Episode summary
Shawn Ryan interviews cyber-security executive Kevin Mandia, tracing his career from US Air Force computer security and counter-intelligence work to founding incident-response firm Mandiant, later sold to Google. Mandia describes early investigations in the mid-1990s, including monitoring at a US university that he says revealed logins originating from Beijing and pivoting into multiple US military and national-lab networks. He argues that state-backed hacking is persistent and asymmetric, and contrasts espionage activity with criminal ransomware, saying he has not personally seen Chinese operators extort or ransom victims.
Mandia revisits Mandiant’s 2013 report publicly attributing a large-scale espionage campaign to PLA Unit 61398, and says the campaign targeted a wide range of US organisations, including defence contractors and companies doing business in China. He also discusses SolarWinds and FireEye’s 2020 compromise, recounting how FireEye chose to disclose the breach despite what he says was no legal requirement, and describes co-operation with competitors and US agencies.
On policy, Mandia says US breach notification regimes focus on personal data and do not compel reporting of intellectual property theft, limiting collective defence. He also recounts Mandiant’s reported identification of alleged Russian social-media influence activity in 2015 and says he briefed Senator Mark Warner. Looking forward, he warns that AI will accelerate offensive cyber operations, citing examples of AI-assisted red-teaming that he says can find weaknesses or gain access far faster than human teams, while arguing that AI-driven defence is the only scalable counter.