Episode Summary
Executive Summary: Andy Greenberg discusses his book Sandworm, arguing that Russia’s GRU unit Sandworm marked a new era of cyberwar through disruptive attacks on Ukraine that escalated into the global NotPetya outbreak. He explains how attribution, diplomacy, and deterrence failed to keep pace, and why governments still struggle to define red lines for cyberattacks on civilians and infrastructure.
Main Topics: Origins of Sandworm and the shift from espionage to disruption (Priority: 5/5): Greenberg explains how the group was first identified through BlackEnergy malware and Dune references, initially appearing as typical espionage actors before revealing a broader disruptive mission. Ukraine as the first real battleground of cyberwar (Priority: 5/5): The interview frames Ukraine as the place where cyber operations became physically disruptive, including blackouts and attacks on media, government networks, and critical infrastructure. NotPetya as the global turning point (Priority: 5/5): The conversation details how a Ukraine-focused attack spread worldwide, crippling multinational companies and hospitals and proving cyberwar could cause massive cross-border damage. US responsibility, hesitation, and failed red lines (Priority: 4/5): Greenberg argues the U.S. helped normalize cyber conflict through Stuxnet and then failed to condemn Russian attacks on Ukraine quickly enough, sending a signal of permissiveness. Attribution, false flags, and deception tactics (Priority: 4/5): The GRU’s use of fake personas, false flags, and misleading narratives is presented as a key operational strategy that obscures responsibility and complicates response. Deterrence, diplomacy, and the search for cyber norms (Priority: 5/5): The discussion contrasts cyberwar with nuclear deterrence, arguing that norms, sanctions, and public attribution are more realistic tools than cyber retaliation alone. What comes next in cyber conflict (Priority: 3/5): Greenberg closes by noting signs of better international attribution and condemnation, but warns that offensive cyber capabilities and more dangerous malware continue to evolve.
Key Arguments: Sandworm is not merely an espionage group; it is a disruptive arm of Russia’s GRU responsible for attacks that directly harmed civilian infrastructure and may have cost lives. Ukraine functioned as the proving ground for modern cyberwar, and the tactics used there later spread globally through NotPetya. The U.S. contributed to the normalization of offensive cyber operations through Stuxnet and then failed to establish meaningful consequences for Russia’s attacks on Ukraine. NotPetya demonstrated that cyberattacks can generate real-world economic damage on a massive scale, not just digital inconvenience. False flags and online personas are central to GRU operations, making attribution harder and enabling plausible deniability. Cyber deterrence is unlikely to work like nuclear deterrence; the more practical response is norms, sanctions, indictments, and public attribution. Failure to call out attacks on civilians and infrastructure encourages escalation because adversaries read silence as permission.
Data Points: Year Greenberg began writing about cybersecurity: 2006 - He says he has been writing about cybersecurity since 2006. First blackout attack in Ukraine: December 2015 - The first hacker-triggered blackout is described as happening in December 2015. NotPetya estimated cost: $10 billion - Greenberg says NotPetya became the worst cyber attack in history by cost. Maersk terminals affected: 17 terminals - NotPetya paralyzed 17 Maersk terminals around the world. Maersk share of global shipping capacity: About one-fifth - Maersk is described as responsible for a fifth of the world’s global shipping capacity. Ukrainian banks affected by NotPetya: 22 banks - He says the attack took down 22 banks in Ukraine. Ukrainian hospitals affected: 4 hospitals - He counts four hospitals in Ukraine disrupted by the attack. Companies specifically named as victims: Maersk, FedEx, Mondelez, Reckitt Benckiser, Merck, Nuance - Examples of major organizations hit when the worm spread globally. Delay before U.S. attribution: 8 months - Greenberg says it took eight months for the U.S. government to publicly say NotPetya was Russia. Delay before sanctions response: 9 months - He says sanctions followed a month after attribution, totaling nine months after the attack. Time span of Ukraine cyberwar: Since fall 2015 - He says the cyberwar in Ukraine began around autumn 2015 and continued escalating. Olympics attack year: 2018 - He discusses the Sandworm attack on the 2018 Winter Olympics.
Pivotal Quotes: "Ukraine is not us. Russia can do what it likes to Ukraine because they're not NATO, they're not EU." — Andy Greenberg: He describes the implicit West-versus-Ukraine logic that delayed a firm response to Russian cyberattacks. "We need to establish norms and make countries like Russia or like organizations like the GRU understand that there will be consequences." — Andy Greenberg: He argues for diplomacy and rules over reliance on cyber retaliation. "Glad to provide people with a different kind of apocalypse as a distraction." — Andy Greenberg: His closing line reflects the grim subject matter and the podcast’s framing of the book as a compelling alternative to pandemic news.
Implications: The episode argues cyberwar is now a real geopolitical weapon, not just a technical nuisance. Listeners should expect more attacks on infrastructure, and governments need stronger norms, attribution, and consequences before the next escalation.
About The Vergecast
The Vergecast is the flagship podcast from The Verge about small gadgets, Big Tech, and everything in between. Every Friday, hosts Nilay Patel and David Pierce hang out and make sense of the week’s most important technology news. And every Tuesday, David leads a selection of The Verge’s expert staffers in an exploration of how gadgets and software affect our lives – and which ones you should bring into yours.