How Hackers Changed the Media (and the Media Changed Hackers)
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
This Black Hat USA talk delves into the profound, evolving, and often contentious relationship between cybercriminals and the mainstream media. Featuring a panel of seasoned journalists and a leading incident response attorney, the discussion illuminates how the landscape of cybercrime, particularly cyber extortion and ransomware, has fundamentally altered how attackers operate and interact with the public. No longer content with stealthy data exfiltration, modern threat actors actively seek and manipulate media attention to amplify their demands, pressure victims, and even build "brand equity" for their illicit operations.

Key moments
- 0:00 Panelist introductions and their roles in cybersecurity
- 2:40 How cyber extortionists changed tactics to use media
- 3:18 Journalists' ethical dilemma: reporting vs. empowering criminals
- 3:40 Ransomware groups' 'brand equity' and media manipulation
- 4:55 Journalists' process: distinguishing threat actors, state-sponsored vs. criminal
- 6:00 Incident response: dealing with attacker threats to publish data
How Hackers Changed the Media (and the Media Changed Hackers)
Speakers: Bob McMillan, Reporter, Wall Street Journal; Lorenzo Franceschi-Bicchierai, Reporter, TechCrunch; Sadia Mirza, Partner, Troutman Pepper
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=a5O4OrYhqWo
Overview
This Black Hat USA talk delves into the profound, evolving, and often contentious relationship between cybercriminals and the mainstream media. Featuring a panel of seasoned journalists and a leading incident response attorney, the discussion illuminates how the landscape of cybercrime, particularly cyber extortion and ransomware, has fundamentally altered how attackers operate and interact with the public. No longer content with stealthy data exfiltration, modern threat actors actively seek and manipulate media attention to amplify their demands, pressure victims, and even build "brand equity" for their illicit operations.
The panel explores the intricate ethical dilemmas faced by journalists who must balance the public's right to know about significant breaches with the risk of empowering or legitimizing criminal entities. Simultaneously, incident response professionals grapple with the communication challenges posed by attackers who threaten to go public, forcing organizations into difficult decisions regarding transparency and engagement. This talk is crucial for anyone in cybersecurity, journalism, or corporate communications seeking to understand the dynamic interplay between these fields in the face of increasingly aggressive and media-savvy adversaries.
The session highlights a significant paradigm shift: while hackers have historically enjoyed some level of media attention, the professionalization of ransomware gangs has transformed this into a deliberate, strategic tactic. This shift forces a re-evaluation of incident response protocols, journalistic ethics, and public relations strategies, underscoring the critical need for integrated approaches to mitigate both technical and reputational damage during a cyber incident.
Background
▶ Watch: Panelist introductions and their roles in cybersecurity (0:00)
Historically, cybercriminals operated with a primary objective of stealth and anonymity. Their methods typically involved covertly infiltrating networks, exfiltrating sensitive data such as credit card numbers or intellectual property, and selling it on underground forums without drawing public attention to the victim organization. The goal was to remain undetected for as long as possible, maximizing their illicit gains before discovery. This era saw breaches often revealed by external parties or through forensic investigations, rather than by the attackers themselves.
However, a significant shift began to emerge approximately five years prior to this Black Hat discussion, coinciding with the rise of widespread ransomware and cyber extortion campaigns. This new wave of criminal activity introduced a powerful and often devastating tactic: weaponizing public perception and reputation. Instead of merely encrypting data and demanding a ransom, threat actors began to threaten victims with the public exposure of stolen sensitive information – a practice often referred to as double extortion. The media became a crucial, albeit unwilling, instrument in this new extortion model.
As Bob McMillan from the Wall Street Journal observed, this evolution saw criminal actors develop "brands" that required brand equity. For a ransomware attack demanding millions of dollars, a known and "reputable" (within the criminal underworld) group might be more likely to receive payment. This brand building often necessitated public visibility and a track record of carrying out threats. Lorenzo Franceschi-Bicchierai of TechCrunch further elaborated on this, noting that even state-sponsored actors, such as the Guccifer 2 hacker (later identified as two GRU agents) involved in the DNC hack, demonstrated a willingness to engage with the media to shape narratives and achieve strategic objectives.
Sadia Mirza, an incident response attorney, reinforced that the threat of media publication is now a common component of extortion demands her clients receive. Cybercriminals explicitly state that if a ransom is not paid, they will release data to the media, often naming specific outlets. This transformation from stealthy operators to public manipulators has created unprecedented challenges for victim organizations and ethical dilemmas for the press, fundamentally changing the dynamics of cyber incident response and reporting.
Key Findings
▶ Watch: Journalists' ethical dilemma: reporting vs. empowering criminals (3:18)
The panel discussion unveiled several key findings regarding the evolving interplay between hackers and the media, highlighting the strategic shifts in cybercriminal operations and their ripple effects across journalism and incident response.
Firstly, a primary finding is the deliberate and calculated use of media by cybercriminals as a pressure tactic. No longer merely an accidental consequence, media attention is actively sought and leveraged by groups like the Black Matter ransomware gang. Examples from the dark web, presented during the talk, explicitly show these groups inviting journalists to register on their platforms and threatening to "inform all the biggest mass media" if ransoms are not paid. This demonstrates a sophisticated understanding of public relations and reputation management, albeit for illicit ends. Criminals aim to "name and shame" their victims, creating additional pressure beyond data encryption or exfiltration.
Secondly, the talk exposed the ethical tightrope journalists walk when reporting on cyber incidents. Reporters like Bob McMillan and Lorenzo Franceschi-Bicchierai frequently interact with hackers, sometimes on "a dozen different chat messaging apps," to verify claims and gather information. The inherent challenge lies in balancing the "incredibly important public need for information" – especially concerning breaches affecting hospitals, schools, or major companies – with the imperative "not to empower the criminals." Journalists must discern truth from manipulation, recognizing that hackers often seek publicity to gain credibility or pressure victims further. The DNC hack and the Guccifer 2 persona serve as a critical historical example of how state-backed actors also use media engagement for strategic purposes.
Thirdly, the discussion highlighted the complex communication dilemmas faced by victim organizations. Sadia Mirza, representing organizations during breaches, noted that companies often receive direct threats from attackers to publish data to the media. This forces difficult decisions on how to respond publicly. While some companies attempt to "put their head in the sand" or downplay incidents, the panel generally agreed this is a detrimental approach. The Uber breach, where the company initially attempted to frame a clear data breach as a "security disclosure," was cited as a "canonical example" of how a lack of transparency can lead to negative consequences and significant public backlash, including regulatory penalties. The consensus was that in major incidents, proactive and honest communication, even when challenging, is often the more responsible and ultimately less damaging path.
Finally, the panel emphasized the public interest aspect of cyberattacks. When critical infrastructure, healthcare providers, or educational institutions are compromised, there is a clear societal need for information. Journalists feel a responsibility to report on these incidents, even if the initial leads come from the attackers themselves. This public interest often creates an "insatiable thirst for more information," meaning that stories will evolve, and follow-ups will be demanded. Companies that refuse to engage risk having incomplete, inaccurate, or one-sided narratives emerge, potentially damaging their reputation more severely than a transparent disclosure.
Technical Deep Dive
▶ Watch: Ransomware groups' 'brand equity' and media manipulation (3:40)
While this Black Hat talk did not delve into specific exploit techniques, vulnerabilities, or reverse engineering of malware, it provided a crucial "technical deep dive" into the operational methodologies of modern cyber extortionists, particularly their sophisticated use of media and communication channels as an integral part of their attack chain. The "technical" aspect here refers to the adversaries' strategic application of communication technology and platforms to achieve their financial and reputational goals.
A core element of this operational shift is the use of dark web platforms as a primary interface for publicizing attacks and interacting with external parties. The panel specifically highlighted the Black Matter ransomware gang as an exemplar. Screenshots from their dark web portal demonstrated a structured, almost business-like approach to their illicit activities. These platforms are not merely data dumps; they are designed as communication hubs. Black Matter's site, for instance, explicitly featured an invitation for "journalists and recovery companies for registration on our platform to register, click contact us." This indicates a deliberate effort to establish communication channels with external stakeholders, including those who might report on their activities or facilitate ransom payments.
Furthermore, these dark web portals serve as the staging ground for their double extortion tactics. After exfiltrating sensitive data from a victim, the data is often listed on these sites with explicit threats. The Black Matter example explicitly stated: "If you do not pay, we will publish that data and inform all the biggest mass media." In some cases, they even "name the media outlets that they're attempting to contact," showcasing a targeted and informed approach to media manipulation. This mechanism transforms data exposure from a passive threat into an active, public relations-driven weapon.
From the journalists' perspective, the "technical" interaction with these groups often occurs over various chat messaging apps. Lorenzo Franceschi-Bicchierai mentioned communicating with hackers on "what feels like a dozen different chat messaging apps." While the specific apps were not named, this points to the use of encrypted, ephemeral, or privacy-focused communication platforms favored by threat actors to maintain anonymity and evade detection. Journalists must navigate these platforms, often in real-time, to verify claims, establish the veracity of data leaks, and understand the attackers' motivations without inadvertently compromising their sources or empowering the criminals. This interaction requires a unique blend of journalistic rigor and technical literacy to operate safely and effectively within these digital spaces.
In essence, the "technical deep dive" of this talk reveals how cybercriminals have integrated advanced communication strategies and dark web infrastructure into their attack methodologies. They have engineered a system where media engagement is not an afterthought but a calculated, critical component for maximizing extortion leverage and building a formidable, albeit illicit, "brand." This operational sophistication demands an equally sophisticated response from victim organizations and a discerning approach from the media.
Demo / Proof of Concept
▶ Watch: Journalists' process: distinguishing threat actors, state-sponsored vs. criminal (4:55)
While the talk did not feature a live technical demonstration of hacking tools or exploits, it provided compelling visual evidence of how cybercriminals integrate media manipulation into their operations. This "proof of concept" was presented through screenshots from the dark web, specifically showcasing the operational tactics of the Black Matter ransomware gang.
The screenshots served as a direct demonstration of the threat actors' proactive engagement with the media and their explicit use of public exposure as an extortion tool. One screenshot displayed a message from Black Matter inviting "journalists and recovery companies for registration on our platform to register, click contact us." This clearly illustrates the gang's intent to establish direct communication channels with journalists, not merely as a passive threat, but as an active outreach strategy.
A second, equally impactful screenshot demonstrated Black Matter's explicit extortion message to a victim: "If you do not pay, we will publish that data and inform all the biggest mass media." The panel further emphasized that in some instances, these gangs even "name the media outlets that they're attempting to contact," showcasing a targeted and calculated approach to public shaming.
These visuals effectively demonstrated the shift from stealthy data theft to aggressive, media-centric extortion. They provided concrete evidence of how ransomware groups leverage their dark web presence to:
- Solicit media attention: By inviting journalists to their platforms.
- Publicly threaten victims: By announcing their intention to release stolen data and inform major news organizations.
- Build a reputation: By demonstrating their willingness to follow through on threats, thereby enhancing their "brand equity" within the criminal ecosystem.
This "demo" was crucial in illustrating the core premise of the talk: that modern cybercriminals have integrated media manipulation as a fundamental and explicit component of their attack methodology, moving beyond purely technical exploits to weaponize public perception.
Defensive Implications
▶ Watch: Incident response: dealing with attacker threats to publish data (6:00)
The insights from this panel discussion carry significant defensive implications for organizations, incident response teams, and even the media itself. The shift in cybercriminal tactics demands a re-evaluation of traditional cybersecurity and communication strategies.
For Organizations and Incident Response Teams:
- Proactive Communication Strategy is Paramount: The era of "putting your head in the sand" and hoping a breach blows over is largely obsolete, especially for significant incidents. Organizations must develop and practice a robust, pre-approved communication plan that anticipates potential media involvement. This plan should outline who speaks, what information can be shared, and when.
- Engage, Don't Evade, the Press (Strategically): While engaging with the media during a crisis is stressful, outright refusal can be more damaging. As Bob McMillan noted, if a story is "a gushing flow of water running downstream," it will be reported regardless. Companies that refuse to engage risk having inaccurate, incomplete, or one-sided narratives published. Providing accurate, confirmed information, even if limited, can help shape the story more favorably.
- Transparency Builds Trust (and Mitigates Damage): The Uber breach serves as a stark warning. Attempts to downplay a clear breach as a "security disclosure" ultimately led to severe reputational damage and legal consequences. Being transparent about the challenges faced during an incident response, the data involved, and the steps taken to remediate can build public trust and potentially mitigate long-term damage.
- Legal and PR Counsel Integration: Sadia Mirza's role highlights the critical need to integrate legal counsel and public relations experts into the incident response team from the outset. Legal teams can advise on disclosure obligations and potential liabilities, while PR professionals can craft appropriate messaging, manage media inquiries, and counter misinformation. Third-party negotiation firms are also essential when dealing with direct ransom demands and communication with threat actors.
- Prepare for Double Extortion: Organizations must assume that if they are targeted by ransomware, data exfiltration for public release is a likely companion threat. This means prioritizing data loss prevention, robust backups, and rapid detection of data egress, in addition to encryption prevention.
- Document Everything: As Sadia Mirza stressed, documenting "your challenges that you face in an incident response and documenting, okay, why is it so hard to figure out the numbers" is crucial. This documentation supports internal learning, external audits, and potential legal defenses.
For Journalists and the Media:
- Vigilant Verification: Journalists must maintain extreme vigilance in verifying claims made by hackers. While hackers may provide leads, their ultimate goal is manipulation. Independent confirmation from multiple sources, forensic evidence, and official statements is critical before publishing.
- Ethical Considerations in Reporting: The panel underscored the ongoing ethical dilemma of reporting on criminal activity without inadvertently empowering or legitimizing the perpetrators. Journalists must consciously evaluate how their reporting might contribute to the "brand equity" of ransomware groups and strive to focus on the public interest and victim impact rather than glorifying criminal acts.
- Understanding Adversary Tactics: A deeper understanding of how cybercriminals use media as a weapon (e.g., inviting journalists to dark web platforms, explicitly naming media outlets in threats) allows journalists to approach such communications with appropriate skepticism and context.
In summary, the defensive posture against modern cyber extortion must extend beyond technical safeguards to encompass sophisticated communication strategies, legal preparedness, and a clear understanding of the adversary's intent to weaponize public perception. Ignoring the media aspect of a breach is no longer a viable option.
Key Takeaways
- Cyber extortion has evolved into a media-driven tactic: Modern ransomware groups leverage public exposure and shaming as a primary mechanism to pressure victims into paying ransoms, moving beyond mere data encryption.
- Criminals actively seek media attention for "brand equity": Groups like Black Matter invite journalists to their dark web platforms and explicitly threaten to "inform all the biggest mass media" if demands are not met, using publicity to establish credibility within the criminal ecosystem.
- Journalists face profound ethical dilemmas: Reporters must balance the public's right to know about significant breaches (e.g., hospitals, schools) with the ethical imperative not to empower or legitimize cybercriminals, requiring rigorous verification of hacker claims.
- Organizations must adopt proactive communication strategies: Attempting to "put your head in the sand" or downplay incidents (as exemplified by Uber's approach to its breach) can lead to greater reputational and legal damage; transparent and proactive engagement with the media is often the better course.
- Integrated incident response is critical: Effective breach response now requires close collaboration between technical teams, legal counsel, and public relations experts to manage both the technical remediation and the complex communication challenges posed by media-savvy adversaries.
- The public interest drives coverage: Despite the manipulative intent of some attackers, major cyber incidents affecting critical sectors or large populations inherently warrant media attention due to their significant impact on individuals and society.
About the Speaker(s)
The panel comprised distinguished professionals from journalism and incident response, offering diverse perspectives on the evolving relationship between hackers and the media.
Bob McMillan is a seasoned reporter with the Wall Street Journal, specializing in cybersecurity. With over 15 years of experience covering the cyber landscape, he has transitioned from writing for trade publications to a prominent business publication, often covering high-profile incidents and, on occasion, directly interacting with hackers during his investigations.
Lorenzo Franceschi-Bicchierai is a reporter at TechCrunch, having previously spent many years covering technology and cybersecurity for Vice Motherboard. With approximately 10 years of experience, he has extensively covered hackers and cybersecurity, noting his first Black Hat attendance in 2013. He regularly engages with hackers across "a dozen different chat messaging apps" to gather information, while also verifying facts with affected companies, highlighting the dual challenge of his reporting.
Sadia Mirza is a partner at Troutman Pepper, where she leads the firm's incident response investigations practice. In her role, she is often among the first to be called when an organization suspects a cyber incident. She guides clients through the entire response process, from initial investigation to any subsequent litigation. Crucially, she is deeply involved in negotiating with cybercriminals, often through third-party firms, and plays a significant role in managing the communication aspects of incident response.