[Music]
Hello and welcome to technically speaking where scientists and Engineers come together to chat about a common interest share knowledge and satisfy some curiosity I'm Jasmin and today I'm joined by Antonia and Ellie to talk about cyber hacking and cyber security so why are we talking about this uh so I was listening to another podcast about cyber hacking and it gave me idea and I thought you know what this would be a cool thing to talk about with your friends I'll take that I mean I
know nothing about cyber hacking or cyber security really apart from what you see on TV and movies which as we all know probably isn't what actually happens and apart from what I get emailed periodically in the year from work being like update your passwords do better uh use two Factor authentication do better do better get hacked just don't get hacked that's it that's all I've got and have you got anything more well yeah like Jasmine said it'd be a fun thing to
talk to your friends about I think I was at some party or some social event and I met someone who works at a company that hacks other companies on purpose to then tell them you are vulnerable wow okay I see that that's a good idea I guess you've got to know your weaknesses to make them better yeah so so up until that point I only knew what Ellie knew literally nothing yeah exactly yes yeah yeah so cyber hacking is essentially once when a person breaks into a computer system or server uh with
either with the intent of stealing something or for some kind of malicious intent which we can go into later if anyone is interested um but the people who do these types of hacking they're called hackers or cyber hackers in particularly and interestingly um there's the they have different types of cat of different types of hackers uh which are refer to as like a color and then a hat so the kind of hacker that Antonio mentioned where they actually hack other companies that is known as a
white hat hacker or an ethical hacker so their job is essentially to identify weaknesses in a company's like online system uh so it so that they that can then put in measures to make themselves stronger and less vulnerable to cyber attacks CU if uh someone does attack them and hold their website hostage or stealed information it's pretty bad for business is that the goal then is to get like I don't know names and addresses or people's records of what they've purchased online or Bank details like
what they actually are yeah so it's lots of different things it depends on like the individual hacker cuz they're kind of like scammers um they want to like get something for a reason so uh personal information which or just data which they can then sell um if they can get onto a computer and Access Financial records and obviously they're going to rob you I see that yeah I not good these people are I guess criminals I suppose yeah they are essentially criminals because um cyber
hacking is strictly speaking illegal but the white hat hackers uh because they're ethical hackers and they've been given permission to hack onto someone's system um that is not illegal because they've being permission but hacking into someone's computer or system without permission is illegal and is punishable with prison time but only if you get caught yeah only if you get caught which is why hacking is really tricky because a lot of hackers like to remain
anonymous yeah I'm not surprised I mean I guess all criminals want to not be caught don't they say that an obvious statement you said white and black hacking is but then the company that I someone I may have met or not met in case I need to cover up their identity worked for a company that sometimes didn't get permission beforehand it's like they got retrospective permission because they were doing that company a favor by identifying their weaknesses and telling them rather than I don't
know blackmailing them for it where does that fall in to your categorizing your categories that would then be called a gray hacker which is really creative cuz it's a mixture of white and black so they hack but not for the atttention of like stealing but more for just so they can go to company say hey we found these things that you should probably fix and they'll either do it like because ethically they want to they want that company to actually fix our problems or they want money so they'll
be like yeah um I've identified these issues but I won't tell you what they are unless you pay me money that is a bold business strategy isn't it to be like it is hi Company B I'm companying I've hacked you uh your defenses aren't very good pay me lots of money to fix your problems like that I mean I guess they could say no right they've got no I mean they could say no but then they're risking the they're risking quite a bit if what was found is quite severe but then again they could just
have their iners team then go in and figure out what what was found true I wonder how hard it is to know uh like if you get told you have such and such a problem how hard is that to fix unless you're one of these companies hacking other companies ethically I was going to say Anton did your friends give you any insights into like what the job is like of being a hacker not not your friend the guy that you met or didn't meet yeah this person I met they they said sometimes it just involved trying
different things um sometimes it was as simple as getting the website source code or sometimes they guess person hacked because they would have asked for information that might help them figure out where to go from there kind of like manipulating um you know kind of like guessing the what's that word you know when you do online banking and there's a question they ask you it's usually like so if there was a version of that they might be able to work it out sort of inferred that way
but it was not necessarily for that application it was for a different thing yeah there's like quite a few ways that hackers can like hack onto systems there's generally things like malware that's something that can be used um but I'm guessing there are other ways though yeah I'm sure there must be yeah I think we've all like our age have come across malware because in the early days of the internet there were free things that you could get but but when you download it
Along Came something else that you didn't want no it there someone has to make it then they have to convince someone to actually open it and install it on their computer and then boom they got access and that Mal can do whatever it was designed to do I feel like the old classic computer virus is that still a thing does that count as hacking or is that just some bug on the internet yeah but yeah the other one that I'm still surprised is still a big thing is fishing emils
cuz wow yeah that I feel like being told as a kid like don't download that CU you'll get a virus and then it'll wipe all the pictures we've got from our holidays or like just you know silly things like that when you really understand what it was all about oh when they're pretending to be your bank oh that is huge I get so much spam like you've won a prize or you have a connected with a Kenyan prince who wants to give you a million pounds convincing have you had the ones
from say an IT team and they made a fishing email to see if you would click on it and then basically flag you as possibly a weakness yeah that's so clever and you get put on some training wow no I haven't had that now I'm going to be extra on the lookout but that's such a good idea though because then you really see when you know which people are vable or how easily people are convinced by silly things yeah so obviously with like fishing if you you can identify that
it's a fishing email then you can eliminate the threat of being hacked but there are other ways of protecting yourselves online so obviously with malware and like viruses there's antiviral software stuff I remembered another type of fishing that I've seen um where one of the contacts I have in has been hacked or had some somewhere they've managed to get into their email and then they spam files out and they it looks like a link and they said oh here is the document you asked
for and and it will be something I don't know I don't download them but the fact that someone that I might not speak to every day but could reasonably send me emails with files in if I wasn't paying attention boom I just got malware or fished so then masquerading is your colleague essentially yeah well they're people from external to my company as well so it got through our filter I mean sometimes if they can hack onto an account then they then that's a pretty easy way to just like send out
like fishing emails or malware through just basic emailing everyone in their inbox cuz that's happened a few times at my work but yeah so obviously with like fishing emails if you can I obiously identify if it's a dodgy email and the dodgy link then that's one way of protecting you and with like malware and stuff there antiviral softwares that will will hopefully uh protect you from having to deal with viruses and malware but there are some other ways of protecting theiles online uh stuff like
encryption and two Factor authentication like they're supposed to be pretty effective they are but they I find them a pain in the ass I'm going to be honest I'm sure many it professionals are rolling their eyes now but I just think I can't be bothered with two Factor authentication it's me it's always me no one else but also I do think that there's not much apart from like Bank details or like actual money there's not much that people don't already know like
Google must know so much data on me like there's not much worth stealing like if I was a cyber hacker I wouldn't be targeting us I'd be going you know NASA or NATO or MI6 or something instead not that I would be a sideb hacker obviously or succeed I suppose that's was where Jasmine was saying how if you can get someone in a your address book it could be convincing enough because that's happened to someone in my family where someone else they knew whatsapped them and said hi I need your
help and then from there she got scammed out of some money so it it might not be the initial information that they want out of you but then they've kind of gained a trusted account maybe yeah I suppose they've used it as like a stepping stone haven't they to like spread more like a Cascade effect of like okay we've had this one person now we have access to all their address book or all their WhatsApp we can then you know keep going and then there just snowballing yeah that's also happened a
few times um with like Twitter accounts or with like Instagram accounts so I think it was in 2020 or maybe um earlier than that but uh um oh yes in July 2020 uh hackers took over more than 130 high-profile Twitter accounts like Barack Obama Joe Biden Jeff Bezos Elon Musk uh as well as like companies um basically they used these Twitter accounts to promote a Bitcoin scan oh my God yep wow that's pretty impressive to do like a targeted you know like hit all these
people 100 people or whatever and then really I could also imagine how effective that is because of the kind you know websites websites pop up all the time and it can be quite hard to trace back well I was going to say I wonder how many people fell for it like if they're you know following Elon Musk on Twitter and he tweets do this Bitcoin thing are people getting sucked into that yeah I feel like it would depend on the person but I think if like Barack Obama was trying to push Bitcoin I think
people be like this is weird yeah but some other people were like n could be legit yeah it's true isn't it I def definitely depends on your like perception of that person and what they normally tweet and whether it like follows on how much money did this person scam out of people or this organization I am not sure but I can look it up cuz people spend a lot of money on cryptocurrency now is it still going so it says that no I think it ended but apparently um it got $110,000 in
transactions that's not that much so it's not that much but still people lost $110,000 yeah it's true to a Bitcoin scam I'm just just found a BBC News article they were 17 years old at the time it's always 17y olds this is what I see in the media about hackers is that it's always teenagers that are like I'm going to hack whatever system or whatever company and they're the ones that do it and I did I wasn't hacking anyone at 17 so how have they got how have they got this
far there was I'm sure the like was that transport for London or tfl or something like that was hacked by 17 year old a few years this year or something sure I was reading that yes a 17-year-old boy was arrested with a cyber security incident and it was yeah transport for Lon and it was 5,000 customers sort codes and bank accounts names emails and home addresses so that's pretty extreme this Experian report that I found doing a forecast to 2025 said that the average age of someone
arrested for cyber crime is 19 years old compared to 37 for any other crime that's so young is it because we are now well not even us but I guess gen Z or whatever's after gen Z are the online generation and they're just better equipped to get into the main frame of the internet I don't know yeah it could be especially if yes especially if it's the like people our generation who are responsible with trying to keep everything online sa yeah I suppose so that's true isn't it
because we were growing up with the rise of the internet but people older than us didn't have it they remember before the internet existed whereas kids people born even in 2024 will have always had the internet and smartphones and all this technology so maybe it's nature if you know how it works from day one that you can manipulate it to how you how you like but I mean obviously people get caught and it's a crime so don't do that yeah that is true but like do you guys think that in
terms of like cyber crime I know that you guys say that you're like very like low priority in terms of targeting but do you feel like you know enough on how to protect yourselves online or do you think you could potentially get scammed or have your private information store that's a good question I think for things like fishing emails and scam emails I'm pretty Savvy I wouldn't click on links and things like that but I think if the company was targeted like you know big scale or
sometimes you see those reports where it's like universities get targeted and alumni data is stolen what do you then do in that situation that's what I would have no clue on it's like oh you get an email from I went to reading saying we've had a security breach data's been stolen what do you do next can you do anything yeah it's really tricky because there's not really much you can do because once the data's stolen it's been stolen Antonio remember when University
of Manchester got hacked I don't actually because I get so many emails about we've had this data breach our servers got hacked it it washes over me at this point well University of Manchester got hacked and they stole a bunch of data and um yeah but for alumni they only stole our like addresses apparently they did not steal any financial information that's what that's what they clarified in the email there was no financial information stolen on alumni yeah but they um most definitely
got our addresses just that contact details should we be worried that cber hackers have our addresses like they're not going to show up at our doors are they they're just going to sell our information to like marketing agencies I don't know what they do with it yeah I think most of it just gets bought and then you get spammed but the thing is that you can then get targeted by people who like scam fire other means right so like the Nigerian prince I heard they caught the person
behind the Nigerian prince the OG Nigerian prin surely there's more than okay maybe at least one of the people who was behind that email um chain letters remember chain letters yes oh my goodness and like if you broke it it would be like 7 years bad luck or some rubbish well weren't they also a form of scam sometimes yeah I think they probably were because in the early early internet days the thing they started is like oh a nice thing let's spread this message mess to as
many people as possible and then obviously like all good things it got you know made worse and then it was a good way of getting I guess addresses and email addresses out of people so maybe yeah maybe that was a part of an original scam I wonder what the first one was do we know like the first ever Cyber attack I think I heard about this I think it was a Le like it you know what actually I think it was in my data protection training from work okay and they said the first scam or hack yeah
hack they called it was actually a letter scam wow it kind of performed the same way as what we consider cyber crime these days oh it was the worm yeah the Morris worm do you know about this I do not know so the basic Al before the internet was the internet there was a thing called arpet it's probably got a better name that and then um I think it was like a University graduate student or someone like that they like put a worm on these computers that had the early internet
version and then it like caused a lot of damage and the guy got like fined and like rejected from University and stuff but it was like it was a legit thing is like famous the Morris worm um for being like a malicious internet program that affected people I don't know what it did I don't know if it just shut down the computers or if it was delete data yeah that was what a lot of early um viruses did they corrupted data oh apparently it didn't destroy files but it's slowed down the network
massively so like you couldn't send emails it was like a complete problem to use than those computers uh apparently the damages started estimates of $100,000 and then soord into millions given the like severity of the attack wow there we go the mors one did they ever catch the guy who created oh wait Antony said it was a university student Ellie said that yes they did University student they catch him and find him and sent him to prison I think yeah Okay cool so obviously like we feel
like our we ourselves in terms of protecting our own data we feel pretty okay cuz we know what a fishing email looks like we've done data protection courses but in terms of what companies who have are sensitive and very very valuable information uh are doing in terms of protecting our data um do we what what what do we think on that so Antonio you mentioned the guy that you met who works for hacking of a companies uh but what else can companies do to protect themselves so that the
information that they have on other people just doesn't get stolen so uh one of the most common data breaches according to a cyber security survey by the UK government said it's mostly through fishing I stop clicking on those dodgy email links I feel like we can do better surely there must be more than just fishing what happened to like the movies where they're like desperately typing code into computers as they hack into you know desperately trying to guess your passwords yeah so 84% of
businesses um experiened a fishing attack that's so high but is that really M I guess it's a lot more low effort than actively hacking I just remember you know like Mission Impossible or like one of the Spy films where they've got a team in a van and they're hacking the building so that they can open the doors the like security doors so like James Bond can run through and like not set off the alarms are people doing that is that a real thing or do I need to speak to
someone at MI5 to find out I think it is something that you can do because there was a hack where someone was hacking ATMs and making them just dispense that is a great hack I mean go straight to the source surely if you want cash out of it then you don't have to Fu around selling people's data just hack the ATM solid but there's a lot of security around an ATM just straight up there's a camera so if they start noticing this person going to every single ATM do you
have to physically do it who's watching it can your remote log on to an ATM um I think they did in the I can't remember exactly what happened but it was like a really interesting and old one that's so impressive I wonder how you get into cyber hacking do you have to just be really good at it things and have no moral compass I'm going to Google generally most cyber hackers have really good Computing skills so the ATM hacking I'm not turning to a Life Of Crime Guys Don't Panic this is a purely
educational guess oh apparently you can use a Mal okay so there's like n you can get if you get get into the bank's Network then you can manipulate the ANTM software to steal Cash There's also malware attacks if you can affect the software that's on the ATM there also just like using a ATM card reader as well as something that's called jackpotting which is using malware to make a um which is basically a type of malware that just interferes with the software
to make the um ATM dispens lots of money jackpotting is the one that I think is associated with the um pictures or images of just ATM just like spewing out cash I love this image I think yeah I that's the thing it's so much of stuff now is on the internet right like my washing machine could be connected to the internet but I refuse but like if you can hack an ATM what 20 years ago now presumably you can hack anything connected to the internet right like I someone could breach my network and hack
my washing machine if they felt like it yeah they could or they can just like steal your Wi-Fi because that's just annoying would they oh they could lock me out couldn't they that would be annoying that would be they could also do that yeah also just stealing your Wi-Fi isn't this just an issue as well with internet of things if people don't put proper Internet Security into those items or Bluetooth security I guess what's bluetooth security I don't know if if
you can make Bluetooth secure hopefully you can can other people hack your headphones then if that's what you're saying like why stuff now because do you reckon that's possible oh here's another flash that's just made me have a flashback to people saying that there were Bluetooth scams as well where people would try and send you a file which would interrupt your phone ah yeah that's true do you have to accept those I don't have an Apple phone yeah I've had I've had the I've
had someone trying to airdrop me something I'm like no I don't know who you are imagine if you were just doing something else at the same time and you just accidentally click it yeah you have the option or you get notified send you something and then you can either accept or reject right fine okay oh I accidentally accepted a scam phone call because it was on my watch and I couldn't cuz I have my phone in my pocket so it was on my watch and I thought it was my watch just like cuz I
have a smartwatch I thought it was my watch doing that thing where it just like automatically wants to connect the heart rate monitor with my iPhone which it weird thing that it does so I was like trying to like get it to stop and then I accidentally clicked accept the call I was like No And I was like no scam calls at least are pretty easy to immediately tell that you can be like you can just hang up right they have your number but it's not the yeah but then what if they've
already stolen your information but at that stage that you realize you've been scammed I feel like it's just feeding into another right these you're being fished or hacked in the first place to see all your information and then they're just selling it to more companies that then want the same information it's very strange we don't understand the criminal on the belly very well I guess not yeah which maybe is because we're not n cuz we're not 19y olds me to ask 19-year-olds what's the
appealing about ha money surely it must be money I understand if you're getting money like that does make if that's the main motivator then that makes sense wonder is there any figures on how much hackers make per year well I suppose if [Laughter] you're I was just thinking well I don't think people make an annual income they probably have one good payout right well it depends what you want like are you are people trying to hack into like government things for State Secrets or
like to find out yeah people have done that so in 2016 when it was the presidential uh election and campaign um Hillary Clinton's AIDS um hackers targeted her AIDS through fishing attacks which led to the leaks of thousands of her emails okay this is interesting I'm sure most people remember because that was one of the reasons why people hate Hill Hillary Clinton so this is like we haven't considered this as an option of like a personal attack or like a smear campaign
or like a yeah a politically motivated you know if you want someone to succeed and someone not to you could hack the opponent and then release these emails and make them look bad or similar yeah oo that seems more malicious than just criminals trying to get money yeah some of the um so like there's some like really malicious attacks that can happen I think they are technically called Red Hat hackers cuz they're just evil and it's more like personal I suppose yeah it's more like crimey
stuff so like that the kind of people like Target companies or individuals with the intent of like um stealing a lot of money or just doing a lot of damage so yeah they're pretty bad I suppose it's also slightly blackmail as well then because you could say I've hacked into your emails I've got all this dirt or things you don't want the public to know or if you're a public figure and then pay me lots of money otherwise I'll just release it yeah there is one case on that I don't think
they were a famous person but it's kind of how remember do you guys remember the a Madison what um dating service SL uh dating uh online dating thing I think I heard about the hack rather than the actual website so a guy was um had his guy had his um information stolen and they were trying to hackr and blackmail him by saying we know that you're having an affair and we won't release it unless you uh pay us this Ransom money wow that that was the whole conceit of the website wasn't it
actually it was for extra marital Affair oh I see so so once you got anyone's information you can just blackmail everyone using that website oh apparently there's going to be a Netflix documentary about it I think that's where I heard about it but isn't that the but isn't going back to Hillary Clint Clinton's data hack or email isn't that the ultimate bad data breach is on a national or International scale that could literally affect politics yeah exactly yeah what are they doing then what are
like Hillary Clinton's team doing to protect her data from that happening again now identifying fishing emails it was fishing emails it all comes back to the fishing emails everything goes back to fishing email oh my gosh so should we Define what a fishing email is then for for anyone listening in case they don't know what it is yeah we probably should what what it's just an email with a dodgy link in right that has passed off to look legit people got taken in they click the
link bad things happen yep uh that that's what I understand the fishing email to be Antonia do you also agree fishing email um I think not only you it has a link or file and it somehow Le steals your data or leaves you with something that can then steal your data like some software right so it's like passed off to look quite good you're taken in click the link either then you download malware that steals your data or whatever's in the link you input it in and you give it away without realizing
yeah like a good fake website that's pretended to be your bank account or pretending to be a government website that kind of thing so everyone be extra vigilant checking their emails this week and forever this is what I've learned from this podcast that this seems to be the main way that we' like spoke about it multiple times that even if it's just someone trying to hack your Instagram or a big multinational organization this is sort of their in right yeah appears so fishing emails are
what will get you and it's not the people like driving around in Vans trying to hack into a building so they can like steal all the company I'm quite disappointed to be honest I was really picturing like you know people hacking in and turning off the lasers as James Bond parachutes in from the ceiling and the doors not being able to open but the GU is like really frantically typing and then just at the last second it goes green on the access panel you can kind
of do that so there was a bug with um sorry that is a bug on my laptop it'll go screen is it a fishing bug be might be a fishing bug yeah make sure you take your time before clicking on things uh I think it was a bug with ring uh the ring doorbells where people could use it to then hop on hop onto your Wi-Fi and then they could just like disable stuff and like I'll just do stuff with your Wi-Fi could it unlock any device that was connected if you had a if you had a electromagnetic door
lock you could just open the door then yeah for sure you it could if you've had that kind of door wow yeah also protect your Wi-Fi yeah oh my goodness going to change the password right now make sure you have a secure network and always be wary when you're on like free Wi-Fi networks cuz um someone could hop on your phone well there we go so like so we talked about like how there's hackers who will hack for malicious intent with like stealing data or private information or stuff that
could could ruin political careers but there are also like actual vigilante hackers so these are like hackers who want to do like good so an example would be there was this guy who was known as the most hated man on the internet called um what was his name it's not Julian Assange is it no his name was Hunter Mo he had like he was like notorious for revenge porn and yeah so he got um hacked by a group of activist is what they call themselves oh like hack hacking
activists yeah so he got attacked by activist group called Anonymous who basically um because they hated him because he was like a terrible person so they did stuff like basically like empty out all his bank accounts like delete a lot of his personal records incredible y yes oh okay so they were like being the Vigilantes I'm with you now they're like batmanning him yeah they were and there was another one so in like there was a group of uh activists who managed to hack onto some
cameras that managed to capture images of a Russian um attempted attack to get into Ukraine so that was another one oh so they would on the side of Ukraine to be like be like hey you got something here of yeah defend defend yourselves I I see yeah so not all hackers are bad people some people some 19 year olds who are really good at like hacking decide you know what I'm not going to try to steal money from people I'm actually going to like help people put my ha for good gonna hack for
good that's a nice note to end on yeah I mean like if you could if you're really good at hacking what would you hack what would I hack oh this is I don't think I wouldn't go criminal cuz I just would get caught I wouldn't be that good a hacker maybe I would hack for good maybe I'd I don't know how I would hack for good but I'd think of something or trying to think if there's any companies I don't like that I would be happy to steal from but maybe I shouldn't admit that on on a public
forum yeah I think anything we say could be incriminating could be very incriminating I definitely lack the uh computer know how to be able to do that so I don't think anyone's in any danger that I'm going to hack them no but you can definitely spot a fishing email remember that's the one that counts the most maybe I'll make some sort of anti- fishing email software in my hacker ability I I'll hack the hackers there we go o maybe imperson hack them maybe they
have don't expect anyone to hack them in person I guess not it's all online are they in Vans are they in basement where are they are they just normal people it's just Ellie just knocking on their van do you want to buy my Scout that's also a classic from TV isn't it girl got cookies are you telling me that's that's not a scam now though is it no I think it was a cover that people would used oh I see right I'm with in the movies wow I'm really gullible okay I need to be extra vigilant that's what
I've learned be extra vigilant don't click any links you're wary of fishing emails are clearly the devil's work and use second two Factor authentication I'll never complain about it again I you know I mean I will but at least I know what it's it's good for yeah cool so we've gone over what cyber hacking is to different types of hackers good and bad um so cyber hacking is the act of breaking into a network or comp computer system to steal data modify data or even something more malicious
and these are carried out by people known as hackers we've also gone over some of the things that you can do to protect your sales online like as Antonio mentioned two Factor funication very important but also important is encryption uh but do we feel like we can protect ourselves like I feel like I do enough to protect myself personally but for like companies a whole another story but I like to think that they're getting better uh but most importantly like if
you yourself are concerned about staying safe online especially from like hackers uh definitely take any data protection Clauses and you can do the stuff that we said we're going to do well and you can also just look at more ways to protect yourself online so thanks for listening and we'll see you in the next episode The Views expressed in this podcast belong entirity to the person that said them they do not represent any industry or organization if you enjoyed listening to these views
it would really help us out if you could rate US leave a review and tell a friend this podcast was sponsored by no one but if you're interested in funding us to continue to have Frank discussions about science and engineering please get in touch
