How Chinese Hackers Breached NASA and DHS Using Home Routers | UnHacked Ep. 101
Hosts:
Justin Shelley - https://www.phoenixitadvisors.com/
Mario Zaki - https://www.mazteck.com/
Joshua Holloway - https://7thdi.com/
NASA, Homeland Security, and the DOJ were just hacked using smart fridges, routers, and Apple TVs turned into a botnet.
Justin Shelley - https://www.phoenixitadvisors.com/
Mario Zaki - https://www.mazteck.com/
Joshua Holloway - https://7thdi.com/
NASA, Homeland Security, and the DOJ were just hacked using smart fridges, routers, and Apple TVs turned into a botnet.
If a Chinese front company staffed by retired military hackers can breach federal agencies with seemingly unlimited security budgets, what chance does a small business have? That's the question Justin Shelley, Mario Zaki, and Josh Holloway tackle in episode 101 of UnHacked, and the answer is more reassuring than you'd think.
Justin, Mario, and Josh break down how a group called QTFY, operating through a front company called XJW, built a database of known, published vulnerabilities (not secret zero-days) by scanning over 2 million routers, firewalls, and devices in a single day. They then hijacked vulnerable home devices, thermostats, cheap Amazon modems, Apple TVs, turning them into a botnet used to disguise attack traffic as normal U.S. internet activity and bypass geo-blocking on China. The operation ran undetected for roughly eight years before a hospital got hit as collateral damage and the FBI finally traced it back and took down the network by seizing the hardcoded command domains.
Here's the part that matters for you: this entire breach was built on things that basic cybersecurity hygiene would have stopped. Unpatched known vulnerabilities. Unmanaged home and IoT devices. No inventory of what's actually on the network. The guys connect this directly back to fundamentals covered in past episodes, patch management, shadow IT, firewall lifecycle, and the death of the network perimeter, and explain why the real failure in most breaches isn't a lack of resources. It's a lack of follow-through.
What you'll learn:
- How hackers built a database of known, published vulnerabilities (CVEs) by scanning over 2 million devices in a single day, and why "known" doesn't mean "harmless"
- Why your home router, thermostat, or cheap Amazon modem could already be part of a botnet attacking someone else without your knowledge
- How the FBI actually shut the operation down by seizing the hackers' own command domains
- Why the real question isn't "can I spend money on this fix" but "what does it cost me if I don't," and how to calculate that number for your own business
- A real example of a company that could lose $5 million a day (up to $30 million on payroll days) from downtime, and why that number changes every security decision
New episodes drop every week with real talk on cybersecurity, AI, and digital risk for business owners who don't have a national security budget. Subscribe so you don't miss the next one.
If this episode made you wonder what's actually sitting unpatched on your network right now, that's exactly the conversation Phoenix IT Advisors has with business owners every day. Visit PhoenixITAdvisors.com to schedule a consult, or go to UnHackMyBusiness.com to use the free portal referenced in this episode to catalog your risks and build a plan.
Links:
- Full episode: https://unhackmybusiness.com/episode/101
- Free risk assessment portal: https://unhackmybusiness.com
- Phoenix IT Advisors: https://phoenixitadvisors.com
- Follow the show: @UnHackedPodcast
Creators and Guests
Host
Bryan Lachapelle
Hi, I’m Bryan, and I’m the President of B4 Networks. I started working with technology since early childhood, and routinely took apart computers as early as age 13. I received my education in Computer Engineering Technology from Niagara College. Starting B4 Networks was always a dream for me, and this dream became true in 2004. I originally started B4 Networks to service the residential market but found that my true passion was in the commercial and industrial sectors where I could truly utilize my experience as a Network Administrator for a large Toronto based Marine Shipping company. My passion today is to ensure that each and every client receives top of the line services. My first love is for my wonderful family. I also enjoy the outdoors, camping, and helping others. I’m an active Canadian Forces Officer working with the 613 Fonthill Army Cadets as a member of their training staff.
Host
Mario Zaki
During my career, I have advised clients on effective – and cost-effective – approaches to developing infrastructure that fosters productivity and profitability. My work has provided me with a broad-based knowledge of business from the inside, with an expertise in areas that go beyond IT alone, ranging from strategic planning to cloud computing to workflow automation solutions.