In short
The episode covers two main topics: rising cybercrime and the difficulty of counting deaths in African conflicts, plus a brief science segment on chocolate. Cybercrime: Alex Hearn (Economist tech correspondent) says ransomware gangs increasingly “smash” systems first, then demand payment, using local UK/anglophonic hackers working with Russian tooling. Key claims include a 50% rise in “highly significant attacks” per Britain’s NCSC, and that disruption can dwarf ransom payments (e.g., JLR shutdown affecting suppliers; UK government underwrote a £1.5bn loan).
Notable examples
MGM Resorts, Jaguar Land Rover, Jaguar Land Rover’s production stoppage, Co-op and Marks & Spencer, Transport for London.
Guests
Alex Hearn; Tom Perriello (US special envoy to Sudan, cited); Tom Gardner (Africa correspondent, leads the death-count segment).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOChallenges in Reporting Death Counts
1:28 to 2:05
Explore the difficulties journalists face in accurately reporting death counts.
“But our Africa correspondent has a problem.”
Evolution of Cybercrime
2:05 to 2:22
Understand how the landscape of cybercrime has changed over the years.
“Back in the day, for many businesses, the biggest security concern was having the cash register robbed.”
Rise of Ransomware Attacks
2:22 to 4:00
Learn about the increase in ransomware attacks and their impact on businesses.
“It's been more than three weeks since MGM Resorts was hit with that massive cyber attack.”
Local Knowledge in Cyber Crime
4:00 to 5:54
Discover how local hackers leverage insider knowledge for cyber attacks.
“We've had a growing frequency of cyber attacks, right?”
Consequences of Cyber Attacks
5:54 to 6:32
Examine the significant disruptions caused by cyber attacks on major companies.
“at least when you measure it by the disruption it's caused.”
Lessons from Cybersecurity Failures
6:32 to 8:28
Explore key lessons businesses can learn from past cybersecurity incidents.
“a£1.5 billion loan to keep those companies afloat.”
Government's Role in Cybersecurity
8:28 to 10:44
Discuss the potential actions governments can take to combat cybercrime.
“What I think some businesses are learning is that outsourcing core parts of their IT security to the cheapest provider is similarly having a problem.”
Wrap-Up and Conclusion
10:44 to 11:12
Reflect on the key takeaways from the discussion on cybercrime and security.
“versus the subtle thieves who break in, ask for payment and then disappear into the night.”
Counting Deaths in African Conflicts
14:00 to 16:47
Learn about the challenges of accurately counting deaths in African wars and the implications for aid.
“Several things explain why it's especially hard to count the dead in African conflicts.”
The Health Debate on Chocolate
16:47 to 17:49
Explore the complexities of chocolate’s health benefits and the science behind flavanols.
“So for example, Medicines Sans Frontières, a medical charity, didn't publish its mortality survey in Ethiopia's Tigre region for fear that the government would retaliate by restricting access to the region.”
Show all 11 chapters
Understanding Flavanols and Their Sources
17:49 to 22:30
Discover how much flavanols are in chocolate compared to other food sources and their health implications.
“I mean, I think the rule of thumb, as I've understood it, is the darker, the better.”
Transcript
Automatic transcript. May contain errors.0:00You want to get your backyard summer ready, but you don't want to break the bank? Wayfair gets it. Planning on dining al fresco or relaxing poolside? Wayfair has everything you need to prep your space. Shop now and save up to 70 % off during Wayfair's 4th of July clearance. Score huge deals on outdoor furniture, area rugs, and more. We're talking thousands of products for every style and budget. Plus, surprise flash deals July 6th. Don't wait. Shop Wayfair's 4th of July clearance now through July 6th at Wayfair.com. Wayfair, every style, every home. This intelligence podcast is sponsored by Backmarket, the leading global marketplace for refurbished tech.
0:38When the kids need phones, laptops or tablets for school, buying refurbished tech makes sense for families trying to save money without sacrificing quality. At Backmarket, tech costs up to 50 percent less compared to new. All devices have been professionally refurbished and come with a one year warranty and 30 day return policy. Start saving money. Visit Backmarket.com or the Backmarket app to shop now.
1:05The Economist
1:12Hello and welcome to The Intelligence from The Economist. I'm Jason Palmer. And I'm Rosie Bloor. Every weekday, we provide a fresh perspective on the events shaping your world.
1:27As journalists, we analyze data and explain what it means. But our Africa correspondent has a problem. In the countries he reports from, it's getting ever harder to count the number of deaths, and therefore to know what's happening. And you may have heard that dark chocolate is not only better for you than the milky kind, but just good for you full stop. We look at the evidence, and as so often with science and medicine, it's more complicated than that.
2:04But first...
2:12Back in the day, for many businesses, the biggest security concern was having the cash register robbed. But like everyone else, criminals have moved with the times. In its annual review release today, Britain's National Cybersecurity Center says in the past year, highly significant attacks have increased 50%. And it's a worldwide problem. Good evening. It's been more than three weeks since MGM Resorts was hit with that massive cyber attack. Jaguar Land Rover has been hit by a major cyber incident. Today is deadline day for London drugs. Tonight a number of new developments. The retail giant Marks and Spencer.
2:48Cyber security attacks. A cyber security attack. Cyber attack. Companies have proved almost powerless to respond. An attack last month on the Japanese brewer Asahi saw it resorting to taking orders by fax. So what can be done about it? Turning up with a baseball bat gets people to open their wallet. Alex Hearn is a tech correspondent for The Economist. It used to be that if you were a ransomware outfit, you used to do that sneakily. subtly. You would try and worm your way in, you'd install this ransomware, and then you'd wait for the payment. And if you're unlucky, they'd restore from a backup and ignore you.
3:26If you were lucky, you'd take a load of cash in Bitcoin and move on with your day. What's happened recently is the criminal gangs that do this, mostly based in and around Russia, but there's a small but important cohort based here in England, have realized that it's easier to get people to pay up if you don't do it subtly. If rather than sneaking in and lifting data from their stores, you instead just smash their systems up digitally and then demand payment or you'll carry on doing it. So let's just back up for a minute. We've had a growing frequency of cyber attacks, right? Yeah, it's been a real issue since around 2013.
4:08CryptoLocker was one of the first pieces of crypto ransomware, this particular type of malicious software that encrypts data, holds it ransom and demands payment in usually Bitcoin to get the keys. That was a real technological leap and it was enabled because of cryptocurrency. Before then, there had been efforts to build software of that sort, but they fell down in the fact that payments were traceable. If you ask someone to post a check and you'll unencrypt their computer, well, the FBI can follow that bank account quite easily and did in a couple of cases. The rise of cryptocurrency meant that this was a viable business model and we saw an explosion in the software and the gangs that would use it.
4:49But for a while, it was still quite a small like one-on-one thing. The criminal gangs weren't doing big targeted attacks, in part because they were usually based in Russia, didn't really know who they were hacking. What's changed recently is A, there's been a really interesting group of anglophonic hackers who seem to have local knowledge. When we arrest usually quite minor members of them, they're young men, 17 to 20 year olds based in Britain often. They still work with tooling and technology provided by these Russian crime gangs, but they have the local knowledge that lets them pick targets, hit them hard, and then not back down.
5:31Demand payment, not just for releasing the files, but also for actually stepping away from the network and letting the business return to profitable operation. And what are some of the targets they've picked? So recently, we've seen massive crippling hacks on grocers like Co-op and Marks and Spencer's, on Transport for London, and the biggest one we think ever in Jaguar Land Rover, at least when you measure it by the disruption it's caused. So what do you mean by that? Why was it so costly in that situation? Because JLR is a huge company. It employs 31 ,000 people across Britain alone and part of a wider network of suppliers that employs hundreds of thousands of people, largely in Merseyside and the West Midlands.
6:14When its production lines fell silent, all of those companies were impacted. And within weeks, some of them were saying they were nearly folding. And, you know, once a company goes under, it can't just come back when the production lines restart. It could have caused permanent damage to a significant chunk of the British economy. As a result, the UK government felt it had to underwrite a£1.5 billion loan to keep those companies afloat. It's a good example also of the discrepancy here between the money that ransomware companies are operating for and the damage they do. Globally, less than a billion dollars in ransoms were paid to ransomware companies in 2024.
6:50So for a billion dollars everywhere, they're causing one and a half billion pounds worth of damage to one company alone. And they're doing that again and again and again. All crime is value destroying, but this is pretty bad. And what can we learn from those attacks? We can learn that this thief-thug dichotomy seems to be really picking up steam. These are not small attacks. These are not efforts to hold a hard drive hostage and get a small amount of cash. These are deliberately destructive. It's not taking the fact that they have data protection obligations and that they'll be embarrassed if their customer lists leak.
7:27It's using the fact that when these systems are so damaged and so locked up that Marks & Spencer can't run its logistics chain and get fresh food on the shelves. It can't do any click and collect ordering. Jaguar Land Rover has to just shut down the production line because the complex machinery that operates it can't run. So what should companies be doing? It's difficult to say. A lot of businesses did the easy stuff and stared at the hard stuff, be that embedded systems in robotic arms or even things like the room booking screens that companies like The Economist have around the office, and went, oh, maybe we don't have to do that.
8:05And it turns out you do. You have to fix everything because anything can be a way in. The other problem is that, to draw an analogy from the pandemic, We learn when everything went to crap that actually having a little bit of slack in the system is good. Having resilience is good. And that maybe having run parts of society on outsourcing to the cheapest provider didn't work so well when you really needed extra resilience. What I think some businesses are learning is that outsourcing core parts of their IT security to the cheapest provider is similarly having a problem. And it seems like one of the popular ways into ransomware in general is to call a large outsourced IT security hub and just keep going until you find the 40th, 50th call center handler who follows the script the wrong way and hands over credentials when they shouldn't.
8:53That can often be the toehold that an attacker needs to break into the wider network. So perhaps not looking for the cheapest way of running your IT can be one of the things that businesses should learn. It sounds like one of the other lessons is that companies actually can't protect themselves. Can governments help? Should governments help? Governments can help. One of the big things that governments can do is attack this as a supply side problem. Criminal hacking is a business. If the cheapest way of getting your operations back up and running is to pay the criminal, then you will. But as a collective action problem, it sucks because it means that there is a market for this business.
9:30one thing governments can do and it would be a bold move right it would be unusual governments don't like doing this but they could ban the payment of such ransoms in a way that they do in other issues like terrorist financing they could say you are not allowed to fund these people it is a criminal act if you do and you have to stop doing it that will be short-term pain because you need to you know bind yourself to the mast prove to the hackers that you're serious they won't get paid no matter how much damage they do the government would need to work out ways to not take all of that risk on itself.
10:01It would probably need to be happy with some businesses going under rather than paying the ransom. One of the fears of banning the payments is that it could drive this sort of payment underground. I think in practice that's unlikely. Big businesses tend not to actually deliberately break the law. Directors of large companies can be trusted, I think, not to do this. But there's also a case for greater transparency requirements here, forcing people to disclose when they have actually been hacked. Currently, they often drag their feet insofar as they have any legal requirements. They disclose it months or even years down the line.
10:35And if they can get away with it, most businesses don't want to admit they've been hacked at all. So they just cover it up, which means that we have no real sense of how serious this is, how rare these sort of wrecking manoeuvres are that you can't hide versus the subtle thieves who break in, ask for payment and then disappear into the night. Alex, thank you so much. Thanks for having me.
11:11We'll see you next time.
11:25huge deals on outdoor furniture, area rugs, and more. We're talking thousands of products for every style and budget. Plus, surprise flash deals July 6th. Don't wait. Shop Wayfair's 4th of July clearance now through July 6th at Wayfair.com. Wayfair, every style, every home.
11:45One of the things that, to me, captures just how invisible and horrific this war is is that we don't have a credible death count. We literally don't know how many people have died. The number was mentioned earlier, 15 ,000 to 30 ,000. Some think it's at 150 ,000. We are now supporting a couple of efforts to use methodologies to document. That's Tom Perriello, then America's special envoy to Sudan, speaking to Congress in May 2024 about the death toll in Sudan's war. The highest of those numbers, 150 ,000, was the one that stuck. But it was just a guess. Tom Gardner is our Africa correspondent.
12:24It was also a necessary one. Prior to that, the most common death toll cited by media and the UN was 20 ,000. And that was compiled by the Armed Conflict Location and Event Data Project, ACLED. But ACLED only counts fatalities when it has specific data for them, such as media reports. By contrast, a study by the London School of Hygiene and Tropical Medicine found more people had been killed by bombs and bullets in just Khartoum, Sudan's capital, over the same period.
13:02It's not just Sudan. In conflicts across Africa, it is hard, perhaps uniquely hard, to count the dead. And it seems to be getting harder. Take one example. Ethiopia's war in Tigray. Akhled said that at least 5 ,325 people died as a result of direct combat or violence targeting civilians. But the most commonly cited death toll is 600 ,000. That's more than 100 times the accurate estimate. A more recent study, however, put the number killed, including by war-induced hunger and disease, at closer to 102 ,000. All of these tallies, by the way, exclude fatalities outside the region of Tigray. discrepancies like these are commonplace and sometimes can be vast one pioneering study published two decades ago on the second congo war uncovered millions of unrecognized deaths a similar study conducted in the insurgency rack central african republic found that 5.6 percent of the country's people had died in 2022 alone that's the highest number recorded in that year anywhere in the world and up to four times what the UN had previously guessed.
14:25Several things explain why it's especially hard to count the dead in African conflicts. Straightforward body counts rely on media reports and violent deaths. But access to reliable telecoms mean that incidents don't always make the news. In South Sudan, for example, about 85 % of the population is offline because telecoms are ropey, which probably explains why in 2024 ACLA rated Kenya more dangerous than both South Sudan and the Central African Republic.
15:02Mortality estimates that include deaths caused indirectly, for example from hunger or war-induced disease, tend to paint a more accurate picture of a conflict. But these require baseline population data, and those are often absent in Africa. Researchers are often forced to rely on UN surveys, which can be fragmentary and out of date. Measuring excess deaths, that's the number of deaths beyond those expected in any normal year, that requires reliable records. But Africa has the most incomplete death registers of any continent, according to one study.
15:43So why does this matter? Numbers are important. They help encourage aid, which many of these countries urgently need more of. In the early 2000s, for example, the news that 2.5 million could have died in Congo helped spur a big increase in Western aid. Some now fear Africa is entering a new data dark age. Wars are lasting longer. Donors are becoming more weary. There have been obviously significant aid cuts in the past few months alone. America's demographic and health surveys, which produced nationally representative household surveys across the continent, both ended this year. And then compounding the problem, several governments in Africa appear to be becoming more hostile to independent body counts.
16:38That means some outsiders may refrain from publishing their studies or refrain from doing them altogether. So for example, Medicines Sans Frontières, a medical charity, didn't publish its mortality survey in Ethiopia's Tigre region for fear that the government would retaliate by restricting access to the region. This probably, in hindsight, saved lives, but ultimately, we won't ever know how many. www.economist .com
17:37I have a milk chocolate bar. I have one which is 70 % dark. And I've got one which is 100 % dark chocolate bar. And I have a question for you. Which one do you think is best for you? Best for health? I mean, I think the rule of thumb, as I've understood it, is the darker, the better. That seems to be what most people say, just on my informal conversations with colleagues here. And I'm not surprised, to be honest. You've probably seen all these headlines of dark chocolate is very healthy for you. And there is indeed research, but... There's a note of doubt in your voice that suggests you're here to tell me that that rule of thumb is maybe not ironclad.
18:21So when you see a headline saying chocolate is good for you, usually it talks about some study that has been done. And oftentimes it's not a study of chocolate, actually. It may be a study of cocoa extracts or just a diet rich in flavanols, which can come from a variety of plant-based foods. So such studies have often found beneficial effects, for example, their blood pressure, but the results overall have been inconsistent and they're usually quite short. So why isn't that link secure then? If flavanols are in preponderance in chocolate and in the lab, they're good for you in various ways, why shouldn't I make the jump to chocolate's good for me?
19:06For several reasons. First of all, you have no idea how much flavanols a chocolate bar has. It has to do with the processing. It doesn't really say in the label how much flavanols there is in the bar. But the other reason is when you eat chocolate, you're also eating lots of other stuff like sugar and saturated fats. And it's really, really high on those. So if we take, for example, the ultimate randomized control trial on flavanols, where researchers gave people capsules with cocoa extract, which contained 500 milligrams of flavanols. and that's a lot to be able to get that from chocolate. You have to eat anywhere between half a bar, 50 grams, to close to 300 grams, which is three of those big bars of chocolate.
20:04Doesn't sound so bad so far, but carry on. So when they did the trial, they gave people every day a capsule containing this much flavanols in the forms of cocoa extract. And after about three and a half years, those study participants didn't really have massive health benefits. There was no difference in terms of the rate of new cases of diabetes. There was no difference for cancer or cognition. There was, however, a 27 % reduction in deaths from cardiovascular disease, so heart attacks and stroke. So that was one result which says that maybe there is something there. But the suggestion is you'd have to eat so much chocolate that you'd ultimately be doing yourself a different kind of harm.
20:56You can get flavanols from just eating a healthy diet that's rich in fruits and veggies and grains and beans. You don't need to eat chocolate. But do I have to eat a similarly large stroke ridiculous amount of other foods to get those levels of flavanols? Just so I know, if I'm tweaking my diet. Not necessarily. By one calculation, like what are the combinations of things you might eat to get those 500 milligrams that were in the study? One combination is two apples, a portion of nuts and a large serving of strawberries. Or two to three cups of green tea, which is actually also particularly rich in flavanols.
21:38You could also have a salad with certain types of beans and grains. So you don't really need chocolate to get that. I mean, you can still eat it as a treat. I mean, what I brought here just smells delicious. But eating the whole bar or three of them isn't really necessary. Among the three bars you have there, I should probably opt for the darkest possible. That part is at least still true. I don't think so. Again, there's been some research out there testing different types of chocolate and independent studies of all sorts have found that some milk chocolate bars may actually have far more flavanols than some dark chocolate bars.
22:19So I would say just go with whatever you like. Just make sure you eat a little bit and you view it as a treat, not as a healthy food. And next thing you're going to come in here and tell me that my small amounts of red wine and coffee are also bad for me. Oh, I hate these conversations. No, coffee's good, coffee's good, coffee's good. Slavea, thanks very much for your time and pass me, I don't know, you choose which chocolate I may have a little square of the milk actually it smells delicious just a tiny little bit a treat
23:01that's it for this episode of The Intelligence we'll see you back here tomorrow
23:25We'll see you next time.
23:374th of July clearance. Score huge deals on outdoor furniture, area rugs, and more. We're talking thousands of products for every style and budget. Plus, surprise flash deals July 6th. Don't wait. Shop Wayfair's 4th of July clearance now through July 6th at Wayfair.com.
From the publisher
Cyberattacks have brought firms like Jaguar Land Rover and Asahi to a standstill. Our correspondent asks what companies and governments should do about a rising problem. Why it is getting harder to count deaths in Africa. And is eating dark chocolate actually good for you?
Listen to what matters most, from global politics and business to science and technology—Subscribe to Economist Podcasts+
For more information about how to access Economist Podcasts+, please visit our FAQs page or watch our video explaining how to link your account.
Hosted on Acast. See acast.com/privacy for more information.




