1 00:00:02,520 --> 00:00:09,160 Speaker 1: Bloomberg Audio Studios, Podcasts, radio news. This is Bloomberg Business 2 00:00:09,240 --> 00:00:13,480 Speaker 1: Week with Carol Masser and Tim Steneveek on Bloomberg Radio. 3 00:00:13,920 --> 00:00:17,720 Speaker 2: Hey, you mentioned Emily Graffeo some of the stuff happening 4 00:00:17,880 --> 00:00:21,720 Speaker 2: when it comes to hacks coinbase specifically, I'm gonna read 5 00:00:21,720 --> 00:00:25,599 Speaker 2: some headlines here, Okay, Sequoia Capital Partners data hacked and 6 00:00:25,640 --> 00:00:30,960 Speaker 2: Coinbase breach. Coinbase hack highlights how greed can overwhelm cyber defenses, 7 00:00:32,040 --> 00:00:35,960 Speaker 2: coinbased customer data stolen. Just a sample of headlines from 8 00:00:36,200 --> 00:00:39,240 Speaker 2: Bloomberg News and from the Wall Street Journal. This garnering 9 00:00:39,240 --> 00:00:41,319 Speaker 2: our attention on a day such as today and kind 10 00:00:41,360 --> 00:00:43,879 Speaker 2: of perfect to have Wendy Whitmore back with us. She's 11 00:00:43,960 --> 00:00:46,000 Speaker 2: chief intelligence officer of the one hundred and twenty eight 12 00:00:46,080 --> 00:00:48,800 Speaker 2: billion dollar market cap Palabelto network. She joins us from 13 00:00:49,080 --> 00:00:52,400 Speaker 2: Santa Clara, California. Wendy, good to have you back with us. 14 00:00:52,840 --> 00:00:58,520 Speaker 2: The Coinbase hack, I think, really highlights how our information 15 00:00:59,440 --> 00:01:03,080 Speaker 2: is at rich even if we think as consumers, as 16 00:01:03,240 --> 00:01:06,680 Speaker 2: users of these products and services, it's safe. I mean 17 00:01:06,720 --> 00:01:08,400 Speaker 2: when you talk about the type of data that's at 18 00:01:08,440 --> 00:01:11,720 Speaker 2: risk here, I mean we're talking images of drivers' licenses, 19 00:01:12,080 --> 00:01:16,720 Speaker 2: being available to hackers as a result of accessing the network. 20 00:01:17,040 --> 00:01:18,640 Speaker 2: Talk to us a little bit about what we know 21 00:01:19,160 --> 00:01:22,560 Speaker 2: regarding this hack and what it highlights about the vulnerabilities 22 00:01:22,600 --> 00:01:23,000 Speaker 2: out there. 23 00:01:24,520 --> 00:01:26,800 Speaker 3: Yeah, hey, thanks Tim, great to be back here today 24 00:01:26,840 --> 00:01:29,319 Speaker 3: with you. So, I think what you highlighted is really 25 00:01:30,520 --> 00:01:32,800 Speaker 3: just the fundamental problem we see here, which is how 26 00:01:32,880 --> 00:01:37,200 Speaker 3: challenging it is for organizations to defend against every possible 27 00:01:37,240 --> 00:01:40,240 Speaker 3: type of attack. The really interesting part of this case 28 00:01:40,360 --> 00:01:43,080 Speaker 3: is that these attackers have demanded twenty million dollars in 29 00:01:43,319 --> 00:01:47,160 Speaker 3: ransom payment, and coinbases really turn the table on them 30 00:01:47,240 --> 00:01:49,360 Speaker 3: in something that we haven't seen yet, which is a 31 00:01:49,480 --> 00:01:52,680 Speaker 3: very public disruption of the attacker. And they said, you 32 00:01:52,680 --> 00:01:54,279 Speaker 3: know what we're going to do. We're going to invest 33 00:01:54,280 --> 00:01:57,320 Speaker 3: twenty million dollars into a fund that goes after finding 34 00:01:57,360 --> 00:01:59,600 Speaker 3: out who the attackers are that are responsible for this 35 00:01:59,680 --> 00:02:03,000 Speaker 3: attack and bringing them to justice. And I think, you know, 36 00:02:03,080 --> 00:02:05,720 Speaker 3: as the largest cybersecurity company in the world, we at 37 00:02:05,720 --> 00:02:08,120 Speaker 3: Palo Alto Networks, we don't ever want to see any 38 00:02:08,160 --> 00:02:11,440 Speaker 3: client be paying a ransom, But we have not seen 39 00:02:11,600 --> 00:02:14,799 Speaker 3: organizations previously take this kind of tactic, and I think 40 00:02:14,800 --> 00:02:18,680 Speaker 3: what they're doing to disrupt the incentive structure and to 41 00:02:18,800 --> 00:02:21,960 Speaker 3: make it a little more challenging. And I think attackers 42 00:02:22,000 --> 00:02:24,080 Speaker 3: in the future asking the question of a wait, I 43 00:02:24,080 --> 00:02:27,320 Speaker 3: don't know if I want that twenty million dollar international fund, 44 00:02:27,360 --> 00:02:29,880 Speaker 3: which is going to mean people who you know, I 45 00:02:30,000 --> 00:02:32,799 Speaker 3: may be in my network, but maybe willing to kind 46 00:02:32,800 --> 00:02:35,920 Speaker 3: of turn me over to international law enforcement. I think 47 00:02:35,960 --> 00:02:39,120 Speaker 3: they're going to start asking questions, and disruption in this 48 00:02:39,200 --> 00:02:40,960 Speaker 3: cycle is really critical. 49 00:02:41,360 --> 00:02:43,920 Speaker 2: Yeah, I mean, I the sense that I have is 50 00:02:43,919 --> 00:02:48,280 Speaker 2: that our information is not safe. I mean, I don't 51 00:02:48,320 --> 00:02:50,960 Speaker 2: know how many times a day I get text messages. 52 00:02:51,400 --> 00:02:54,400 Speaker 2: I probably get half a dozen text messages from these 53 00:02:54,480 --> 00:02:57,280 Speaker 2: so called pig butchers. I oftentimes I don't even pick 54 00:02:57,320 --> 00:03:00,520 Speaker 2: up my phone if I don't recognize the number. I mean, honestly, 55 00:03:00,600 --> 00:03:02,280 Speaker 2: the world we live in when it comes to this stuff, 56 00:03:02,520 --> 00:03:05,240 Speaker 2: it's pretty annoying. Like this is a very annoying place 57 00:03:05,280 --> 00:03:07,320 Speaker 2: to be as a consumer right now. Is it going 58 00:03:07,360 --> 00:03:09,720 Speaker 2: to get any better? Or is this just the reality 59 00:03:09,760 --> 00:03:10,440 Speaker 2: that we live with? 60 00:03:11,160 --> 00:03:13,800 Speaker 3: Yeah, it's a great question. I don't think you're alone 61 00:03:13,880 --> 00:03:17,640 Speaker 3: in that sentiment whatsoever. It is challenging, right So, we 62 00:03:17,840 --> 00:03:22,280 Speaker 3: are actually blocking thirty one billion attacks per day across 63 00:03:22,280 --> 00:03:25,240 Speaker 3: our customer base, and up to nine million of those 64 00:03:25,440 --> 00:03:28,960 Speaker 3: every single day are new attacks where their novel we 65 00:03:29,040 --> 00:03:31,560 Speaker 3: haven't seen that same type of vector. So that gives 66 00:03:31,600 --> 00:03:33,960 Speaker 3: you an idea of what companies throughout the world are 67 00:03:34,040 --> 00:03:37,120 Speaker 3: up against. And then certainly you highlighted some examples that you, 68 00:03:37,200 --> 00:03:41,160 Speaker 3: as an individual consumer are feeling. So your question though, 69 00:03:41,360 --> 00:03:43,400 Speaker 3: was you know, hey, is it getting any better? 70 00:03:43,480 --> 00:03:46,600 Speaker 2: It's not getting any better for me, will it? 71 00:03:48,320 --> 00:03:50,320 Speaker 3: I think it can get better, and I think that 72 00:03:50,400 --> 00:03:54,080 Speaker 3: we're seeing AI actually be a massive tool for the 73 00:03:54,120 --> 00:03:56,840 Speaker 3: side of the defenders because, as I highlighted, we're up 74 00:03:56,880 --> 00:04:00,200 Speaker 3: against such a major scale problem, these attacks are going 75 00:03:59,920 --> 00:04:03,800 Speaker 3: to be more sophisticated. Real time defense is absolutely critical. 76 00:04:03,920 --> 00:04:06,400 Speaker 3: So what you're going to start seeing tim certainly at 77 00:04:06,400 --> 00:04:10,640 Speaker 3: the company level, all of the technologies we're able to 78 00:04:10,760 --> 00:04:13,560 Speaker 3: use are actually making us able to scale against that better. 79 00:04:13,760 --> 00:04:15,680 Speaker 3: But you're going to see that get into your consumer 80 00:04:15,760 --> 00:04:18,320 Speaker 3: technologies as well, where they're going to start doing more 81 00:04:18,360 --> 00:04:21,039 Speaker 3: effective blocking and you're going to receive less text match 82 00:04:21,240 --> 00:04:24,040 Speaker 3: messages moving forward that are scams in nature. 83 00:04:24,480 --> 00:04:26,840 Speaker 4: When you talk about AI, you know, something that comes 84 00:04:26,880 --> 00:04:31,520 Speaker 4: to mind is just how scammers can use AI to 85 00:04:31,560 --> 00:04:36,919 Speaker 4: say impersonate so impersonate a parent, a family member, a 86 00:04:37,000 --> 00:04:41,159 Speaker 4: loved one and try and hack you that way. How 87 00:04:41,200 --> 00:04:45,000 Speaker 4: concerned are you that the advancement of this technology like 88 00:04:45,080 --> 00:04:47,799 Speaker 4: we're not going to be able to keep the defenses 89 00:04:47,920 --> 00:04:50,680 Speaker 4: up strong enough to kind of combat the growth of 90 00:04:51,640 --> 00:04:53,200 Speaker 4: cyber criminals using AI. 91 00:04:54,520 --> 00:04:56,679 Speaker 3: Well, I think there's two parts of it to really 92 00:04:56,839 --> 00:04:59,719 Speaker 3: hit effectively to answer your question. First is on the 93 00:04:59,720 --> 00:05:02,599 Speaker 3: tech side that has to continue to get better. But two, 94 00:05:02,600 --> 00:05:05,200 Speaker 3: we have to continue to increase awareness at the public 95 00:05:05,360 --> 00:05:08,120 Speaker 3: level and then make sure that people are making smart 96 00:05:08,120 --> 00:05:11,480 Speaker 3: decisions about how they use technology. So when we look 97 00:05:11,520 --> 00:05:15,160 Speaker 3: at it at a wider spread level in organizations, we 98 00:05:15,200 --> 00:05:17,600 Speaker 3: see what you're talking about. Just last week, we were 99 00:05:17,640 --> 00:05:21,640 Speaker 3: investigating a case where we were working for a firm 100 00:05:21,839 --> 00:05:24,800 Speaker 3: who was a victim of ransomware, and we were negotiating 101 00:05:24,839 --> 00:05:28,160 Speaker 3: with the attackers to try to get additional information from them, 102 00:05:28,200 --> 00:05:30,880 Speaker 3: and it became very clear almost instantly that we weren't 103 00:05:30,920 --> 00:05:33,240 Speaker 3: talking to a person on the other end, but we 104 00:05:33,240 --> 00:05:36,120 Speaker 3: were actually talking to a chatbot that they had enabled 105 00:05:36,120 --> 00:05:40,120 Speaker 3: to do the negotiations for them. We certainly will continue 106 00:05:40,200 --> 00:05:43,320 Speaker 3: to see more of that. Another example that we saw 107 00:05:43,400 --> 00:05:47,000 Speaker 3: just in the last couple weeks of investigating a case 108 00:05:47,040 --> 00:05:50,279 Speaker 3: for a major organization, the attackers, once they got inside 109 00:05:50,279 --> 00:05:53,760 Speaker 3: the environment they actually used, they went straight to that 110 00:05:53,880 --> 00:05:58,160 Speaker 3: company's internal large language model and started interacting with it 111 00:05:58,279 --> 00:06:01,520 Speaker 3: to try to get more sinse me asking them questions 112 00:06:01,520 --> 00:06:04,120 Speaker 3: about where the domain controllers were, what were their names, 113 00:06:04,360 --> 00:06:06,880 Speaker 3: and finding out information that was actually helpful for them 114 00:06:06,880 --> 00:06:09,440 Speaker 3: in the course of an attack. So that means that 115 00:06:09,560 --> 00:06:13,040 Speaker 3: in order to really be successful here, organizations have to 116 00:06:13,080 --> 00:06:16,800 Speaker 3: fight AI attacks with AI on the defense, and that 117 00:06:16,960 --> 00:06:18,040 Speaker 3: has to be in real time. 118 00:06:18,480 --> 00:06:20,160 Speaker 2: And then what do we do as consumers? I mean, 119 00:06:20,160 --> 00:06:23,040 Speaker 2: I know a guy who was getting calls like that 120 00:06:23,120 --> 00:06:26,000 Speaker 2: looked like it was from his bank. It literally said 121 00:06:26,040 --> 00:06:28,200 Speaker 2: his bank's name on the phone, and he was so 122 00:06:28,360 --> 00:06:31,000 Speaker 2: close to actually giving up the information when he realized 123 00:06:31,040 --> 00:06:33,920 Speaker 2: that it wasn't actually his bank. Like, what are we 124 00:06:33,960 --> 00:06:35,160 Speaker 2: supposed to do as consumers? 125 00:06:35,880 --> 00:06:38,760 Speaker 3: Well, I think we've got to approach every conversation unfortunately 126 00:06:38,800 --> 00:06:41,839 Speaker 3: with skepticism, do that same with every message. But for 127 00:06:41,960 --> 00:06:45,320 Speaker 3: your bank, for example, most banks will say, hey, we're 128 00:06:45,360 --> 00:06:46,880 Speaker 3: not going to reach out to you and ask you 129 00:06:46,880 --> 00:06:52,240 Speaker 3: for personal information. Everywhere you can use multi factor authentication, 130 00:06:52,600 --> 00:06:55,039 Speaker 3: it not only sometimes adds a little bit of time 131 00:06:55,040 --> 00:06:56,720 Speaker 3: for you to get in, but it's going to make 132 00:06:56,760 --> 00:06:59,159 Speaker 3: it a lot harder for an attacker to try to 133 00:07:00,320 --> 00:07:03,640 Speaker 3: log in as you and essentially try to steal money 134 00:07:03,720 --> 00:07:07,200 Speaker 3: or move money or maybe infact a social media account 135 00:07:07,400 --> 00:07:09,840 Speaker 3: if they have to go through a number of additional 136 00:07:09,880 --> 00:07:11,080 Speaker 3: steps to get there as well. 137 00:07:11,600 --> 00:07:14,160 Speaker 2: All right, well leave it on a positive note. Make 138 00:07:14,200 --> 00:07:17,520 Speaker 2: sure to have two factor authentication, art time unique passwords too, 139 00:07:17,600 --> 00:07:20,040 Speaker 2: is something that we hear over and over again when 140 00:07:20,080 --> 00:07:23,559 Speaker 2: it comes to sort of safe security hygiene. Wendy always 141 00:07:23,560 --> 00:07:26,920 Speaker 2: appreciate you joining us. Wendy Whitmore, chief intelligence officer of 142 00:07:27,000 --> 00:07:29,160 Speaker 2: the one hundred and twenty eight billion dollar market cap 143 00:07:29,200 --> 00:07:34,640 Speaker 2: Palo Alto Networks, joining us from Santa Clara, California,