AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102

Justin Shelley (00:11)
I think I need some Stevie Wonder glasses if I'm gonna do that.

Mario Zaki (00:14)
Mm-hmm.

Joshua Holloway (00:14)
yeah, absolutely.

Justin Shelley (00:18)
shit. Welcome everybody to episode 102 of Unhacked. Mario, Josh, appreciate you guys being here. listen, I'm not even gonna get into any of the topics or anything. Let's go straight into some brief introductions. Then we're gonna dive in because today is a very intriguing episode. I'm gonna do my little evil

Hand motion laugh.

Mario Zaki (00:40)
Fingers.

Justin Shelley (00:41)
Well, I have an evil laugh, but I'm embarrassed about it. So I'm not gonna do that on the air. 'cause

Joshua Holloway (00:45)
Yeah.

Justin Shelley (00:46)
it's probably not as cool to other people as it is to me. I used to do that in front of my kids. They didn't think it was cool either. So I'll withhold. Let's do introductions. Mario, then Josh, then I'll I'll say something. I don't know what. Mario, who are ya?

Mario Zaki (00:59)
Yeah,

Mario Zacki, CEO of Mastec IT, located in New Jersey, about fifteen minutes outside of Manhattan. we help small to medium sized businesses stay secure, operate on a regular basis, and we specialize in helping business owners sleep better at night, knowing that their business will be there the next morning.

Justin Shelley (01:20)
Josh?

Joshua Holloway (01:21)
And I'm Joshua Holloway. I'm the CEO for 70i Technologies. As always, we're an MSP that's built around helping businesses that operate under a compliance and have to do all that fun paperwork and policy writing and make sure your technology works with you. So we're here to help you do what you need to do so that you get to make money, but we're also helping to make sure that your compliance

Justin Shelley (01:42)
Beautiful. And I'm Justin Shelley, CEO of Phoenix IT Advisors. And if after a hundred and two episodes, you don't know who I am. You don't deserve to know. So we're just gonna move on. Today, guys, we have the biggest headline of all time. AI has been out there scaring everybody senseless. Today, I'll buy it's lonesome. It executed its first ransomware attack. not today. This happened July f what was it, Josh? You're the expert here.

Joshua Holloway (02:08)
It

was around July first that it was discovered. Yeah.

Justin Shelley (02:10)
July first, that's what I thought. Yeah. You're

the expert. Well, you're the one that proposed the topic, anyways. so without any ado whatsoever, let's talk about Josh. I I gave you a task that I don't know if you're up for or not, but I'm gonna start a timer. And I said I want you to describe what happened in two minutes or less. Ready? Go. I don't really have a timer, but anyways.

Joshua Holloway (02:32)
I was just about to say we had our first fully automated AI driven ransomware attack from start to finish. No humans were included. Done. Was that what you're looking for? No.

Justin Shelley (02:41)
There it is. Beautiful. Yeah, that was that's

Mario Zaki (02:41)
Ha ha ha.

Justin Shelley (02:44)
brilliant. All right. So guys, we've seen iRobot, right? Like I always keep going back to that movie. Will Smith, you guys familiar?

Joshua Holloway (02:53)
Uh-huh.

Mario Zaki (02:53)
Mm-hmm.

Justin Shelley (02:54)
Okay. Well, I'm old, so I don't know. I I don't think the younger generation has seen that movie. it it's here, right? The robots have taken over, they're doing stuff, start to finish, as you said. but Josh, let's go ahead and do the two minute and fifteen second version and

Tell us like what happened and how it happened.

Joshua Holloway (03:15)
Yeah, so basically what we happened, we have threat actors that kicked off an LLM that was given a task to perform its own attack against a system. It was uncovered by a security firm called Sys Sysdig, and they completely categorized an attack where an LLM attacked a company, figured out ways to get in, as it bypassed the firewall and got into the network, it mapped the network, and then it

launched its payload, ransomware an entire drive, and closed out. Now, the biggest thing is is is the speed in which it did it. So all of you guys, you all know, right? Like we have systems set up so that certain things alert sometimes LLMs are alerted that grab humans, right? So the speed of service of this is is huge because most hacks take time, right? So let's digest what an actual hack

you know, its time frame looks like. They get in, they poke around, they use some pre architecture based software that they probably bought off the dark web. They poke, but they do it very slowly because they know that they can't change anything on the fly. And they start to feel and map and see what they could do. This all takes time, right? It takes hours, sometimes days, months, weeks and years. What this new attack, which is being coined as Jade Puffer.

so I'd say like a you know, like a puffer fish.

Justin Shelley (04:45)
Where yeah, where do they come up with these stupid names?

Joshua Holloway (04:47)
I mean it's it

Mario Zaki (04:47)
Yeah.

Joshua Holloway (04:48)
it's technology guys coming up with cool names for things that they just don't know how to how to label. So it's like, yeah, let's

Justin Shelley (04:52)
Cool. You use the

the technology guys and cool in the same sentence. Go on, Josh. Wishful thinking.

Mario Zaki (04:56)
Guy was guy guy was probably just looking

Joshua Holloway (04:56)
Yeah.

Mario Zaki (04:59)
at his fish tank like five feet away from him. He's like, let's just call this puffer, you know.

Joshua Holloway (05:04)
Yeah, exactly. Well, and I I think the idea behind the puffer is the fact that its speed of service was something we've never seen before. So it broke in, it mapped, it it constantly changed or updated it its own code because it could, versus anything that's hash sign or anything like that. Our security tools look for hash signs, other other things. They could change it on the fly. But if you think about a puffer fish, right, you go from

Zero to a hundred real quick and all of a sudden it's really big, it's expanding, and it's deadly. So that idea is the same thing that took place here. Yeah.

Justin Shelley (05:37)
Probably AI. AI probably came up with that term.

Joshua Holloway (05:39)
Probably. It it's probably the same a AI that did it. And it's like, I want to

Justin Shelley (05:43)
Yeah.

Joshua Holloway (05:43)
be known as the Jade Puffer because that would be super cool. No, but I think the the the biggest thing to to take away from this is it did everything in a 30-minute window. And a lot of experts are saying our window has now shrunk down to 15 minutes.

For

us to receive some kind of notification and act. And I think what's changing for us now is we need to have more automated systems slamming doors close. I think the other problem too is a lot of our systems are disjointed, right? We buy a firewall from s one manufacturer, not gonna name any, right? Then we get our A V or some security software from another manufacturer.

You know, and then we get another security tool from another manufacturer and and it's kind of like disjointed. I I think the idea here is looking at this attack that we have to get away from a disjointed environment and kind of start to maybe more centralized. But I wanna hear your guys' thoughts.

Justin Shelley (06:40)
Or or the article you read was put out by a vendor who does exactly what you're saying should be done, which is actually the case.

Joshua Holloway (06:46)
Or yeah. Or

Mario Zaki (06:47)
Mm-hmm.

Justin Shelley (06:50)
Mario, what are your thoughts here?

Mario Zaki (06:51)
I mean

it it pretty much what it did is it it just you know eliminated humans, it sped up what a a normal human could do. But the underlying security that you would we would have used to protect from, you know, something six months ago or a year ago or two years ago, it's still in play, you know, like patching, you know, making sure all your stuff is up to date, making sure you're s you know, you have security in place.

you know, application whitelisting, you know, stuff all that stuff would have at least from what I read would have still been able to prevent or reduce the amount of issues that this this system would have attacked. You know, it it is like a you know, it's like a burglar getting to a house. He's checking every window until he finally finds one that's open. But this this system is literally just checking a lot faster.

Justin Shelley (07:49)
So, all right.

Joshua Holloway (07:49)
Yes, within milliseconds.

Justin Shelley (07:52)
I'm gonna I'm gonna I'm gonna throw some stuff out there. And correct me if I'm wrong. but first and foremost, this was not AI gone rogue. That's the headline that keeps getting put out there. AI is doing this end to end, no human involvement whatsoever. Horse shit. Somebody got like, and you've you said it, Josh, right? Like, somebody got the tools, they discovered the target, they knew the vulnerability, and they pointed AI at it, and AI fa

knocked it down like super fast. So speed is the number one issue. the fact that it can self like it lost credentials and then within like the 30 seconds, I think it was, it was able to get logged back in. but the main point here that I want to make is this was a known vulnerability that had been published over a year ago. It was an unpatched system that was exposed to the internet.

Joshua Holloway (08:45)
Mm-hmm.

Justin Shelley (08:46)
Right? So

And and Mario, I'm glad you brought that point up because this is still what I what I keep seeing over and over with all the fear and the hype around AI attacking things so far, anyways, it still has to exploit known vulnerabilities that we still have the ability to patch. Yes.

Joshua Holloway (09:05)
Yes.

Mario Zaki (09:05)
Correct.

Joshua Holloway (09:06)
And and and

Justin Shelley (09:06)
Okay.

Joshua Holloway (09:07)
Mario brought this up last week where I think this is a huge key point that we need to bring up again too. And and it's we are showing the hackers and the attackers what those patches are by putting out zero day notices. And I'm not saying we have to stop doing that, right? But I'm but I am saying that we are giving them the keys to the kingdom, the where they can get these C V E's and they can go searching for this stuff, which means we need to be patching faster. The other the other thing to it

The LLMs are being trained on all the information that we post out to the internet, which means all the MITRETAC frameworks, all of the different, you know, scenarios and different things that we would use to combat a lot of these attacks. It's learning off of that. And then at its own speed, which is system-based speed. It's no longer human-based speed. At system-based speed, which is far faster than the rest of us can move, it's it's learning all of those tricks and trades, and it's now

starting to build its own path through, knowing how we would typically block it. So again,

Justin Shelley (10:12)
Go.

Joshua Holloway (10:12)
us being good is push is is getting us in trouble.

Justin Shelley (10:16)
I'm gonna point like because we have this has come up a couple of times. This idea that we shouldn't, or maybe we shouldn't, or or maybe it's a problem that we publish these C V E's, right? For what are if you know, common vulnerabilities and exploit exploit exploitations, exploits. Vulner What am I saying? Anyways, I I knew I was I know I was gonna blank on

Mario Zaki (10:35)
TVs.

Justin Shelley (10:38)
that. I looked it up because I like it's a stupid name. There's a lot of stupid names out here, and and that one I can't get to stick in my head. But

These are not published so that the bad guys can exploit them. I would argue the bad guys already have this stuff. It's called the Dart Web. They can they've got their own databases of all the exploits. What this does, in my opinion, it doesn't teach them anything. It levels a playing field. It makes it so that guys like us have a fighting chance because you know what we don't do all day long is sit around and find vulnerabilities personally. Like I don't personally go out and try to break into the networks. But

Now we have a catalog of like 300,000 different ways that the bad guys do. So I love CVEs. I I I hope they never go anywhere. I hope that the the only real problem with them is that there's 300,000 of them. Am I getting that number

Mario Zaki (11:26)
Mm-hmm.

Justin Shelley (11:27)
right? As I again, I looked that up too, but it's it's crazy. but we also have tools that will go in and and take all the CVEs and apply them to our systems and show us where they live and and what needs to be done to patch it. So

I will not blame AI for this. I will not let AI take the the dirty hit. Some company out there had a production environment. what was the name of the the software that they exploited? because it's it's C V E 2026. I looked up a different one. Never mind. God damn it. I had all my notes ready and then we started recording and they all I blew them all out.

Somebody help me out. What's what's the what's the software they exploited? Anybody? anybody bueller? Bueller? Landflow. Langflow.

Joshua Holloway (12:17)
I don't remember off the top of my head, hold on a second.

Justin Shelley (12:19)
Langflow. Okay. So that's a development tool. It's a production server running MySQL. they the attack used default signing keys that had shipped unchanged since 2020. So six year old default keys.

Like everything that could go wrong went wrong here. And and this was preventable stuff. So that's if if we get nothing else from this conversation, I wanna point out that we are not in iRobot yet. I'm not saying we won't get there, but so far it's still bad guys that just have better tools. And by the way, us good guys also have better tools.

Mario Zaki (12:58)
My qua what I wanna know is how why did the L L target these guys? Like w did the hacker it so they did they did.

Justin Shelley (13:05)
'Cause the bad guys pointed it at them. It wa it was it was a targeted

attack. This was not that's what I'm saying. This was not autonomous. This was not AI acting on its own th this was targeted.

Joshua Holloway (13:19)
It was pointed from the f the fat the point that it was pointed at that direction, it ran autonomously. So somebody bait ba gave it a job.

Justin Shelley (13:26)
Correct. Once it got in, it

it was able to be intelligent, right? That's the whole point. And and go ahead and get its job done. But also the credentials that were used to get into the sequ MySQL database were not compromised from within the network. Those those were already obtained in a previous breach of some sort. So

Mario Zaki (13:45)
Yeah, so

Justin Shelley (13:46)
this this was a multi-step, it happened over time. it was researched, it was targeted. It's just that once they had all the ammunition.

lined up the target and pulled the trigger, it happened super fast.

Mario Zaki (13:59)
Yeah. No, I I think we're we're getting to a point where we're we're definitely gonna have to you know fight fire with fire or AI with AI. You know, I I think I I I think security is still in play here. It's not something

Joshua Holloway (14:12)
Mm-hmm.

Mario Zaki (14:12)
that is gonna go away. We you know, we're not working with like old technology. It it's still what we've been preaching about for a hundred and two episodes. That's still in play. Everything that

you need to to do, no matter if it's against a AI, against a human, against a team of hackers, it's still the same security measures at the moment that has you know, has to be patched. It, you know, computers that don't need to be facing the internet, take off. If they need to be facing the internet, you you know

Justin Shelley (14:46)
Or if they are, patch the hell out

of them. That's that's kind of what I'm saying. This was a publicly facing system that hadn't been patched with a known vulnerability, severe or critical, I think, was the level. Like this wasn't just a minor thing that had gone unpatched for over a year. Like if you're gonna point that stuff at the internet, take care of it.

Joshua Holloway (15:03)
Well, and I think there's a different thing that we should be looking at too is take all of our security tools out of the equation for what took place, right? The vulnerability was a compromise password, default password for a piece of software.

Justin Shelley (15:19)
Yeah. Yeah.

Joshua Holloway (15:20)
So, right off the bat, take all the security out of it. That human setting up that service was I hate to say it, lazy.

Mario Zaki (15:30)
Stupid.

Joshua Holloway (15:31)
lazy and didn't update the password. And I I think this is where it's super important for business owners who who kind of like set it and forget it. They let their IT do whatever their IT does and because it works, great. You know, it responsibility falls on upper management here to start asking those questions. Like have we truly done everything that we are supposed to to be secure? Have a plan. I'm del I'm deploying a new piece of software. Okay, well I'm not going to have the same default password.

Guys, raise your hands. How many of you c you know, leave the default password, right? None of us do.

Justin Shelley (16:05)
Anytime

I need to work on a MFP multifunction printer, right? The big copiers,

Joshua Holloway (16:09)
Mm-hmm.

Justin Shelley (16:10)
printers, scanners, anytime I can Google the password on those things. I've I've I think once or twice in my career seen that changed. And I'm

Mario Zaki (16:18)
Correct, same here.

Joshua Holloway (16:18)
Well

Justin Shelley (16:19)
it doesn't sound like a big deal until we talk about all the the IoT stuff that you know, where they're going in and they're finding these devices, these smart devices, and then they're hijacking them. Or they're getting in and they're pulling information off a hard drive because guess what? People, printers have hard drives and it stores everything you send to print or scan.

So now that you've got PHI or or P I I any any kind of protected information that you're printing, scanning or or storing through their printer, that's that's all publicly available.

Joshua Holloway (16:46)
Right. Yeah. So I think biggest thing is is installing anything, be it a printer, copier, piece of software, change the passwords. And don't just change it once. Change it quarterly, biannually, whate whatever it works out for you. You know, th that that's just simple stuff right there before you tack on the security software.

Justin Shelley (17:09)
Right. No, this absolutely this was preventable. What like what I used to always say, preventable with basic security measures. And then I quit saying basic because it is really pretty complicated. But not this. This was actually really simple. All they had to do is update the software to the current version. Period.

Mario Zaki (17:26)
Yeah. And and change passwords.

Joshua Holloway (17:28)
changed the

Justin Shelley (17:28)
And

change a password.

Joshua Holloway (17:29)
password. Well, and I think the other thing

go ahead, Red.

Justin Shelley (17:33)
No,

just you this is we shouldn't have to say this stuff. Like this is stupid. We we should not be having this episode.

Mario Zaki (17:37)
Yeah. honestly.

Justin Shelley (17:39)
One two deleted. We shouldn't even be here today. Good God.

Joshua Holloway (17:41)
All right, everybody. Have a good one.

Mario Zaki (17:42)
Yeah. W we we we could

liter honestly that's it. We could wrap this up because it really this is not something you know, the the biggest high you know, thing is how fast they were able to do it because they used the AI. You know, we all know they're everybody's now using AI. You know, we've dedicated months, you know, of the show talking about how you could use AI. You know, we're not the only ones that h know the secret that, you know, AI makes things easier and faster and you know,

Whatever, you know, like it it it hackers are using the hackers are probably using it before any of us were using it.

Joshua Holloway (18:20)
Well, and here's a couple of things you know, on this trajectory of how is attack, I think we should also talk about two. One, Mario, you just hit it, right? Attack speed will continue to outpace human response time. So we need to be doing everything we can upfront to mitigate this as much as possible. Today's the day AI will be used to target multiple multiple organizations simultaneously. This is not the this is a proof of concept, right? They they they pointed

Justin Shelley (18:44)
Yeah, absolutely. Mm-hmm.

Joshua Holloway (18:45)
the gun, they pulled the trigger, they made a proof of concept of how

AI fully driven attacks, we can all download an LLM and take the guardrails off. Like we'll there's been multiple conversations here in this podcast as well that show that we have the capability to download a model and take off the guardrails and do things just like this. And they're becoming more and more sophisticated. The attack chain, I think, is gonna be more adaptive, right? This also proves AI is gonna be super adaptive. It's gonna change its code, it's gonna change the way it looks, making it difficult to block.

And then here's the scarier one. We used to deal with this a long time ago when people found the dark web and then they realized for two dollars and thirty cents they could buy malware. Well, the skill floor for launching a sophisticated attack has now it's dropping even further, faster because they don't even have to go to the yep,

Justin Shelley (19:33)
Yeah. Yeah. It's now free basically.

Joshua Holloway (19:37)
yep, pretty much. You don't have to go to the dark web. You just need an LLM and you take the guardrails off and then start having fun. And it's just a conversation at that point.

Justin Shelley (19:47)
Yeah. And and this w just is off topic, but just an interesting note about this one. it was a ransomware attack, which the the point of ransomware, if you don't know by now, is you get money and then in exchange for the money, you hope to get your stuff back. they encrypted it with a key that was never stored, never like it there was no way of ever getting the their data back. So this

The AI was a little clumsy there, or maybe they didn't care. I don't know. But I will say, you know, this is something I used to talk about in the early days of of ransomware discussions. the bad guys have to have good customer service or their business model blows up. If they don't give your

Mario Zaki (20:25)
Mm-hmm.

Justin Shelley (20:26)
data back, then we stop paying them. And people are still pretty good about paying. So in this case, they're kind of shooting themselves in the foot. And and maybe, while you're right, Josh, the floor's kind of dropping out and you can get fucking idiots out there now.

running

these attacks. It used to require a level

Joshua Holloway (20:41)
Mm-hmm.

Justin Shelley (20:42)
of intelligence. Well now they're they're they're they're gonna ruin their industry if they don't clean up their act, right? Like, come on, bad guys, up your game. Jesus Christ. Did I s did I say that live?

Mario Zaki (20:51)
No, I I think I I

Joshua Holloway (20:53)
Ha

Mario Zaki (20:53)
I I I

Joshua Holloway (20:53)
ha.

Mario Zaki (20:53)
think I think it's like what you're saying we I said earlier. This is a targeted attack. It was probably a former employee or a competitor and he's like,

Justin Shelley (21:00)
Maybe, maybe.

Mario Zaki (21:02)
you know what? I don't even want

Joshua Holloway (21:02)
Ooh. Corporate espagnage.

Mario Zaki (21:04)
I yeah, I don't want money. I just want these guys to to not operate or to to really be hurt. You know, it doesn't you know, he would have I I'm sure if he w his whole point was getting money, I'm sure he would have been able to get money.

Justin Shelley (21:20)
Well, but it was the AI agent that was making its own decisions that encrypted things, printed the key out like on a console screen or something, and then made claims about how, you know, we'll we'll be able to get your stuff back. Also said that it had exfiltrated data, which they can't prove that did or didn't happen. So it was this that this is where the AI agent did kinda go rogue, but not in the bad guy's favor.

Mario Zaki (21:44)
Now why can't we use AI to unencrypt the stuff?

Joshua Holloway (21:48)
It's good question. Has anybody tried?

Justin Shelley (21:52)
that's quantum computers. We're on the wrong subject. because they will. With with quantum computers are that's that's kind of the fear with them is they'll they'll decrypt anything.

Joshua Holloway (22:02)
But yeah, quantum computers c encryption no longer exists.

Justin Shelley (22:05)
Correct. I mean they're working on it. I've I I can't talk intelligently on the subject. I've just asked enough smart people enough questions that I'm comfortable saying that I think there's a solution potentially in place. Maybe perhaps one day. That's how confident I am in it. but it is a

Mario Zaki (22:20)
Well, you broke up

on my side w within how long?

Justin Shelley (22:25)
I don't know. Did I break up or did I just not say? soon

Joshua Holloway (22:27)
Yeah.

Justin Shelley (22:30)
nobody knows, Mario. How how fast until the next Fable 5.1 just dropped, I think today. I don't know. It just popped up on my thing saying, Hey, you got a new thing, a new toy to play with. Yay. I don't know.

Joshua Holloway (22:42)
Yeah.

Justin Shelley (22:42)
I mean, it it's it's the race. The, you know, is are the Chinese gonna get quantum computers before us, or vice versa? Because that's the game. We've just got another.

Cold War almost going on here. That one's scary. I we haven't even talked about quantum computers. That one is actually really scary. I'm more afraid of that than I am of AI, honestly.

Mario Zaki (23:03)
Yeah. But it

Justin Shelley (23:04)
Anyways.

Mario Zaki (23:05)
will be it will be very soon, I think.

Justin Shelley (23:08)
Which? Quantum? I mean, yeah, they've they've those proof of concepts are there. You can actually yeah, I don't know. We maybe should have an episode on quantum computers, 'cause I'll need to do some research before I say anything publicly. But

Mario Zaki (23:20)
Yeah.

Justin Shelley (23:22)
it's sketch.

Joshua Holloway (23:22)
Maybe find

a guest that can attend to to talk about it.

Justin Shelley (23:25)
That that actually we should probably do. Yeah.

Joshua Holloway (23:27)
Like melt our brains.

Justin Shelley (23:29)
Yeah.

Mario Zaki (23:29)
Mm-hmm.

Justin Shelley (23:32)
All right, guys. I promised we were gonna keep this one a little bit shorter today, so let's go ahead and did we miss anything first of all? Bueller? No.

Joshua Holloway (23:41)
No,

the only thing that I think that was missed is in a part of this attack, all of the the backups were also detected and blocked. And I think that's another thing we probably want to hit on is having intelligent backups. Backups that are immutable that can't be changed. That that's

Justin Shelley (23:57)
Immutable. Yeah, they've got to be immutable.

Joshua Holloway (23:59)
they gotta be immutable. They can't be changed, they can't be messed with. and they can't be, you know, the backup appliance can't be attached to the domain or it can't be in the same network. It can't be easily found.

You know, so there's a lot of different things to that too, because it's it's it's learning it. But Mario, what do you got?

Mario Zaki (24:16)
Yeah, again, shit that we've been talking about for like from like episode like four, you know, like stuff you know

Justin Shelley (24:21)
I know. Yeah, this is not new.

Mario Zaki (24:23)
these guys i if everything we've discussed and what we've read is true, then these guys deserve to to to really get effed like this because you know, it it's it's security one one, you know, like it it's everything everything that we're talking about, backups and security and passwords and patching and stuff like that, come on.

You know, like w i it's twenty twenty six, almost twenty twenty seven. You know? They deserve it.

Justin Shelley (24:53)
Episode four. Now I'm I'm fact checking your ass just randomly. I'm like, what did we talk about on episode four?

Joshua Holloway (24:56)
Ha ha

Justin Shelley (24:59)
A day in the life of a CISO. That's what that one was. And it's before

Joshua Holloway (25:04)
shoot.

Justin Shelley (25:04)
your time, so you don't even know, Mario. You weren't on episode four. You started eight.

Mario Zaki (25:08)
Well, I was a I I was a l I was a listener back then.

Justin Shelley (25:11)
Okay, okay, fair enough. Fair enough.

Joshua Holloway (25:14)
No, I like

that. Well, and the the other thing

Justin Shelley (25:17)
Alright.

Joshua Holloway (25:17)
I want I I wanted to bring up with you guys, and I know you wanted to make it short today. but we are, you know, this is a podcast for business owners and things like that. And one of the other things I want to talk about is I got a horror story if you guys are interested. And yeah.

Justin Shelley (25:30)
Mm. That's right. You tease us with that and then almost left us hanging. What do you got, Josh?

Mario Zaki (25:32)
Yeah.

Joshua Holloway (25:35)
Yes. So I got a a horror story. and we're just weren't it's just an MSP that I know about.

And somebody had reached out to us because basically they were freaking out because their data is hosted and there's a legal battle between the MSP and one of the other owners of another of the of the MSP where they they it was an MA, and MA later fell apart and everybody's fighting. So they reached out to us through a referral. Thank you for the referral. and they were super afraid of

What's happening to their data? They haven't been getting things taken care of. And when I say getting things taken care of, I mean months. So vulnerability scans were given to the owner of the company that reached out to me. Vulnerability scans been sitting there for months. Nothing done about it. Her her VPN had a SSL certificate issue, so they couldn't, they could barely log in with SSL cert for their VPN, not getting taken care of. Simple fixes, right? But because the MSP

inner fighting with each other, one side's trying to help her. The other side's saying, well, like we'll help you, but to help you, you need to do all these things and pay all this money and or we're not going to do anything. And it's like she doesn't they don't know who are they paying to get what done. They don't know where their data resides, what the passwords are are. And then here's where all of a sudden it turned it got on fire yesterday.

They called me up freaking out because they received their invoice.

On the first, they received a letter yesterday on the second stating their services are being discontinued.

And if they want to keep their say their their services and and their VPN has been disabled. If they want to keep their services and get access to their VPN, to their software, to their services, to this stuff that they own, they need to come current immediately, which you've had an invoice for 24 hours. It's the only open invoice. I did double check. It's the only open invoice. Everything's turned off. She's like they're freaking out. We we can't. yeah, yeah. No, I told her.

Justin Shelley (27:52)
Call an attorney. You know this already, right? Okay.

Joshua Holloway (27:56)
I was like, call

call you know, call an attorney. But but it's like

Justin Shelley (27:58)
Immediately.

Joshua Holloway (28:02)
they couldn't work. And then the other thing is, is I got wind of a couple of quotes, $44,000 quote, quote to do some other things. They're basically giving that company until the ninth or the tenth of this month to decide which quote they're they're going with to maintain services or off board.

Which to me I know what the easy answer is because like why would you want to do business with an MSP

Justin Shelley (28:28)
Yeah.

Joshua Holloway (28:29)
that's holding you ransom at this point? But I w Yeah.

Justin Shelley (28:31)
Basically it's the same thing, yeah.

Mario Zaki (28:33)
Yeah,

I was about to say what's the difference between this and and what we talked about earlier?

Justin Shelley (28:34)
It's a ransomware attack. It's nothing. And it's illegal.

Joshua Holloway (28:37)
Yeah.

Yeah. Well, of course, I was like, hey, I know you haven't signed with us. Call your attorney, give them your your your master service agreement, figure all that out because like what they're doing is not right. And at least protect yourself there. But I wanted to bring this up because I think I've heard of this a couple of times in in my area where MSPs do really crazy things off the wall like this, where they they

Hold on to the passwords and refuse to give them over while the ship is sinking. You know, or they

Justin Shelley (29:09)
Mm. Mm-hmm.

Joshua Holloway (29:10)
are essentially holding the gun to your head saying, Pick which thing you want to do that's gonna cost you a huge amount of money that you weren't prepared for, or just fire us because maybe we just don't want you as a client. I don't know. You know, but like

Justin Shelley (29:29)
It's crazy. And it it just goes back to what I keep saying over and over. Our industry is unregulated, and that is a problem. I don't necessarily want the government involved, but I have really am tired of shitty MSPs and and they plague our industry because there is no barrier to entrance to be an MSP. To be a cybersecurity expert. You can you can be a nobody. Anyone can be a cybersecurity expert, charge good

Mario Zaki (29:55)
No.

Justin Shelley (29:57)
money.

Make all kinds of promises and not do a goddamn thing. That's the problem.

Joshua Holloway (30:03)
That's the whole reason why I started doing this. Go ahead, Mara.

Mario Zaki (30:03)
I think it also yeah, I I think

it also needs to protect the MSP as well too, because you know, certain things like, you know as an MSP, we're paying for security, we're paying for our technicians and stuff like that, we're providing a service, you know, we need to get paid for it, you know, so there has to be some sort of guidelines like, Hey, you know you know, you need to pay your bill. If you don't pay bills, then you know, you need to do you know, y yes.

They can shut you down, you know, because at the end of the day too, you know, we we've discussed it. Like if if you have somebody that hasn't paid you in six months, you know, what do you do? You know? so I I think it does work both ways, but you know, Josh, you said that they had no open invoices. Like they can't just say say, Okay, it's the third of the month we're shutting you down, you know.

Joshua Holloway (30:55)
Yeah, and they did this on the second. They did this yesterday. So

Mario Zaki (30:58)
yes. So

It it what they're doing, they're they're giving a a bad name to you know, to all of us, you know, a company like that. You know,

Justin Shelley (31:05)
Absolutely. Yeah. Yep.

Mario Zaki (31:07)
but you know, i if it it's a different story of this customer had like six months where they haven't paid you know, at the end of the day, you know, why should this MSP keep paying for their services if they if they're not getting compensated? The contract works both both ways. But if they if they don't have anything open, then you know what? The the right thing for them to do is say, you know what

You have here's your passwords, here's your whatever you have until this, you know, day, and you know, to find somebody else. You know, that's the professional thing to do, not just say, take plan A or B, otherwise we're shutting you down. You can't you they can't do that. You know, we've talked about it. You know, sometimes, you know, owners don't end up doing, you know, what's recommended and then it

It you know, you have to document it and you you just continue and you let know like this is a vulnerability, but you can't just shut them down.

Justin Shelley (32:03)
Can you imagine a doctor just saying, you know what, pay your bill? I'm not stitching you back up until you pay your bill.

Joshua Holloway (32:08)
Oof.

Justin Shelley (32:08)
I'll just I'll just let you

Mario Zaki (32:09)
Yeah.

Justin Shelley (32:09)
die here on the operating table because it's the same goddamn thing. Like this is the stuff that MSPs do. It's it's it's a terrible industry. I don't I I will not understand for the life of me how something this critical to infrastructure in our country is completely unregulated. We regulate the clients, great, that's a starting point. But how is it that anybody can be an MSP?

With no accountability whatsoever. We gotta fix that. I mean, like I I I I just firmly believe that we've gotta elevate our industry. It's not good.

Joshua Holloway (32:39)
No,

we definitely need to elevate our industry. I I wholeheartedly agree. And there should be some rules, regulations, licensing, things that we have to obtain, whatever that looks like. I I think the other thing is businesses who get excited because a company, you know, brand new pops up off the street and they're saying we can come in and we can do your IT for twenty five bucks a computer. So I'm sorry, but you should run.

and or really investigate how they're able to do what they do for such a low price.

Justin Shelley (33:10)
I was gonna say one

of the cool things right now, business owners, if if you're listening to this, punch in what you're paying, put your whole service agreement in there and and ask it to rank your agreement, both what you're getting and what you're paying, against the standard. Because now we at least have that information. We can go into AI and say, Hey, what should it cost to, you know, manage the IT for a small dermatology office in Dallas, Texas? You can do that and it'll tell you.

And if you're paying half of that, good luck.

Joshua Holloway (33:43)
Or start asking questions. What am I getting? How often am I getting it? What's being taken care

Justin Shelley (33:46)
Yeah. Yep.

Joshua Holloway (33:47)
of? Because just like we all said, we all have people we have to pay, software we have to pay for, that choose that chews up our our ability to earn a profit, right?

Justin Shelley (33:57)
We

run industry average is a good business. A good MSP is hitting twenty percent margin. A good one. more common is ten percent. So if somebody's discounting their price by more than ten percent of the average price, they're short changing you somewhere. Like it can't be

Joshua Holloway (34:16)
Mm-hmm.

Justin Shelley (34:17)
done. This is just math. It's not like they're good people and they're, you know, somehow figured out some magic trick that they can support you for super cheap. It doesn't work that way.

Mario Zaki (34:24)
Yeah, because

another thing is too like this the good security tools that we use, they don't just let you sign up for like a ten, you know, ten licenses at a time or thirty licenses at a time. You know, to get good like to even just get in the door with like good companies, good security tools, you need like a thousand computer minimum, fifteen hundred computer minimum. and in order to really have that, you have to have a a a larger MSP.

You have to have several employees, several customers. You know, these little ones that just pop up, they're just trying to they're trying to go with quantal quality instead of quantity. And they're not using good tools. There's no way those guys are using good tools and giving it to you at that price.

Justin Shelley (35:08)
No, their tools, even if

it's the same tools, then they cost three or four times as much. So they're actually working in a different economy of scale. They should be able to provide worse service, not better, for more money, not less. So when you're going with that,

Mario Zaki (35:18)
Yeah. Exactly. Or they're not using anything.

Joshua Holloway (35:22)
Mm-hmm.

Justin Shelley (35:23)
which is exactly what I'm talking about. This is the problem with the unregulated industry. And it's the problem I am trying to solve with unhackmybusiness.com. There's my shameless plug. This is where you can go in and and use it to rank your own IT company. Go in and look at what they should be doing.

Make them show you proof that they're doing it. Because guess what? They're probably not. All right, guys. So much for our 20-minute episode that's now 37 minutes. no, it and it got me

Joshua Holloway (35:49)
Hey, I I I just had a horror story I wanted to share.

Mario Zaki (35:51)
Mm.

Justin Shelley (35:52)
going. It got me going, Josh. So, all right, guys, let's go ahead and wrap this up. key takeaways if you got them. I think we've kind of beat this thing to death. But as always, Mario and Josh, thank you for being here. Appreciate your insights.

Your homework in preparing for these things and guys we're gonna come back next week. Bigger, better, stronger, and more brilliant. that's all I got. Mario, Josh, say your goodbyes and we're gonna get the hell out of here.

Mario Zaki (36:19)
Yeah, guys. I mean stick stick what we've been telling you from day one, you know, work with your MSP. If you're not working with an MSP, give us a call. stay secure. You know, you need to be able to sleep better at night, you know, knowing your business will be there tomorrow.

Justin Shelley (36:37)
Yep. Josh.

Joshua Holloway (36:37)
And don't

accept that d defaults and change passwords.

Mario Zaki (36:40)
Mm-hmm.

Justin Shelley (36:41)
Yeah.

Joshua Holloway (36:43)
But yeah, ha have security tools that are being updated, they are being patched, and they cohesively talk and communicate. And that could be dissimilar stuff. As long as it's communicating and protecting you, I think you're great. if you use tools like some of us might use where all of our tools communicate, that's even better. But whatever you could do to make sure that you're being protected and help you sleep better at night.

this is what this podcast is for. We're we're teaching everybody about it and you know, discussing the things that we're running into and the new t new topics that are coming in. So be safe, be aware, and update those passwords. Thanks, guys.

Justin Shelley (37:18)
Make sure your MSP slash IT company proves to you that they're doing what they're charging you to do. That's what I got, guys. We'll see you next week. Take care, everybody. Thanks for.

Mario Zaki (37:28)
And stay unhacked.

Joshua Holloway (37:30)
Unhacked.

Justin Shelley (37:30)
Unhacked.

Creators and Guests

Bryan Lachapelle
Host
Bryan Lachapelle
Hi, I’m Bryan, and I’m the President of B4 Networks. I started working with technology since early childhood, and routinely took apart computers as early as age 13. I received my education in Computer Engineering Technology from Niagara College. Starting B4 Networks was always a dream for me, and this dream became true in 2004. I originally started B4 Networks to service the residential market but found that my true passion was in the commercial and industrial sectors where I could truly utilize my experience as a Network Administrator for a large Toronto based Marine Shipping company. My passion today is to ensure that each and every client receives top of the line services. My first love is for my wonderful family. I also enjoy the outdoors, camping, and helping others. I’m an active Canadian Forces Officer working with the 613 Fonthill Army Cadets as a member of their training staff.
Mario Zaki
Host
Mario Zaki
During my career, I have advised clients on effective – and cost-effective – approaches to developing infrastructure that fosters productivity and profitability. My work has provided me with a broad-based knowledge of business from the inside, with an expertise in areas that go beyond IT alone, ranging from strategic planning to cloud computing to workflow automation solutions.
AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102
Broadcast by