A Reformed Cybercriminal's Live Black Hat Demo: AI Doesn't Change the Physics of an Attack, Just the

A Reformed Cybercriminal's Live Black Hat Demo: AI Doesn't Change the Physics of an Attack, Just the

BackerLeader 43 231 394
calendar_today agoschedule3 min read

Brett Johnson opens most rooms the same way: by telling them exactly who he used to be. The U.S. Secret Service once called him the "original Internet Godfather," a title he earned the hard way. He built and ran Shadow Crew, an early organized cybercriminal marketplace widely credited as a direct precursor to today's darknet markets, and did time on the U.S. Most Wanted list before serving prison time, escaping once, and eventually going straight. At Black Hat, moderated by Illumio's Public Sector CTO Gary Barlet, Johnson ran a live tabletop demo built to answer one question for the room: how much does AI actually change what someone like his former self can do to a company.

His answer, delivered through a split-screen simulation of a fictional manufacturer called Meridian, a company with multiple plants, remote employees, cloud identity, and the usual sprawl of ERP, production scheduling, and shared files, was direct. AI doesn't hand an attacker anything new. It removes the time cost from the parts of an intrusion that used to require patience: researching a target, figuring out who to pressure and how, mapping an unfamiliar internal environment once inside, and deciding what to go after first. In the demo, a manual version of Johnson worked through Meridian's public footprint by hand, guessing at vendor relationships and internal structure. An AI-assisted version had the same information summarized and ranked in a fraction of the time. Same target, same objective, only the clock changed. "AI is not giving me any secret data whatsoever," Johnson said. "It is helping me make sense of available data faster and more consistent."

The demo included two live audience polls that doubled as a stress test of instinct. In the first, faced with signs of a compromised session and identity-adjacent activity, the room had to choose between watching and gathering more evidence, isolating the first affected machine, or containing the broader set of suspicious internal pathways. Isolating a single machine drew real support, but broad containment of pathways was the stronger answer, since a compromised identity or trust relationship can easily persist somewhere else even after one machine is cleaned up. The second poll added business pressure into the mix: production didn't want downtime, finance was closing the quarter, and leadership wanted certainty. The room converged on targeted containment around the systems that actually mattered, rather than a full shutdown or continued watching, and that instinct was correct.

Barlet used his own two decades in federal IT, including a stretch as a federal CIO, to explain why that's harder in practice than it sounds. Most enterprises don't actually have the network visibility they think they do; the clean architecture diagram a CIO gets handed rarely matches the tangled reality underneath it, and building real containment starts with figuring out what's actually connected to what before deciding what connections are safe to cut. His framing for prioritizing that work leaned on a real, recent example: the 2025 ransomware attack on Jaguar Land Rover, which caused significant damage precisely because core production and financial systems were reachable, not just peripheral ones. Barlet's advice is to treat some systems as deliberately sacrificial. Contain an attacker away from ERP and finance even if it means letting something lower-value, a marketing web server, a survey tool, take the hit.

The core technical argument, from Barlet, is that segmentation doesn't care whether a human or an AI model is driving the attack. Traffic still has to move from system to system; nothing teleports. Breaking the connection between two systems blocks that movement regardless of who or what is attempting it, which is why Barlet argues the physics of containment hasn't changed even as the speed of attacks has. He also pushed back on how security teams typically get evaluated: graded on whether an attacker got in at all, an outcome nobody can reliably prevent, rather than on how well they limited the damage once an attacker inevitably does. "I should get a bonus for that," Barlet said of successfully containing an intrusion. "Not get fired because he got in."

Asked what a developer, engineer, or architect in the audience should actually take away from the demo, Barlet's answer was aimed squarely at how code gets shipped today. Teams increasingly rely on AI to write code quickly, he said, and AI will get you to working code fast, not necessarily secure code. Every deployment introduces some number of unnecessary connections and pathways, and most of those go unnoticed until someone like Johnson finds a use for them. His closing point was less about tooling and more about posture: security and development shouldn't be adversarial functions where developers look for ways around the rules. The two need to work from the same side, because the alternative is exactly the kind of exploitable gap Johnson spent the better part of an hour walking the room through.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

The Zero-Net-Loss Fleet & The Mercenary Squad: A Live AI Economy

DEVPlank - Aug 4

Your AI Doesn't Just Write Tests. It Runs Them Too.

Kevin Martinez - May 12

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

Defending Against AI Worms: Securing Multi-Agent Systems from Self-Replicating Prompts

alessandro_pignati - Apr 2

Europe Just Dropped the Hammer on AI: A Wake-Up Call?

PrabashanaDev - Jul 15
chevron_left
15.9k Points668 Badges
202Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Commenters (This Week)

1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!