Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

  1. 1d ago

    S0:E27 — The Agentic Ransomware Story That Wasn't

    Palo Alto's Unit 42 published a report describing a fully automated, agentic AI ransomware attack, complete with an 80-page lessons-learned document the attackers supposedly left behind for the victim. It got picked up and ran with by outlets looking for the AI-apocalypse angle. Jess and Jake go through what the report actually says versus what got exaggerated in the retelling, and call out the pattern of vendors using AI-attack framing to sell their own AI-defense product. Second half: a stolen API key with no spending cap burned through hundreds of thousands of dollars in usage before anyone noticed. Jess and Jake use it to talk through exposure management, reachability analysis, and toxic combinations, why chasing CVSS criticals alone is the wrong way to prioritize vulnerability management, and where AI can actually help defenders instead of just generating more hype. In this episode: Unit 42's "agentic ransomware" report: what checks out and what's marketing spinWhy "the threat actor used AI" doesn't mean the defense should be AI-shapedPractical advice for stakeholders asking "how do I defend against AI-driven attacks"Toxic combinations and why prioritizing by CVSS score alone failsA stolen API key with no spending cap and the usage spike that followedExposure management, reachability analysis, and where AI genuinely helps defendersAdam Shostack's updated threat modeling book and his PHANTOM-B threat model framework Show notes: Unit 42 report: https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/The Register coverage: https://www.theregister.com/security/2026/09/02/ai-agents-carried-out-every-step-of-this-ransomware-attack-then-left-the-victim-an-80-page-security-audit/5294009API key incident (The Register): https://www.theregister.com/security/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/5293730Threat Modeling, 2nd Edition (preorder): https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1394413327PHANTOM-B whitepaper: https://shostack.org/files/papers/PHANTOM-B_Whitepaper_Shostack.pdf Breach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. Nothing in this episode is legal, financial, or security advice. Do your homework before pointing anything we said at prod.

  2. Aug 28

    S0E23. The LA County Museum of Art breach that took a year to unravel

    LACMA’s year-long breach disclosure delay and what it says about incident responseJess Hebenstreit and Jake Williams break down a Los Angeles County Museum of Art data security incident that raises big questions about breach timelines, notification delays, and response ownership. They focus on what the disclosure says, what it leaves unsaid, and why the cleanup process may have taken far longer than it should have. In this episode, they examine the gap between initial detection, timeline validation, data review, and eventual notification. They also unpack why the kind of data exposed suggests employee and benefits records, and why that matters for both legal exposure and response logistics. Key topicsThe breach timeline looks unusually longJess and Jake note that LACMA says it detected suspicious activity on July 11, 2025, but did not publish the disclosure until August 24, 2026.They question how it took weeks to confirm the intrusion window and then months more to complete the data review. The delay in scoping the incident raises red flagsJake points out that the investigation later narrowed the third party’s access to July 7 through July 11.They discuss how incident teams can get stuck chasing false leads in logs, but still say this timeline feels slow. Data review appears to have dragged onThe disclosure says the initial data review results arrived in late February 2026.Jess and Jake interpret that as a sign of weak data governance, poor vendor management, or both. The affected data suggests employee and benefits recordsThe potentially exposed data includes full names, dates of birth, Social Security numbers, government ID numbers, financial account numbers, payment card data, health insurance information, and limited medical details.Jess argues that this pattern looks like employee data, possibly tied to a self-funded health plan. Notification logistics seem inconsistentJake questions why the organization spent months trying to obtain “accurate contact information” before notifying impacted people.He notes that breach notification rules generally do not wait for perfect contact data before state reporting obligations begin. A class action lawsuit seems likelyJess says she expects litigation, and Jake agrees.They also suggest state attorney general investigations are likely. The response may have suffered from leadership turnoverJess thinks a change in leadership or responsibility may have disrupted the response.Jake agrees that handoffs, missing context, or people being removed mid-incident can create major problems. They believe outsourcing the data review was the right move, but too lateJake explains why identifying impacted records is harder than it sounds, especially with inconsistent name formats, spellings, and duplicate records.Both agree this kind of work should be handled by a firm that does breach review every day. Cyber insurance and breach counsel likely shaped the responseThey debate whether the organization had cyber insurance and how that would have affected the handling of the case.Jake explains that cyber claims usually involve upfront costs and reimbursement later, which can slow response work. The human cost of a broken incident responseJess closes by saying she feels bad for the responders who had to deal with the mess.Jake advises responders to keep notes, assume they may be deposed later, and remember that the organization will not protect them in enforcement actions. Timestamps00:00 - Breach Please intro and the show’s no-nonsense mission 01:33 - LACMA data security incident enters the conversation 01:50 - Why the disclosure timeline is so hard to believe 03:18 - What the timeline says about detection and scoping 06:01 - Late February 2026 data review results 07:57 - Why “accurate contact information” is a weak explanation 08:52 - Why a lawsuit and state investigations seem likely 09:27 - The exposed data and why it looks like employee records 10:54 - A Reddit post suggesting notifications were already going out 12:12 - Possible leadership change during the response 13:37 - When even counsel decides the incident is too messy 15:31 - Whether cyber insurance was involved at all 17:04 - How cyber claims actually get paid 18:38 - Procurement problems or failed in-house review? 20:21 - Why identifying impacted people is much harder than it sounds 22:36 - Why outsourcing the review was probably necessary 23:35 - Why state reporting obligations still matter even if mailing is slow 24:04 - Sympathy for the responders caught in the middle 25:02 - Why responders should document everything now 25:57 - Final reminder: organizations do not protect employees in enforcement actions 26:11 - Outro and closing sign-off

About

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.