Skip to main content

Search site

Find podcasts, news, articles, webinars, and contributors in one search.

2 Minute Drill
2 Minute Drill artwork

What a Ransomware Gang's Leaked Group Chat Reveals About Insider Threats | 2 Minute Drill with Drex

Questions Answered in This Episode

  • What do leaked ransomware gang chats reveal about insider threat vulnerabilities?
  • How did one criminal's change of heart save an entire country's health system?
  • Why do cyber gangs experience the same internal conflicts as legitimate companies?
  • Could a disgruntled insider do to your organization what they did to Conti?
  • What happens when even criminal networks disagree about attacking hospitals?

About This Episode

In 2022, a furious insider leaked more than 300,000 internal messages from Conti, one of the most notorious ransomware gangs on the planet, and it read like the group chat from hell.

Buried in the gossip and office politics was a message that should stop you cold, a gang member pushing to attack hundreds of American hospitals and laughing about who might die. But not everyone inside Conti agreed with him.

What happened next in Ireland shows just how thin the line is between catastrophe and survival, and why you can never build a security program on the hope that the person attacking you has a conscience.

Thank You to Our Episode Partner

Fortified Health

Contributors

People featured in this episode — open a profile for more.

Transcript

Hey everyone, I'm Drex and this is the Two Minute Drill. Thanks to Fortified Health Security for sponsoring today's podcast. It's great to see you today. Here's some stuff you might wanna know about. There's a company I wanna tell you about, and as you would imagine, it has a founder, it has an office manager, it has payroll headaches. Uh, like a lot of companies, it has a bunch of staff who grumble that they're overworked and they're underpaid. The office manager, by the way, a guy who goes by the name Mango, tells the boss that he spent his whole career getting all this company's amazing work organized and planned, and it's been a lot of stress, and it's driving him crazy, and that it might even eventually make his hair turn gray. And we've all worked for Mango or some version of Mango. But in this case, the company was one of the biggest ransomware gangs on the planet, a ransomware gang called Conti. In 2022, after Conti publicly backed Russia's invasion of Ukraine, a furious insider at Conti dumped more than 300,000 of the gang's internal messages onto the internet. And all at once, we could read the group chat of a criminal empire, and it was like the worst version of an office you've ever worked at. Gossip and ego and burnout, and a boss who went by Stern, who vanished from the chats about three days before the invasion and left everyone wondering whether or not they were gonna get paid. And then buried inside of all that ordinary workplace noise, you hit a message that stops you cold. A member called Target wanted to attack hundreds of American hospitals. And he sa-- in his words, he said, "Let them pay millions. Let them die," and was even laughing about the potential of the scenario. But this is the thing that kind of really struck me, was that inside of Conti, reading through those messages, not everyone in the gang was aligned with Car- Target's idea of attacking US hospitals. When someone asked about the plan to lock up hospitals, another member pushed back and said, "If the boss doesn't approve these kinds of attacks, I-" "I'll hand over the decrypter keys to the clinic for free. We agreed not to touch the medical sector, remember?" The monsters inside of Conti were arguing about ethics inside their own chat. In May 2021, Conti took down Ireland's entire health service right in the middle of COVID, nearly every hospital in the country. Patients like Donna Marie Cullen sat there not knowing if she would receive her life-saving cancer treatment. And what helped Ireland recover wasn't a ransomware payment, and it wasn't some brilliant defense. Somebody on the inside of Conti decided to hand over the decryption keys. A whole country's health system got a lifeline partly because one of the criminals inside the network had a change of heart. And that should make you uncomfortable because it might be one of the few times I've ever heard of something like this happening. These ransomware groups are normally ruthless. They don't care about you. They don't care about your organization. They don't care about your patients. I've said this many, many times. So you can't build a security program on the hope that the person attacking you will feel bad about it. The link Conti chats revealed a lot of other stuff too, the division of labor, the use of specialized outside contractors for specific kinds of attacks. Cyber gangs continue to run a lot like big tech companies, with all the internal politics that can create disgruntled employees who may then act against the best interest of their employer. And all of that makes me wonder, if one angry insider can bring down an entire ransomware gang, what could one angry insider do to you and your organization? That's it for today's Two Minute Drill. Thanks again to Fortified Health Security for sponsoring today's podcast. Drop me a note. Let me know what you're working on. I'm always happy to hear from you. I'm drex@229project.com. Thanks for being here. Stay a little paranoid, and I will see you around campus

Found this useful? Share it with your network