Shawn Ryan Show - #328 Kevin Mandia - The Man Who Exposed China's Military Hackers
Episode Date: August 6, 2026Kevin Mandia is CEO of Armadin, where he leads the company's mission to secure some of the world's largest and most complex environments. A globally recognized cybersecurity leader, he is also a Gener...al Partner at Ballistic Ventures, mentoring and investing in the next generation of cybersecurity entrepreneurs. Best known as the founder of Mandiant and former CEO of FireEye, Mandia helped redefine the cybersecurity industry through pioneering digital forensics, the groundbreaking APT1 report exposing state-sponsored cyber espionage, and his leadership during the SolarWinds attack. Today, he continues to shape cybersecurity strategy, national security policy, and the future of AI-driven defense. Privacy isn't Paranoia. It's Protection. Download Glacier - https://srs.site/glacierapp Website - https://theglacierapp.com Shawn Ryan Show Sponsors: Get 10% Off your entire order & take advantage of Ridge’s Annual Sweepstakes by going to https://www.Ridge.com/SRS #Ridgepod NO PURCHASE NECESSARY. Open only to legal residents of the promotion territory, who have reached the age of majority in their jurisdiction of residence. Void elsewhere & where prohibited by law. Enter by 9:00 a.m. USPT on 8 September 2026. 2 winners, prizes total ARV: up to approx. $539,165 CAD / £284,170. Skill-testing question required in CA. See Official Rules at ridge.com/pages/rules for complete eligibility, entry instructions, how to enter without a purchase, entry limits, prize details, odds, and restrictions. Sponsor: The Ridge Wallet LLC. Get started with Claude at https://claude.ai/srs and use promo code srs for access to all features mentioned in today’s episode. Visit https://betterhelp.com/srs. #ad Go to https://calderalab.com/SRS and use code SRS for 20% off your first order. Kevin Mandia Links: Armadin - https://www.armadin.com Ballistic Ventures - https://ballisticventures.com LinkedIn - https://www.linkedin.com/in/kevin-mandia-0a07173 Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Kevin Mandia.
Welcome to the show.
Thank you.
Man.
Cyber.
Cyber security.
We got practice saying it.
Cyber.
Cyber.
We got this.
You ready?
I'm ready.
All right.
We're going to make it cool.
Man, I have been, uh, yeah, I always thought cybersecurity was boring until I started, uh,
researching you for this interview.
Holy shit, man.
Yeah, it's, uh, what a fucking badass.
It's a weird world.
You know, I've walked the halls.
a lot of the headlines people read in cybersecurity and the press never really gets it.
You know, nobody really understands what it's like to be a victim of a cybercrime, you know,
whether it be someone hacking you to steal all your corporate secrets or extorting you, you know,
and yeah, hey, you got to serve a higher purpose. Mine's always been, you know, the phone rings,
I answer it, and it's a CEO on the other side saying, hey, you know, we're getting ransomed and
damn it, we're not paying it. And my response is always like, hey, man, we're not paying it.
you know let's show up uh but it's a sean let's see if we make this interesting for everybody you know
because i remember a judge i had testified once in a case and the judge is like this stuff's so cool
i can't wait till there's like a ncIS show on it or something like that i'm like man if you could see
the war room in a cyber case it's just really quiet it looks like your back room right there
with those guys in it you know what to be and everybody's clicking on a computer going clickety-clack
there's nothing to see um but you can see the emotional changes in the victims you know what i mean
you can see it on their faces. So we'll make it real.
What is, let's talk about what does a victim go through?
Yeah. Oh.
You're like a worst case scenario for everybody here.
You know, there's nothing, here's bad. You're an executive at a company and somebody breaks in and your email gets released.
It's now Google searchable. Every, you know, you're at, let's say you're at a Fortune 100,
Fortune 500 company and or your photos get released, you know, things like that, your private thoughts
get released. I've seen, I've been in the room with executives when their email got posted.
Nobody ever should have to go through that. I just, it's just a terrible thing to see.
Even I get physiologically like, I can't eat. And I'm like, man, this is, this is bad.
So I think that's the worst thing. It personally impacts people. It gets exaggerated. The press does
search your emails. They do write articles about people. And it's happened to actors, you know,
their photos get stolen. It happens to the kids, like during our interview today, it's going to happen to
some 20-year-old college kid, you know,
where their photos get stolen.
Nobody should ever go through that stuff.
So to me, those are the ones that hurt the most.
Companies survive them, you know, you get back up and running,
you get your operations running, you get over the reputational hits
that happens sometimes.
I just feel for the people that, you know, go through losing their email.
Yeah.
And by the way, it goes in stage, they lose their email.
And like, a month later they lose their family, you know?
I mean, some of these things are pretty bad.
Is that how they always start?
They always started your email?
No, the intrusions are all different, right?
It depends on who's doing it.
You know, you have the modern nations, China and Russia, Iran, North Korea, North Korea hacks for money, take them out.
But China hacks for espionage, you know.
So if they break into your company, they'll break into the defense industrial base.
They'll break into any company doing business in China.
And they steal emails.
They steal things, communications.
But they don't post it online, Sean.
extort you. They follow rules of engagement that whatever their doctrine is, they follow it,
but it's not destructive. They don't change your data. They're kind of like the polite hackers.
But criminals, it's gotten hard. I mean, because they want to monetize any breach they've got.
So they pull on every thread to monetize it, right? If the Sean Ryan Show got compromised,
what they would try to do to you is steal your emails, steal things that matter to you and say,
we're going to share it with the world, unless you pass five.
million, $10 million.
And those are the ones that are, you know, you're always making the least bad of 10 decisions,
you know?
So, shortest answer, people hack for espionage and security, securing a nation.
People maybe even hack, you know, espionage to me supports diplomacy.
And then people hack for criminal reasons.
And then probably there's a third.
They just hack for the game of it, you know, the attractive nuisance of it.
And I don't really respond to too many of those.
What do you recommend for people that like individuals, not executives, but just individuals who have
had their photos of their emails had?
Do they pay the ransom?
Oh, it depends, meaning it's already happened.
Yeah.
It is, I've never said pay the ransom or don't pay the ransom.
I've never said that, but I've been in the room when people think about it.
And I've sat there going, man, I think I'd pay this one.
Like if you're a hospital, somebody breaks in and they've encrypted every machine so they're
unusable. And they say for $10 million, we're going to hand you back a key to unlock all your
machines again. You've got two options. You're either getting every doctor in a room saying,
what surgeries can we do, which surgeries can we not do, or you're evacuating patients,
or you're diverting ambulances, or you're paying a ransom. In that situation, I'd never opine,
but boy, have I said, oh, I get it. You know, I'd pay that one and get back online. So I've seen
people pay extortions and pay ransoms. And the difference is a ransom is to like get a key
to decrypt your things. Like people will ransom and say, I've hacked into your network. I've
shut down 10,000 machines for 10 million bucks, I'll turn them back on for you. And that one, you know,
if lives are at stake or you want to protect the privacy, the second of the extortion is, I've hacked
in, I've stolen emails, I've stolen client data, I've hacked the law firm.
and I've taken your briefs, those extortions are really painful.
It's, I will release the data unless you pay me.
And I see people pay it because you're protecting your customers or you're protecting
people in general.
So hospitals will pay.
Law firms would pay.
Yeah, it's a tough decision.
And luckily, I've never had to make that decision.
I hope I never have to.
That's brutal.
Damn.
Yeah.
Yeah, think about it.
How do you even know that they're going to stop if you pay them?
Well, exactly.
Like they're only capable of one bad thing, right?
And then they're done.
And you don't.
The reality, though, is usually if you're getting extorted,
it's highly probable whoever's extorting you is in a safe harbor like Russia.
I've not, others have written that they've seen Chinese actors do this.
I have personally never seen a Chinese actor extort a company or even ransom a company.
So I think culturally the Chinese really don't do this.
It comes out of Russia.
And the good news is this.
If somebody in Russia hacks Company A in the United States extorts them, and Company A pays the extortion,
let's say they pay $20 million in Bitcoin, an anonymous currency, and then they still leak the data.
The reality is, is people just stop paying the ransom.
So I actually think there's a governance over in Russia of, oh, if you get paid, you don't post.
because otherwise people will stop paying
and they've got a good racket going.
So it's been my observation when people pay
the vast majority of the time the data does not leak.
Makes sense.
There are exceptions, Sean. It's rare.
I can count the exceptions on a single hand.
Wow.
And there's probably over a thousand times
we've responded to these things.
How often is this happening?
Every day. During this call, during this interview,
it'll happen to somebody.
Can you believe that?
During our interview, an 80-year-old American woman will probably lose 200 grand of her life savings.
During our interview, a company will get compromised and probably extorted for $5 to $10 million.
It is happening at a rate, and this is not a fear and certainty in doubt thing.
Nobody knows the rate.
So then you go to the government and say, well, how much money is getting paid in Bitcoin every year to Russia and organized crime?
It's in the billions of dollars.
Holy shit.
Billions, like the lowest estimates are billions.
So all we know is the lowest bounds.
But as I sit here today, people I've worked with are definitely responding to extortion cases
and trying to figure out.
And there will be a new one today, a big one.
Wow.
Damn.
And they're handled quietly and discreetly or sometimes they're front-page news.
You never really know.
Wow.
Yeah.
Well, you're the guy to talk to about all this.
Yeah, exactly.
And I sit there and say, hey, let's, yeah.
By the time we get that phone call, Sean, that there's been a breach, there's been an extortion.
It's tough.
There's nothing you can do about it except work through it.
How do you know, how did you meet Joe Lonsdale?
He's the one that connected us.
Joe, thank you for that.
So that's a great question.
You know, first we live in, well, he's a Texan now, right?
So he lives outside of Austin.
But when he moved to Woodside, California, he has a place there.
And so we met there.
And in general, it's a small community.
You know what people are doing.
And he and I just knew of each other.
You know, I knew what he had done with Palantir.
He knew I was the cyber person.
And just over time, you get, you know, if something happened,
then he would give me a call.
Hey, listen, we got a company that needs this
or a company that needs that.
And, you know, I've been in the cybersecurity domain
for 34 years.
Sooner or later, you're either good at it
or you're not doing it, you know.
I like to think I'm still pretty good.
at it. So that's kind of it. You know, when people need, when people had a computer intrusion,
we had a unique, my company kind of responded to every breach that mattered. And so I think
I'm on speed dial for a lot of these folks. And probably Lonsdale, I'm on his speed doll when something
bad happens somewhere. Right. Yeah. I'm the emergency room doctor for cybersecurity incidents.
That's a perfect way to put it. Yeah. Let me give you a quick introduction here.
Yeah, thanks. Kevin Mandia.
You have 30 years on the front lines of American cyber defense.
You began your career as a United States Air Force officer.
Serving as a computer security officer at the Pentagon and is a special agent in Air Force
Counterintelligence.
In 2004, with no outside funding, you founded Mandian and spent the next decade building
it into the gold standard for incident response.
Authored the groundbreaking APT1 report, exposing China's PLA, U.S.
Unit 61398 in a sweeping cyber espionage campaign targeting over 140 U.S. companies,
a revelation that reshaped global cybersecurity policy, led with transparency during the
solar winds breach, publicly disclosing the compromise of Fire Eye and helping uncover one of the
most significant cyber attacks in U.S. history impacting multiple federal agencies, oversaw the
oversaw the $5.4 billion acquisition of Mandiant by Google, one of the largest cybersecurity deals ever,
and led the company through integration as the CEO. Most recently, you are the founder of Armadon,
a pioneering autonomous AI agents designed to identify and exploit vulnerabilities like nation-state
attackers, backed by a record $189.9 million rate.
from top-tier investors, including Incutel, the CIA's investment arm.
That's right. They are in.
Why not? We're in America.
How is it working with Incutel?
Why not?
You know, when you get into offensive cyber, the cyber domain's been contested my whole life,
your whole life, Sean, literally.
I mean, it's something that people that are faceless, nameless,
and have no risk and repercussions can rob people, hack people, extort people,
steal information, and they can do it from 10,000 miles away, you know.
And so when we started, you know, Armiden, the whole thing was we want to support the United
States government.
Like the cyber domain is contested.
That's at least when, when it is contested.
During times of peace, it's contested.
Imagine during a time of war what it might look like, you know?
So, yeah, getting in Qutel involved, to me, it just felt like the right thing to do.
You want to service the intelligence organizations and the military.
It makes sense.
I am curious, though, because nobody's really come out and said that they have them as an investor.
I don't think we did.
I don't know how you knew that.
It wasn't the first one I would have listed because now, you know, you try to do business in Germany.
They're like, oh, the U.S. governments inside of Armadden.
They're not.
It's just you want to support the war fight, you want to support our intelligence agencies,
and you want to believe, you know, America can be the beacon on the hill still.
Do they have any specific stipulations that they want insight into your company that other venture
capital firms are not going to have access to?
Well, you know, it's funny that we're talking in QTal, just the latest Dan Brown book,
Incutal are the bad guys.
No shit.
True story.
They're the bad guys somehow.
It's been my career.
Like, I'm biased.
I believe in the institutions of the U.S.
government.
Every institution can have its downsides and upsides, but you look at the missions of what we try to do.
We try to do the right thing, you know, and it's the fastest way to bring capability to the intelligence agencies and to the military is through Incutal sometimes.
And I believe in what we're doing, and I want to make sure the American Warfighter has the advantage in the cyber domain.
That's simple. Do they have covenants? I'm sure they do. You know, did I sit here and memorize them for your show? No. I do know they, you know, they'll all tend.
the board meetings when we have them. And as an entrepreneur, you'll learn if you haven't yet,
man, board meetings can be long. And I've been the operator at board meetings. I'm trying to push
these things off as long as I can. You know, let's start them when finally we will start board meetings.
That's the problem. I was unfunded the first time. So I didn't have board meetings for the first
seven years of mandi and I'm, but now I've done funding and I'm like, should I be doing a board
meeting yet. And I'm just going to sit quietly now. Someone will listen to the show and say,
okay, man, do you have a board meeting? I'm not going to really schedule until someone's begging
for them, you know, but I'm sure Incutel will show up and the others will show up. But we are so
early on, what's the value in a board meeting? Yeah. You know, it's, they think there's value. What are you doing
with their money? For me, it's let us prove ourselves and let's get some things done first. So I'm not sure
I need a 90-day cadence yet. Right on. Although I'd probably just,
spoke my mind and I'll have one in two weeks now.
Yeah.
I've been using Ridge for a while.
And what I like about them is they take everyday gear and make it cleaner, tougher, and more
functional.
Wallets, power banks, luggage, travel gear, all the stuff you actually carry and use.
In fact, their power banks, I just got three charges off one bank at the airport.
Amazing.
And now Ridge is back with their annual sweepstakes for the sixth year.
And this one is insane.
Two winners get to choose between a Lamborghini-Orakhan-Storato, a Hennessee Velociraptor, a custom Ford Bronco, or $100,000 in cash.
I'd probably take the Velociraptor.
It's got 558 horsepower twin turbo and, it's basically American muscle built into an all-terrain truck.
That's a hard one to pass up.
Even if you don't win, Ridge is still worth checking out.
Their power bank has built-in cables, wireless charging, mag-safe compatibility, and enough power for up to three full phone charges.
Their wallets are slim, durable, and built for everyday carry.
Ready to upgrade your wallet and maybe your ride?
For a limited time only, head to Ridge.com and use code SRS at checkout for 10% off your order and a chance to win Ridge's biggest sweepstakes ever.
A Lamborghini, Urukon, Storato, a Hennessy Velociraptor, a Ford Bronco, or $100,000 in cash.
No purchase necessary to enter, but every dollar you spend gets you more entries.
That's ridge.com and use code SRS.
After you purchase, they'll ask you where you heard about them.
Please support our show and tell them our show sent you.
As you guys know, once upon a time, I was a Navy SEAL, and then I contracted for CIA.
We were hunting ISIS, Taliban, terrorist organizations.
China was there, Russia was there, the Iranians were there,
and everybody's kind of collecting on each other.
One thing I learned is how important encryption in protecting your data is.
That experience has just always made me extremely paranoid
about what's being sucked out of my phone, what information are people getting.
I wanted something that could protect everybody.
And so we turned it into an application.
We call it the Glacier App.
We have Secure DNS.
Now, what's Secure DNS?
Well, very simply put, secure DNS keeps your phone from being exploited while you're browsing the internet.
Just a couple of buttons.
Your phone's protected.
You got yourself a burner number or more.
You hit Connect, done.
You're protected.
This is like the real James Bond shit, MI6 CIA level stuff made in the U.S.
Theglacier app.com or just go on the app store and look up the Glacier app.
Take your privacy back. Download Glacier today.
Well, before we get two into the weeds here,
and this is going to be a fascinating interview.
I don't think anybody can make cyber as exciting as you can.
And with your backstory.
Yeah. Wow. But everybody gets a gift.
Oh, thanks, and we got you a couple. Thank you.
Oh, thank you. Those are vigilance league gummy bears made in the USA.
Legal in all 50 states. Not that you have to worry about that being out in Cali, but
And I'm the guy that true story.
It's in Southall right now in the hotel.
There's a little white bag on my table with your gift in it.
So I'm going to send you something as well.
And I apologize that I didn't bring it with me.
I was so eager to get here.
I ran out to the car without it.
No sweat.
I got you one other thing too.
This is the most exciting one.
So there you go.
Yes.
So that is, that's just an iPhone.
But that has our new application in there.
So.
I got really paranoid through some of the interviews that I've been doing.
This for me.
This for you.
I want your honest feedback on that.
All right.
You'll get it.
Wow.
Thank you.
So I'll give you the backstory.
So I started getting paranoid about a lot of the people that I'm connected with in the U.S., out of the U.S.
Then we did an interview in Taiwan with Bashi Kim.
Okay.
You know all about China.
We're going to talk about it later.
So I started getting really paranoid and I wanted about my email, about my text, about, you know, my phone and secured.
So I started asking a lot of the former buddies or buddies of mine that were former Intel guys, hey, what is the latest and greatest black phone?
And so I got pointed to this company called Glacier.
Okay, yeah.
And so Glacier was started by a handful of former.
Intel guys over at NSA.
And so I got to talk him with them.
I got one of their phones and their phones are awesome.
They secure VPN, all-American VPN, secure DNS.
They will upload and take away your footprint.
So like when we went to Taiwan, they uploaded a false footprint,
got rid of it when we got back home, can re-upload it if we go back.
So nothing looks fishy.
and then they have also they have virtual numbers so I talked to them a lot about how to
disappear off the internet and they basically said hey you you have to you need to keep that
number your real number sacred so what we have here is that's awesome you can put in
oxy to it any area code you want it'll give you a list of burner numbers it's got a great case
thank you it's like bulletproof right well so it was hard but we got it on the iPhone
Nice.
Because nobody wants to use an Android.
So that was a challenge.
The device is extremely expensive.
So when I talked about going into business with him, I said, hey, you know, this is really expensive for the everyday user, not only for the device, but for the subscription as well.
A lot of money.
And so I said, what would be great is if we could dub this down into an application.
that's a lot more consumer-friendly.
So we took everything, almost everything
that Glacier has, put it into an app.
And like I said, it's a full-blown security suite
on your privacy app on your phone.
So I'd love your honest feedback.
You'll get it.
And it's weird.
So now, one of the things I'd learn throughout my career
is how to solve the read, write, store, and delete data.
What's the app really do?
You know, so we'll end up kind of reversing it.
You know, we'll kind of try to figure that out.
But I think you're right to be paranoid.
You know what I mean?
It is a strange world where, you know, the digital exhaust we leave behind is way high, way higher than people think.
Every time you browse the web, you know, whether you say, hey, I want cookies or don't want cookies, you're getting them.
You know, we had a company come in and pitch us on a, we got a cookie tracker.
And I'm like, you know, we didn't invest in it.
But we went out and just tested their software during, you know, while the entrepreneur was pitching us,
on, hey, listen, this is what happens.
And we went to a medical site that everybody uses.
And when we connected to it, Sean, of course, we got the prompt.
Do you want to accept cookies or not?
We're like, hell no.
We got a bunch.
We got over 900 cookies just by doing one search on one site about a specific disease.
And those cookies come onto your hard drive.
And then when you go to other sites, you're letting, like, a marketing company know,
or you're letting a PR firm know.
or in this case, we looked at all the cookies,
and one of them was .rU.
Like, we were sending our IP address
and the sites we were visiting to somewhere in Russia.
And so this whole, yeah, like everybody,
we have a whole generation, by the way,
that's probably waiving the right to privacy
by posting everything on, you know, Facebook, you know, meta.
But I get it, you know, it's right.
It's like if I had to give one privacy tip,
use iOS devices, use Apple.
Really?
Yeah, totally.
Like, just it's not, if you look at, by the way, simplest metric in the world on, hey, what's really secure?
Look at the payouts if somebody has a zero-click exploit for the iOS phone.
In some places, it's $20 million.
You know, and Apple itself, I think you can get $4 to $6 million on the bug bounty program.
Like if you find a zero-click, someone just like, hey, that looks interesting.
They don't touch anything.
iOS is hard to compromise.
And they really, anyone who's on offense and can compromise it, it'll probably be a modern nation and they're really coming after you.
But that doesn't mean it's undoable.
So I love the fact that you picked the iOS as the platform.
I think it's right.
Thank you.
And I think more and more people probably should think, where's my data going?
Who's getting it?
Well, the other thing that I actually can't believe I forgot to mention is there's,
there's data blocking.
So everything getting sucked out of your phone is no longer getting sucked out with that
application.
So it's, we'll put the link in the description for anybody that wants to check it out.
But you just mentioned, so when I was researching you, and you were talking about the China,
that was a section I was in the China.
What is the, 6-1-6-39-8?
6-138.
6-138, yeah.
And when I was researching that, you had mentioned that.
You had mentioned that if anybody had done business in China, you're compromised.
Pretty much.
Isn't Apple doing business without a business?
Well, they probably were compromised in some way.
An interesting thing about Apple, my whole career, Apple's never called and said, hey, man, can you respond to a breach here?
So, and there's a couple, like, if I went through the whole Fortune 100, there might be eight of them that didn't hire us to respond to a breach, and that's it.
And Apple's one of them.
And they've always, there's a couple places.
You know, Goldman's one.
You know, they have usually homogenous networks, very simple.
similar, lots of tight controls.
If anything does happen, they detect it quickly
and respond quickly.
And Apple's always struck me as one of those companies
that's pretty damn good at security, you know?
It's good to hear.
Yeah, it's just there's something different about them.
I mean, think about what they did with the iOS, they closed it.
It's not like you can just write an app and do it.
You've got to use their libraries, their APIs,
and publish it their way.
You know, no one really jail breaks the iOS phone.
to put whatever they want on it.
So if you, for the most part,
you almost have to hack yourself to hack your iPhone.
You know, a window should pop up,
hey, this software is unsafe.
You have to go, I'll take it, you know?
Gotcha.
And hit it.
So except for the rarest of cases
is you're really targeted by like a foreign intelligence service.
That's about the only way I think you're gonna see a phone get popped.
Okay.
Yeah.
Okay. Well, that's good to know.
Yeah, no, it's a good selection.
Thank you. Thank you.
You nailed it.
Right on.
Well, let's, so let's, I want to do a full-blown life story.
All right, I'm ready.
Where'd you grow up?
When I grew up, formative years, Pittsburgh, Pennsylvania
during like the crappiest decades of living in Pittsburgh.
Yeah, we were winning Super Bowls,
and that's about the only thing we were winning.
That's not a bad thing.
Seventies and 80s, every steel mill closing down.
You know, I still remember probably 1983, 84 coming home from school.
My dad, you know, dawned me, my dad never sat at the kitchen table.
unless he was eating. And I came home from school one day and A, he was home, B, he was sitting at the
kitchen table, and then it hit me, something's different and he lost his job. You know what I mean?
And I remember in an instant, you know, nonverbal communication could say it all sometimes. I instantly
thought, man, he'd pick cancer over this. You know what I mean? And so Pittsburgh was a rough place to
grow up. And I spent, you know, the late 70s and early 80s there and then moved away from there and I
went back to there. And I still remember when we left, they called, man, I don't ever want to
go back there. It had three years later by dad's like, hey, we're heading back. So anyway,
formative years, Pittsburgh, great people, tough town. I think if you live in Pittsburgh from
1970 and 1985, all you saw is, you know, a tough place. Probably like Detroit, you know what I mean,
sister city Detroit, I feel for that place. Yeah. What were you into as a kid? Football, right,
it's Pittsburgh, you know, football, baseball, basketball. I was the youngest of four boys. I think that
matters, you know, you got somebody, you know, you got to live in Alice Cooper fan and your older brother,
you know, you learn about rock music, you know, I was 10 years younger, my oldest brother. So I got a
real education on music early. Everybody played football. Everybody, you know, it didn't matter where,
you know, it's a, you go in the backyard and pummel each other. You had to, you know,
so it was football, baseball, basketball, and then you go to entertainment, it was like Magnum P.I.,
Quincy shows you probably don't know.
I mean, we missed the shows.
Oh, no, I know Magnum P.I.
You got Fresh Prince Bel Air.
I got, you know, Quincy.
The, but you get it.
It was, you know, Pittsburgh was a black and white city.
You know, you move away from that and you get to see color.
But in Pittsburgh, when I meant by that, it's just, it was gray.
It was, it was like it felt like it was always winter, you know.
And in hindsight, you don't know it till you leave it and look back on it.
It was a depressed state.
Like, the people were all struggling, you know, period.
you know, and I was in one of the nicer towns.
But I think I was in the sports, you know.
And then I had a father who was old school, right?
Old school is, hey, son, get A's.
What that meant is get A's or I'll kick your ass.
Dead A's or similar a brain.
Life's going to get real hard for you.
I mean, I didn't want to find out what the alternative was.
I found out.
Wasn't great.
Yeah.
Well, you know it then, right?
I mean, my dad had a set of rules that if you broke him,
you did get hit, and it was fast.
I always was like, how does this large man move so quickly, you know?
But he was consistent about it, you know?
People are like, hey, corporal punishment is bad.
For me, at the youngest of four boys, I think it was necessary in a way.
You know what I mean?
Like, we were probably going to be pretty.
My dad liked to order, quiet, clean, and I don't think you would get that naturally
without some enforcement, you know, and at the edge, as they say,
and my dad had that.
So I knew every time when I was going to be disciplined, it never surprised me,
other than how fast he could move to do it.
And by the way, it would have done no good to run because that would have just made it worse.
You know, you just got to stand there and take it.
And it wasn't like he beat me.
It was just, you know, he had a discipline to it.
And so, you know, going back to the original question, what I was into is probably saying
that every teenage boy in Pittsburgh was in sports, except I was a Vikings fan for some damn reason.
Yeah.
Right on and figured that one out.
So how did you, were you into cybersecurity by the time you joined the Air Force?
No, it didn't even exist.
So I get in the Air Force in 93, but, you know, I graduated college in 92.
And back then there was a little bit of a lag.
You know, we had the Clinton years.
There was a lot of riffs going on and you could do ROTC and never actually get orders.
You know, so it was an interesting time for the military.
It was time of peace for the most part.
We had done Kuwait in the 1990, Desert Storm.
So I graduated college in 92, but I grew up, you know, I thought Magnum P.I. was cool.
You know, he's former military. He was, you know, he solved cases.
I always felt like you. You got to have a mission bigger and self.
You got to, you know, when you contribute to society.
And I grew up a forensic fan. I mentioned Quincy earlier.
I used to watch Quincy going, hey, man, let's solve cases.
I did computer science in college from 88 to 92 because I grew up with Pong.
I still remember the first Pong game, Nintendo.
Wow.
in television, The Odyssey by Magnavox.
Like I grew up with the whole Atari 2,600.
You'd grow up these games, and that kind of gets you into computers.
So by the time, 1980 or 1981, I'm 10 or 11 years old,
my Christmas present was the TRS 80 color computer.
Like other kids are asking for, I don't know,
stretch Armstrong and Rock'em Sockham Robots.
And I'm like, hey, man, can I get a computer?
And my dad, my mom, my grandparents all pitched in
and bought me like this $700 Christmas present,
which back then is like, are you kidding?
That's like better than a car back then, actually, Sean.
So in hindsight, I should probably be more thankful.
So in 1980-81, I get my first computer,
and even though I'm playing football, baseball, basketball,
basketball, running track, and out, he was pummeling people,
and I'd come in and be like, hey, man, I like this computer crap, you know?
So I kind of grew up with the computer.
I got computer science ROTC at a small school in Pennsylvania called Lafayette College,
called Lafayette College where I went all out.
I took a pencil, filled out the common application,
applied to one school, got in and went there.
Nice.
There was none of this, 20 schools, TED schools.
I had like no plan B.
It applied to Lafayette, did RTC at Lehigh,
and did computer science.
And I got stationed at a Pentagon in 1993.
And the way I got into cybersecurity was
I got stationed at Pentagon.
was six second lieutenants.
And we were all waiting in line
to go in to see in 06, a colonel,
full bird Air Force colonel.
We were stationed at what was called
the 7th Communications Group.
And we're all, you know,
chicken shitting out in the hallway.
Who wants to go first?
What do you want to do people want to do?
And I like to tell you,
there's this elaborate plan
for me to go into cybersecurity,
but what really happened is I went first.
I was like, I'll go meet the colonel.
I'll go figure this crap out.
So I just get first in line
and I go in.
and the 06 behind the desk gives me a, and literally it was the whole thing, you go and, you know,
stand at attention, go to that ease and wait. And he lays out five options for my next couple
years. Here's what your assignment can be. So I actually had a choice. And all the choices were bad.
And it was the weirdest thing, Sean, right at the end of it, I still remember it. He was like,
oh, oh, when we have one slot left, one job left to do computer security. That's what he called it.
And I remember thinking all five options prior to that were horrible.
Like it would have sentenced me to death.
It was like job control language, mainframe programming in the basement of the Pentagon.
When he said there was one slot left, I'm a sucker for there's only one left, you know.
And so I'm like, I'll take that.
There's only one left.
That's valuable.
And, you know, in hindsight, I backed into, you know, it ends up playing out very well.
I loved forensics.
I ended up getting a master's in forensic science at GW on my own time while serving.
And computer security worked.
Like immediately I had this job doing computer security.
And what it was is who's accessing what.
And about a year into me doing that job, it was 1993.
The Air Force put eyes on the network for the first time.
I mean, for the first time ever, we started watching,
what are people doing on the network?
So I kind of got to grow up with computer security.
You know, we started watching people.
The Department of Energy created a tool called the automated
security, incident measurement tool.
It's free.
And we deployed it at the Pentagon.
And for first time ever, we could see, what are people doing?
Like, what files are they transferring?
And what commands are they doing?
And where are they logging into?
And when we lit it up, right away, we recognize, wait, we're not the only ones on this network.
You know what I mean?
Who are these other people on it?
And so by 1995, I cross-trained into the Air Force Office of Special Investigations
from computer security to do computer intrusion investigation.
The military was starting to use the internet, you know, from 93 onwards.
So we had to start figuring out who the hell's on our networks and what the hell are they up to?
Who was on the networks?
First one I ran into was China.
Literally go all the way back to, I think it was summer 95.
It might have been summer 96.
One of those summers, we, you know, at that point we had the Air Force Computer Emergency Response Team.
The Air Force had one.
I don't think the Army had one yet.
I don't think the Navy had one yet.
And then the government had one called U.S. SERT
out of Carnegie Mellon University in Pittsburgh.
And so maybe there's something in the water in Pittsburgh
to get you into this stuff.
But I remember there was a West Coast University.
I'm in the Air Force Special Investigations,
and our ASEM boxes showed something like 20 Air Force bases
were logged into from one university.
what the hell's going on?
Like, no university should be logging into that many,
you know, Wright-Patterson Air Force Base, Oak Ridge,
Lawrence Livermore, Los Alamos, right-Patterson, all of them.
And they were, and so I flew out to the university,
and at that timeframe, I'm in the United States military,
I go to this university, and I'm like, do you mind if I monitor
all traffic to and from this machine?
Now, everybody's listening to this, it'll be like,
the government watches everything.
We really didn't.
Back then, I had to brief the judge, advocate general,
hey, this is what I want to do.
And to the Air Force's credit,
if we did what we would call wiretap
and there was nothing fruitful in it,
oh, it got killed fast.
Like you had to have fruitful real results.
Or Jagu's going to be like, stop it, get out.
There was a great control
to not wantonly watch.
But the university allowed consent.
Is you still like that?
I don't know.
You know, I often wonder if the military
is the same as when I grew up,
maybe atop of for later,
because to me, but then it absolutely was.
I remember going, man, I need to tap this
because someone's coming from somewhere in the world
into this system and then from there
to all these military installations.
So I got consent to monitor to the colleges
or the university's credit, they were like,
yeah, go ahead and do it.
And then I, the way I did taps back then,
I just ran software on the machine itself.
You know, it was a Unix machine,
and I watched all incoming traffic.
In the first day, I'll never forget this, Sean.
Summer of 95 or 96, it was one of those two.
The very first day I did the tap, somebody was logging,
this is how you go one hop back every time.
Like, if somebody hacked you, we'd only know the first, like,
IP address or first address they came from.
But in computers, you can connect, to connect, to connect,
and they're called hop points.
And everybody obfuscates where they're really sitting.
If you're sitting in Russia and hacking, you know, the Pentagon,
you're not going straight from .rU to Pentagon.
You're going from .RU to the UK to China to wherever you want.
How do you pick those?
They compromise them first.
Like if you're on offense, you have a network that you use to launch your attacks.
And for the most part, you almost have a team that maintains that compromised infrastructure
for you.
So if I'm a foreign intelligence service, I have a team that maintains access on all these
intermittent sites, not my real targets, just sites like universities and business.
businesses. And it's called a non-attributed network of victim machines. At least this is how
other nations do it against the United States. And then they have their operators use that
infrastructure. And that's exactly what we ran into in this case. I do this tap at a West Coast
University. The very first morning I go in and like download the files to look at what happened.
Somebody came directly from Beijing into West Coast University using the account of a Chinese
foreign national, I went to this college, but I had since graduated, and logged into 37 or so
military installations. And each login was somewhat haunting. They used a user ID, like S. Ryan,
and then a passphrase. Then the next one, they would go to, like, write Pat and go,
John, Jay Smith, and the right passphrase. They were validating accounts at all these different
places, and I had the right choke point to see all the traffic. They came to this one machine,
logged into right pat logged out
logged into Los Oak Ridge logged
out, logged in a lone
you know Los Alamos logged out
right pat
keep going down the list
and they never fat-fingered
the passphrase they got in every time
and I remember thinking how do we fix this
like you can't we call
37 bases who do you call
they were hitting Army they were hitting Air Force
they had the Marine Corps
they hit us all I mean just just for
the viewer context here
those are the most secure
secret military bases that the U.S. has.
Yeah, it's just the protocol.
Yeah, and it was just,
it was the Defense Research and Engineering Network
is essentially what these guys are in.
And the unfortunate reality in hacking
or fortunate if you're the offense,
like if I break into the Pentagon,
it's just a matter of time before I break in
all the other military installations.
If you break into an Ivy League school,
you're going to end up being able to hack all the Ivy League's,
because that's just where the traffic goes.
That's where the information is shared.
And that's what happened here.
I don't know where they originally broke into,
but it was extensive.
And that was in the 90s.
So, and I remember there was no one to call.
Like, that case went on for like 10 years.
I mean, I had code names and classified names,
and it just kept going.
There was nowhere, I was a first lieutenant at the time.
I mean, what do I do?
Call the base?
Like, hello, operator, I need the cybersecurity guy.
There wasn't, there was no way to remediate it.
That simple. So instead, what we ended up doing is running an operation largely run by the military
jointly with the FBI, and we did counterintelligence. We just watched it. And then we found the Russians.
For me, every day, let's just shortcut. It is 2026. My first incident response is 1995. So it's been
31 years. I would say every day of my 31 years, we've been responding to an intrusion out of China
somewhere on the planet here, every single day.
And by the way, not just one, way more than that.
So they have mass, they have just a scale
that they can operate at that's pretty high.
And then probably the Russian SVR had counter-frenzics earlier,
so they would go dark on us.
And back in my day, Sean, if I responded
as an Air Force Special Agent, what was amazing to me
if I responded to Russia, every time we caught them,
they just went away.
They were like, ah, you got us.
We're going to go away for now.
And there was almost like rules of engagement.
If they got caught spying, they just went away.
And you can tell when someone's monitoring what you're doing,
you can find the tools we use,
or you can see that we're starting to remediate
and clean up around you,
or we shut off the account that you're using,
or we change pass phrases.
And the Russians never let us observe them, period.
From literally, from 1995, 1995, 1996,
anytime I responded to a Russian-based intrusion,
They were super stealthy.
That did change right around 2015, where they got louder
and probably they stretched their mission too much
to do counter-forensics and counter-surveillance stuff.
But they had a 20-year run where we'd have them in our sites
and lose them, and I went years not finding them.
Like, literally, we're like, we know they're out there
because that's their day job.
You know what I mean?
They're paid to hack us.
You know, they show up every day badge into a building
and do it, but most of those cases probably got classified
and I was on the outside by then.
But they were really hard to find.
China was more like a tank through a cornfield.
I mean, they were just like, they didn't care if we saw them.
They didn't do counter-phrenics.
They didn't change the data.
They didn't extort.
They didn't do anything.
They just stole everything, you know.
Who do you think is better?
It sounds like Russia's better at it.
You know, for the vast majority of my 31 years responding,
Russia was better.
Better tradecraft?
Yeah, their operators really didn't like getting caught, you know.
and they just, here's an example.
Like, I think China just had so many people, Sean.
Like, I just said the other day,
I knew a lot about religion,
because I took art history.
I feel like I know a lot about the Chinese culture
just by responding to intrusions.
They definitely threw people at it.
And here's an example.
If a Russian hacked your machine,
what they would do is they would bring their own way
to search your machine.
They would hack your computer.
Then they'd upload a file
that would search everything on your machine
looking for specific keywords, whatever they're after.
Or they'd just grab your email.
And even when they grabbed email, they would minimize it.
They'd grab like the last month's worth or something like that.
They were always very precision strike.
If a Chinese operator got on your machine alphabetically, file by file,
and directory by directory, they'd look through your machine.
Because they had, and I thought about it, they have human capital.
There's eight hours in the day.
There'd be an operator on a keyboard on, I'm on Sean's machine,
let me just look at this file.
And literally, they almost did it alphabetically.
The second thing I noticed is early in my career, the SVR would always steal, the Foreign
Intelligence Service out of Russia, the SVR, would always steal specific files respondent to
what they wanted.
They were just real good at that.
The Chinese would just compress a whole directory and steal it.
Like if you ever use like ZIP or something like that, they would say, oh, this directory called
Documents looks interesting.
I'm going to take the whole thing.
So I could actually tell who the operators were just.
by the data theft.
I'd be like, that was Russia.
They took 32 files.
That was China.
They took three terabytes of everything.
Because China would even steal operating system files that were the same on every machine.
But it just had operators that would go, that was an interesting director.
I'll take everything in it.
That was an interesting director.
I'll take everything there.
I'm sure they had a unit that was more precise, more stealthy.
Every nation does.
But China took front seat in 2020.
You know, every year at the end of, so from 2004 to 2020,
five, I worked at Mandia, you know, my company.
And we, at the end of every year, I'd be like, hey, guys,
brief me on the coolest cases we got.
And for the most part, I got involved in those during the year.
It was in 2020 where I saw the Chinese government
break in using what's called a zero-day attack.
There's no patch to it.
Similar to like when we were talking earlier about Stuxnet.
Zero days are attacks that work
against an application and you can't stop them. They will simply work. And the goal of a hacker is
to get remote access to your machine. So I can be 10,000 miles away and get to your phone,
or 10,000 miles away and get to your server or desktop. And then it's usually, I want your email,
I want your files that you've created. I want reports that you're writing about our supreme
leader or whatever it might be. And in 2020, the most expensive offensive attack was done by China.
They used multiple zero days to break into a defense industry-based company.
And everything they did that were special.
Like everything they did had to be custom crafted for that environment.
And that is, in my whole career, that is very, very rare.
And China did it.
So I'd say China's number one now for scale scope and sophistication.
And then China decided to get stealthy in 2020 as well.
They weren't prior to that.
They decided to, from a forensic standpoint, leave less famous.
fingerprints. Wow. And Russia went the other way, by the way. Russia is now like, we found them,
you know? And I think Russia with conflict and everything, they're just operating at such a scale
and scope that they can't, they don't have enough operators to clean up after themselves. And it's very
manual to clean up after yourself. It is not, it takes a human intelligence on a keyboard to say,
I don't want to leave a trace on this machine, so I have to edit the log file, take myself out,
You know, so the counter forensics of Russia
is down a notch or two right now.
I mean, you were tracking nation-state hackers
before the majority of people even had email.
Yeah, I think we were the first ones to do it.
When you walked into that, what was the program you were at?
What was it called?
Well, so I made it.
That's kind of what I get.
Yeah, yeah, so I had a master's the way.
Yeah, so I had a masters in forensic side
so you can think about all these intrusions I'm responding to,
to are like crime scenes. Like, what are the fingerprints left behind by the intruders? Well, it's the
malicious code they run. It's the commands they execute. It's the encryption algorithms they use. It's the
type of files they steal. It's the type of targets they even compromise. And so with my forensic
science background, I created a thing called an indicator of compromise. I, you know, I'd worked enough
cases where we're like, we got to call the fingerprint something. So the indicators, and we started
just bucketizing them. So we respond to company A and be like, oh, the attack came from here,
They use this software, and as we bucket-tize or cataloged the evidence,
we started just seeing the same people over and over.
They used the same custom code to break in.
Like, I'll give you a weird one.
Like, if you break into the two dominant operating systems are Unix-based operating systems,
UNI-X and Windows.
And Mac is a Unix derivative.
You know, in Windows, if you break in, you do what's called a directory command.
I've broken in and I want to see what's on your heart.
hard drive, I'll do DIR, and just kind of look at what's on there.
And the Russians, when they break in, they do a directory listing of everything on your drive.
And that's all they do.
It's really smart.
It's a great recon.
They don't even poke around sometimes.
They break in and go, just show me a map of everything on the machine.
They download the map, then five days later they come back and just take what they wanted.
The Chinese would break in, show me everything, and then go through it alphabetically with
a human just sitting there 10,000 miles away looking at every single file and doing it.
So we even cataloged in Unix, the DIR command is called LS for List.
And we would catalog, did they do an L.S-A-L option or L-S-Dash-L-A?
Different operators typed it differently, and we could even get down to the speed at which they typed.
I mean, we were tracking on a lot of cases.
We had it up to 650 criteria we would track, but only like 10 mattered.
We just took the fingerprints of each group.
And it turns out the Chinese did great training
and the Russians did great trading,
so they were actually really consistent.
You know, the commands they typed.
If you're a kid and you break into a machine,
you just get undisciplined.
You start going, I'll check out this directory,
and then randomly this directory,
and then randomly this, and I'll look over here
and I'll do this, and they're all over the place.
It looks like a monkey shit fight at the zoo, right?
And then you respond to the SVR,
and it's just all economics.
They did a directory listing and left.
That's it. Gone.
Kids don't do that.
Foreign intelligence services do that.
Because they're going to come back in
after they've looked at the file listing
and just by names alone, they know what they want
or even the apps they want to steal.
And at the time I started responding to intrusions in 95,
we didn't export our supercomputers.
So all our modeling and simulation
of modern weapon systems
were done on supercomputers, the C-90, the Origin 2000.
The front nodes to all these supercomputers
were what we would respond to.
The Chinese and Russians would hack these things,
and literally they would run our modeling and simulation
on our systems, but export the output
all the way back to China and Russia.
Isn't that amazing?
So one of the first cases I ever did with Russia,
they were literally running, they were stealing,
stuff and they were running the modeling and simulation of a certain system we were creating,
unclassified, though, but they were exporting the display right to their desktop. So they were just
sitting back watching, oh, there's the model, and this is how it looks. They were literally stealing
it that way in 95. So again, though, those fingerprints, that's just an example of fingerprints.
The commands they type, how fast they type, the malware they use, who they target and how they
operate. At my company, Mandia, we started creating these dossiers, basically, and we were boring.
We didn't know what the call, we didn't name the groups like, you know, this is fluffy snuggle duck,
and this group's called, you know, whatever, bad rabbit. We just called a minigures.
AP, advanced persistent threat one was China. It actually was PLA Unit 61398. And we just named
them integers. And now we're up to, I don't know, 50 something. And that's where we have
definite attribution. Like, we can get you to build a building.
they're coming out of, you know?
So when we started this,
we had maybe 40 groups in the first eight years
that we had fingerprinted, only 40 different fingerprints
for every cybercrime.
Now we're in, I don't know, 6,000.
How big was your team back then?
Oh, by the time, I mean, there was one, me,
and then we grew it to about five hundred.
Yeah, one person for the whole country?
No, no, no, no, no.
I started it, right?
But we were about, by a time we're labeling groups,
APT, one, two, three,
were 350, 350 people.
All ex-government, like at one point,
Mandi, it was 500 people,
and I'd say 350 came from the U.S. military.
I'm sorry, I meant, I meant...
Oh, just the Intel side?
The Air Force.
Oh, in the Air Force.
When you were a special age...
When I was doing that, there was 13 of us.
That's it.
We doubled at the 26, yeah.
It kept doubling, and, you know,
cyber was new in 1995 when I was in the Air Force doing this.
And so they kept doubling the teams.
Now I bet it's hundreds and hundreds.
Like if you're a special agent in the FBI today
and you're not digitally, forensically educated,
you're not very useful.
I mean, you have to know our networks function,
how every case has digital evidence now.
Counterintelligence, crime, espion, all of it, period.
But when I started doing this,
there was like the computer-aware agent
and the non-technical, non-computer-aware agent.
I think that one's almost obsolete at this point,
you know, unless you're a great accountant,
or you speak 20 languages.
I don't know how you can be an agent today
investigating anything
without understanding digital forensics.
So small team, 13, 14 of us
massively grew even while I was doing it.
We were called computer crime investigators
and we did the, and the FBI
had a thing called the carp team.
I don't even remember what that stands for
if it was like computer forensic stuff.
And all I can tell you is we're always,
no matter what, it was almost like we had a sticking line
where we're always six months behind.
No matter what the case was, we were six months behind on the forensics.
You know, it was like, because it was real hard to keep up with all the digital evidence piling up.
So.
Here at Sean Ryan Show, we cover subjects that get complicated fast.
Intelligence, war, technology.
And when you're dealing with topics like that, the hard part isn't just finding information.
It's making sense of it all.
That's why we use Claude.
Claude helps us take a messy topic and start connecting the pieces.
Timelines, contradictions, different angles.
angles, follow-up questions, things we may have missed.
It helps us slow down the research process and think more clearly before we ever sit down
for an interview.
And we use it across the show, episode prep, research, strategy, and even our hot question
segment.
It's become one of those tools that help sharpen the work behind the scenes.
Claude is the AI for minds that don't stop it good enough.
It's the collaborator that actually understands your entire workflow and thinks with you.
Whether you're debugging code at midnight or strategizing your next business move,
Claude extends your thinking to tackle the problems that matter.
And with features like deep research and connectors,
Claude can help pull context together from the tools you already use
and turn complicated information into something that you can actually work with.
Companies like Stripe and Shopify Trust Anthropic with the rollout of AI in their businesses.
For problems worth solving, get started with Claude,
at Claude.a.a.a.s. That's Claude.a.a. slash SRS. And check out Claude Pro,
which includes access to all the features mentioned in today's episode. Clod.a.a. slash sRS.
Let's talk about, if we're ready for this. Let's talk about exposing China, the APT1 report.
February 2013 released a 76-page report publicly naming PLA, U.S.
unit 61398, operating from a 12-story building in Shanghai's Pudong district.
Yeah.
As the source of espionage against 141 U.S. organizations across 20 industries unprecedented.
Yeah.
Stold technology, blueprints, manufacturing processes, test results, business plans,
and executives' contacts list.
Yeah.
How did you, I mean, huh.
Well, this is.
Yeah.
This is all you.
Yeah, but I think the government knew.
You know, so this was 2013.
The back story on that is I start Mandia in 2004 and out of premise, let's respond to every breach
that matters because in the cyber domain prior to Mandiant, here was the intelligence model
in cyber.
It was McAfee and Symantec Antivirus.
You've probably heard of them, right?
McAfee and Smantec, you'd run antivirus on your machine.
If antivirus missed a bad file, a malicious file that was stealing your stuff, the only way
semantic and Macfee got smarter is you would be like, hey man, you missed this malware, so I'm
going to submit it to you so that you detect it next time.
Well, here's the problem.
My mother's never going to find malware on her system, and Sean, you're never going to find
it either unless you read an 800-page book I wrote that were bored of hell out of you.
You know, it's hard to find this crap.
It's ridiculous.
So I decided we need a new intelligence model on cyber.
Let's learn from all the red teams out there, the offense from Russia, China, the criminal
element, North Korea.
Let's respond to every breach that matters and learn from it and build the defenses.
Because I thought antivirus, and I hate to say it, thinking semantic and McAfee was securing
you at that time was like believing in the Easter Bunny.
I mean, it literally was so easy to invade.
I was actually talking to one of your guys earlier.
And we were talking about he even experimented with offensive cyber and could evade AV because all you had to do is encrypt or compress your executable, put it on your machine, and when it executed it would decrypt itself, meaning it had no signature. So AV would miss it. So Longster made short, we needed a new model in cyber. How do we build better defense? Well, let's actually get in a ring with the offense. Look at what the hell they're doing. So I think I was the first company ever started with. We're going to respond to.
every breach that matters. And I got to be honest with you, I didn't know if breaches would go on
forever. But I had that phrase. I think I made my first website, and you're an entrepreneur,
so you know, there is no website team. I had to make my own website back in 2004. And I literally
wrote on the website, the first phrase was, you cannot solely rely on preventive measures,
and that was boring. So I went with security breaches are inevitable. No one believed it. I think
the only reason Mandant was successful is that a premise.
Security breaches are inevitable.
We'll respond to everyone that happens so that we can build a better defense against them.
First knowledge, first mover knowledge on what the bad guys are really doing to circumvent defense.
Nobody believed that premise so we had no competition.
So every damn major breach, my phone rang.
I still don't know how to hell my number got out there, but we had to be good at it.
And then everybody recommended us.
and breaches took off.
In 2004, when I started a company,
every election year, both sides have a problem.
I can tell you that right now.
So in 2004, you get to respond.
If you respond to Pepsi, you don't respond to Coke.
If you respond at the RNC, you don't respond at the DNC.
But those things are heavily targeted.
But in 2004, when I started Mandiant,
right in the summer of 2004,
we were only like, I started a company February.
By June or July, we're nine people in a basement,
in Old Town, Alexandria.
And we get a phone call from the defense industrial base, and we couldn't respond to.
We're already fully pegged responding to a breach somewhere else because it was an election year.
But it was Honeywell.
And I guess I can say that now because that was 22 years ago.
They were the first ones I saw where the Chinese government that I was responding to in Dot Mill, the military, just went, I'm going to shoot the headlight over here and hit Honeywell now.
then they go through the whole day.
They go after Lockheed Martin.
They go after Boeing.
They go after Rolls-Royce.
They go after U-TX and Raytheon.
And it was considered fair-ness.
All of them.
Well, you know, they are heavily attacked in the cyber domain every day by China.
Holy shit.
I mean, that one's contracted are coming for you.
And these companies have, like, what's funny, people would be like, man, the banks have great security.
Well, in cyber, the best security I ever saw at one point in time was Lockheed Martin.
I mean, what they did on defense was, I mean, all the defense contractors, trust me,
they do everything they can to secure their stuff.
But they also have these joint projects that are, you know, a bunch of mad professors getting together.
But in 2004, 2005, I saw the military of China suddenly expand scope and go after our defense
industrial base.
And that was right when Mandi had started.
So all those companies hired us, and we would respond.
And I remember I would brief, hey, this is a guy in Beijing doing this.
And, you know, it was the beginning of it.
You know, that's when we realized China's all over our networks.
I guess I always knew it.
Dot mill, dot mill felt fair game.
I think nobody really expected them in China to suddenly say, hey, let's hit dot com.
And then they went way down.com.
Like if you were a law firm, if you were an accounting firm,
if you were doing business in China in any capacity,
they had guys in uniform hack you.
So they don't separate economic dominance
from military dominance in China probably.
You know, they hack, we would hack on offense
as a country for security purposes and defense purposes.
China hacks for economics.
So, and then since then, Sean, everything went public.
General Alexander, and he's running the NSA,
largest theft of IP in human history.
You know, to the correct,
Chinese didn't damage anything.
They didn't delete stuff.
In my whole career of responding to the Chinese threat actor,
I only saw like one operator delete the logs once.
You know what I mean?
They leave everything there, but they got way more surreptitious lately.
So, yeah, since 1995 until now,
China's heavily targeted our defense industry.
What do you think when you figure out
that the CCP is hacking into our defense tech companies
are like lock,ied, rating, like, these are the companies that hold the keys.
Well, I think, you know, a lot of folks think when a nation targets you should be able to withstand it.
But I've always thought, like the analogy, well, I'll use this one, you were a seal.
If a seal wants to rob the Lego store at the mall, they're going to evade Paul Blart,
the mall cop and rob the store.
You know what I mean?
No problem.
When you have the Chinese government trying to hack you.
you and you're a company, you will lose over time.
There is nothing, I don't think it's reasonable
for the American people to think any company
can withstand a foreign intelligence service
trying to break in in the cyber domain.
It's not.
And so I remember early on, every victim company
wouldn't tell anybody, you know, but it became,
because you'd say it, and then you'd have pundits on the hill go,
hey, what irresponsibility to let the Chinese hack you?
Are you kidding?
It's like your grandmother,
an ultimate fighting championship.
It's simply an unfair fight.
And it still is today.
Even for the companies that do everything they can in cybersecurity,
you really don't want to come under the lens of the SVR
and the MSS when they decide to go on offense.
It's a tough thing to do.
So what, yeah, so we had like eight,
that's why we went public in 2013.
I mean, I just told you in 2004, the first company I saw China go,
hey, we're going after was Honeywell.
I just, I hate saying that out loud.
I don't know if I've ever said that publicly, but with this amount of separation, they can live with it.
They, and you used to go, man, you know, the thermostat company, but they also make, you know, helicopters and dashboards.
And they're a defense contractor.
But they all had the Chinese come for them.
And it's a sucker punch at that time frame.
There's no, actually true story, Sean, there was no defense for how China was breaking in back then.
It didn't exist.
We had no software to detect it, really.
You could just log in.
You could just do things.
There was no reasonable way to defend yourself in the cyber domain against the nation back done.
Shit.
Yeah.
I mean, that's pretty fucking scary.
Just dawned on me just now.
Yeah.
You know what I mean?
What dawned on you back then when you saw it happening?
Back then, you're more tactical.
Yeah, you know, well, that's why we went public.
You know, we had Mike Rogers.
Congressman from Michigan. We had a Congressman from Maryland. They wanted to do, they wanted to make it so you could share when you've been compromised. Like stop like hiding the fact that we're all in this together. They wanted to have more of team ball, like Team America. So we decided let's help the U.S. government with like some information sharing that when you're hacked and you know it, you can share that information and not get condemned by the government for doing it. You know, you kind of got a safe harbor. And so we we recognize.
Two things kind of, there's like eight reasons why we went public with this report.
I'll give you three of them.
First, Mandian at the time were a bunch of ex-US soldiers,
and we were like, screw China for doing this.
You know what I mean?
So I wasn't going to be able to stop going public.
My team wrote this.
I was just a face on it.
But we knew it was China from 2004 onwards.
So it took us nine years before we finally just said,
hey, man, let's just tell the world what the hell is going on here.
Second, you could feel the government knew about this.
but they didn't know what to do about it.
And at least, you know, the House Intelligence Committee
was like, let's pass a law
that allows people to share information
so we can defend each other.
And then the third thing was the CEOs were like,
what the hell?
You know, I would sit down with the CEOs of these companies
and were like, we're doing a joint project with China.
Why the hell are they hacking and stealing all this crap?
And, you know, the companies knew,
hey, it's on us to defend ourselves.
But they also, at some point in time,
I remember thinking, hopefully,
maybe if we just bring it up, the heads of state would actually come up with, hey, let's knock
this crap off. You can hack us for espionage, but don't hack, you know, Disney because they're trying
to open Disney China, or don't hack, you know, whatever, a soft drink company or somebody else because
they're trying to do some bottling in China. It was time to have dialogue. So we did go live in 2013
and do that. It just so happens that on the day that Obama was going to meet with Xi Jinping, the
talk about some cyber stuff in optimistic sounding sunny land, California in 2013, that was when
Snowden leaked and that stole the show. So I've never, you know, I've always believed since 2004
when I first started responding as a private company to these intrusions that neither China nor
the United States really wants a whole cyber conflict. You know what I mean? Neither nation really wants
it. And at least that's two nations that can come to the table and probably have a dialogue
and come out with rules of engagement. I don't know if you can do that with Russia, too much
criminal element. I don't think you can do that with North Korea and I don't think you can do with
Iran. But China is the one place where I've seen them follow rules. We have to infer the rules,
Sean, when we respond. But China follows rules and etiquette when they act still. Their operators
are predictable. Interesting. What kind of stuff did they steal?
it would be hard to say what they didn't.
You know, that's the reality.
And that's why General Alexander's,
you read the testimony from the director of the NSA,
largest IP theft in history,
Admiral Rogers after him, General Nacosone,
all of them kind of allude to.
China's kind of taken a ton.
Now, there was a dialogue.
After that report, here's what's amazing.
At Mandi and what we were doing
is we were kind of monitoring victim networks,
meaning we saw traffic coming in and out with consent.
And the whole defense industrial base
was working together.
by then. They started a whole consortium where Raytheon and Lockheed and Boeing. They all worked together
to figure out what's kind of doing, how do we thwart this? So they do play team ball now, and it's actually
pretty organized. But I remember at the time going, we're seeing over 70 companies a month
compromised by China right now, just in our little network of watching what they do. After we went
public with that report, it went down to zero for a while. So I think they noticed.
We changed behavior.
Or some say, well, maybe just lost vision on them.
Because when we wrote that report, one of the things we didn't kind of say in the report
is we provided that trace evidence, the fingerprints, we provided over 5,000 fingerprints
of this is their infrastructure they're using the hack us.
This is the malware they're using.
So all the defense companies that make software to stop it, we could just stop them.
So we kind of burn their infrastructure.
We burn their methods.
Their TTPs or tools, tactics, and procedures were fried.
So we fried it.
So they had to go away anyway and recreate all that stuff.
But again, going from anywhere from 10 to 70 companies hacked a month, just in what we could see, and I could tell we probably saw less than 1% of what they were doing.
We'll never know.
Did we see 80% or 2%?
It was probably closer to 2, down to 0 for a few months, and then it starts creeping back up again.
Just for the audience, can you elaborate on some of the stuff that you thought was most concerning that they got, they,
they hacked access into.
Flag officer's email.
I always hated that stuff, you know,
because you get to see what contracts matter,
what weapon systems matter.
I'd never read those emails, you know, I didn't want to know, you know,
but when you see a communication of a high-level official
gets stolen, I've always felt, oh, man,
like there's unvarnished truth in that, period.
Like, no matter what we're trying to posture publicly,
you really, you've got the backdoor story
in China as to what we're thinking
and how we're going to arbitrate.
And I think I just,
that was the first,
the first time I ever saw,
it was in the mid-90s that China got
flag officers email,
just instinctively went,
man, that's bad.
First off, the good news,
most flag officers
didn't really use email back then.
But what did you put in it?
You thought it was private, you know?
And I just felt, I didn't like that.
Like a Sipternet email?
No, no, I've never seen a Sipronet breach.
You know, not that it's got to be physical separation.
I've heard rumors of it.
I've never been involved in one, and I don't know if, I don't, I personally don't think it's happened, but
probably a physical security issue if there's a Sipternet breach, someone got to a Sipernet terminal,
you know.
They get blueprints to weapons, bombs.
Yeah, the problem we've got as a nation is we're so damn open, you know, in academia, everything
that becomes classified somewhere was unclassified first, for the most part, you know, how it's
used and who's using it and where they're using it, usually is classified, but we have this, you know,
you look at University Illinois or Bonner-Champaign,
LSU, Penn State, all these great American universe,
Harvard, MIT, I can name them all.
Almost all them, Berkeley, they're all doing work with the government.
And you want to, like, the easiest thing
to compromise on offense is a university, period.
So go do it.
And go look at the programs and you're probably,
I mean, I'm giving the playbook,
but the Chinese already knew the playbook.
The students, I mean, we have a bunch of Chinese foreign nationals at the schools.
That's a challenge.
And, you know, somebody once came to me, Sean, and they said, hey, man, if you were working
at a company in another country, and Uncle Sam came to you and said, can you just take this
for us?
Would you do it?
I'm like, yeah.
You know, I'll do that for Uncle Sam.
I'll do that for you.
So now I'm unemployable to any foreign company.
That's what's happening here, you know, with all the, you know, we went with this global economy,
and we said, come work here and we'll take your best and bright.
The problem is where are their families and who are they truly loyal to?
So I actually felt, man, you know, the compromises occurred because you can do it from 10,000 miles
away and there was no risk to it.
But I actually felt, and I remember for years working with the defense industrial base,
we always thought to ourselves, if we lock down the cyber door, are we just going to have
an HR problem?
Are we going to be hiring the scientists that steals everything?
And most people would rather have a cyber problem than personnel working at their company stealing their stuff.
You know, so it's a tough, man, when you're heavily targeted like the dib is, defense industrial bases, it's a complex place to secure.
Wow.
Looks like at that time frame, IP theft by China was an estimated 300 billion and 1.2 million American jobs per year.
Impacted?
Yeah.
Yeah, I mean, there's no question like they won in solar power, right?
Do you think they hack the solar power companies?
Probably every damn one of them.
You know, everybody makes fun of, you know, the space shuttles all look the same.
Well, how did I get it, you know?
The least risky way to spy, cyber, period.
And probably the most comprehensive.
Because when you spy, you want comms, you want the communication, right?
Did they ever, China ever confirm that they did it?
No, when we went live, certain quotes you remember your whole life.
I'll probably get this one wrong.
But when we went live, yeah, we went live because we did that report in conjunction with the New York Times, by the way,
deciding that they were going to go live because they had their reporters compromised.
They had a reporter named Mike Barbosa over in China in the United.
Chinese were still in his email. And, you know, when we wrote that report, by the way, I remember
it was like a movie in a way. I remember getting on the phone with David Sanger, who wrote the article
from New York Times. But all of our press were compromised. They were going after Washington Post. They
were going after New York Times. They were going at the USA Today. They were going after all the press
because China wants to see, what are you going to publish about us before you publish it? I don't know
why, but they do that, especially if you have a bureau in China. And I just remember getting on a call
And on the other side, it's like, hey, it's Barbosa.
You know?
And the New York Times wanted to verify PLA unit 61398.
So we gave him an address.
And I think Barbosa went and checked it out and went, oh, man, it's like a whole bunch of
noodle shops.
And then there's this NSA looking thing with antenna everywhere right in the middle of them all
and a bunch of dudes in uniform going in every day.
We had it right because we used Google Earth, Sean.
We saw the building get built.
Isn't that insane?
We just watched it grow, you know, on Google.
And we went, okay, that's where.
they're doing it from. Are you just shitting me? We we figured it out in a couple ways.
Everyone's, and you got to look every day to find it because a lot of evidence will pop up and
disappear. We were finding resumes by Chinese students that were transferring schools or
going for jobs. We had Mandarin speaking folks who would translate these resumes. This was before
you could just use Google Translator and just read everything in English. So we had to hire our own
translators and we were translating resumes and we kept hearing about this PLA unit 61398 and what people did there.
When you read the bullets, you know, you transferred from Chinese character set to English,
it was basically like, you know, we hack for a living.
We get our orders and we hacked those companies.
That was it.
And we knew where they were.
But the New York Times went public at the same time frame about their compromise.
And they were the first ones, really one of the first victims.
Google was another first victim.
Google's so big when they were hacked by China, they just told everybody.
And they actually withdrew doing business in China.
like, yeah, this isn't worth it.
You know, because China does have to learn about the Chinese dissidents here and what they're doing.
So, bottom mind, you know, whenever there's ideological conflict, you're going to see cyber activity.
And we have plenty of that right now.
Wow.
Wow.
You know, speaking at China, be familiar with Polymarket?
Oh, yeah, yeah.
Speaking of China, people in Polymarket say there is a 93% percent, you know,
chance that China will not invade Taiwan by the end of 2026. Only 7% say that they will. What do you think?
And we're talking about this for a while. Yeah, it's deadlines 2027. Yeah, I think that's what people say.
You know, to me, and this is Kevin Mandy anecdotal, you know, dad from California thinking about it,
unofficial, I don't think they need to evade it. I think just population growth alone. You never know the will of a nation.
Like, Ukraine surprised me how hard they're fighting back.
You know, I didn't go over to Ukraine.
I didn't know the Ukrainian people.
I didn't know their will to be independent.
I didn't know if they had the leadership for it.
And I think, like many Americans, when the invasion happened in, what, February of 22,
I remember thinking, well, that's going to take three days and look where we're at, right?
I mean, this is unbelievable.
But then I apply that.
I don't know what Taiwan would do either, but it's different.
It just feels like we never acknowledged it as a standalone nation.
You know, I think no one really recognizes.
There's only 12 countries in the world that recognize it as its own nation.
And so think about it culturally how tight it is, you know, and then I think population-wise,
I've always discussed Sean.
Like, look at Singapore.
Like, I think it's 30 to 40 percent Chinese foreign nationals.
Like, how long does it survive?
You just look at population growth.
At what point is there just a majority?
So I think China could just win.
Everybody says the population in China is going down.
I'd be fascinated if we look globally
is the population of the Chinese culture going down.
I doubt it.
So I just think that that's a tough one.
I don't know.
I'm the wrong guy to ask.
I just go on gut alone.
They might be winning without having the fight.
See, that's what I went over there.
They have this thing, I mean, cognitive warfare.
It seems to be the thing that the Taiwanese are most concerned about.
Yeah.
I mean, basically, in a nutshell, it's a sci-op to.
to convince the Taiwanese people that they still belong to China.
Well, and then I just don't know throughout history,
have they been offensive and warlike?
You know what I mean?
I just, I think they probably win through,
if they, everybody says that their culture
has a longer-term view of things.
Okay, well, the longer-term view is over time
will just win Taiwan over ideologically.
That's kind of what I'm getting at.
Yeah, there's a reason why it's 93%.
They don't need to go to, I think they're winning.
So it's like, if you're going,
this up and to the right, why go to war? It's heading in the direction you want. That's just my gut,
though. And I haven't read enough on it, and I should. But I even looked at, you know,
I was very interested in our war or whatever we're calling it with Iran. You know, what would
China's response be? And it just doesn't seem very aggressive. It's almost like, hey, whatever's
happened and it's happened. They feel like they're not even in the scene. They've exited stage left for now.
And I just feel like a country that's prepping for war
might want to exert a little more muscle than that.
Hmm.
You think they're standing off?
I mean, why do you think there's, I think they're standing up
because I think they're hoping that the petro dollar
turns into the Petro-U-N.
Yeah, maybe.
Oh, good point.
Well, and I do know.
Longer this goes on, the more pissed up,
everybody's gonna get at us.
Yeah.
I think the dialogue in DC is there's never been a ramp up
of Navy in history as much as the Chinese
have ramped up their Navy.
If you look at Taiwan, well, that's a naval.
battle, that's a naval blockade, that's Navy, Navy, Navy.
So there's evidence that shows it, but if you want to be a global power, I still feel
like we're one of the only nations that can project force remotely.
You know, I've heard we may not, depend on who you listen to, we may not be able to project
in two fronts anymore.
And I've always felt we were always built to at least do two wars at once.
That may not be the case.
But China's building for something, right?
And you always think back to when we sent our, whatever, beautiful
white ships around the world with Teddy Roosevelt or whenever you carry a big stick.
And I wonder when China's going to do that if they're already doing it.
I think they're probably already doing it in parts of the world.
Yeah.
But we'll see if they do it globally someday.
Yeah.
You brought up Snowden earlier.
Yeah.
What do you think about that leak?
You know, I'm never a leaker.
You know, I get it that the dialogue needed to happen.
But I mean, I'm the wrong guy to ask.
I'm pro.
It is a weird sense that I've had my whole life.
I got to probably, and maybe as I get older, I'm less trustworthy.
But I believed in the institution of the NSA and still do.
And I've known the leaders there.
Nobody is trying to do the wrong thing.
I really don't believe it.
And, you know, there's tons of inspection there.
I would almost argue we inspect so much, we almost hamstring ourselves, you know.
And so I'm in the, I don't know if I'm probably in a minority camp.
I trust the NSA to do the right thing.
I really do.
And I, but again, I've walked the halls there and I believe in the people in the mission.
And I think you should never, there's, there had, you would like to think there was another path he could have taken if that was his fight.
And I, and I still believed in, you know, they looked at the violations done.
I can't remember the exact code that came out of the, you know, I think they called it the Patriot Law for one, for a while.
But, you know, there was a huge investigation and what were the procedures and who are the people.
And they even had people from, I mean, they had left liberals, they had right wing, they had everybody.
And it really came back at nothing burger from the extent, at least from my understanding of it as to what we were really doing.
So I don't know.
To me, a spy is a spy.
I still believe that you can whistleblow appropriately.
But I could be wrong, Sean.
I would be fast at your opinion.
If I were sitting in that building, I'd never have done it.
But, you know, maybe I'm a weaker person.
and maybe it takes, the dialogue is good to have all the time, right?
The checks and balances, that's why we had the press and freedom of the press.
You know, to keep the government in check, you know, I still think marketing companies
probably know way more about us than the government ever could.
Like you're probably right.
Yeah, but marketing companies won't break down your door and take your assets.
You know what I mean?
So we don't worry about them as much, right?
So I do believe in checks and balances and the government's got to get called out,
whether appropriately or inappropriately, it's always a good check.
Yeah, no matter what.
I get worried.
I see both sides, too.
I mean, I get worried about it.
Obviously, I mean, we're just talking about glacier.
Yeah.
But obviously, I get really worried about it.
But I can see both angles.
I do.
I get concerned about government overreach.
Yeah.
I do.
If unchecked over time, doesn't it automatically go there?
I mean, that's just the theory I've always had,
is that it is a good thing to have healthy debate,
no matter what spawned it.
Right? Whether it was, so even my opinion on Snowden, whether positive or negative, it's a great
conversation to have all the time, you know? So that was kind of my take at the time. I just wish
what I don't know and what probably nobody in the general public knows is what were the downside
problems that that created. I'm certain there were certain lives that became real complicated
to do those leaks.
Yeah. Yeah. Yeah.
Well, Kevin, let's take a quick break.
When we come back, we'll get into solar winds.
This episode is sponsored by BetterHelp.
You've heard we talk about BetterHelp for a long time.
And one of the things that stands out is how many people have shared real, positive experiences with it.
Therapy is personal.
So hearing directly from the people who have used the service matters.
BetterHelp makes those reviews easy to find at BetterHelp.com slash
reviews, and they update them every day. BetterHelp has an average live therapy session rating
of 4.9 out of 5. That's based on over 1.7 million client session reviews. That kind of feedback
from people who've actually used the service speaks for itself. And getting started is simple.
You answer a few questions. BetterHelp matches you with a therapist based on your needs,
and if that's not the right fit, you can switch therapists at any time. More than 6 million people have
use BetterHelp globally. And their therapists have at least three years and 1,000 hours of hands-on
experience. See the reviews, see what stands out, and see if BetterHelp is right for you.
Visit BetterHelp.com slash SRS. That's BetterHELP.com slash SRS.
Looking for another way to support the Sean Ryan Show? Head to Sean Ryan Show.com
and check out the latest drops from Vigilance Elite. We just released new games.
gear, including this beautiful moisture wicking VE performance hat and SRS campfire mugs, and
you guessed it, vigilance leak gummy bears.
Oh shit!
Every purchase directly supports the show and helps us continue bringing you independent
conversations without compromise.
Visit Sean Ryan Show.com and grab yours today.
All right, Kevin, we're back from the break.
you were just telling me a story about when you expose a 6-1-3-9-8.
It's funny.
You know, even when I went live with that, I didn't know the five digits right away.
You know, I remember being on like 60 minutes.
I'm like six, two, four, three, you know what I mean?
It's like you worry about those damn things.
And as I get older, I forget it.
But yeah, when we did that story, David Sanger kind of and Nicole Pearl Roth from New York Times,
it was kind of coincided with the New York Times.
by a Chinese government. That's a little weird. And they decided to go live with it. And we decided,
well, let's go with who did it and what they've been doing. That's the PLA unit 61398 thing.
And it was Sanger's idea and Nicole's idea. Let's just put this on the front page. And I remember
like the day before, I don't know where, every once in why I think I'm an expert when I don't
know shit. You know what I mean? So I'm literally on the phone with Sanger and I'm thinking I know his job
better than him. He's like, this is going to be a big deal. I'm like, no, it's not.
Dave, you're wrong. Nobody gives a damn about hacking. And I've been doing this for
for 20 years, no one's ever cared, and they still don't.
I go into work the next morning, and I get in,
I still remember my lights weren't even on in my office yet.
And I go in, it's out, you know, in Alexandria, Virginia,
it's about 7.20 in the morning.
And it's live.
We're on, you know, it was like February 13th and 2013.
We're the front page.
And I don't even remember what the headlines said.
And what's weird, too, you're an entrepreneur, you know,
it's like, no matter how good yesterday was,
the only thing that matters is tomorrow.
I already been done.
We're fine, we're on the front page who gives a shit,
we're off, let's get our workday done.
And all of a sudden my cell phone rings,
and I answer it, and it's my now ex-wife,
and her exact words, exact words were,
what the fuck did you do?
And I went, and immediately, because I'm a guy,
I'm like, what left field thing am I in trouble for now?
Like, I didn't know it why she was saying it.
And I'm like, what are you talking about?
You know, I probably got defense, right?
Like, what the hell are you talking about?
I didn't do anything.
You know, she's like, turn on your TV.
And I have a TV right in my office.
I turn it on.
And I'm not even kidding.
The very first scene I saw is a, the building, I recognize the building in the background.
It's P.L.A. Unis, 611, 398's headquarters.
And there's like a dude in a taxi going, drive away, drive away.
And I look at the bottom, it's like, you know, or Mandy Report and all that.
I'm like, oh, crap, what did I do?
Like, I didn't even know.
We didn't think about, people were like, there's a marketing drill.
Really?
No, it wasn't.
was a bunch of former U.S. soldiers saying, screw this, it's Chinese New Year. Let's get the report out. Let's burn their infrastructure, burn their operation, give our government a tool so the government doesn't have to point the finger at China. We'll do it for them. And let's just see what happens. And we dialed that report back. We actually had the names of a few of the soldiers. Like, we knew who they were. And we pulled, I remember I edited those things out. I'm like, no, we're not going to put that in there. Because I didn't know what happened to these guys were getting caught.
Anyway, I ended up that day doing about 13 interviews or something like that.
And by the way, with no staff.
Like, nobody's handing me power bars.
Nobody's coordinating.
I think, you know, I just ran around trying to get out the truth of it.
Because what's weird is if I didn't go out and do those, Sean, those interviews,
someone would make crap up or say something.
And we were in the ring.
Like, you know, we were in the ring.
We knew exactly what China was doing.
So I just felt, let's be the voice of reason on this one and get it out there.
Nobody had even heard of 618.
61398 before.
I don't know.
To be honest, I had neither.
My team wrote it.
We picked, here's what's weird.
We had like three groups who could have picked in China.
There's like a little naval group we caught APT4.
We chose APT1 for a lot of different criteria.
But one was they kind of, they weren't the Mike Tyson in the rent, you know, in his prime.
They were more, you know, Buster Douglas.
We knew we could take the upper cut coming back from them.
And so we literally picked.
them. And it was a tool to give, you know, Congressman Rogers, you know, something, the government.
Like, U.S. government, we know. We probably know you know, but we'll let you guys have this work
of art from us. So we did it. Have you heard of, you know, we were just talking about Snowden.
Yeah, yeah. And have you heard of this FISA thing that's going on today?
FISA court stuff? No, what's happening? This is a tweet from Thomas Massey. The House passed FISA
Section 702 renewal
yesterday. I voted no. This was a
uniparty vote in favor of unchecked
government surveillance without
adequate warrants or accountability.
The vote tally is
Republicans have voted yes,
192, 42
Democrats voted yes, nay,
Republicans, 22, Democrats
169. Total yes,
235, no,
191.
Do you know what this means for
You know, what I would tell the viewer just, like, in my view at a time when I was in the U.S. government and in law enforcement, I never, ever saw witnessed or knew about unchecked surveillance, period. And I feel that's healthy skepticism for folks to have. I personally never saw it and never executed it. In fact, it was hard for me to get the ability to do it. You really did have to go talk to judges. You really had process. So FISA's foreign intelligence.
kind of taps, right? And to me, U.S. law protects U.S. citizens, and I think a lot of times you forget
that, you know, and so, you know, bottom line, it's good for the view to know that. I never,
ever witnessed or saw what I would consider unchecked governments. I dug into this a little
bit this morning, and I understand why everybody's making a big deal of it, but the way I read it
and deciphered it was that in order for the government to actually,
surveil you under this, you have to be in contact and talking with a foreign state actor.
And there's still a FISA court.
That they're watching.
Yeah.
There's still.
Not just anybody from any foreigner, a foreign state actor that is that's already under investigation.
And there's a FISA court.
And that's all classified stuff.
And you go and present to a special FISA judge and you get your ability to go do it.
I had to get approval for consent monitoring.
Like literally, people would like,
You can monitor.
I'd be like, no, I actually can't.
I got to ask my JAG if I can go do that.
So people could have asked us to come in to monitor and we wouldn't have been allowed to do it.
And in cyber at the time, some people did, you know.
Like if the government knows more about what the bad guys are doing on offense than anybody
else, why not let the government help protect the defense industrial base or why not let them
protect the banks or protect a hospital?
And we can't do that as a nation because of the separation between the two.
So it just, I think I would rest assured of fire in this country that I've never seen,
and I don't know of, and I'm in D.C. all the time, you know, no, there's nobody, it's not unchecked.
You know, it's not, not for my.
That's good to hear.
Yes, yeah, that's great to hear.
I guess, you know, everybody can innocently make mistakes.
Relieving to hear.
Yeah.
I've never had to brief a FISA court, but I've had to brief.
you know, a judge, it's not easy to monitor anybody in this country.
I haven't found it to be easy.
Maybe it was cyber stuff.
Maybe it was me.
I'm not compelling, Sean.
I get in front and be like, we need to do this.
And they'd be like, eh.
But, you know, anyway, I'm not worried about it.
I believe in my gut is if we restrict our ability to spy, we're hurting Europe.
We're hurting ourselves.
We're hurting a lot of people.
And so I think I would trust our organizations to do their job.
All right. Let's move into solar ones. Thank you. I'll just jump right in then for you.
Imagine, Sean, you're sitting at work one day. I had about 4,000 employees. I was the CEO of a public company called Fire Eye. And I looked down on my schedule. I'd just done an all-hands with 4,000 employees where I told them, and it was fall of 2020. So it's during COVID. And I'm doing weekly calls during COVID because
You want to keep the wheels on the bus.
And we have 25-year-olds in Alexandria, Virginia,
living by themselves, and their parents won't even see them
because they're so afraid of the damn, you know, of COVID.
So I'm doing weekly all-hands, guest speakers.
I felt like I was doing the Kevin Mandia show.
Every Wednesday, I'd do it twice,
just to keep people in the ring together
and entertained almost
because I had a lot of folks struggling during COVID
to stay motivated and stay human.
And late COVID, February, so it's November of 2020, I do my all hands where Blackstone did a
$400 million investment in my company so I could split it.
You know, so I could split my company and sell off the more mature portion of my portfolio
and carve Mandian out to be a standalone company.
Blackstone gave me the air cover to do it.
So I do the announcement to the whole company.
I hang up the all hands, you know, meaning Zoom call.
And I looked out on my calendar and it says that my chief information security officer wants
to talk to me at 1 o'clock.
And it's a Friday.
It's 1257.
And I'm not kidding.
I'm about to go downstairs and grab a beer.
You know, I'm like, man, this has been a long week.
I just did a $400 million raise.
I just wrote my presentation.
This pre-AI, I'd write all my own speeches, you know, no help.
And I don't know.
Half the company is going to be like, wait, am I going to be in the part of the company he sells or
in part of the company he keeps?
and we were still kind of figuring out
which students go right and left,
and it was complex,
and it was something that had to be done
in a public market.
I see this invite,
I get on the phone at one,
and man, I should have known
it was going to be bad news,
you know what I mean?
Chief Information Security Officer
really wants to talk to the CEO.
I get on the call,
and one of the first,
and I'm getting a briefing
from one of our IT guys
who ended up moving into the Security Operations Center,
and he's telling me that somebody
is logged into our network,
network. And the very next thing they did after they logged in is they dumped all our user
accounts and pass phrases from a Microsoft tool called Active Directory. So in other words,
that's like somebody broke into the hotel. And the first thing they do when they broke into
the Marriott is they didn't grab the room key that just opened up room 101. They grabbed the
room key that opens up every room. They had the master key. You don't get the master key to first
time you break into the hotel.
You know what I mean?
So luckily, I'm a CEO that's responded
to breaches this whole career because when I get that news,
I literally go, call board meeting.
This is the one, this is the one I'm worried about.
And even my sister was like, call, board me,
what the hell are you doing?
And I'm like, I think this is Russia.
Like, they're accessing our network the way we do.
That's perfect offense.
Access the network that you're targeting,
the same way the employees access it, using their accounts.
And that's what whoever this was did.
So 10 minutes into my briefing, my heart sang.
I'm like, well, I'm not getting that beer today.
And honestly, every day, Sean, I remember going,
I got the board together a couple hours later.
And I think I gave them like the Sully speech
landing a plane on the Hudson.
I just said, brace for impact, man.
This is going to go from bad to worse.
We're a cybersecurity company, someone's in our network.
They got all the keys.
They've got all our accounts.
Did you know, did you think you were the only company?
No.
At least,
Yeah.
Which is October 2019, Russian SVR hackers inject malicious code into the Solar Winds Orion Update, used by 300,000 customers.
Yeah.
March 2020, the back door goes live.
U.S. Treasury, state, homeland security, and the Pentagon compromised for over a year before anyone noticed.
December 8th, 2020, Manda discovers Mandean itself has been hacked.
Yep.
Red Team Tool stolen goes.
public with your company, blog the same day against most legal and PR advice.
Yeah, because, well, we found out beforehand.
We went live as soon as we could, but here's what held up us going live even faster
is so Friday, I get the briefing Friday afternoon.
Sunday, I just already scheduled a board meeting for Sunday afternoon, and luckily I did
the job of computer forensics.
How did people break in?
It was always what happened, what to do about it.
That was my job for every day of my career.
You know, what happened, what to do about it,
in every computer investigation.
And then sometimes who did it.
And on this one, I just felt right away, it was the SVR.
Just my gut went, okay, this is a problem.
On that Sunday, three days or two days after I knew we were probably compromised,
I would get an update every day and it just got worse every day.
I'm like, man, I hope they don't get to our secret server that has all our passphrases.
Like an hour later, a guy would call, hey, we just did forensics on the secret server.
They've got it, you know?
I'd be like, oh, I hope they don't grab some of our email.
Day one, I called our best email investigator and said,
hey, I'm pulling you off the job and you got to go look at our email that's stored at Microsoft.
He called me back exactly 47 minutes later with, we got a problem.
So if we didn't know to look, Sean, we'd never looked, but we knew to look, so we did.
And we started noticing, why is our backup account backing up our email all the time?
It's not backing up our email.
They were using our backup account to log in and steal our emails.
You know, and so I just went, oh, this is going to get ugly.
Sunday night I call frontline responder for a pep talk.
We're working around the clock.
And I can tell you day one, even as an incident response company,
I didn't think my team was taking it serious enough.
I'm like, guys, this is the one.
This is the one we're worried about.
By day three, everything was changing.
The team went, yeah, it's the one we got to worry about.
Oh, shit.
You know?
And so I call a frontline guy Sunday night.
He's working around the clock.
And I just happened to be talking to him.
And he goes, yeah, they stole our red team tools.
These are tools that we use to be surreptitious and break into our customers, you know, kind of simulate the offense, simulate bad guys.
And the minute we lost them, I was like, well, can we stop them?
Can we stop our own red team tools?
And the answer was we couldn't.
We made software to stop bad guys.
The unfortunate reality is we had created all this offensive stuff that our defensive platform couldn't even stop.
And I'm like, I can't go live with that.
You know, we got to fix this.
to the credit of Microsoft, to the credit of CrowdStrike,
to the credit of Palo Alto Networks,
so we didn't have anywhere for me to go in the government, really.
I went to the NSA because it's a damn lonely world
when they're compromised.
Day one, by the way, I called the NSA,
and I told them, hey, listen, we're burned, don't email us.
Don't talk to my guys, don't email my guys.
I have no idea how bad this is,
but it's going to go from bad to worse, and it did.
And to their credit, they were a great ally.
Second, we immediately started reversing our own Red Team Tools
to figure out how to detect them.
And then we called, I called the CEOs of these companies.
Like, hey, Necash, could you please have Palo Alto Networks help us out?
Before we ever went public, Sean, we were working inside the community.
And to the credit, these are companies that competed with us.
They helped me.
Thank God.
Wow.
You know, I was like, hey, George at Krauset, can you please?
We were giving them the rule set to stop our cyber weapons, just in case the Russians used them.
They've never used them that we're aware of.
But they sure saw learned a lot from.
it. And boy, was I scared. Like the whole time was like, I'm going to be the reason the
internet goes down. I'm going to be the reason, you know, all hell breaks loose. So I was in a
race to go public no matter what. Catholic guilt call it the right thing to do. I remember I got
so much unsolicited advice during this intrusion from employees in the board that I remember
two things distinctly. One, every time I was advising a CEO during their own intrusion, I would
tell them this is your day job now. You've got to get through the crisis. So I remember my own voice
in my head of what I told other people. Now I had to live by my own advice. It was a little weird that
almost was like, you know, bipolar. I was telling myself how to handle my own incident, period,
you know, coaching myself with the same words I told other people. But we were in a race to go live
right away. And I was so worried the Russians would use what they took to their credit. And thankfully,
they didn't.
And I think I didn't think we were alone
because the SvR always says multiple victims.
It's not to have one company at once.
But I could feel when I went out to the community,
it starts NSA to me.
I go right to them, hey, man, we got something new,
a novel, we don't know what the hell we're dealing with.
You want to defend the military first.
We do have, and then they go to Five Eyes with,
we got something new and novel,
and it kind of percolates through.
And it does no good to go public right away
because all you're going to do scared a hell out of everybody,
and there's nothing they can do about it.
So we did get Microsoft's help.
Thank God they showed up in a big way.
Turns out they were compromised by the same people.
CrowdStrake showed up in big way.
Palo Alto Networks, Fortinette.
All the cybersecurity companies kind of rallied.
But it was all informal.
And even today, Sean, if we knew a cyber attack was coming,
there's no way for the nation to go shields up with coordination.
The way you do it is you call the vendors personally and go,
hey, we got something new and novel and we need help.
I had to protect America from the very tools.
We had millions, you know.
So we did it.
And I'll never forget, to my board's credit, too,
I went into a board meeting.
This was December 8th when I went public.
There was no legal obligation to go public about the breach.
We didn't violate anything.
We didn't lose any covered data by statute.
And the lawyer's a great guy.
I'm an incredible lawyer,
and he gave the whole board a presentation on,
you have no legal obligation to go public.
And I had like five pages of notes, and I was ready to fight my board with.
I'm going public anyway, God damn it.
And here's why.
They rolled over in 10 seconds.
There's the easiest board meeting I ever had was conveying the news to the public.
And by the way, here's what happens when you're hacked and you know it and you tell the world.
Market cap goes down by 20% for us.
We get sued right away by shareholders, and you're considered negligent.
And I even had a phone call.
And then you're calling all your customers, and I've lived this with a lot of folks.
I called one money center bank, and the guy on the other end who I've known for 20 years was like,
man, do you, how did you let this happen? How did you let your company get compromised?
And I remember saying internally, don't lose your shit. And I just went, let this happen,
and I lost my shit. I didn't let it happen. Nobody lets it happen. We have a modern nation
with an incredibly smart people coming after America. We're going to lose. We can't throw a perfect game
every day. I was so pissed off because let it happen. Every day we woke up, I had spent every Friday,
Sean, downside to my jobs is every Friday I'd get a threatening email from a ransomware actor,
and they were real people. And they'd say, we're going to hack you this weekend. And the reason why is
because we were preventing payouts. We'd respond to an intrusion, bottled it up so fast that companies
didn't feel they needed to pay the ransom. So they would threaten us. And they did break into us.
and we'd have to play this whack-a-mole game with them
before they could do anything.
We made our own security software.
We could program it any way we wanted,
and we can't even stop the criminal element.
That's how asymmetric this fight is.
So I remember every weekend,
any time my lawyer called,
my heart rate would go to 1.30, no matter what I mean?
Yeah, you had the phone ring certain times.
Just like, oh, shit.
I had it every weekend.
And then so during Solar Winds,
I think part of that side of me came out.
I didn't let this happen.
Nobody lets this happen.
We're getting sucker punched here.
We're giving Wayne Gretzky unlimited shots on goal.
I mean, the puck's going to get in the net sooner or later, for God's sakes, you know?
And that's what we're doing.
So I remember just you've had those moments where you're like, don't lose your shit, don't lose your shit, and then you lose it anyway.
I had that one.
Just about every other day.
You got it.
That was one of it was the, you know, that don't do it, don't do it.
And then I didn't let this happen.
But solo wins for me was a you learn under crisis whether you gain weight or lose weight, I lose weight.
And it's weird because it's not like you're bleeding out in Afghanistan.
That's what I kept telling the team.
This is a cyber intrusion.
We're still healthy, you know.
But what I've learned is when your credibility gets attacked or your competence gets attacked, it is.
I personally don't respond well to it.
You know, like every time I got a subpoena as a public company CEO, I didn't do anything wrong.
But you read the first paragraph.
and I just get this energy like, F this, I didn't do this.
You know, I got that during solar winds.
A lot of energy to prove we're not incompetent.
We're good people that got, you know, just lost that day to a foreign intelligence service that really kicked their ass.
What did they get from all the government agencies from Department of State, from Homeland?
I mean, what are they getting out of that?
In my experience, the Russians always had an etiquette where I've never really,
really seen them take the top person's email.
It's almost like they're like, hey, man, don't take the secretary's email.
Just take all the people that report to them.
You know what I mean?
True story.
I've always felt that.
It's always the emails, huh?
Yeah, it is because everything's there.
They took email and they took from us our Red Team Tools.
I think it was source code for some of the victims.
It was emails for some of the victims.
It was methodologies.
A lot of it was how do we detect them, find them, and what do we know about them?
You know, to their credit, they did a lot of keyword searches.
You know, so we could see what they're looking for.
That's a goldmine force.
I've never seen China do, well, that's not true.
I have seen the Chinese recently do keyword searches,
and that's a goldmine force because you know what they're interested in.
Keyword search means they hack into the machine,
and they say, find any document that has the word secret in it,
or, you know, Heggseth in it, or whatever the hell it is.
You know, they picked their words and then go.
The Russians did that on us, so I could tell you exactly what.
They were after our Red Team Tools.
I mean, they were absolutely after.
So let me, I'm just curious, let me ask you this, you know, coming from the intelligence world,
I mean, you have all signs, you have code names, you have all that kind of shit.
Yeah.
Is do, do, does the USG use pseudonyms in emails?
Have we started?
Not that I'm aware.
A tactic like that?
Yeah.
No, it's just, yeah.
So, you know, there's, here's the reality.
We're, there was a whole idea once by a company that started and they since pivoted where they were like,
we're going to make a bunch of fake stuff.
So when the Chinese steal at all,
they won't know what's real and what's fake.
Well, here's the problem.
Even companies don't know the last version of something.
We have bad enough document control
and email control on our own shit,
let alone this fake them out or head fake or code names.
And I did protective services when I was in the Air Force.
I'd all meant the secret service.
I can tell you we did do code names then
because the radios were probably not even encrypted.
There were these big bricks we wore.
And I remember the very first thing that ever happened,
And I don't know if it was for show, just to scare the 27-year-old Air Force guy, but it was like, Raven 1 to Raven 3.
And the response was, I'm Raven 1, you dip shit.
No, I'm Raven 1.
And we argued about who was Raven 1 or something.
You know what I mean?
So, you know, you use code dames.
You got to change them all the time.
And I don't think it's going to work.
So I don't know of any real obfuscation you encrypt and you try to keep your communications out of plain view from the Chinese.
So, but Solar Winds was something that, it was a supply chain hatch on where SolarWinds was a
company that we all used for kind of controlling our infrastructure.
And I feel bad for them in a way, you know, I mean, imagine this.
I had to call them.
We found an implant in their published code.
That's no different in like Microsoft getting hacked and you get the next update of Microsoft
and it's a backdoor for the SVR to steal all your email.
We, it's, or you're on your phone and you download an app and like, well, thank God I updated
my app and the update itself signed by SolarWinds had a backdoor in it that the Russians now had
a menu of who do we want to hack today?
Well, we have a choice of at the time 18,042 companies had downloaded the new version
with the back door.
So they had a menu of 18,042 companies.
And to the Russian SVR's credit, they didn't hit everybody.
They could have literally shut us all down, just delete everything.
You know, if it was a destructive attack, well, there's a whole lot of data deleted right
down and that's that. What they did was very precision-based, real espionage. They went in and took
what they wanted. You described this as a special operations cyber unit? Absolutely. Yeah, I remember
I went to the Senate Intelligence Committee. I said this was a sniper shot, not a spray and prey.
They went right at the 50-something. I'm aware of about 50 or so companies or U.S. government
agencies they went after.
February 2021, you testified before the Senate Intelligence Committee was the most credible,
you were the most credible voice in the room.
Who said that?
Push for mandatory breach disclosure laws that still don't fully exist.
They still don't fully exist?
Yeah, there's no national level breach disclosure law that I'm aware of.
That is useful or helpful in any way, shape, or form.
The problem we had is the privacy laws, the privacy zealots got there first and said,
if you're hacked and you know it and you lose like your personal data, Sean,
then we got to tell, you know, 48 state governments or whatever it is.
Now it's probably all 50.
And so there was things to protect American citizens when you lost their email or their
data birth or the Social Security number or their bank account number or private bank account
number.
It's called Covered Data.
And that's great.
But what covers the Chinese going in and just,
stealing all your IP. Nothing. There's no disclosure law required. And the problem with that
is no company gets better from it. Like if company A is hacked today and the Chinese use all new
and novel techniques to break in, no one's learning from it. You know, so if they can go to one
place and say, listen, we're broken into, even if, I hate to say it, I was even a proponent of,
if it's defense industrial-based or criminal infrastructure, hell, let the best in government
show up and help. Because then we can go shields up,
Learn the tools, tactics, and procedures that were successful at Company A, and they should be the only victim to that breach, period.
And then you just kind of create a better imaginal line.
You have to have a learning system.
As a nation, we haven't built a learning system where we learn from everyone's compromise and we all get bolstered from, you know, all the breaches responded to.
Like, I could just pick any of them.
Hell, it's every single brand you can name.
But if you get compromised today, wouldn't you feel good about, well, at least nobody else has to go through this?
You know what I mean?
So I think if we get compromised, I would immediately say, here's the TTPs used against us.
And it better be a new, a novel attack.
I don't want anything that preexist to work against us.
And we got to get it out there to make sure we're the only victim.
We've got to do that.
It's no different in neighborhood watch.
You see an asshole robin a house.
You better tell everybody in the neighborhood, you know,
they drive this car and they're doing this. We need that as a nation and we could do better there.
We're in a neighborhood where people are getting robbed and no one's telling you they're driving
a white van and there's their plate numbers and three dudes and the van. We need it. Are we working
on this? Yes, the challenge is that every time you go public, no matter what, there's never really
a safe harbor for you. So unfortunately, and I can never guess when you're hacked and you know it
and you tell the government, I've never been sure
what the government's response would be,
and I can never tell the public's response.
Example would be, like, when Target was breached,
they lost credit card numbers,
and they over-communicated, and they had great people, great talent,
but people lost their job over that breach.
It happened in really 2000, the end of 2013, beginning of 2014.
Almost the exact same breach happens at Home Depot,
and nothing happened.
Public wasn't in an upper era or anything.
But there's something about this target breach,
that it just got a lot of attention.
It was during Christmas time, its holidays.
It was the front damn page every day.
And then Home Depot, same thing happens.
Someone hacks, steals credit data and does stuff.
And Home Depot will say, well, we handled it better.
There wasn't that big a difference in the handling of it.
It's just a public respond of different.
You know, and maybe there's a few minor tweaks here and there
between those responses, but I never know.
And so a lot of times companies get hacked, and they do disclose,
and then they still have to show up and testify in front of the government.
And you'll have a senator from Oregon and say, well, how come you don't have firewalls?
And you'd be like, dude, firewalls don't do a damn thing.
Like, are you kidding?
That's not even a padlock in cyberspace.
You know, it's, you just get held to account no matter what.
Gotcha.
Yeah.
Damn, damn.
Let's talk about the colonial pipeline and critical emphasis.
Sure. May 2021, Darkside Ransomware hits Colonial Pipeline.
45% of East Coast fuel supply.
Mandian called in to respond six days of shutdown, $4.4 million ransom.
Gas lines across the Southeast shut down.
Yep.
I can tell you I found out.
And with a lot of these, you never know how much is still under litigation or not.
But the upside for me is you always get to see the leadership and you get to learn from them.
So for me, Sean, kind of like you doing the show, I get to show up and talk to the CEO,
and I just feel like Colonial had great leadership, you know, just like unflappable, calm,
yep, here's what we got to do.
But whenever there's a cyber attack, like when somebody ransoms you, they break in and they encrypt your hard drive,
it's not like you know what's going on.
Machines start to just go dark.
They just shut down.
And some of them shut down after 30 minutes.
some three minutes, some 50 minutes.
And if you're, imagine being in a control room
and all of a sudden, hey, my machine doesn't work.
Hey, my machine's not working.
Hey, I'm going down.
You have no idea what the hell is going on.
And you don't know if there's a physical threat.
You don't know if something cut an electric wire.
Like, non-cyber people have different responses.
And I feel like whether it's Sony pictures
had to deal with something like this, so many companies have.
You know, different defense firms had to deal with it.
And then Colonialial,
pipeline. The way that one came to me is, I think we were responding on a Friday and somehow,
some way, my young frontline responders didn't see this as national security issues, so I never
got the update. My phone rings from somebody who works in the government, and literally they open
up. It's eight in the morning. I'm just waking up to go to the gym, which means that's a late
morning. And I get a call from someone I know in the government. They're like, hey, are you responding
to colonial pipeline? And I don't want to act like I don't know. So I have to say, well, let me check.
you know, I'll get back to you.
And actually, it was weirder than that.
I think he called and said,
is it true the Iranians hack the pipeline
or something like that?
And I'm like, what are you talking about?
And then I was like, let me go check.
I call my front, and by the way,
I'm thinking colonial pipeline
they make faucets or something.
You know what I mean?
So I don't even know who the hell they are.
So I get on the phone with my guys,
sure enough, we're responding.
And then I hear what they do
and I'm lecturing my frontline nerd
because these guys are so into cybersecurity
who are like, all right, you've been breached.
What happened?
What to do about it?
They never thought that.
escalate, hey, man, 40-something percent of the U.S. fuel on the East Coast is going to be not transmitted.
I got a call from the government on that first. And that does happen for me every once in.
I've had that happen maybe at least three times in my life. I learned we're responding to a
breach because someone from the White House called me, you know? But on this one, I got a call
from somebody at an agency, and then I looked in it was definitely not Iranians right out of the
gates who knew who it was. And that's based on, again, we're cataloging forensic evidence
at every breach we respond to.
So we can go into like a colonial pipeline.
Look at the evidence.
And plus they said who they were.
It makes a lot easier.
And they wanted to get paid so you know who you're paying.
You can pull the evidence out and just match it and marry it up.
So we're pretty confident with who they were.
But on that one, it's just an example of many of them where, first, there's always a fog of war.
You have no idea what's happening.
If you're a hospital and stuff starts going down, a lot of hospitals would be like physically
secure the hospital.
Like you call security
and say,
guard all the exits
because you don't know
if there's someone
on the inside doing it.
It's a weird,
uncontrollable moment,
but I've seen
incredible leadership
and I did attend
a lot of the calls
of Colonial
where you do your daily briefs
and they were just,
they did,
they show that you plan ahead,
like do the plan
that you wrote
when you weren't under duress.
And that's exactly what they asked you.
That's the best way said.
They had already kind of said,
hey, if something like this happens,
here's what we're going to do,
And they just pulled out that playbook and did it.
And it works because it keeps everybody calm.
Because there is nothing, it is a weird thing when you're hacked and you know it.
You know, I've lived it where I'm like, man, I wonder if they're stealing my email right now.
You know, what the hell's in that?
Nobody knows what's in their email.
So Colonial Pipeline, again, though, just all of these, whether it's colonial pipeline,
hospital, cell company, every one of them, it's a full sprint the whole time, no matter what.
Like you show up and our job is always physically impactful, Sean.
Like when we show up, we have to figure out what happened and what to do about it.
We're not really sleeping.
Like you show up and you're just triaging and working around the clock.
And it's, it's, colonial was no different.
Like some of these intrusions, we did United Healthcare.
I mean, do you remember what happened to them?
I think it was last year.
Yeah.
Somebody hacked the United Healthcare and ransomed them and people couldn't get their drugs at pharmacies.
people literally work themselves into hospital visits.
I'm not making that up.
Where people literally worked around the clock
until, like, one guy didn't show up at a meeting,
they had to go find him, and he was like,
passed out on the ground, they had to hospitalize them.
You know what I mean?
So these things are absolute races.
Colonial, the upside they had is, you know,
they don't have a competitor.
You know what I mean?
You just got to get it right.
And I think what they had is the constant,
Like, it's everything, like when you, it's a political issue.
You've got to get oil and gas.
So I think they probably, you know, I'm not aware of it, but my gut is they felt an incredible
immense pressure to get back up and running.
You know, and most companies do.
Oh, bad.
Yeah.
Tough to do it.
It's way harder than people think.
4.4 million in ransom for 45% of the East Coast fuel supply seems pretty minimal.
You know, I, you never, to me, yeah, you never opine whether people should pay or not.
Obviously, here's what I will tell you.
I've never met a CEO who wanted to pay.
Like, it was never the default answer.
But you certainly see the logic in paying that one, right?
I do.
Four million?
Yeah, I'd have paid it.
I've gone through the hypothetical of what would I have paid
to keep my legal counsel's email from getting posted?
Now I'm advertising to the bad guys.
But I would pay to not read the amount of lawsuits you get
as a public company CEO if your general counsel's emails online.
It's amazing.
I mean, reporters read it.
They write articles on this stuff, you know.
It's a tough situation.
What about texts?
Do they ever go after text messaging?
Well, do some reading on a, yes, as the answer, modern nations do.
And, you know, both of all our sell companies have a, there are certain industries that you need to withstand military-grade attacks or,
modern nations attacking them or sell companies or phone companies are definitely one of them they are
fair game for espionage every day last year there was widely publicized breach in 18 team Verizon who's in
2024 and 25 and the advice from the FBI was and this is pretty telling hey you signal are you
shitting me no meaning text are in the clear and text can be found
and sell companies are fair game.
And in reality, they are so valuable to espionage most likely
that if you're on offense against us,
you're trying to place people there,
you're trying to hack them,
you're trying to do anything you can
to make sure you maintain access to the data from those companies.
Is signal legit?
I think signal is.
Like, you use it.
There's always ways around everything,
but you have to have a massive, like in transit,
signal's legit.
Like, if somebody hacked your phone,
my gut is they can get to at least half the equation and maybe be able to decrypt it.
That means it's a modern nation targeting you specifically,
but signal is infinitely better than not using it.
Same with glacier.
Like these things are massively annoying if you're on offense.
Because that means I can't just intercept your dialogue and read it,
and I can't find it stored in plain text.
I have to do a lot of work to get to that.
Ben, didn't they just, didn't they just?
just, what was I reading this?
I can't remember what it was, but they broke signal and they were able to get the messages
through notifications by breaking into the app.
Have you heard about this?
No, there's usually workarounds like that.
Like, I can tell you, usually, I wouldn't say usually, in the times where we needed to decrypt
something and we only had one key, we always were able to decrypt it over time.
And usually there's two keys, public and private key.
key to something. And so there was a time where we could decrypt at my company, remote desktop
protocol from Microsoft. And we thought we were the smartest guys on the plan. We're like, look what we
can do. And if we can do, China can do it. In reality, none of our customers cared that we could do it.
But what it allowed us to do is whenever the Chinese broke in, they would remote desktop
to all these machines. We could see exactly what they were doing because we could tap it. And even
though it was encrypted, we could decrypt it. And we thought, oh, we're awesome. Nobody really
cared. But the reality is most stuff today probably can't be decrypted easily until you have
quantum compute come out and then realize you have two problems if you're worried about this.
One, someone got your traffic or your data somehow. And two, they can decrypt it, right?
But quantum, that's the biggest issue with quantum compute and that's going to come like AI.
Everything's coming faster when we want. When the Chinese and the Russians and others have quantum,
the vast majority of things we've done in the past
that they've already intercepted, tapped, stole
that's encrypted will be decrypted.
That'll be the risk we run.
The secrets that we once kept
will no longer be secret.
How far are we from that?
Under 10 years.
Shit.
For the most, here's the good news.
The Chinese really don't have a whole lot to decrypt.
They accessed everything with a valid key,
meaning a valid user account and passphrase.
So everything was presented in plain text anyway.
I actually think the threat from quantum
is far less than people realize, because for the most part, even when the Russians were stealing
stuff, it was not encrypted. So the vast majority of the intrusion is, I'm speaking with like
5,000-plus intrusion investigations behind me, very rarely does an attacker have to overcome encryption
because they are accessing your data with your keys, your credentials. And so it's just plaintext
anyway. So I think quantum is not going to be a big issue. It is for some things, but,
We'll see what comes out then, Sean.
You'll have a lot of good shows then.
I'll bet I will.
Yeah.
It scares the shit out of it.
I mean, the way I understand.
Figure out where Hoff is buried or something.
Yeah.
I mean, it's just, you know, people describe it as your banks will be done.
All your passwords will be gone.
Every financial network will be completely...
I think AI is going to impact that more than anything
because you have AI doing trades, not humans.
So imagine a whole system of AI agent doing all the trades.
At some point, the market's going to be managed by them.
The AI agents, not humans.
You've heard me talk about Caldera Lab before.
And lately, the product I've been reaching for the most is the good.
Between being a dad, hosting the show, traveling, training,
and trying to keep up with everything else.
I don't have time for some complicated,
skincare routine. I don't want 10 steps. I don't want a cabinet full of products and I don't want
something that takes a bunch of time every morning and every night. I just want one simple product
that actually does something. That's what I like about the good. It's an antioxidant rich
facial oil serum made specifically for men's skin. The good is formulated with 27 botanicals
And it's designed to help deeply moisturize, support skin recovery, even skin tone, and visibly
reduce the appearance of lines and wrinkles.
For me, the biggest thing is that my skin doesn't look as dry or worn down.
It feels softer, smoother, and just looks healthier.
And the results back it up.
96% reported healthier-looking skin, 91% reported less dryness, and 89% showed improved
radiance and luminosity.
If you're looking for one simple product that actually makes a difference, that's the good.
Visit caldera lab.com slash SRS and use code SRS for 20% off your first order.
Again, that's caldera lab.com slash SRS in use code SRS for 20% off your first order.
What is the worst case scenario for a cyber attack on U.S. critical infrastructure?
What is the worst case?
I'll start with this.
Nobody knows what would happen when the gloves could.
come off. And a couple reasons why. We're in times of basically, at least ostensibly,
we're at peace right now with the modern nations like China and Russia. We may be fighting proxy
things or ideological differences. But on defense, we don't know if we've seen 99% of their
capability on offense or 20%. My gut is it's like 80%. In other words, they have stuff on the shelf
shown they've never deployed. We haven't seen it yet. That you save for the moment of need,
right so the first thing i would tell you there's a book by ted couple called lights out and i read
enough of that to go i don't know if that happens i don't think it's that bad but genuinely nobody
knows what it happened if all modern nations go all out in cyber um i can tell you our kids probably
aren't going to school i can tell you some regional trains aren't running um but i don't know if it's
like the there's deniro there's a book the movie out on netflix called zero day and it's all about this
exact situation, but it's done by Hollywood. And I couldn't make it past the first 10 minutes.
Trains were crashing into each other. You know, some child gets killed or some people get killed
in a car accident because the lights aren't changing right, traffic lights. And I was like,
man, I don't want to watch this. The problem is, I think you're going to get a situation that
there's such a rippling butterfly effect that most of society will come to an absolute.
We'd better go back to the old way. I'll give you an example.
like there was an attack in 2021 and it worked.
It shut down software that was used by a lot of restaurants.
And I mean, you and I've been ordering food and restaurants from long before the internet,
or at least, you know, someone wrote down your order.
What I was amazed at is when the internet went down at about 800 restaurants,
just the app itself that they were using got compromised,
the majority of the restaurants couldn't take orders.
They didn't know how to run their business off the grid.
If you want to do something weird, see how many Fortune 500 companies can actually run their business if they're off the Internet.
The answer is probably none of them.
Some aspect or most of their business might actually falter.
And that's unfortunately probably what will happen if the gloves come off in the cyber domain.
So much will be unreliable and unpredictable.
It'll impact so many weird things.
Like your running app, hey, how far do I run today?
Oh, my running app doesn't work now.
or you're tracking calories, you can't track calories,
your schedule blows up, your organization can't get on the grid,
or you can't transact, or you can't sell,
or you can't get your money, or you can't believe what you're reading.
And there's a lot of different kinds of attacks.
Like, if I had to privilege a couple of times
of teaching a modern warfare class at the Naval Academy,
I'd show up in guest lecture.
And I'd depress myself, because first of all,
the attacks start a year out, and you won't even know it's us.
Yeah, I won't even give you the playbook.
But when the cyber stuff happens, you know, I think we're staying home from work that day.
I don't think the grid crashes.
I think the power grid crashes.
You don't think the power grid crashes?
I think it might crash in the Midwest.
The mom and pop utilities, Sean, are going to have a problem.
Maybe some of the water facilities.
But it also depends on who's doing the attack and what their goal is.
I would like to dive into that a little bit more because that is one of them, that's where I thought we were going, was the grid's going down, water treatment plants are going down.
You better have fault tolerance.
I think some will.
I mean, the way I understand the way things are going, China manufactures all of our,
damn near all of our power infrastructure, the Transformers, water, truth.
Well, and so if they're manufacturing that shit, they're putting stuff in there to be able to access it.
You've got to trust the country you do business with.
And even the former FBI director said that they are in our power grid and our water.
Well, they hacked into it.
Yeah.
They have, and not everywhere, and that we know of.
Nobody knows what will happen.
Here's what I will tell you.
The minimum is small municipalities are going to lose electricity.
They're going to have their waterworks probably shut down.
Now, again, it depends on the attack, and if we go full Monty right away versus gradual
incrementalism, most wars gradually increment, depends on the actor because there's a blunt force
way to attack us that might not be as successful as a...
slow erosion of our capabilities.
Why?
Does that make sense?
Here's why.
If I break into a major utility, you know, like Con Ed runs, you know, is New York City or PG&E or, you know, down in LA or Southern Code, these are strong cybersecurity entities.
If you broke into any of them and try to run malware, they probably can detect them out with compensating controls and stop it.
Or if you try to just delete everything on a machine, they'll have redundant.
So what you actually have to do is reverse.
So how does this utility work?
And what commands do I issue that will be unique
to every single one of them to get it to perform differently
or to impact it negatively?
That's lower and slower.
You gotta read the freaking manuals.
Does that make sense?
On the littler guides, you probably can just delete everything.
I call that blunt force trauma.
We hacked it and we just said, hey, delete everything, go.
That might shut down municipalities.
It won't shut down the bigs.
they're going to keep giving you energy.
The bigger problem with the bigs is the load they've got to take
if things start to shut down.
We saw that happen in Texas, right?
They had like an early winter or late winter.
And all of a sudden, the whole darn thing ripples across the state,
you know, because if one utility went down,
the other tried to bear the load, and it couldn't do it.
It pops down.
And we had that cascading in August of whatever it was
when New York went down.
You know, do you remember that happened in maybe 2003, 2004?
It was 2002 maybe.
I can't remember.
It was August of 2003.
Grid goes down in New York City.
You know, and it was all peace and happiness because it got back up in three days.
But what's it like after five, you know?
I was actually in New York at the time.
It was really good because people learned after 9-11 how to work together during crises.
And that was August of 2003.
But I also remember walking around the city going, it's August.
It's hot as hell.
Aircon's not working.
How long before this thing unravels?
You know, but I think if I'm on offense against us,
you take out energy, you take out everything.
That's health care, that's finance, that's everything.
And I think that's what you got to worry about.
And then you're just going to get this weird ripple effect of regional transit not working.
ATMs, maybe not working.
You know, life will change.
So.
What about water treatment facilities?
Hard to defend.
If they just made a minor.
changes to how they treat it to what they're putting in it, how they're...
They're all different, Sean.
That's the thing.
Like, there's, you're going to have to...
They're fucking poison us.
Yeah, I think you've got to know more than that.
I think they're going to go for...
That's why I said you either shut down or alter.
Shutdown is blunt force.
They just...
We're going to delete everything versus we're going to change the commands being executed.
They're unique per utility.
They really are.
Like, you've got to read the manual.
That being said, if I ever hack a company, I find the manuals.
not hard to find. They really aren't. You just look at a debt, like everybody stores them in the same
place and it's usually called the name of the system and the user guide. Read the freaking manual.
We do a lot of assessments of these utilities. And if I were, you know, if my red team lead was
sitting here, be like, yeah, we usually, if we can get to the OT or operational network,
that's a problem. So what you have to do is segment the internet network is the IT network. We've
all heard IT, right? You got to keep that IT separate from the OT. You better have one hell of a wall
between the two. The problem is everybody has a crossover somewhere. It's almost like nippernet
the Sipternet. You know, we can go one way, but not the other. You know, you've got to figure
this out. I think the small utilities are uniquely disadvantaged at time of war.
So you're from Missouri, hometown. Probably not going to do great. Yeah. Yeah. I don't even like
thinking about it.
Well, you've got to think about it all the time.
Yeah, but there's no, when you, the challenge, so here's the, let's try to, I'm not a
pessimist or an optimist.
I'm a realist.
I do think we can have a future with AI.
Everybody's going to say, AI on offense is going to create a problem, and that is true.
I think it's near-term pain with AI on offense and what, you know, and we can probably
get more into that.
But I do see a future where AI on offense will be uniquely a very.
available built by the good guys. That's what Armadon is doing to train your AI on defense.
The biggest problem we have in cybersecurity is there's a starvation line. The big companies have
great expertise, great talent, and great software to defend it. And then you hit a poverty line
and all these utilities can't defend themselves. And all the small companies can't defend
themselves. With AI, we're going to get the scale of the expert. The problem is we have to live
that transition period, Sean, and the advantage will go to offense during a transition period.
And we're in that now.
AI is just emerging.
It will advantage offense.
However, in the long run, it will advantage the defense.
But we're going to have an ugly transition.
So when you talk about a, like a, how did you do just not blunt force when you're talking about a triple-office?
Yeah, blunt force promise, like a bad hack.
Like if I'm on offense, I don't do blunt force because I don't want you to notice I've hacked you and I've screwed with you until it's too late.
So what does that look like?
You slowly erode a system.
How would you do it?
Slowly pollute the water,
slowly degrade the utilities.
Yeah, but I would have to read the manual
because it's unique to different things.
Yeah, I almost hate giving the playbook away, you know,
because I'd already have, if I were against us,
I'd already have people working there.
I'd already know how to bring down the major utilities
because I have one guy on the inside
feed me the manuals, feed me the access,
if I needed as well.
You know, so it's real hard to stop that.
We have a very international culture, and not all loyalties lie in the same place.
So, you know, I hate thinking about what, and I instantly, Sean, go, what would I do
if I were against us?
And I just don't like what the outcome would be.
So I'm hoping that our adversaries gradually increment.
We have to have a proportionate response.
If someone attacks us in cyber, our best deterrence is not in cyber.
It's explosive.
It's kinetic.
It's, you bring the pain.
That's the unfortunate reality.
We are in the glass house in cyber compared to the rest of the world.
You know, I think China might be too because they have such centralized control.
We may be the two biggest glass houses.
You know, if North Korea hacks us and we think, you know, we're going tit for tap by hacking back,
they're in a mud hut, throwing rocks at a glass house.
And we're in a glass house throwing rocks at a mud hut.
It's stupid.
It's not the right domain to fight the conflict in.
And I think, unfortunately, that's the reality.
We have to, if somebody starts hacking our utilities,
we have to respond very quickly and violently to that.
What about the financial markets?
I don't even think I start number one.
And they like to think they are.
You know, you talk to the banks.
But to me, I've never, ever had a scenario in my head
where I targeted the banks.
No one gives them about money if they can't go to a hospital.
You know, I go after electric first and foremost,
probably water, you know,
because it's unguarded, it's hard, hard to protect.
And health care.
That's it.
The financials are so well defended and they're so good at,
they can always roll back to one second ago.
They have thought tolerance everywhere.
They're confidence games, they cover losses.
And I would put, if you could wage a war on every front
in the cyber domain, yeah, I'd go after every domain.
I'd go after every industry, I mean, and let them all have it.
And I'd have AI on offense that can hack 24-7
in total recall. And that's what's common, unfortunately, Sean, is a future where all of us,
there's an attempted hack against all of us all the time. It's almost that bad now, you know,
but it will be that way with AI. So it's like a lot of needles coming at the balloon and it only takes
one to pop it, you know. How do you, I mean, what do you, what would you tell just the average American
to prepare for if that were to happen? Everybody needs to be able to live off the grid. You know,
that's actually a fact. We tell businesses, I call them red lever events. If I'm meeting a
CEO at any company, never forget how to do business the way you used to, just in case we're under
conflict. Be able to dust off a book and say, okay, man, we're going to have to do insurance
claims with pen and paper again. Whatever it is, because you never know what conflict can bring
and what you may have to work. Like, if you're a restaurant, for God's sakes, you ought to be able to take
an order without the internet and without a damn iPad. You ought to be able to write it down,
and walk back to the kitchen and do it.
And I saw over 50% of restaurants falter with no internet.
Literally couldn't operate the business.
In fact, waitstaff didn't even know the menu because they were so used to it.
So great companies spent, and by the way, critical infrastructure for damn sure,
you drill the red lever events off the grid.
How well do you operate?
Every machine becomes inoperable right now, how fast to recover.
Those are like pull the lever, what happens?
And most companies, when they do those red lever events,
have unique findings.
Like, wait, I never thought about it,
but no one can park in the parking garage.
When we come off the internet,
when people badge to go in to the parking garage,
your badge gets digitized and sent somewhere
for authorization to open the gate.
No internet, no gate.
Traffic jams the whole block of LA.
So you gotta figure out how do people buy lunch at work?
No internet.
Can't take visa cards.
How do we, you know, critical infrastructure
needs to operate off the grid,
It needs no way to do it.
It needs to be able to operate how it used to.
I believe that.
What about for people, about for businesses?
People, you know, there's no way to, unfortunately, you know,
for me for people, it's when we're talking about the rest moments, I hate to say it, and I know
you believe this, you have to at least have a family plan for what do we do if the dirty
bomb goes off, what do we do if the earthquake hits, what do we do if blank?
You know, great idea about technology.
I do believe with proper diligence, you can know where your kids are, know where your family is,
and do so in a safe way.
You can have protocols and place you're in communicate in a safe way.
If the grid comes down, I don't know how to do that, but you can't really take down the
Internet in the United States.
That's why it was created.
Survived nuclear war.
That's literally how we went from packet, you know, packet switching from circuit switching.
Circuit switching was one line.
You sever it, no comms.
The Internet was created, literally, so we could communicate.
after nuclear fallout. That was one of its reasons. So you're not shutting down the internet here,
and there's ways to have redundancy. Go satellite and fiber to your house, have backups.
But it's virtually impossible for me to say to any individual, you should prepare to withstand
an AI-based attack coming from a modern nation. That's going to fall in the hands of the companies
to protect us at that point. Okay. Yeah. Apple's got to
protect us. Google's got to protect us. Amazon and AWS needs to protect us. Microsoft
protect us. CrowdStrike. Palo Alto Networks, Ford, Net, Cisco. You go through the brands
that we all use for our infrastructure, use for applications, and say, hey, guys, you've got
to be able to do shields up during conflict. And they know that. Actually, I would argue they are critical
infrastructure. If we think Google Cloud's not critical infrastructure, it is. It's running a lot of
businesses. So is AWS. So is Microsoft's Azure.
So you got to put them in the category of they're critical and they should have, I hate to say it, wartime protocol.
What do we do?
What about the USG?
I mean, talking about the capabilities of China, Russia, in the next segment after this, we'll talk about China, Russia, Iran, North Korea.
But what are our capabilities?
Are we, do we have an offensive hacking arm that is conducting us?
Spinaj on our behalf?
You know, anything we do offensively is going to be classified.
And one of the things I will tell you is I started arm it into absolutely benefit the offense
for nations that are governed by laws.
And those laws are things we aspire to abide to and we do it.
I've always felt on gut intuition and to some extent experience, we were the best in the
world.
We probably still are.
And, you know, but China's great.
And the problem is, Sean, AI is the equalizer between all of us.
AI will enable nations like Saudi Arabia, UAE, other nations,
to have the same level of offense as us potentially over time.
Because you can train systems.
It only takes one exceptional offensive mind that can do vulnerability, discovery,
exploitation, development.
All these skills were going to be automobiles.
automated into AI.
And so that highest tranche of talent and capability
is just going to get more distributed over the next few years.
So it used to be, US was in a land of its own.
Israel is incredible in offense.
I'm starting to realize war makes you innovate faster.
And Israel could be the best world on offense.
And maybe there's certain platforms, different nations
are number one in, like the mobile platform.
Got to give some shout outs to the Israeli offensive capability
in mobile.
period, right?
And I don't know, how did you respond
when Pagers exploded and supply company?
You think about when command and control
is eroded like that,
who to hell wants to be part of that network, huh?
The radio explodes, the Pagers explode.
I don't want the next thing you're giving me, you know?
Right?
Just give me a smoke signal from a mile away now,
and hell, that'll probably blow.
So there's a lot of nations that...
The thing about cyber is one smart person
is infinitely scalable.
So all you need is that one
or two great offensive minds at the right time, you know,
and the vulnerabilities in cyber change.
Like today, there might be first time in Internet history,
no zero days work.
But right now there's two 23-year-old kids working on an app
that everybody's got to have.
Do we know who those great minds are?
Where they live?
Different times.
Like today, it could be that the architecture
that matters is Siemens.
Tomorrow could be Parsons.
And the next day, it could be Cisco.
you don't know what skills you need on offense until the moment.
I'm actually talking about a foreign adversaries offense.
Do we know who those great minds are?
Do we know who to take out if they hit us?
I would think it's hard.
Yeah, I doubt we know.
We probably know some.
You always know the lowest bounds, right?
Whatever you know, it's the lowest bounds of your knowledge.
But now, and I think ours aren't really well known either.
I think the best offense I've ever seen, nobody knows who these guys are.
You know, they're smart.
They go home, walk their dog, and they don't blog about it, you know.
They don't go to black hat or conferences and really share what the hell they're doing.
And the great thing about offense is the government's mission still draws in incredible talent.
But at the same time frame, in my lifetime, I remember growing up going, the best in world at physics would be in the U.S. government, the best in the world at offensive cyber would be in the U.S. government.
The best in the world at Big Data would be in the U.S. government.
And now that I've worked at Google or I'm familiar with Amazon and I see the paid differentials that have probably expanded massively in our lives, I'm starting to think that there's more talent on the outside, right?
So, but I would put, the U.S. will always be excellent on offense.
We have the, you know, and I hope we just stay there.
That's good to hear.
Yeah.
Let's take one more break.
Got it.
All right, Kevin, we're back from the break.
We had a
We had a really good discussion
off camera on what you would do
if you were going to hack into a nation.
How would you...
Yeah, you know, if you were,
you always wonder,
what would our enemies do to the United States of America?
And one of the things that you need to us,
that First Amendment allows any...
You know, there's a...
There's no line between
you have to say the truth
when you're speaking your mind.
You know, what's the difference
to you know, really, really bad opinion
and being out and out,
lying to incite a riot.
You know, nobody knows where these bright lines are.
With the First Amendment in the United States
and the freedoms that everybody's afforded for that,
I think we're uniquely susceptible to manipulation
to the hearts and minds of the American people.
And, you know, what I was trying to remember, Sean,
is sometime in, I think, August of 2015,
I had one of my intel folks.
We built a global intelligence infrastructure at Mandate.
So we had hundreds of people that spoke
30, more than 30 languages in over 30 countries.
And one of these guys just walked in my room one day and said,
foreign intelligence from Russia is influencing the hearts and minds of people
through these X handles, these Facebook walls, and he just unloaded.
And it was like a 100-page document.
And I remember going, and this feels wrong.
This is before anybody ever talked about Russia is trying to influence the U.S. elections.
Well, no crap.
Every nation is, right?
With whatever they've got.
I mean, if you're getting funding in your Liberia,
Wouldn't you maybe try to get a few votes for that side?
I think there's no different, there's good people trying to manipulate hearts and minds for good reasons.
But what we saw and what I saw in the 100 pages, and we went public as a company about this with about 90 of those pages.
But I remember, I think I literally flew back in and brief Senator Warner, he was, you know, the Senate Intelligence Committee saying, I don't know what to do with this, but here's what's happening.
Like, Facebook walls are being started.
And when we went back and we traced it,
I don't remember the details now other than our guys were really good
that spent their whole time kind of tracing certain Russian actors
and they're like, this is them.
This is them using these platforms.
And all they did is Amplified would already exist it.
They weren't even really making stuff.
They were just like, let's push this issue, let's push that issue.
And they were just driving things.
And people would ask, well, what side did they push?
I'm not sure they cave a damn about any of that.
I think they more cared about just push American people.
people this way, both directions. You know, and I apologize, I don't remember the details as well as I did,
you know, a decade ago. But I mean, that was a cool part of my job. It's literally a guy just walks
in my office, you're going to want to read this. And me read it and go, what the how do I do
with this, you know, and then you just talk to people like, you know, we got Facebook involved.
We got Google involved. There was a third OX. And we did talk to their trust people. And all of us
were like, yeah, this doesn't feel right. But we didn't know what to do. You know what to be. It was
the earliest onset, in my opinion, of social media being used.
And you can't tell what's artificial amplification versus real amplification.
That's a problem, right?
You can't tell if this is an issue that matters to Americans or not based on the number of hits
and number of volumes.
And that stuff's feeding our algorithms and changing things.
So we've got to figure this one out.
And I know a lot of work's been done since I inspected it.
So I'm sure today there's a constant whack-a-mole at these social media companies say,
that's a foreign actor, kill it, kill that.
And yet people don't want that to happen either
because it's censorship.
But I can tell you it's real.
And if I were on offense against us,
because of the First Amendment
and you're right to say anything you want,
for the most part, you know,
shy of screaming, fire in a crowded movie theater kind of thing,
we are susceptible to attacks Iran is not,
and Russia is not, and China's not.
They're not bastions of internet freedom.
They control their press.
And we can't really push,
back on the buttons there as effectively as you can push our buttons. So you even can look at
our nation today, and many people describe it as divided. I can't tell because I think people are
amplifying the edge. And I think we're getting that through our media in such drastic numbers
that nobody really knows what's normal anymore. And it's too easy to do, you know? So I think
if you go on offense against us, you just get us to tear ourselves apart. You know, that's what
you do. Psychological worker. Absolutely.
And you can, you know, and if we've even seen that, you know, no matter what people say about the DNC breach of 2015 and the documents leaked in 2016, a lot of people don't like to talk about that. It became a political issue, but somebody hacked these servers and somebody leaked documents. We'll leave it at that. I would say that the, to me, all of the facts did align in my experience to it really was the Russian GRU and SPR that did it.
just all the same tools.
And what's interesting about those guys, by the way,
they really used their own crap.
So if you find their crap, it's them.
I don't think they're leaking it out
and giving their custom tooling to other people.
And I've never seen a modern nation hack
and then leaked documents before.
That was kind of the first.
That was an escalation in my domain.
China doesn't do that.
They're not going to hack Sean Ryan
and then take all your email and throw them out on the Internet.
Russia seems to do that now.
You know, it's a little bit different, but that's what I'd do.
And then what would stop you from hacking people like Hillary Clinton or Obama?
They lost her emails before to what we would attribute as foreign actors.
Leat the emails, make crap up in them.
I mean, we are our culture now where I don't even know if you need the evidence to toss someone under the bus, you know.
So I think the way I'd go to war with the U.S. is maybe what we're already seeing.
you create...
Division.
Absolutely.
You create discord.
It doesn't matter.
You don't even pick a side.
You pick all sides.
Just throw it out.
I would actually pick the two opposite sides
and keep pushing both of them.
And you see it.
It's going to make it tough to lead in our country.
And it's that freedom of speech.
Everybody has a right to say whatever they want.
And so we've got to figure out how to protect that freedom
while still showing, I would argue,
the biggest thing we have to do,
is find artificial amplification of ideas and quash it.
Does that make sense?
Because you think it's like 50% of America thinks something,
but it's like 3% plus amplification.
But that's really hard to do.
And in reality, the biggest guilty people for amplification
are marketing people.
You know, yeah, the foreign intelligence will absolutely amplify certain ideas,
but unfortunately so do U.S. organizations.
You have to do this, or, you know, here's the cure.
So it's really, it's a tough battle.
And you know, you often study, there's a book out, you have kids now, so you're going to have to read these things.
And you look into the anxious generation, the same person that wrote the coddling of the American mind.
And when I leave, I'll send you these books.
It's a reporter.
You don't even need to read the book, Sean.
Just look at the graphs.
Ever since the iPhone came out and people use social media, depression goes skyrocketing thousands of percent.
Suicides go skyrocketing hundreds to thousands of percent.
they don't know anything other than, well, it all starts going bad in 2007, the year of the first iPhone.
You don't blame Apple, but was the species ready for what we're actually developing?
Did tech finally get out in front of us in a way where we couldn't manage the fallout from it?
And to some extent of social media, I think that's the case.
Social media in many ways, because of the anonymity behind it does have the propensity
to amplify the minority.
It has that possibility.
So anyway, it's a tough one.
So if I'm on offense against United States,
I'm all hearts and minds.
Fake media, synthetic media,
even if you know it's fake,
you won't get it out of your mind, right?
You know, we even have an administration that uses it.
And I think it's, we're going to have a future
where we won't be able to tell probably
between synthetic media and non-synthetic.
I think we're already there.
I think you're right.
And so the hearts and minds, when you have a nation like us with this openness,
I mean, we're pulling ourselves apart pretty hardcore right now.
Feels that way.
I mean, you would even mention breaching companies and grading refs.
Oh, absolutely.
And companies.
Absolutely.
Get the trusted business leaders.
I hate seeing these ideas publicly because you can do it.
Discredit public leadership in credible ways.
I don't even think you need credible ways, but just do it in credible ways.
meaning say you hacked someone and get their email, leak it.
I've seen what that does to people, but leak it, nothing stops you from adding to it
and doing it in a frenzically sound way or in a way where some, there's always a pun and it goes,
oh, it's definitely real, I'm an expert and that's real.
And then you have someone who really knows what you're doing going on, this looks fabricated.
I've worked cases where all the evidence was fabricated digitally.
That was amazing to me.
Couldn't believe it.
at least my opinion was it was and people agreed with it uh in today's day and age it's just too easy
um we all have digital lives we all rely on technology more than ever before you have wearables
that tell you how much you sleep when you should take uh pills or drugs you have wearables that might even
you may even have apps that require prescription at some point in time because you know you have
something on your wrist that says you need more of something you know i'm sure it already exists we rely on this
text so much, but the unfortunate reality is you can take it. You can take that data. You can
skew that data. You can use it against people. We have a whole generation, Sean, I think all their
deepest thoughts is already written down, you know, in the text they shared, in the photos they share.
Maybe we've waived their right to privacy, and maybe that's the transition mankind's going
through from the private life. And, you know, people didn't need to know our thoughts did. Now everybody
knows everything we're thinking. And maybe we cross the chasm and just recognize it's okay
to think whatever the hell you want, how dark it is or how great it is. But we haven't crossed
it yet. So, damn. Yeah, so that's what I would do on offense. That's what I taught, you know,
when I was at the Naval Academy, we were talking about it and everybody was coming on with their
neutron bomb, blow-up GPS, and that's what we do before war. I'm like, how about a road confidence
in your lawmakers and your business leaders and how easy that is to do? And it is easy to do. And it is easy
to do. One allegation creates doubt in a lot of people, whether it's founded or not. You know,
so we need to have a better system to, they call it a cancel culture. You know, it's tough.
Damn. Sorry. Dark stuff, man. We got to end on a, we need some sunshine. Well, I don't think we're
going to get it any anytime. But the hypothetical is how do you attack us? What do we do about it?
Boy, is there ever a time for critical thinking, you know what I mean? And how do you teach that? How do you
trained at. And honestly, and I've heard you talk about this and you're exactly right, and this is a
cybersecurity episode, but when studying cybersecurity, it's directly related to ideological conflict,
you know, period. It really is. And people with opposite opinions got to learn to talk and respect
each other. The American way has got to be, you can have a disagreement, still be fans of each other.
Yeah. You know, so we kind of. We have definitely lost that. It reflects it in cyberspace.
too. It really does. Like it's, we used to be able to, and this is something that happened in my career.
If you committed cybercrime in the United States, you got caught and penalties were stiff.
They were, a lot of people would argue they were really stiff because judges and lawmakers
didn't like the invisible crime and the anonymity of it, and they wanted to stop it because
it was maybe too easy. So you have a severe penalty because of how easy it is.
And suddenly in the last few years, we're running the Western Hemisphere hackers and
they're not getting arrested. And I don't know why. You know what I mean? Like in my career,
I had at least a 25-year run. If you hacked from L.A., oh, man, you got caught. If you hacked
from anywhere in this country, you got caught. If you were doing it in Canada, you got caught.
It's seemingly getting harder. And I don't know what's going on, but we do now have, in my career,
we're responding to intrusions and the threat actors are on our continent. Isn't that weird?
Didn't used to be the case. And hopefully we get, you know, we get back to where we were. We
push all unauthorized or unlawful internet-based activity for most of us. We got to get that.
We ought to be able to control our backyard.
The internet wasn't built with your privacy in mind, but Glacier was. Open the app,
tap connect, done. You're protected. Remember, privacy isn't paranoia. It's protection.
Do you ever wonder what it takes to make an episode of the Sean Ryan show? In this exclusive
studio tour, I'm taking you behind the scenes for an in-depth look at every part of the operation,
from the editing room in the main studio to the spaces where we film Range Day, content,
and more. You'll see how the show comes together, meet some of the people behind it,
and get a closer look at the work that happens off-camera. When you become a paid member of the
SRS Patreon community, you get more than just the podcast. Watch new episodes early alongside
other members, join monthly live shows with guest Q&As, and submit questions, just like you see on the show, for upcoming guests on the Protector Tier.
You'll also unlock exclusive Range Day videos, behind-the-scenes content, and premium ambience videos that you're not going to find anywhere else.
Join the Patreon community today and get access to the full experience.
Let's move into our four adversaries.
Yeah.
Who are they?
In cyber, you got to go with Russia as a two-trick pony, criminal and real foreign intelligence
services, high capability.
When focused, they are Wayne Gretzky on the penalty shot, right?
They're real good.
China, scale and scope, you can add all the threat groups I tell you up, and they do not
create the volume of compromise that the Chinese government does.
So all of it together.
Criminal, Russia, North Korea, Iran, all of it together, doesn't add up to the steady tsunami
of Chinese-based intrusions.
And we only know what we know.
But we look at my old company, Mannia, responds over 1,000 cybersecurity breaches a year, Sean,
and these aren't the ones you're five minutes behind.
We get hired when the scale and scope of the intrusion requires additional expertise, and that's us.
And we're responding with companies that have great talent and great defense.
and we're still showing up going, all right, how did they break in?
And it is new and novel attacks.
It is things that would work 99% of the time or higher.
And that's, you know, so we've got to respond to those.
And when we look at that, without a doubt, since 2004, China's led away.
We've always responded way more to breaches coming out of China.
They follow rules of engagement that I don't think are written down, but they are polite hackers.
They don't delete your data.
They don't destroy your systems.
They steal things.
Russia hacks for security reasons.
And, you know, the SVR, in my opinion, follows probably the same rules as our offense does.
But their FSB, GRIU are a little bit more broad than what we would ever probably allow.
And I've heard stories of Russian threat actors that hack for the government during the day and hack, you know, to make money at night, I'd believe it.
Certainly Russia condones all crime being done in the cyber domain, period.
They actually, from what I've heard, both China and Russia, I mean, they have put on classes, courses, schools.
Oh, totally.
In the schools, they actually just hack the U.S. as a train.
Probably.
I think with China, they'll hack not to make money, though.
You know, not directly.
Russia, they would.
North Korea only hacks to make money, it seems.
I mean, in reality, North Korea is the only people in uniform badging into a building every day,
or at least showing ID to get in,
are hacking to make money because they fund themselves.
Isn't that incredible?
Have you heard about the North Korean IT problem?
Where it's not hundreds.
Thousands of North Koreans have been hired by companies in the United States
because we all started hiring remotely during COVID.
We hire IT professionals.
They speak English.
They know what they're talking about,
but they're actually North Koreans.
And you hire them,
and a couple days after you hire them,
they just steal all your crap and go.
And sometimes they keep a lot of them,
working for you because you're paying them 130 grand a year. There's a podcast coming out by Nicole
Peroroff and maybe you'll meet Nicole. She's a New York Times reporter. She's doing her story on this now.
Her last podcast was on the Chinese cyber espionage campaigns and she can do things I can't.
Like she'll say things I won't say or she'll talk to the victims and follow up when I never got
to do that. She saw the ramifications of companies losing their IP. I just saw what the attackers did
and how to clean it up.
She's doing a North Korean thing now.
And when I first heard that problem, hey, North Korea, you know, has IT workers getting hired.
I'd, like, burst out laughing out.
There's no freaking way that this can be a problem.
And I was at a conference with a bunch of heads of security from really reputable companies.
And as soon as I was, like, laughing it off, like, five of them came up to me and started saying, hey, no, we have the problem.
And when they explained what happened, I went, there's no fix for it.
But the fix is you've got to get people in the chair across from you and hire them.
And the problem is we literally hire internationally.
Many U.S. companies will hire people in Europe through Zoom, Google Meet, you know, or Microsoft Teams.
And these are programmers that can answer the questions right.
I mean, and quite frankly, they'll even do the damn job for you.
It just so happens you're paying someone who's working for a weapons of mass destruction unit.
You know what I mean?
literally. And so the North Koreans, you may hire them, and then they hack to steal Bitcoin.
They're hacking to make money. Russia's hacking for spying and crime. China's hacking for spying
in long-term economic gain through theft of IP. In Iran right now, you know, with what's going
on, the excursion going on right now, the it's like your, the cyber domain was already a crappy
neighborhood. Think of it as it's like Camden, New Jersey. No offense, Camden.
tough place. It just got five new gangs to it. You know what I mean? It's like cranking it, as they say in
spinal tap, crank it to 11. The cyber domain, if you can be hacked by an Iranian effort, they'll do so.
But the way they break in right now is with user accounts and passphrases that are already on the
dark web. Like you lost your use ID and passphrase from some prior breach somewhere, maybe your
own company, maybe somebody else's. They tend to brute force log in and then they're going to delete everything
it to get in right now, whoever they are, the gangs that want to support the Iranian cause.
So, yeah.
Do you think we'll see any retaliation in the cyberspace from what's going on in Iran?
I think right now there's probably automated programs running on behalf of the Ministry of
Security, Intelligence and Security, M-O-I-S over there, that if it can break-in will.
And then they've got to get a human operator to go do something with it.
It doesn't take a lot of bandwidth.
If you can get, you know, you don't need a whole lot of satellite dishes to get something working for you there.
Yeah, you'll see something.
And it'll be real hard to tell, Sean, whether it's really the Iranians or a proxy or just somebody who wants to have for the hell of it and, you know, make some noise.
Which one of these, you know, out of Russia, China, Iran, North Korea.
Yeah.
Which ones?
Who are you most worried about?
You worry about them for different reasons.
I would say sophistication now goes to China for how they first break in.
How people break in will always change.
China seems to be the forerunner of what's called zero-day development now.
They can find attacks that are going to work.
And then, but when they break in, they're not leaking your email to the press.
They're not extorting you.
Those are really complicated.
So I would say Russian criminal, really hard to go against.
There's some now Western Hemisphere criminal gangs.
There's a group called Shiny Hunters.
There's a few others that they break in with social engineering.
They'll like call your help desk and help desk help people.
And they have whole scripts written and they're very bold and they get one time authentication
into your network and they then go in and once you can get any beachhead in the cyber domain,
usually that means you take the island.
You just need that one boot on the ground and you'll do fine.
So you need one way to access the network, you'll spread from that.
The Russian criminals are really hard to deal with.
The U.S., now we have Western Hemisphere criminals.
They're really, really hard.
Iran's going to delete everything right now, probably if they get in.
That's not going to be a fun cleanup.
They're all bad.
I mean, that's the reality shot.
But the public humiliation does not come from being hacked by the Chinese.
Those you can handle quietly and discreetly.
I think the Russian and the North Korean and the Iranians are probably going to go public.
And that just adds complexity to your response.
Gotcha.
Yeah.
Gotcha.
All right.
How are you hanging in there?
Cyber in there.
Scary shit.
Yeah.
So.
Yeah, we've got to get more optimistic.
This would move into your new company.
It got a hot question.
Yeah.
So, you know, Claude, I'm sure.
Oh, God.
Anthropic.
Yeah, totally.
So we had Claude Anthropics.
A.I.
Scraped the Internet to ask you a question.
How did it do?
And here's what it came up with.
In 2010.
Then Stuxnet became widely known as the world's first cyber weapon.
The US and Israel used it to physically destroy Iran's nuclear centrifuges.
That was 15 years ago.
Now with AGI being reported as achieved, do you think AI is the new cyber weapon and why?
Fast answer, yes.
You have to use all technology to advance crime, to advance war, to advance societies.
It does all of it.
good, it does bad. The invention of the gun helped the hunter, but it also helped criminals
to some extent, depending on your frame of reference. AI will make the speed of intrusion take the
human out of the loop. That's what it will do. It's too fast at discovering vulnerabilities.
So I started Armidon and combined what's called Red Team consultants, the best Red Teamers in the
world. These are folks that get paid to hack into Fortune 500 companies and see if you can stop the train
or corrupt the food or shut down the grid or steal the email from the CFO. We took those guys and
we're still hiring a bunch of them and we paired them up with AI native developers and said automate
what we humans do. And we started as company September of last year, Sean. Here's what I can tell you
happens already. If somebody tells us, they hire our red team and says, take a look at this custom
application. You build an application that you gave me here. Someone will say, take a look at this
application. Can you hack it? Well, you used to take us five days with two smart humans is five minutes
to 10 minutes with AI now. That already exists today. So what you see is the compression down.
But it gets unfortunately more daunting.
When we go on offense as humans,
we only find one way in at one point of time
to achieve the goal you've told us to try to achieve.
Try to shut down the assembly line.
Try to get to our IP.
We find the fastest path in, we prove it,
and then you fix that.
With AI, we launch 100,000 threads coming at you.
It finds all paths in almost immediately,
but it does a few things humans can't do,
has total recall the next time we ask it to do that.
So if there's a vulnerability it found that Company A two months ago,
it instinctively already knows.
Look for that again, just case you didn't fix it.
It's the speed, though, the fact that AI can think, learn,
and has total recall and can be trained,
it will be the cyber weapon in the future.
Just like no different than drones,
if you think you can fight the next war
and when you better have software that thinks, learns, and is secure.
And you better hope it thinks the fastest, learns the fastest,
and is the most secure to win that war.
Or you're going to lose.
And that's going to be cyber domain.
That's going to be autonomous planes, drones, you name it.
So yeah.
There's a follow-up.
Got it.
On a different note, by 2027, every new car in America will have an infrared camera
pointed at the driver's face, and that's by federal law.
from a cybersecurity, from a cybersecurity expert's perspective, what's your honest take on this?
Does this leave vulnerabilities for our adversaries to hack American vehicles?
There's been an equal and opposite compelling argument inside security since the dawn of time.
If we're distributed, it's harder to beat us, but it's harder to defend us.
If all our eggs in one basket, it's easier to defend, but easier to beat us. Does that make sense?
Right now, we're putting data about everything everywhere.
I mean, I grew up, there were no cell phones in college.
Otherwise, I would never be able to be a Supreme Court justice, you know, right?
Evidence would exist.
Now there's cameras everywhere for everything.
There's just no question, even though it's going to get harder and harder to compromise things.
I believe that.
You know, the Internet was pretty damn open in the 90s, and I, you know, and I've lived that.
It was pretty damn open in 2000, really until 2020, 2021.
And we're in a whole different world.
AI is going to help us write more secure code.
There'll be less vulnerabilities.
But at the same time frame, should someone break in, I think the impact's going to be far
more than what it used to be in the past.
You know, early on in this interview, you asked, what was the worst breach we saw?
And I remember going, I always hated it if a flag officer lost his email.
That's just weird, you know, because they do important things.
Fast forward to now, with wearable devices and our dependency on everything,
whole businesses can't operate if the Internet goes.
down. So AI will be the offensive choice, and unfortunately, because of the speed of compute,
AI is going to have to be the answer on defense. And that's why Armadon exists. We will be the
ultimate offense built by the good guys to train and automate the defense. And every company
is going to need a different defense. We're all going to write our own apps. We talked about Anthropic
and Claude. Talk about magic. I had a computer science degree. I hate to say it. Don't
Don't tell your kids to get a computer science degree, okay?
Heck, ask the CEOs of these companies, you know, ask Dario at Anthropic, hey, you want
your kid to learn computer science, you'd probably say, eh, it's like learning Latin.
No one's going to speak it.
The computers are going to do it for us.
The whole goal of Anthropics to have Anthropics Claude build the next Claude.
At Armiden, we want to get our AI attacker to be so good.
It's building its next AI attacker.
They self-propagate.
And the unfortunate reality is we have to build it,
or the adversary will.
And it is the only way to get to autonomy.
But back to your original question, yeah,
we're gonna have cameras in the cars,
cameras on the streets, cameras in our homes,
data everywhere.
I think it'll be harder to break into all that stuff,
but should the break in occur, I think the impact will be grave,
more grave than in the past.
Now, I'm thinking today, two years from now,
you should be driving
driving a car that has something in it that instantiates normal Sean driving.
And if anything happens, something very bespoke to you can recognize and say, that's not him.
That's not what he wants.
That's not what he does.
And it may save you.
It may do the opposite of that.
But we are going to have defense that can thwart attacks we've never seen before.
You know, and do it in a way that a human's not in the loop for.
something's asking this system to do something that's never done before.
They automatically get stopped and ask for a human in a loop to say,
hey, listen, this has never happened in this car before?
Do you really want it to happen?
Or this never happened on your computer before or on this camera before
or on your HVAC before.
Do you really want to allow it?
Stuff like that will exist.
Interesting.
And then you'll pick in your house, you'll say,
I want to be prompted every time someone's accessing my camera.
Other people, it'll get trained specific to them.
It'll get one time, human a loop, go ahead and allow it to happen.
And after like three times where the user says, go ahead and allow the program to do something,
it'll just do it from their own end.
We'll all have bespoke software.
Trained by you.
Your phone wound up being trained by you.
The AI on your phone will know you, be personal to you.
There's got to be vulnerabilities within that alone.
Well, yeah, you often wonder, now we're talking to true AI Skynet story, right?
One brain in the sky doesn't mean we all share one brain over time.
And that brain will always reflect the culture of those who built it to some extent, right?
And then all AI models, no matter what anybody says, we had to at Armadon build a way to as soon as they update at the Frontier Labs, their models,
we plug them right into our shooting range and see which ones are the best at the things we normally do now.
And they'll flip and flop all the time or they'll be about equitable.
And we test them on the range, as they say.
But these things, you test them day one, you test them day 20, they're already different.
They're like organisms that grow.
These models learn and change and sway in ways that are different.
Like what we get out of a model today could be totally different tomorrow.
Not totally different.
It's always, you know, to me, I haven't gotten a hallucination at a long time.
And I use Gemini a lot and I use cloud a lot.
I'm a little bit less open AI.
And I use it for real stuff every day.
It's common I'll have like cloud running on something that I want because it's
great at making PowerPoint slides, and I'll have Gemma and I'm making some graphics for me or answering
questions. I'm using them both. Interesting. Interesting. Where do the motivation come from to start
Armaden? Has to exist, right? It's, I get two things. One, I wanted our, the first motivation is,
you know, my company got bought by Google and I'm an entrepreneur, you know, some people would say,
once you're an entrepreneur, you can't sell your baby. I had no problem being a public company
and getting bought. The company is no longer mine. I was a face for it.
But if you're a great entrepreneur, at some point in time, you're also the owner.
But, you know, I had no problem letting it go.
I was bought by Google and I went in like a lion.
Like Google can change the world.
It really can.
The resources it has, I just didn't fit.
You know, so I was a little upset in a way that I didn't fit there because I know the power
and capability of that company or Amazon or Microsoft.
We have great companies.
They can do great things in cybersecurity.
And you want to be a part of that.
But one thing they would never do is offense, and I respect it, I get it,
wouldn't fit with a large brand.
And I thought to myself, the exact thesis I had was the first intel on the Internet was terrible.
You had to find what Symantec missed and give it to them.
The second intel on the Internet, I feel I created.
We'll respond to every breach that matters, and people are like, that's not even a market.
There are no breaches.
Oh, there were.
And we responded to all of them, and we learned about the new and novel text first
so that we could build better defenses against them.
Well, the third wave of intel is we're going to create the attacks,
and we're going to create them before the bad guys do,
and we're going to fix your problem before they come out.
It's almost, you know, I guess they call it gamification in a way for viruses,
but if you can create the viruses that are coming 10 years from now
and inoculate today, we're ready.
You know, same thing here.
But we have to build it because, hey, it's going to be what we're up against,
and if you want to know if a bulletproof vest works,
you've got to shoot a bullet at it.
We're going to be shooting bullets at networks.
And if you can withstand our bullets, the assumption,
and what we want to become is that seal of approval,
if Armadin can't break in, oh, you're good to go.
Brief the board, let them know.
There's no other way to reduce your cyber risk.
And I actually believe that.
So we started Armid in so that we can dry run and practice
what we're up against.
And it's common.
There are no risk or repercussions to the folks stealing from us,
hacking us.
It's just we haven't shown a means
to impose risk to these threat actors.
So you got into it a little bit,
but what is the future of cyber warfare with AI coming online?
Oh, boy.
You will have systems dedicated.
I think, so the general models are what are called horizontal models.
Like Anthropics Cloud is a horizontal model, right?
Open AI, horizontal model, X as a model, Gemini for Google.
There's going to be very verticalized models
where you train them and learn from these huge models
that have read every book, every human's ever written
or watched every YouTube video of everything.
You've contributed to models probably,
and you don't even know it.
And you're gonna have offense against very specific things.
Like we're gonna end up creating models
that are offense against cell phone, offense against drone,
offense RF against drone, offense against Windows,
like deep models that are actively working,
the same way a human did, but at thousands and thousands of times the speed,
and doing the same tasks we did to try to find vulnerable code, vulnerable IP,
you know, it'll all be automated and specialized for the targets they go after.
It's going to happen.
And the sad thing is we had to build Armidon because it's automatically going to happen.
Every shift change.
I lived through this, Sean.
In 2000, there was a guy named Alexei Ivanov and a guy named a businessman.
Gorschkov. At the time in 2000, Alexei was 18 in Chelyabins, Russia, Vassili was 25 in Chelyabins,
Russia. These guys extorted hundreds of U.S. companies. They would break in, and what they did
is they scripted everything. They even scripted. We got to do the forensics on their laptops.
These two Russians were lured to the United States for jobs, and the jobs they got were with the FBI.
The FBI lured them over. They flew into C-TAC airport or Tacoma Airport. And, um,
They got arrested.
And when you look at what they did, it was at a time when PayPal was just coming out, eBay was getting big.
These guys had monetized that they could steal credit cards, and they wrote software that would sell fictional items on eBay,
buy it with stolen PayPal credit cards, and they were making money selling fictional stuff.
And the whole thing was automated.
They could literally hit buttons, script it, and walk off and come back with, we made $72,000 selling stuff we don't even know.
and buying it with fake stuff happened.
So every shift change is embraced by every personality.
AI is going to be embraced by a criminal element and it's coming.
And we can't withstand it unless we build it ourselves and figured out.
So I always believed the best way to build a safe at a bank
is to get the best bank robber to build it for you.
You got it out of rob banks to investigate a bank robbery.
And I had the privilege of training thousands of FBI agents to FBI Academy.
So when it came to cyber, we taught them how to break it.
Get a sense of what you're up against, the actors, why they do it, how they do it,
and now let's investigate what they did.
And you couldn't really just start with, let's just investigate it.
It just wouldn't work.
You had to give them that sense of doing the criminal act and then investigating it.
It's going to happen in cyber.
We have to build the offensive cannon.
So Arminan's going to build the cyber cannon.
We're going to shoot it at the best companies in the world.
And those companies, if they can withstand the blast, they're good to go.
and if they can't, we're over time with no human in the loop,
building fixes to however we broke in.
If we find a permeable membrane and we get through,
you're going to patch it.
You're going to compensate for it.
And that is the future.
And oddly enough, that future is scalable.
Finally, you can, once we build the Aeon Offense versus Aon Defense,
we can go down to the utility in Aliquipa, Pennsylvania,
and say the Waterworks is not going to be compromised.
And the small mom and pop electric company in Missouri will not be compromised because we can now
instantiate a national risk policy through an offensive cyber cannon training the defense.
And it's just software.
You're not going to be people dependent.
It really is going to happen.
And will it have flaws?
Will we get beaten?
Yes.
There will every once in a while be something on offense that gets through.
But you can literally use the analogy of drone swarm.
in the cyber domain. Like, you're going to send 3,000 drones at a city, and we can only shoot down 2,990.
You know, we're not the same problem in the cyber domain. We're trying. But the best part of it is it will be automated,
and it's actually going to raise the tide for cybersecurity for most people. And then the bigs
will always have their own team still doing stuff to help secure.
I'm just curious, and I'm sure it's very different, but on average, how many volunteers,
What vulnerabilities are you finding per company?
And how fast do you find them with these AI agents?
As I sit here today, it's never taken longer than day to break in.
Shit.
With any...
Is there anything you haven't been able to?
Yeah, and here's what's interesting.
So I can tell you this.
I still think the best findings we had were by humans, but that's going to go away within a year.
And nobody knows how fast, but AI keeps surprising us.
But here's how we broke in the first time.
A Fortune 100 company...
He literally said, hey, break into us and see if you can break this custom application we built.
Very important application.
We have an AI agent.
They didn't even expect us to do this, but we've done this a lot.
We had an AI agent go out to the dark web and go to a bunch of password brokers, and we found
440 or so accounts that were the domain of this company.
And all we did is tried all of them.
At human speed, not AI speed, because AI speed's too fast, you can rate limit and block it.
Cisco routers can block fast attacks.
We just logged in.
Seven of the accounts actually just logged into the app.
We just logged in, and this is an app you don't really want people logging into.
And on one of the thing, and we did it all, human speed, you saw a browser just kind of pop up
on our agent's screen.
It was acting like it was a human.
Tried all the accounts it found.
It gets in seven times, but on one of them, the app we broke into prompted,
you don't have multi-factor authentication turned on.
Would you like to register your phone?
So we did.
So now we literally hacked the company like stuff we found on the internet.
And but humans wouldn't have found it because it's really a pain in your arse.
If you script it's too fast and you get blocked or detected,
if you have a human login every time, takes days and it's annoying and they're going to fat finger stuff.
We just all automated no human intervention hacked the company.
That was it.
And that works.
I would have bought that when I was a CEO.
I would have been like, I just want that.
I don't even need you to try to hack my app and break in the old.
way of the vulnerability, just tell me if you can log into my damn network.
Because that stuff changes.
Everybody thinks, oh, we have two-factor authentication, meaning user account, passphrase,
and then, you know, the digits to your phone or, you know, your fingerprint and all this other crap.
I would want to, you can't, there is no magic wand that says, do we have two-factor everywhere?
It doesn't exist.
But this would prove it.
The attacker's view of your network matters, and AI can comprehensively do that.
So I'm not convinced.
Just yesterday, I got a text.
I'll show you when we're off camera of what we do to a company yesterday.
100% ownership of every machine, day one.
We've gotten into all of it.
And here's the secret in cyber.
So for everybody out there listening, the hardest part's getting in from the Internet.
Every company does everything they can, well, at least above the poverty line in the cyber domain.
The 1A enterprises do about everything they can to not have a breach.
They don't want to deal with it.
And they're truthful about that.
They hire good people and they try.
If we can't get in, I would say, I would say, I would say, I would say, I would say, I would
say over 90% of time we do. But once we get in, it's easy as health. It's all downhill skating
at that point, you know. So, Sean, that's just the problem right now. Everybody's built their
Maginot line, and they've hardened that as much as they can. If we get around it, oh, it's just
Waltsin into Paris. You know, it's too easy once we break in. Everything we need is on the very first
machine we get to. And usually the Achilles heel is every company has one account that works
everywhere so you can patch things so you can fix things. You can't keep that account from us.
That's just the Achilles heel. So it's funny, the very thing you use to make sure you're secure
is probably the very thing that we get every time to make you insecure.
Wow.
So anyway, we will get better. Everything, as bad as this whole three hours or so is gone,
everyone's getting better at cyber defense. We are in a tough time. The offense is still
uniquely advantaged. That's the problem. I think it does change.
changed in under two years.
To equitable.
I don't think defense is it.
The only advantage defense has is we should have access to the software we build to make it secure
before the offense can try to hack it.
That's our only advantage.
We can secure our code before we publish it, get it out of the market.
And the anthropics of the world are making that a reality.
Microsoft, Anthropic, Google really are making it so the code we're writing is better today,
not worse.
That is happening.
So in theory, it'll get better, Sean.
That's good news.
It's just we're going through two years from now, this dialogue would be different.
I would say, you know what?
We're stopping 99.999% of attacks now.
It's just the best in the world.
We never get to stop them.
They are, they're scoring.
Wow.
Yeah.
Well, Kevin, we're wrapping up the interviews.
This has been, I've learned a ton.
Really?
Yeah, so thank you for coming.
One last question.
Yeah, sure.
If you had three guests to recommend for the show, who would they be?
Well, I love Bruce Springsteen.
Bruce Springsteen.
All right.
Three guests for your background.
If you do another one in cyber, the best person that can bring this to everyone is Nicole Pearl Roth,
the New York Times reporter.
I told you, she is exceptional on camera, and she tells better stories than I do.
You know, because I came up through computer science and had to solve the problems.
I had less of a humanity side to me.
When I met CEOs, I was always like, hey, man, sucking up.
with the crisis. She's better at it. She tells better stories as to what China did and what the
North Koreans are doing. She's more personable, more likable. So she's a great one for cyber.
You know, and I don't know, you're doing a great job. People like listening. Like I listen to Kent,
the guy that you just had. Joe Ken? Yeah, I thought he was great. I'm a political. I want the United
States to be successful. I thought he did an incredibly good job doing the same, being apolitical. People
probably hate the guy, I'm probably getting in trouble saying it.
I just listened to it and thought, okay, I learned something.
You know, you listen to, you know, bottom line, you get both sides.
You get people that at least are well-intentioned.
I think that's important.
I get a lot of attention.
Yeah, I mean, it's important.
So anyway, I'll give you those two.
Springsteen's always good.
Perfect.
It's getting old.
Kevin, I really appreciate it.
Thank you.
Hope to see you.
No matter where you're watching the Sean Ryan show from,
if you get anything out of this at all, anything.
Please like, comment, and subscribe.
And most importantly, share this everywhere you possibly can.
And if you're feeling extra generous, head to Apple Podcasts and Spotify and leave us a review.
