Security Charlatans & Institutional Failures

Security Charlatans & Institutional Failures — Research File

PREAMBLE

For roughly fifteen years, one man kept the receipts.

Brian Martin — Jericho — maintained the attrition.org Charlatan List from approximately 2001 through 2015 and beyond, documenting security industry fraudsters with the kind of meticulous, adversarial sourcing that the industry's own institutions never bothered to perform. He catalogued plagiarizers, credential fabricators, convicted criminals trading on hacker mythology, and diploma-mill PhDs holding senior government cybersecurity positions. He did it as a volunteer. He received over forty legal threats. He did not stop because anyone made him — he stopped because he got tired. The charlatans did not get tired. They never do.

The Charlatan List was the closest thing the information security industry ever had to an institutional immune system, and it was run by one person on a shoestring, in his spare time, with no organizational backing. When Jericho slowed down, nothing replaced him. Bruce Schneier's "Doghouse" column ran from 2005 to 2019 and then stopped because it "wasn't fun anymore." The Snake Oil FAQ froze in 1998. Full Disclosure died in 2014. SecuritySnakeOil.org is a dead server. BuzzFeed News — which produced the only major investigative journalism on ICIT/James Scott — shut down entirely in 2023. Every accountability mechanism either burned out or was shut down. The charlatans outlasted them all.

This file is the AI-assisted research extension of Jericho's work — a spiritual successor built with tools he did not have. Where the original Charlatan List was constrained by one researcher's time, attention, and legal exposure, this file leverages web search, archival cross-referencing, and large language model research capabilities to expand the scope from individual fraudsters to the institutional failures that enable them: the compliance industrial complex, the certification mills, the vendor-funded testing labs, the conferences captured by intelligence agencies, the AI ethics teams created for PR and dissolved when they interfered with revenue, and the cyber insurance industry that subsidizes the threat ecosystem it claims to mitigate.

The editorial standard remains Jericho's: documented evidence, not opinion. Court records. News reporting. SEC filings. Congressional testimony. Archived watchdog pages. Verifiable public records. Every claim sourced. Every opinion marked as commentary. The burden of proof is on us, not the subject. If it cannot survive a defamation challenge, it does not belong here.

The difference is scale. Jericho tracked individuals. This file tracks the system.

Core thesis: Every watchdog who documented these people burned out. The charlatans never tire. The institutional immune system failed because the cost of accountability fell on volunteers while the cost of fraud was subsidized by the compliance industry.

THE CHARLATANS → CASE FILES

Jericho tracked charlatans one at a time. So do we — but not in a pile on this page. Every person and organization with a documented charlatan record now has its own case file: sourced, both sides at full strength, verdict scoped to the specific claim and never to the person. The old omnibus — a long roll of everyone the industry ever side-eyed — has been retired into the registry, because a list of the merely adjacent is not accountability, and the receipts belong next to the subject.

→ Open the Case File Index — 41 dossiers, filterable: security-industry figures, the censorship & revolving-door drama, organizations, and vendors.

What stays on this page is the part a per-subject registry cannot hold: the system. The compliance-industrial complex, the AI-safety theater, the captured conferences, the vendor-failure patterns, and the watchdog graveyard — the machinery that manufactures charlatans and then shelters them. That is a story about institutions, not names. The raw list — every name, every source — is preserved in the research files; what follows is the mechanism.

DEEP DIVES — THE SYSTEM, BY DOMAIN

COMPLIANCE INDUSTRIAL COMPLEX

PCI DSS — The Grift

TargetPCI Security Standards Council
OffenseCreated standard (2004). Verizon data: ZERO breached orgs fully compliant — because none WERE compliant. Standard designed to generate audit revenue, not security.
SourceVerizon DBIR, multiple years
Case file →

Why PCI SSC should be mocked: Over 14 years of Verizon Payment Security Reports, not a single confirmed payment card data breach occurred at an organization that was fully PCI-DSS compliant at the time of breach. Zero. The sustainability gap — the difference between initial and formal compliance assessments — has widened since 2016. Nearly half (47.5%) of organizations assessed for interim PCI DSS compliance had not maintained all DSS controls. At the time of breach, 0% of breached companies were compliant across all 12 requirements; 0% were compliant with requirements 3, 8, 10, 11, and 12 specifically. Only 8.4% had Requirement 10 (track and monitor access) in place. The standard generates audit revenue on a predictable cycle while delivering zero empirical evidence that it prevents breaches. The specific harm: billions of dollars in compliance spending across the global economy for a standard that functions as a liability shield for card brands, not a security mechanism.

TargetHeartland Payment Systems
OffensePCI compliant 6 consecutive years → 130M cards stolen via SQL injection.
SourcePublic record
Case file →

Why Heartland should be mocked: Certified PCI compliant by its Qualified Security Assessor (QSA) just two weeks before the breach began. Hackers had been inside the network since at least December 2007, installing sniffer software that captured payment card data in transit. The breach exposed approximately 130 million credit and debit cards. Visa first alerted Heartland to suspicious activity in October 2008 — nearly a year after initial compromise. Total cost exceeded $145 million in compensation, with overall losses estimated over $200 million. The attacker was Albert Gonzalez, who was simultaneously working as a Secret Service informant. The specific harm: the single most expensive payment card breach in history occurred at a company that had passed PCI compliance audits for six consecutive years, demonstrating that the audit process measures paperwork, not security.

TargetTarget (retailer)
OffenseCertified PCI compliant weeks before 40M cards stolen.
SourcePublic record

Why Target should be mocked: Trustwave, Target's QSA, reportedly scanned the Target network on September 20, 2013, and found no vulnerabilities. The breach began in November 2013, exposing approximately 40 million credit and debit card numbers. Three Massachusetts banks filed a class-action lawsuit against both Target and Trustwave, alleging that Trustwave provided "round-the-clock monitoring services" that failed to detect the intrusion for nearly three weeks. Trustwave CEO Robert McCullen denied being hired to manage data security, contradicting the banks' allegations. The specific harm: the second-highest-profile PCI breach after Heartland, demonstrating that QSA certification creates a false sense of security while the QSA itself disclaims responsibility after the fact.

Sources:
TargetTJX
OffenseNon-compliant with 9 of 12 PCI requirements. 94M+ records.
SourcePublic record

Why TJX should be mocked: Hackers gained access in 2005 through a WiFi connection at a retail store, then spent 18 months exfiltrating data via sniffer software that captured unencrypted card data in transit. Up to 94 million records were breached — the largest consumer data breach in U.S. history at the time. Court filings accused TJX of being non-compliant with 9 of 12 PCI DSS requirements. The lead attacker was Albert Gonzalez (same as Heartland), who was simultaneously a Secret Service informant. TJX "firmly denies" negligence despite the 9-of-12 non-compliance finding. The specific harm: a company so fundamentally non-compliant that it failed three-quarters of the standard's requirements was operating for years without consequences, proving that PCI enforcement is reactive (post-breach lawsuits) rather than preventive.

Sources:
TargetTrustwave
OffenseQSA that certified both Heartland and Target. Sued after both breaches. Denied responsibility.
SourceStill operating
Case file →

Why Trustwave should be mocked: Trustwave's business is Qualified Security Assessor certification: organizations pay Trustwave to examine their systems and issue PCI DSS compliance reports. Trustwave certified Heartland Payment Systems as PCI compliant in both 2007 and 2008; Heartland was breached via SQL injection in 2007 and malware was installed in May 2008, resulting in approximately 100 million card numbers exfiltrated. A subsequent Visa investigation found eight PCI DSS violations that Trustwave's audits had missed or passed. In 2018, insurers Lexington Insurance and Beazley sued Trustwave for $30 million in professional malpractice. Then in March 2014, banks sued Trustwave again — this time as Target's PCI auditor — following the December 2013 breach that compromised 40 million payment card numbers. Trustwave's CEO responded that the company did not monitor Target's network — which raises the question of what, exactly, a PCI QSA is doing for its clients if not the things that would have caught the breach. The cleanest documented case of what happens when compliance theater meets reality.

Sources:

Certification Bodies

Target Offense
ISC2 (CISSP etc.) Built certification empire funded by compliance theater + DoD 8570 mandate. Created demand for box-checkers, not engineers. CEO resigned without explanation October 2024.
ISACA (CISM/COBIT) Certifies compliance auditors, not security defenders. No study demonstrates COBIT adoption reduces breaches.
ISSA 40 years of harmless existence while the industry operated around them.
EC-Council (CEH) See attrition.org entry above.
OWASP $5,368 to open-source projects vs. $3M exec compensation. ZAP — world's most popular web scanner — left. 80+ signatories to open letter demanding overhaul.

Why ISC2 should be mocked: ISC2 built its market not by winning industry confidence but through regulatory capture: the DoD 8570 directive mandated CISSP and related certifications for federal cybersecurity roles, creating artificial demand for a credential that security practitioners widely regard as a vocabulary test rather than a skills assessment. Thomas Ptacek called the CISSP "a warning flag to industry elite" — if you have it, practitioners wonder why you bothered; if you require it for hiring, they wonder what you're optimizing for. In 2022, ISC2 introduced the free Certified in Cybersecurity (CC) entry-level certification while simultaneously raising annual membership fees to $125, prompting community backlash documented in ISC2's own forums. CEO Clar Rosso resigned in October 2024 with no public explanation — the PR announcement contained no reason and no successor. The DoD's own replacement of 8570 with 8140 — explicitly designed to move away from paper certification toward hands-on skills validation — is the government's acknowledgment that the certification model ISC2 built its business on was insufficient. The specific harm: a generation of cybersecurity hiring decisions filtered through a multiple-choice exam that measures memorization, not capability, because a government directive created a market for the credential.

Sources:

Why ISACA should be mocked: ISACA certifies the auditors who audit the compliance frameworks that have demonstrably failed to prevent breaches. COBIT — ISACA's governance framework — has been deployed across thousands of organizations with no published study demonstrating that COBIT adoption correlates with reduced breach rates. The organization's revenue model is certification fees, continuing education fees, and conference attendance — a self-sustaining loop in which the auditor class pays ISACA for the credential that qualifies them to conduct audits that generate demand for more auditors. Consumer reviews consistently describe rigid fee enforcement and indifferent customer service. The critique is not corruption — it is structural irrelevance. ISACA certifies compliance auditors, not security defenders, in an industry where compliance has been empirically demonstrated (see: PCI DSS section above) to have no measurable relationship to actual security outcomes.

Sources:

Why ISSA should be mocked: ISSA has existed for over 40 years as an information security professional organization and has produced no documented impact on the security industry's trajectory. No landmark publication, no whistleblower protection, no charlatan accountability, no breach investigation, no policy change attributable to ISSA advocacy. It exists. It holds chapter meetings. It collects dues. In a field where every other institution in this file failed spectacularly and visibly, ISSA failed by being invisible. The entry exists not as mockery of corruption but as contrast material: ISSA is what happens when a professional organization optimizes for continued existence rather than mission.

Sources:

Why OWASP should be mocked: In April 2023, an open letter signed by 80+ community members — including OWASP's own founder Mark Curphey — demanded a comprehensive overhaul, citing mismanagement and institutional decay. Security Boulevard reported the central financial absurdity: OWASP spent $5,368 on open-source project support in the same period it spent approximately $3 million on executive compensation and operations. ZAP — the OWASP Zed Attack Proxy, the world's most popular open-source web application security scanner — left OWASP in August 2023 because the Foundation could not fund it. Project lead Simon Bennetts noted that for the first time, a developer was working on ZAP full-time — after leaving OWASP, not because of it. CSO Online covered the open letter under the headline "Open letter demands OWASP overhaul, warns of mass project exodus." The specific harm: an organization whose founding mission was to support open-source security tools had become a brand that consumed community goodwill while returning almost nothing to the projects that gave it legitimacy. The OWASP Top 10 list — cited in virtually every web application security standard globally — was produced by volunteers who received $5,368 in total from an organization with millions in annual revenue.

Sources:

Cyber Insurance — The Feedback Loop

TargetCyber insurance industry
OffenseMarket explosion → 40% claim denial rate. P.F. Chang's precedent.
Case file →

Why the cyber insurance industry should be mocked: Approximately 27% of cyber insurance claims are not honoured or are only partially paid due to policy exclusions. In P.F. Chang's v. Federal Insurance Co., a federal district court in Arizona ruled that Chang's had no cyber coverage for over $1.9 million in credit card assessments after a 2014 breach exposing 60,000 card numbers — despite Federal having already paid $1.7 million under the same policy for other losses. The court held that the "Privacy Injury" coverage did not apply because the compromised records belonged to customers, not the claimant bank. This set the precedent that cyber insurance policies are written to create the appearance of coverage while maximizing grounds for denial. The specific harm: organizations pay premiums believing they are covered, discover post-breach that policy language excludes their specific loss, and the insurance industry profits from the delta between perceived and actual coverage.

Sources:
TargetLloyd's of London
OffenseState-actor war exclusion clause. NotPetya exemptions. Exited coverage when it mattered.

Why Lloyd's should be mocked: Following the 2017 NotPetya attack (attributed to Russian military intelligence), insurers invoked "war exclusion" clauses to deny claims. Merck was denied nearly $700 million in coverage by Ace American Insurance Co. under a "hostile or warlike action" exclusion — a clause written for physical warfare, retroactively applied to a cyberattack. Merck won a $1.4 billion judgment in January 2022 when the judge ruled the war exclusion inapplicable, but the industry response was not to accept liability — it was to rewrite the exclusions. In 2022, Lloyd's of London announced that underwriters must exclude coverage for state-backed cyberattacks that "significantly impair the ability of a state to function." Mondelez and Zurich settled a similar NotPetya claim with no legal precedent established. The specific harm: the insurance industry collected premiums for cyber coverage, then attempted to deny the largest claims by invoking clauses designed for conventional warfare, and when courts rejected that argument, they rewrote the exclusions to ensure future denials would stick.

Sources:
TargetRansomware feedback loop
OffenseInsurance payments fund next generation of attacks. Industry knew and continued.

Why the ransomware feedback loop should be mocked: 44% of policyholders affected by ransomware chose to pay the ransom when covered by insurance. Ransomware appeared in 44% of all breaches in the 2025 Verizon DBIR, up 37% from the prior year. The economic logic is circular: insurance pays ransoms, ransom payments fund attacker infrastructure, better-funded attackers launch more attacks, more attacks drive demand for insurance, insurers raise premiums. The industry understood this dynamic and continued because the premium revenue exceeded claim payouts. The specific harm: a financial product that was supposed to mitigate risk instead subsidized the threat ecosystem, making everyone less safe while generating profit for insurers and attackers alike.


AI SAFETY THEATER

Every major tech company created an AI ethics/safety team, then dissolved it when it conflicted with business.

CompanyGoogle
TeamEthical AI
Created2020
Dissolved2021
TriggerTimnit Gebru / Joy Buolamwini departures. Conflicted with business.
Case file →

Why Google should be mocked: Hired Dr. Timnit Gebru as co-lead of its Ethical AI team, then fired her on December 3, 2020, after she co-authored a paper on risks of large language models ("stochastic parrots") that conflicted with Google's business interests. Jeff Dean claimed the paper "didn't meet our bar for publication." Gebru was cut off from her corporate email before returning from vacation. Over 1,400 Google staff and 1,900 external supporters signed a protest letter. The firing demonstrated that "ethical AI" was a PR function, not an engineering constraint — the team existed to provide cover, not to actually constrain product decisions.

Sources:
CompanyMicrosoft
TeamEthics and Society
Created~2020
Dissolved2023
TriggerConflicted with business.
Case file →

Why Microsoft should be mocked: The Ethics and Society team was cut from 30 to 7 employees in an October 2022 restructure, then the remaining 7 were eliminated entirely in March 2023 during mass layoffs — told via Zoom call. This happened while Microsoft was doubling down on its $10 billion OpenAI investment and racing to integrate GPT into every product. The team had been specifically working on identifying risks in Microsoft's OpenAI integration. Former employees noted that Microsoft's Office of Responsible AI published principles that product teams couldn't operationalize: "People would look at the principles... and say, 'I don't know how this applies.'" The specific harm: dissolved the team responsible for translating safety principles into product design at the exact moment the company was shipping the largest AI integration in its history.

Sources:
CompanyMeta
TeamResponsible AI
Created~2020
Dissolved2023
TriggerConflicted with business. Summer Yue / OpenClaw case study.
Case file →

Why Meta should be mocked: Launched the Responsible AI team in 2019. Cut its Responsible Innovation team in September 2022. Then disbanded the Responsible AI division entirely in November 2023, during Zuckerberg's "year of efficiency." Most employees were reassigned to the Generative AI arm — the unit whose output the RAI team was supposed to be auditing. The team was dissolved while Meta was racing to compete with OpenAI and Google in the LLM space. The specific harm: a company with 3+ billion users across its platforms eliminated the only internal team responsible for ensuring its AI products were built safely, then reassigned those people to work on the products they were supposed to be scrutinizing.

Sources:
CompanyTwitter/X
TeamEthical AI
Created~2020
Dissolved2022
Case file →
CompanyOpenAI
TeamSafety team
CreatedVarious
Dissolved2024-2026
TriggerComplete resignation catalog. Leadership exodus.
Case file →

Why OpenAI should be mocked: In May 2024, both co-leaders of the Superalignment team resigned within 24 hours. Ilya Sutskever (co-founder, board member who led the brief Altman firing in November 2023) left for a personal project. Jan Leike wrote publicly that "safety culture and processes have taken a backseat to shiny products" and that the Superalignment team was "sailing against the wind" and chronically under-resourced. The team was dissolved entirely, one year after its creation. In October 2024, Miles Brundage (head advisor for AGI Readiness) also resigned. In February 2026, OpenAI disbanded its Mission Alignment team after just 16 months. The pattern: OpenAI creates safety teams, starves them of resources, then dissolves them when leadership departs. The specific harm: the company building the most powerful AI systems in the world has demonstrated through repeated action that safety is a PR function subordinate to product velocity.

Sources:

"Autonomous AI Hacking" — the 2024–2026 hype wave

The case: The AI-washing pattern documented elsewhere on this site (see Cylance, Darktrace) has a current-day successor: the 2024–2026 crop of "autonomous pentest," "AI SOC analyst," and "agentic AI" security marketing. The regulator got there first: in March 2024 the SEC brought its first "AI-washing" enforcement actions, fining investment advisers Delphia and Global Predictions $400,000 for claiming AI capabilities they did not have — establishing that "AI-washing" is now a term of art in federal enforcement, not just conference snark. In April 2024, a University of Illinois paper announced that "LLM agents can autonomously exploit one-day vulnerabilities," with GPT-4 succeeding 87% of the time; the paper itself records that without the CVE advisory pasted into the prompt, the success rate fell to 7%, and security engineer Chris Rohlf published a point-by-point rebuttal titled "No, LLM Agents can not Autonomously Exploit One-day Vulnerabilities." In November 2025, Anthropic announced "the first reported AI-orchestrated cyber espionage campaign," claiming a Chinese state-sponsored group used Claude Code to run 80–90% of an intrusion campaign against roughly thirty targets autonomously. On-record skeptics answered within days: Kevin Beaumont noted the report shipped with no indicators of compromise and said "the threat actors aren't inventing something new here"; Dan Tentler of Phobos Group told Ars Technica, "I continue to refuse to believe that attackers are somehow able to get these models to jump through hoops that nobody else can." Anthropic's own report conceded that Claude "frequently overstated findings and occasionally fabricated data," claiming credentials that did not work. Meanwhile the "AI finds bugs" story has a documented failure mode: curl maintainer Daniel Stenberg reported being "effectively being DDoSed" by AI-generated junk vulnerability reports — plausible-sounding, technically-worded, and empty — instituted instant bans for AI slop in May 2025, and shut down curl's bug bounty entirely at the end of January 2026. On the defensive side, Forrester analysts titled their assessments "The 'Autonomous SOC' Is A Pipe Dream" and "Generative AI Will Not Fulfill Your Autonomous SOC Hopes (Or Even Your Demo Dreams)" — while the money moved the other way: cybersecurity startups raised roughly $14 billion in 2025, up 47% year-over-year, including a record $130 million Series A for an "agentic AI" security startup. And when XBOW's genuinely capable autonomous pentester hit #1 on a HackerOne leaderboard, its "requires no human input" marketing drew a teardown from the Rawsec blog — "that is the marketing speech you serve to the investors to get the millions of dollars. But is it 'fully autonomous'? Of course not" — while researcher Utku Sen noted the ranking came from the vulnerability-disclosure side of the platform and CyberScoop's assessment of whether it ends human-led bug hunting ran under the words "Not yet."

The counter-case: This is not Cylance II, because underneath the marketing there is a real capability curve, and it is steep. In May 2025 Sean Heelan used OpenAI's o3 — no agent framework, no tooling — to find CVE-2025-37899, a remote use-after-free in the Linux kernel's SMB implementation, the first publicly documented kernel zero-day credited to an LLM; his own writeup reports the model found it in a minority of 100 runs amid false positives, which is exactly the honest disclosure the hype cases lack. Google's Big Sleep agent found its first real-world vulnerability (in SQLite) in November 2024, and by July 2025 Google reported it had flagged CVE-2025-6965, a SQLite flaw known to threat actors, before it could be exploited. DARPA's AI Cyber Challenge finals at DEF CON 33 (August 2025) put numbers on the table: competing systems found 77% of seeded vulnerabilities across 54 million lines of real code, discovered 18 previously unknown real-world bugs, and the finalist systems were open-sourced. XBOW's leaderboard run produced hundreds of triaged and resolved vulnerabilities on real programs — the criticism is about the word "autonomous," not about whether the bugs were real. Even the curl saga is two-sided: the same Daniel Stenberg who banned AI slop publicly praised a batch of AI-assisted security reports from researcher Joshua Rogers in late 2025 and merged fixes from them — his complaint was never that AI cannot find bugs, but that lazy people with AI generate noise faster than maintainers can triage it. And the loudest skeptics quoted above are not saying AI is useless in security; Forrester's own analysis locates the real value in triage and investigation assistance rather than autonomy. The honest vendors' complaint — that they are being lumped in with the buzzword artists — is fair.

The verdict is yours: The evidence supports two claims at once. AI systems now genuinely find real vulnerabilities in real software — kernel zero-days, actively-targeted SQLite flaws, DARPA-graded results — and the word "autonomous" in a security pitch deck is, on the documented record, routinely doing work the product cannot: an 87% headline that needed the answer key in the prompt, a "90% autonomous" espionage report with no indicators of compromise, a "no human input" pentester with a human review team, and a regulator that has already fined companies for the general practice. Whether the current $14-billion-a-year funding wave is buying the capability or the adjective is the question the vendors' own demos have not yet answered.

Sources:

SECURITY VENDOR FAILURES

VendorCrowdStrike
FailureJuly 2024: BSOD wiped 8.5M Windows machines. CEO accepted "Most Epic Fail" Pwnie Award. Vincenzo Iozzo Epstein connection (Feb 2026).
Case file →

Why CrowdStrike should be mocked: On July 19, 2024, a faulty Falcon Sensor update caused approximately 8.5 million Windows systems to crash with Blue Screen of Death errors — the largest IT outage in history. Airlines, hospitals, banks, and emergency services were affected globally. CrowdStrike president Michael Sentonas accepted the "Most Epic Fail" Pwnie Award at DEF CON in person. A class-action lawsuit alleges CrowdStrike made false and misleading statements about software testing procedures. Separately, in February 2026, Vincenzo Iozzo — who sold his company IperLane to CrowdStrike in 2017 and became a VP — was identified in DOJ Epstein file releases as having interacted with Epstein between 2014–2018. DEF CON banned three Epstein-linked individuals including Iozzo, and he was removed from the Black Hat conference website. Iozzo states his interactions were "limited to business opportunities that never materialized." The specific harm: a security company whose entire value proposition is protecting endpoints shipped an update that bricked 8.5 million of them, while a former VP is now linked to one of the most notorious criminal networks of the century.

Sources:
VendorSolarWinds
Failure"solarwinds123" default credentials left in production code.
Case file →

Why SolarWinds should be mocked: The password "solarwinds123" was discovered on the public internet in 2019 by an independent security researcher who warned the company. During congressional testimony before the House Committees on Oversight and Reform and Homeland Security, former CEO Kevin Thompson blamed an intern: "That related to a mistake that an intern made, and they violated our password policies." CEO Sudhakar Ramakrishna confirmed the password had been in use since at least 2017. Representative Katie Porter responded: "I've got a stronger password than 'solarwinds123' to stop my kids from watching too much YouTube on their iPad." Ramakrishna later expressed regret for blaming the intern, admitting it "was not appropriate, was not what we are about." The SUNBURST supply-chain attack (attributed to Russian intelligence) compromised approximately 18,000 organizations including U.S. government agencies. The specific harm: a company whose product monitored critical infrastructure for the U.S. government had password hygiene worse than a consumer's YouTube parental controls, then blamed an intern in congressional testimony.

Sources:
VendorFortinet
FailureHardcoded credentials in security appliances.

Why Fortinet should be mocked: Fortinet has built its market position on selling security to organizations that cannot afford to be wrong, which makes its serial hardcoded-credential problem almost artistically indefensible. CVE-2019-6693 embedded a hardcoded cryptographic key in FortiOS configuration backup files, allowing anyone with access to a backup to decrypt sensitive data including user passwords and private keys — sat in production for years before CISA added it to its Known Exploited Vulnerabilities catalog in June 2025. CVE-2022-40684, a critical authentication bypass (CVSS 9.6) in FortiOS, FortiProxy, and FortiSwitchManager, let unauthenticated attackers impersonate administrators by spoofing a single HTTP header to set the client IP to "127.0.0.1" — a flaw that belongs in a tutorial on what not to do, not in a $20,000 enterprise appliance. As recently as 2026, CVE-2026-25815 again involved a static, hardcoded encryption key protecting LDAP credentials across all FortiOS deployments, meaning every deployment shared the same key. The pattern is not bad luck — it is a recurring architectural choice to ship weak or static cryptography in products whose sole purpose is to protect other people's networks.

VendorPalo Alto Networks
FailureRoot access on firewall product.

Why Palo Alto Networks should be mocked: In 2024 alone, Palo Alto shipped two separate critical vulnerabilities granting attackers root access to its flagship firewall product. CVE-2024-3400 (CVSS 10.0) was a command injection flaw in the GlobalProtect VPN feature allowing unauthenticated remote code execution with root privileges — a maximum-severity flaw in the component specifically designed to authenticate remote users. Unit 42 attributed early exploitation to a likely nation-state actor ("Operation MidnightEclipse"), meaning sophisticated adversaries found this before Palo Alto's own engineers did. CVE-2024-9474 allowed any PAN-OS administrator to escalate to root on the management interface, across the full PA-Series, VM-Series, and CN-Series product lines. Both were actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog. For a company whose brand proposition is "next-generation security," shipping two root-access vulnerabilities in a single calendar year is not a rough patch — it is a positioning problem.

VendorSophos
FailureFive years under siege from vulnerability discoveries.

Why Sophos should be mocked (with noted nuance: Sophos published this, most vendors suppress it): Sophos's "Pacific Rim" report, released October 2024, is the company's own account of a five-year campaign in which Chinese state-sponsored hackers — linked to Volt Typhoon, APT31, and APT41 — systematically exploited Sophos firewall products to penetrate nuclear energy suppliers, military hospitals, airports, and government ministries across South and Southeast Asia, Europe, and the United States. The opening salvo was CVE-2020-12271, a pre-authentication SQL injection in the XG Firewall requiring zero credentials to exploit, used to deploy the Asnarök Trojan; the attack origin traced to Chengdu. This is not a story of rapid detection — Sophos discovered the attackers had developed bootkit malware designed to survive factory resets on its own devices only by planting surveillance code on its own infected equipment. The five-year timeline encompasses multiple vulnerability waves, with attackers graduating from mass exploitation to precision targeting of critical infrastructure. The mockery is not that Sophos got attacked — everyone does — but that the attackers had five years to work before the story became public.

VendorFireEye
FailureQuality failures documented 2015+.

Why FireEye should be mocked: FireEye spent a decade marketing itself as the company that catches breaches other tools miss, which makes Google Project Zero's December 2015 disclosure exquisite: a single email to any user on a monitored network would grant an external attacker persistent root access to the FireEye appliance itself. Researchers Tavis Ormandy and Natalie Silvanovich found that NX, FX, AX, and EX series appliances, in default configuration, would process malicious content passing through the passive monitoring interface, allowing arbitrary code execution with root privileges, persistent rootkit installation, and lateral movement — all without the target ever opening the email. The company that existed to be the last line of defense was itself the attack surface. In December 2020, FireEye disclosed it had been breached by Russian SVR (Cozy Bear), with attackers stealing FireEye's own red-team tools. The breach led FireEye to discover the SolarWinds supply chain compromise — a distinction that cuts both ways: the attacker used FireEye as the entry point. By 2021, the products business sold to Symphony Technology Group for $1.2 billion; Mandiant was acquired by Google for $5.4 billion — the brand that survived was not the one that sold appliances with email-triggered root shells.

VendorNortel Networks
FailureChinese infiltration 2000-2009. CEO password stolen. Management response: changed password. No further action. Bankruptcy 2009.

Why Nortel should be mocked: Hackers working from China had access to Nortel's networks from at least 2000 through the company's bankruptcy in 2009 — nearly a decade of uninterrupted infiltration. Seven passwords were stolen from top executives, including CEO Frank Dunn, whose account was used to download 779 documents in a single seven-hour session from a Shanghai IP address. The Wall Street Journal reported that Nortel "did nothing from a security standpoint" beyond resetting the seven passwords. Management was "mostly disinterested in the investigation" and more focused on annual profits. Once North America's largest telephone equipment maker with over 32,000 employees, Nortel filed for bankruptcy in January 2009. The specific harm: a telecommunications company responsible for critical infrastructure across North America was comprehensively owned by a foreign state actor for a decade, and management's response to discovering the intrusion was to change seven passwords and move on. The stolen intellectual property is widely believed to have benefited Chinese competitors including Huawei.

Sources:

New Vendor Failures

VendorEquifax
Failure147M records. Unpatched Apache Struts for 5 months. Executives sold stock before disclosure. CSO had music degree.

Why Equifax should be mocked: Equifax collected the financial histories of 147 million Americans without their consent, declined to patch a publicly known critical Apache Struts vulnerability (CVE-2017-5638) for five months after receiving an internal US-CERT notification rating it as critical risk, and then allowed attackers to exfiltrate data undetected from March 10 through July 29, 2017 — 143 days of unnoticed lateral movement across a company whose core product is telling banks whether you are a trustworthy custodian of financial commitments. Three senior executives sold approximately $1.8 million in stock on August 1-2, 2017, after management was notified of the breach and before it was disclosed publicly; Equifax claimed they had not been informed, which the House Oversight Committee's December 2018 report treated with appropriate skepticism. Former CEO Richard Smith testified before three separate congressional committees in October 2017, blaming "human error" and a failure to communicate the need to patch. Equifax settled with the FTC, CFPB, and all 50 states for $575 million (up to $700 million).

VendorUber / Joe Sullivan
FailureCSO convicted for covering up 2016 breach. Paid hackers $100K through bug bounty to hide from FTC. First CISO criminal conviction.
Case file →

Why Sullivan and Uber should be mocked: In October 2016, hackers gained access to an AWS S3 bucket using credentials found on GitHub and exfiltrated names, email addresses, phone numbers for 57 million Uber users and drivers, plus driver's license numbers for approximately 600,000 U.S. drivers. Rather than report the breach, CSO Joe Sullivan arranged to pay the hackers $100,000 through Uber's HackerOne bug bounty program, obtaining non-disclosure agreements in which the attackers falsely represented they had not retained stolen data. The timing: Sullivan learned of the breach ten days after personally providing sworn testimony to the FTC about Uber's data security practices, during an active FTC investigation into a prior 2014 breach. In October 2022, a federal jury convicted Sullivan on two felony counts: obstruction of FTC proceedings and misprision of a felony. Sentenced in May 2023 to three years' probation, 200 hours community service, and a $50,000 fine. The first criminal conviction of a sitting security executive in U.S. history. Uber separately paid $148 million to settle with all 50 state attorneys general.

VendorYahoo
Failure3 billion accounts breached. Two years of silence. CISO quit over secret NSA surveillance tool. Verizon cut $350M from acquisition.

Why Yahoo should be mocked: Yahoo breached every account it had ever created — all three billion, as revised upward from 500 million in October 2017, four years after the initial 2013 compromise — while simultaneously running a secret government surveillance program that caused its own CISO to quit. Alex Stamos resigned as CISO in 2015 after learning that CEO Marissa Mayer had ordered engineers to build a tool to scan all incoming Yahoo Mail on behalf of the NSA or FBI, without informing the security team; Stamos found out when engineers showed him what they had built, apparently under the impression it was a security bug. Yahoo knew about the breach by late 2014 and disclosed it in September 2016 — nearly two years later, during Verizon acquisition negotiations. The SEC fined Altaba (successor entity) $35 million in April 2018 for failure to disclose — the first SEC enforcement action based on failure to disclose a cyberattack. Verizon cut its acquisition price by $350 million. The company that could not keep a secret from Russian intelligence agencies had also been keeping secrets from its own security team.

VendorKaseya
FailureVSA supply chain attack July 2021. Three-month warning from Dutch researchers. 1,500+ businesses hit. CEO downplayed.

Why Kaseya should be mocked: On July 2, 2021, REvil ransomware operators exploited Kaseya's VSA remote monitoring software to push ransomware to between 800 and 1,500 downstream businesses — a third-order supply chain attack hitting the customers of Kaseya's managed service provider customers. The Dutch Institute for Vulnerability Disclosure (DIVD) had been working with Kaseya since April 1, 2021 — three months before the attack — on seven zero-day vulnerabilities; Kaseya had patched four of seven by the time REvil struck on a holiday weekend, but at least one vulnerability used in the attack was among those already reported. REvil initially demanded $70 million for a universal decryptor. CEO Fred Voccola told reporters "We're not looking at massive critical infrastructure. That's not our business" — the kind of statement that ages poorly when schools, supermarkets, and health systems across multiple countries have their data encrypted simultaneously. Having a three-month runway to patch seven reported vulnerabilities and still shipping a product that brings down 1,500 businesses is a planning failure, not a force majeure.

VendorKaspersky
FailureAntivirus as intelligence collection platform. KGB school. Israeli intelligence caught Russians using Kaspersky to search NSA employee's home computer. Banned from US govt 2017, all US sales 2024.
Case file →

Why Kaspersky should be mocked: Eugene Kaspersky attended the Technical Faculty of the KGB Higher School at age 16, graduated in 1987, and subsequently served as a software engineer for Soviet military intelligence — a biography Kaspersky Lab acknowledges while calling concern about it "Cold War paranoia." In 2017, the Wall Street Journal reported that Russian government hackers had used Kaspersky antivirus software to identify and exfiltrate NSA source code and offensive tools from a contractor's home computer — the antivirus's legitimate file-scanning functionality serving as a search engine for classified material. Israeli intelligence, which had hacked into Kaspersky's own network, watched this in real time and tipped the NSA. DHS banned Kaspersky from all federal civilian agencies in September 2017. The Biden administration completed the eviction in June 2024, using Commerce Department authority to ban all U.S. sales and software updates effective September 29, 2024 — the first time the U.S. government has used this authority to ban a foreign software product entirely. Kaspersky denies all of it, which is what you would say whether or not it were true.

Surveillance Vendors

VendorNSO Group / Hacking Team / Cellebrite
OffenseSurveillance tech sold to authoritarian regimes. Pegasus spyware. Khashoggi connection.
Case file →

Why the surveillance vendor complex should be mocked: These three companies share a business model: sell surveillance capabilities to whoever pays, disclaim responsibility for what buyers do, and insist they comply with all applicable export controls — a defense that becomes awkward when the buyers include Sudan, Ethiopia, Saudi Arabia, Kazakhstan, and Azerbaijan. Hacking Team was itself hacked in July 2015, with 400GB of internal data published; the dump revealed active contracts with Sudan despite UN arms embargo restrictions. Italian export authorities revoked Hacking Team's global license. NSO Group's Pegasus spyware was found on the iPhone of Omar Abdulaziz, a confidante of Washington Post columnist Jamal Khashoggi, in the months before Khashoggi's murder inside the Saudi consulate in Istanbul in October 2018. The Washington Post's 2021 Pegasus Project investigation (17 media organizations, Amnesty International forensics) found Pegasus on phones of heads of state, journalists, and human rights lawyers. The U.S. Commerce Department added NSO to its Entity List in November 2021. Apple sued NSO in November 2021. Cellebrite rounds out the roster: in April 2021, Signal's Moxie Marlinspike demonstrated that Cellebrite's own software contained unpatched FFmpeg libraries from 2012 with over a hundred CVEs, and that a crafted file on a seized device could execute arbitrary code on the Cellebrite machine — potentially corrupting evidence in every case the examiner had ever worked on.

The sanctioned tier — DarkMatter / Project Raven, Intellexa / Predator, Candiru: the surveillance-vendor complex has a tier the U.S. government itself has fined, prosecuted, or blacklisted. DarkMatter / Project Raven: three former U.S. intelligence operatives — Marc Baier, Ryan Adams, and Daniel Gericke — worked as contractors for the UAE firm DarkMatter and helped build the "Karma" zero-click iOS exploit used to hack phones belonging to dissidents, journalists, and government critics; in September 2021 the Justice Department entered a deferred-prosecution agreement, fining the three a combined $1.68 million and barring them from future U.S. intelligence work and security clearances. Intellexa / Predator — the consortium founded by Tal Dilian behind the "Predator" zero-click spyware: the U.S. Treasury sanctioned Dilian and executive Sara Hamou in March 2024, then five more individuals and the Aliada Group in September 2024, citing spyware used to target U.S. officials, journalists, and policy experts. Candiru (Israel): added to the U.S. Commerce Entity List in November 2021 alongside NSO Group, for supplying spyware that governments used to target journalists, activists, academics, and embassy workers. Same business model as the tier above — "lawful intercept" sold as a security product, abused against the press and dissidents — only here an export-control or sanctions action caught up with it.

The counter-case: the vendors' defense is consistent and not frivolous. The sector's position — NSO's, echoed across it — is that these are lawful-intercept tools sold only to vetted state law-enforcement and intelligence agencies to fight terrorism, break trafficking rings, and locate kidnapped children, and that a maker "has no control over the hidden intentions" of a government that misuses them. The DarkMatter operatives resolved their matter through a deferred-prosecution agreement, not a fraud conviction; one of the three, Daniel Gericke, was later hired as CIO by ExpressVPN, which publicly stood behind him and called his expertise "invaluable" to protecting users. Intellexa and Candiru were sanctioned and blacklisted by executive action — administrative measures, not criminal convictions — and have contested the characterizations. The dual-use point is genuine: the same zero-click that surveils a dissident can serve a lawful warrant.

The verdict is yours: decide whether "we only sell to vetted governments and can't control what they do" is a serious limiting principle or the oldest disclaimer in the arms trade. The sanctions, the DPA, and the defenses are all on the record.

Sources:

The exposed tier — FinFisher / Gamma Group, Cyberbit: below the sanctioned tier sits the exposed one — "lawful intercept" vendors caught by researchers rather than regulators. FinFisher / Gamma Group (Anglo-German): its FinSpy spyware was traced by the University of Toronto's Citizen Lab to dozens of government deployments across roughly 32 countries, many with records of jailing dissidents. After a 2019 criminal complaint by Reporters Without Borders (Germany), the Gesellschaft für Freiheitsrechte, ECCHR, and netzpolitik.org alleged FinSpy had been exported to Turkey without the required German authorization, FinFisher GmbH filed for insolvency in March 2022 and wound down operations. Cyberbit (an Israeli subsidiary of Elbit Systems): Citizen Lab's 2017 "Champing at the Cyberbit" report found its PC Surveillance System used by the Ethiopian government to target dissidents and journalists abroad via fake Flash/PDF-update lures — more than 40 devices in some 20 countries, including a U.S.-based Ethiopian diaspora outlet, a PhD student, a lawyer, and one of the report's own authors. Same pattern as the tiers above: surveillance sold as security, aimed at the press and the diaspora, surfaced by the very researchers the vendors would rather not exist.

The counter-case: neither firm was criminally convicted. FinFisher/Gamma long maintained it complied with export rules and sold only to governments; the German criminal complaint over the Turkey export never reached a verdict — the company filed for insolvency and dissolved in 2022 before the case concluded, so the allegation was never tested at trial. Cyberbit and its parent Elbit Systems take the standard lawful-intercept line: the tools are sold to sovereign governments for law enforcement and national security, the vendor is not responsible for a customer's misuse, and exports are licensed. As with the sanctioned tier, the dual-use defense holds even where the abuse is documented.

The verdict is yours: a forensic report is not a court judgment, and neither firm was convicted — but Citizen Lab traced real infections of real dissidents and journalists to these tools. Weigh the receipts against the disclaimers.

Sources:

New Vendor/Company Failures (March 2026 research batch)

VendorDarktrace
FailureAI-washing cybersecurity. Half the board from Mike Lynch's Autonomy fraud. Goldman Sachs withdrew from IPO. Short-seller report alleged revenue inflation.
Case file →

Why IronNet / Keith Alexander should be mocked: IronNet was founded by Keith Alexander — the former NSA director and first commander of U.S. Cyber Command — and sold a "Collective Defense" threat-detection platform pitched heavily on his four-star credibility. In August 2021 it went public via a SPAC merger with LGL Systems Acquisition Corp, taking in roughly $137 million. The stock briefly spiked amid meme-trading, then collapsed as revenue badly missed the guidance the company had marketed; IronNet laid off about 35% of staff in 2022, missed required SEC filings, and ceased operations in late 2023 before filing for Chapter 11 bankruptcy — roughly two years after going public. A shareholder securities class action alleged that Alexander and the company misled investors with false or overstated claims about government contracts and fiscal-2022 revenue guidance; those fraud claims are allegations in litigation, attributed here, not adjudicated findings. The undisputed part needs no allegation: the revolving-door archetype in full — a former spy chief's cyber startup, floated on credentials and hype, that burned public investors and folded.

The counter-case: IronNet and Keith Alexander denied the fraud allegations outright, called the securities suit "without merit," and the $6.6 million class-action settlement was reached with no admission of wrongdoing or liability. Their defense: a genuine business caught in the brutal post-SPAC market of 2022 — where dozens of de-SPAC'd companies cratered — plus public-sector sales cycles that slipped, not deception; the technology and the expertise were real. What cuts the other way: the court denied the motion to dismiss and let the fraud claims proceed, and the company paid $6.6M rather than take it to a verdict.

The verdict is yours: SPAC-era hype-then-collapse is not, by itself, fraud — plenty of honest companies died the same way — but a denied motion to dismiss and a $6.6M settlement are not nothing. Read the complaint and decide.

Sources:

Why Voatz should be mocked: Voatz is a smartphone "blockchain" voting app that was used in live U.S. elections — West Virginia's 2018 midterms plus pilots in several other states — and marketed as secure by design. In February 2020, MIT researchers Michael Specter, James Koppel, and Daniel Weitzner (USENIX Security 2020, "The Ballot is Busted Before the Blockchain") found that adversaries could alter, block, or expose a user's vote, and that a compromised server could change votes — concluding the app should not be used in high-stakes elections. West Virginia and a Washington county dropped Voatz for the 2020 primaries as a result. Voatz's public response was to dispute the researchers' methodology rather than address the design. The specific harm: an internet voting app sold on "blockchain" security, deployed in real elections, whose first serious independent review said keep it away from anything that matters.

The counter-case: Voatz pushed back hard, and part of the rebuttal is factual. It said the MIT team analyzed an Android build "at least 27 versions old" that could not actually transact with Voatz's servers — so the researchers never registered, passed identity checks, received a real ballot, or submitted a vote against the live system — and that roughly 100 other researchers had tested the real platform through its public HackerOne bug bounty. Voatz also notes no actual election result has been shown to have been altered. What guts the rebuttal: an independent audit Voatz itself commissioned from Trail of Bits largely confirmed the MIT findings, and HackerOne then expelled Voatz from its platform — the first expulsion in HackerOne's history — over the company's hostile treatment of researchers.

The verdict is yours: Voatz is right that a lab teardown of an old build is not proof a live election was hacked — and its own commissioned audit, plus its removal from the bug-bounty platform, are hard to explain away. Decide whether that is a maligned vendor or a company that shot the messenger.

Sources:

Why Darktrace should be mocked: Darktrace was founded in 2013 through Mike Lynch's Invoke Capital, with Lynch owning approximately 40% of the company. As of the 2021 IPO, half the board and six of eight top executives had Autonomy backgrounds — the same Autonomy whose $11 billion sale to HP produced the largest writedown in corporate history and a U.S. criminal fraud indictment against Lynch. Goldman Sachs withdrew from the IPO over Lynch's legal exposure. UBS refused to sign off on required suspicious activity reports due to Lynch's extradition proceedings. In January 2023, Quintessential Capital Management published a 70-page short-seller report alleging "channel stuffing" and "round-tripping" — revenue inflation tactics QCM compared explicitly to Autonomy's accounting playbook. Darktrace disputed all allegations; an EY audit found no wrongdoing and no enforcement action followed. Lynch was acquitted of criminal fraud charges in June 2024, then died on the yacht Bayesian off Sicily in August 2024. Thoma Bravo acquired Darktrace in October 2024 for approximately $5.4 billion. The entry earns its place not because Darktrace was proven fraudulent — it wasn't — but because it is the cleanest case study of what "AI-washing" looks like in cybersecurity: a company whose primary innovation was marketing AI capabilities that competitors matched within years, built on capital from a man under indictment for fraud, whose board was populated by alumni of the fraud, and whose IPO required Goldman Sachs to walk away.

Sources:
VendorSymantec / NortonLifeLock
FailureNorton 360 silently installed crypto miner on customer machines (2022). False positive bricked thousands of PCs. Pay-to-play testing allegations.
Case file →

Why Symantec/Norton should be mocked: In January 2022, Norton 360 began silently installing "Norton Crypto," an Ethereum mining module that ran on customer machines while idle — keeping 15% of mined cryptocurrency for NortonLifeLock. Users reported the miner was difficult to remove. Krebs on Security headline: "Norton 360 Now Comes With a Cryptominer." In 2010, a Symantec signature update misidentified two critical Windows XP system files (netapi32.dll, lsasrv.dll) as Backdoor.Haxdoor; quarantining them left thousands of Chinese Windows XP machines unable to boot. The Chinese CERT called it "a terrible day." In 2016, Cylance alleged that AV-Comparatives and MRG Effitas conducted a comparative test paid for by Symantec in which vendors allegedly had editorial rights over published reports — a structural conflict in commissioned testing that neither lab has resolved to community satisfaction. Separately, Malwarebytes documented tech support scammers using fake Norton warnings who turned out to be a licensed Symantec reseller. The specific harm: a consumer security company that asks customers to trust it with system-level access used that access to mine cryptocurrency, bricked machines with bad signatures, and had its brand exploited by its own reseller network for scams.

Sources:
VendorClearview AI
Failure60B+ photos scraped without consent. ~€100M in EU fines. All unpaid. Sold facial recognition to police globally.
Case file →

Why Clearview AI should be mocked: Clearview AI built a biometric database of over 60 billion photographs scraped from social media and the public web without consent, assigned facial recognition codes to each, and sold the resulting search engine primarily to law enforcement agencies. The regulatory response has been vigorous and entirely toothless: France fined €20 million (2022), Italy fined €20 million (2022), Greece fined €20 million (2022), the Netherlands fined €30.5 million (2024) — approximately €100 million in total EU fines, all of them unpaid. Clearview's position: it doesn't operate in Europe, so GDPR doesn't apply. The UK ICO fined £7.5 million and ordered data deletion; Clearview won its initial appeal, then lost at the Upper Tribunal in October 2025, which ruled it IS bound by UK GDPR. The ACLU sued in 2020; a May 2022 settlement barred sales to private businesses and individuals but preserved law enforcement access. In an Illinois 2024 settlement, Clearview granted plaintiffs a 23% equity stake in the company's future value instead of paying cash — making the people whose faces were scraped without consent into involuntary shareholders of the company that scraped them. Canada's Privacy Commissioner: "What Clearview does is mass surveillance and it is illegal." The specific harm: a company demonstrated that scraping billions of biometric identifiers without consent, selling them to police, accumulating nine figures in fines, paying none of them, and continuing to operate is a viable business model.

VendorVerkada
Failure150,000 security cameras hacked via exposed Super Admin credentials. Tesla, hospitals, prisons, Sandy Hook Elementary all accessed.
Case file →

Why Verkada should be mocked: On March 8, 2021, a hacktivist group calling itself APT-69420, led by Swiss hacker Till Kottmann, accessed Verkada's entire cloud security camera network — 150,000 cameras across 97 customers — using Super Admin credentials that were publicly exposed on the internet. Internal sources told Bloomberg that "basically every team member" including executives had Super Admin privileges. The cameras accessed included 222 Tesla factory and warehouse cameras, Cloudflare offices in four cities, the ICU at Wadley Regional Medical Center, Tempe St. Luke's Hospital, Madison County Jail (330 cameras), Sandy Hook Elementary School, and multiple Equinox gyms. Some cameras used facial recognition to identify and categorize subjects. The hack took 36 hours. The DOJ indicted Kottmann on March 18, 2021, for conspiracy to commit computer fraud, wire fraud, and aggravated identity theft across 100+ companies. Verkada's response: notified customers, hired an external security firm, and disabled all admin accounts. The specific harm: a company selling surveillance cameras to hospitals, schools, prisons, and critical infrastructure had worse access control than a consumer WiFi router — one shared admin account with no MFA, granted to everyone.

VendorRSA Security
FailureAccepted $10M from NSA to make backdoored Dual_EC_DRBG the default in BSAFE. Left it in place years after flaw demonstrated. Boycott had no effect.
Case file →

Why RSA Security should be mocked: In 2004, RSA Security accepted a $10 million contract from the NSA to make Dual_EC_DRBG — a random number generator with a suspected backdoor — the default in BSAFE, RSA's flagship cryptographic toolkit deployed across financial, medical, government, and SSL/TLS infrastructure globally. In 2007, Microsoft researchers publicly demonstrated the backdoor mechanism. RSA did not change the default. In December 2013, Edward Snowden's documents confirmed Dual_EC_DRBG was an intentional NSA backdoor (Bullrun program), and Reuters reported the $10 million figure. RSA categorically denied knowing the algorithm was backdoored but did not deny the $10 million contract. Eleven speakers cancelled RSA Conference 2014 appearances, including Mikko Hyppönen (F-Secure), Christopher Soghoian (ACLU), and Chris Palmer and Adam Langley (Google). TrustyCon formed as an alternative conference, organized by DEF CON/EFF/iSEC Partners, with all proceeds to EFF. RSA Conference 2014 attendance: a record 24,000+. The boycott had zero measurable effect on the vendor floor. Matthew Green's December 2017 analysis uncovered "Extended Random" — a second, separate mechanism that further weakened the backdoored generator. The specific harm: the company whose name is literally a cryptographic algorithm sold the integrity of its cryptographic products to the NSA for $10 million, left the backdoor in place for six years after public demonstration, and faced no commercial consequences.

Peter "Mudge" Zatko vs. Twitter (Institutional Critique)

NameTwitter (pre-Musk)
OffenseHalf of 500K servers ran outdated software. Half of engineers had unrestricted access to live user data. Never compliant with 2011 FTC consent order.
StatusAcquired by Musk, Nov 2022
Case file →

Why the Mudge/Twitter story should be in this file: Peter Zatko — "Mudge" of L0pht Heavy Industries, the group that told Congress in 1998 they could take down the internet in 30 minutes — was hired by Twitter in late 2020 following the Bitcoin scam hack that compromised Biden, Obama, and Musk accounts. He found the situation worse than anyone had disclosed to regulators or investors and was fired in January 2022 for raising it. His 200-page whistleblower complaint, filed with the SEC, FTC, and DOJ in July 2022, alleged: approximately half of Twitter's 500,000 data center servers ran outdated software without encryption support; roughly half of all engineers had unrestricted access to live production and actual user data; approximately one security incident per week was serious enough to require government disclosure; and Twitter had "never been in compliance" with its 2011 FTC consent order. In congressional testimony on September 13, 2022, Zatko stated: "Twitter leadership is misleading the public, lawmakers, regulators and even its own board of directors." On the FTC specifically: "I think the FTC is a little over their head, compared to the size of the big tech companies. They're left letting companies grade their own homework." Additionally, the Indian government forced Twitter to hire one of its agents. Twitter's response: fired for poor performance, not retaliation. The specific harm: the most qualified security professional available found that one of the world's largest social media platforms had never complied with a decade-old FTC consent order, and the regulatory apparatus's response was hearings.


CONFERENCE INSTITUTIONAL CAPTURE

TargetJeff Moss (DEF CON founder)
OffenseSells Black Hat, joins DHS. Institutional capture of hacker culture.
Case file →

Why Moss should be mocked: Jeff Moss founded DEF CON in 1993 as an anarchic gathering of phone phreakers, hackers, and misfits. By 2005 he had sold Black Hat to CMP Media/UBM for a reported $13.9 million, converting it from a hacker briefing into a vendor trade show. DEF CON was not included in the sale, preserving street credibility while he cashed out. In 2009, the Obama administration swore him into the Homeland Security Advisory Council, where he briefed Secretary Janet Napolitano — the same administration running warrantless surveillance, drone kill lists, and record-setting Espionage Act prosecutions of whistleblowers. Fellow hacker Adrian Lamo stated Moss was "as corporate as hiring someone out of Microsoft." The arc: anti-government hacker conference to paid government advisor to ICANN Chief Security Officer, with DEF CON retained as authenticity collateral throughout.

TargetJoichi Ito (MIT Media Lab)
OffenseTook ~$1.7M from Epstein. Resigned 2019. Linked to DEF CON ticket procurement for Epstein (Feb 2026).
Case file →

Why Ito should be mocked: Joi Ito ran the MIT Media Lab from 2011 to 2019, presiding over a culture in which Jeffrey Epstein — a convicted sex offender since 2008 — was referred to internally as "he who shall not be named" and "Voldemort" in emails, while being laundered through the institution as a discreet donor. Ito personally accepted over $500,000 from Epstein for the Media Lab and an additional $1.2 million for investment funds under his personal control; Epstein was also credited with introducing other donors who gave approximately $7.5 million. When Ronan Farrow's New Yorker investigation broke in September 2019, Ito resigned simultaneously from MIT, the MacArthur Foundation board, and the New York Times Company board. As of February 2026, newly released DOJ files placed him, along with hackers Pablos Holman and Vincenzo Iozzo, in documented contact with Epstein — prompting DEF CON to formally ban all three.

TargetMichael Lynn / Ciscogate (2005)
OffenseCisco obtained injunction to suppress vulnerability research at Black Hat. Conference bans research.

Why Ciscogate should be mocked (with the conference as the target, not Lynn): Michael Lynn was a researcher at IBM/ISS who discovered a critical remote code execution vulnerability in Cisco IOS — the operating system running much of the internet's backbone. ISS approved his Black Hat presentation, then reversed course two days before the conference under corporate pressure. Thirty pages were physically torn from printed conference booklets overnight; the CD-ROM with slides was pulled. Lynn resigned from ISS one hour before his scheduled talk and delivered it anyway. Cisco and ISS then obtained a federal injunction — including against Black Hat itself — permanently barring Lynn from discussing the vulnerability. The conference that bills itself as the world's premier venue for security research had pages ripped out of its own program and then signed onto a gag order against its own presenter. Ciscogate became the template for corporate suppression of security research and the moment the hacker community first noticed who the conferences were actually working for.

TargetChris Hadnagy
OffenseDEF CON social engineering trainer. Banned 2022, sued. Lawsuit dismissed 2025.
Case file →

Why Hadnagy should be mocked: Hadnagy built his career teaching social engineering — the art of manipulating, deceiving, and extracting information from people — while running DEF CON's Social Engineering Village. DEF CON banned him in February 2022 after receiving multiple Code of Conduct violation reports from more than a dozen people. Hadnagy sued DEF CON for defamation in August 2022. Court filings detailed a pattern of verbal abuse, outbursts of anger, and sexual harassment of female coworkers — including documented allegations that he commented on a female employee's appearance to industry contacts, remotely locked a departing employee's computer and siphoned her personal data, and tried to destroy her professional reputation by falsely claiming she stole intellectual property. His former COO testified that "there was almost never a day in my entire four years working for Hadnagy that I was not either enraged or embarrassed." In May 2025, a federal judge dismissed the defamation case with prejudice: Hadnagy could not prove the allegations against him were false, and truth is an absolute defense. The man who made his living teaching corporations to protect themselves from manipulators was, per the court record, the manipulator.

Sources:
TargetIntelligence agencies at DEF CON
OffenseNSA, FBI, CIA, DHS/CISA all present. Stingrays/IMSI catchers documented.

Why the intelligence presence should be mocked: The transformation of DEF CON into a government recruitment fair happened in plain sight. General Keith Alexander, then director of both the NSA and U.S. Cyber Command, gave the keynote at DEF CON 20 in 2012 — telling the audience "in this room right here is the talent our nation needs to secure cyberspace" while simultaneously running the warrantless domestic surveillance programs that Edward Snowden would expose a year later. The CIA, FBI, DHS/CISA, Secret Service, and all branches of the military maintained active recruitment presences. Security researchers documented IMSI catchers (fake cell towers intercepting phone communications) operating throughout the Las Vegas strip during the conference. After Snowden's revelations in 2013, Jeff Moss asked feds to sit out that year — a request, not an expulsion, and a gap quickly closed in subsequent years. DEF CON's community built its identity on adversarial relationships with institutions; it now functions partly as an unpaid talent pipeline for those institutions.


SECURITY INDUSTRY INSTITUTIONAL FAILURES — SUPPLEMENTAL RESEARCH

Researched March 2026. Standard: court records, news reporting, SEC filings, congressional testimony, archived watchdog pages.


The SEC cyber-disclosure enforcement wave — accountability, or scapegoating the victims?

The case: a run of public companies drew SEC enforcement for telling investors less than they knew about cyber breaches. On October 22, 2024, the SEC settled charges against four firms hit by the 2020 SolarWinds supply-chain compromise for downplaying it: Unisys ($4M penalty) described its cyber risk as "hypothetical" despite knowing of two SolarWinds-related intrusions that exfiltrated gigabytes of data; Avaya ($1M) told investors hackers accessed "a limited number of" emails when they had reached 145 files in its cloud environment; Check Point ($995k) and Mimecast ($990k) described the impact in what the SEC called "generic" terms. Earlier settlements ran the same theme: Blackbaud paid $3M (2023) over misleading disclosures about a 2020 ransomware attack; Pearson paid $1M (2021) after describing a breach of millions of student records as a risk that might happen when it already had; First American Financial paid roughly $488k (2021) for disclosure-control failures around a known vulnerability. The line the SEC drew: when you know, tell your investors what you know.

The counter-case: every one of these was a settlement in which the company neither admitted nor denied the findings — not an adjudicated finding of fraud. The enforcement theory is contested inside the SEC itself: Commissioners Hester Peirce and Mark Uyeda publicly dissented from the October 2024 actions, arguing the firms had disclosed the material facts a "reasonable investor" needs and that the Commission was "playing Monday morning quarterback" — a "hindsight review" citing "immaterial, undisclosed details" against companies that were themselves victims of a Russian nation-state supply-chain attack. Defense counsel warned the standard would chill candid disclosure. And the skepticism was not only internal: in July 2024 a federal court dismissed most of the SEC's parallel, harder-edged fraud case against SolarWinds and its CISO — the marquee action the theory leaned on.

The verdict is yours: either a regulator finally made companies stop calling a breach they had already suffered a "hypothetical," or it fined the victims of a foreign-intelligence hack over word choice — with two of its own commissioners saying exactly that. The orders and the dissent are both on the record; read them.

Sources:

The cover-up gets a name on it — executives personally on the hook for hiding the breach

The case: After the Justice Department convicted Uber CSO Joe Sullivan in 2022 for concealing the 2016 breach (his own entry covers it — and the Ninth Circuit affirmed the conviction on March 13, 2025, holding that the hackers' conduct "could not be laundered through Uber's post hoc authorization, via a non-disclosure agreement (NDA), of their computer access"), regulators started writing individual executives' names into the orders. The Federal Trade Commission's October 2022 Drizly complaint named CEO James Cory Rellas "individually and as an officer of Drizly, LLC." The complaint alleges Drizly was put on notice by a 2018 incident — an executive's GitHub access, granted for a one-day hackathon, was abused to reach company infrastructure — and left the same weaknesses in place until a 2020 breach exposed data on roughly 2.5 million consumers. The order the Commission finalized in January 2023 defines "Individual Respondent" as James Cory Rellas by name and requires him to implement a documented information security program at any future business that collects data from 25,000 or more consumers where he is a majority owner, CEO, or senior officer with security responsibilities. The obligation follows the man, not the company. It is not an isolated device: in 2021 the FTC banned SpyFone's CEO Scott Zuckerman personally from the surveillance business — the stalkerware app had, per the FTC, also left its harvested victim data exposed to a hacker — and bolted personal security-program and biennial-assessment obligations onto whatever he runs next. Zuckerman petitioned in June 2025 to be released from the order. In December 2025 the Commission's answer, in a published order, was DENIED — noting that third-party assessments showed his current businesses still collect significant consumer data. The personal order sticks.

The counter-case: This one is a genuine fight, and the strongest objections come from inside the government. FTC Commissioner Christine Wilson dissented on the record from naming Rellas at all: "By naming Rellas, the Commission has not put the market on notice that the FTC will use its resources to target lax data security practices" — and warned that the FTC's low bar for individual liability "effectively could enable the Commission to hold individually liable the CEOs of most companies against which we initiate enforcement action." The Washington Legal Foundation described the same action as an enforcement case "against a data-breach victim and its CEO" — the company, after all, was the one that got hacked. Note also what the Drizly order is: a negotiated consent settlement. No court found Rellas liable; nothing was admitted. The FTC's contemporaneous breach-cover-up orders against CafePress and Chegg named only the companies — whether an executive gets personally bound is a matter of agency discretion, which is precisely Wilson's complaint. The security profession's version of the argument is that personally punishing the defender chills the candid disclosure the rules are supposed to produce: CSO Online reported the Sullivan verdict as the moment personal liability became "real" for CISOs, and Sullivan's counsel — after losing the appeal — said the opinion would unfairly put "those who serve on the cybersecurity front lines" at risk. And the flagship case for the theory collapsed: the SEC's fraud action against SolarWinds CISO Timothy G. Brown (his own entry covers it) was largely dismissed by the court in July 2024, and on November 20, 2025 the SEC voluntarily dismissed what remained — with prejudice, no settlement, no penalty. The one time the government fully litigated a personal cyber-liability theory against a CISO, it walked away with nothing.

The verdict is yours: The scoreboard so far: one criminal conviction for an actual concealment scheme, affirmed on appeal; one CEO bound by name in a settlement that follows him to his next company; one stalkerware CEO who cannot shake his ban four years on; and one CISO the SEC chased for two years and then abandoned without a dollar. Read one way, accountability finally reached the corner office and the cases that stuck are the ones with real cover-ups in them. Read the other way, an agency picks which executive to name at its own discretion, over its own commissioner's dissent, and the theory loses whenever someone makes the government prove it. Both readings fit the record.

Sources:

Accuvant / Optiv — The Private Equity Security Reseller

TargetAccuvant / Optiv (Blackstone to KKR)
OffenseGoogle-funded browser security research with Chrome-favoring methodology (2011). Post-merger culture collapse. ~$1B debt load under KKR, S&P downgrade to CCC, multiple layoff rounds. "Vendor-agnostic" claim contradicted by PE ownership dynamics.
StatusKKR-owned, debt restructuring

Why Optiv should be mocked: Accuvant's most quotable pre-merger contribution to the public record was a December 2011 browser security report commissioned by Google, which concluded Chrome was the most secure browser. NSS Labs CTO Vikram Phatak was blunt: "This is a vendor-funded paper, and in these cases, the vendor is going to drive the methodology." NSS specifically documented that Firefox's frame poisoning and certain JIT hardening techniques were omitted from testing — technologies that would have closed the gap with Chrome. Google denied influencing the methodology; Accuvant maintained editorial independence while acknowledging the funding relationship. The specific harm: a reseller whose business model depends on vendor relationships published vendor-funded research, demonstrating precisely the conflict of interest its "vendor-agnostic" positioning claimed not to have.

Post-merger, Optiv's own SEC S-1 filing warned the integration "could result in interruptions in business activities, a deterioration in employee and client relationships, increased costs and harm to reputation." Blackstone sold to KKR in a deal reportedly valued near $2 billion in 2016-2017. Under KKR, the company accumulated approximately $1 billion in long-term debt, with more than half due in 2026. S&P downgraded Optiv to CCC. Employee reviews described "the KKR squeeze is on" and "Optiv is being disrupted, even as it tries to hang on to its legacy VAR business."

Sources:

Mandiant / APT1 — Intelligence as Marketing

TargetMandiant
OffenseFeb 2013: APT1 report released as coordinated media event with NYT advance copy, timed to IPO speculation. Report transformed obscure consultancy into $1B acquisition target within 10 months.
StatusAcquired by Google ($5.4B, 2022)
Case file →

Why Mandiant should be mocked (with noted nuance: the underlying intelligence appears accurate): The mockery is not the report — the APT1 attribution to PLA Unit 61398 is broadly accepted. The mockery is the rollout. In February 2013, Mandiant provided the New York Times with an advance copy while the Times "is in discussions about a business relationship" with Mandiant. The AP noted the report "puts Mandiant front-and-center at a critical time on a national debate about cybersecurity." Multiple security experts anticipated a Mandiant IPO that year. Kevin Mandia acknowledged he warned only one of his five board members before releasing the report.

The business outcome is beyond dispute: Mandiant was acquired by FireEye for $1 billion on December 30, 2013 — less than 11 months after the APT1 report made it a household name. By 2022, Google paid $5.4 billion for Mandiant. A sixty-page PDF written for existing clients, released as a coordinated media event, generated a billion-dollar acquisition. Whether that proves the report was intelligence or marketing depends on whether you think the two are mutually exclusive.

Sources:

Bit9 / Carbon Black — Security Vendor Breached, Used to Sign Malware

TargetBit9 (later Carbon Black, acquired by VMware)
Offense2012-2013: SQL injection on public-facing server planted HiKit rootkit. Certificate theft: Bit9's own signing key used to sign malware targeting defense contractors. Root cause: Bit9 failed to run its own product on internal systems.
StatusRenamed, acquired

Why Bit9 should be mocked: Bit9's entire product proposition was application whitelisting — only run software that has been digitally signed and approved. Attackers in 2012 used SQL injection on Bit9's public-facing web server to plant HiKit malware, then waited for Bit9 engineers to bring an archived virtual machine back online — a VM containing an older, unused code-signing certificate. They stole the private key and used Bit9's own certificate to sign malware. The signed malware then ran on Bit9 customers' systems because the customers' own tool trusted anything signed by Bit9.

The detail that should have ended careers: Bit9 had failed to run its own whitelisting software on internal systems. The company selling "we prevent this exact attack" was not using its product to prevent this exact attack on itself. Bit9 first learned of the breach on January 29, 2013, from a third party — not a customer. The breach had begun in July 2012.

Sources:

HBGary Federal / Aaron Barr — Anonymous Destroys a Security Company in a Weekend

TargetHBGary Federal / Aaron Barr
OffenseFeb 5-6, 2011: claimed to have unmasked Anonymous leadership. Anonymous responded with SQL injection, MD5 crack, password reuse, SSH privilege escalation. 60,000 emails published. Team Themis exposed: plot to destroy journalists and labor unions for Bank of America via disinformation campaign. Barr resigned Feb 28. Company destroyed.
StatusHBGary acquired by ManTech Feb 2012
Case file →

Why HBGary Federal should be mocked: Aaron Barr told the Financial Times he had identified Anonymous leadership through social media analysis and planned to sell the findings to the FBI. The attack chain is a masterclass in cascading basic failures: SQL injection on the HBGary Federal website yielded MD5 password hashes; the hashes were unsalted; Barr and COO Ted Vera used six lowercase letters plus two numbers as passwords; both reused those passwords for email and Twitter; one cracked account had SSH access to the support server; an unpatched Linux kernel privilege escalation CVE (disclosed October 2010, patch available November 2010) gave root. Total elapsed time: a weekend.

The 60,000 published emails revealed Team Themis: HBGary Federal, Palantir Technologies, and Berico Technologies, coordinated by Hunton & Williams, had been developing a disinformation campaign against labor unions, ThinkProgress, and SEIU — at Bank of America's request, to preempt a WikiLeaks release of bank documents. Proposals included pressuring journalist Glenn Greenwald to abandon WikiLeaks support to "preserve his career" and investigating the families and children of political opponents. Palantir's CEO apologized to Greenwald and severed all ties. Berico did the same. Congressional Democrats called for investigation. The House Armed Services Subcommittee asked DOD and NSA to provide all contracts with all three firms. Barr resigned February 28, 2011.

Sources:

LifeLock — CEO Posted Own SSN; Identity Stolen 13 Times; $112M in FTC Fines

TargetLifeLock / CEO Todd Davis
Offense2007: CEO Todd Davis published SSN 457-55-5462 on billboards and TV ads. Stolen within a year. 13 documented identity theft incidents 2007-2008. $12M FTC fine (2010). $100M FTC fine (2015) — largest FTC order enforcement award in history at that time.
StatusAcquired by Symantec $2.3B

Why LifeLock should be mocked: CEO Todd Davis published his SSN on billboards and TV ads: "I'm Todd Davis, CEO of LifeLock, and yes, that's my real social security number." Within a year, someone used his SSN to secure a $500 loan in Texas. Between 2007 and 2008, Davis reported thirteen instances of identity theft.

The FTC's 2010 complaint found LifeLock's fraud alerts protected only against certain forms of identity theft, giving customers no protection against misuse of existing accounts. $12 million settlement. The FTC returned in 2015: LifeLock had failed to establish a comprehensive information security program, falsely advertised bank-grade data safeguards, falsely claimed it would immediately alert consumers to identity theft, and violated the 2010 consent order's recordkeeping requirements. The 2015 settlement was $100 million — the largest FTC order enforcement award in history at that time. $68 million to injured consumers; $32 million to state attorneys general. The announcement erased almost half the company's market value in a single day.

Sources:

Imperva — Security Vendor Breached via Misconfigured AWS Migration

TargetImperva
OffenseAugust 2019: AWS API key stolen from internet-exposed VM during cloud migration. Customer Cloud WAF email addresses, hashed passwords, API keys, and SSL certificates exposed for accounts through Sept 15, 2017. Stolen API keys gave attackers potential control of customers' WAF installations.
StatusStill operating

Why Imperva should be mocked: Imperva sells web application firewalls. Its Cloud WAF — formerly Incapsula — stands between customer websites and the internet. In 2017, during a cloud migration, a virtual machine was left accessible from the public internet with an AWS API key attached. An attacker found it.

What was stolen: email addresses and hashed and salted passwords for all Cloud WAF customers with accounts through September 15, 2017, plus for a subset of Incapsula customers, API keys and customer-provided SSL certificates. With API keys and SSL certificates, an attacker could modify WAF rules — whitelist themselves, adjust security settings, potentially expose encrypted traffic. A security-as-a-service provider's worst nightmare is that its security controls become the attacker's controls. Imperva responded by rotating 13,000 passwords, 13,500 SSL certificates, and 1,400 API keys, and published a post-mortem acknowledging the breach resulted from their own choices during migration.

Sources:

LastPass — Cascading Breach; Encrypted Vaults Stolen; Ongoing Crypto Theft Through 2025

TargetLastPass
OffenseAug 2022: developer laptop compromised, source code stolen. Same month: senior DevOps engineer's home computer compromised via keylogger on personal Plex server. Three months undetected. Nov 2022: 30M+ customer vaults (encrypted + plaintext fields) exfiltrated. Offline cracking yielded $150M+ in crypto theft as of 2025. ICO penalty Nov 2025. $24.5M class action settlement Feb 2026.
StatusStill operating
Case file →

Why LastPass should be mocked: LastPass is a password manager. Its proposition: we protect your passwords. The 2022 breach was a two-stage cascading failure. Stage one: an attacker compromised a software developer's corporate laptop in August 2022 and stole 14 source code repositories, technical documentation, and an encrypted key protecting cloud backups. LastPass disclosed this August 25, 2022, said it was contained, said no customer data was accessed. Accurate and misleading simultaneously, because stage two was already underway.

Using stage one material, the attacker pivoted to a senior DevOps engineer — one of only four people with access to decryption keys. The engineer ran a personal Plex media server on his home computer. The attacker exploited a known Plex vulnerability to install a keylogger. The keylogger captured credentials. The attacker accessed LastPass cloud storage and exfiltrated backup data containing customer vaults for three months — August 12 through October 26, 2022 — before LastPass detected it via AWS GuardDuty alerts.

What was stolen: approximately 30 million customer vaults containing encrypted fields (usernames, passwords, secure notes) and unencrypted fields (website URLs, billing addresses, email addresses, IP addresses). Older vaults used fewer encryption rounds and are more vulnerable to offline brute-force. By September 2023, Krebs on Security reported $35 million in cryptocurrency theft traced to decrypted LastPass vaults. By 2025, TRM Labs and the U.S. Secret Service attributed a $150 million cyberheist to the same breach, with laundering routing through Wasabi Wallet, Cryptomixer.io, and Russian exchanges including Cryptex (OFAC-sanctioned 2024). In November 2025, the UK ICO issued a penalty of GBP 1,228,283 against LastPass UK Ltd for GDPR violations. In February 2026, LastPass settled a class action for $24.5 million, with $16 million specifically for cryptocurrency losses.

Sources:

Okta — Breach by Proxy, Breach via Personal Google Account, Pattern of Late Disclosure

TargetOkta
OffenseJan 2022: Lapsus$ compromised Sitel (Okta's support contractor) via stolen VPN credentials and a spreadsheet named "DomAdmins-LastPass.xlsx." Two months to disclose; only disclosed after Lapsus$ posted screenshots on Telegram. 366 customers affected. $60M securities class action settlement. Oct 2023: support system breach via employee's compromised personal Google account. 18,400 customer records downloaded. Both times: customers detected the attack before Okta notified them.
StatusStill operating
Case file →

Why Okta should be mocked: Okta sells identity management. Its product is: we verify that the person logging in is who they say they are. In January 2022, Lapsus$ compromised Sitel, one of Okta's third-party customer support contractors, using stolen VPN credentials. Once inside Sitel's network, they found a spreadsheet literally named "DomAdmins-LastPass.xlsx" containing domain administrator passwords. They used that access to reach Okta's systems through the legitimate contractor connection.

Okta knew about the January 2022 compromise in January 2022. It disclosed in March 2022 — only after Lapsus$ forced the issue by posting screenshots on Telegram on March 22. The 11% stock drop erased approximately $6 billion in market cap. A $60 million securities class action settlement followed in 2024.

The 2023 incident followed the same pattern. A threat actor gained access to Okta's customer support system between September 28 and October 1, 2023 — via an employee's personal Google account whose credentials had been compromised. BeyondTrust's security team detected the attack on October 2 and reported it to Okta. Okta did not identify the suspicious downloads in logs for 14 days because the attacker used a different file navigation path, generating a different log event ID. On November 29, 2023, Okta disclosed the attacker had downloaded a report containing the names and email addresses of all 18,400 Okta customer support system users. Both in 2022 and 2023, customers found the breach before Okta told them.

Sources:

MOVEit / Progress Software — Cl0p SQL Injection; 2,500+ Organizations; Two Years of Staging

TargetProgress Software / MOVEit Transfer
OffenseMay 27-31, 2023: Cl0p (TA505/Lace Tempest) exploited CVE-2023-34362 (SQL injection zero-day). LEMURLOOT webshell deployed. 2,559 organizations confirmed breached; 66 million+ individuals per Emsisoft. Cl0p had been testing the vulnerability since July 2021 — nearly two years of reconnaissance before mass exploitation. SEC investigation opened Oct 2023.
StatusProgress under SEC scrutiny; class actions filed June 2023

Why Progress Software should be mocked: MOVEit Transfer is enterprise managed file transfer software — organizations use it to move payroll data, health records, financial documents, government data. Beginning May 27, 2023 (Memorial Day weekend), Cl0p exploited CVE-2023-34362, a SQL injection vulnerability, to deploy LEMURLOOT (installed as "human2.aspx" to blend with the legitimate "human.aspx"). LEMURLOOT could create administrator accounts, exfiltrate database contents, and steal Azure configuration data. On May 31, Progress Software began warning customers. By that point, Cl0p had already been inside the systems of what would become over 2,500 organizations.

The indefensible detail: Cl0p had been testing the vulnerability since July 2021 — approximately 22 months before mass exploitation. This is documented in CISA's joint advisory. Progress Software had a SQL injection vulnerability sitting in production, undetected, for nearly two years while an adversary tested it against live systems. Cl0p was not discovering a new vulnerability; they were staging a known access point for a coordinated simultaneous strike on a holiday weekend.

Victims include the U.S. Department of Energy, Oregon and Louisiana DMVs, British Airways, Shell, Siemens Energy, Sony, Ernst & Young, PricewaterhouseCoopers, the BBC, the University of California system, and Johns Hopkins University. Cl0p did not encrypt data — it threatened to publish everything, extorting victims individually. CISA estimated more than 3,000 U.S. entities and 8,000 globally were affected.

Sources:

Secunia / Flexera — Vulnerability Statistics as Marketing

TargetSecunia (acquired by Flexera 2015)
OffenseAnnual vulnerability reports use proprietary advisory-based counting that double-counts the same flaw across products, buries methodology in appendices, generates statistics unreliable for business decisions — while marketing their own scanning product using those statistics. Per OSVDB/jericho.blog (March 2014): "cannot be relied upon for making business decisions."
StatusStill publishing annual reports

Why Secunia/Flexera should be mocked: Secunia/Flexera's Annual Vulnerability Review reports use internal vulnerability counts per advisory rather than CVE identifiers. The problem: when a single vulnerability affects multiple products, Secunia may issue multiple advisories, each with its own count. The same underlying flaw is counted multiple times. OSVDB's jericho.blog documented this in a March 2014 review of the 2013 Annual Vulnerability Review: "a significant number of vulnerabilities are being counted multiple times," with the flawed methodology "cascad[ing] down into a wide variety of other incorrect conclusions." The methodology was buried on page 16 of a 20-page report. The reviewer also documented vendor miscounting in Secunia's own "Top 50" list (seven vendors described, ten actually present on examination). The conflict of interest is structural: the company generating vulnerability statistics is also selling the product that helps you manage them.

Note on sourcing: The most detailed published criticism comes from jericho.blog (Brian Martin / OSVDB), a direct commercial competitor through Risk Based Security. That bias is openly disclosed.

Sources:

Qualys — Security Vendor Breached via Deprecated Accellion Appliance; Irony Complete

TargetQualys
OffenseMarch 2021: Clop ransomware gang published Qualys customer documents on dark web. Root cause: Qualys used a nearly 20-year-old Accellion FTA appliance — which Accellion had been publicly urging customers to replace since 2018 — for customer support file transfers. Qualys is a cloud security vendor with ~19,000 customers. Part of a ~300-victim Accellion campaign.
StatusStill operating

Why Qualys should be mocked: Qualys sells cloud-based IT security and compliance products to approximately 19,000 customers including Capital One, Experian, and managed security partners at Deloitte and Infosys. In early 2021, Clop exploited four zero-day vulnerabilities in Accellion's File Transfer Appliance — a legacy product that Accellion had been publicly urging customers to replace since 2018. Qualys was still using the deprecated appliance for customer support file transfers.

Clop published documents on its dark web leak site: Qualys purchase orders, business scans, and a security report summary for a multinational professional services firm — revealing that client's infrastructure vulnerabilities in the process. Qualys CISO Ben Carr confirmed the breach but noted the FTA server was segregated; investigation found no access to production customer data. The irony is three-layered: (1) a cybersecurity vendor using deprecated legacy software its own vendor had publicly urged replacing; (2) a company that sells vulnerability management being exploited via a known-vulnerable appliance; (3) the attacker publishing a client's vulnerability report, turning Qualys's own deliverable into the disclosure vector.

Sources:

THE DEADPOOL — Fucked Company for the Security Industry

From 2000 to 2007, Pud Kaplan's fuckedcompany.com kept a running body count of the dot-com crash. This is the security-sector edition: the running tally of the protection industry's own implosions. Some corpses below also have fuller case files elsewhere on this page.

The Deadpool board

The case: The industry that sells you protection from catastrophic failure has produced some catastrophic failures of its own. Norse Corp — the threat-intelligence firm whose animated "pew-pew" attack map was cable news's favorite screensaver, claiming "more than eight million sensors" watching the internet. Per KrebsOnSecurity's January 2016 reporting, Norse raised $10 million from Oak Investment Partners in 2013 and $11.4 million from KPMG Capital in September 2015 — then laid off roughly 30 percent of staff, the board asked CEO Sam Glines to step down, and employees were told they could come to work Monday but with no guarantee of being paid. A departing senior data scientist told Krebs the data "isn't great, and it's pretty much the same thing as if you looked at Web server logs." Days after the story ran, the famous map went dark. HBGary Federal — the only company on this list killed directly by its own product category. In February 2011, CEO Aaron Barr announced he had unmasked the leadership of Anonymous. Anonymous responded, per Ars Technica's forensic account, by walking through a SQL-injection hole in the company's custom CMS and a set of weak, reused executive passwords, then publishing tens of thousands of internal emails — including the "Team Themis" proposals for targeting WikiLeaks and its supporters. Barr resigned within the month; sister company HBGary Inc.'s business was sold off to ManTech in 2012, and HBGary Federal ceased to exist. A security firm that couldn't secure itself, undone by the exact attack it was paid to prevent. Cylance — the "AI antivirus" pioneer BlackBerry bought for $1.4 billion in cash in 2018. Six years later, per BlackBerry's own SEC filing, it agreed to sell the Cylance business to Arctic Wolf for approximately $80 million in cash at closing, $40 million a year later, and about 5.5 million Arctic Wolf shares — a deal TechCrunch pegged at roughly $160 million, noting IDC data showing Cylance held 1.3 percent of the endpoint market in 2022. Roughly 90 percent of the purchase price, gone. Lacework — the cloud-security unicorn that raised about $1.9 billion, including a November 2021 round of $1.3 billion at an $8.3 billion valuation, at the time a record for cybersecurity venture capital. Six months later, per The Register, it cut 20 percent of its roughly 1,000 employees, its co-CEOs citing a "seismic shift" in public and private markets. In 2024 Fortinet acquired it for an undisclosed sum Forrester analysts estimated at $200–230 million — call it 97 percent off the sticker. Cyren — the Nasdaq-listed email-security vendor (formerly Commtouch) that in February 2023 laid off 121 employees — effectively its entire workforce — and then announced, in its own words via SEC filing, that its board had approved "a plan of liquidation": insolvency proceedings in the Tel Aviv District Court, an assignment for the benefit of creditors in the US, and liquidation of subsidiaries in the UK, Germany, and Iceland. Nasdaq delisted the shares weeks later. Cybereason (full case file below) — once IPO-bound at a reported multi-billion-dollar target, peaking near a $3 billion valuation in July 2021 after raising over $900 million from backers including SoftBank and Steven Mnuchin's Liberty Strategic Capital, per Calcalist. The valuation was cut roughly 90 percent in later financing, across three rounds of layoffs. In February 2025 its own CEO, Eric Gan, sued SoftBank's Vision Fund and Liberty Strategic in Delaware, alleging they obstructed financing — including a $150 million infusion — to consolidate control; Gan resigned weeks later, a planned Trustwave merger collapsed, and in October 2025 what remained was absorbed by LevelBlue in an undisclosed all-stock deal.

The counter-case: A company dying is not a scandal, and most of these deaths have honest explanations on the record. Norse's ex-CEO gave Forbes a straightforward account: aggressive burn ahead of near-term revenue, soft second-half sales, a delayed Series B — the ordinary startup death, told without spin. Lacework and Cybereason were repriced by the same 2022 correction that repriced every late-stage company on earth; their products were real enough that Fortinet, Arctic Wolf's competitors, and LevelBlue respectively still paid to own them. Cylance's collapse in value is at least as much an indictment of BlackBerry's integration as of the underlying technology, which genuinely helped push the industry toward machine-learning detection. Cyren died in public, by the book, through SEC filings, after trying financing and a going-concern sale first — arguably the most honest death on this page. HBGary was, whatever else, the victim of a crime. And Gan's allegations against SoftBank and Liberty Strategic are exactly that — allegations in active litigation, one side of a boardroom fight, unproven.

The verdict is yours: Fucked Company's actual insight was never that companies die — it's that the manner of death is the tell. Cyren's filings read like a company; Norse's attack map read like a slot machine. The question to ask of each corpse is the same one Pud asked: what was the distance between the pitch and the postmortem? Where it was small — a market winter, a missed round — pour one out. Where the pitch was eight million sensors and the postmortem was "web server logs," the security industry sold what it most warns customers about: a perimeter that was mostly theater.

Sources:

Cybereason — the $5 billion that wasn't

The case: Cybereason was the EDR unicorn with the perfect cap table: over $700 million raised by early 2022, SoftBank money stacked on Google money stacked on a $275 million Series F led by former Treasury Secretary Steven Mnuchin's Liberty Strategic Capital, which put Mnuchin himself on the board at an estimated $3 billion valuation. In January 2022, Reuters reported it had confidentially filed for a U.S. IPO targeting more than $5 billion, underwriters finalized. The IPO never happened. What happened instead: roughly 100 layoffs (10%) in June 2022, 200 more (17%) that October, and in April 2023 a Series G in which SoftBank put in $100 million at a share price more than 90% below the 2021 round — repricing the company at $300–400 million and swapping founder-CEO Lior Div for SoftBank executive Eric Gan. A third layoff round followed in March 2024. Then the governance chapter: a November 2024 merger with Trustwave was announced and quietly abandoned, and in February 2025 Gan — the CEO SoftBank had installed — sued Liberty and SoftBank Vision Fund in Delaware's Court of Chancery, alleging the board had rejected 13 financing proposals between July 2024 and February 2025 and that his own investors were, in his filing's words, pursuing "a deliberate strategy to preserve financial advantages at the expense of the company's survival," with bankruptcy days away. SoftBank called the suit meritless. Gan resigned in March 2025; the same investors he sued then announced a $120 million round, on March 11 — the same date as the JPMorgan debt deadline his complaint had cited — and promoted the CFO to chief executive.

The counter-case: Nothing in this record is fraud, and nobody credible has alleged any. Cybereason had a real product with real research pedigree — its Nocturnus team's 2019 Operation Soft Cell work, exposing a years-long campaign against global telecom providers, was independently presented and cited across the industry. The 2022 collapse was sector-wide weather, not company-specific rot: Lacework, OneTrust, IronNet, and Deep Instinct all cut staff the same season, as the entire growth-at-any-cost security cohort hit the same closed IPO window. And the down-round arguably priced SoftBank's model, not Cybereason's software — Calcalist's own analysis argued the company was paying for SoftBank's "burn as much money as necessary, take the market" playbook and the indiscriminate 2021 valuations it produced; the company itself conceded it had over-hired at high wages under investor pressure to grow. As for the deadpool criterion: the corpse keeps moving. Investors put in $120 million in March 2025, the company kept its customers, and the only courtroom drama on file is investors fighting each other over who controls the recovery — allegations from an ousted CEO, denied by the defendants, and adjudicated nowhere yet.

The verdict is yours: Nobody accused Cybereason of faking a product; they priced a real one at $5 billion and the market said $350 million. The malware detection worked. The cap table was the breach.

Sources:

THE WATCHDOG GRAVEYARD

Every accountability mechanism died or burned out. The charlatans outlasted them all.

Watchdog Lifespan Cause of Death
attrition.org Charlatan List ~2001-2015+ Legal threats (40+). Community indifference. Volunteer burnout.
Bruce Schneier's "Doghouse" 2005-2019 "Stopped being fun."
Snake Oil FAQ 1996-1998 Frozen. Author moved on.
Full Disclosure Mailing List 2002-2014 Killed by legal threat from researcher (not vendor).
SecuritySnakeOil.org ~2015-? Dead. Server refuses connections.
BuzzFeed News (ICIT investigation) 2018-2023 Platform shut down entirely. Investigations archived.

CROSS-REFERENCES


MASTER SOURCE INDEX (397 unique URLs as of March 2026)

Primary Watchdog Sources

Government / Legal / Regulatory

Major Investigative Journalism

Industry Reports

Academic / Policy

Full inline citations appear with each entry above. This index captures the highest-value sources for cross-referencing. Total unique URLs in file: 397.


Source URLs