Odd Lots
Odd Lots

Here's What Cyber War With Russia Would Actually Look Like

Russia’s invasion of Ukraine has set off a new wave of concern about cyber attacks. Indeed, there were already reports of some in the run up to the war—like when hackers reportedly targeted U.S. gas producers. But while worries about cyber attacks have been around for a long time, it remains hard to

Featured Speakers

Bloomberg HostMatt Suish Guest

Topics Discussed

Episode Summary

Executive Summary: The episode examines cyber warfare in the context of Russia’s invasion of Ukraine, arguing that cyber operations are usually an intelligence and disruption layer within broader hybrid conflict rather than a standalone war. Guest Matt Suish explains attribution challenges, why critical infrastructure attacks are often limited or indirect, how exploits are bought and used, and why governments increasingly rely on sanctions, indictments, and resilience rather than dramatic retaliation.

Main Topics: Cyber warfare as part of hybrid war (Priority: 5/5): The hosts and guest frame cyber activity as one component of broader conflict, alongside kinetic warfare, disinformation, electronic warfare, and sanctions. Cyber is described as most useful before or around the start of a conventional conflict. Attribution and uncertainty in cyber attacks (Priority: 5/5): Suish explains that identifying the perpetrator is difficult and often depends on patterns, timing, motives, and intelligence rather than direct proof. Nation-state cyber operations can take years to uncover. Critical infrastructure risk and real-world impact (Priority: 5/5): The discussion covers attacks on power grids, satellites, railways, and telecom systems, emphasizing that many attacks disrupt communications or logistics more than they cause physical destruction. Government response: indictments, sanctions, and resilience (Priority: 4/5): Rather than overt counterstrikes, responses often include public indictments, sanctions, and private defensive measures by states and companies. The speakers note that much of this work is invisible to the public. Exploit markets and the economics of hacking (Priority: 4/5): The guest explains that exploits are scarce, expensive, and brokered through opaque markets, with governments often among the biggest buyers. Security researchers, brokers, and state buyers all play roles in this ecosystem. Crypto, ransomware, and wartime financing (Priority: 3/5): Crypto is portrayed as highly useful for ransomware payments and for wartime fundraising, especially in Ukraine. The guest argues that crypto created a new payment rail for criminals but also enabled legitimate fundraising and mobilization. Limits of cyber as a decisive weapon (Priority: 5/5): The guest argues that cyber rarely ‘wins’ wars on its own; once kinetic conflict begins, traditional military and communications warfare dominate. Cyber is often more about access, intelligence, and shaping the battlespace.

Key Arguments: Cyber warfare should be understood as a component of hybrid war, not a separate, decisive battlefield. Most nation-state cyber activity is designed for intelligence gathering, persistence, and limited disruption rather than dramatic public destruction. Attribution is inherently hard; investigators rely on timing, targeting patterns, and historical context to infer responsibility. Attacks on infrastructure often affect communications or logistics more than physical assets, as seen in satellite and railway disruptions. Governments do respond, but often through slow-moving tools such as indictments, sanctions, and policy changes rather than immediate retaliation. Companies and security vendors matter because their telemetry can reveal campaigns that would otherwise remain invisible, as in SolarWinds. The exploit economy is sophisticated, expensive, and broker-driven, with states as major customers. Crypto is a practical tool for ransomware and fundraising, while also being used strategically by Ukraine for support and messaging.

Data Points: Podcast format: 5 minutes or less - Described in the opening Bloomberg Stock Movers ad as a short-form audio report Bloomberg reporting network: 3,000 journalists and analysts - Mentioned in the Stock Movers promotional segment Shadow Brokers activity period: 2016-2017 - Guest says the group was especially active around this time SolarWinds customers targeted: around 20,000 - Guest uses SolarWinds as an example of a supply-chain attack SolarWinds compromised customers later identified: 18,000 - The guest says investigators realized roughly 18,000 customers were targeted Ukrainian power grid outage: a few hours - Guest cites 2015-2016 attacks on Ukraine’s electricity grid Belarusian rail disruption group size: 20 to 30 people - Guest describes the Cyber Partisan group as small but organized German wind turbines affected: 3,000 - Collateral disruption after the Viasat-related incident Bangladesh Central Bank heist attempt: $1 billion - Guest references a North Korean-linked attack aimed at stealing this amount Security research keynote denial: 1 denied entry - Guest recounts being turned back at the Russian airport before a security conference Career span statistic: 40 years - Mentioned in a podcast advertisement for real estate investing, not the main discussion Career reduction claim: 15 years - Mentioned in the real estate ad as potential timeline reduction through investing State-sponsored cyber attack share from Russia: 60% - Cited by Joe from a Goldman Sachs note near the end of the episode

Pivotal Quotes: "cyber war, cyber warfare might look like... there is this conception that people have that cyber war is going to be like completely different" — Matt Suish: Explaining that cyber conflict is often imagined as something radically unlike prior conflict, but in practice resembles familiar operations "cyber is a component of war" — Matt Suish: His central framing of cyber within hybrid warfare rather than as a standalone domain "when you get hacked, you know, you don't get like some face showing up on your screen and some guy laughing" — Matt Suish: Clarifying that most intrusions are covert and intended for intelligence rather than spectacle

Implications: Listeners should expect cyber to remain persistent but often invisible, with the biggest risks in espionage, disruption, and misinformation rather than instant collapse. Governments and firms will likely rely more on resilience, intelligence sharing, and sanctions than dramatic cyber retaliation.

🔓 Sign Up for Unlimited Episode Search

About Odd Lots

Bloomberg's Joe Weisenthal and Tracy Alloway analyze the weird patterns, the complex issues and the newest market crazes. Join the conversation every Tuesday and Thursday for interviews with the most interesting minds in finance, economics and markets.

View all episodes from Odd Lots