EPISODE · Aug 3, 2026 · 45 MIN
Extortion WITHOUT Encryption: Why Hackers Skipped Ransomware
from DTF Cyber Podcast
What happens when cybercriminals don't even bother encrypting your files, but still demand $5 million? In Episode 49 of DTF Cyber, Damian, Troy, and Fern sit down with former 3x Financial CISO Brian Rosario to break down a terrifying shift in the threat landscape: Extortion Without Encryption. We analyze recent breach news (like Abbott Laboratories) to reveal how bad actors quietly exfiltrate crown jewel data, bypass traditional backup recovery options, and hold reputational/SEC clocks over your head. Plus, we dive into the risks of "Vibe Coding" with AI, unmonitored OAuth tokens, and how to build a security culture without ego.----------------------------------------------------------------📌 TIMESTAMPS:00:00 - Cold Open: $5M Ransom, Zero Encrypted Files00:49 - Guest Intro: 20-Year CISO Veteran Brian Rosario01:50 - Abbott Labs Incident: The Shift Away From Encryption03:55 - Why Bad Actors Pre-2020 Pivot To Pure Data Exfiltration06:32 - Why Cloud Snapshots & Backups Aren't Stopping Extortion08:28 - Supply Chain Threats: Codebases & Hardcoded Secrets10:30 - The SolarWinds & NotPetya Effect11:47 - Email Protection & Siphoning CEO Mailboxes via OAuth14:35 - "Vibe Coding" & Unmonitored Citizen Developers18:30 - The Explosive Rise of AI Governance Platforms20:26 - "Is It Better To Not Know?" The CISO Visibility Dilemma23:27 - Getting Ego Out of Security Leadership28:20 - Analyzing the Kill Chain: Vishing, Smishing & DefCon Lessons36:06 - SEC Disclosures & Data Layer Visibility42:30 - Data at Rest Encryption: Is AI The Solution?
Embed this episode
Ready to play
Extortion WITHOUT Encryption: Why Hackers Skipped Ransomware
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.