Logo
    Search

    Podcast Summary

    • Password reset request leads to major heistImposter gained access to network, transferring millions after password reset. Emphasizes importance of securing access to sensitive info.

      A seemingly innocuous password reset request led to a major heist at MGM Resorts in Las Vegas, resulting in the potential loss of tens of millions of dollars. The incident began on a typical busy Friday night when an imposter called tech support posing as an MGM employee, requesting a password reset. The tech support team, following protocol, complied and granted the imposter access to the account. However, this seemingly minor event raised no red flags initially. It wasn't until the following day, when MGM's IT department started noticing unusual activity, that they began to suspect something was amiss. The thieves had used the compromised account to gain access to the network and began transferring large sums of money from various MGM accounts. The incident highlights the importance of securing access to sensitive information and the potential consequences of seemingly insignificant security breaches.

    • MGM's Unusual Hacking IncidentRobust cybersecurity measures are crucial to prevent unpredictable cyber threats and protect sensitive data, even from less conventional hacking groups like Star Fraud.

      Hackers breached MGM's network and caused significant disruption. They were not only trying to steal sensitive data but also left behind juvenile jokes and crude behavior, which is unusual for hacking groups like the Chinese or Russians. MGM's CEO, Bill Hornbuckle, was attending a dessert-themed fundraiser when he received worrying messages about the intrusion. The IT department was struggling to remove the hackers, who kept finding new ways to re-enter the network. By midnight, Hornbuckle recognized the gravity of the situation and initiated a defense strategy, including cutting off email access and bringing in a cybersecurity firm. The group responsible for the breach was identified as Star Fraud, known for their advanced hacking abilities. This incident highlights the importance of robust cybersecurity measures and the unpredictable nature of cyber threats.

    • US-based cybercriminal group Starfraud uses cultural similarities to manipulate victimsStarfraud, a cybercriminal organization primarily composed of native English-speaking teenagers from the US, UK, and Canada, uses cultural similarities to impersonate employees and manipulate victims, causing significant damage to US cybersecurity with attacks ranging from account theft to company disruption.

      Starfraud, a cybercriminal organization, has emerged as a significant threat to US cybersecurity, with most members being native English-speaking teenagers from the US, UK, and Canada. Their ability to impersonate people and manipulate victims over the phone, due to cultural similarities, gives them an advantage. Starfraud has evolved from causing mischief in video games to stealing accounts, breaking into phones, and stealing cryptocurrency, and even freezing the operations of companies. They have targeted high-profile companies like MGM, Clorox, and Caesars, likely for both financial gain and bragging rights. The group's success lies in their ability to impersonate employees over the phone, using native English fluency to avoid detection. Understanding the origins and motivations of Starfraud highlights the importance of addressing cybersecurity threats from within one's own cultural sphere.

    • Efficiently hiring candidates and handling cybersecurity threatsUsing platforms like Indeed for scheduling, screening, and messaging can streamline hiring. Drastic measures may be necessary for cybersecurity threats, but they should be taken carefully to minimize impact.

      Relying solely on searching for candidates online may not be the most effective hiring strategy. Instead, utilizing platforms like Indeed for scheduling, screening, and messaging can help streamline the hiring process and connect with candidates more efficiently. Additionally, when facing a cybersecurity threat, drastic measures such as shutting down certain systems may be necessary to prevent further damage, even if it means temporarily disrupting business operations. However, it's important to note that these measures should not be taken lightly and should be implemented carefully to minimize impact on customers and business operations. Despite MGM's best efforts to prevent a data breach, the hackers were able to bypass their defenses and demanded a large ransom. It's crucial for companies to stay informed and responsive to cybersecurity threats to mitigate potential damage.

    • MGM Resorts faced a ransomware attack causing widespread disruptionA successful ransomware attack can cause chaos and significant financial impact, emphasizing the importance of strong cybersecurity measures

      MGM Resorts Properties experienced a major disruption due to a combination of their own systems shutdown and a ransomware attack by the Starfraud group. The hackers were able to plant destructive software before being kicked out, causing widespread issues including slot machines and ATMs going offline, email systems down, and guests unable to use digital keys for hotel rooms. The hackers then began pressuring MGM to pay a ransom, threatening to release digital keys to unlock the systems. MGM faced a difficult decision between paying the ransom and potentially trusting the hackers or rebuilding their computer systems from scratch. The attack highlighted the potential chaos and financial impact of a successful ransomware attack, and the importance of strong cybersecurity measures to prevent such incidents. Rebuilding computer systems from scratch is a significant undertaking, requiring extensive resources and time, much like the process of getting a new phone.

    • MGM's Refusal to Pay Ransom Saved More in the Long RunRefusing to pay a ransom can save more in the long run despite initial high costs and potential risks. Address vulnerabilities to prevent future attacks.

      Fighting off a cyber attack, even if it means starting from scratch, can be more cost-effective in the long run than giving in to the attacker's demands. This was the case for MGM when they experienced a ransomware attack in 2020. Despite the attack causing chaos and costing over $100 million to recover, MGM refused to pay the $30 million ransom. The risk of decryption keys not working and the possibility of extortion were concerns, and once systems were rebuilt, confidence was regained. However, it's important to address the initial point of entry for attacks, such as the tech support system, to prevent future intrusions. The rise of ransomware attacks tricking tech support into resetting passwords is a growing concern as it's a widespread vulnerability. Extraditing cybercriminals from countries with difficult legal systems remains a challenge.

    • Teenage hackers and journalist detention pose challengesComplexities in pursuing teen hackers and journalist detention threaten individual rights and press freedom

      The issue of teenage hackers, even if they are located in the West, poses significant challenges for law enforcement due to the complexities involved in pursuing minors through the legal system. Additionally, the detention of Wall Street Journal reporter Evan Gershkovitch in Russia on espionage charges serves as a stark reminder of the risks journalists face while reporting on critical global issues. The journal's editor in chief, Emma Tucker, denounced the detention as an attack on press freedom. The complexities of pursuing teenage hackers and the ongoing detention of Evan Gershkovitch highlight the importance of continued dialogue and cooperation between law enforcement, legal systems, and media organizations to protect individual rights and ensure a free press.

    Recent Episodes from The Journal.

    Will the U.K. Send Asylum Seekers To Rwanda?

    Will the U.K. Send Asylum Seekers To Rwanda?
    After a steep increase in migration, the United Kingdom turned to a controversial plan: sending migrants to Rwanda. But the plan has faced years of delays and legal challenges. Max Colchester explains why the U.K. pushed ahead, and what Rwanda stands to gain.  Further Reading: - Britain’s Radical Plan to Tackle the Migrant Crisis Turns Into a Cautionary Tale  Further Listening: - Smuggling Migrants Toward the U.S. Is a Booming Business  - Texas Took On Border Security. Is It Working?  - What the End of Title 42 Means for U.S. Immigration Policy  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJuly 02, 2024

    Trump Has Broad Immunity

    Trump Has Broad Immunity
    The Supreme Court dealt a major blow to prosecutors hoping to convict Donald Trump on charges he sought to subvert the 2020 election. The court ruled 6-3 that former presidents enjoy sweeping immunity for their acts while in office. WSJ's Jess Bravin discusses what this ruling could mean for the future of American democracy.  Further Reading: -Supreme Court Deals Blow to Trump’s Prosecution, Ruling He Has Broad Immunity  Further Listening: -Will the Supreme Court Kick Trump off the Ballot?  -The Origin Story of Trump's Guilty Verdict  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJuly 01, 2024

    Farm-to-Table Pioneer on Why We Still Need Better Food

    Farm-to-Table Pioneer on Why We Still Need Better Food
    Alice Waters helped the farm-to-table movement go mainstream in the U.S. through her restaurant Chez Panisse. In the decades since she has kept advocating for locally grown, organic food over the fast food Americans regularly consume. Kate Linebaugh sat down with Waters at The Wall Street Journal’s Global Food Forum. To watch a video of the conversation, check out the episode on Spotify. Further Listening: – Could Paris Hilton Create the 'Next Disney?' – Live from Seattle: A Weird Economy + Election Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 28, 2024

    All Eyes on Biden, Trump – and CNN

    All Eyes on Biden, Trump – and CNN
    Tonight, two presidents, one current and one former, are set to debate live on CNN. The stakes are high for the candidates and for the network that’s been struggling to win viewers. WSJ’s Isabella Simonetti reports on how CNN is remaking the debate, and Annie Linskey analyzes what the format change could mean for the candidates. Further Reading: - Presidential Debate Carries Great Opportunity—and Risk—for CNN  - Biden-Trump Debate Takes Shape  - We Rewatched the 2020 Trump-Biden Debates. Here’s What We Learned.  Further Listening: - The Downfall of CNN’s CEO  - Behind Closed Doors, Biden’s Age is Showing  - The Origin Story of Trump’s Guilty Verdict  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 27, 2024

    How Ukraine Built a Weapon to Control the Black Sea

    How Ukraine Built a Weapon to Control the Black Sea
    Ukraine has sunk or damaged about two dozen Russian ships using a technical innovation: naval drones. WSJ’s James Marson unspools the story of the drones’ development and explores how they’re turning the tide in a key area of the war. Further Reading: - How Ukraine’s Naval Drones Turned the Tide in the Battle of the Black Sea  Further Listening: - Ukraine Makes a Deal with Wall Street  - Ukraine's $30 Billion Problem  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 26, 2024

    The Unusual Economics of the Bilt Credit Card

    The Unusual Economics of the Bilt Credit Card
    Rent has long been an expense people wanted to pay on credit cards. In 2022, Wells Fargo launched a credit card with Bilt Technologies that allowed users to pay for rent, avoid processing fees and earn points. But the partnership is costing Wells Fargo millions. WSJ’s AnnaMaria Andriotis reports. Further Listening: -The Fight Over Your Credit Card Swipe  -The Deal That Could Change Credit Cards  Further Reading: -Wells Fargo Bet on a Flashy Rent Credit Card. It Is Costing the Bank Dearly.  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 25, 2024

    Southwest Changed Flying. Can It Change Itself?

    Southwest Changed Flying. Can It Change Itself?
    An activist investor says Southwest Airlines is stuck in the past. Elliott Investment Management says it has amassed a $1.9 billion stake, making it one of Southwest’s biggest shareholders and one of its most vocal critics. WSJ’s Alison Sider explains what Elliott wants, and why critics say some of the things that made Southwest great are now holding it back.  Further Reading: - Southwest Changed Flying. Now It Can’t Change Fast Enough  - Meet the Southwest Superfans Who Don’t Want the Airline to Change  Further Listening: - Ryanair: Cheap, Cramped and Making Its CEO a Fortune  - The Love Triangle Over Spirit Airlines  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 24, 2024

    Zyn pouches, ‘Zynfluencers’ and ‘the Zyndemic’

    Zyn pouches, ‘Zynfluencers’ and ‘the Zyndemic’
    For about a decade, Zyn, a brand of nicotine pouch, was a niche product used by former smokers. But now it’s exploded in popularity and is hard to find on store shelves. WSJ’s Jennifer Maloney explains how Zyn achieved social media virality and has found itself in the middle of a culture war. Further Reading: - Zyn Nicotine Pouches Take Off—and Land in the Culture Wars  - Why America Is Running Low on Zyn Nicotine Pouches  Further Listening: - The Juul Paradox  - The ‘Existential Threat’ Facing Big Tobacco  - How Puff Bar Became the Most Popular Vape for Kids  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 21, 2024

    Sam Altman's Opaque Investment Empire

    Sam Altman's Opaque Investment Empire
    OpenAI CEO Sam Altman has a day job and a side gig. Only one of them makes him rich. WSJ's Berber Jin explains how Altman makes most of his wealth through investing in tech startups and how some of those startups' business relationships with OpenAI raise questions about conflicts of interest. Further Reading: - The Opaque Investment Empire Making OpenAI’s Sam Altman Rich  Further Listening:  - Artificial: The OpenAI Story  - Tesla's Multibillion-Dollar Pay Package for Elon Musk  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 20, 2024

    How ‘Conflict Gum’ Is Helping Fuel Sudan’s Civil War

    How ‘Conflict Gum’ Is Helping Fuel Sudan’s Civil War
    Gum arabic is a widely used but little-known ingredient found in products like soda, gum, makeup and beer. But as WSJ’s Nicholas Bariyo and Alexandra Wexler report, the product has been used for a darker purpose: helping to fund the civil war in Sudan.Further Reading: -How Soda, Chocolate and Chewing Gum Are Funding War in Sudan  -What Is Happening in Sudan? The Fighting Explained  Learn more about your ad choices. Visit megaphone.fm/adchoices
    The Journal.
    enJune 18, 2024

    Related Episodes

    The Growing Ransomware Threat: Targets, Insights, and Strategies with Halcyon's Jon Miller | E1877

    The Growing Ransomware Threat: Targets, Insights, and Strategies with Halcyon's Jon Miller | E1877

    This Week in Startups is brought to you by…

    Scalable Path. Want to speed up your product development without breaking the bank? Since 2010, Scalable Path has helped over 300 companies hire deeply vetted engineers in their time zone. Visit http://www.scalablepath.com/twist to get 20% off your first month.

    Northwest Registered Agent. When starting your business, it's important to use a service that will actually help you. Northwest Registered Agent is that service. They'll form your company fast, give you the documents you need to open a business bank account, and even provide you with mail scanning and a business address to keep your personal privacy intact. Visit http://www.northwestregisteredagent.com/twist to get a 60% discount on your next LLC.

    Vanta. Compliance and security shouldn't be a deal-breaker for startups to win new business. Vanta makes it easy for companies to get a SOC 2 report fast. TWiST listeners can get $1,000 off for a limited time at http://www.vanta.com/twist

    *

    Today’s show:

    Jon Miller, CEO and Founder of halcyon joins Jason to discuss how ransomware attackers get away with it and stay anonymous (6:12), hacker markets, bounties, tools, and AI's role (16:20), proactive measures for startups to safeguard themselves (34:42), and more!

    *

    Timestamps:

    (0:00) Jon from Halcyon joins host Jason.

    (2:52) Delving into the renaissance of ransomware.

    (6:12) How ransomware attackers get away with it and stay anonymous.

    (8:27) Strategies for counteraction and policy implications.

    (10:10) Scalable Path - Get 20% off your first month at http://www.scalablepath.com/twist

    (11:31) 2023 ransomware attacks on MGM and Caesar's in Las Vegas.

    (13:52) Halcyon's endpoint agent: a solution to thwart threats.

    (16:20) Exploring hacker markets, bounties, tools, and AI's role.

    (19:57) Northwest Registered Agent - Get a 60% discount on your next LLC at http://www.northwestregisteredagent.com/twist

    (21:55) The effectiveness of multi-factor authentication and strong passwords.

    (22:49) Comparing financial vs. espionage attacks and the Colonial Pipeline event.

    (29:26) The escalating danger for companies and the Uber cyber attack.

    (31:27) Vanta - Get $1000 off your SOC 2 at http://www.vanta.com/twist

    (32:35) AI and quantum computing: new frontiers for hackers.

    (34:42) Proactive measures for startups to safeguard themselves.

    (37:08) Growing hacker sophistication in places like China, North Korea and Iran.

    (41:00) How the USA ranks in the world with cybersecurity and computer hacking.

    (43:41) Your privacy is an illusion and a look at the information available on TikTok.

    (48:01) The biggest threat that keeps Jon up at night.

    (50:36) American Power Grid Vulnerabilities and ways to be prepared.

    *

    Check out halcyon: https://www.halcyon.ai

    *

    Thanks to our partners:

    (10:10) Scalable Path - Get 20% off your first month at http://www.scalablepath.com/twist

    (19:57) Northwest Registered Agent - Get a 60% discount on your next LLC at http://www.northwestregisteredagent.com/twist

    (31:27) Vanta - Get $1000 off your SOC 2 at http://www.vanta.com/twist

    *

    Follow Jon:

    X: https://twitter.com/HalcyonAi

    LinkedIn: https://www.linkedin.com/in/jonmillerhalcyon

    *

    Follow Jason:

    X: https://twitter.com/jason

    Instagram: https://www.instagram.com/jason

    LinkedIn: https://www.linkedin.com/in/jasoncalacanis

    *

    Great 2023 interviews: Steve Huffman, Brian Chesky, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland

    *

    Check out Jason’s suite of newsletters: https://substack.com/@calacanis

    *

    Follow TWiST:

    Substack: https://twistartups.substack.com

    Twitter: https://twitter.com/TWiStartups

    YouTube: https://www.youtube.com/thisweekin

    *

    Subscribe to the Founder University Podcast: https://www.founder.university/podcast

    126: REvil

    126: REvil
    REvil is the name of a ransomware service as well as a group of criminals inflicting ransomware onto the world. Hear how this ransomware shook the world. A special thanks to our guest Will, a CTI researcher with Equinix. Sponsors Support for this show comes from Zscalar. Zscalar zero trust exchange will scrutinize the traffic and permit or deny traffic based on a set of rules. This is so much more secure than letting data flow freely internally. And it really does mitigate ransomware outbreaks. The Zscaler Zero Trust Exchange gives YOU confidence in your security to feel empowered to focus on other parts of your business, like digital transformation, growth, and innovation. Check out the product at zscaler.com. Support for this show comes from Arctic Wolf. Arctic Wolf is the industry leader in security operations solutions, delivering 24x7 monitoring, assessment, and response through our patented Concierge Security model. They work with your existing tools and become an extension of your existing IT team. Visit arcticwolf.com/darknet to learn more. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    Who is Hacking the U.S. Economy?

    Who is Hacking the U.S. Economy?

    In the past few weeks, some of the biggest industries in the U.S. have been held up by cyberattacks.

    The first big infiltration was at Colonial Pipeline, a major conduit of gas, jet fuel and diesel to the East Coast. Then, J.B.S., one of the world’s largest beef suppliers, was hit.

    The so-called ransomware attacks have long been a worry. But who are the hackers and how can they be stopped?

    Guest: Nicole Perlroth, a reporter covering cybersecurity and digital espionage for The New York Times. 

    Sign up here to get The Daily in your inbox each morning. And for an exclusive look at how the biggest stories on our show come together, subscribe to our newsletter

    The Daily is doing a live online event: We follow up with students and faculty from our series Odessa. And we hear from the team who made the documentary. Times subscribers can join us June 10.

    Background reading: 

    For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday. 

    World Press Freedom Day from Chile to Kenya: why institutions and innovation matter

    World Press Freedom Day from Chile to Kenya: why institutions and innovation matter
    On 3 May each year, the world marks Press Freedom Day to show support for journalists whose ability to report freely is curtailed through harassment and intimidation, physical and online threats, financial and legal pressures. For this episode of our podcast, we speak to two Journalist Fellows, Paula Molina from Chile and Maurice Oniang'o from Kenya on the importance of press freedom for a democratic society and how strong institutions and innovation are crucial to underpin it. Find a transcript of the podcast on our website: https://reutersinstitute.politics.ox.ac.uk/news/our-podcast-world-press-freedom-day-chile-kenya-why-institutions-and-innovation-matter Paula Molina co-founded news chatbot LaBot, which received the Journalism Award for Digital Excellence, one of her country's top journalism prizes, hosts a weekly Chilean female-only political prime-time TV programme and has worked as a BBC Mundo contributor since 2014. Maurice Oniang'o is an award-winning freelance Multimedia Journalist and Documentary Filmmaker based in Nairobi, Kenya. He has written for National Geographic, the Global Investigative Journalism Network and Africa.com among others. He has produced documentaries for a range of outlets including National Geographic, Africa Uncensored and NTV Wild. Host Meera Selva is Deputy Director of the Reuters Institute, and Director of the Journalist Fellowship Programme.

    10/20/22: Truss Resigns, Russia vs Ukraine, Energy Policy, Midterm Races, Landlord Collusion, Corruption, & More!

    10/20/22: Truss Resigns, Russia vs Ukraine, Energy Policy, Midterm Races, Landlord Collusion, Corruption, & More!

    Krystal and Saagar discuss the Chicago live show, Liz Truss resigning, Russia-Ukraine war, energy geopolitics, midterm races, FBI raiding an ABC Producer, landlord cartel, & systematic corruption!


    To become a Breaking Points Premium Member and watch/listen to the show uncut and 1 hour early visit: https://breakingpoints.supercast.com/


    To listen to Breaking Points as a podcast, check them out on Apple and Spotify


    Apple: https://podcasts.apple.com/us/podcast/breaking-points-with-krystal-and-saagar/id1570045623 


    Spotify: https://open.spotify.com/show/4Kbsy61zJSzPxNZZ3PKbXl 


    Merch: https://breaking-points.myshopify.com/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    See omnystudio.com/listener for privacy information.