CISO Talk by James Azar

CISO Talk by James Azar

Ransomware, SaaS Supply Chains & the Token Time bomb

From Ingram Micro to Snowflake to Salesloft Drift — ransomware’s new weapon is your vendor’s token.

James Azar's avatar
James Azar
Sep 06, 2025
∙ Paid
Share

☕ Good morning Security Gang — coffee cup cheers,

Saturdays are for pausing, grabbing perspective, and reading between the lines of the week’s chaos. This week’s theme couldn’t be sharper: ransomware isn’t about malware anymore. It’s about trust, tokens, and supply chains. And if you think that’s hype, let’s walk through how Drift, Snowflake, and recent ransomware campaigns all prove the point.

🚨 The Evolution of the Playbook

Ransomware Reimagined

Classic ransomware meant encrypting your hard drive and demanding Bitcoin. Today’s crews know encryption alone is too noisy and too reversible. Instead, they steal your data, post snippets online, and dangle the full leak over your head. As Kovrr pointed out in their Snowflake analysis, attackers now lean on regulatory leverage — threatening fines, lawsuits, and shareholder blowback to drive ransom negotiations.

Keep reading with a 7-day free trial

Subscribe to CISO Talk by James Azar to keep reading this post and get 7 days of free access to the full post archives.

Already a paid subscriber? Sign in
© 2025 James Azar
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture