UNFUCG
DashboardSearchChatBookmarksNotificationsActivityPremiumProfile
?
Home
Search
Chat
Saved
Profile
Episode
Chasing The Most Hated Hacker In History - Joe Tidy
~105 min
Episode Brief·YouTube

Chasing The Most Hated Hacker In History - Joe Tidy

Chris Williamson
Watch on YouTube Add to chat My bookmarks← All sources

TL;DR

The four things you'd lose by not watching

4 items

TL;DR

The four things you'd lose by not watching

4 items
1

Joe Tidy details the rise of teenage hacking gangs like Scattered Spider, who use social engineering and ransomware to cripple major companies, and explains how they are underestimated as 'noob persistent threats'.

2

He traces the shift from chaotic good to chaotic evil in hacking culture, driven by the rise of Twitter clout and Bitcoin, and profiles the most hated hacker, Julius Kivimaki, from Lizard Squad to the Vastaamo psychotherapy hack.

3

Tidy shares insights from his dangerous investigation into the Russian cybercrime gang Evil Corp, and emphasizes that basic cybersecurity practices like password managers and multi-factor authentication are still the best defense.

4

He warns that the CrowdStrike incident revealed the fragility of interconnected systems, and that quantum computing poses a future threat to encryption, but for now, hackers still rely on old-school social engineering.

Protocols

Concrete recipes — what, when, how much, and why

5 items

Use a password manager

WhatUse a password manager to generate and store unique, strong passwords for each account.
WhenWhen setting up any online account, and to replace existing weak or reused passwords.
For whomEveryone, especially those who reuse passwords.
WhyPrevents password reuse and weak passwords, making you a harder target for credential stuffing attacks.
CaveatsNone mentioned, but ensure the master password is strong and unique.

Tidy emphasizes that hackers go for the easiest targets. Using a password manager moves you from the 'easy bucket' to the 'harder bucket,' significantly reducing your risk. He notes that even having a password manager is a step ahead of most people. The host shares that a former FBI most wanted hacker told him the 90/10 solution is just to use a password manager.

Personal experience

Tidy endorses the host's use of a password manager, saying 'It's good that you got one.'

It's good that you got one.

Also said
“If you take yourself out of that easy bucket into the slightly harder bucket massively reduce your chance of getting hacked.”— Explains the rationale.

Enable multi-factor authentication

WhatEnable two-factor or multi-factor authentication on all accounts that offer it.
WhenImmediately on all important accounts (email, banking, social media).
For whomEveryone.
WhyAdds an extra layer of security beyond passwords, making it much harder for hackers to gain access even if they have your password.
CaveatsNone mentioned.

Tidy includes multi-factor authentication as part of the basic cybersecurity hygiene that, if widely adopted, would make the cyber world safer. He mentions it alongside password managers and software updates as simple but effective measures.

Do do two factor on your or multiffactor.

Keep software up to date

WhatRegularly update all software, including operating systems and applications, to patch known vulnerabilities.
WhenEnable automatic updates where possible, but be aware of the risks of immediate updates for critical systems.
For whomEveryone, but with caution for business-critical systems.
WhyHackers often exploit known vulnerabilities that have patches available. Keeping software updated closes these entry points.
CaveatsThe CrowdStrike incident showed that updates can sometimes cause more harm than good. Tidy advises to generally keep software up to date, but be mindful of the risks.

Tidy explains that despite the CrowdStrike incident, keeping software up to date is still crucial because hackers often exploit old vulnerabilities. He says, 'generally speaking, Crowd Strike aside, keep your software up to date.' He notes that the CrowdStrike problem was an exception where the update itself caused a global outage, affecting millions of computers. He advises that for most people, automatic updates are beneficial, but for critical systems, a delay to test updates might be wise.

Generally speaking, Crowd Strike aside, keep your software up to date.

Also said
“If you look at the list of how hackers are getting in, it's the same old stuff. They're going through something that should have been patched a year ago.”— Explains why updates are important.

Be skeptical of unsolicited requests

WhatVerify the identity of anyone asking for sensitive information or access, especially if they claim to be from IT or a colleague.
WhenWhenever you receive an unexpected email, phone call, or message requesting credentials or actions.
For whomEveryone, especially employees with access to sensitive systems.
WhySocial engineering is the primary way hackers gain initial access. Being skeptical can prevent most attacks.
CaveatsNone mentioned, but it requires constant vigilance.

Tidy explains that most hacks start with social engineering, such as calling the IT help desk and pretending to be a staff member who forgot their password. He says it sounds stupid but it works. He emphasizes that this has been the main attack vector for 20 years and nothing has changed. He also mentions that even sophisticated attacks like Stuxnet used physical social engineering (USB sticks in a parking lot). Therefore, being skeptical and following verification protocols is the best defense.

It sounds so stupid but it works.

Also said
“Nothing in cyber has changed for 20 years. Social engineering, find a person who's prepared to let you into the system, go from there.”— Reinforces the importance of skepticism.

Install security cameras if you feel threatened

WhatInstall a security camera system around your home if you feel intimidated or threatened due to your work.
WhenWhen you perceive a credible threat to your physical safety from cybercriminals.
For whomJournalists, researchers, or anyone who may have angered cybercriminals.
WhyCybercriminals can be dangerous and may retaliate against those who investigate them. Physical security measures can provide peace of mind and protection.
CaveatsThis is a personal decision based on threat assessment.

Tidy shares that after his Moscow trip to investigate the Evil Corp gang, he felt intimidated and installed a security camera system around his house. He also mentions that a cybersecurity researcher named Fabian Wasa fled Germany due to threats from ransomware gangs. This highlights the real-world dangers of investigating cybercrime.

Personal experience

When I got back, I installed a security camera system on around my house cuz I was I just started feeling a little bit intimidated.

When I got back, I installed a security camera system on around my house cuz I was I just started feeling a little bit intimidated.

Also said
“Some of these gangs are very very rich and it wouldn't be much to drop, you know, 20 grand to go and get someone's legs broken or whatever.”— Explains the threat.

What's new

Personal practice updates, fresh positions, predictions

6 items

Noob Persistent Threats (NPTs)

early

Teenage hackers are underestimated as 'noob persistent threats' who can cause massive damage despite low technical skill.

Why this matters: Challenges the perception that only advanced state-sponsored groups are dangerous; these loosely organized teens have crippled major companies.

Background

Traditional cyber threats were seen as advanced persistent threats (APTs) from nation-states. Researcher Allison Nixon coined NPTs to describe the new wave of teenage hackers.

Joe Tidy explains that groups like Scattered Spider are part of a larger collective called 'the Comm,' a community of thousands of online delinquents, mostly young boys, who coordinate on Discord and Telegram. They are not highly organized but are persistent and cause mayhem, including ransomware attacks on companies like M&S and Harrods. They are motivated by clout and money, and they often don't care about getting caught. Tidy notes that despite their amateurish operational security, they have caused significant disruption, and law enforcement has been slow to take them seriously. He cites the example of Lizard Squad, who took down Xbox Live and PlayStation Network on Christmas 2014, and how the same individuals evolved into more serious cybercriminals.

Personal experience

Tidy recounts his first encounter with a teenage hacker from Lizard Squad, who appeared on Sky News without hiding his face or voice, showing a complete lack of remorse.

They're not advanced, but they are persistent and they are a threat and we should take them seriously.

Also said
“Scattered Spider are part of this larger collective known as the Comm, the community, which is a group of thousands of online delinquents, really, largely boys, obviously, it always is.”— Describes the scale and demographic of the Comm.
“Every single step of the way, they've been underestimated.”— Highlights the recurring underestimation of teenage hackers.

Shift from chaotic good to chaotic evil in hacking culture

early-mid

The rise of Twitter and Bitcoin transformed teenage hackers from curious explorers into profit-driven cybercriminals.

Why this matters: Provides a clear historical explanation for the moral decline in hacking communities.

Background

In the early 2000s, hacking was often about exploration and making the internet safer. The emergence of social media clout and cryptocurrency changed motivations.

Tidy argues that two factors drove the shift: Twitter introduced the concept of followers, retweets, and online clout, which attracted hackers seeking fame. Then Bitcoin provided a way to monetize their activities anonymously. He traces the 'conveyor belt' of teenage cybercrime gangs starting with LulzSec in 2011, who loved the attention, to modern groups like Scattered Spider who are after money. He notes that before Twitter, social networks were about being social with your network, but Twitter invented the idea of clout. The combination of fame and money turned what was once 'chaotic good' into 'chaotic evil.'

Personal experience

Tidy observed this shift firsthand as a journalist covering cybercrime over a decade, seeing the same individuals evolve from pranksters to extortionists.

I think Twitter is a very that you could kind of see at that point when Twitter becomes mainstream this shift starting to take place because of course before Twitter social networks were about being social with your network whereas Twitter sort of invented the idea of followers and retweets and likes and you know clout online and that's when we started seeing in 2011 when Twitter was really on the ascendancy we saw Lulc the first of this conveyor belt of teenage cyber crime gangs

Also said
“As soon as you start introducing Bitcoin into the lives of young teenage boys, you're looking at trouble.”— Highlights the role of cryptocurrency in enabling cybercrime.
“Without cryptocurrency, a lot of cyber crime that happens these days would be a lot harder.”— Emphasizes the dependency on crypto.

Social engineering remains the primary attack vector

mid

Most hacks start with simple social engineering, like calling IT help desks, rather than advanced technical exploits.

Why this matters: Demystifies hacking and emphasizes that human error is the weakest link.

Background

Popular culture portrays hacking as sophisticated coding, but in reality, tricking people is the easiest way in.

Tidy explains that the initial entry into systems is usually through social engineering, such as phishing emails or phone calls pretending to be a staff member who forgot their password. He says, 'it sounds so stupid but it works.' Once inside, hackers then use technical methods to spread and deploy ransomware. He also mentions the Stuxnet attack, which used USB sticks dropped in a parking lot to infect Iranian nuclear facilities, proving that even the most sophisticated attacks often rely on low-tech methods. He emphasizes that this has been true for 20 years and nothing has changed.

Nothing in cyber has changed for 20 years. Social engineering, find a person who's prepared to let you into the system, go from there.

Also said
“It sounds so stupid but it works.”— Highlights the simplicity and effectiveness of social engineering.
“A lot of hacking is that to get into a system, it's not really like in the movies where you kind of hunch over a laptop typing code furiously to get in.”— Contrasts media portrayal with reality.

Cryptocurrency as the enabler of modern cybercrime

early-mid

Bitcoin and other cryptocurrencies allow cybercriminals to extort and launder money anonymously, fueling the ransomware epidemic.

Why this matters: Explains why ransomware has become so prevalent and why it's hard to stop.

Background

Before crypto, cybercriminals relied on traceable methods like bank fraud. Crypto provides pseudonymity.

Tidy argues that without cryptocurrency, cybercrime would be much harder. He explains that crypto allows criminals to receive payments directly to wallets without banks being able to stop them. He contrasts this with the early days of hacking, where a teenage hacker he profiles spent stolen money on PlayStation games and land, which was easily traced by police. With crypto, laundering is more difficult but still possible. He also notes that gift cards are another untraceable method used by less sophisticated criminals. The rise of Bitcoin in 2011-2013 coincided with the shift in hacking culture from fun to profit.

Personal experience

Tidy observed the evolution of payment methods in cybercrime cases he covered, from credit card fraud to Bitcoin ransoms.

The great thing about crypto, of course, if you're a cyber criminal, is that I can steal crypto or I can extort crypto from someone and then it goes to my wallet and people don't know who I am.

Also said
“Without cryptocurrency, a lot of cyber crime that happens these days would be a lot harder.”— Reinforces the dependency on crypto.
“As soon as you start introducing Bitcoin into the lives of young teenage boys, you're looking at trouble.”— Links crypto to the moral decline of teenage hackers.

The CrowdStrike incident as a cautionary tale

late

The CrowdStrike update that caused a global IT outage shows that even security software can be a vector for massive disruption.

Why this matters: Highlights the fragility of interconnected systems and the risks of automatic updates.

Background

CrowdStrike is a leading cybersecurity firm. In July 2024, a routine update caused the 'blue screen of death' on millions of computers worldwide.

Tidy recounts how CrowdStrike's update bricked systems, affecting airlines, hospitals, and businesses. He notes the irony that those who followed best practices of keeping software up to date were the ones hit. He says the world 'bounced back' but there are ongoing lawsuits. He uses this to illustrate that while keeping software updated is generally good advice, it's not without risks. He also mentions that the incident shows how dependent we are on a few key software providers.

It completely bricked the system. It caused the blue screen of death on something like I think it was 2 and a half million computers around the world.

Also said
“The people that kept their software up to date, which is what we're being told all the time, they were the ones that got hit.”— Points out the paradox of security advice.

Hackers' poor operational security leads to capture

mid

Despite their technical skills, many hackers get caught due to simple mistakes like forgetting to hide their IP address or accidentally uploading their home directory.

Why this matters: Demystifies the 'mastermind' image of hackers and shows they are often their own worst enemy.

Background

Law enforcement often catches cybercriminals not through advanced tracking but through blunders.

Tidy gives the example of Julius Kivimaki, who accidentally uploaded his entire home directory while trying to extort a psychotherapy company. The police found his IP address and traced him. He also mentions that teenage hackers often don't disguise their voices or faces, and they don't protect themselves well because they don't care about getting caught. He quotes a researcher who says 'everyone thinks that cyber criminals are masterminds when they're carrying out the hacks, but they're not masterminds at covering their tracks.' This leads to their downfall.

Personal experience

Tidy witnessed Kivimaki's lack of operational security firsthand when he interviewed him on Skype without any disguise.

Everyone thinks that cyber criminals are masterminds when they're carrying out the hacks, but they're not masterminds at covering their tracks.

Also said
“These groups, these NPTs are terrible at it because they don't seem to care.”— Explains the psychological aspect.
Disclosed sponsorships1speaker disclosed

Control Alt Chaos: How Teenage Hackers Hijack the Internet

Book Sponsored · disclosed

Tidy discusses the book throughout the interview, which covers the evolution of teenage hacking gangs, the rise of ransomware, and his investigations into specific hackers like Julius Kivimaki and Evil Corp.

DisclosureJoe Tidy is the author of the book.

The book traces the 'conveyor belt' of teenage cybercrime from the early 2010s to the present, focusing on how social media and cryptocurrency transformed hacking culture. It includes firsthand accounts from hackers, law enforcement, and victims. Tidy highlights the story of Julius Kivimaki, the 'most hated hacker in history,' and his journey from Lizard Squad to the Vastaamo psychotherapy hack. The book also covers the Scattered Spider group and the Comm, as well as the Russian cybercrime gang Evil Corp.

Personal experience

Tidy wrote the book based on a decade of reporting on cybercrime for the BBC, including dangerous trips to Moscow and interviews with convicted hackers.

My book is called Control Alt Chaos: How Teenage Hackers Hijack the Internet. Um and it's out on the 3rd or the 5th of June.

Find Control

Notable quotes

Lines worth pulling out — contrarian, specific, or perfectly phrased

6 items
Ransomware completely cripples an organization. It's like going back to medieval times.
Vividly illustrates the devastating impact of ransomware on modern organizations.
The great thing about crypto, of course, if you're a cyber criminal, is that I can steal crypto or I can extort crypto from someone and then it goes to my wallet and people don't know who I am.
Succinctly explains why cryptocurrency is so attractive to cybercriminals.
They're not advanced, but they are persistent and they are a threat and we should take them seriously.
Captures the essence of the 'noob persistent threat' concept and the need to take teenage hackers seriously.
Nothing in cyber has changed for 20 years. Social engineering, find a person who's prepared to let you into the system, go from there.
Highlights the enduring primacy of social engineering in hacking.
If you look at the list of how hackers are getting in, it's the same old stuff.
Reinforces that despite technological advances, basic attack vectors remain unchanged.
The thing about him was he just wanted to sort of see watch the world burn.
Memorably describes the anarchistic motivation of some hackers like Julius Kivimaki.

Sign in to share feedback

Tell us if this brief hit the mark or missed it — feedback feeds back into the next iteration of the prompt.

Topics covered

scattered-spiderteenage-hackersransomwaresocial-engineeringcryptocurrencyvastaamo-hackevil-corpcrowdstrike-incidentcybersecurity-advicejulius-kivimakilizard-squadnptoperational-securityquantum-computingautonomous-vehicles
Free account

Make this library yours

Reading is free for everyone. A free account adds the personal layer: save protocols, follow experts, and see how the other experts weigh in on this same topic.

Create a free accountSign in

Where the experts disagree — weekly

One email a week: the sharpest new disagreements and protocols from the library. No spam, unsubscribe anytime.

Educational summary of the cited expert source — not medical advice. Open the source recording linked above and consult a qualified physician before acting on any protocol.