Axios Codebook

December 03, 2024
Happy Tuesday! Welcome back to Codebook.
- ❤️ Hope you all had a relaxing and restful Thanksgiving break.
- 📬 Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,107 words, a 4-minute read.
1 big thing: Hackers pivot from data breaches to total destruction
Hackers are increasingly looking to shut down victim companies during cyberattacks.
Why it matters: Organizations need to prepare their defenses to fend off service disruptions and malware wipers, experts say.
The big picture: The number of ransomware attacks in 2024 has been about the same as last year, according to Palo Alto Networks.
- Palo Alto Networks' threat intelligence team says it has seen just a 4% increase this year in the number of companies listed on so-called extortion sites — websites where ransomware gangs publicly list the companies they've attacked that haven't yet paid a ransom.
- Sam Rubin, global head of operations at Palo Alto Networks' Unit 42 team, told Axios that companies are finally getting better at backing up their data. Doing so helps them recover faster from ransomware attacks that seize their files.
- Hackers have caught on and are now pivoting to destructive attacks in the hopes of getting businesses to pay ransoms again, he said.
Threat level: These attacks focus on bringing companies "to their knees," Rubin said.
- Attackers are looking to render key systems useless and unsalvageable. Think malware wipers and denial-of-service attacks.
- The hackers behind these attacks try to target large tech vendors whose customers include big-name companies so they can also cause more widespread destruction.
- These groups often return to target the same companies as part of a persistent campaign, Rubin added.
Zoom in: Rubin shared one example where hackers targeted just one company that had more than 100 partners. Each one had to disconnect from the unnamed vendor's product, even if it wasn't affected, to prevent the hackers from gaining access.
- It took "weeks to go through and assure the safety [of] 100 different business partners," Rubin added.
- In another case, Rubin said, one company felt so much pain from the business shutdowns that when it heard the hackers would take a ransom to stop the bleeding, it paid it immediately. The company was losing millions of dollars each day.
- "If you're a [software-as-a-service] business, and you are absolutely shut down and hemorrhaging customers and hemorrhaging money, that's an incredibly painful situation," Rubin said.
Between the lines: Many of the groups behind major ransomware attacks are the ones pivoting to these destructive attacks, including Scattered Spider, which targeted MGM Resorts and Caesars Entertainment.
- These groups are also using many of the same tactics to get into a company's systems, such as phishing emails, software vulnerabilities and social engineering, Rubin said.
- They're often looking to install file-corrupting malware onto a company's virtual machines, rendering the whole system useless.
Yes, but: Attackers have to do a lot more research and planning to carry out these schemes.
- It costs money and time to figure out which vendors a specific, high-value company relies on and what software vulnerabilities they're exposed to.
What we're watching: Palo Alto Networks predicts that these attacks will become even more prominent in the new year — especially as hackers get better at using generative AI to find vulnerabilities.
2. Elections dodge deepfake threat
AI-driven deepfakes weren't the disinformation catastrophe that tech companies and global governments feared ahead of a slew of major elections this year, Meta president of global affairs Nick Clegg told reporters yesterday.
Why it matters: The spread of broader conspiracy theories has proven to be a much more challenging misinformation threat than AI-doctored photos or videos.
- "From what we've monitored across our services, it seems these risks did not materialize in a significant way and that any such impact was modest and limited in scope," Clegg said.
By the numbers: Meta said that while its systems did catch several covert attempts to spread election disinformation using deepfakes, "the volumes remained low and our existing policies and processes proved sufficient to reduce the risk around generative AI content."
- During the election periods of major races globally this year, content verification ratings from Meta's international fact-checking partners on AI content related to elections, politics and social topics represented less than 1% of all fact-checked misinformation, per Clegg.
State of play: Meta introduced new policies this year — including blocking the creation of AI-generated media of politicians — to prevent everyday users from spreading election misinformation using its Meta AI chatbot.
- The company said its systems rejected 590,000 user requests to generate AI images of President-elect Trump, Vice President-elect JD Vance, Vice President Kamala Harris, Minnesota Gov. Tim Walz, and President Biden in the month leading up to the election.
- Clegg said he didn't see much activity in terms of bad actors trying to game Meta's rules around labeling AI-generated imagery in ads.
Zoom out: Meta has invested heavily in broader threat intelligence over the past few years, which Clegg said has helped the company identify coordinated disinformation networks, regardless of whether they use AI or not.
- "We seek to build policies and enforcement practices that are agnostic about the origin of the content, whether it's synthetic or human," Clegg said.
- "That's why I don't think the use of AI and generative AI in and of itself was a particularly effective tool for them to evade or trip our wires, because it's not the means by which we try and identify them in the first place."
3. Catch up quick
@ D.C.
❌ The Consumer Financial Protection Bureau has proposed new rules limiting data brokers' ability to sell Americans' sensitive personal and financial information, including Social Security numbers. (The Verge)
🇨🇳 The Commerce Department is imposing export controls on 140 new entities to prevent China from developing advanced AI weapons systems. (Axios Pro)
🏛️ Three South Dakota politicians are expected to have a lot of sway in U.S. cyber policy next year. (CyberScoop)
@ Industry
📈 CrowdStrike has avoided a significant customer exodus after the global IT network outage in July, the company said on an earnings call last week. (Cybersecurity Dive)
☁️ Cloud security provider Upwind has raised $100 million in a private funding round led by Craft Ventures. (Reuters)
💻 An Apple employee is suing the company for monitoring its workers' personal devices. (Semafor)
@ Hackers and hacks
🚔 Russian authorities have arrested a high-profile hacker, known as Wazawaka, who is accused of creating malware for several ransomware gangs. (The Record)
💪🏻 T-Mobile said it has prevented hackers from breaching its systems as several telecom providers respond to Salt Typhoon intrusions. (Axios)
🛢️ The FBI has been investigating a longtime Exxon Mobil consultant for an alleged role in a hack-and-leak operation that targeted many of the oil giant's critics. (Reuters)
4. 1 fun thing
🥘 Many of us spent the weekend eating Thanksgiving dinner with loved ones.
- 🍌 The crypto entrepreneur who bought the art of a banana taped to a canvas had a different type of meal.
☀️ See y'all Friday!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.



