guys are, you know, using the F word all the time. And it sounded great. They read out these words, particularly target, who's incredibly a great. Some of those were absolutely great. I then got told, I think it was the day after by my BBC bosses that
Starting point is 00:47:30 we weren't allowed to have swearing in the podcast. And we couldn't even bleep it out because I think American broadcast authorities don't allow bleeped out swear words even. So it's our God, we could have told us that. We've just voiced all these swear words. So there were all these other characters. So what I did in the end
Starting point is 00:47:46 was said, look, we'll have the main three characters. We'll have Stern, mango, and Target, you know, developed as characters. But we'll have, what I called the Rosencrantz and Guildenstern, who are two characters from Shakespeare, who was sort of backstage characters. But famously, the play was written making them the main characters. There's a whole set of also Rans who have interesting stuff to say. So we just sort of voiced them up in kind of generic things. So they kind of come in and people come in and out.
Starting point is 00:48:13 Because it's funny that there's this always gossip by the lower level members, about the higher members. And so you needed to have some of that gossip in there. But if you started trying to explain who all these people were, it just got out of hand. So, We kind of went, okay, it's the main three. And then, you know, two, two kind of bit players who just play the parts of, you know, of all the others. Like you see in plays where somebody goes off and puts on a wig and comes back on, you know, it's that kind of thing. That's really good. And then the third category in this cast of characters, you spent a lot of time in this.
Starting point is 00:48:43 Who are the heroes of this story? The people who try and fend these attacks off, which is an absolutely unforgiving task, which, again, Jordan, you'll know this very well. you know, it's the 3am phone call and that's deliberate because the gangs know exactly when to trigger their viruses, it's when the office is minimally staffed, if staffed at all, because speed is of the essence with ransomware, if somebody spots it and can unplug it
Starting point is 00:49:08 and can disconnect the system from the internet or disconnect computers from each other, you can stop the ransomware. You get a partial infection, but you can clear it up. So they want to infect as quickly as possible, but they want to have the maximum amount of time to infect as possible. And it's a bit like a thief breaking into a jewelry store. You know, you do it over a long weekend, like a holiday weekend.
Starting point is 00:49:29 So they would, you know, often trigger the virus to start at sort of 3 o'clock in the morning. Increasingly, companies know about that, so they have alerts set up. But in the first case, we investigated in the podcast, an attack on a local council in the UK, the individual had to drive into the data center and literally unplug, like switch the power switches off the servers to try and stop this. So even the amount of time to get from home in the car to the office can feed into, you know, the impact of the attack. So the people who are trying to defend against this are absolutely on the front end. And when these attacks happen, there's an acknowledgement, I think, of this is going to be an awful week. You know, it's going to be awful.
Starting point is 00:50:09 But what comes across loud and clear in the podcast is it's not just a few days a week. It's months. And so if, you know, people are listening and they want kind of advice about this, yes, have a response plan. but also understand your response plan is potentially going to have to spill out over weeks, months, etc. The people who haven't slept for three days at the beginning, they can't keep going. You need a second team to come in and reinforce them while they take a break, get some sleep. Things like food, you know, food and drink, you need water supplies. You might need beds set up in the office.
Starting point is 00:50:42 Have you thought about all this human-level stuff, human-scale stuff? So that's, I think, one of the learnings that kind of comes out in the podcast. understand the impact this is going to have on particular small groups of people, because in your organization you will have a small group of people who are going to be in the real frame to defend against this. You've put the time into reporting on this story, the kind of deep investigative reporting that I think stories like this increasingly need. These kinds of stories are going to become a bigger and bigger part of our world.
Starting point is 00:51:10 And it's really cool to see the depth you've gone into here. What's the one last big thing that you want people to take away from this series? It's that distinction between crooks and competitors. The number one thing to understand about the people who run these campaigns is they do not think of themselves as crooks. There's a small part of their brain that must know it, but that is overwhelmed by the bit of their brain that casts this as a business. You are not being attacked by an attacker who is a threat actor to you.
Starting point is 00:51:41 You are being challenged by a competitor to your business. They have better software than you do. And the evidence of that is your data's been copied and exfiltrated, and your data has been scrambled in your organisation. It happened because they have better software than you. Now, people may struggle with that and say, well, these are crooks. Yes, yes, they are. Our view of them is still valid.
Starting point is 00:52:04 But if you really want to understand them, and I think get an insight into have to challenge them, seeing them as they see themselves is useful. They do not see themselves as crooks. They see themselves as competitors. They're competing internally within the gang. They're competing with other gangs. They're competing with victims.
Starting point is 00:52:19 They're not victims. They're competitors. And they're competing with the hero set, with law enforcement. So, for example, massive cybersecurity company has some software. The Conti gang got hold of a copy of it. And they reversed engineered it because that piece of software was stopping them doing their job. So they got a copy of it. Looked it and went, okay, we can make our software get around this.
Starting point is 00:52:40 You know, they don't see victims, villains, heroes, these gangs. They see just a state of nature, a jungle where there's just competing. competitors. You know, there's no neat categories in a jungle. There's just who wins and who loses, who lives and who dies. You don't make categories of this. I don't know whether you watch these nature programs, the David Attenborough Nature Programme. I always find it interesting. Which animal Atimbra casts as the victim and the villain? Do you notice this? Like an animal's getting chased. And sometimes he says, oh, this poor animal's getting chased. Will the animal get away? But other times, he says, oh, the animal doing the chasing is desperate to feed her children
Starting point is 00:53:17 or his family or whatever. I find that really fascinating. But that's fundamentally what it's like in the jungle. Anybody could be a victim or a villain, or indeed a hero. So I think understanding that you're not in an attacker, defender situation, you're in a competitive marketplace.
Starting point is 00:53:32 That's maybe a different way of framing it. There's an adage about storytelling. I'm sure you've bumped into this. That is exactly that. You open on a shot of a bear walking through the woods. You don't want that bear to go hungry, But if you open on a shot of the rabbit or whatever that it goes after, you want that rabbit to get away. And everyone views themselves, I guess, in some sense, as the rabbit.
Starting point is 00:53:54 I'm not sure which animal they would see themselves as. It's a very, very interesting question. That's a very interesting question. As I said it, I wondered if maybe that's not the case. Maybe they view themselves as the bear, but the bear's still got to eat. It really is an interesting thing to unpack how a group of people, especially when you look at the bottom line with the economic toll of all of this and in the human toll in some cases, how do you understand yourself? What do you have to tell yourself to avoid the cognitive dissonance of what you're doing?
Starting point is 00:54:24 And it's all competition is a pretty interesting story to tell yourself. Yeah, yeah. It's just, you know, I wake up in the day. I have some software. I use it. You know, you've got to reframe what you do as a business and business is about competition. So that will do as the reframing. That will work as the reframing. I really believe that. I've seen it in the chats. Like I say, there's a bit of the business. their brain, these people have wives, girlfriends, kids. I don't know what they tell them. It's a bit of their brain that must know that what they're doing is wrong and criminality, but they just, they can go to work, close the door and reframe what they do. I imagine some service personnel
Starting point is 00:54:58 have that. What you're forced to do in the in the armed services is pretty hard. You have to close the door and say, this is business. It's a mental switch. Various people in society have to do, actually. It is interesting to draw that parallel. It's like you, there are certainly people that must have gone home at night and told their children very true stories about morality and how they ought to behave in the world before going to work at nine o'clock in the next morning and, you know, ransom wearing a hospital in Ireland. Yeah. I don't, I mean, the person who's accused of running all of this, you know, Vitale Covalve,
Starting point is 00:55:30 has family, you know, partner, kids. They live a very opulent life from what we've seen in the videos, very opulent. Dad's in business. Oh, he's in computers. but as soon as they Google his name, they're going to find the accusations against him. So how do you cast that? Do you say, oh, it's all lies on the internet, darling, don't worry about it?
Starting point is 00:55:54 I find it fascinating. It's not unique to the cybercrime gangs. I mean, generally, an organised crime. Understanding what you can tell your family, how honest you can be, and reframing the accusations against you so that your family can live with you and you can live with them, that's a perennial challenge. But I do find that fascinating.
Starting point is 00:56:10 It's all competition. Jeff, I appreciate you taking the time to chat with me. Where can folks find the show? It's going to be on Spotify, on iTunes, BBC Sounds, if you're in the UK. It's going to be all over the place. And if you search Cyberhack, BBC Cyberhack, you will find it. It was called Lazarus Heist, obviously the first couple of series about North Korea and the Lazarus Group. If you search, you'll come across it.
Starting point is 00:56:34 So whichever way you search, you'll find it there. And it will be all over the place from the first of June. Awesome. First two seasons were incredible. check it out. Jeff, thank you so much for your time. Thank you so much for having me. I really enjoyed it. Spotify, it's Jay Shetty. Are you one of those media strategy people? Scrolling through spreadsheets, searching for an audience that pays twice as much attention to your ads than they do on social? Let me introduce you to fans. And they're here with me on Spotify. Trust me, I know fans.
Starting point is 00:57:19 They don't skip. They stay for hours. They don't move on. They manifest. They're not a demigrant. They're graphic group, they're fans. Spotify advertising. You're among fans.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.