How Chinese Hackers Breached NASA and DHS Using Home Routers | UnHacked Ep. 101
How Chinese Hackers Breached NASA and DHS Using Home Routers | UnHacked Ep. 101Justin Shelley (00:04.44)
There we go. We got the Egyptian
Joshua Holloway (00:10.467)
You
Justin Shelley (00:11.638)
Mario, you were supposed to start singing. I thought you're I thought we were gonna hear the bangles. There we go.
Mario Zaki (00:14.031)
Walk like an Egyptian.
Joshua Holloway (00:14.509)
you
Mario Zaki (00:21.047)
I should just do the rest of the session like this.
Justin Shelley (00:23.948)
do it. Do it.
Joshua Holloway (00:26.994)
man.
Justin Shelley (00:27.79)
guys, I mean like what the hell? I I hit I I don't remember what was said, and I look up and everybody's gone. Like I said let's record. Are you guys ready to hit I'm gonna hit record and fucking all three cameras are blank, including mine. I don't know what the hell happened there. All right. Let's get rolling. Welcome to episode 101 of Unhacked. Mario back from Egypt, I think to stay, but possibly not. He's ready to maybe
Mario Zaki (00:28.763)
No.
Joshua Holloway (00:51.351)
Woo woo.
Justin Shelley (00:56.92)
Defect back down there. Josh is cooking in his office with no AC. I mean, guys, we're we're we're full of problems today. Let's go ahead and do some quick introduction. we're gonna talk about the hackers today. The Russian well, maybe the Chinese hackers. let's get going. I know. I've been wrong all along. Guys, introduction time.
Joshua Holloway (01:01.64)
it's a fun one.
Mario Zaki (01:07.311)
It's fucking hackers.
Joshua Holloway (01:17.569)
Yeah.
Justin Shelley (01:23.98)
I haven't gone first in a while. I'm Justin Shelley, CEO of Phoenix IT Advisors. And I help people use technology, especially AI, to make lots of money. And then we help you protect that money from the Russian Chinese hackers, the federal government. Well, they might be in trouble too. and the attorneys. We want to help you keep it from all the bad guys. that's what I do. Josh, what do you do? Who do you do it for?
Joshua Holloway (01:50.709)
Yeah, I'm Joshua Holloway. I'm the CEO for seven, the I technologies and we help companies that are buried under compliances or pause compliances while they figure out what's going on. No, no hit on the CMMC stuff. Not at all. But we help you guys get your it in order so that you can operate to the full capacity. So you're making extra money and you're staying compliant and we're babysitting what's going on in the back.
Justin Shelley (02:17.623)
Mario.
Mario Zaki (02:18.607)
Yeah, Mario Zacchi, CEO of Mastec IT, located in beautiful Cairo, Egypt. sorry, New Jersey. forgot, you know. I did a couple sessions over there, so that give me some credit. located in New Jersey, outside of New York City. we help small to medium-sized businesses, you know, with all their technology needs to keep them safe and specializing in helping business owners sleep better at night.
Joshua Holloway (02:31.53)
Hey, you get it, you get it.
Justin Shelley (02:31.575)
I know.
Mario Zaki (02:48.695)
Knowing that their businesses will be there the next morning. That's it.
Justin Shelley (02:53.623)
The hope and pray method. Please let my business be there the next morning. Cause that's where we're gonna. That's that's my segue into today's topic. Here's the thing, guys. I hear this all the time. Today it's been reinforced, reiterated, and not today, but developing over the last couple days. It's been by the time this drops, it'll be a week. Hear it all the time. If the big guys, and we're talking about the government, big corporations,
Mario Zaki (02:55.255)
Yep. At this point.
Justin Shelley (03:21.697)
if if these people, these businesses, these organizations with seemingly unlimited resources still have problems with security incidents. What are we supposed to call it? You can't say we've been hacked or breached. it's a security incident. If they're still getting targeted successfully, what hope do we have? Like for for reels, I'm I don't want you to answer it because we're gonna come back to it. There is an answer. I will spoiler alert, there is an answer. I've got a really good answer, but
This is a common fear, a common frustration. And honestly, it turns into behaviors of apathy. We're just like, fuck it. What what what can I do? We're just gonna hope and pray. Hope it's there in the morning. So, Josh, I'm gonna turn this your way. I'm gonna pass my microphone over to you. and I want you and Mario to just kind of dissect this. I'll add some commentary where I feel it's appropriate. but I'm gonna, or in especially that.
Joshua Holloway (04:10.762)
Hahaha
Joshua Holloway (04:18.783)
Or inappropriate.
Justin Shelley (04:21.639)
And I want you guys to talk about what is going on in the world today. and then we're gonna wrap up with how how what what what really can us little guys do about that? So take it away, Josh.
Joshua Holloway (04:33.036)
Yeah, yeah, not a problem. what you're referring to is what came out in the news yesterday, which is basically Homeland Security has been hacked. NASA has been hacked. Department of Power has been hacked. The DOG has been hacked and
Justin Shelley (04:49.727)
My my attorneys are whispering in my ear, security incident.
Joshua Holloway (04:53.492)
Yeah, so literally phrase that. Currently, right now, they have spoken about a security incident from all of these different departments. And they've disclosed that it was through a Chinese front company acting as a full corporation, but was staffed by all retired PLA.
Mario Zaki (04:54.211)
Mm-hmm.
Justin Shelley (05:17.345)
I am very offended. I have seen the Chinese official statement on this, they had nothing to do with it. And we should stop trying to insult them and smear them. Seriously. S. You you know they actually came out and did that, right? Like, it was not us. We did not do that.
Joshua Holloway (05:27.052)
All right, well, we'll stop trying. We're just trying to share the information with them because I know I every time. Yeah. Yeah. Which is funny because somebody stood there and was literally pointing out all the different things that pointed directly to the front company XJW has a very long name but acronym is down to XJW on where they were involved. The only downside is we don't know how bad it is because it's still under investigation. We're just starting to get the information.
But what happened is there was a hacker group, QTFY is pretty much what they're known by. They were operating through XJW, which was a corporate front company. And what they essentially were doing was they had built a database of, they built a piece of software to gather information and store in the database of known exploited threats. So not zero day threats. You can call them like end day threats or what was the other word you had there Justin that you referred to?
for known vulnerabilities.
Justin Shelley (06:26.453)
I mean, just just say they're they're published, they're they're well known in the industry. the good guys C V E
Mario Zaki (06:32.438)
C C V E's, right?
Joshua Holloway (06:34.356)
Yeah, so they're, they're seeing, yes, the CVs is another way to put it. So they're known threats that patches have been released and that it should have been patching or fixing. So what they did is they just scan the internet for these known exploits and they just cataloged it in a database. And while they were doing that, they, and that piece of software was called Q scan. So that was the engine of it. That was what was scanning the internet. One day back in like 2024,
they scan was over 2 million different routers firewalls devices just gathering information on zero day threats.
Mario Zaki (07:11.829)
Now now they're gathering public information. These CVEs that, you know, these different companies like Microsoft, for example, they release CVEs, correct? so they're gathering these patches and the what they're essentially saying is like we've dis we've discovered that there's a vulnerability in our software. You know, here's a C V E number and this latest update will fix the so and so issue that was discovered.
Joshua Holloway (07:22.944)
Mm-hmm.
Mario Zaki (07:41.904)
So essentially they're telling hackers, which is very smart of them, to to publicly put this out there. They're like, hey, we have discovered this, you know, big problem and here it is on the public internet. But if you install this update, which not everybody does, it will fix it, right? So hackers are gathering this information that's out in the public and they're just putting it into a database.
Joshua Holloway (08:00.747)
Yeah.
Joshua Holloway (08:07.542)
Yep. Yeah, essentially, because every time a CV is released, they give you the who's the what's the where's in the house, right? So really, it is a blueprint blueprint on how to exploit that.
Mario Zaki (08:16.217)
Where
which if you ask me it's fucking retarded. You know. But you know, that's my opinion. Sorry.
Joshua Holloway (08:29.094)
Hey, don't know I get it. And it's a double edged sword, right? They're trying to be open telling everybody how to block these trying to be the good guys. But then the bad guys, of course, are like, Hey, thank you for giving us the keys to the castle. You just made our lives a lot easier because we're not looking for zero day exploits and trying to figure out where the holes are until AI gets involved. And then but for this
it's known vulnerabilities, what they're banking on is people not patching on a regular basis, you know, so so you have this database, right? And yeah.
Justin Shelley (09:04.109)
Well, real quick, I want to make two points on this. Number one, it it is a double edged sword. Mario, you make a good point. We published this stuff, and the bad guys can just go ahead and use that against us. That sucks. number two, as IT guys who are responsible for patching this stuff, the the good news here is as we mentioned back in episode eighty two, there's only like a hundred and thirty new vulnerabilities discovered every single day of the year.
Joshua Holloway (09:33.772)
That's it.
Justin Shelley (09:34.249)
So that's all. Like this isn't that big of a deal. It's not that hard to patch it. Patch your stuff, guys. It's very simple. Anyways.
Mario Zaki (09:37.207)
Easy peasy.
Joshua Holloway (09:38.547)
I mean, I usually have what 6666 60 of those fixed by my coffee's cup is empty for my 9am right? Yeah, it's super easy. Well, I okay, how about this you guys when you're you ever look at your your vulnerability scanner, I try and explain a vulnerability scanner where, like, I tell everybody, when you're looking at these reports, you should see a sawtooth, right? Can you vulnerabilities are found? Everything is patched.
Justin Shelley (09:45.057)
Yeah, yeah. Piece of cake, piece of cake.
Justin Shelley (09:55.627)
Yeah, it's scary.
Joshua Holloway (10:07.296)
right? He goes back down and then new vulnerabilities are scanned, you keep going. It's just a sawtooth, right? versus a hill that just keeps going up because you're not patching and new vulnerabilities are being found every day in your networks, but you're not doing anything. So that hill turns into like Mount Everest, right? Yeah. It's just some of the things that you look for. But this gets it gets even worse because it's actually a pretty, pretty smart hack. So what they also started doing is looking for vulnerable
Justin Shelley (10:11.585)
Yeah, yeah.
Justin Shelley (10:19.873)
Well, right. Yeah.
Joshua Holloway (10:36.8)
Home devices, thermostats, home routers, anything, mobile devices, anything that's vulnerable or open to hacking. And they started to use those by loading, I guess one way to put it would be they would lobotomize the device and inject their own code and slave it to a botnet. So, and the reason why they were doing that was to obfuscate or hide their traffic amongst
your network and your Netflix streaming, right? It just looks like normal traffic. And the other big thing is all routers, almost all router routers are set up to drop communication from China, right? Like most of us we go in, that's some of the first things we do block certain country regions. So this front company couldn't attack directly from China, because immediately all the big firewalls would stop that. So what they started doing is they started to
Justin Shelley (11:19.98)
Right.
Joshua Holloway (11:30.878)
attack and slave multiple small devices that don't have high-end SOC teams looking for issues. And they began to slave them into a botnet and they would obscure their traffic. And they would use those devices because they would be coming from local IP addresses, America-based IP addresses, to then brute force or attack the government agencies that had an incident.
Mario Zaki (11:58.672)
So you're like for example, somebody's Apple T V broke into NASA, for example, right?
Justin Shelley (11:58.87)
An incident, yes.
Joshua Holloway (12:03.532)
that? Yeah, it's a good way to put it. Yes, absolutely. Yeah. Or or that $85 modem that you bought from Amazon because you wanted to save a buck that has no real security built into it. And you didn't change the password when you opened up the box. And like, it could have already had a chip in there. It could have already had the software because it's all firmware. It's all firmware based, right? And we all know that firmware is the software that drives the brain of how that all functions.
Justin Shelley (12:03.757)
Pretty much. Pretty much. Yeah.
Mario Zaki (12:06.239)
Ha ha
Mario Zaki (12:34.371)
You guys ever really like I sometimes like I'll notice like neighbors or if I'm like you know around town or whatever and I open up my Wi Fi, you'll you're s I'm surprised how many people have these like Wi-Fi like broadcasted and it's still like the default, like D link five two five three, you know, whatever. They don't even know they don't even change the they if they're lucky if they put a password you're lucky if they put a password on it.
But the most of them won't even change the name. They'll just call it whatever. It's just keep it the default. Do you ever notice that? Like a lot of people still have that.
Justin Shelley (13:10.398)
yeah. Yeah.
Joshua Holloway (13:11.852)
Yeah, most people do. I used to do like FBI van, you know, as a joke for our Wi Fi. And then I also have used like NSA surveillance node. So when somebody's like, go on the Wi Fi and they're like, what the hell?
Justin Shelley (13:16.973)
Yeah.
Justin Shelley (13:24.353)
Yeah, yeah.
Justin Shelley (13:29.088)
Yeah.
Joshua Holloway (13:31.254)
But that's my nerdiness, right?
Mario Zaki (13:31.439)
I guess that's the Yeah, I was about to say that's the nerd in us that wants to do stuff like that. That we only w only us find it funny.
Joshua Holloway (13:40.724)
Yeah. Yeah.
Justin Shelley (13:43.938)
Well, I mean, this is where we're off track. I mean, my home Wi-Fi is named Elon because it's Starlink. You talk about you talk about nerdy. I mean, it's not NSA, it's not something super clever, but it's just like this is Elon's network. All right, so I mean summarizing briefly, the bad guys built a database of all the known weaknesses around the federal government's networks. they attacked, they got in, they they they enslaved a bunch of devices.
Joshua Holloway (13:50.058)
Hey, see that...
Justin Shelley (14:13.601)
They use them to get in and then you know, like this one great big brute force attack, and then they came in behind the scenes. using that so as to not get discovered, they would use this dispersed network of refrigerators, Apple TVs, home firewalls, home Wi-Fi, whatever. Yeah, yeah. So when when you look at what really happened,
Joshua Holloway (14:32.716)
cheap cameras.
Justin Shelley (14:41.429)
And this is kind of where I started. It's just like when when you only see the headline that the federal government was hacked, NASA was hacked, DOJ, I like these are some big organizations with some, like I said, seemingly endless resources, very the the brightest minds, or so we're told, working on these problems. like it it really can be kind of defeating. And so when I first heard about it, that was my first thought. I was like, God.
How do I go out and sell security when this is what I'm going to hear all day long? Then I start digging and I'm like, actually, this is the stuff we've been talking about for 101 episodes now. We did a whole mini series on cybersecurity basics. I did like come back later and say, well, maybe this isn't so basic. That's a lot of stuff once we like put it all on paper and look at it. so then I built the dashboard or portal or whatever you want to call it, unhackmybusiness.com.
Joshua Holloway (15:31.532)
Yeah.
Justin Shelley (15:39.721)
but if you go in there and you go through this and you and you do what you're supposed to do and you apply these security measures, these problems go away. This problem with the federal government was technically preventable. What do you got, Mario?
Mario Zaki (15:50.169)
Now
Mario Zaki (15:56.186)
I I was gonna say, I mean, I'm gonna play devil's advocate here. I think the you know, most of our listeners are probably listening to us and say, Okay, well, the federal you know, my device, okay, fucked up something on the federal government. It's not my pro like it's not my problem. You know, w you know, they they most people are not gonna give a shit because it wasn't affecting the home users, it was affecting the the government or the target. They were just, you know, part of the the the the
the attack. you know, but but at the same time I you know what I I'm presenting the problem, but I also want them to to also understand because I know that they'll they're probably thinking that way, they have to understand now there is a vulnerability on your network, on your home network or on your business network that they're just using you to you know to target you know somebody else, but doesn't mean they can't turn around and target you.
Justin Shelley (16:29.689)
yes and no. Go no, go ahead, go ahead, finish.
Justin Shelley (16:54.967)
But it was used in both places. It was both used in the attack and also you know they they were exploiting to actually get in. So you've got on one hand, you're the the bad guys are taking command, basically, of these devices that you're talking about. Home devices, refrigerators, whatever we're talking about, inter Internet of Things, IoT devices. They've they've turned those into an army, effectively. But then they didn't just blindly attack the government. What they then did is went and attacked
a database of known vulnerabilities, known unpatched software, hardware, and whatever, to the tune of two million in one day. You know, they it this was it was a shotgun approach, but it was also at a target, if that makes sense. Right?
Joshua Holloway (17:43.319)
There also was some indiscriminate hits too. So where this started to unravel was a hospital was actually attacked and there and it actually crippled the hospital too. Yeah. And that, yeah, and that's one, that's where, yeah.
Justin Shelley (17:46.583)
Sure.
Justin Shelley (17:54.538)
No surprise there. I mean, honestly, there's always collateral damage with this stuff. That's why I say a shot, a targeted shotgun. You know, it's not this this was not a sniper rifle. This was a targeted shotgun. Have you guys ever shot a shotgun? You just kind of point it in the general direction of the bird or the clay pigeon, whatever you're shooting at, and hope. that's kind of what they're doing here. But they built that database first of the of the direction they want to shoot at.
Mario Zaki (17:58.8)
Mm-hmm.
Joshua Holloway (18:06.741)
yeah.
Joshua Holloway (18:15.424)
Yeah.
Yeah. Well, and think the other thing that most people aren't hitting on too is, this is it's being uncovered that they've been around for about eight years doing this. So think about that. Like think of how fast we move in technology. Think how fast AI is currently moving in technology, right? It's every day, every day. It's some new LLM or some new model that's doing this or breaking that or breaking out. Right? Think of how fast we move eight years is almost like infinite.
Justin Shelley (18:29.035)
Right. Right.
Justin Shelley (18:47.865)
A lifetime. It's it's insane. Yeah. Infinity and beyond for the buzzlight your lovers. okay, so I'm gonna briefly go through. I'm gonna this is little bit of shameless self promotion for both the podcast and the portal that I bit built that by the way is free for anybody out there that wants to use it. Unhackmybusiness.com. Shameless self promotion. Episode 76. Inventory all of your equipment, secure the remote and distributed workforces.
Joshua Holloway (18:49.094)
It's infinity. Yeah, it's it's insane. Yep.
Mario Zaki (19:10.553)
Yeah.
Justin Shelley (19:17.119)
Episode 77, Shadow IT. Kind of goes along with 76, but go out and look for the stuff that you don't know is there. Episode 79, review your firewalls. Don't have out-of-date firewalls. Don't have because a lot of times firewalls are purchased, they're thrown in a closet, and they're forgotten about. Whether they're enterprise great or not, but like for the love of God, don't start with the something you bought off Amazon or or whatever. Get good quality equipment, know where it is, and keep it up to date. Episode 81.
Is the death of the network perimeter. We talked about how it's it's everywhere. We we don't just have to in inventory our equipment and our users. We've got to know where our software what software we're using, where it lives, where the data lives. We used to have this really sweet little deal where it was like a castle with a moat around it. You just protect the building. Like that was it. A firewall, some antivirus, data backup, good. Those days are gone. You've got to know where your data lives and and where it's being.
Processed. episode 82. Your IT guy is probably not patching your system. Here's how to catch them. These patches, you know, the the CVEs. Well, Mario, you make a good point. We're publishing this stuff so that even the bad guys know about it. But at least it gives all of us some sort of a fighting chance. AI is helping with this. You've got to know where your vulnerabilities are and you've got to patch them. This is this is the stuff that needs to be done all the time. It's the stuff that commonly gets forgotten by both MSPs and
All the way up to the top of the federal government. But this is the stuff that if we would do it and do it right, it's what we used to say, and I kind of backed off of it. 97% of these breaches were preventable. This is evidence of that. The stuff that happened was largely preventable. We don't know everything. I'm not making a blanket statement here, but I am saying basic measures would have significantly at least mitigated this situation. Yes?
Mario Zaki (21:12.033)
Yeah.
Joshua Holloway (21:13.13)
Well, I'm also curious to one of the biggest problems is like end of life or end of service, where people will just keep running that firewall. It's 10 years because it just keeps running, but it's into service, which means it's not getting patched or there's there's there's nothing happening for that. Not saying that this is happening on the government side, but I'm just curious how many of those devices were end of service because they just haven't gotten around to, you know, swapping them out or like if it's not broke, why fix it?
Justin Shelley (21:20.706)
Mm-hmm.
Joshua Holloway (21:42.836)
And this is why.
Justin Shelley (21:43.032)
Yeah. Budget constraints, politics. You know, I've I've talked several times about a city in Texas, a well known city in Texas, that had a a major security incident. And and it it's like the IT guys brought it to their superiors and said, Here's the problem, here's the solution, here's what it'll cost. And they were told to just go away because they didn't want to go to their board and ask for money.
Because they were afraid the board would come back and say, Well, why haven't you already fixed this? So to avoid the embarrassment, they shut down, eventually fired the IT guy. it turned into a great big debacle. They got sued. I d I don't know. Like our culture's messed up around this stuff.
Joshua Holloway (22:28.672)
Well, because they're they need jerk to blame blame the it guy and the easy answers is we'll just swap you out for somebody else. Right? Well, and and here's something super important. I hear you Mario, I'm gonna give it to you here in one sec. I just want to make one point is this is that point when it is on us to shine a light that this is a huge glaring hole problem and this will blow up if it's unchanged and then document the ever living Jesus out of the fact that
Mario Zaki (22:36.151)
Yeah. Yeah.
Justin Shelley (22:36.33)
Exactly.
Mario Zaki (22:41.017)
No, no, no, it's fine.
Joshua Holloway (22:58.668)
you told them about it, when did you tell them about it, and hand over liability. Because when they come back and tell you like, we're not gonna spend the $1,500 for that firewall or the $2,000 for that firewall, and it does blow up, you can hold up that piece of paper and say, we warned you two years ago, or we warned you six months ago, saying that this is a problem, this has to be fixed, because that's your CYA.
Justin Shelley (23:00.439)
Yes.
Justin Shelley (23:21.771)
Another option, shameless self-promotion coming soon. Unhackmybusiness.com will tell you all this stuff and help you catalog it and build a plan. So if you can't do it right now, rather than have a fight between the IT guy and the decision maker, you can both agree, hey, we know this is an issue, we know the approximate cost. We're going to push that back to Q1 of next year, right? At least then there's a plan in place so that when it blows up, that will help you out.
In the third thing I always talk about, which is the attorneys are gonna sue you, when you when you would have a documented plan for the known gaps. It's better to have that than to have unknown gaps or like you're saying, Josh, where y the recommendations recommendation's made and it's just flatly denied, turned down with no plan. That's a big problem in court.
Mario Zaki (24:13.281)
I I I think, you know, to to add on to what Josh was talking about, I think and I see it a lot, the problem is people still have the mentality if it's not broken, don't fix it. You know, if a router's still working, they're gonna continue using it. I if if their laptop, even though it's ten years old, you know, and whatever, they're still gonna use it because it still turns on and you know, yes, it doesn't receive updates or whatever, but it still goes online.
I'm still able to go on to my Amazon account and you know, blah blah blah. That's the problem, is people still have that mentality like it's it's working fine. Why do I need to replace it? You know? and that goes along with like, you know, computers, servers, you know, firewalls, you know, there's certain things that, you know, we're recommending it and it's not because we want to just stay busy. It's because we're doing our job. What we're what they're paying us for is to tell like this is what we recommend.
You know, and unfortunately, you know, when they get the the quote, they're like, it it's working fine. We'll just we'll push it on to next year. We'll see what happens next year.
Justin Shelley (25:24.023)
Well, part of the other problem here is that we we make decisions with half of the formula or half of the numbers as as business owners. And you know, I think we're all guilty of it to an extent. But when when you put a proposal or a quote in front of somebody who's responsible for everything in their business, not just IT, they're measuring it against if I spend money here, I can't spend money there. Right. And the only number they're looking at is the cost of that particular recommendation.
The number they're not looking at, which is where I think our industry badly fails people, is they're not looking at the cost of not doing it. They're looking only at the cost of doing it. That number of not doing it needs to be right there on the proposal of everything we do. Every security control that we recommend or that we put in place should have both the cost to do it and the cost of what you what happens if you don't do it.
Joshua Holloway (26:06.188)
you
Joshua Holloway (26:23.296)
The problem is, is you have to have a very difficult conversation with your client to figure out like if you were down for a day, a couple of days a week, what is that? What does that look like in loss revenue? So I've had these conversations because we've done a couple like sock two audits and we have to talk about those things. I had a staffing agency client that I worked with and they've been a client for 22 years, right? We sat down a long time ago and I said, Hey,
Justin Shelley (26:40.812)
Mm-hmm.
Joshua Holloway (26:52.938)
We make sure your payroll runs. I'm actually really curious. If it doesn't work because there's a flood in your building, like how much money could you stand to lose? And it was awesome because this gentleman actually kind of did not even skip a beat. He looked at me and says, if it's Tuesday through Thursday, we will lose approximately $5 million a day. When Friday hits, you could triple it because we're not delivering checks.
And then you get into the we just didn't deliver all these checks to all these people and they're now calling wanting to know where are their checks? Where is their direct deposits? What's going on? So I always operated with if they were down, I could potentially lose them $30 million. And that's how I that's how I operated all day every day. Now mind you, they're in a flood zone, hurricane zone, you name it, and they felt it all. And we actually house their equipment.
in a data center because we sat down and we talked about I'm like, hey, if you if your generator doesn't work, and you're down, you're out that money. It's very little in comparison to have it in a data center to where it's always up and running. That's not in a flood zone. It's not in a tornado alley or anything like that. We actually we actually had it over here in California. So barring earthquakes, primarily, like that's all we had we had to deal with. They never experienced that.
Justin Shelley (28:07.81)
Right.
Joshua Holloway (28:20.064)
They were up 99.9999 % of the time, but we actually were smart enough to have that that conversation. Now sock two and I think this is going to go back to a conversation that we can hit on on other things talking about frameworks, right? Just following a standardized framework, you are forced to have those conversations. So that when you do come in here and say like, hey, we want you to change this firewall. And going to your point, Justin, like we as it guys should know this like
Justin Shelley (28:25.943)
Yeah. Yeah.
Joshua Holloway (28:48.468)
If you don't change this and we stay this way forever and we're no longer patching or blocking it, your worst day is going to be X amount of dollars. So what's worth it? Is it this little cost down here or your X amount of dollars that could potentially turn into your entire business? what is it? 90, what's the statistic now for businesses that don't recover from a ransomware? There's a 90 some odd percent.
Justin Shelley (29:12.839)
No, I last I heard it was like sixty. I don't know. But in in my experience, it it's a lot. Yeah. It it it's enough that we shouldn't be messing with it. Yeah. This is you know, I've done the analogy before of Russian roulette, like load that load that thing up with only one bullet and spin it. Point
Joshua Holloway (29:17.1)
It's a hype. Yeah.
Mario Zaki (29:17.143)
No, it's more than that, but yeah, it's it's more than fifty percent.
That don't recover.
Joshua Holloway (29:25.676)
Mm-hmm.
Joshua Holloway (29:34.272)
Yeah, but it's like Russian roulette with a semi-automatic, not a revolver.
Justin Shelley (29:37.453)
I mean i yeah, and it like all of it we shouldn't be doing.
Joshua Holloway (29:44.396)
Yeah, exactly. man, that's horrible.
Justin Shelley (29:50.068)
All right, guys. Listen, I'm I'm just gonna keep I'm gonna keep hammering this portal because that that's one of the things we're tying in there with all of the the the frameworks, the controls, the things you should be doing, we are including in there the cost of doing it and the cost of not doing it. So, you know, when you go in and and what I like about it is when you build out your company profile and you talk about your industry and what you do and the cost of downtime and you put all those numbers in there so that it can calculate this for you. And that way when you're looking at
You know, your your total exposure for a company might be six million, let's say. And then as you add in verified data backups, it reduces your your financial exposure by two million dollars or or whatever. And you can just watch this number go down as you put the controls in place. So I I do
Mario Zaki (30:36.087)
And you can do this on on hackmybusiness dot com.
Justin Shelley (30:39.149)
Correct. Yep. Yes, you can. Thank you for that that little promotion. Let's flash it on the screen. Unhackmybusiness dot com. but I I just I really believe that we need more information when we're making these decisions, other than just like a number that it's gonna come out of my bank account. Because that's an absolute and that's the only number we're working with most of the time. So
Joshua Holloway (30:40.798)
perfect. Perfect plug, Mario.
Joshua Holloway (30:48.694)
But you
Joshua Holloway (31:02.486)
Well, before you move on, I think for closing out what we were talking about today for the this, you know, US government incident, we should probably talk about how it was taken down because a point a point a point I would like to make is how repeatable their process was to where this is not going to die here. There's going to be other front companies or other
Justin Shelley (31:12.429)
Mm-hmm.
Yeah, yep.
Joshua Holloway (31:30.646)
bad actors that are going to take this model that they did and replicate it. And because it's a, it's, it's simplistic in nature and it's easy to set up. And I don't know if Justin, if you want to go through how they blocked it, or if you want me or Mario or somebody. Yeah. So basically, you know, FBI pretty much, they started figuring out what was going on and they started watching this traffic and they figured out that the way that they were obfuscating through all of these different devices.
Justin Shelley (31:42.763)
No, go ahead. Do it.
Joshua Holloway (31:59.851)
instead of having a randomization of where to get their orders, where to get their threat. These hackers made a design decision to make their lives easier. So everything that was taken over, everything that was hacked was hard coded with, you always come back to these specific domains to talk to the mothership essentially, because they were centrally managing it, controlling it. And you always come back here and this is where you're going to get your stuff. So what happened is that the FBI,
through the court system took ownership and took over those domains. So when the devices came to those proxies looking for what's my next steps or where you want me to go or what do you want me to do? That traffic was rerouted and essentially killed. Thus, it was their method for taking down the whole entire like central control bot network and everything because now they own those domains, they can't use those which means
they can't go and update these devices and say, go to these domains now, because they have no way to communicate with these devices any longer. they, they're essentially going dormant, but that was how they stopped it. But if you stop and think about it, like that is the most simplistic way to like easily transfer information. And you might think it's a flaw in the design. I think it was like the most, like the strongest way you could have it because they're
disseminating and moving so much data so fast that this made it a lot easier to keep all that together. Because think about all the different like hundreds, thousands of devices constantly getting update, handing over information, doing all this. So it made that for them, the hackers that made their lives easier to do it this way, which in turn made it super easy for the FBI to stop in turn, it's going to be super easily easy to replicate. You can you can look at this and stand one up today or tomorrow and
Mario Zaki (33:50.382)
Mm-hmm.
Joshua Holloway (33:54.539)
redo their process. So who's to say that they don't copy everything that they did, move it somewhere else and already starting somewhere else.
Justin Shelley (34:01.601)
Yeah, no, that's a good point.
Mario Zaki (34:03.949)
Yeah, I find I find it hard to believe that they don't have like a plan B. You know, they're they're probably you already have something planned or, you know, have done something because they knew eventually that's what that's gonna you know, happen, but
Joshua Holloway (34:20.714)
Yeah, but again, I mean, they might have gotten a little sloppy, though, because they've been up and running for eight years.
Justin Shelley (34:25.506)
Right.
Mario Zaki (34:26.126)
Yeah.
Justin Shelley (34:28.557)
I don't know, guys. Crazy stuff. I I actually what I enjoy about this A, like I've said before, I get to learn. You know, I get to learn how this stuff happens. I get to learn how to protect against it. it is always very reassuring to me when I can see these great big headline issues that do have there's something we can do about it, you know. Is anything a hundred percent no, but we can get pretty dang close.
by relentlessly doing the things that we're supposed to do. It has to be a dedicated, like a a it has to be full court press. You know, you this can't be a half-hearted thing. And it's not simple, it's not easy, it's not even cheap, but the the cost of not doing this is so catastrophic that we just we can't ignore it. But unfortunately so many, so many do. So let's go ahead and kind of wind this thing down.
We'll go around the room, guys. If you have any key takeaways, final thoughts, and then then we're gonna sign off and we'll be back next week. But Mario, I'm gonna punt it over to you first, then Josh, and then we're gonna call it a day slash week. Go ahead, Mario.
Mario Zaki (35:41.038)
Yeah, I mean for me, key takeaway is you know, don't don't always go with the cheapest, you know, system out there. Make sure you're keeping up with any updates, any recommendations from your IT to update or replace stuff. And you know, just you know, you gotta be responsible. Think of what it could cost you, you know, if you don't do it, you know, versus if I do this, how much is it gonna cost me?
Justin Shelley (36:09.089)
Yeah. Okay. Josh?
Joshua Holloway (36:13.332)
I think I want a second on what Mario was saying. When it is coming to you saying they need to spend money. It's not because they like to swipe the credit card. You know, push back on them, ask them questions as to why and they should be able to intelligently explain to you why this needs to happen. But listen to what they have to say and they're they're trying to protect you and if they're not there's three guys on this podcast for guys on this podcast that are willing to talk to you help you figure out your directions of where to go but
Look at always keeping that equipment up to date. Don't just keep it going because it's just working and you've had it for 10 or 15 years, you know, replace it, update it. And second, talk to your IT, make sure that they're doing these updates, ask for proof that this is happening. And if you don't know how to do that again, shameless plug, you can come to the just to go ahead and do the shameless plug come to
Justin Shelley (37:06.346)
No, no, you g you got it. I I I'm like a broken record over here.
Joshua Holloway (37:11.34)
Yeah, no, but like you can come to that portal on hack my business.com and you can sign up you can ask questions and we're all willing to donate our time initially to help you figure out where to go how to ask questions what you should be looking for because we are trying to uplift our businesses and do right by our customers. So we're happy to share that because we hate hearing horror stories about people losing money because they incorrectly transferred or something bad has happened. So guys, you know, please, please be on the lookout for
Justin Shelley (37:42.698)
And just one more note, because I know that, you know, our target audience is business owners that are not necessarily technology inclined business owners. but I I also know just from talking to people, you know, I'll go to a convention or whatever and like, hey, I've been listening to your podcast. And it's other MSPs, other IT guys. So I know that a a significant part of our audience also own MSPs. And for the record, the unhackmybusiness.com portal that I love to talk about.
is set up for MSP. So and it's free to you as well. If you want to set up your own tenant and use it with your clients, that is perfectly acceptable. my goal here, yes, I want to promote myself. I want to build trust. That's why I do a podcast, but ultimately I want to elevate our industry. I I really am tired of an industry that has no accountability. it it it's so hard to recommend something to somebody because they think we are just trying to line our pockets. Like
This gives you the information to back it up, why it is that you have to do it. And we're tying it to published frameworks as well. It's not just like because you should, or because there's a dollar amount, but like this is why it comes from either CMMC or it comes from a HIPAA framework
What what what do they call a HIPAA, Josh? It's not a framework. it's you know, just compliance, anyways. brain freeze. but like we we tie all of these recommendations back to the reason why, and then we tie the the the completion, the sign off of it back to evidence of, you know, that so that we can prove it was done. We're not we're we're proving both sides. We're proving why it needs to be done, we're proving that it has been done. And we're tying the financial risk and everything else to it. So
Joshua Holloway (39:03.328)
Compliance.
Mario Zaki (39:04.355)
Plan.
Justin Shelley (39:30.319)
I really am trying to just like we need to elevate this industry. We need to do better than we have done. that's that's my personal belief. So that's where I'm gonna kind of wrap up. Guys, Mario, glad to have you back from Egypt. Is this your first one back in the States? It's not, right? I think you were back last week. Is it? It is, you're right. This is your first time back.
Mario Zaki (39:46.523)
yes. No no I I I yeah, yeah, because I can't my first day back at work was Tuesday.
Justin Shelley (39:53.996)
That's right. So, anyways, appreciate you showing up while on vacation. Well, get back over there. Listen, I'm I'm not gonna I I I I have no opinion there. I just like that you're here. So just come back wherever you come back from. thank you for being here. Josh, same. your insights are much appreciated. Your research on this one today, really do appreciate that. so with that, guys, we're gonna sign off. We'll be back next week with more riveting information on the world of technology and cybersecurity.
Mario Zaki (39:57.805)
I think I'd do my best work over there though, to be honest with you.
Joshua Holloway (40:00.78)
You
Joshua Holloway (40:05.696)
Yeah
Justin Shelley (40:23.223)
Take care. We'll see you next
Mario Zaki (40:25.315)
Bye guys.
Joshua Holloway (40:25.622)
Bye everybody.
Creators and Guests