
← DTF Cyber Podcast3 Aug · 46 min
Extortion WITHOUT Encryption: Why Hackers Skipped Ransomware
What happens when cybercriminals don't even bother encrypting your files, but still demand $5 million?
In Episode 49 of DTF Cyber, Damian, Troy, and Fern sit down with former 3x Financial CISO Brian Rosario to break down a terrifying shift in the threat landscape: Extortion Without Encryption. We analyze recent breach news (like Abbott Laboratories) to reveal how bad actors quietly exfiltrate crown jewel data, bypass traditional backup recovery options, and hold reputational/SEC clocks over your head. Plus, we dive into the risks of "Vibe Coding" with AI, unmonitored OAuth tokens, and how to build a security culture without ego.
----------------------------------------------------------------
📌 TIMESTAMPS:
00:00 - Cold Open: $5M Ransom, Zero Encrypted Files
00:49 - Guest Intro: 20-Year CISO Veteran Brian Rosario
01:50 - Abbott Labs Incident: The Shift Away From Encryption
03:55 - Why Bad Actors Pre-2020 Pivot To Pure Data Exfiltration
06:32 - Why Cloud Snapshots & Backups Aren't Stopping Extortion
08:28 - Supply Chain Threats: Codebases & Hardcoded Secrets
10:30 - The SolarWinds & NotPetya Effect
11:47 - Email Protection & Siphoning CEO Mailboxes via OAuth