Skip to content
By Podcasts

The Podcasts That Explained the Biggest Breaches Best

One first listen and one deeper episode for six major breaches: SolarWinds, NotPetya, Log4Shell, MOVEit, Scattered Spider and XZ Utils. Each verified against the show's feed, linked to a primary source, with the identity lessons pulled out.

The Podcasts That Explained the Biggest Breaches Best, by Deepak Gupta on guptadeepak.com

The best podcast episodes on the biggest breaches were recorded close to the event, often by people who worked on it. My picks: Malicious Life on SolarWinds, Darknet Diaries on NotPetya, Andres Freund on XZ Utils, and Microsoft's researchers on Scattered Spider. Below is one first listen and one deeper episode for each of six breaches, plus what the audio explains that the written coverage tends to skip.

Verified as of 1 October 2026 against each show's own feed.

I founded LoginRadius in 2013 and scaled it to over a billion users, and I run Start with Identity, the non-profit identity community I founded. That background is why this post reads every breach with one question in mind: where did identity fail, and which episode explains it best? I also curate the podcast directory these picks come from.

How These Picks Were Chosen

Each breach below has its own page in the directory with every episode we verified, from five to eight per breach. For this post I picked two per breach: one short, plain-language first listen and one longer episode for practitioners.

Every episode was checked against the show's own feed for title, date, and length. Each section also links one primary source, such as a CISA advisory or an SEC filing, so you can check the facts before you press play.

Where a show is run by a security vendor, I say so. Vendor shows can be excellent on breaches because their researchers often worked the incident. You should still know who is paying for the microphone.

At a Glance: The Best First Listen for Each Breach

BreachYearBest first listen (show, minutes)Page
NotPetya2017Darknet Diaries, 57 min6 NotPetya episodes
SolarWinds2020Malicious Life, 35 min8 SolarWinds episodes
Log4Shell2021Hacking Humans, 9 min8 Log4Shell episodes
MOVEit2023Click Here, 24 min5 MOVEit episodes
Scattered Spider2023Hacking Humans, 30 min5 Scattered Spider episodes
XZ Utils2024Crying Out Cloud, 13 min8 XZ Utils episodes

NotPetya (2017): The Most Destructive Attack, Told as a Story

On June 27, 2017, NotPetya spread from M.E.Doc, Ukrainian tax accounting software whose development environment attackers had backdoored. It encrypted files on networks worldwide with no working way to restore them. In February 2018 the White House attributed it to the Russian military and called it the most destructive and costly cyberattack in history. CISA's July 2017 alert on the Petya ransomware is the primary record from the time.

First listen: Darknet Diaries, 54: NotPetya (2019-12-24, 57 minutes). It is the best single story of the attack: what got hit, how it spread, and who was responsible. Darknet Diaries is independent and one of the 12 keepers in my weekly listening stack.

Go deeper: Security Unfiltered, Episode 90 - Saving The World From NotPetya (2023-02-06, 54 minutes). Researcher Amit Serper tells, at long-form interview length and in his own words, how he worked to stop NotPetya's spread.

What the audio adds: written coverage of NotPetya is mostly about cost and attribution. The episodes spend time on the defender's side. Malicious Life (run by Cybereason) covers it in NotPetya Part 2 (2021-03-15, 25 minutes): how Serper found a vaccine against the malware within an hour, from his parents' living room. That detail makes the case that one prepared person can change an outbreak's course.

Hear all 6 episodes on NotPetya, including a Research Saturday look back after the 2020 DOJ indictment.

SolarWinds (2020): A Supply Chain Attack With an Identity Ending

Beginning in at least March 2020, attackers used a compromised component of SolarWinds' Orion network management software to break into US government agencies, critical infrastructure operators, and private companies. CISA also flagged abuse of SAML authentication tokens in the campaign. In April 2021 the US government formally named Russia's foreign intelligence service, the SVR, as responsible. Start with CISA's advisory AA20-352A.

First listen: Malicious Life (Cybereason), Special: The Solarwinds Hack (2020-12-28, 35 minutes). It was recorded two weeks after disclosure and is still the clearest plain-language walk through what happened and why it mattered.

Go deeper: Behind the Binary (Google Cloud Security), EP04 Stephen Eckels (2025-01-15, 66 minutes). A Mandiant FLARE reverse engineer who worked on the SUNBURST backdoor explains how it was found.

The identity episode: Identity at the Center, #84 - Solorigate Recap with Robb Reck (2021-03-15, 45 minutes). Ping Identity's CISO reads the campaign through an identity and Zero Trust lens three months in. Identity at the Center is independent and also on my keeper list. Its Start with Identity profile has more episodes by topic.

What the audio adds: written coverage framed SolarWinds as a software build compromise. The CISA advisory's SAML token point is easy to miss in print. SAML is the standard behind much enterprise federation, where one system vouches for a user to another. When signed tokens can be abused, the trust chain itself becomes the attack surface, and that is the thread the Identity at the Center episode pulls on. CyberWire Daily adds a different angle in SolarWinds, SUNBURST, and supply chain security. [CyberWire-X] (2021-03-14, 35 minutes): how affected organizations worked out what was breached and for how long, beyond ejecting the intruders.

Hear all 8 episodes on SolarWinds, including SolarWinds' own CISO on CISO Tradecraft and two Lawfare episodes on policy and the SEC case.

Log4Shell (2021): One Library, Everywhere at Once

In December 2021, CISA and its partners began responding to active, widespread exploitation of Log4Shell (CVE-2021-44228). It is a critical remote code execution flaw in Apache's Log4j logging library, versions 2.0-beta9 to 2.14.1. Because Log4j is built into so many consumer, enterprise, and operational technology products, CISA issued an emergency directive on December 17, 2021. Read CISA's Apache Log4j vulnerability guidance.

First listen: Hacking Humans (N2K Networks), Log4j vulnerability (noun) [Word Notes] (2022-01-11, 9 minutes). Nine minutes on what Log4j is and why one logging library caused so much damage. This is the one to send a student or a non-technical colleague.

Go deeper: Talkin' Bout [Infosec] News (Black Hills Information Security), The Floor is Java, 12/15/2021 (2021-12-15, 64 minutes). Recorded in the first days, it covers how the exploit works, mitigations, and finding it on hosts. For the exploit mechanics, Day[0] has the vulnerability researcher's view of JNDI from the same week.

What the audio adds: episodes recorded during the response capture what defenders did not yet know. Open Source Security, Episode 302 - Log4j is a mess (2021-12-20, 34 minutes), lays out every gap defenders faced from the open source side. Malicious Life's short side episode covers the community vaccine released to blunt exploitation while patches rolled out, a stopgap that rarely makes the written retrospectives.

Hear all 8 episodes on Log4Shell, including the Cyber Safety Review Board's leaders on Lawfare.

MOVEit (2023): Mass Data Theft Through a File Transfer Tool

Beginning on May 27, 2023, the Cl0p ransomware gang exploited a previously unknown SQL injection flaw (CVE-2023-34362) in Progress Software's MOVEit Transfer. Internet-facing MOVEit servers were infected with a web shell called LEMURLOOT, used to steal data from the underlying databases. The primary source is the joint CISA and FBI advisory AA23-158A.

First listen: Click Here (Recorded Future), 82. The Clop gang's in love with a special kind of bug (2023-08-29, 24 minutes). A tight narrative on how Clop pulled off the mass theft, and why its method raised eyebrows.

Go deeper: The Defender's Advantage Podcast (Google's Mandiant), Threat Trends: The Implications of the MOVEit Compromise (2023-07-20, 28 minutes). Mandiant's Charles Carmakal explains how this campaign differed from FIN11's earlier ones, and why it has a long tail.

What the audio adds: written coverage of MOVEit became a running count of victims. The Mandiant episode places it in a pattern of earlier campaigns, which is more useful for planning than a count. If you only have three minutes, CyberWire's feed has the CISA and FBI advisory read aloud, indicators and mitigations included.

Hear all 5 episodes on MOVEit, including Wiz's Crying Out Cloud on the cloud exposure.

Scattered Spider (2023): The Help Desk Was the Way In

In September 2023, MGM Resorts and Caesars Entertainment disclosed cyberattacks in SEC filings. Caesars said its intrusion began with a social engineering attack on an outsourced IT support vendor. A joint CISA and FBI advisory AA23-320A describes Scattered Spider's methods: posing as IT or help desk staff, push bombing, and SIM swapping to obtain credentials and bypass MFA.

First listen: Hacking Humans, Click for a pay bump? (2025-07-31, 30 minutes). A plain-language profile of how the group fools people rather than breaking systems.

Go deeper: Microsoft Threat Intelligence Podcast (Microsoft), Octo Tempest Threat Actor Profile (2023-11-01, 46 minutes). Microsoft's researchers on the group they track as Octo Tempest: SIM swapping, SMS phishing, and hands-on persistence.

What the audio adds: written coverage tends to stop at "social engineering". The episodes stay on the mechanics. Research Saturday has two useful follow-ups: GuidePoint's incident responders on the tools and playbooks that tie intrusions to the group, and Kroll on its industry-by-industry targeting and how the next sector can prepare.

This is the most identity-heavy case in the post. The methods the advisory names target a person or an authentication step, not a software flaw. Vishing gets the caller to the help desk. Push bombing wears down MFA approvals. A SIM swap takes over the phone number that receives codes. The end state is account takeover. I wrote up the defensive side in Your Help Desk Is the New Perimeter.

Hear all 5 episodes on Scattered Spider.

XZ Utils (2024): The Backdoor Found by a Slow Login

On March 29, 2024, Andres Freund disclosed on the oss-security mailing list that XZ Utils versions 5.6.0 and 5.6.1 contained a backdoor that could lead to SSH server compromise. The malicious code sat in the release tarballs rather than the project's git source. CISA advised users to downgrade to an uncompromised version (CVE-2024-3094).

First listen: Crying Out Cloud (Wiz, now part of Google Cloud), CROC News - XZ Utils backdoor explained (2024-03-31, 13 minutes). Thirteen minutes, recorded within days: the fastest way to understand what was found.

Go deeper: Three Buddy Problem, Costin Raiu joins the XZ Utils backdoor investigation (2024-04-05, 52 minutes). Costin Raiu digs into the timeline and the long-con tradecraft behind the attack.

What the audio adds: the discoverer in his own words. On the Microsoft Threat Intelligence Podcast, Behind the Scenes of the XZ vuln with Andres Freund and Thomas Roccia (2024-05-08, 33 minutes) has Freund explaining how an SSH performance oddity led him to the backdoor. Application Security Weekly then names the lessons: abuse of maintainer trust, obscured changes, and suppressed warnings. XZ is a trust story too: the abused trust was in a maintainer, which is a question of who you rely on, not only of what the code does.

Hear all 8 episodes on XZ Utils, and the wider supply chain attacks list.

The Identity Thread Running Through These Breaches

Read the six together and identity shows up in at least two of them directly. SolarWinds involved abuse of SAML authentication tokens. Scattered Spider worked through help desk impersonation, push bombing, and SIM swaps. Both turn on who, or what, a system chooses to trust.

The common defensive answer is phishing-resistant MFA, plus treating token theft as its own threat, separate from password theft. A push prompt can be fatigued and a code can be relayed. A FIDO2 credential bound to the real domain gives an impersonator nothing to ask for.

For episodes on these techniques outside any single breach, use the identity attacks list. Start with two from it. The first is The Defender's Advantage on How Threat Actors Bypass Multi-Factor Authentication (2024-09-26, 27 minutes). The second is Identity at the Center's #373 - Going Passkey Phishing with Nishant Kaushik (2025-09-15, 58 minutes), with FIDO Alliance's CTO on where passkeys stop phishing.

For identity-only listening, Start with Identity, the non-profit identity community I founded, keeps a directory of more than 20 identity podcasts. Its passkeys and FIDO learning guide is the best next step after the Scattered Spider episodes, because it orders episodes from concept to deployment.

The Breaches Podcasts Have Not Explained Well Yet

Some major incidents are missing from this post on purpose. Uber (2022), LastPass (2022), Snowflake (2024), and Okta's 2022 and 2023 breaches got mostly short news segments in the 51 shows we track, not dedicated episodes.

That is an observation about these shows' feeds, not about the incidents or the wider podcast world. A ten-minute news segment can be accurate. It rarely has room for the how and the why that make an episode worth a list.

Until dedicated episodes appear, the identity attacks list is the place to learn the account takeover techniques behind many recent incidents. When a show publishes a real episode on one of them, it goes on its own page.

How to Use These Episodes

If you are a student, start with the short first listens: Hacking Humans on Log4j (9 minutes), Crying Out Cloud on XZ (13), and Click Here on MOVEit (24). Then take Darknet Diaries on NotPetya as the long one. The beginner episode list has 25 more.

If you are a practitioner, take the "go deeper" picks and read the linked primary source alongside each. The gap between the advisory and the episode is where most of the learning sits. The incident response list and nation-state operations list extend several of these cases.

All themed and breach lists live on the episodes index, organised by topic on the topics index.

Frequently Asked Questions

What is the best podcast episode on the SolarWinds hack?

Start with Malicious Life's "Special: The Solarwinds Hack" (35 minutes, December 2020), the clearest plain-language account. For the identity angle, Identity at the Center's "#84 - Solorigate Recap with Robb Reck" reads it through identity and Zero Trust. For how SUNBURST was found, Behind the Binary's EP04 with a Mandiant reverse engineer goes furthest.

Which podcast explains Log4Shell for beginners?

Hacking Humans' "Log4j vulnerability (noun) [Word Notes]" explains it in nine minutes: what Log4j is and why one logging library caused so much damage. Follow it with Open Source Security's "Episode 302 - Log4j is a mess" for the defender's view from the week of disclosure.

Is there a good podcast episode on the XZ Utils backdoor?

Yes. Crying Out Cloud's 13-minute "CROC News - XZ Utils backdoor explained" is the fastest overview. The Microsoft Threat Intelligence Podcast episode with Andres Freund has the discoverer explaining how an SSH performance oddity led him to it.

What podcast covers NotPetya best?

Darknet Diaries episode 54, "NotPetya", is the best single story of the attack. For the defender's side, Security Unfiltered's Episode 90 has Amit Serper on stopping its spread, and Malicious Life's two-part series covers the Ukrainian context.

Which podcast episodes explain Scattered Spider's help desk attacks?

Hacking Humans' "Click for a pay bump?" is a plain-language profile of how the group fools people. Microsoft's "Octo Tempest Threat Actor Profile" covers SIM swapping, SMS phishing, and persistence in more depth. The CISA and FBI advisory AA23-320A lists the help desk impersonation, push bombing, and SIM swapping methods.

Get new Identity & CIAM writing

Enjoyed this? Subscribe and tell us what you read most. Identity & CIAM is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks