Transcript of #328 Kevin Mandia - The Man Who Exposed China's Military Hackers

The Shawn Ryan Show
03:15:39 162 views Published 10 days ago
Audio transcriber by
00:00:05

Kevin Mandel, welcome to the show.

00:00:08

Thank you, man. Cyber, cybersecurity, saying it— cyber, cyber. We got this. You ready? I'm ready. All right, we're gonna make it cool, man.

00:00:19

I have been, uh, yeah, I always thought cybersecurity was boring until I started, uh, researching you for this interview.

00:00:27

Holy shit, man. Yeah, it's, uh, what a fucking badass. It's a weird world, you know. I've walked the halls of a lot of the headlines people read in cybersecurity, and the press never really gets it, you know. Nobody really understands what it's like to be a victim of a cyber crime, you know, whether it be someone hacking you to steal all your corporate secrets or extorting you, you know. And yeah, hey, you got to serve a higher purpose. Mine's always been the phone rings, I answer it, and it's a CEO on the other side saying, hey, we're getting ransomed and damn it, we're not paying it. And my response is always like, hey, man, we're not paying it. Let's show up. But it's a— Sean, let's see if we make this interesting for everybody. Because I remember a judge— I had testified once in a case and the judge is like, this stuff's so cool. I can't wait till there's like an NCIS show on it or something like that. I'm like, man, if you could see the war room in a cyber case, just really quiet. Looks like your back room right there with those guys in it, you know what I mean?

00:01:26

And everybody's clicking on a computer going clickety clackety. There's nothing to see, um, but you can see the emotional changes in the victims, you know what I mean? You can see it on their faces. So we'll, we'll make it real.

00:01:37

What is— let's talk about what does a victim go through? Yeah, you know, like a worst-case scenario for everybody here.

00:01:43

You know, I— there's nothing— here's bad. You're an executive at a company and somebody breaks in and your email gets released. It's now Google searchable. Every— you know, you're at a— let's say you're at a Fortune 100, Fortune 500 company, and— or your photos get released, you know, things like that. Your private thoughts get released. I, I've seen— I've been in the room with executives when their, their email got posted. Nobody ever should have to go through that. I, I just— it's just a terrible thing to see. Even I get physiologically like, I can't eat. And I'm like, man, this is This is bad. So I think that's the worst thing. It personally impacts people. It gets exaggerated. The press does search your emails. They do write articles about people. Um, and it's happened to actors, you know, their photos get stolen. It's ha— it happens to kids. Like, during our interview today, it's going to happen to some 20-year-old college kid, you know, where their photos get stolen. Nobody should ever go through that stuff. Um, so to me, those are the ones that hurt the most. Companies survive them. You know, you get back up and running, you get your operations running, you get over the reputational hits that, that happen sometimes.

00:02:50

I just feel for the people that, you know, go through losing their email.

00:02:55

Yeah.

00:02:55

And by the way, it goes in stages. They lose their email, and like a month later they lose their family, you know. I mean, some of these things are pretty bad.

00:03:02

Is that how they always start? They always start at your email?

00:03:05

No, the intrusions are all different, right? It depends on who's doing it. You know, you have the modern nations— China and Russia Iran, North Korea. North Korea hacks for money, take them off. But China hacks for espionage, you know. So if they break into your company, they'll break into the defense industrial base, they'll break into any company doing business in China, and they steal emails, they steal things, communications. But they don't post it online, Sean. They don't extort you. They follow rules of engagement that whatever their doctrine is, they follow it. But it's not destructive. They don't change your data. They're kind of like the plight hackers. Um, but criminals, it's gotten hard. I mean, because they want to monetize any breach they've got, so they, they pull on every thread to monetize it, right?

00:03:51

They'll—

00:03:51

if, if the Sean Ryan Show got compromised, what they would try to do to you is steal your emails, steal things that matter to you, and say, we're going to share it with the world unless you pay us $5 million, $10 million. And those are the ones that are, you know, you're always making the least bad of 10 decisions, you know. So, so shortest answer, people hack for espionage and security, securing a nation. People maybe even hack, you know, espionage to me supports diplomacy. And then people hack for criminal reasons. And then probably there's a third, they just hack for the game of it, you know, the attractive nuisance of it. And I don't really respond to too many of those. No.

00:04:31

What do you recommend for people that, like, individuals? Yeah, not who executives, but just individuals who have had their photos, their emails hacked. Do they pay the ransom?

00:04:41

Oh, it depends. Meaning it's already happened? Yeah, it is. I've never said pay the ransom or don't pay the ransom. I've never said that. But I've been in the room when people think about it and I've sat there going, man, I think I'd pay this one. Like, if you're a hospital, somebody breaks in and they've encrypted every machine so they're unusable. And they say, for $10 million, we're going to hand you back a key to unlock all your machines again. You got two options. You're either getting every doctor in a room saying, what surgeries can we do, which surgeries can we not do, um, or you're evacuating patients, or you're diverting ambulances, or you're paying a ransom. In that situation, I'd never opine, but boy, have I said, oh, I get it. You know, I'd pay that one and get back online. So I've seen people pay extortions and pay ransoms. And the difference is, a ransom is to like get a key to decrypt your things. Like, people will ransom and say, I've hacked into your network, I've shut down 10,000 machines, for $10 million I'll turn them back on for you. And, and that one, you know, if lives are at stake or you want to protect the privacy, uh, the second, the extortion is I've hacked in, I've stolen emails, I've stolen client data, I've hacked the law firm and I've taken your briefs.

00:05:58

Those extortions are really painful. It's, I will release the data unless you pay me. And I see people pay it because you're protecting your customers or you're protecting people in general. So hospitals will pay, law firms would pay. Yeah, it's a tough decision. And I'm— luckily, I've never had to make that decision. I hope I never have to. That's brutal.

00:06:26

Damn.

00:06:26

Yeah. Yeah. Think about it.

00:06:28

How do you even know that they're going to stop if you pay them?

00:06:31

Well, exactly. Like, they're only capable of one bad thing, right? And then they're done. And you don't— the reality, though, is usually if you're getting extorted, it's highly probable whoever's extorting you is in a safe harbor like Russia. I've not— others have written that they've seen Chinese actors do this. I have personally never seen a Chinese actor extort a company or even ransom a company. So I think culturally the Chinese really don't do this. It comes out of Russia. And the good news is this, if somebody in Russia hacks Company A in the United States, extorts them, and Company A pays the extortion, let's say they paid $20 million in Bitcoin, an anonymous currency, and then they still leak the data, the reality is, is people just stop paying the ransom. So I actually think there's a governance over in Russia of, oh, if you get paid, you don't post, because otherwise people will stop paying, and they've got a good racket going. So it's been my observation, when people pay, the vast majority of the time, the data does not leak.

00:07:33

Makes sense.

00:07:34

There are exceptions, Sean. It's rare. I can count the exceptions on a single hand. Wow. And there's probably over 1,000 times we've responded to these things.

00:07:44

How often is this happening?

00:07:45

Every day. Every— during this call, during— I mean, this interview, it'll happen to somebody. Can you believe that? During our interview, an 80-year-old American woman will probably lose $200 grand of her life savings. During our interview, a company will get compromised and probably extorted for $5 to $10 million. It is happening at a rate— and this is not a fear, uncertainty, and doubt thing. Nobody knows close the rate. So then you go to the government, say, well, how much money is getting paid in Bitcoin every year to Russian organized crime? It's in the billions of dollars. Holy billions. Like, the lowest estimates are billions. So all we know is the lowest bounds. But as I sit here today, people I've worked with are definitely responding to extortion cases and trying to figure out— and there will be a new one today, a big one. Wow.

00:08:33

Damn.

00:08:33

And they're handled quietly and discreetly, or sometimes they're front page news. You never really know what all. Wow. Yeah.

00:08:41

Well, you're the guy to talk to about all this.

00:08:43

Yeah, exactly. And I sit there and say, hey, let's, yeah. By the time we get that phone call, Sean, like that there's been a breach, there's been an extortion, it's tough. You know, there's nothing you can do about it except work through it.

00:08:58

How do you know, how did you meet Joe Lonsdale? He's the one that connected us.

00:09:02

Oh yes, Joe. Joe, thank you for that. So that's a great question. You know, first we lived in— well, he's a Texan now, right? So he lives outside of Austin. But when he moved to Woodside, California, he has a place there. And so we met there. And in general, it's a small community. You know what people are doing. And he and I just knew of each other. You know, I knew what he had done with Palantir. He knew I was the cyber person. And just over time, you get— you know, if something happened, and he would give me a call, hey, listen, we got a company that needs this, or a company that needs that. And, you know, I've been in the cybersecurity domain for 34 years. Sooner or later, you're either good at it or you're not doing it, you know. I like to think I'm still pretty good at it. So that's kind of it, you know. When people need— when people had a computer intrusion, we had a unique— my company kind of responded to every breach that mattered. And, and so I think I'm on speed dial for a lot of these folks, and probably Lonsdale, I'm on his speed dial, and something bad happened somewhere, right?

00:10:04

Yeah, I'm the emergency room doctor for, uh, cybersecurity incidents.

00:10:09

That's a perfect way to put it. Yeah, let me give you a quick introduction here.

00:10:13

Thanks.

00:10:14

Kevin Mandia, you have 30 years on the front lines of American cyber defense. You began your career as a United States Air Force officer, serving as a computer security officer at the Pentagon and as a special agent in Air Force counterintelligence. In 2004, with no outside funding, you founded Mandiant and spent the next decade building it into the gold standard for incident response. Authored the groundbreaking APT-1 report exposing China's PLA Unit 61398 in a sweeping cyber espionage campaign targeting over 140 U.S. companies, a revelation that reshaped global cybersecurity policy. Led with transparency during the SolarWinds breach, publicly disclosing the compromise of FireEye and helping uncover one of the most significant cyberattacks in U.S. history, impacting multiple federal agencies. Oversaw the $4— oversaw the $5.4 billion acquisition of Mandiant by Google, one of the largest cybersecurity deals ever, and led the company through integration as the CEO. Most recently, you are the founder of Armada, a pioneering autonomous AI agent designed to identify and exploit vulnerabilities like nation-state attackers, backed by a record $189.9 million raised from top-tier investors, including In-Q-Tel, the CIA's investment arm.

00:11:48

That's right. They are in. Why not? We're in America.

00:11:53

How is it working with In-Q-Tel?

00:11:55

Why not? You know, when you get into offensive cyber, the cyber domain has been contested my whole life. Your whole life, Sean, literally. I mean, it's something that people that are faceless, nameless, and have no risk and repercussions can rob people, hack people, extort people, steal information, and they can do it from 10,000 miles away, you know? And so when we started, you know, Armageddon, the whole thing was We want to support the United States government. Like, the cyber domain is contested. Let's at least win when it is contested. During times of peace, it's contested. Imagine during a time of war what it might look like, you know. So, um, yeah, getting In-Q-Tel involved, to me, it just felt like the right thing to do. You want to service the intelligence organizations and the military.

00:12:43

It makes sense. I am curious though, because nobody's really come out and said that they have them as an investor.

00:12:49

Uh, I don't think we do. I don't know how you knew that. It wasn't the first one I would have listed because now, you know, you try to do business in Germany, they're gonna be like, oh, the U.S. government's in inside of Armada. They're not. It's just you want to support the war fighter, you want to support our intelligence agencies, and you want to believe, you know, America can be the beacon on the hill still.

00:13:08

So do they have any specific stipulations that they want insight into your company that other, that other venture capital firms are not gonna are not going to have access to.

00:13:18

Well, you know, it's funny that we're talking in Qatar because the latest Dan Brown book, in Qatar are the bad guys.

00:13:25

Oh shit.

00:13:26

True story. They're the bad guys somehow. It's been my career— like, I'm biased. I believe in the institutions of the U.S. government. You know, I served in the military. People can— people can— every institution can have its downsides and upsides, but you look at the missions of what we try to do, we try to do the right thing. You You know, and, uh, it's the fastest way to bring capability to the intelligence agencies and to the military is, is through In-Q-Tel sometimes. And I believe in what we're doing, uh, and I want to make sure the American warfighter has the advantage in the cyber domain. That simple. Do they have covenants? I'm sure they do. You know, did I sit here and memorize them for your show? No. I do know they, you know, they'll attend the board meetings when we have them. And as an entrepreneur you'll learn if you haven't yet, man, board meetings can be long. And I've been the operator at board meetings. I'm trying to push these things off as long as I can. You know, let's start them when finally— we will start board meetings. That's the problem. I was unfunded the first time, so I didn't have board meetings for the first 7 years of Mandiant.

00:14:32

But now I've done funding and I'm like, should I be doing a board meeting yet? And I'm just going to sit quietly now. Someone will listen to the show and say, okay, Mandy, I have a board meeting. I'm not going to really schedule them until someone's begging for them, you know. But I'm sure In-Q-Tel will show up and, and the others will show up. But we are so early on, what's the value in a board meeting? Yeah, you know, it's, it's, uh, they think there's value. What are you doing with their money? Uh, for me it's let us prove ourselves and let's get some things done first. So I'm not sure I need a 90-day cadence yet.

00:15:03

Right on.

00:15:04

Although I probably just spoke my mind and I'll have one in 2 weeks now.

00:15:09

Yeah, I've been using Ridge for a while, and what I like about them is they take everyday gear and make it cleaner, tougher, and more functional. Wallets, power banks, luggage, travel gear— all the stuff you actually carry and use. In fact, their power banks— I just got 3 charges off one bank at the airport. Amazing. And now Ridge is back with their annual sweepstakes for the 6th year.— and this one is insane. 2 winners get to choose between a Lamborghini Huracán Sterrato, a Hennessey Velociraptor, a custom Ford Bronco, or $100,000 in cash. I'd probably take the Velociraptor. It's got 558 horsepower twin turbo and it's basically American muscle built into an all-terrain truck. That's a hard one to pass up. Even if you don't win, Ridge is still worth checking out. Their power bank has built-in cables, wireless charging, MagSafe compatibility, and enough power for up to 3 full phone charges. Their wallets are slim, durable, and built for everyday carry. Ready to upgrade your wallet and maybe your ride? For a limited time only, head to ridge.com and use code SRS at checkout for 10% off your order and a chance to win Ridge's biggest sweepstakes ever: a Lamborghini Huracán Sterrato, a Hennessey Velociraptor, a Ford Bronco, or $100,000 in cash.

00:16:34

No purchase necessary to enter, but every dollar you spend gets you more entries. That's ridge.com and use code SRS. After you purchase, they'll ask you where you heard about them. Please support our show and tell them our show sent you. As you guys know, once upon a time I was a Navy SEAL, and then I contracted for CIA. We were hunting ISIS, Taliban, terrorist organizations. China was there, Russia was there, the Iranians were there, and everybody's kind of collecting on each other. One thing I learned is how important encryption in protecting your data is. That experience has just always made me extremely paranoid about what's being sucked out of my phone, what information are people getting. I wanted something that could protect everybody, and so we turned it into an application. We call it the Glacier app. We have secure DNS. Now, what's secure DNS? Well, very simply put, secure DNS keeps your phone from being exploited while you're browsing the internet. Just a couple of buttons, your phone's protected. You got yourself a burner number or more. You hit connect, done. You're protected. This is like the real James Bond shit. MI6, CIA level stuff.

00:17:50

Made in the US. theglacierapp.com or just go on the App Store and look up the Glacier App. Take your privacy back. Download Glacier today. Well, uh, before we get too into the weeds here, this is going to be a fascinating interview. I don't think anybody can make cyber as exciting as you can, and with your backstory.

00:18:16

Yeah, wow.

00:18:17

But, uh, everybody gets a gift.

00:18:19

Oh, thanks, Andy.

00:18:20

Got you a couple.

00:18:21

Thank you. Oh, thank you.

00:18:23

Those are Vigilance League gummy bears, made in the USA. Legal in all 50 states. Not that you have to worry about that being out in Cali, but—

00:18:31

And I'm the guy that— true story, it's in South Hall right now in the hotel. There's a little white bag on my table with your gift in it. So, uh, I'm gonna send you something as well, and I apologize I didn't bring it with me. I was so eager to get here, I ran out to the car without it.

00:18:44

No sweat. I got you one other thing too. This is the most exciting one. So here you go. Yes.

00:18:52

So that is—

00:18:53

that's just an iPhone. But that is— that has our new application in there. So I got really paranoid through some of the interviews that I've been doing. And this for me, this for you. I want— I want your honest feedback on that.

00:19:10

All right. You'll get it.

00:19:11

Wow.

00:19:11

Thank you.

00:19:12

So I'll give you the backstory. So I started getting paranoid about a lot of the people that I'm connected with. Okay. In the US, out of the US. Then we did an interview in Taiwan with Bao Shi Kim.

00:19:23

Okay.

00:19:24

Yeah, you know all about China. We're going to talk about it later. So I started getting really paranoid and I wanted to— I wanted about my— yeah, right, my email, about my texts, about, you know, my phone being secured. So I started asking a lot of the former buddies of my— or buddies of mine that were former intel guys, hey, what is the latest and greatest black phone? Um, and so I got appointed this company called Glacier.

00:19:50

Okay. Yeah.

00:19:51

And, um, so Glacier was started by a handful of former Intel guys over at NSA. And so I got to talking with them. I got one of their phones, and their phones are awesome. They, they secure VPN, all-American VPN, secure DNS. They will upload and, and take away your footprint. So like when we went to Taiwan, they uploaded a false footprint, got rid of it when we got back home, can re-upload it if we go back so nothing looks fishy. Uh, and then they have also, they have, uh, virtual numbers. So I talked to them a lot about how to disappear off the internet, and they basically said, hey, you, you have to, you need to keep that number, your real number, sacred. So what we have here is—

00:20:41

oh, that's awesome—

00:20:42

you can put in proxy to it. Any area code you want, it'll give you a list of burner numbers.

00:20:47

It's got a great case. Thank you. It's like bulletproof, right?

00:20:51

Well, so it was hard, but we got it on the iPhone.

00:20:54

Nice.

00:20:54

And because nobody, nobody wants to use an Android, so that was a challenge.

00:21:03

Yeah.

00:21:03

The device is extremely expensive. So when I talked about going into business with them, I said, hey, you know, this is really expensive for the everyday user, not only for the device, but for the subscription as well. A lot of money. And so I said, what would be great is if we could, we could dub this down into an application that's a lot more consumer friendly. So we took everything, almost everything that Glacier has, put it into an app. And like I said, it's, it's, it's a full-blown security suite on your privacy app on your phone. But, uh, so I'd love your honest feedback.

00:21:40

You'll get it. And it's weird. So now one of the things I had to learn throughout my career is how to softer read, write, store, and delete data. What's the app really do? You know, so we'll end up kind of reversing it, you know, we'll kind of try to figure that out. Um, but I think you're right to be paranoid, you know what I mean? It is a strange world where, you know, the digital exhaust we leave behind is way high, way higher than people think every time you browse the web, you know, whether you say, hey, I want cookies or don't want cookies, you're getting them. You know, we, we had a, a company come in and pitch us on a— we got a cookie tracker. And I'm like, you know, we didn't invest in it, but we went out and just tested their software during, you know, while the entrepreneur was pitching us on, hey, listen, this is, this is what happens. And we went to a medical site that everybody uses, and when we connected to it, Sean, of course we got the prompt, do you want to accept cookies or not?

00:22:32

We're like, hell no. We got a bunch. We got over 900 cookies just by doing one search on one site about a specific disease. And those cookies come onto your hard drive, and then when you go to other sites, you're letting like a marketing company know, or you're letting a PR firm know. Or in this case, we looked at all the cookies and one of them was .ru, like we were sending our IP address and the sites we were visiting to somewhere in Russia. And so this whole— yeah, like everybody, we have a whole generation, by the way, that's probably waiving the right to privacy by posting everything on Facebook, Meta. But I get it. It's right. Like, if I had to give one privacy tip, use iOS devices. Use Apple.

00:23:21

Really?

00:23:21

Yeah, totally. It's not— if you look at, by the way, simplest metric in the world on, hey, What's really secure? Look at the payouts. If somebody has a zero-click exploit for the iOS phone, it's— in some places it's $20 million, you know. And Apple itself, I think you can get $4 to $6 million on the bug bounty program. Like, if you find a zero-click, someone just, hey, that looks interesting, they don't touch anything. Um, iOS is hard to compromise, and they really— anyone who's on offense and can compromise it it'll probably be a modern nation and they're really coming after you. Um, but that doesn't mean it's undoable. So I love the fact that you picked iOS as the platform. I think it's right.

00:24:06

Thank you.

00:24:06

Um, and, uh, and I think more and more people probably should think, where's my data going? Who's getting it?

00:24:14

And, well, the other thing that I actually can't believe I forgot to mention is there's a— there's data blocking. So everything getting sucked out of your phone is no longer getting sucked out with that application. So It's— we'll put the link in the description for anybody that wants to check it out. But you just mentioned— so when I was researching you and you were talking about the China, that was the section I was in, the China. What is the 61398?

00:24:45

61398. Yeah.

00:24:47

And when I was researching that, you had mentioned that if anybody had done business in China, you're compromised.

00:24:52

Pretty much.

00:24:53

Isn't Apple doing business with—

00:24:55

Well, they probably were compromised in some way. Interesting thing about Apple, my whole career, Apple's never called and said, hey man, can you respond to a breach here? So, and there's a couple, like if I went through the whole Fortune 100, there might be 8 of them that didn't hire us to respond to a breach and that's it. And Apple's one of them. And they've always, there's a couple places, you know, Goldman's one, you know, they have usually homogenous networks, very similar, lots of tight controls. If anything does happen, they detect it quickly and respond quickly. And Apple's always struck me as one of those companies that's pretty damn good at security, you know? I mean, good to hear. Yeah, yeah, it's, it's just there's something different about them. I mean, think about what they did with the iOS. They closed it. It's not like you can just write an app and do it. You've got to use their libraries, their APIs, and publish it their way, you know? No one really jailbreaks the iOS phone to put whatever they want on it. So if you, for the most part, you almost have to hack yourself to hack your iPhone, you know, a window should pop up, hey, this software is unsafe and you have to go, I'll take it, you know, gotcha, and hit it.

00:26:01

So except for the, the rarest of cases is you're really targeted by like a foreign intelligence service. That's about the only way I think you're going to see a phone get popped.

00:26:11

Okay. Yeah. Okay. Which is good to know.

00:26:15

Yeah. No, it's a good selection.

00:26:16

So thank you. Thank you.

00:26:18

You nailed it right on.

00:26:19

Well, let's, so let's— I want to do a full-blown life story.

00:26:23

All right.

00:26:23

I'm ready.

00:26:24

Where'd you grow up? Where'd I grow up? Foreman of Years, Pittsburgh, Pennsylvania, during like the crappiest decades to live in Pittsburgh. So yeah, we're winning Super Bowls. That's about the only thing we're winning.

00:26:34

Yeah, not a bad thing.

00:26:36

'70s and '80s, every steel mill closing down. You know, I still remember, uh, probably 1983, '84, coming home from school. My dad— I did, you know, dawn on me, my dad never sat at the kitchen table unless he was eating. And I came home from school one day and A, he was home, B, he was sitting at the kitchen table, and then it hit me, something's different. And he lost his job, you know what I mean? And I remember in an instant, you know, nonverbal communication could say it all sometimes. I instantly thought, man, he'd pick cancer over this, you know what I mean? And so Pittsburgh was a rough place to grow up. And I spent, you know, the late '70s and early '80s there and then moved away from there and then went back to there. And I still remember when we left it going, man, I don't ever want to go back there. And then 3 years later, my dad's like, hey, we're heading back. So anyway, formative years, Pittsburgh, great people, tough town. I think if you lived in Pittsburgh from 1970 to 1985, all you saw is, you know, a tough place.

00:27:34

Yeah, probably like Detroit, you know what I mean? Sister city Detroit. I feel for that place.

00:27:38

Yeah. What were you into as a kid?

00:27:41

Football, right? It's Pittsburgh, you know, football, baseball, basketball. I was the youngest of 4 boys. I think that matters. You know, you got somebody, you got a live-in Alice Cooper fan and your older brother, you know, you learn about rock music. You know, I was 10 years younger than my oldest brother. So I got a real education on music early. Everybody played football. Everybody, you know, it didn't matter where, you know, it's a, you go in the backyard and pummel each other. You had to, you know, so it was football, baseball, basketball. And then you go to entertainment. It was like Magnum P.I., Quincy, shows you probably don't know.

00:28:18

I mean, oh no, I know Magnum, P.I.

00:28:20

You got Fresh Prince of Bel-Air. I got, you know, Quincy. The, uh, but you get it. It was, uh, you know, Pittsburgh was a black and white city. You know, you move away from that and you get to see color. But in Pittsburgh, what I meant by that is just it was gray. It was, it was like, it felt like it was always winter, you know. And in hindsight, you don't know it till you leave it and look back on it. It was a depressed state. Like, the people We're all struggling, you know, period. You know, and I was in one of the nicer towns, but I think I was into sports, you know? And then I had a father who was old school, right? Old school is, "Hey, son, get A's." What that meant is get A's or I'll kick your ass. You know what I mean? Get A's or life's gonna get real hard for you. I mean, I didn't want to find out what the alternative was.

00:29:08

I found out it wasn't great.

00:29:10

Yeah.

00:29:10

Yeah.

00:29:10

Nah, shut up. Well, you know it then, right? I mean, my dad had a set of rules that if you broke them, you did get hit, and it was fast. I always was like, how does this large man move so quickly? You know, uh, but he was consistent about it. You know, people are like, hey, corporal punishment is bad. For me, at the youngest of 4 boys, I think it was necessary in a way, you know what I mean? Like, we were probably going to be pretty— my dad liked to order quiet, clean, and I don't think you would get that naturally without some enforcement, you know, and, uh, at the edge, as they say. And my dad had that. So I knew every time when I was going to be disciplined, it never surprised me other than how fast he could move to do it. And by the way, it would have done no good to run because that would have just made it worse. You just got to stand there and take it. It wasn't like he beat me. It was just he had a discipline to it. And so going back to the original question, what I was into was probably the same thing every teenage boy in Pittsburgh was into— sports.

00:30:09

Except I was a Vikings fan for some damn reason. Yeah, right on. Figured that one out.

00:30:14

So how did, how did you— were you into cybersecurity by the time you joined the—

00:30:19

no, it didn't even exist. So I get in the Air Force in '93, but, uh, you know, I graduated college in '92, and back then there was a little bit of a lag. You know, we had the Clinton years, there was a lot of rifts going on, and you could do ROTC and never actually get orders, you know. So it was an interesting time for the military. It was time of peace for the most part. We had done Kuwait in 1990, Desert Storm. So I graduated college in '92, but I grew up, I thought Magnum, P.I. was cool. He's former military. He solved cases. I always felt like you, you got to have a mission bigger than self. You got to want to contribute to society. And I grew up a forensic fan. I mentioned Quincy earlier. I used to watch Quincy going, hey, man, let's solve cases. I did computer science in college from '88 to '92 because I grew up with Pong. I still remember the first Pong game, Nintendo.

00:31:10

Wow.

00:31:11

Intellivision, the Odyssey by Magnavox. Like, I grew up with the whole Atari 2600. You grow up these games and that kind of gets you into computers. So by the time 1980 or 1981, I'm 10 or 11 years old. My Christmas present was the TRS-80. Color computer. Like, other kids are asking for, I don't know, Stretch Armstrong and Rock 'Em Sock 'Em Robots. And I'm like, hey man, can I get a computer? And my dad, my mom, my grandparents all pitched in and bought me like this $700 Christmas present, which back then is like, are you kidding? That's like better than a car back then, actually, Sean. So in hindsight, I should probably be more thankful. So 1980, '81, I get my first computer. And even though I'm playing football, baseball, basketball, running track, And now he's pummeling people. And I'd come in and be like, hey man, I like this computer crap, you know? So I kind of grew up with the computer. I got computer science ROTC at a small school in Pennsylvania called Lafayette College where I went all out. I took a pencil, filled out the Common Application, applied to one school, got in and went there.

00:32:17

You know?

00:32:18

Nice.

00:32:18

There was none of this 20 schools, 10 schools. I had like no plan B. I just applied to Lafayette., did ROTC at Lehigh and, uh, did computer science, uh, and I got stationed at the Pentagon in 1993. And the way I got into cybersecurity was, uh, I got stationed at Pentagon with 6 second lieutenants, and, and, uh, we were all waiting in line to go in to see an O-6, a colonel, full bird Air Force colonel. We were stationed at what was called the 7th Communications Group. And we're all, you know, chicken-shitting out in the hallway. Who wants to go first? What do people want to do? And I like to tell you there's this elaborate plan for me to go into cybersecurity, but what really happened is I went first. I was like, I'll go meet the colonel, I'll go figure this crap out. So I just get first in line and I go in, and the, and the O-6 behind the desk gives me, uh, and literally it was the whole thing. You go and, you know, stand at attention, go to at ease, and, and wait. And he lays out 5 options for my next couple years.

00:33:20

Here's what your assignment can be. So I actually had a choice, and all the choices were bad. And it was the weirdest thing, Sean, right at the end of it, I still remember it, he was like, oh, oh, when we have one slot left, one job left to do computer security. That's what he called it. And I remember thinking all 5 options prior to that were horrible, like it would have sentenced me to death. It was like job control language, mainframe programming, and the basement of the Pentagon. When he said there was one slot left, I'm a sucker for there's only one left, you know? And so I'm like, I'll take that. There's only one left. That's valuable. And, you know, in hindsight, I backed into, you know, it ends up playing out very well. I loved forensics. I ended up getting a master's in forensic science at GW on my own time while serving. And computer security worked. Like, immediately I had this job doing computer security.. And what it was is who's accessing what. And about a year into me doing that job, it was 1993, the Air Force put eyes on the network for the first time.

00:34:26

I mean, for the first time ever, we started watching what are people doing on the network. So I kind of got to grow up with computer security. You know, we started watching people. The Department of Energy created a tool called the Automated Security incident measurement tool. Interesting. And we deployed it at the Pentagon. And for the first time ever, we could see what are people doing, like what files are they transferring and what commands are they doing and where are they logging into. And when we lit it up right away, we recognized, wait, we're not the only ones on this network. You know what I mean? Who are these other people on it? And so by 1995, I cross-trained into the Air Force Office of Special Investigations from computer security to do computer intrusion investigations. Um, the military was starting to use the internet, you know, from '93 onwards. So, um, we had to start figuring out who the hell's on our networks and what the hell are they up to.

00:35:19

Who was on the networks?

00:35:21

First one I ran into was China. Literally go all the way back to, um, I think it was summer '95, might have been summer '96, one of those summers. We, uh, You know, at that point we had the Air Force Computer Emergency Response Team. The Air Force had one. I don't think the Army had one yet. I don't think the Navy had one yet. And then the government had one called US-CERT out of Carnegie Mellon University in Pittsburgh. And so maybe there's something in the water in Pittsburgh that gets you into this stuff. But I, I remember there was a West Coast university I'm in the Air Force Office of Special Investigations, and our ASIM boxes showed something like 20 Air Force bases were logged into from one university. What the hell's going on? Like, no university should be logging into that many, you know, Wright-Patterson Air Force Base, Oak Ridge, Lawrence Livermore, Los Alamos. Oh, shit. Wright-Patterson, all of them. And they were— and so I flew out to the university, and at that time frame, I'm in the United States military. I go to this university. And I'm like, do you mind if I monitor all traffic to and from this machine?

00:36:29

Now, everybody's listening to this will be like, the government watches everything. We really didn't. Back then, I had to brief the Judge Advocate General. Hey, this is what I want to do. And to the Air Force's credit, if we did what we would call a wiretap and there was nothing fruitful in it, oh, it got killed fast. Like, you had to have fruitful, real results, or a JAG was going to be like, Stop it. Get out. There was a great control to not wantonly watch, but the university allowed consent. Is it still like that? I don't know. I often wonder if the military is the same as when I grew up. Maybe a topic for later, because to me— but then it absolutely was. I remember going, man, I need to tap this because someone's coming from somewhere in the world into this system and then from there to all these military installations. So I got consent to monitor. To the college's or the university's credit, they were like, yeah, go ahead and do it. And then I, I— the way I did taps back then, I just ran software on the machine itself. You know, it was, it was a Unix machine, and I watched all incoming traffic.

00:37:32

And the first day, I'll never forget this, Sean, summer of '95 or '96, it was one of those two, the very first day I did the tap, somebody was logging. This is how you go one hop back every time. Like when some— if somebody hacked you, we'd only know the first IP address or first address they came from. But in computers, you can connect to connect to connect to connect, and they're called hop points. And everybody obfuscates where they're really sitting. If you're sitting in Russia and hacking the Pentagon, you're not going straight from .ru to Pentagon. You're going from .ru to the UK to China to wherever you want.

00:38:10

How do you pick those?

00:38:12

They compromise them first. Like if you're on offense, you have a network that you use to launch your attacks. And for the most part, you almost have a team that maintains that compromised infrastructure for you. So if I'm a foreign intelligence service, I have a team that maintains access on all these intermittent sites, not my real targets, just sites like universities and businesses. And, um, it's called a non-attributed network of victim machines. At least this is how other nations do it against the United States. And then they have their operators use that infrastructure. And that's exactly what we ran into in this case. I do this tap at a West Coast university. The very first morning I go in and like download the files to look at what happened, somebody came directly from Beijing into West Coast University using the account of a Chinese foreign national that went to this college but had since graduated and logged into 37 or so military installations. And each login was somewhat haunting. They used a user ID like S. Ryan, and then a passphrase. Then the next one, they would go to like RightPat and go John J.

00:39:19

Smith and the right passphrase. They were validating accounts at all these different places, and I had the right choke point to see all the traffic. They came to this one machine, logged into RightPat, logged out, logged into Los Oak Ridge, logged out, logged into, you know, Los Alamos, logged out. RightPat, keep going down the list. And They never fat-fingered the passphrase. They got in every time. And I remember thinking, how do we fix this? Like, you can't— you call 37 bases. Who do you call? They were hitting Army, they were hitting Air Force, they had, you know, the Marine Corps. They hit us all.

00:39:55

I mean, just, just for the viewer context here, those are the most secure, secret military bases that the U.S. has.

00:40:05

Yeah, it's just the protocol. Yeah, and it was just— it was the Defense Research and Engineering Network is essentially what these guys are in. And, and the unfortunate reality in hacking, or fortunate if you're the offense, like, if I break into the Pentagon, it's just a matter of time before I break into all the other military installations. If you break into an Ivy League school, you're gonna end up being able to hack all the Ivy Leagues because that's just where the traffic goes, that's where the information is shared. And, uh, and that's what happened here. I don't know where they originally broke into, but it was extensive, and that was in the '90s. So, and I remember there was no one to call. Like, that case went on for like 10 years. I mean, it had code names and classified names, and it just kept going. There was nowhere— I was a first lieutenant at the time. I mean, what do I do, call the base? Like, hello, operator, I need the cybersecurity guy. There wasn't, uh, there was no way to remediate it that simple. So instead, what we ended up doing is running an operation largely run by the military jointly with the FBI.

00:41:08

And we did counterintelligence. We just watched it. And then we found the Russians. For me, every day— let's just shortcut. It is 2026. My first incident response is 1995. So it's been 31 years. I would say every day of my 31 years, we've been responding to an intrusion out of China somewhere on the planet. Wow. Every single day. And by the way, not just one, way more than that. So they have mass. They have just the scale that they can operate at that's pretty, pretty high. And then probably the Russian SVR had counterforensics earlier, so they would go dark on us. And back in my day, Sean, if I responded as an Air Force special agent, what was amazing to me, if I responded to Russia, every time we caught them, they just went away. They were like, ah, you got us. We're going to go away for now. And it was almost like rules of engagement. If they got caught spying, they just went away. And you can tell when someone's monitoring what you're doing. You can find the tools we use, or you can see that we're starting to remediate and clean up around you, or we shut off the account that you're using, or we change passphrases.

00:42:14

And the Russians never let us observe them, period. From literally from 1995, 1996, anytime I responded to a Russian-based intrusion, they were super stealthy. That did change right around 2015 where they got louder and probably they stretched their mission too much to do counterforensics and counter-surveillance stuff. But they had a 20-year run where we'd have them in our sights and lose them. And I went years not finding them. Like, literally, we're like, we know they're out there because that's their day job. You know what I mean? They're paid to hack us. They show up every day, badge into a building and do it. But most of those cases probably got classified. And I was on the outside by then, but they were really hard to find. China was more like a tank through a cornfield. I mean, they were just like— they didn't care if we saw them. Uh, they didn't do counterforensics, they didn't change the data, they didn't extort, they didn't do anything. They just stole everything, you know.

00:43:10

Who's— who, who do you think is better? It sounds like Russia's better at it, you know.

00:43:14

Yeah, for the vast majority of my 31 years responding, Russia was better.

00:43:19

Better tradecraft.

00:43:21

Yeah, their operators really didn't like getting caught, you know. And they just— here, here's an example. Like, I think China just had so many people, Sean. Like I, I just said the other day, I knew a lot about religion because I took art history. I feel like I know a lot about the Chinese culture just by responding to intrusions. They definitely threw people at it. And here's an example. If, if a, if a Russian hacked your machine, what they would do is they would bring their own way to search your machine. They would hack your computer Then they'd upload a file that would search everything on your machine looking for specific keywords, whatever they're after. Or they'd just grab your email. And even when they grabbed email, they would minimize it. They'd grab like the last month's worth or something like that. They were always very precision strike. If a Chinese operator got on your machine alphabetically, file by file and directory by directory, they'd look through your machine because they had— and I thought about it— they have human capital. There's 8 hours in the day. There'd be an operator on a keyboard going, I'm on Sean's machine.

00:44:20

Let me just look at this. File. And, and literally, they almost did it alphabetically. The second thing I noticed is early in my career, the SVR would always steal— the Foreign Intelligence Service out of Russia— the SVR would always steal specific files responding to what they wanted. They were just real good at that. The Chinese would just compress a whole directory and steal it. Like, if you ever use like ZIP or something like that, they would say, oh, this directory called Documents looks interesting, I'm going to take the whole thing. So I could actually tell who the operators were just by the data theft. I'd be like, that was Russia, they took 32 files. That was China, they took 3 terabytes, you know, of everything. Because China would even steal operating system files that were the same on every machine. But it's just they had operators that would go, that was an interesting directory, I'll take everything in it. That was an interesting directory, I'll take everything there. I'm sure they had a unit that was more precise, more stealthy. Every nation does. But, um, China took front seat in 2020. You know, every year at the end of— so from 2004 to 2025, I worked at Mandiant, you know, my company.

00:45:28

And, and we— at the end of every year, I'd be like, hey guys, brief me on the coolest cases we got. And for the most part, I got involved in those during the year. It was in 2020 where I saw the Chinese government break in using what's called a 0-day attack. There's no patch to it. Similar to like when we were talking earlier about Stuxnet. Zero-days are attacks that work against an application and you can't stop them. They will simply work. And the goal of a hacker is to get remote access to your machine. So I can be 10,000 miles away and get to your phone or 10,000 miles away and get to your server or desktop. And then it chooses you. I want your email. I want your files that you've created. I want reports that you're writing about our Supreme Leader or whatever it might be. And, uh, in 2020, the most expensive offensive attack was done by China. They used multiple 0 days to break into a defense industry-based company, and everything they did there was special. Like, everything they did had to be custom crafted for that environment. And that is, in my whole career, that is very very rare.

00:46:35

And China did it. So I'd say China's number one now for scale, scope, and sophistication. And then China decided to get stealthy in 2020 as well. They weren't prior to that. They decided to, from a forensic standpoint, leave less fingerprints.

00:46:51

Wow.

00:46:52

And Russia went the other way, by the way. Russia is now like, we found them, you know. And I think Russia, with conflict and everything, they're just operating at such a scale and scope that they can't— they don't have enough operators to clean up after themselves. It's very manual. To clean up after yourself. It is not— it takes a human intelligence on a keyboard to say, I don't want to leave a trace on this machine, so I have to edit the log file, take myself out, you know. So the, the, uh, counterforensics of Russia is down a notch or two right now.

00:47:21

I mean, you were, you were tracking nation-state hackers before the majority of people even had email.

00:47:29

Yeah, I think we were the first ones to do it.

00:47:31

When you walked into that, what was the program you were at? What was it called?

00:47:37

Well, so I made it. That's kind of what— Yeah. So I had a master's— Paved the way. Yeah. So I had a master's in forensic science. So you can think about all these intrusions I'm responding to are like crime scenes. Like, what are the fingerprints left behind by the intruders? Well, it's the malicious code they run. It's the commands they execute. It's the encryption algorithms they use. It's the type of files they steal. It's the type of targets they even compromise. And so with my forensic science background, I created a thing called an indicator of compromise. I'd worked enough cases where we're like, we got to call the fingerprints something. So the indicators, and then we started just bucketizing them. So we'd respond to Company A and be like, oh, the attack came from here. They use this software. And as we bucketized or cataloged the evidence, we started just seeing the same people over and over. They use the same custom code to break in. Um, like, I'll give you a weird one. Like, if you break into, uh, the two dominant operating systems are Unix-based operating systems, Unix and Windows, and, and Mac is a Unix derivative.

00:48:40

It, you know, in, in Windows, if you break in, you do what's called a directory command. I've broken in, I want to see what's on your hard drive, I'll do dir and just kind of look at what's on there. Now, and the Russians, when they break in, they do a directory listing of everything on your drive. And that's all they do. It's really smart. It's like great recon. They don't even poke around sometimes. They break in and go, just show me a map of everything on the machine. They download the map, then 5 days later come back and just take what they wanted. The Chinese would break in, show me everything, and then go through it alphabetically with a human just sitting there 10,000 miles away looking at every single file and doing it. So we even cataloged— in Unix, the DIR command is called ls for list. And we would catalog, did they do an LS -AL option or LS -LA? Different operators typed it differently, and we could even get down to the speed at which they typed. I mean, we were tracking on a lot of cases, we had up to 650 criteria we would track, but only like 10 mattered.

00:49:43

Long story made short, we just took the fingerprints of each group, and it turns out that Chinese did great training and the Russians did great training, so they were actually really consistent, you know, the commands they typed. If you're a kid and you break into a machine, you just get undisciplined. You start going, I'll check out this directory and then randomly this directory and then randomly this, and I'll look over here and I'll do this. And they're all over the place. It looks like a monkey shit fight at the zoo, right? And then, uh, you responded, yes, we are, and it's just all economics. They did a directory listing and left. That's it. Gone. Kids don't do that. Foreign intelligence services do that because they're going to come back in after they've looked at the file listing, and just by names alone, they know what they want, or even the apps they want to steal. And at the time I started responding to intrusions in '95, we didn't export our supercomputers. So all our modeling and simulation of modern weapon systems were done on supercomputers, the Cray C90, the Origin 2000. The front nodes to all these supercomputers were what we would respond to.

00:50:52

The Chinese and Russians would hack these things and literally they would run our modeling and simulation on our systems, but export the output all the way back to China and Russia. Isn't that amazing? So one of the first cases I ever did with Russia They were literally running— they were stealing stuff and they were running the modeling and simulation of a certain system we were creating, unclassified though. But they were exporting the display right to their desktop. So they were just sitting back watching, oh, there's the model and this is how it looks. They were literally stealing it that way in '95. So again, though, those fingerprints, that's just an example of fingerprints, the commands they type, how fast they type, the malware they use. Who they target and how they operate. At my company Mandiant, we started creating these dossiers basically, and we were boring. We didn't know what to call— we didn't name the groups like, you know, this is Fluffy Snuggle Duck and this group's called, you know, whatever, but Bad Rabbit. We just called them APTs. Advanced Persistent Threat 1 was China. It actually was PLA Unit 61398, and we just named them APTs.

00:52:03

And now we're up to, I don't know, 50-something And that's where we have definite attribution. Like, we can get you to the building they're coming out of, you know. So when we started this, we had maybe 40 groups in the first 8 years that we had fingerprinted. Only 40 different fingerprints for every cybercrime. Now we're into, I don't know, 6,000.

00:52:22

How big was your team back then?

00:52:24

Oh, by the time— I mean, it was one, me, and then we grew it to about 5. One person for the whole country? No, no, no, no, no. I, I started it, right? But we were about— by the time we're labeling groups, APT 1, 2, 3, or 350, 350 people, all ex-government. Like, at one point, Mandiant was 500 people, and I'd say 350 came from the U.S. military.

00:52:48

I'm sorry, I meant, I meant—

00:52:50

oh, just the intel, the Air Force. Oh, in the Air Force, when you were a special agent, when I was doing that, there was 13 of us. I think we doubled it to 26. Yeah, it doubling. And, you know, cyber was new in, in 1995 when I was in the Air Force doing this. And, um, so they kept doubling the teams. Now I bet it's hundreds and hundreds. Like, if you're a special agent in the FBI today and you're not digitally forensically educated, you're not very useful. I mean, you have to know how networks function, how every case has digital evidence now. Counterintelligence, crime, espionage, all of it, period. But when I started doing this, there was like the computer-aware agent and the non-technical, non-computer-aware agent. I think that one's almost obsolete at this point, you know, unless you're a great accountant or you speak 20 languages. I don't know how you can be an agent today investigating anything without understanding digital forensics, you know. So small team, 13, 14 of us. Massively grew even while I was doing it. We were called Computer Crime Investigators, and we did the— and, and the FBI had a thing called the CART team.

00:53:59

I don't even remember what that stands for. It was like computer forensic stuff. And all I can tell you is we're always— no matter what, it was almost like we had a sticking line where we're always 6 months behind. No matter what the case was, we were 6 months behind on the forensics, you know. It was like, uh, because it was real hard to keep up with all the digital evidence piling up.

00:54:15

So Here at Sean Ryan Show, we cover subjects that get complicated fast— intelligence, war, technology. And when you're dealing with topics like that, the hard part isn't just finding information, it's making sense of it all. That's why we use Claude. Claude helps us take a messy topic and start connecting the pieces— timelines, contradictions, different angles, follow-up questions, things we may have missed. It helps us slow down the research process and think more clearly before we ever sit down for an interview. And we use it across the show— episode prep, research, strategy, and even our hot question segment. It's become one of those tools that helps sharpen the work behind the scenes. Claude is the AI for minds that don't stop at good enough. It's the collaborator that actually understands your entire workflow and thinks with you, whether you're debugging code at midnight or strategizing your next business move. Claude extends your thinking to tackle the problems that matter. And with features like deep research and connectors, Claude can help pull context together from the tools you already use and turn complicated information into something that you can actually work with. Companies like Stripe and Shopify trust Anthropic with the rollout of AI in their businesses.

00:55:36

For problems worth solving, get started with Claude at claude.ai/srs. That's Claude.ai/SRS and check out Claude Pro, which includes access to all the features mentioned in today's episode. Claude.ai/SRS. Let's talk about— if we're ready for this, let's talk about exposing China. The APT-1 report, February 2013, released a 76-page report publicly naming PLA Unit 61398. Operating from a 12-story building in Shanghai's Pudong District.

00:56:19

Yeah.

00:56:19

As the source of espionage against 141 U.S. organizations across 20 industries. Unprecedented.

00:56:27

Yeah.

00:56:28

Stole technology blueprints, manufacturing processes, test results, business plans, and executives' contacts list.

00:56:36

Yeah.

00:56:38

How did you—

00:56:39

I mean Huh. Well, this is— yeah, it happens.

00:56:45

All you—

00:56:46

it— yeah, but I think the government knew, you know. So this was 2013. The backstory on that is I start Mandiant in 2004, and I had a premise: let's respond to every breach that matters. Because in the cyber domain, prior to Mandiant, here was the intelligence model in cyber. It was McAfee and Symantec antivirus. You've probably heard of them, right? McAfee and Symantec. You'd run antivirus on your machine If antivirus missed a bad file, a malicious file that was stealing your stuff, the only way Symantec and McAfee got smarter is you would be like, hey man, you missed this malware, so I'm gonna submit it to you so that you detect it next time. Well, here's the problem. My mother's never gonna find malware on her system, and Sean, you're never gonna find it either unless you read an 800-page book I wrote that would bore the hell outta you. You know, it's hard to find this crap. It's ridiculous. So I decided we need a new intelligence model in cyber. Let's learn from all the red teams out there, the offense from Russia, China, the criminal element, North Korea. Let's respond to every breach that matters and learn from it and build the defenses.

00:57:56

Because I thought antivirus— and I hate to say it— thinking Symantec and McAfee was securing you at that time was like believing in the Easter Bunny. I mean, it literally was so easy to evade. I was actually talking to one of your guys earlier, and we were talking about he even experimented with offensive cyber and could evade AV because all you had to do is encrypt or compress your executable, put it on your machine, and when it executed, it would decrypt itself, meaning it had no signature, so AV would miss it. So long story made short, we needed a new model in cyber. How do we build better defense? Well, let's actually get in the ring with the offense. Look at what the hell they're doing. So I think I was the first company ever started with, we're going to respond to every breach that matters. And I got to be honest with you, I didn't know if breaches would go on forever, but I had that phrase. I think I made my first website, and you're an entrepreneur, so you know there is no website team. I had to make my own website back in 2004, and I literally wrote on the website, The first phrase was, you cannot solely rely on preventive measures.

00:59:01

And that was boring. So I went with security breaches are inevitable. No one believed it. I think the only reason Mandiant was successful is that a premise, security breaches are inevitable. We'll respond to everyone that happens so that we can build a better defense against them. First knowledge, first mover knowledge on what the bad guys are really doing to circumvent defense. Nobody believed that premise, so we had no competition. So every damn major breach, my phone rang. I still don't know how the hell my number got out there, but we had to be good at it. And then everybody recommended us, and breaches took off. In 2004, when I started the company, every election year, both sides have a problem. I can tell you that right now. So in 2004, you get to respond. If you respond to Pepsi, you don't respond to Coke. If you respond to the RNC, you don't respond at the DNC. But those things are heavily targeted. But in 2004, when I started Mandiant, right in the summer of 2004, we were only like— I started the company February. By June or July, we're 9 people in a basement in Old Town Alexandria.

01:00:05

And we get a phone call from the defense industrial base. And we couldn't respond to it. We're already fully pegged responding to a breach somewhere else because it was an election year. But it was, uh, Honeywell. And I guess I can say that now because that was 22 years ago. They were the first ones I saw where the Chinese government that I was responding to in DOT MIL, the military, just went, I'm going to shoot the headlight over here and hit Honeywell now. Then they go through the whole dip. They go after Lockheed Martin, they go after Boeing, they go after Rolls-Royce, they go after UTX and Raytheon. And it was considered— companies, all of them, well, you know, they'll— they are heavily attacked in the cyber domain every day by China. Fair game. I mean, that one's contracted or coming for you. And, and these companies have like— what's funny, people would be like, man, the banks have great security. Well, in cyber, the best security I ever saw at one point in time was Lockheed Martin. I mean, what they did on defense was I mean, all the defense contractors, trust me, they do everything they can to secure their stuff.

01:01:14

But they also have these joint projects that are, you know, a bunch of mad professors getting together. But in 2004, 2005, I saw the military of China suddenly expand scope and go after our defense industrial base. And that was right when Mandiant started. So all those companies hired us and we would respond. And I remember I would brief, hey, this is a guy in Beijing doing this. And, or, you know, It was the beginning of it, you know. That's when we realized China's all over our networks. I guess I always knew it. .mil, .mil felt fair game. I think nobody really expected them in China to suddenly say, hey, let's hit .com. And then they went way down .com. They— like, if you're a law firm, if you were, um, if you were an accounting firm, if you were doing business in China in any capacity, they had guys in uniform hack you. So they don't separate economic dominance from military dominance in China, probably. You know, they hack— we would hack on offense as a country for security purposes and defense purposes. China hacks for economics. So, and then since then, Sean, everything went public.

01:02:23

General Alexander, when he's running the NSA, largest theft of IP in human history. Um, you know, to the credit, Chinese didn't damage anything. They didn't delete stuff. In my whole career of responding to the Chinese threat actor, I only saw like one operator delete the logs once, you know what I mean? They leave everything there, but they got way more surreptitious lately. So yeah, and since 1995 till now, China's heavily targeted our defense industrial base.

01:02:51

What are you thinking when you figure out that the CCP is hacking into our defense tech companies, our like Lockheed, Raytheon, like, these are the first— these are the companies that hold the keys.

01:03:06

Well, I think, you know, a lot of folks think when a nation targets you, you should be able to withstand it. But I've always thought, like, the analogy I use— well, I'll use this one. You were a SEAL. If a SEAL wants to rob the LEGO store at the mall, they're going to evade Paul Blart the Mall Cop and rob the store. You know what I mean? No problem. When you have the Chinese government trying to hack you and you're a company, you will lose over time. There is nothing— I don't think it's reasonable for the American people to think any company can withstand a foreign intelligence service trying to break in in cyber domain. It's not. And, and so I remember early on, every victim company wouldn't tell anybody, you know. But it became— because you'd get— you'd say it, and then you'd have pundits on the Hill go, hey, what a responsibility to let the Chinese hack you. Are you kidding? It's like your grandmother in an Ultimate Fighting Championship. It's simply an fair fight, and it still is today. Even for the companies that do everything they can in cybersecurity, you really don't want to come under the lens of the SVR and, and, and the MSS when they decide to go on offense.

01:04:13

It's, it's a— it's a tough thing to do. So, so what— yeah, so we had like 8— that's why we went public in 2013. I mean, I just told you, in 2004, the first company I saw China go, hey, we're going after, was Honeywell. I just, I hate saying that out loud. I don't know if I've ever said that publicly, but with this amount of separation, they can live with it. Um, they, uh, and you just go, man, you know, the thermostat company, but they also make, you know, helicopters and dashboards, and they're a defense contractor. But they all had the, the Chinese come for them, and, and, uh, it's, it's a sucker punch. At that time frame, there's no— actually, true story, Sean— there was no defense for how China was breaking in back then. It didn't exist. We had no software to detect it, really. You could just log in, you could just do things. There was no reasonable way to defend yourself in the cyber domain against the nation back then.

01:05:07

Shit.

01:05:08

Yeah.

01:05:10

I mean, that's— Yeah, pretty fucking scary.

01:05:14

Just dawned on me just now. Yeah. You know what I mean?

01:05:17

I mean, what dawned on you back then when you saw it happening?

01:05:21

Back then you're more tactical. Yeah, you know, well, that's why we went public. You know, we had Mike Rogers, uh, congressman from Michigan. We had a congressman from Maryland. They wanted to do— they wanted to make it so you could share when you've been compromised, like stop like hiding the fact that we're all in this together. They wanted to have more of team ball, like Team America. So we decided let's help the U.S. government with like some information sharing that when you're hacked and you know it, you can share that information and not get condemned by the government for doing it. You know, you kind of got a safe harbor. And so we, we recognize two things, kind of. There's like 8 reasons why we went public with this report. I'll give you 3 of them. First, Mandy and I at the time were a bunch of ex-US soldiers, and we were like, screw China for doing this, you know what I mean? So I wasn't going to be able to stop going public. Our— my team wrote this. I was just a face on it. But we knew it was China from 2004 onwards.

01:06:17

So it took us 9 years before we finally just said, hey man, let's just tell the world what the hell is going on here. Second, um, you could feel the government— the government knew about this, but they didn't know what to do about it. And at least, you know, the House Intelligence Committee was like, let's pass a law that allows people to share information so we can defend each other. Um, and then the third thing was the CEOs were like, what the hell? You know, I would sit down with the CEOs of these companies, they're like, we're doing a joint project with China, why the hell are they hacking and stealing crap. And, and, you know, the companies knew, hey, it's on us to defend ourselves. But they also, at some point in time, I remember thinking, hopefully, maybe if we just bring it up, the heads of state would actually come up with, hey, let's, let's knock this crap off. You can hack us for espionage, but don't hack, you know, Disney because they're trying to open Disney China, or don't hack, you know, whatever, soft drink company or somebody else because they're trying to do some bottling in China.

01:07:15

It was, it was time to have dialogue. So we did go live in 2013 and, and do that. It just so happens that on the day that Obama was going to meet with Xi Jinping to talk about some cyber stuff in optimistic-sounding Sunnyland, California in 2013, uh, that was when, uh, Snowden leaked, and that stole the show. So I, I've never— you know, I've always believed since 2004 when I first started responding as a private company to these intrusions that neither China nor the United States really wants a whole cyber conflict. You know what I mean? Neither nation really wants it. And that, at least that's two nations that can come to the table and probably have a dialogue and come up with rules of engagement. I don't know if you can do that with Russia, too much criminal element. I don't think you can do that with North Korea, and I don't think you can do it with Iran. But China is the one place where I've seen them follow rules. We have to infer the rules, Sean, when we respond. But China follows rules and etiquette when they hack. Still, their operators are predictable.

01:08:18

Interesting. What kind of stuff did they steal?

01:08:23

It would be hard to say what they didn't, you know. That's the reality. And that's why General Alexander's— you read the testimony from the director of the NSA, largest IP theft in history. Admiral Rogers after him, General Nakasone, all of them kind of allude to China's kind of taken a ton now. There was a dialogue after that report. Here's what's amazing. At Mandiant, what we were doing is we were kind of monitoring victim networks, meaning we saw traffic coming in and out with consent. And the whole defense industrial base was working together by then. They started a whole consortium where Raytheon and Lockheed and Boeing, they all worked together to figure out what's China doing? How do we thwart this? So they do play team ball now, and it's actually pretty organized. But I remember, uh, at the time going, we're seeing over 70 companies a month compromised by China right now, just in our little network of watching what they do. After we went public with that report, it went down to zero for a while. So I think they noticed we changed behavior. Or some say, well, maybe just lost vision on them, because when we wrote that report, one of the things we didn't kind of say in the report is we provided that trace evidence, the fingerprints We provided over 5,000 fingerprints of this is their infrastructure they're using to hack us.

01:09:41

This is the malware they're using. So all the defense companies that make software to stop it, we could just stop them. So we kind of burned their infrastructure. We burned their methods. Their TTPs, or tools, tactics, and procedures, were fried. So we fried it. So they had to go away anyway and recreate all that stuff. But again, going from anywhere from 10 to 70 companies hacked a month just in what we could see, and I could tell we probably saw less than 1% of what they were doing. We'll never know, did we see 80% or 2%? It was probably closer to 2, down to zero for a few months, and then it starts creeping back up again.

01:10:16

Just for the audience, can you, can you elaborate on some of the stuff that you thought was most concerning that they got— they, they hacked access into?

01:10:26

Flag officer's email. I always hated that stuff, you know, because you get to see what contracts matter, what weapon systems matter. I, I'd never read those emails, you know, I didn't want to know, you know. But when you see a communication of a high-level official get stolen, I've always felt, oh man, like there's unvarnished truth in that, period. Like no matter what we're trying to posture publicly, you really— you've got the, the backdoor story in China as to what we're thinking and how we're going to arbitrate. And I think I, I just— that was the first, the first time I ever saw— it was in the mid-'90s— that China got flag officers' email. Just instinctively, I went, man, that's bad. First off, the good news, most flag officers didn't really use email back then. But what did you put in it? You thought it was private, you know? And I just felt I didn't like that.

01:11:15

Like SIPRNET email?

01:11:16

No, no, I've never seen a SIPRNET breach, you know. Okay, not, not that— it's got to be physical separation. I've heard rumors of it. I've never been involved in one, and I don't know I don't— I personally don't think it's happened, but probably a physical security issue if there's a SIPRNET breach. Someone got to a SIPRNET terminal, you know, they get blueprints to weapons. Yeah, the problem we've got as a nation is we're so damn open, you know. In academia, everything that becomes classified somewhere was unclassified first, for the most part. You know, how it's used and who's using it and where they're using it usually is classified, but we have this— you look at University of Illinois Urbana-Champaign, LSU, Penn State, all these great American univers— Harvard, MIT. I can name them all. Almost all of them. Berkeley. They're all doing work with the government. And you want to— like, the easiest thing to compromise on offense is a university, period. So go do it and go look at the programs. And I mean, I'm giving the playbook, but The Chinese already knew the playbook. The students, I mean, we have a bunch of Chinese foreign nationals at the schools.

01:12:25

That's a challenge. And, you know, somebody once came to me, Sean, and they said, hey, man, if you were working at a company in another country and Uncle Sam came to you and said, can you just take this for us, would you do it? I went, yeah, you know, I'll do that for Uncle Sam. I'll do that for U.S. government. You know, so now I'm unemployable at any foreign company. That's what's happening here. With all the— we went with this global economy and we said, come work here and we'll take your best and brightest. The problem is, where are their families and who are they truly loyal to? So I actually felt, man, the compromises occurred because you can do it from 10,000 miles away and there was no risk to it. But I actually felt, and I remember for years working with the defense industrial base, we always thought to ourselves, if we lock down the cyber door, are we just going to have an HR problem? Are we going to be hiring the scientist that steals everything? And most people would rather have a cyber problem than personnel working at their company stealing their stuff, you know.

01:13:24

So it's a tough— man, when you're heavily targeted like the DIB is, Defense Industrial Base is, it's a, it's a complex place to secure. Wow.

01:13:33

Looks like in that time frame, IP theft by China was an estimated $300 billion and 1.2 million American jobs per year impacted.

01:13:45

Yeah, yeah. I mean, there's no question, like, like they won in, uh, in solar power, right? Do you think they hacked the solar power companies? Probably, probably every damn one of them. Um, you know, everybody makes fun of, you know, the space shuttles all look the same. Well, how did they get it? You know, uh, the least risky way to spy cyber, period. And probably the most comprehensive, because when you spy, you want comms, you want the communication, right?

01:14:13

Did they ever— China ever confirm that they did it?

01:14:19

No. When we went live, certain quotes you remember your whole life. I'll probably get this one wrong, but, uh, when we went live, yeah, we went live because we, we did that report in conjunction with the New York Times, by the way. Deciding that they were going to go live because they had their reporters compromised. They had a reporter named Mike Barbosa over in China, uh, and the Chinese were stealing his email. And, um, you know, when we wrote that report, by the way, I remember it was like a movie in a way. I remember getting on the phone with David Sanger, who wrote the article for New York Times, but all of our press were compromised. They were going after Washington Post, they were going after New York Times, they were going at the USA Today, they were going after all the press. Because China wants to see what are you going to publish about us before you publish it. I don't know why, but they, they do that, especially if you have a bureau in China. And I just remember getting on a call, and on the other side it's like, hey, it's Barbosa, you know.

01:15:13

And the New York Times wanted to verify PLA Unit 61398, so we gave him an address. And I think Barbosa went and checked it out and went, oh man, it's like a whole bunch of noodle shops, and then there's this NSA-looking thing with antenna everywhere, right in the middle of them all, and a bunch of dudes in uniform going in every day. We had it right because we used Google Earth, Sean. We saw the building get built. Isn't that insane? We just watched it grow, you know, uh, on Google. And we went, okay, that's where they're doing it from. We figured it out.

01:15:41

Kidding me?

01:15:42

Yeah, we, we figured it out in a couple ways. Everyone's— and you got to look every day to find it because a lot of evidence will pop up and disappear. We were finding resumes by Chinese students that were transferring schools or going for jobs. We had Mandarin-speaking folks who would translate these resumes. This was before you could just use Google Translator and just read everything in English. So we had to hire our own translators, and we were translating resumes, and we kept hearing about this PLA Unit 61398 and what people did there. And when you read the bullets, you transferred from Chinese character set to English, it was basically like, we hack for a living. We get our orders, we hack those companies. That was it. And, uh, we had— we, um, we knew where they were, uh, but The New York Times went public at the same time frame, uh, about their compromise, and they were the first ones, really one of the first victims. Google was another first victim. Google's so big, when they were hacked by China, they just told everybody, and they actually withdrew doing business in China. They were just like, yeah, this isn't worth it, you know, um, because China does have to learn about the Chinese dissidents here and what they're doing.

01:16:47

So, uh, bottom line, you know, whenever there's ideological conflict, you're going to see cyber activity, and we have plenty of that right now. Wow.

01:16:57

Wow. You know, speaking of China, are you familiar with Polly Market?

01:17:01

Oh yeah, yeah.

01:17:03

Speaking of China, yeah, people on Polly Market say there is a 93% chance that China will not invade Taiwan by the end of 2026. Only 7% say that they will.

01:17:17

Yeah.

01:17:18

What do you think? I've been talking about this for a while. Yeah, deadline's 2027, right?

01:17:22

Yeah, I think that's, that's what people say. You know, to me, and this is Kevin Mandy anecdotal, you know, dad from California thinking about it unofficial, I don't think they need to invade it. I think just population growth alone You never know the will of a nation. Like Ukraine surprised me how hard they're fighting back. You know, I didn't go over to Ukraine. I didn't know the Ukrainian people. I didn't know their will to be independent. I didn't know if they had the leadership for it. And I think like many Americans, when the invasion happened in, what, February of '22, I remember thinking, well, that's going to take 3 days. And look where we're at, right? I mean, this is unbelievable. But then I apply that. I don't know what Taiwan would do either. But it's different. It just feels like we never acknowledged it as a standalone nation. You know, I think no one really recognizes—

01:18:14

There's only 12 countries in the world that recognize it as its own nation.

01:18:19

And so think about it culturally, how tight it is, you know? And then I think population-wise, I've always just guessed, Sean, like, look at Singapore. Like, I think it's 30 to 40% Chinese foreign nationals. Like, how long has it survived? You just look at population growth. At what point is there just a majority? So I think China could just win. Everybody says the population in China is going down. I'd be fascinated if we looked globally. Is the population of the Chinese culture going down? I doubt it. So I just think that that's a tough one. I don't know. I'm the wrong guy to ask. I just go on gut alone. They might be winning without having to fight.

01:18:56

See, that's what they— when I went over there, they have this thing. I mean, cognitive warfare. Yeah, seems to be the thing that the Taiwanese are most concerned about. Yeah, it'd be— I mean, basically in a nutshell, it's a psyop to convince the Taiwanese people that they, they still belong to China.

01:19:13

Well, and then I just don't know throughout history have they been offensive and warlike, you know what I mean? I just, I think they probably win through— if they— everybody says that their culture has a longer-term view of things. Okay, well, the longer-term view is over time we'll just win Taiwan over ideologically.

01:19:31

That's kind of what I—

01:19:31

yeah, I'm getting— yeah, there was a reason why it's 93%. They don't need to go to— I think they're winning. So it's, it's like if you're going like this up into the right, why go to war? It's heading in the direction you want. That's just my gut though, and, and I haven't read enough on it, and I should, um, but I even looked at, you know, I was very interested in our war, or whatever we're calling it, with Iran, you know, what would China's response be? And it just doesn't seem very aggressive. It's almost like, hey, whatever's happening has happened. They feel like they're not even in the scene. They're off— they've exited stage left for now. And I just feel like a country that's prepping for war might want to exert a little more muscle than that. Hmm.

01:20:14

You think they're standing off? I mean, why do you think there's— I think they're standing off because I think they're hoping that the petrodollar turns into the petro UN.

01:20:22

Yeah, maybe. Oh, good point.

01:20:24

Well, and I, I do know, longer this goes on, the more pissed off everybody's going to get at us.

01:20:29

Yeah, I think the dialogue in DC is there's never been a ramp-up of Navy in history as much as the Chinese have ramped up their Navy. If you look at Taiwan, well, that's a naval battle, that's a naval blockade, that's Navy, Navy, Navy. So there's evidence that shows it. But if you want to be a global power, I still feel like we're one of the only nations that can project force remotely. You know, I've heard we may not— depending on who you listen to, we may not be able to project in two fronts anymore. And I've always felt we were always built to at least do two, two wars at once. That may not be the case, but China's building for something, right? And you always think back to when we sent our, whatever, beautiful white ships around the world with Teddy Roosevelt, whenever you carry a big stick. And, uh, I wonder when China's going to do that, if they're already doing it. I think they're probably already doing it in parts of the world. Yeah, but we'll see if they do it globally someday.

01:21:21

Yeah. You brought up Snowden earlier.

01:21:23

Yeah.

01:21:24

What do you think about that leak?

01:21:25

You know, I'm never a leaker. You know, I get it that the dialog needed to happen, but I mean, I'm the wrong guy to ask. I'm pro— it is a weird sense that I've had my whole life. I got to probably— and maybe as I get older, I'm less trustworthy, but I believed in the institution of the NSA and still do. And I've known the leaders there. Nobody is trying to do the wrong thing. I really don't believe it.. And, you know, there's tons of inspection there. I would almost argue we inspect so much we almost hamstring ourselves, you know. And, um, so I'm in the— I don't know if— I'm probably in a minority camp. I, I trust the NSA to do the right thing. I really do. And I, and I— but again, I've walked the halls there, and I believe in the people in the mission. And, and I think you should never there's— there had— you would like to think there was another path he could have taken if that was his, his fight. And I, and I still believed in, um, you know, they looked at the violations done. I can't remember the exact, uh, code that came out of the— you know, I think they called it the Patriot Law for one for a while.

01:22:29

But, um, you know, there was a huge investigation into what were the procedures and who are the people. Um, and they even had people from, uh I mean, they had left liberals, they had right-wing, they had everybody. And it really came back a nothing burger from the extent, at least from my understanding of it, as to what we were really doing. So I don't know. To me, a spy is a spy. I still believe that you can whistleblow appropriately, but I could be wrong, Sean. I would be fascinated in your opinion. If I were sitting in that building, I'd never have done it. But, you know, maybe I'm a weaker person. Maybe it takes— the dialogue is good to have. All the time, right? The checks and balances. That's why we had the press and freedom of the press, you know, to keep the government in check. You know, I still, I still think marketing companies probably know way more about us than the government ever could.

01:23:18

I think you're probably right.

01:23:19

Yeah, but marketing companies won't break down your door and take your assets, you know what I mean? So we don't worry about them as much, right? So I, I do believe in checks and balances, and the government's got to get called out, whether appropriately or inappropriately. It's always a good check.

01:23:32

Yeah, right.

01:23:33

No matter what.

01:23:34

I get worried. I, I see both sides too. I mean, I get worried about it, obviously. I mean, we're just talking about Glacier. Yeah, but, um, so obviously I'm— I get, I get really worried about it. But, um, but I can see both angles. But I, I do— I, I get concerned about government overreach.

01:23:52

Yeah, I do. If unchecked over time, doesn't it automatically go there? I mean, that's just the theory I've always had, is that it is a good thing to have healthy debate, no matter what spawned it, right? Whether it was— so even my opinion on Snowden, whether positive or negative, it's a great conversation to have all the time, you know. So that was kind of my take at the time. I just wish— what I don't know, and what probably nobody in the general public knows, is what were the downside, uh, problems that that created. I'm certain there were certain lives that became real complicated through those leaks, you know?

01:24:30

Yeah. Yeah. Well, Kevin, let's take a quick break. When we come back, we'll get into SolarWinds. This episode is sponsored by BetterHelp. You've heard me talk about BetterHelp for a long time, and one of the things that stands out is how many people have shared real positive experiences with it. Therapy is personal, so hearing directly from the people who have used the service matters. BetterHelp makes those reviews easy to find at betterhelp.com/reviews, and they update them every day. BetterHelp has an average live therapy session rating of 4.9 out of 5. That's based on over 1.7 million client session reviews. That kind of feedback from people who've actually used the service speaks for itself, and getting started is simple. You answer a few questions, BetterHelp matches you with a therapist based on your needs. And if that's not the right fit, you can switch therapists at any time. More than 6 million people have used BetterHelp globally, and their therapists have at least 3 years and 1,000 hours of hands-on experience. See the reviews, see what stands out, and see if BetterHelp is right for you. Visit betterhelp.com/srs. That's betterhelp.com/srs. Looking for another way to support the Sean Ryan Show?

01:25:54

Head to seanryanshow.com and check out the latest drops from Vigilance Elite. We just released new gear including this beautiful moisture-wicking VE Performance hat and SRS Campfire mugs, and you guessed it, Vigilance Elite gummy bears.

01:26:13

Oh shit!

01:26:15

Every purchase directly supports the show and helps us continue bringing you Independent conversations without compromise. Visit shaunryanshow.com and grab yours today. All right, Kevin, we're back from the break. You were just telling me a story about— oh yeah, when you expose a 61—

01:26:39

61398. 61398. You know, even when I went live with that, I didn't know the 5 digits right away. You know, I remember being on like 60 Minutes, I'm like, 6243, you know what I mean? It's like you, you worry about those damn things. And as I get older, I, I forget it. But yeah, when we did that story, David Sanger kind of and Nicole Pearlroth from The New York Times, it was kind of coincided with The New York Times was compromised by the Chinese government. That's a little weird. And they decided to go live with it. And we decided, well, let's go with who did it and what they've been doing. That's the PLA Unit 61398 thing. And it was Sanger's idea and Nicole's idea. Let's just put this on the front page. And I remember like the day before, I don't know where, every once in a while I think I'm an expert when I don't know shit. You know what I mean? So I'm literally on the phone with Sanger and I'm thinking I know his job better than him. He's like, "This is gonna be a big deal." I'm like, "No, it's not, Dave, you're wrong.

01:27:29

Nobody gives a damn about hacking. I've been doing this for 20 years. No one's ever cared and they still don't." I go into work the next morning and I get in, I still remember my lights weren't even on in my office yet. And I go in, it's out, you know, in Alexandria, Virginia, it's about 7:20 in the morning. And it's live. We're on, you know, it was like February 13th, 2013. We're the front page. And I don't even remember what the headline said. And what's weird too, you're an entrepreneur, you know, it's like no matter how good yesterday was, the only thing that matters is tomorrow. I've already been, I'm done. We're fine. We're on the front page. Who gives a shit? We're off. Let's get our workday done. And all of a sudden my cell phone rings and I answer it and it's my now ex-wife. And her exact words, exact words were, what the fuck did you do? And immediately, because I'm a guy, I'm like, what left field thing am I in trouble for now? I didn't know it, why she was saying it. And I'm like, what are you talking about?

01:28:28

I probably got defensive. I'm like, what the hell are you talking about? I didn't do anything. She's like, turn on your TV. And I have a TV right in my office. I turn it on, and I'm not even kidding, the very first scene I saw is a the building. I recognize the building in the background. It's PLA Unit 61398 headquarters. And there's like a dude in a taxi going, "Drive away, drive away." And I look at the bottom, it's like, you know, or "Mandate Report" and all this. I'm like, oh, crap, what did I do? Like, I didn't even know. We didn't think about— people were like, this is a marketing drill. Really? No, it wasn't. It was a bunch of former US soldiers saying, screw this. It's Chinese New Year. Let's get the report out. Let's burn their infrastructure, burn their operation, give our government a tool so the government doesn't have to point the finger at China. We'll do it for them, and let's just see what happens. And we dialed that report back. We actually had the names of a few of the soldiers, like we knew who they were, and we pulled— I remember I edited those things out.

01:29:24

I'm like, no, we're not going to put that in there because I didn't know what would happen to these guys for getting caught. Uh, but anyway, I ended up that day doing about 13 interviews or something like that. And by the way, with no staff, like nobody's handing me Power Bars, nobody's coordinating. I think, you know, I just ran around trying to get out the truth of it. Because what's weird is if I didn't go out and do those, Sean, those interviews, someone would make crap up or say something. And we were on— we were in the ring. Like, I, you know, we were in the ring. We knew exactly what China was doing. So I just felt, let's be the voice of reason on this one and get it out there.

01:29:58

Nobody had even heard of 618.

01:30:00

61398. I don't know, to be honest. I had neither. My team wrote it. We picked— here's what's weird— we had like 3 groups we could have picked in China. There's like a little naval group we called APT-4. We chose APT-1 for a lot of different criteria, but one was they kind of— they weren't— they weren't the Mike Tyson in the ring, you know, in his prime. They were more, you know, Buster Douglas. We knew we could take the uppercut coming back from them, uh, and, uh, so we literally picked them. And it was a tool to give, you know, Congressman Rogers, you know, something— the government, like, U.S. government— we know, we probably know you know, but we'll let you guys have this work of art from us. So we did it.

01:30:43

Have you heard of— you know, we were just talking about Snowden.

01:30:46

Yeah, yeah.

01:30:47

And, uh, have you heard of this FISA thing that's going on today?

01:30:50

FISA Court stuff? No. What's happening?

01:30:52

This is a tweet from Thomas Massie. The House The House passed FISA Section 702 renewal yesterday. I voted no. This was a uniparty vote in favor of unchecked government surveillance without adequate warrants or an accountability. The vote tally— the vote tally is Republicans voted yes, 192. 42 Democrats voted yes. Nay Republicans, 22. Democrats, 169. Total yes Yes, 235. No, 191. Do you know what this means for—

01:31:26

You know what I would tell the viewer, just like, in my view, at a time when I was in the US government and in law enforcement, I never ever saw, witnessed, or knew about unchecked surveillance, period. And I feel that's healthy skepticism for folks to have. I personally never saw it and never executed it. In fact, it was hard for me to get the ability to do it. You really did have to go talk to judges. You really had process. So FISA is foreign intelligence, uh, kind of taps, right? And to me, U.S. law protects U.S. citizens, and I think a lot of times we forget that, you know. And, uh, so, you know, bottom line, it's good for the viewer to know that I never ever witnessed or saw what I would consider unchecked governments.

01:32:13

I dug into this a little bit this morning, and, and I, I I understand why everybody's making a big deal of it, but the way I read it and deciphered it was that in order for the government to actually surveil you under this, you have to be in contact and talking with a foreign state actor.

01:32:34

And there's still a FISA court that they're watching.

01:32:36

Yeah, they're not just anybody from any foreigner, a foreign state actor that is—

01:32:42

that's already under investigation. And there's a FISA court and that's all classified stuff. And you go and present to a specialize a judge and you get your ability to go do it. I had to get approval for consent monitoring. Like, literally, people like, you can monitor. I'd be like, no, I actually can't. I got to ask, you know, my JAG if I can go do that. So people could have asked us to come in to monitor and we wouldn't have been allowed to do it, you know. And in cyber at the time, some people did, you know. Like, if the, if the government knows more about what the bad guys are doing on offense than anybody else, why not let the government help protect the defense industrial base, or why not let them protect the banks or protect a hospital? And we can't do that as a nation because of the separation between the two. So it just— I think I would rest assured of fire in this country that I've never seen, and, and I don't know of. And I, I'm in DC all the time, you know. No, there's nobody, uh, it's not unchecked, you know.

01:33:40

It's not, not for mine.

01:33:42

That's good to hear.

01:33:42

And it's— yeah.

01:33:43

That's great to hear.

01:33:44

I guess, you know, everybody can innocently make mistakes. Relief. And yeah, I've never had to brief a FISA court, but I've had to brief, you know, a judge. It's not easy to monitor anybody in this country. I haven't found it to be easy. Maybe it was cyber stuff. Maybe it was me. I'm not compelling, Sean. I get in front and be like, we need to do this. And they'd be like, eh. But, uh, you know, anyway, I'm not worried about it. I believe in, uh, my gut is if we restrict our ability to spy, we're hurting Europe, we're hurting ourselves, we're hurting a lot of people. And so I, I think I would trust our, uh, our organizations to do their job.

01:34:25

All right, let's move into SolarWinds.

01:34:28

Thank you. I'll just jump right in then for you. Imagine, Sean, you're sitting at work one day I had about 4,000 employees. I was the CEO of a public company called FireEye. And I looked down on my schedule. I'd just done an all-hands with 4,000 employees where I told them, and it was fall of 2020, so it's during COVID and I'm doing weekly calls during COVID because you want to keep the wheels on the bus. And we have 25-year-olds in Alexandria, Virginia living by themselves and their parents won't even see them because they're so afraid of the damn of COVID So I'm doing weekly all-hands, guest speakers. I felt like I was doing the Kevin Mandia Show every Wednesday. I'd do it twice just to keep people in the ring together and entertained almost, because I had a lot of folks struggling during COVID to stay motivated and stay human. Late COVID, February, so it's November of 2020, I do my all-hands where Blackstone did a $400 million investment in my company so I could split it, you know, so I could split my company and sell off the more mature portion of my portfolio and carve Mandiant out to be a standalone company.

01:35:44

Blackstone gave me the air cover to do it. So I do the announcement to the whole company. I hang up the all hands, you know, mean Zoom call. And I look down on my calendar and it says that my chief information security officer wants to talk to me at 1 o'clock and it's a Friday. It's 12:57, and I'm not kidding, I'm about to go downstairs and grab a beer. You know, I'm like, man, this has been a long week. I just did a $400 million raise. I just wrote my presentation. This pre-AI, I had to write all my own speeches, you know, no help. And I don't know, half the company's gonna be like, wait, am I gonna be in the part of the company he sells or in part of the company he keeps? And we were still kind of figuring out which students go right and left, and it was complex and it was, something that had to be done in a public market. I see this invite, I get on the phone at 1, and man, I should have known it was going to be bad news, you know what I mean?

01:36:32

Chief Information Security Officer rarely wants to talk to the CEO. I get on the call and one of the first— and I'm getting a briefing from one of our IT guys who ended up moving into the security operations center, and he's telling me that somebody is logged into our network And, uh, and the very next thing they did after they logged in is they dumped all our user accounts and passphrases from a Microsoft tool called Active Directory. So in other words, that's like somebody broke into the hotel, and the first thing they do when they broke into the Marriott is they, they didn't grab the room key that just opened up room 101. They grabbed the room key that opens up every room. They had the master key. You don't get the master key the first time you break into the hotel, you know what I mean? So I— luckily I'm a CEO that's responded to breaches his whole career, because when I get that news, I literally go, call board meeting, this is the one, this is the one I'm worried about. And even my sister was like, call board meeting, what the hell are you doing?

01:37:32

And I'm like, I think this is Russia. Like, they're accessing our network the way we do. That's perfect offense— access the network that you're targeting the same way the employees access it using their accounts. And that's what whoever this was did. So 10 minutes into my briefing, my heart sank. I'm like, well, I'm not getting that beer today. And honestly, every day, Sean, I remember going— I got the board together a couple of hours later, and I think I gave them like the Sully speech landing a plane on the Hudson. I just said, brace for impact, man. This is going to go from bad to worse. We're a cybersecurity company. Someone's in our network. Uh, they got all the keys. They've got all our accounts.

01:38:11

Did you— and did you know— I mean, did you think you were the only company?

01:38:14

I mean, no, at least. Yeah, let me just—

01:38:18

October 2019, Russian SVR hackers inject malicious code into the SolarWinds Orion update used by 300,000 customers.

01:38:27

Yeah.

01:38:27

March 2020, the backdoor goes live. U.S. Treasury, State, Homeland Security, and the Pentagon compromised for over a year. Yeah, before anyone noticed. December 8th, 2020, Mandia discovers Mandiant itself has been hacked.

01:38:43

Yep.

01:38:43

Red team tools stolen. Goes public.

01:38:46

Yep.

01:38:46

With her company blog the same day against most legal and PR advice.

01:38:52

Yeah, because, well, we found out beforehand. We went live as soon as we could. But here's what held up us going live even faster is so Friday I get the briefing Friday afternoon. Sunday, I, I just already scheduled a board meeting for Sunday afternoon. And I, luckily, I did the job of computer forensics. How did people break in? It was always what happened, what to do about it. That was my job for my every day of my career, you know, what happened, what to do about it in every computer investigation. And then sometimes who did it. And on this one, I just felt right away it was the SVR. Just my gut went, okay, this is a problem. On that Sunday 3 days or 2 days after I knew we were probably compromised, I would get an update every day and it just got worse every day. I'm like, man, I hope they don't get to our secret server that has all our passphrases. Like an hour later, a guy would call, hey, we just did forensics on the secret server. They've got it. I'd be like, oh, I hope they don't grab some of our email.

01:39:46

Day 1, I called our best email investigator and said, hey, I'm pulling you off the job and you got to go look at our email that's stored at Microsoft. He called me back exactly 47 minutes later with, we got a problem. So if we didn't know to look, Sean, we'd never looked. But we knew to look, so we did. And we started noticing, why is our backup account backing up our email all the time? It's not backing up our email. They were using our backup account to log in and steal our emails. And so I just went, oh, this is going to get ugly. Sunday night, I call frontline responder for a pep talk. We're working around the clock, and I can tell you, day one, even as an incident response company, I didn't think my team was taking it serious enough. I'm like, guys, this is the one. This is the one we're worried about. By day 3, everything was changing. The team went, yeah, it's the one we got to worry about, shit, you know? And so I call a frontline guy Sunday night. He's working around the clock, and I just happen to be talking to him.

01:40:41

And he goes, yeah, they stole our red team tools. These are tools that we use to be surreptitious and break into our customers. You know, kind of simulate the offense, simulate the bad guys. And the minute we lost them, I was like, "Well, can we stop them? Can we stop our own red team tools?" And the answer was we couldn't. We made software to stop bad guys. The unfortunate reality is we had created all this offensive stuff that our defensive platform couldn't even stop. And I'm like, "I can't go live with that. You know, we gotta fix this." To the credit of Microsoft, to the credit of CrowdStrike, to the credit of Palo Alto Networks, we didn't have anywhere for me to go in the government. Really. I went to the NSA because it's a damn lonely world when you're compromised. Day one, by the way, I called the NSA and I told them, hey, listen, we're burned. Don't email us. Don't talk to my guys. Don't email my guys. I have no idea how bad this is, but it's going to go from bad to worse. And it did. And to their credit, they were a great ally.

01:41:38

Second, we immediately started reversing our own red team tools to figure out how to detect them. And then we called— I called the CEOs of these companies like, hey, Nikesh, could you please have Palo Alto Networks help us out? Before we ever went public, Sean, we were working inside the community. And to the credit, these are companies that competed with us. They helped me. Thank God. Wow. You know, I was like, hey, George at CrowdStrike, can you please— we were giving them the rule set to stop our cyber weapons just in case the Russians used them. They've never used them that we're aware of, but they sure as hell learned a lot from it. And boy, was I scared. Like, the whole time I was like, I'm going to be the reason the internet goes down. I'm going to be the reason, you know, all hell breaks loose. So I was in a race to go public no matter what. Catholic guilt, call it the right thing to do. I remember I got so much unsolicited advice during this intrusion from employees and the board that I remember two things distinctly. One, every time I was advising a CEO during their own intrusion, I would tell them, this is your day job now.

01:42:43

You got to get through the crisis. So I remember my own voice in my head of what I told other people. Now I had to live by my own advice. It was a little weird. That almost was like bipolar. I was telling myself how to handle my own incident, period. Coaching myself with the same words I told other people. But we were in a race to go live right away, and I was so worried the Russians would use what they took. To their credit, and thankfully they didn't. And I think I didn't think we were alone. Because the SVR always has multiple victims. It's not like they have one company at once. But I could feel when I went out to the community— it starts NSA to me, I go right to them, hey man, we got something new, novel, we don't know what the hell we're dealing with, you want to defend the military first, we, we do have— and then they go to Five Eyes with, we got something new, novel, and it kind of percolates through. And it does no good to go public right away because all you're gonna do is scare the hell out of everybody and there's nothing they do about it.

01:43:39

So we did get Microsoft's help. Thank God they showed up in a big way. Turns out they were compromised by the same people. CrowdStrike showed up in a big way, Palo Alto Networks, Fortinet. All the cybersecurity companies kind of rallied, but it was all informal. And even today, Sean, if we knew a cyberattack was coming, there's no way for the nation to go shields up with coordination. The way you do it is you call the vendors personally and go, hey, you know, we got something new and novel and we need help. I had to protect America from the very tools we had made, you know? So we did it. And I'll never forget, to my board's credit too, I went into a board meeting— this was December 8th when I went public. There was no legal obligation to go public about the breach. We didn't violate anything. We didn't lose any covered data by statute. We— and the lawyer's a great guy, incredible lawyer. And he gave the whole board a presentation on, you have no legal obligation to go public. And I had like 5 pages of notes and I was ready to fight my board with, I'm going public anyway, goddammit, and here's why.

01:44:40

They rolled over in 10 seconds. It was the easiest board meeting I ever had was conveying the news to the public. And by the way, here's what happens when you're hacked and you know it and you tell the world. Market cap goes down by 20% for us. We get sued right away by shareholders and you're considered negligent. And I even had a phone call and then you're calling all your customers and I've lived this with a lot of folks I called one money center bank, and the guy on the other end who I've known for 20 years is like, Mandy, how did you let this happen? How did you let your company get compromised? And I remember saying internally, don't lose your shit. And I just went, let this happen? And I lost my shit. I didn't let it happen. Nobody lets it happen. We have a modern nation with incredibly smart people. Coming after America. We're going to lose. We can't throw a perfect game every day. I was so pissed off because let it happen. Every day we woke up, I spent every Friday, Sean, downside to my jobs is every Friday I'd get a threatening email from a ransomware actor and they were real people and they'd say, we're going to hack you this weekend.

01:45:46

And the reason why is because we were preventing payouts. We'd respond to an intrusion, bottle it up so fast that companies didn't feel they needed to pay the ransom. So they would threaten us, and they did break into us, and we'd have to play this whack-a-mole game with them before they could do anything. We made our own security software. We could program it any way we wanted, and we can't even stop the criminal element. That's how asymmetric this fight is. Wow. So I remember every weekend, anytime the— anytime my lawyer called, my heart rate would go to 130. It didn't matter what, you know what I mean? You know how you had the phone ring certain times, you're just like, "Oh, shit." I had it every weekend. And then when this— And then, so during SolarWinds, I think part of that side of me came out. I didn't let this happen. Nobody lets this happen. We're getting sucker punched here. We're giving Wayne Gretzky unlimited shots on goal. I mean, the puck's gonna get in the net sooner or later, for God's sakes, you know? And that's what we're doing. So I remember just— You've had those moments where you're like, "Don't lose your shit, don't lose your shit." And then you lose it anyway.

01:46:48

I had that one. Just about every other day.

01:46:49

You got it.

01:46:51

That was one of those, you know, the don't do it, don't do it. And then I didn't let this happen. But SolarWinds for me was a, you learn under crisis whether you gain weight or lose weight. I lose weight. And it's weird because it's not like you're bleeding out in Afghanistan. That's what I kept telling the team. This is a cyber intrusion. We're still healthy, you know? But what I've learned is when your credibility gets attacked or your competence gets attacked, it is, it's, I personally don't respond well to it. You know, like every time I got a subpoena as a public company CEO, I didn't do anything wrong, but you read the first paragraph and I just get this energy like, "F this, I didn't do this." You know, I got that during SolarWinds. A lot of energy to prove we're not incompetent, we're good people that got, you know, just lost that day to a foreign intelligence service that really kicked our ass.

01:47:43

What did they get from all the government agencies, from Department of State, from Homeland? Yeah. What are they getting out of that?

01:47:51

In my experience, the Russians always had an etiquette where I've never really seen them take the top person's email. It's almost like they're like, hey, man, don't take the secretary's email. Just take all the people that report to them. You know what I mean? True story. I've always felt that it's always the emails, huh? It is, because everything's there. They took email and they took from us our red team tools. I think it was source code for some of the victims. It was emails for some of the victims. It was methodologies. A lot of it was how do we detect them, find them, and what do we know about them, you know. To their credit, they did a lot of keyword searches, um, you know, so we could see what they're looking for. That's a gold mine for us. I've never seen China do— well, that's not true. I have seen the Chinese recently do keyword searches, and that's a gold mine for us because you know what they're interested in. Keyword search means they hack into the machine and they say find any document has the secret in it, or, you know, Hegseth in it, or whatever the hell it is.

01:48:45

You know, they pick their words and they go. Um, the Russians did that on us, so I could tell you exactly what they were after— our red team tools. I mean, they were absolutely after—

01:48:55

so let me— I'm just curious, let me ask you this, you know, coming from the intelligence world. I mean, you have— you have, yeah, all signs, you have code names, you have all that kind of shit. Is— do— do— does the USG use pseudonym— pseudonyms in emails? Have we started—

01:49:13

not that I'm aware—

01:49:13

tactic like that?

01:49:15

Yeah, yeah. So, you know, there's— here's the reality. We're— there was a whole idea once by a company that started, and they since pivoted, where they were like, we're gonna make a bunch of fake stuff so when the Chinese steal it all, they won't know what's real and what's fake. Well, here's the problem: even companies don't know the last version of something. We have bad enough document control and email control on our own shit, let alone this fake 'em out or head fake or code names. And I did protective services when I was in the Air Force. I'd augment the Secret Service. I can tell you we did do code names then because the radios were probably not even encrypted. They were these big bricks we wore. And I remember the very first thing that ever happened. I don't know if it was for show, just to scare the 27-year-old Air Force guy, but it was like, Raven 1 to Raven 3. And the response was, I'm Raven One, you dipshit. No, I'm Raven One. And we argued about who was Raven One or something, you know what I mean? So, you know, you use code names, you got to change them all the time, and, and I don't think it's going to work.

01:50:12

So there— I don't know of any real obfuscation. You encrypt and you try to keep your communications out of plain view from the Chinese. So, but SolarWinds was something that, um, it was a supply chain hatch on where SolarWinds was a company that we all use for kind of controlling our infrastructure. And I feel bad for them in a way, you know, I mean, imagine this, I had to call them. We found an implant in their published code. That's no different than like Microsoft getting hacked and you get the next update of Microsoft and it's a backdoor for the SVR to steal all your email. Or you're on your phone and you download an app and like, whoop, thank God I updated my app. And the update itself, signed by SolarWinds had a backdoor in it that the Russians now had a menu of, who do we want to hack today? Well, we have a choice of, at the time, 18,042 companies had downloaded the new version with the backdoor. Holy shit. So they had a menu of 18,042 companies. And to the Russian SVR's credit, they didn't hit everybody. They could have literally shut us all down, just delete everything.

01:51:16

You know, if it was a destructive attack, Well, there's a whole lot of data deleted right now, and that's that. What they did was very precision-based, real espionage. You know, they went in and took what they wanted.

01:51:27

You described this as a special operations cyber unit.

01:51:31

Absolutely. Yeah, I remember I went to the Senate Intelligence Committee and I said this was a sniper shot, not a spray and pray. They went right at the 50-something— I'm aware of about 50 or so companies that are US government agencies it went after.

01:51:50

In February 2021, you testified before the Senate Intelligence Committee, was the most credible— you were the most credible voice in the room. Pushed for man—

01:51:58

you said that—

01:52:00

pushed for mandatory breach disclosure laws that still don't fully exist. They still don't fully exist?

01:52:07

Yeah, there's no national level breach disclosure law that I'm aware of that is useful or helpful in any way, shape, or form. The problem we had is the privacy laws— the privacy zealots got there first and said, if you're hacked and you know it and you lose, like, your personal data, Sean, then we got to tell, you know, 48 state governments or whatever it is now. It's probably all 50. And there— so there was things to protect American citizens when they— when you lost their email or their their date of birth or the Social Security number or their bank account number or private bank account number. It's called covered data, and that's great. But what covers the Chinese going in and just stealing all your IP? Nothing. There's no disclosure law required. And the problem with that is no company gets better from it. Like, if Company A is hacked today and the Chinese use all new and novel techniques to break in, no one's learning from it, you know. So if they can go to one place and say, listen, we've broken into Even if— I hate to say it, I was even a proponent of if it's defense industrial base or critical infrastructure, hell, let the best in government show up and help because then we can go shields up, learn the tools, tactics, and procedures that were successful at Company A, and they should be the only victim to that breach, period.

01:53:23

And then you just kind of create a better maginot line. You have to have a learning system. As a nation, we haven't built a learning system where we learn from everyone's compromise and we all get bolstered from You know, all the breaches responded to, like, uh, just— I could just pick any of them. Hell, it's every single brand you can name. But if you get compromised today, wouldn't you feel good about, well, at least nobody else has to go through this? You know what I mean? So I, I think if we get compromised, I would immediately say, here's the TTPs used against us, here it is. And it better be a new and novel attack. I don't want anything that pre-exists to work against us. And we got to get it out there to make sure we're the only victim. We got to do that. It's no different than, you know, a neighborhood watch. You see an asshole robbing a house, you better tell everybody in the neighborhood, you know, and they drive this car and they're doing this. We need that as a nation and we could do better there. We're in a neighborhood where people are getting robbed and no one's telling you they're driving a white van and there's their plate numbers and 3 dudes in the van.

01:54:25

We need it.

01:54:26

Are we working on this?

01:54:30

Yes. The challenge is that every time you go public, no matter what, there's never really a safe harbor for you. So unfortunately, and I can never guess— when you're hacked and you know it and you tell the government, I've never been sure what the government's response would be, and I can never tell the public's response. Example would be like when Target was breached, you know, they lost credit card numbers and they over— communicate, and they had great people, great talent, but people lost their job over that breach. It happened in really 2000, the end of 2013, beginning of 2014. Almost the exact same breach happens at Home Depot and nothing happened. Public wasn't in an uproar or anything, but there's something about this Target breach that it just got a lot of attention. It was during Christmas time, it's holidays, it was the front damn page every day. And then Home Depot, same thing happens. Someone hacks, steals credit data and does stuff, and Home Depot will say, well, we handled it better. There wasn't that big a difference in the handling of it. It's just public responded different, you know? And that— and maybe there's a few minor tweaks here and there between those responses, but I never know.

01:55:39

And so a lot of times companies get hacked and they do disclose, and then they still have to show up and testify in front of the government. And you'll have a senator from, you know, Oregon say, well, how come you don't have firewalls. And you'd be like, dude, firewalls don't do a damn thing. Like, are you kidding? That's, that's, uh, it's not even a padlock in cyberspace, you know. It's, it's, uh, you just get held to account no matter what.

01:56:02

Gotcha.

01:56:03

Yeah. Damn, damn.

01:56:05

Let's talk about the Colonial Pipeline and critical infrastructure.

01:56:08

Yeah, sure.

01:56:09

May 2021, DarkSide ransomware hits Colonial Pipeline, 45% of East Coast fuel supply. Mandiant called in to respond. 6 days of shutdown, $4.4 million ransom. Gas lines across the Southeast shut down.

01:56:27

Yep. I can tell you, I found out— and, and, you know, with a lot of these, you never know how much is still under litigation or not. But the upside for me is you always get to see the leadership and you get to learn from them. So for me, Sean, kind of like you doing the show, I get to show up and talked to the CEO. And I just feel like Colonial had great leadership, you know, just like unflappable, calm. Yep, here's what we got to do. Uh, but let— whenever there's a cyber attack, like when somebody ransoms you, they break in and they encrypt your hard drive, it's not like you know what's going on. Machines start to just go dark, they just shut down, and some of them shut down after 30 minutes, some 3 minutes, some 50 minutes. And if you imagine being in a control room and all of a sudden, hey, my machine doesn't work. Hey, my machine's not working. Hey, I'm going down. You have no idea what the hell is going on. And you don't know if there's a physical threat. You don't know if someone cut an electric wire.

01:57:24

You like— non-cyber people have different responses. And I feel like whether it's Sony Pictures had to deal with something like this, so many companies have, you know, different defense firms had to deal with it. And then Colonial Pipeline. The way that one came to me is, um, I think we were responding on a Friday, and somehow, some way, my young frontline responders didn't see this as national security issues, so I never got the update. My phone rings from somebody who works in the government, and literally they open up— it's 8 in the morning, I'm just waking up to go to the gym, which means that's a late morning— and I get a call from someone I know in the government. They're like, hey, are you responding to Colonial Pipeline? And I don't want to act like I don't know. So I have to say, well, let me check. I'll get back to you. And actually, it was weirder than that. I think he called and said, is it true the Iranians hacked the pipeline or something like that? And I'm like, what are you talking about? And then I was like, let me go check.

01:58:20

I called my front— and by the way, I'm thinking Colonial Pipeline, they make faucets or something. You know what I mean?

01:58:25

Oh, shit.

01:58:25

So I don't even know who the hell they are. So I get on the phone with my guys. Sure enough, we're responding. And then I hear what they do. And I'm lecturing my frontline nerd because these guys are so into cybersecurity. They're like, all right, you've been breached. What happened? What to do about it? They never thought to escalate. Hey, man, 40-something percent of the US fuel on the East Coast is going to be not transmitted. I got a call from the government on that first. And that does happen for me every once in a while. I've had that happen maybe at least 3 times in my life. I learned we're responding to a breach because someone from the White House called me. But on this one, I got a call from somebody at an agency, and then I looked in and it was definitely not Iranians right out of the gates. We knew who it was. And that's based on— again, we're cataloging forensic evidence at every breach we respond to. So we can go into like a Colonial Pipeline, look at the evidence, and plus they said who they were, makes it a lot easier.

01:59:15

And they wanted to get paid. So you know who you're paying. You can pull the evidence out and just match it and marry it up. So we're pretty confident with who they were. But on that one, it's just an example of many of them where first, there's always a fog of war. You have no idea what's happening. If you're a hospital and stuff starts going down, you— a lot of hospitals be like, physically secure the hospital. Like, you call security and say, guard all the exits, because you don't know if there's someone on the inside doing it. You know, it's a weird, uncontrollable moment. But I've seen incredible leadership. And I did attend a lot of the calls of Colonial where you do your daily briefs, and they were just— they did they show that you plan ahead. Like, do the plan that you wrote when you weren't under duress. And that's exactly what they actually— that's the best way to say it. They had already kind of said, hey, if something like this happens, here's what we're going to do. And they just pulled out that playbook and did it. And it works because it keeps everybody calm.

02:00:11

Because there is nothing— it is a weird thing when you're hacked and you know it. You know, I've lived it where I'm like, man, I wonder if they're stealing my email right now. You know, what the hell's in that? Nobody knows is what's in their email. So, uh, Colonial Pipeline again, though, it's just all of these, whether it's Colonial Pipeline, hospital, cell company, every one of them, it's a full sprint the whole time, no matter what. Like, you show up, and our job is always physically impactful, Sean. Like, when we show up, we have to figure out what happened, what to do about it. We're not really sleeping. Like, you show up and you're just triaging and working around the clock. And Colonial was no different. Like, some of these intrusions— we did UnitedHealthcare. I mean, do you remember what happened to them? I think it was last year.

02:00:58

Yeah.

02:00:58

Somebody hacked UnitedHealthcare and ransomed them, and people couldn't get their drugs at pharmacies. People literally worked themselves into hospital visits. I'm not making that up, where people literally worked around the clock till— like, one guy didn't show up at a meeting. They had to go find him and he was like passed out on the ground. They had to hospitalize him. You know what I mean? So these things are absolute races. Colonial, the upside they had is they don't have a competitor. You know what I mean? You just got to get it right. And I think what they had is the constant— like, it's a political issue. You got to get oil and gas. So I think they probably— I'm not aware of it. But my gut is they felt an incredible, immense pressure to get back up and running, you know, and most companies do. Medicare did. Yeah. I mean, I've got to be way harder than people think.

02:01:50

$4.4 million in ransom for 45% of the East Coast fuel supply seems pretty minimal.

02:01:56

You know, I, you know, to me, yeah, you never opine whether people should pay or not. Obviously, here's what I will tell you. I've never met a CEO who wanted to pay. Not like it was never the default answer. But you certainly see the logic in paying that one, right? I do. $4 million. Yeah, I would have paid it. I've gone through the hypothetical of what would I have paid to keep my legal counsel's email from getting posted. Now I'm advertising to the bad guys, but I would pay to not read the amount of lawsuits you get as a public company CEO if your general counsel's email's online. It's amazing. I mean, reporters read it. They write articles on this stuff. You know, it's, uh, it's, um, it's a tough situation.

02:02:43

What about texts? Do they ever go after text messaging?

02:02:46

Uh, well, do some reading on, uh, yes, as you answered, modern nations do. And, uh, you know, both of all our cell companies have a— there are certain industries that you need to withstand military-grade attacks or modern nations attacking them. Our cell companies, our phone companies are definitely one of them. They are fair game for espionage every day. Last year there was widely publicized breach in AT&T and Verizon. It was in 2024 and '25. And the advice from the FBI was, and this is pretty telling, hey, use Signal.

02:03:27

Are you shitting me?

02:03:28

No. Meaning techs are in the clear and techs can be found and, and cell companies are fair game. And in reality, they are so valuable to espionage, most likely, that if you're on offense against us, you're trying to place people there, you're trying to hack them, you're trying to do anything you can to make sure you maintain access to the data from those companies.

02:03:51

Is Signal legit?

02:03:53

I think Signal is like— you use it, there's always ways around everything, but you have to have a massive comp— like, in transit, Signal's legit. Like, if somebody hacked your phone, my gut is they can get to at least half the equation and maybe be able to decrypt it. That means it's a modern nation targeting you specifically. But Signal is, is infinitely better than not using it. Same with Glacier. Like, these things are massively annoying if you're on offense, because that means I can't just intercept your dialogue and read it, and I can't find it stored in plain text. I have to do a lot of work to get to that.

02:04:31

Ben, didn't they just— didn't they just—

02:04:33

where was I reading this?

02:04:34

I can't remember what it was, but they broke signal and they were able to get the messages through notifications by breaking into the app. Have you heard about this?

02:04:47

Now, there's usually workarounds like that. Like, I can tell you, usually— I wouldn't say usually— in the times where we needed to decrypt something and we only had one key, we always were able to decrypt it over time. And usually there's two keys, a public and private key to something. And so there was a time where we could decrypt at my company Remote Desktop Protocol from Microsoft, and we thought we were the smartest guys on the planet. We're like, look what we can do. And if we can do it, China can do it. In reality, none of our customers cared that we could do it. But what it allowed us to do is whenever the Chinese broke in, they would remote desktop to all these machines. We could see exactly what they were doing because we could tap it. And even though it was encrypted, we could decrypt it. We thought, oh, we're awesome. Nobody really cared. But the reality is most stuff today probably can't be decrypted easily till you have quantum compute come out. And then realize you have two problems if you're worried about this. One, someone got your traffic or your data somehow.

02:05:49

And then two, they can decrypt it, right? But quantum, that's the biggest issue with quantum compute. And that's going to come like AI. Everything's coming faster than we want. When the Chinese and the Russians and others have quantum, the vast majority of things we've done in the past that they've already intercepted, tapped, stole that's encrypted will be decrypted. That'll be the risk we run. The secrets that we once kept will no longer be secret.

02:06:14

How far are we from that?

02:06:17

Under 10 years.

02:06:19

Shit.

02:06:19

For the most part, here's the good news: the Chinese really don't have a whole lot to decrypt. They accessed everything with a valid key, meaning a valid user account and passphrase, so everything was presented in plain text anyway. I actually think the threat from quantum is far less than people realize because for the most part, even when the Russians were stealing stuff, it was not encrypted. So the vast majority of the intrusions— I'm speaking with like 5,000+ intrusion investigations behind me— very rarely does an attacker have to overcome encryption because they are accessing your data with your keys, your credentials. And so it's just plaintext anyway. So I think quantum is not going to be a big issue. It is for some things, but we'll see what comes out then, Sean. You'll have a lot of good shows then.

02:07:06

I'll bet I will. Yeah, it scares the shit out of me. I mean, the way I understand—

02:07:10

figure out where Hoff is buried or something. Yeah, the way—

02:07:14

I mean, it's just, you know, people, people describe it as your banks will be done, all your passwords will be gone, every financial network will be completely—

02:07:25

I think AI is going to impact that more than anything because you have AI doing trades, not humans. So imagine a whole system of AI agents doing all the trades. At some point, the market's going to be managed by them, the AI agents, not humans.

02:07:45

You've heard me talk about Caldera Lab before, and lately the product I've been reaching for the most is the Good. Between being a dad, hosting the show, traveling, training, and trying to keep up with everything else, I don't have time for some complicated skincare routine. I don't want 10 steps, I don't want a cabinet full of products, and I don't want something that takes a bunch of time every morning and every night. I just want one simple product that actually does something. That's what I like about The Good. It's an antioxidant-rich facial oil serum made specifically for men's skin. The Good is formulated with 27 botanicals, and it's designed to help deeply moisturize, support skin recovery, even skin tone, and visibly reduce the appearance of lines and wrinkles. For me, the biggest thing is that my skin doesn't look as dry or worn down. It feels softer, smoother, and just looks healthier. And the results back it up. 96% reported healthier looking skin, 91% reported less dryness, and 89% showed improved radiance and luminosity. If you're looking for one simple product that actually makes a difference, That's the good. Visit calderalab.com/srs and use code SRS for 20% off your first order.

02:09:04

Again, that's calderalab.com/srs and use code SRS for 20% off your first order. What is the worst-case scenario for a cyberattack on US critical infrastructure? What is the worst case?

02:09:21

I'll start with this. Nobody knows what would happen when the when the gloves come off. And there are a couple reasons why. We're in times of basically, at least ostensibly, we're at peace right now with the modern nations like China and Russia. You know, we may be fighting proxy things or ideological differences, but on defense, we don't know if we've seen 99% of their capability on offense or 20%. My gut is it's like 80%. In other words, they have stuff on the shelf, Sean, they've never deployed. We haven't seen it yet, that you save for the moment of need. Right. So the first thing I would tell you, there's a book by Ted Koppel called Lights Out, and I read enough of that to go, I don't know if that happens. I don't think it's that bad. But genuinely, nobody knows what would happen if all modern nations go all out in cyber. I can tell you our kids probably aren't going to school. I can tell you some regional trains aren't running. But I don't know if it's like the— there was De Niro— there was a movie out on Netflix called 0 Day, and it's all about this exact situation, but it's done by Hollywood.

02:10:23

And I couldn't make it past the first 10 minutes. Trains are crashing into each other. You know, some child gets killed or some people get killed in a car accident because the lights aren't changing right, traffic lights. And I was like, man, I don't want to watch this. The problem is, I think you're going to get a situation that there's such a rippling butterfly effect that most of society will come to an absolute— we better go back to the old way. I'll give you an example. Like, there was an attack in 2021, and, and, and it worked. It shut down, uh, software that was used by a lot of restaurants. And I mean, you and I have been ordering food in restaurants from long before the internet, or at least, you know, someone wrote down your order. What I was amazed at is is when the internet went down at about 800 restaurants, just the, the app itself that they were using got compromised. The majority of the restaurants couldn't take orders. They didn't know how to run their business off the grid. If you wanna do something weird, see how many Fortune 500 companies can actually run their business if they're off the internet.

02:11:30

The answer is probably none of them. Some aspect or most of their business might actually falter. And that's unfortunately probably what will happen if the gloves come off in the cyber domain. So much will be unreliable and unpredictable. It'll impact so many weird things like your running app. Hey, how far did I run today? Oh, my running app doesn't work now. Or you're tracking calories. You can't track calories. You— your schedule blows up. Your organization can't get on the grid or you can't transact or you can't sell or you can't get your money or you can't believe what you're reading. And there's a lot of different kinds of attacks. Like, if I had the privilege a couple of times of teaching a modern warfare class at the Naval Academy, I'd show up and guest lecture and I'd depress myself because first off, the attacks start a year out and you won't even know it's us. Yeah, I won't even give you the playbook. But when the cyber stuff happens, you know, I think we're staying home from work that day. I don't think the grid crashes. I think hospitals function.

02:12:29

You don't think the power grid crash?

02:12:30

I think it might crash in the Midwest. The mom-and-pop utilities, Sean, are going to have a problem. Maybe some of the water facilities, but it also depends on who's doing the attack and what their goal is.

02:12:41

I would like to dive into that a little bit more because that is one of them. That's where I thought we were going, was the grid's going down, water treatment plants.

02:12:48

You better have fault tolerance. I think some will.

02:12:52

I don't mean this isn't— I mean, the way I understand the way things are going, China manufactures all of our damn near all of our power infrastructure, the transformers, water treatment. Well, and so if they're manufacturing that shit, they're putting stuff in there to be able to access it.

02:13:10

You got to trust the country you do business with.

02:13:13

And even the former FBI director said that they are in our power grid and our—

02:13:19

well, they hacked into it. Yeah, they have. And not everywhere. And that we know of. Nobody knows what'll happen. That's the challenge. Here's what I will tell you. The minimum is small municipalities are going to lose electricity. They're going to have their waterworks probably shut down. Now, again, it depends on the attack. And if we go full monty right away versus gradual incrementalism, most wars gradually increment, uh, depends on the actor because there's a blunt force way to attack us that might not be as successful as a slow erosion of our capabilities. Does that make sense? Here, here's why. If I break into a major utility, you know, like ConEd runs, you know, is New York City, or PG&E, or, you know, down in LA, or Southern Code— these are strong cybersecurity entities. If you broke into any of them and tried to run malware, they probably can detect the malware with compensating controls and stop it. It. Or if you try to just delete everything on a machine, they'll have redundancy. So what you actually have to do is reverse. So how does this utility work, and what commands do I issue that will be unique to every single one of them to get it to perform differently or to impact it negatively?

02:14:40

That's lower and slower. Um, you got to read the freaking manuals. Does that make sense? On the littler guys, you probably can just delete everything. I call that blunt force trauma. We hacked in and we just said, hey, delete everything, go. So that might shut down municipalities. It won't shut down the bigs. They're gonna keep giving you energy. The bigger problem with the bigs is the load they've gotta take if things start to shut down. We saw that happen in Texas, right? They had like a early winter or late winter and all of a sudden the whole darn thing ripples across the state, you know, because if one utility went down, the other tried to bear the load and it couldn't do it and it pops down. And we had that cascading in August of whatever it was, was when, uh, New York went down, you know. The, uh, do you remember that happened in maybe 2003, 2004? Uh, it was 2002 maybe. I can't remember. It was August of 2003, grid goes down in New York City, you know. And, um, it was all peace and happiness because it got back up in 3 days.

02:15:34

But what's it like after 5, you know? I was actually in New York at the time. It was really good because people learned after 9/11 how to work together during crises. And that was August of 2003. But I also remember walking around the city going, it's August, it's hot as hell, aircon's not working. How long before this thing unravels? You know, but, uh, I think if I'm on offense against us, you take out energy, you take out everything. That's healthcare, that's finance, that's everything. And I think that's, that's what you gotta worry about. And then you're just going to get this weird ripple effect of regional transit not working, ATMs maybe not working. You know, life will change.

02:16:19

So what about water treatment facilities? Hard to defend if they just made minor changes to how they treat it, to what they're putting in it, how they're—

02:16:29

they're all different though, Sean. That's the thing. Like, there's— you're gonna have to fucking poison us. Yeah, I think you got to know more than that. I think they're going to go for— that's why I said either shut down or or alter. Shutdown is blunt force. They just— we're going to delete everything versus we're going to change the commands being executed. They're unique per utility. They really are. Like, you got to read the manual. That means— that being said, if I ever hack a company, I find the manuals. They're not hard to find. They really aren't. You just look at it like everybody stores them in the same place, and it's usually called the name of the system and the user guide. Read the freaking manual. Uh, it— we do a lot of assessments of these utilities And if I were, you know, if my red team lead was sitting here, he'd be like, yeah, we usually, if we can get to the OT or operational network, that's a problem. So what you have to do is segment. The internet network is the IT network. We've all heard IT, right? You got to keep that IT separate from the OT.

02:17:27

You better have one hell of a wall between the two. The problem is everybody has a crossover somewhere. It's almost like Nibernet the SIPRNet, you know, we can go one way but not the other. You know, you've got to figure this out. I think the small utilities are uniquely disadvantaged at time of war. So you're from Missouri, hometown, probably not going to do great. Yeah, yeah, I don't even like thinking about it.

02:17:54

You, but you've got to think about it all the time.

02:17:56

Yeah, but there's no— when the, the chall— so here's the— let's I'm not a pessimist or an optimist. I'm a realist. I do think we can have a future with AI. Everybody's going to say AI on offense is going to create a problem, and that is true. I think it's near-term pain with AI on offense, and we can probably get more into that. But I do see a future where AI on offense will be uniquely available, built by the good guys. That's what Armadin is doing, to train your AI on defense. The biggest problem we have in cybersecurity is there's a starvation line. The big companies have great expertise, great talent, and great software to defend it. Then you hit a poverty line and all these utilities can't defend themselves and all the small companies can't defend themselves. With AI, we're going to get the scale of the expert. The problem is we have to live that transition period, Sean, and the advantage will go to offense during a transition period. And we're in that now. AI is just emerging. It will advantage offense. However, in the long run, it will advantage the defense. But we're going to have an ugly transition.

02:19:01

So when you talk about a— how did you— not blunt force.

02:19:09

Yeah, blunt force trauma is like a bad hack. If I'm on offense, I don't do blunt force because I don't want you to notice I've hacked you and I've screwed with you till it's too late.

02:19:19

So what does that look like?

02:19:20

You slowly erode a system.

02:19:23

How would you do it?

02:19:24

Slowly pollute the water, slowly degrade the utilities. Um, yeah, and but I would have to read the manual because it's unique to different things. That— yeah, I almost hate giving the playbook away, you know, because I'd already have— if I were against us, I'd already have people working there. I would already know how to bring down the major utilities because that one guy on the inside feeding me the meals. Feed me the access if I need it as well, you know. So it's real hard to stop that. We have a very international culture, and, and not all loyalties lie in the same place. So, you know, I hate thinking about what— and I instantly, Sean, go, what, what would I do if I were against us? And I just don't like what the outcome would be. So I'm hoping that our adversaries gradually increment. Um, we have to have a proportionate response. If someone attacks us in cyber, our best deterrence is not in cyber. It's explosive. It's kinetic.

02:20:21

It's—

02:20:22

you bring the pain. That's the unfortunate reality. We are in the glass house in cyber compared to the rest of the world. You know, I think China might be too because they have such centralized control. We may be the two biggest glass houses. You know, if you're— if North Korea hacks us and we think, you know, we're going tit for tat by hacking back, they're in a mud hut throwing rocks at a glass house, and we're in a glass house throwing rocks at a mud hut. It's stupid. It's not the right domain to fight the conflict in. And I think unfortunately that's the reality. We have to— if somebody starts hacking our utilities, we have to respond very quickly and violently to that.

02:20:57

What about the financial markets?

02:21:00

I don't even think— I started number one, and they like to think they are, you know, you talk to the banks, but to me I've never ever had a scenario in my head where I targeted the banks. No one gives a damn about money if they can't go to a hospital. You know, I, I go after electric first and foremost, probably water, you know, because it's, it's unguarded, it's hard, hard to protect, and healthcare. Uh, that's it. The financials are so well defended and they're so good at— they can always roll back to one second ago. They have fault tolerance everywhere. They're confidence games. They cover losses. And I would put— if you could wage a war on every front in the cyber domain, yeah, I'd go after every domain. I'd go after every industry, I mean, and let them all have it. And, uh, and I'd have AI on offense that can hack 24/7 with total recall. And that's what's coming, unfortunately, Sean, is a future where all of us— there's an attempted hack against all of us all the time. It's almost that bad now. You know, but it will be that way with AI.

02:22:02

So it's, uh, it's like a lot of needles coming at the balloon and it only takes one to pop it, you know.

02:22:07

How do you— I mean, what, what do you— what would you tell the, just the average American to prepare for if that were to happen?

02:22:16

Everybody needs to be able to live off the grid, you know. That's actually a fact. We tell businesses, I call them red lever events. If I'm meeting a CEO at any company. Never forget how to do business the way you used to, just in case we're under conflict. Be able to dust off a book and say, okay man, we're gonna have to do insurance claims with pen and paper again, whatever it is. Because you never know what conflict can bring and what you may have to work. Like, if you're a restaurant, for God's sakes, you ought to be able to take an order without the internet and without a damn iPad. You ought to be able to write it down, walk back to the kitchen and do it. And I saw over 50% of restaurants falter with no internet. Literally couldn't operate the business. In fact, waitstaff didn't even know the menu because they were so used to it. So great companies— and by the way, critical infrastructure for damn sure. You drill the red lever events off the grid. How well do you operate? Every machine becomes inoperable right now. How fast to recover?

02:23:10

Those are like pull the lever, what happens? And most companies, when they do those red lever events, have unique findings. Like, wait, I never thought about that. No one can park in the parking garage when we come off the internet. When people badge to go into the parking garage, your badge gets digitized and sent somewhere for authorization to open the gate. No internet, no gate. Traffic jams the whole block of LA. So you got to figure out, how do people buy lunch at work? No internet, can't take Visa cards. How do we, you know, I— critical infrastructure needs to operate off the grid. It needs no way to do it. It needs to be able to operate how it used to. I believe that.

02:23:51

What about for people, not for businesses?

02:23:53

People, you know, there's no way to— unfortunately, you know, for me, for people, it's— when we're talking about duress moments, I hate to say it, and I know you believe this, you have to at least have a family plan for what do we do if the dirty bomb goes What do we do if the earthquake hits? What do we do if blank? You know, great idea about technology. I do believe with proper diligence, you can know where your kids are, know where your family is, and do so in a safe way. You can have protocols in place. You can communicate in a safe way. The grid comes down. I don't know how to do that, but you can't really take down the internet in the United States. That's why it was created— survive nuclear war. That's literally how we went from packet, you know, packet switching from circuit switching. Circuit switching was one line, you sever it, no comms. The internet was created literally so we could communicate after nuclear fallout. That was one of its reasons. So you're not shutting down the internet here, and there's ways to have redundancy. Go satellite and fiber to your house, have backups.

02:24:58

But it's, it's virtually impossible for me to say to any individual, you should prepare to withstand an AI-based attack coming from a modern nation, um, that's going to fall in the hands of, of the companies to protect us at that point.

02:25:12

Okay.

02:25:12

Yeah, Apple's got to protect us. Google's got to protect us. Amazon and AWS needs to protect us. Microsoft protect us. CrowdStrike, Palo Alto Networks, Fortinet, Cisco. You go through the brands that we all really, like, use for our infrastructure, use for our applications and say, hey guys, you got to be able to do shields up during conflict. And they know that, you know, they're actually— I would argue they are critical infrastructure. If we think Google Cloud's not critical infrastructure, it is. It's running a lot of businesses. So is AWS, and so is Microsoft's Azure. So you got to put them in the category of they're critical, and they should have— I hate to say it— wartime protocol. What do we do?

02:25:55

What about the USG? I mean, We're talking about the capabilities of China, Russia. Uh, in the next segment after this, we'll talk about China, Russia, Iran, North Korea. But what, what are our capabilities? Are we— are we— do we have an offensive hacking arm that, that is conducting espionage on our behalf?

02:26:16

You know, anything we do offensively is going to be classified. And, and one of the things I will tell you is I started Armageddon to absolutely benefit the offense for nations that are governed by laws. And those laws are things we aspire to abide to, and, and we do it. I've always felt on gut intuition and to some extent experience we were the best in the world. Um, we probably still are. And, you know, but China's great. And, and the problem is, Sean, AI is the equalizer between all of us. AI will enable nations like Saudi Arabia, UAE, other nations to have the same level of offense as us potentially over time. Because you can train systems. It only takes one exceptional offensive mind that can do vulnerability discovery, exploitation development. All these skills are going to be automated into AI. And then— and so that highest tranche of talent and capability is just going to get more distributed over the next few years. So it used to be US was in a land of its own. Israel is incredible in offense. I'm starting to realize war makes you innovate faster, and Israel could be the best in the world on offense.

02:27:34

And maybe there's certain platforms different nations are number one in, like the mobile platform. Got to give some shoutouts to the Israeli offensive capability in mobile. Um, period, right? And I don't know, how did you respond when pagers exploded and supply— I mean, you think about when command and control is eroded like that, who the hell wants to be part of that network, huh? The radio explodes, the pagers explode. I don't want the next thing you're giving me, you know, right? Just give me a smoke signal from a mile away now, and hell, that'll probably blow. So there's a lot of nations that— the thing about cyber is one smart person is infinitely scalable. Available. So all you need is that one or two great offensive minds at the right time, you know. And the vulnerabilities in cyber change. Like today, there might be— first time in internet history, no 0 days work. But right now there's two 23-year-old kids working on an app that everybody's got to have.

02:28:30

Do we know who those great minds are?

02:28:34

Uh, different times they work. Like today, it could be that, um, The architecture that matters is Siemens. Tomorrow could be Parsons, and the next day it could be Cisco. You don't know what skills you need on offense till the moment.

02:28:48

I'm actually talking about a foreign adversary's offense. Do we know who those great minds are? Do we know who to take out if they hit us?

02:28:57

I would think it's hard. Yeah, I doubt we know. We probably know some. You always know the lowest bounds, right? Whatever you know, it's the lowest bounds. Of your knowledge. But no, and I think ours aren't really well known either. I think the best offense I've ever seen, nobody knows who these guys are. You know, they're smart, they go home, walk their dog, and they don't blog about it. You know, they don't go to Black Hat or conferences and really share what the hell they're doing. And the great thing about offense is the government's mission still draws in incredible talent. But at the same time frame, in my lifetime, I remember growing up going, the best in the world at physics would be in the government. The best in the world at offensive cyber would be in the US government. The best in the world at big data would be in the US government. And now that I've worked at Google, or I am familiar with Amazon, and I see the pay differentials that have probably expanded massively in our lives, I'm starting to think that there's more talent on the outside. Right. But I would put the US will always be excellent on offense.

02:30:00

We have the, you know, and I hope we just stay there.

02:30:03

That's good to hear.

02:30:04

Yeah.

02:30:04

Let's take one more break.

02:30:06

Got it.

02:30:06

All right, Kevin, we're back from the break. We had a, we had a really good discussion off camera on what you would do if you were going to hack into a nation.

02:30:18

How would you? Yeah. You know, if you were, you always wonder what would our enemies do to the United States of America? And one of the things that's unique to us, that First Amendment, allows any— you know, there's a— there's no line between you have to say the truth when you're speaking your mind. You know, what's the difference between a really, really bad opinion and being out and out lying to incite a riot? You know, nobody knows where these bright lines are. With the First Amendment in the United States and the freedoms that everybody's afforded for that, I think we're uniquely susceptible to manipulation to the hearts and minds of the American people. And, you know, there— what I was trying to remember, Sean, is sometime in, I think, August of 2015, I had one of my intel folks— we built a global intelligence infrastructure at Mandant, so we had hundreds of people that spoke 30, more than 30 languages in over 30 countries. And one of these guys just walked in my room one day and said, foreign intelligence from Russia is influencing the hearts and minds of people through these X handles, these Facebook walls, and he just unloaded.

02:31:23

And it was like a 100-page document. And I remember going, this feels wrong. I don't— this is before anybody ever talked about Russia's trying to influence the US elections. Well, no crap, every nation is, right? With whatever they've got. I mean, if you're getting funding and you're Liberia, wouldn't you maybe try to get a few votes for that side? I, I think there's no different— there's good people trying to manipulate hearts and minds for good reasons But what we saw and what I saw in the 100 pages— and we went public as a company about this with about 90 of those pages. But I remember, I think I literally flew back in and briefed Senator Warner. He was, you know, the Senate Intelligence Committee, saying, "I don't know what to do with this, but here's what's happening. Like, Facebook walls are being started." And when we went back and we traced it, I don't remember the details now other than our guys were really good. That spent their whole time kind of tracing certain Russian actors. And they're like, "This is them. This is them using these platforms." And all they did is amplify what already existed.

02:32:22

They weren't even really making stuff. They were just like, "Let's push this issue. Let's push that issue." And they were just driving things. And people would ask, "Well, what side did they push?" I'm not sure they gave a damn about any of that. I think they more cared about just push American people this way, both directions, you know? And I apologize, I don't remember the details as well as I did, you know, a decade ago. But I mean, that was the cool part of my job. It's literally a guy just walks in my office, you're going to want to read this, and me read it and go, what the hell do I do with this? You know? And then you just talk to people like, you know, we got Facebook involved, we got Google involved. There was a third— oh, X. And we did talk to their trust people and all of us were like, yeah, this doesn't feel right. But we didn't know what to do. You know what I mean? It was the earliest onset, in my opinion, of social media being used and you can't tell what's artificial amplification versus real amplification.

02:33:14

That's a problem, right? You can't tell if this is an issue that matters to Americans or not based on the number of hits and number of volumes. And that stuff's feeding our algorithms and changing things. So we got to figure this one out. And I know a lot of work's been done since I inspected it. So I'm sure today there's a constant whack-a-mole at these social media companies. Say that's a foreign actor, kill it. Kill that. And yet people don't want that to happen either because it's censorship. But I can tell you it's real. And if I were on offense against us, because of the First Amendment and your right to say anything you want for the most part, you know, shovskim and fire in a crowded movie theater kind of thing, we are susceptible to attacks. Iran is not, and Russia is not, and China is not. They're not bastions of internet freedom. They control their press. And we can't really push back on the buttons there as effectively as you can push our buttons. So you even can look at our nation today, and many people describe it as divided. I can't tell because I think people are amplifying the edge.

02:34:16

And I think we're getting that through our media in such drastic numbers that nobody really knows what's normal anymore. And it's too easy to do, you know? So I think if you go on offense against us, You just get us to tear ourselves apart, you know, that's what you do.

02:34:32

Psychological work.

02:34:33

Absolutely. And you can, you know, and if we've even seen that, you know, no matter what people say about the DNC breach of 2015 and the documents leaked in 2016, um, a lot of people don't like to talk about that, it became a political issue, but somebody hacked these servers and somebody leaked documents. We'll leave it at that. I would say that the To me, all of the facts did align in my experience to— it really was the Russian GRU and SVR that did it. Just all the same tools. And what's interesting about those guys, by the way, they really use their own crap. So if you find their crap, it's them. I don't think they're leaking it out and, and giving their custom tooling to other people. And, um, I've never seen a modern nation hack and then leak documents. Before. That was kind of the first— that was an escalation in my domain. China doesn't do that. They're not going to hack Sean Ryan and then take all your email and throw them out on the internet. Uh, Russia seems to do that now. You know, it's a little bit different, but that's what I'd do.

02:35:35

And then what would stop you from hacking people like Hillary Clinton or Obama? They lost their emails before to what we would attribute as foreign actors. Leak the emails. Make crap up in them. I mean, we are a culture now where I don't even know if you need the evidence to toss someone under the bus, you know? So I think the way I'd go to war with the US is maybe what we're already seeing. You create division. Absolutely. You create discord. It doesn't matter. You don't even pick a side. You pick all sides. Just throw it at us. I would actually pick the two opposite sides. Sides and keep pushing both of them. And, and you see it, it's just, uh, and it's going to make it tough to lead in our country. Um, and, uh, and it's that freedom of speech. Everybody has a right to say whatever they want. And that's— and so we got to figure out how to protect that freedom while still showing— I would argue the biggest thing we have to do is, uh, find artificial amplification of ideas and quash Does that make sense? Because you think it's like 50% of America thinks something, but it's like 3% plus amplification.

02:36:47

But that's really hard to do. And in reality, the biggest guilty people for amplification are marketing people. You know, you have the foreign intelligence will absolutely amplify certain ideas, but unfortunately, so do U.S. organizations. You have to do this, or, you know, here's the cure. So it's really— it's a tough battle. And I, you know, you often study— there's a book out. You have kids now, so you have to read these things. Things. And you look into The Anxious Generation, the same person that wrote The Coddling of the American Mind. And when I leave, I'll send you these books. It's a, it's a reporter. You don't even need to read the book, Sean. Just look at the graphs. Ever since the iPhone came out and people use social media, depression goes skyrocketing thousands of percent. Suicides go skyrocketing hundreds to thousands of percent. They don't know anything other than, well, it all starts going bad in 2000 I think '07, the year of the first iPhone. You don't blame Apple, but was the species ready for what we're actually developing? Did tech finally get out in front of us in a way where we couldn't manage the fallout from it?

02:37:52

And to some extent with social media, I think that's the case. It, it, social media in many ways, 'cause of the anonymity behind it, does have the propensity to amplify the minority. It has that possibility. So anyway, it's a tough one. So if I'm on offense against United States, I'm all hearts and minds. Uh, fake media, um, synthetic media— even if you know it's fake, you won't get it out of your mind, right? You know, we even have an administration that uses it. And, and I think it's, uh, we're going to have a future where we won't be able to tell probably between synthetic media and synthetic.

02:38:31

I think we're already there.

02:38:33

Yeah, I think you're right. And so the hearts and minds, when you have a, a nation like us with this openness, I mean, we're pulling ourselves apart pretty, pretty hardcore right now. Feels that way.

02:38:42

I mean, you would even mention breaching companies and creating rifts.

02:38:46

Oh, absolutely.

02:38:47

And companies.

02:38:48

Absolutely. Get the trusted business leaders. I, I hate saying these ideas publicly because you can do it. Discredit public leadership in credible ways. I don't even think you need credible ways. Ways, but just do it incredible ways. Meaning, say you hacked someone and get their email, leak it. I've seen what that does to people, but leak it. Nothing stops you from adding to it and doing it in a forensically sound way, or in a way where some— there's always a pundit that goes, well, it's definitely real, I'm an expert and that's real. It just seemed— and then you have someone who really knows what they're doing going, oh, this looks fabricated. I've worked cases where all the evidence was fabricated. Created digitally. That was amazing to me. Couldn't believe it. Um, at least my opinion was it was, and people agreed with it. Uh, in today's day and age, it's just too easy. We all have digital lives. We all rely on technology more than ever before. You have wearables that tell you how much you sleep, when you should take pills or drugs. You have wearables that might even— you may even have apps that require prescription at some point in time because, you know, you have something on your wrist that says you need more of something.

02:39:53

You know, I'm sure it already exists. We rely on this tech so much. But the unfortunate reality is you can take it, you can take that data, you can skew that data, you can use it against people. All our— we have a whole generation, Sean. I think they— all their deepest thoughts is already written down, you know, in the text they shared, in the photos they share. Maybe we've waived the right to privacy, and maybe that's the transition mankind's going through from the private life and, you know, people didn't need to know our thoughts. Now everybody knows everything we're thinking. And maybe we cross the chasm and just recognize it's okay to think whatever the hell you want, how dark it is or how great it is. But we haven't crossed it yet. So damn.

02:40:38

Yeah.

02:40:39

So that's what I would do on offense. That's what I taught, you know, when I was at the Naval Academy, we were talking about it and everybody was coming out with their neutron bomb blowup. GPS, and that's what we do before war. I'm like, how about erode confidence in your lawmakers and your business leaders and how easy that is to do? And it is easy to do. One allegation creates doubt in a lot of people, whether it's founded or not, you know. So we need to have a better system to, uh, they call it a cancel culture. Um, you know, it's tough.

02:41:09

Damn.

02:41:10

Yeah, sorry, dark stuff, man. We gotta end on We need some sunshine.

02:41:14

Well, I don't think we're going to get any anytime soon.

02:41:17

But the hypothetical is, how do you attack us? What do we do about it? Boy, is there ever a time for critical thinking, you know what I mean? And how do you teach that? How do you train that? And honestly, and I've heard you talk about this, and you're exactly right, and this is a cybersecurity episode, but when studying cybersecurity, it's directly related to ideological conflict, you know? Period. It really is. People with opposite opinions gotta learn to talk and respect each other. The American way has got to be you can have a disagreement, still be fans of each other. Yeah, you know, so we kind of—

02:41:53

we have definitely lost that.

02:41:54

It reflects it in cyberspace too. It really does. Like, it's— we used to be able to— this is something that happened in my career— if you committed cybercrime in the United States, you got caught, and penalties were stiff. They— a lot of people would argue they were really stiff because judges and lawmakers didn't like the invisible crime and the anonymity of it, and they wanted to stop it because it was maybe too easy. So you have a severe penalty because of how easy it is. And, um, suddenly in the last few years, we're running into Western Hemisphere hackers and they're not getting arrested, and I don't know why. You know what I mean? Like, in my career, I had at least a 25-year run. If you hacked from LA, oh man, You got caught if you hacked from anywhere in this country. You got caught if you were doing it in Canada. You got caught. It's seemingly getting harder, and I don't know what's going on, but we do now have— in my career, we're responding to intrusions and the threat actors are on our continent. Isn't that weird? Didn't used to be the case.

02:42:51

And hopefully we get, you know, we get back to where we were. We push all unauthorized or unlawful internet-based activity for the most part. We got to get that. We ought to be able to control our backyard.

02:43:07

The internet wasn't built with your privacy in mind, but Glacier was. Open the app, tap connect, done. You're protected. Remember, privacy isn't paranoia, it's protection. Do you ever wonder what it takes to make an episode of The Sean Ryan Show? In this exclusive studio tour, I'm taking you behind the scenes for an in-depth look at every part of the operation, from the editing room in the main studio to the spaces where we film range day content and more. You'll see how the show comes together, meet some of the people behind it, and get a closer look at the work that happens off camera. When you become a paid member of the SRS Patreon community, You get more than just the podcast. Watch new episodes early alongside other members. Join monthly live shows with guest Q&As and submit questions just like you see on the show for upcoming guests on the Protector tier. You'll also unlock exclusive range day videos, behind-the-scenes content, and premium ambience videos that you're not gonna find anywhere else. Join the Patreon community today and get access to the full experience. Let's move into our 4 adversaries. Yeah, who are they?

02:44:39

In cyber, you got to go with Russia. It's a two-trick pony— criminal and real foreign intelligence services, high capability. When focused, they are Wayne Gretzky on the penalty shot, right? They're, they're real good. Uh, China, massive scale and scope. You can add all the threat groups I tell you up and they do not create the volume of compromise that the Chinese government does. So all of it together— criminal, Russia, North Korea, Iran— all of it together doesn't add up to the steady tsunami of Chinese-based intrusions. And we only know what we know. But we look at my old company, Mandiant, responds to over 1,000 cybersecurity breaches a year, Sean. And these aren't the ones you're 5 minutes behind. We get hired when the scale and scope of the intrusion requires additional expertise, and that's us. And we're responding with companies that have great talent and great defense, and we're still showing up going, all right, how did they break in? And it is new and novel attacks. It is things that would work 99% of the time or higher. Um, and that's, you know, so we've got to respond to those. And when we look at that, without a doubt, since 2004, China's led the way.

02:45:54

We've always responded way more to breaches coming out of China. Um, they follow rules of engagement that I don't think are written down, but they are polite hackers. They don't delete your data, they don't destroy your systems. They steal things. Russia hacks for security reasons. And, you know, the SVR, in my opinion, follows probably the same rules our offense does, but their FSB, GRU are a little bit more broad than what we would ever probably allow. And I've heard stories of Russian threat actors that hack for the government during the day and hack, you know, to make money at night. I believe it. Certainly Russia condones all crime being done in the cyber domain, period.

02:46:34

But they actually Yeah, from what I've heard, both China and Russia, I mean, they have put on classes, courses, schools.

02:46:43

Oh, totally.

02:46:44

And in the schools, they, they actually just hack the US as a training.

02:46:50

I think with China, they'll hack not to make money though, you know, not, not directly. Russia, they would. And so North Korea only hacks to make money, it seems. I mean, in reality, North Korea is the only people in uniform badging into a building every day, or at least show an ID to get in, are hacking to make money because they fund themselves. Isn't that incredible? And have you heard about the North Korean IT problem where it's not hundreds, thousands of North Koreans have been hired by companies in the United States because we all started hiring remotely during COVID We hire IT professionals. They speak English. They know what they're talking about. But they're actually North Koreans, and you hire them, and a couple days after you hire them, they just steal all your crap and go. And sometimes they keep working for you because you're paying them $130 grand a year. There's a, a podcast coming out by Nicole Pearlroth, and maybe you'll meet Nicole. She's a New York Times reporter. She's doing her story on this now. Her last podcast was on the Chinese cyber espionage campaigns, and she can do things I can't.

02:47:50

Like, she'll say things I say, or she'll talk to the victims and follow up, when I never got to do that. She saw the ramifications of companies losing their IP. I just saw what the attackers did and how to clean it up. She's doing a North Korean thing now. And when I first heard that problem, hey, North Korea, you know, has IT workers getting hired, I'd like burst out laughing. There's no freaking way that this can be a problem. And, and I was at a conference with a bunch of heads of security from really reputable And as soon as I was like laughing it off, like 5 of them came up to me and started saying, hey, no, we have the problem. And when they explained what happened, I went, there's no fix for it, dude. The fix is you've got to get people in the chair across from you and hire them. And the problem is we literally hire internationally. Many US companies will hire people in Europe through Zoom, Google Meet, you know, or Microsoft Teams. These are programmers that can answer the questions right. I mean, and quite frankly, they'll even do the damn job for you.

02:48:52

It just so happens you're paying someone who's working for a weapons of mass destruction unit, you know what I mean? Literally. And so the North Koreans, you may hire them and then they hack to steal Bitcoin. They're hacking to make money. Russia's hacking for spying and crime. China's hacking for spying and long-term economic gain through theft of IP. In Iran right now, you know, with, with what's going on, the excursion going on right now, the, um, the, the— it's like you're— the cyber domain was already a crappy neighborhood. Think of it as it's like Camden, New Jersey. No offense to Camden, tough place. It just got 5 new gangs to it, you know what I mean? It's like cranking it, as they say in Spinal Tap, crank it to 11. The cyber domain, if you can be hacked by an Iranian effort, they'll do so. But the way they break in right now is with, uh, user accounts and passphrases that are already on the dark web. Like, you lost your user ID and passphrase from some prior breach somewhere, maybe your own company, maybe somebody else's. They tend to brute force log in, and then they're going to delete everything if they get in right now, whoever they are, the gangs that want to support the Iranian cause.

02:50:03

So, um, yeah, do you think we'll see any retaliation from in the cyberspace from what's going on in Iran?

02:50:10

I think right now there's probably automated programs running on behalf of the Ministry of Security, Intelligence and Security, MOIS, over there that if it can break in, will. And then they got to get a human operator to go do something with it. It doesn't take a lot of bandwidth. Bandwidth, if you can get, you know, you don't need a whole lot of satellite dishes to get something working for you there. Yeah, you'll see something and it'll be real hard to tell, Sean, whether it's really the Iranians or proxy or just somebody who wants to hack for the hell of it and, you know, make some noise.

02:50:46

Which one of these, you know, out of Russia, China, Iran, North Korea— yeah, which ones, who are you most worried about?

02:50:53

You worry about them for different reasons. I, I would say sophistication now goes to China for how they first break in. How people break in will always change. China seems to be the forerunner of what's called 0-day development. Now they can find, uh, attacks that are going to work. And then, but when they break in, they're not leaking your email to the press, they're not extorting you. Those are really complicated. So I would say Russian criminal, really hard to go against. There's some now Western Hemisphere criminal gangs. There's a group called Shiny Hunters, there's a few others, uh, that they break in with social engineering. They'll like call your help desk and help desk help people. And they have whole scripts written and they're very bold and they get one-time authentication into your network and they, you know, then go in. And once you can get any beachhead in the cyber domain, usually that means you take the island. Um, you just need that one boot on the ground and you'll do fine. So you need one way to access a network, you'll, you'll spread from that. Um, the Russian criminals are really hard to deal with.

02:51:55

The Now we have Western Hemisphere criminals. They're really, really hard. Iran's going to delete everything right now, probably, if they get in. That's not going to be a fun cleanup. They're all bad. I mean, that's the reality, Sean. But the public humiliation does not come from being hacked by the Chinese. That, you know, those you can handle quietly and discreetly. I think it's the Russian and the North Korean and the Iranians probably going to go public. And that just adds complexity to your response.

02:52:25

Gotcha. Yeah, gotcha.

02:52:28

All right, how you hanging in there? Scary shit.

02:52:33

So, right, yeah, we gotta get more optimistic as we move into your new company. You got a hot question. Yeah, so you know Claude, I'm sure.

02:52:41

Oh God, Anthropic. Yeah, totally.

02:52:44

So we had Claude Anthropic say, I scraped the internet to ask you a question.

02:52:48

How did it do?

02:52:48

And here's what it came up with. In 2010, Stuxnet became widely known as the worst— first— the world's first cyber weapon. Why? The U.S. and Israel used it to physically destroy Iran's nuclear centrifuges. That was 15 years ago. Now, with AGI being reported as achieved, do you think AI is the new cyber weapon and why?

02:53:15

Fast answer, yes. You have to use all technology to advance crime, to advance war, to advance societies. It does all of it. Does good, it does bad. Um, the invention of the gun helped the hunter, but it also helped criminals to some extent, depending on your frame of reference. AI will make the speed of intrusion take the human out of the loop. That's what it'll do. It's too fast at discovering vulnerabilities. The— so I started Armadin and combined what's called red team consultants, the best red teamers in the world. These are folks that get paid to hack into Fortune 500 companies and see if you can stop the train or corrupt the food or shut down the grid or steal the email from the CFO. We took those guys, and we're still hiring a bunch of them, and we paired them up with AI-native developers and said, automate what we humans do. And we started this company September of last year, Sean. Here's what I can tell you happens already. If somebody tells us, they hire our red team and says, take a look at this custom application, you build an application that you gave me here, someone will say, take a look at this application, can you hack it?

02:54:29

What used to take us 5 days with 2 smart humans is 5 minutes to 10 minutes with AI now. That already exists today. So what you see is the compression down, but it gets unfortunately more daunting. When we go on offense as humans, we only find one way in at one point in time to achieve the goal you've told us to try to achieve, try to shut down the assembly line, try to get to our IP. We find the fastest path in, we prove it, and then you fix that. With AI, we launch 100,000 threads coming at you. It finds all paths in almost immediately, but it does a few things humans can't do. Has total recall the next time we ask it to do that. So if there's a vulnerability it found at Company A 2 months ago, it instinctively already knows, look for that again, just in case you didn't fix it. The— it's the speed though. The fact that AI can think, learn, and has total recall and can be trained, it will be the cyber weapon in the future. Just like no different than drones. If you think you can fight the next war and win, you better have software that thinks, learns, and is secure.

02:55:43

And you better hope it thinks the fastest, learns the fastest, and is the most secure to win that war, or you're going to lose. And that's going to be cyber domain. That's going to be autonomous planes, drones, you name it. So yeah, there's a follow-up. Got it.

02:55:58

On a different note, by 2027, every new car in America will have an infrared camera pointed at the driver's face, and that's by federal law. From a cyber security— from a cyber security expert's perspective, what's your honest take on this? Does this leave vulnerabilities for our adversaries to hack American vehicles?

02:56:18

There's been an equal and opposite compelling argument inside security since the dawn of time. If we're distributed, it's harder to beat us, but it's harder to defend us. If all our eggs in one basket, it's easier to defend but easier to beat us. Does that make sense? Right now we're putting data about everything everywhere. I mean, I grew up, there were no cell phones in college. Otherwise I would never be able to be a Supreme Court Justice. All right? Evidence would exist. Uh, now there's cameras everywhere for everything. Um, there's just no question, even though it's going to get harder and harder to compromise things— I believe that. Um, you know, the internet was pretty damn open in the '90s, and I, you know, and I've lived that. It was pretty damn open 2000, really till 2020, 2021, and we're in a whole different world. AI is going to help us write more secure code, there'll be less vulnerabilities. But at the same time frame, should someone break in, I think the impact is going to be far more than what it used to be in the past. You know, early on in this interview, you asked, what was the worst breach we saw?

02:57:21

And I remember going, I always hated it if a flag officer lost his email. That's just weird, you know, because they do important things. Fast forward to now with wearable devices and our dependency on, on everything, uh, whole businesses can't operate if the internet goes down. So AI will be the offensive choice. And unfortunately, because of the speed of compute, AI is going to have to be the answer on defense. And that's why Armada didn't exist. We will be the ultimate offense built by the good guys to train and automate the defense. And every company is going to need a different defense. We're all going to write our own apps. We talked about Anthropic and Claude. Talk about magic. I had a computer science degree. I hate to say it, don't tell your kids to get a computer science degree, okay? Um, heck, ask the CEOs of these companies at, you know, ask Dario at Anthropic, hey, you want your kid to learn computer science? You'd probably say, uh, it's like learning Latin, no one's going to speak it. The computers are going to do it for us. The whole goal of Anthropic is to have Anthropic's Claude build the next Claude.

02:58:29

At Armageddon, we want to get our AI attacker to be so good it's building its next AI attacker. They self-propagate. And the unfortunate reality is we have to build it or the adversary will. And it is the only way to get to autonomy. But back to your original question. Yeah, we're going to have cameras in the cars, cameras on the streets, cameras in our homes, data everywhere. I think it'll be harder to break into all that stuff. But should the break-in occur, I think the impact will be grave, more grave than in the past. Now I'm thinking today, 2 years from now, you should be driving a car that has something in it that instantiates normal Sean driving. And if anything happens, something very bespoke to you can recognize and say, that's not him, that's not what he wants, that's not what he does. And it may save you, it may do the opposite of that. But we are going to have defense that can thwart attacks we've never seen before, you know, and do it in a way that a human's not in the loop for. Something's asking this system to do something it's never done before.

02:59:38

May automatically get stopped and ask for a human in a loop to say, hey, listen, this has never happened in this car before. Do you really want it to happen? Or this never happened on your computer before. Or on this camera before or on your HVAC before. Do you really want to allow it? Stuff like that will exist.

02:59:55

Interesting.

02:59:56

And then you'll pick in your house, you'll say, I want to be prompted every time someone's accessing my camera. Other people, it'll get trained specific to them. It'll get one time human in the loop, go ahead and allow it to happen. And after like 3 times where the user says, go ahead and allow the program to do something, it'll just do it from there on in. We'll all have bespoke software trained by you. Your phone will end up being trained by you. The AI on your phone will know you, be personal to you.

03:00:24

There's got to be vulnerabilities within that alone.

03:00:28

Well, yeah, you often wonder— you now we're talking to AI Skynet story, right? One brain in the sky. Doesn't that mean we all share one brain over time? And, uh, and that brain will always reflect the, the culture of those who built it to some extent, right? And then all AI models, no matter what anybody says, we, we had to at Armageddon build a way to— as soon as they updated Frontier Labs, their models, we plug them right into our shooting range and see which ones are the best at the things we normally do now. And they'll flip and flop all the time, or they'll be about equitable, and we test them on the range, as they say. But these things, you test them day 1, you test them day 20, they're already different. They're like, they're like organisms that grow. These models learn and change and sway in ways that are different. Like how we— what we get out of a model today could be totally different tomorrow. Not totally different, it's always, you know, kind of, you know, to me, I haven't gotten a hallucination in a long time, and I use Gemini a lot, and I use Claude a lot.

03:01:22

I'm a little bit less OpenAI, and I use it for real stuff every day. It's common I'll have like Claude running on something that I want because it's great at making PowerPoint slides, and I'll have Gemini making some graphics for me or answering questions. I'm using them both.

03:01:35

Interesting. Yeah, interesting. Where did the motivation come from to start Armageddon?

03:01:40

Has to exist, right? It's— I, I get two, two things. One, I wanted our— the first motivation is, you know, my company got bought by Google, and I'm an entrepreneur. You know, some people would say once you're an entrepreneur, you can't sell your baby. I had no problem being a public company and getting bought. Company was no longer mine. I was the face for it. But if you're a great entrepreneur, at some point in time you're also the owner. But, you know, I had no problem letting it go. I was bought by Google and I went in like a lion, super— like, Google can change the world. It really can. The resources it has. I just didn't fit, you know. So I was a little upset in a way that I didn't fit there because I know the power and capability of that company, or Amazon or Microsoft. We have great companies. They can do great things in cybersecurity, and you want to be a part of that. But one thing they would never do is offense. And I respect that. I get it. Wouldn't fit with a large brand. And I thought to myself, the exact thesis I had was the first intel on the internet was terrible.

03:02:41

You had to find what Symantec missed and give it to them. The second intel on the internet, I feel I created. We'll respond to every breach that matters. And people were like, that's not even a market. There are no breaches. Oh, there were. We responded to all of them, and we learned about the new and novel attacks first so that we could build better defenses against them. Well, the third wave of intel is we're going to create the attacks, and we're going to create them before the bad guys do, and we're going to fix your problem before they come out. It's almost, I guess they call it gamification in a way for viruses. But if you can create the viruses that are coming 10 years from now and inoculate today, we're ready. You know, same thing here. But we have to build it because, A, it's going to be what we're up against. And if you want to know if a bulletproof vest works, you got to shoot a bullet at it. We're going to be shooting bullets at networks. And if you can withstand our bullets, the assumption— and what we want to become is that seal of approval.

03:03:33

If Armadin can't break in, oh, you're good to go. Brief the board, let them know. There's no other way to reduce your cyber risk. And I actually believe that. So we started Armadin. So that we can dry run and practice what we're up against. And it's common. There are no risks or repercussions to the folks stealing from us, hacking us. It's just we haven't shown a, a means to impose risk to these threat actors. So you get—

03:04:00

you got into it a little bit, but what is the future of cyber warfare with AI coming online?

03:04:08

Oh boy. You will have systems dedicated, I think. So the general models are what are called horizontal models. Like Anthropic's Claude is a horizontal model, right? OpenAI, horizontal model. X has a model, Gemini for Google. There's gonna be very verticalized models where you train 'em and learn from these huge models that have read every book every human's ever written or watched every YouTube video of everything. You've contributed to models probably and you don't even know it.

03:04:34

It.

03:04:35

And you're going to, you're going to have offense against very specific things. Like we're going to end up creating models that are offense against cell phone, offense against drone, offense RF against drone, offense against Windows, offense— like deep models that are actively working the same way a human did, but at thousands and thousands of times the speed and doing the same task we did to try to find vulnerable code. Vulnerable IP, you know, it'll all be automated, uh, and specialized for the targets they go after. It's going to happen. And, and the sad thing is we had to build Armadin because it's automatically going to happen. Every shift change— I lived through this, Sean. In 2000, there was a guy named Alexei Ivanov and a guy named Vasily Gorchkov. At the time, in 2000, Alexei was 18 in Chelyabinsk, Russia. Facilities, 25 in Chelyabinsk, Russia. These guys extorted hundreds of U.S. companies. They would break in, and what they did is they scripted everything. They even scripted— we got to do the forensics on their laptops. These two Russians were lured to the United States for jobs, and the jobs they got were with the FBI.

03:05:48

The FBI lured them over. They flew into Sea-Tac Airport or Tacoma Airport, and They got arrested. And when you look at what they did, it was at a time when PayPal was just coming out, eBay was getting big. These guys had monetized that they could steal credit cards and they wrote software that would sell fictional items on eBay, buy it with stolen PayPal credit cards, and they were making money selling fictional stuff. And the whole thing was automated. They could literally hit buttons, script it, and walk off and come back back with, we made $72,000 selling stuff we don't even own and buying it with fake stuff. Yeah, happened. So every shift change is embraced by every personality. AI is going to be embraced by the criminal element, and it's coming, and we can't withstand it unless we build it ourselves and figure it out. So I always believed the best way to build a safe at a bank is get the best bank robber to build it for you. You know, you got to know how to rob banks to investigate a bank robbery. And I had the privilege of training thousands of FBI agents at the FBI Academy.

03:06:53

So when it came to cyber, we taught them how to break in, get a sense of what you're up against, the actors, why they do it, how they do it. And now let's investigate what they did. And you couldn't really just start with, let's just investigate it. It just wouldn't work. You had to give them that sense of doing the criminal act and then investigating it. Um, it's going to happen in cyber. We have to build the offense offensive cannon. So Arminian's going to build the cyber cannon. We're going to shoot it at the best companies in the world. And those companies, if they can withstand the blast, they're good to go. And if they can't, we're over time with no human in the loop building fixes to however we broke in. If we find a permeable membrane and we get through, you're going to patch it, you're going to compensate for it. And that is the future. And oddly enough, that future's scalable. Finally, You can— once we build the AI on offense versus AI on defense, we can go down to the utility in Aliquippa, Pennsylvania, and say the waterworks is not going to be compromised, and the small mom-and-pop electric company in Missouri will not be compromised, because we can now instantiate a national risk policy through an offensive cyber count and training the defense.

03:08:04

And it's just software. You're not going to be people dependent. It really is going to happen. And will it have flaws? Will we get beaten?

03:08:11

Yes.

03:08:12

There will every once in a while be something on offense that gets through. But you can literally use the analogy of drone swarm in the cyber domain. Like, you're going to, you're going to send 3,000 drones at a city and we can only shoot down 2,990. You know, we have the same problem in the cyber domain. We're trying. But the best part of it is it will be automated and it's actually going to raise the tide for cybersecurity for most people. And then the bigs will always have their own team still doing stuff to help secure.

03:08:44

I'm just curious, and I'm sure it's very different, but on average, how many vulnerabilities are you finding per company and how fast do you find them with these AI agents?

03:08:57

As I sit here today, it's never taken longer than a day to break in.

03:09:00

Shit.

03:09:01

Yeah. With anything you have up in the air. Yeah. And here's what's interesting. So I can tell you this. I still think the best findings we had were by humans, but that's going to go away within a year. And nobody knows how fast, but AI keeps surprising us. But here's how we broke in the first time. A Fortune 100 company literally said, hey, break into us and see if you can break this custom application we built. Well, very important application. We have an AI agent. They didn't even expect us to do this, but we've done this a lot. We had an AI agent go out to the dark web and go to a bunch of password brokers, and we found 440 or so accounts that were the domain of this company. And all we did is tried all of them at human speed, not AI speed, because AI speed's too fast. You can rate limit and block it. Cisco routers can block fast attacks. We just logged in. 7 of the accounts actually just logged into the app. We just logged in. And this is an app you don't really want people logging into. And on one of the things— and we did it all human speed.

03:10:02

You saw a browser just kind of pop up on our agent screen. It was acting like it was a human. Tried all the accounts it found. It gets in 7 times. But on one of them, the app we broke into prompted, you don't have multifactor authentication turned on. Would you like to register your phone? So we did. So now we literally hacked the company by stuff we found on the internet. And, but humans wouldn't have found it because it's really a pain in your arse. If you script it, it's too fast and you get blocked or detected. If you have a human log in every time, it takes days and it's annoying and they're gonna fat finger stuff. We just all automated, no human intervention, hacked the company. That was it. And that works. I would've bought that. When I was a CEO, I would have been like, I just want that. I don't even need you to try to hack my app and break in the old way with a vulnerability. Just tell me if you can log into my damn network, because that stuff changes. Everybody thinks, oh, we have two-factor authentication, meaning user account passphrase, and then, you know, the digits to your phone or, you know, your fingerprint and all this other crap.

03:11:02

I would want to— you can't— there's no magic wand that says, do we have two-factor everywhere? It doesn't exist. But this would prove it. The attacker's view of your network matters, and AI can comprehensively do that. So I'm not convinced— just yesterday I got a text. I'll show you when we're off camera of what we did to a company yesterday. 100% ownership of every machine, day one. We got into all of it. And here's the secret in cyber. So for everybody out there listening, the hardest part's getting in from the internet. Every company does everything they can to— well, at least above the poverty line in the cyber domain. The 1A enterprises do about everything they can to not have a breach. They don't want to deal with it, and they're truthful about that. They hire good people and they try. If we can't get in, I would say over 90% of the time we do. But once we get in, it's easy as hell. It's all downhill skating at that point. So Sean, that's just the problem right now. Everybody's built their Maginot Line and they've hardened that as much as they can. If we get around it, Oh, it's just waltzing into Paris.

03:12:03

You know, it's too easy once we break in. Everything we need is on the very first machine we get to. And usually the Achilles heel is every company has one account that works everywhere so you can patch things, so you can fix things. You can't keep that account from us. That's just the Achilles heel. So it's funny, the very thing you use to make sure you're secure is probably the very thing that we get every time to make you insecure. Secure, you know. So anyway, we will get better. Everything— as bad as this whole 3 hours or so is gone, everyone's getting better at cyber defense. We are in a tough time. The offense is still uniquely advantaged. That's the problem. I think it does change in under 2 years. To equitable, I don't think defense is— the only advantage defense has is we should have access to the software we build to make it secure before the offense can try to hack it. That's our only advantage. We can secure our code before we publish it, get it out the market. And the, and the Anthropics of the world are making that a reality.

03:13:04

Microsoft, Anthropic, Google really are making it so the code we're writing is better today, not worse. That is happening. So in theory, it'll get better, Sean.

03:13:15

That's good news.

03:13:16

Yeah, it's just we're going through 2 years from now, this dialogue would be different. I would say, you know what, we're stopping 99.999999% of attacks now. It's just the best in the world. We never get to stop them. They are— they're scoring.

03:13:32

Wow.

03:13:32

Yeah.

03:13:33

Well, Kevin, we're wrapping up the year.

03:13:35

Yeah, sure.

03:13:35

This has been— I've learned a ton.

03:13:38

Really? Yeah.

03:13:39

So thank you for coming.

03:13:41

Thanks.

03:13:41

One last question.

03:13:42

Yeah, sure.

03:13:42

If you had 3 guests to recommend for the show, who would they be?

03:13:48

Well, I love Bruce Springsteen.

03:13:49

Bruce Springsteen.

03:13:50

All right, uh, 3 guests for your background. If you do another one in cyber, the best person that can bring this to everyone is Nicole Perlroth, the New York Times reporter I told you. She is exceptional on camera, and she tells better stories than I do. Yeah, because I came up through computer science and had to solve the problems. I had less of a humanity side to me. When I met CEOs, I was always like, hey man, sucking up, deal with crisis. She's better at it. She tells better stories as to what China did, uh, what— and what the North Koreans are doing. She's more personable, more likable. So she's a great one for cyber.

03:14:26

Those are the—

03:14:26

you know, and I don't know, you're doing a great job. People like listening. Like, I listen to Kent, the guy that used to have— okay, yeah, I thought he was great. I'm apolitical. I want the United States to be successful. I thought he did an incredibly good job doing the same, being apolitical. People probably hate the guy. I'm probably getting in trouble saying it. I just listened to it and thought, okay, I learned something. You know, you listen to, you know, bottom line, you get both sides. You get, you get people that at least are— I think that's important.

03:14:54

I get a lot of—

03:14:54

yeah, I mean, it's, uh, it's important. So anyway, I'll give you those two. Springsteen's always good.

03:14:59

Perfect.

03:14:59

It's getting old.

03:15:00

Well, Kevin, I really appreciate it.

03:15:02

Thank you. Hope to see you again.

03:15:16

No matter where you're watching The Sean Ryan Show from, if you get anything out of this at all, anything, please like, comment, and subscribe. And most importantly, share this everywhere you possibly can. And if you're feeling extra generous, head to Apple Podcasts and Spotify and leave us a review.

Episode description

Kevin Mandia is CEO of Armadin, where he leads the company's mission to secure some of the world's largest and most complex environments. A globally recognized cybersecurity leader, he is also a General Partner at Ballistic Ventures, mentoring and investing in the next generation of cybersecurity entrepreneurs. Best known as the founder of Mandiant and former CEO of FireEye, Mandia helped redefine the cybersecurity industry through pioneering digital forensics, the groundbreaking APT1 report exposing state-sponsored cyber espionage, and his leadership during the SolarWinds attack. Today, he continues to shape cybersecurity strategy, national security policy, and the future of AI-driven defense.

Privacy isn't Paranoia. It's Protection.

Download Glacier - https://srs.site/glacierapp

Website - https://theglacierapp.com

Shawn Ryan Show Sponsors:

Get 10% Off your entire order & take advantage of Ridge’s Annual Sweepstakes by going to https://www.Ridge.com/SRS #Ridgepod NO PURCHASE NECESSARY. Open only to legal residents of the promotion territory, who have reached the age of majority in their jurisdiction of residence. Void elsewhere & where prohibited by law. Enter by 9:00 a.m. USPT on 8 September 2026. 2 winners, prizes total ARV: up to approx. $539,165 CAD / £284,170. Skill-testing question required in CA. See Official Rules at ridge.com/pages/rules for complete eligibility, entry instructions, how to enter without a purchase, entry limits, prize details, odds, and restrictions. Sponsor: The Ridge Wallet LLC.

Get started with Claude at https://claude.ai/srs and use promo code srs for access to all features mentioned in today’s episode.

Visit https://betterhelp.com/srs. #ad

Go to https://calderalab.com/SRS and use code SRS for 20% off your first order.

Kevin Mandia Links:

Armadin - https://www.armadin.com

Ballistic Ventures - https://ballisticventures.com

LinkedIn - https://www.linkedin.com/in/kevin-mandia-0a07173
Learn more about your ad choices. Visit podcastchoices.com/adchoices