CISO Talk by James Azar

CISO Talk by James Azar

Ransomware, SaaS Supply Chains & the Token Time bomb

From Ingram Micro to Snowflake to Salesloft Drift — ransomware’s new weapon is your vendor’s token.

James Azar's avatar
James Azar
Sep 06, 2025
∙ Paid

☕ Good morning Security Gang — coffee cup cheers,

Saturdays are for pausing, grabbing perspective, and reading between the lines of the week’s chaos. This week’s theme couldn’t be sharper: ransomware isn’t about malware anymore. It’s about trust, tokens, and supply chains. And if you think that’s hype, let’s walk through how Drift, Snowflake, and recent ransomware campaigns all prove the point.

🚨 The Evolution of the Playbook

Ransomware Reimagined

Classic ransomware meant encrypting your hard drive and demanding Bitcoin. Today’s crews know encryption alone is too noisy and too reversible. Instead, they steal your data, post snippets online, and dangle the full leak over your head. As Kovrr pointed out in their Snowflake analysis, attackers now lean on regulatory leverage — threatening fines, lawsuits, and shareholder blowback to drive ransom negotiations.

User's avatar

Continue reading this post for free, courtesy of James Azar.

Or purchase a paid subscription.
© 2026 James Azar · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture