The 229 Podcast

The Hidden First Step in Healthcare Ransomware Attacks Revealed | 2 Minute Drill with Drex DeFord

3 min · 21 de may de 2026
Portada del episodio The Hidden First Step in Healthcare Ransomware Attacks Revealed | 2 Minute Drill with Drex DeFord

Descripción

Ransomware attacks don't always start with a ransomware gang. They start with someone who gets paid to find the door. Aleksey Volkov, known online as ChewbaccaCore, was an initial access broker. His job was identifying vulnerable companies, exploiting their networks, establishing a foothold, and selling that access on dark web marketplaces. Over 16 months in 2021-2022, his work enabled attacks on seven confirmed US businesses, resulting in $9M in confirmed losses and $24M in intended ransom demands. In March 2026, he was sentenced to 81 months in federal prison. For healthcare leaders, the takeaway is uncomfortable: healthcare organizations are premium listings on these dark web markets. Legacy systems, large vendor and contractor ecosystems, high-value data, massive operational disruption risk, and historically thin security investment relative to exposure all show up in the listing price. Someone may have already found a way into your network. They may be holding it. It may have already been sold. Stopping a ransomware gang when they arrive is one problem. Knowing whether someone has already been paid to find the door is a different one. Remember, Stay a Little Paranoid X: This Week Health [https://twitter.com/thisweekhealth] LinkedIn: This Week Health [https://www.linkedin.com/company/ThisWeekHealth] Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer [https://www.alexslemonade.org/mypage/3173454]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de The 229 Podcast!

Empezar

2 meses por 1 €

Después 4,99 € / mes · Cancela cuando quieras.

  • Podcasts exclusivos
  • 20 horas de audiolibros / mes
  • Podcast gratuitos

Todos los episodios

200 episodios

Portada del episodio Creating a World without Passwords and Beating Social Engineering | Executive Interview with Peter Barker

Creating a World without Passwords and Beating Social Engineering | Executive Interview with Peter Barker

June 10, 2026: In healthcare where downtime means lives, identity security is no longer just about who logs in. Bill Russell sits down with Peter Barker [https://www.linkedin.com/in/peterbarker/], Chief Product Officer at Ping Identity [https://www.pingidentity.com/en.html], to unpack why the agentic AI era demands a fundamental rethinking of identity. From giving AI agents first-class credentials to shifting the security boundary from login to the point of action. If your health system is deploying AI and you have not addressed non-human identity, this conversation is where to start. Keep up to date on the latest in health IT: https://thisweekhealth.com/news/ Key Points: * 01:18 Why Agents Change Identity * 07:43 Runtime Identity And Authorization * 15:00 Healthcare Passwordless Trust * 20:11 CISO Playbook And Wrap Up X: This Week Health [https://twitter.com/thisweekhealth] LinkedIn: This Week Health [https://www.linkedin.com/company/ThisWeekHealth] Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer [https://www.alexslemonade.org/mypage/3173454]

10 de jun de 202625 min
Portada del episodio CISA's Own Credentials Were Sitting on GitHub for Six Months

CISA's Own Credentials Were Sitting on GitHub for Six Months

CISA -- the federal agency whose job it is to protect America's critical infrastructure -- had its own internal credentials sitting in a public GitHub repository for six months. Plain text passwords. AWS GovCloud keys. SSH access tokens. Visible to anyone on the internet with a browser.What makes this worse: the contractor who created the repository didn't slip up accidentally. They actively disabled the default GitHub protections designed to prevent exactly this from happening. And when the repository finally came down, those AWS keys stayed valid for another 48 hours before anyone thought to revoke them.Drex brings this back to the question every health system CISO should be sitting with: How many contractors have access to your most sensitive systems right now -- and if one of them made this choice six months ago, would you even know today?Remember, Stay a Little Paranoid Linkedin: https://www.linkedin.com/company/ThisWeekHealth Twitter: https://twitter.com/thisweekhealth Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454

9 de jun de 20264 min
Portada del episodio Major Biometric Breach, HIPAA Deadline Falls Flat, and the Microsoft AI Budget Blowout | Newsday

Major Biometric Breach, HIPAA Deadline Falls Flat, and the Microsoft AI Budget Blowout | Newsday

June 8, 2026: Bill Russell, Drex DeFord, and Sarah Richardson break down three headlines every health IT leader needs to hear. New York City Health and Hospitals suffered a breach that exposed biometric data, fingerprints, palm prints, and geotagged photo metadata through a third-party vector. Unlike passwords or Social Security numbers, that data cannot be replaced. Second, the long-anticipated HIPAA Security Rule update is overdue, and organizations that had two years to prepare are still unprepared. Lastly, Microsoft burned through its entire AI budget in five months. As AI spending spirals, the panel asks the harder question: Does every AI project reduce spend or increase revenue? If not, why is it funded? Key Points: * 02:31 Biometric Breach Fallout * 10:41 Data Retention and Hoarding * 12:59 HIPAA Security Rule Update * 21:10 AI Spend and ROI Reality Keep up to date on the latest in health IT: https://thisweekhealth.com/news/ X: This Week Health [https://twitter.com/thisweekhealth] LinkedIn: This Week Health [https://www.linkedin.com/company/ThisWeekHealth] Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer [https://www.alexslemonade.org/mypage/3173454]

8 de jun de 202627 min
Portada del episodio Rewriting and Overcoming the Burnout Narrative | Flourish Rerelease with Bree Bacon

Rewriting and Overcoming the Burnout Narrative | Flourish Rerelease with Bree Bacon

June 5, 2026: Bree Bacon [https://www.linkedin.com/in/breebaconauthor/] doesn't just talk about burnout; she survived it. Author, Speaker, & Elite Energy [https://www.linkedin.com/company/baconenterprises/]™ Coach, Bree spent years giving 110% to everything until panic attacks and her miscarriage forced her to crash. What she discovered in the aftermath became a life-saving framework that challenges everything healthcare leaders think they know about performance, capacity, and sustainable success. Elite Energy isn't just a theory; it’s tested through fertility loss, chemotherapy, and the impossible choice between career and survival. Key Points: * 02:54 The Reality of Burnout * 07:37 Bree's Personal Journey with Healthcare * 10:52 The Elite Energy Framework * 21:07 Overcoming Cancer and Embracing Life X: This Week Health [https://twitter.com/thisweekhealth] LinkedIn: This Week Health [https://www.linkedin.com/company/ThisWeekHealth] Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer [https://www.alexslemonade.org/mypage/3173454]

5 de jun de 202640 min