In short
Tech Life Podcast Episode Notes: Dealing with Cyber Attacks
Episode Overview
- Podcast Title: Tech Life
- Episode Title: Dealing with Cyber Attacks
- Presenter: Zoe Kleinman
- Producer: Tom Quinn
- Editor: Monica Soriano
- Air Date: [Insert Date]
Description This episode explores the rising cyber threats in Singapore, particularly an ongoing cyber attack targeting the nation’s critical infrastructure. It features an interview with David Coe, Singapore's Commissioner of Cybersecurity. Additionally, the episode delves into a peculiar story involving a synthetic band and a personal tech adventure involving social media and a metal detectorist.
---
Key Discussions
- Cyber Attacks in Singapore
- Date of Incident: July 18, [Insert Year]
- Key Figure: Keishun Mugam, Minister for Home and Security
- Threat Actor Identified: UNC 3886 (linked to state-sponsored activity, likely from China)
Significance of the Minister's Speech
- Unprecedented Transparency:
- Acknowledged targeting of critical information infrastructure.
- Named the threat actor publicly for the first time.
Importance of Critical Infrastructure
- Services at Risk:
- Water supply
- Power supplies
- Telecommunications
- Hospital and emergency services
- Transportation (air, land, seaport)
Perception of Cybersecurity in Singapore
- Public Awareness:
- Aiming to inform citizens about the seriousness of cyber threats despite the country’s physical safety.
- Characteristics of Cyber Threats
- Advanced Persistent Threats (APTs):
- Highly sophisticated, state-sponsored cyber actors.
- Motivations can be state-directed or financially driven.
Trends in Cybersecurity
- Ransomware Growth:
- Ransomware is a business ecosystem, evolving with better technology and techniques.
- Collaboration between nations (UK and Singapore) to tackle the financial flow of ransomware.
- The Velvet Sundown Controversy
- Synthetic Band:
- Gained popularity on Spotify.
- Initial media coverage highlighted the bizarre nature of a potentially fake band.
The Hoax
- Andrew Fralon:
- Fake spokesperson who claimed the band wasn’t AI-generated, leading to widespread media frenzy.
- Tim Boucher:
- The true identity behind the hoax, who aimed to challenge perceptions of authenticity in the digital age.
The Nature of Truth in Digital Media
- Cultural Implications:
- Discussion on how easy it is to be misled in an age of AI-generated content.
- Call to strengthen public scrutiny and critical thinking about digital content.
- Personal Tech Adventure: Lost Ring
- Zoe Kleinman's Experience:
- Lost a sentimental family ring while at the beach.
Community Response
- Social Media Rescue:
- A Facebook SOS led to Doug Hamlin, a metal detectorist, successfully locating the lost ring.
Doug's Perspective
- Motivation for Helping:
- Enjoyment of detecting and personal satisfaction in aiding others.
---
Key Takeaways
- Cybersecurity Threats: Cyber threats are increasingly sophisticated, requiring transparency and public awareness.
- Authenticity in Media: The Velvet Sundown story illustrates the challenges of identifying truth in the digital landscape.
- Community Connectivity: Social media can effectively mobilize community support and resources in times of need.
Closing
For further discussions or listener feedback, contact
- Email: techlife@bbc.co.uk
- WhatsApp: +44 330 1230 320
---
Note: This episode highlights the intersection of technology and daily life, showcasing both the risks and community benefits of modern tech.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Welcome to Tech Life on the BBC World Service, the programme about technology and how it touches all our lives. I'm Zoe Kleinman. This week, I speak to the man who's leading Singapore's fight against international cyber attackers. We'll have more on that in a moment. Also in today's edition, we hear from the hoaxer who stirred up a reality-blurring controversy about the AI band Velvet Sundown. And I'll tell you about how social media and a man with a metal detector saved my day. It was good that you knew roughly what area it was in. and just by chance I happened to do a couple of sweeps and hit the right spot straight away.
0:58We start today in Singapore. On the 18th of July, the city-state's Home and Security Minister revealed a cyber attack was underway, targeting critical infrastructure. This is how it was reported on the BBC World Service at the time. Singapore says it's dealing with a serious and ongoing cyber attack against its critical infrastructure. The city-state's Home and Security Minister, Keishun Mugam, maimed the perpetrator as UNC 3886. He said efforts were underway to combat the assault. The cyber espionage group is allegedly linked to China, though Beijing insists it opposes such practices. The minister delivered the information in a speech he made marking the 10th anniversary of the Cyber Security Agency of Singapore.
1:42Only a few weeks earlier, David Coe, the agency's chief executive and the country's first commissioner of cyber security, was at Chatham House in London discussing security challenges in the Asia-Pacific region. Well, I've been speaking to David Coe in Singapore about those challenges and the cyber attack and I began by asking him about the significance of that speech. In the speech, Minister Shah Mugum made an unprecedented by Singapore standards decision to firstly speak about a certain class of cyber threat actors. And these are APTs, Advanced Persistent Threat Actors. They are highly sophisticated and typically are state sponsored.
2:26So they don't typically work for criminal game, but rather operate on state intentions. Second, he made the unprecedented announcement that Singapore's critical information infrastructure was under attack. And third, he made a decision to identify the threat actor. And this is UNC 3886. But what he didn't say was what many experts believe, which is that the group is linked to China. Indeed, I think this is a calibrated decision on our part. We have made the decision that the situation is serious enough that we want to inform our domestic public that this indeed is what is happening. As you're well familiar, Singapore is a peaceful place.
3:22And I think on the surface, in the physical world, it is safe and secure. And the decision is that we want to tell our public that while in the physical world, it may be safe and secure, the reality is in the cyber world, these things are indeed happening. Secondly, we want to tell our domestic public that it is serious enough because our critical infrastructure, which is responsible for providing essential services to Singapore and Singaporeans, is being targeted. And in the worst case, the services which we depend on could potentially be disrupted. And that would cause significant inconvenience to Singapore and Singaporeans and potentially form a national security threat as well.
4:11Can you just give me a couple of examples of what could be knocked out if they succeeded? Critical infrastructure would include things like water, power supplies, telecommunications, hospital services, emergency services, air transportation, land transportation, our seaport, government services, etc. So advanced persistent threat actors might target critical infrastructure for a variety of reasons. For example, they might go after the information that is contained in the critical information infrastructure owners systems. These could include databases of customers, citizens, personal data, credit card information, etc.
5:00And we should say that while experts are linking this group with China, the Chinese embassy in Singapore has asked for evidence of a Chinese link. And it says that China is firmly against any form of cyber attack. Is naming and shaming cyber attackers in this dramatic style a new tactic from Singapore? Yes and no. Other countries have actually also identified and attributed cyber attacks. Some countries have gone so far as to not just name the technical threat actors, but linked it explicitly to states. So country A may say that country B has been attacking our system or country C has been responsible for this data theft in our companies, etc.
5:53We have made a decision not to do that, rather to name the threat actor. We were silent on whom the threat actor works for and whether there is any particular link to a state. Some commentators, as you have pointed out, have made the link. We have no comment on that. You trade with all of your neighbours, including China. This is quite complicated, isn't it, if you're also experiencing cybersecurity threats from them? We trade with all our neighbours. And I would say that increasingly in this fraught geopolitical environment that we operate in, it is indeed true that things are becoming more complicated and, in fact, complex.
6:44I think the world is now at an inflection point. Global institutions are getting weaker and the international norms and the rules-based international order is eroding. Exactly what form a new order might take is unclear. But what is clear right now is that the situation has changed. The rules-based international order that we were familiar with in the last couple of decades, post-World War II, has eroded significantly. This effect is impacting different domains, and cyberspace is no different. So it indeed is rippling through cyberspace, as it were. It's clear to me as geopolitical tensions intensify, cyber threats will similarly intensify.
7:33So we see the situation in Singapore in the last four years, for example. Our records show that well-equipped, advanced, persistent threat actors, the activities of which in our systems has gone up by more than four times in the last four years. And is it state-sponsored activity or is it individuals or is it criminal gangs or is it all of them? It's a great question. What is clear to us is that these are activity linked to advanced, persistent threat actors. We have taken criminal activity out of this particular statistic, and this is just the, as it were, the higher-end threat actors. As to what their motivations are, some of them may be state actors.
8:19Some of them may be loosely controlled by the state. Some may be perhaps moonlighting. They might be working with the state in some circumstances, but then they're moonlighting and perhaps targeting some enterprise for criminal or financial gain on the side, as it were. So the exact circumstances under which they operate are not always that clear. It's a bit murky because the lines between criminal activity, sanctioned, unsanctioned activity or state directed activity is not always 100 percent clear. Here in the UK, we've had some big headlines over the last couple of years, but very recently as well regarding ransomware, which has massively been on the rise here.
9:08Is that a problem for you in Singapore too? It is a common problem. One of the big challenges with ransomware is that it is not a technical issue. It's actually a business. So it is an entire business ecosystem which has developed and the profits from this business are being plowed back into R &D, as it were, of the technical capabilities, attracting new entrants into the field. It's the money flows which are fueling this. So one of the efforts which the UK and Singapore are working together is to try to link the money flows together with the operational and technical law enforcement elements to it.
9:56The second element of ransomware is that it is by definition, and all cyber issues are by definition, borderless. So the criminals are typically not coming from within our borders. So it behooves us, therefore, on the defender side to try to coordinate, have intergovernment coordination and cooperation in order to defeat the bad guys, as it were. That's David Coe, the chief executive of the Cybersecurity Agency of Singapore and the country's commissioner of cybersecurity.
10:38You're listening to Tech Life on the BBC World Service with me, Zoe Kleinman. Thanks to everyone who's contacted us since last week's show. Greg Powell emails after hearing our item on what happened to DeepSeek six months from its launch. Greg's a big fan of DeepSeek. He says, I felt compelled to write in because I only use DeepSeek when needing AI assistance. Greg also reckons more people use DeepSeek than we think. Let me say hello to Kuda Kwashe in Zimbabwe. Kuda Kwashe has been a fan of our podcast for years. Thank you. And writes, Since 2008, I've been using the Opera mini browser on my mobile phone to download BBC World Service podcasts.
11:15Its data-saving features have been a game-changer for me and many others in Africa. Thank you, Kida Kwashe, and I should probably add that other browsers are also available. Now, for the last few weeks, we've been inviting you to tell us about your mini adventures with tech. Tech Live listener Martinus, who lives in Vilnius in Lithuania, sent us a WhatsApp voice note. As you'll hear, his mini-adventure is all about computer operating systems and taking inspiration from AI. In October this year, there's a coming deadline when Windows 10 is not going to be supported. I have an old PC with Windows 10.
11:51And I started thinking, what can I do with this PC? I asked this question, artificial intelligence. and this way I came up with an idea to install Chrome OS Flex, an operation system for old PCs. Now I can prolong my old PC's life. Smart thinking, Martinus. Thank you for sharing that with us. I'm glad you found a solution to your problem. A little later in the program, I'm going to share with you my own mini-adventure with tech. I'll give you a clue. It involves a ring, Facebook and a metal detector. you'll have to stay listening. If you want to share your mini adventure with tech or tell us anything else you think we should know you can email us techlife at bbc.co.uk that's our email address or you can send us a voice note or message on whatsapp the number is plus 44 330 1230 320 remember to include your name and where you live and I'll repeat those contact details at the end of the show.
13:00If you like your music, you might have heard about this. A month ago, a new band racking up hundreds of thousands of streams on Spotify hit the headlines. If you've been on Spotify recently, you might have seen a band called The Velvet Sundown on your feed. There are what appear to be AI-generated pictures of the group. They're a 70s rock-flavoured band blowing up with over a million streams online. I mean, catch is they're not real, are they? That was News 10 in Australia, CTV in Canada and France 24 reporting along with dozens of other media outlets on a band called The Velvet Sundown. We'd love to play you a bit of their music, but the complexities of music rights mean we can't.
13:43It's basically 1960s and 70s inspired American rock and roll. If you imagine Crosby, Stills and Nash mixed with The Grateful Dead, you'll kind of get the idea. The story of the Velvet Sundown started off as a row about whether what many saw as a fake band with AI-generated music and images should be getting hundreds of thousands of streams on Spotify. But then a man claiming to be a spokesperson for the Velvet Sundown started giving interviews under the name Andrew Fralon. And the story grew into something even weirder, something that asks us to think about how to differentiate truth and falsehood in the digital age.
14:19TechLife's Chris Vallance has been looking into what happened. Yes, early in July, I figured out who Andrew Fralon really was. Well, now he's revealed who he actually is. And he's got a lot to say about AI, misinformation, and why he chose to hoax the media as a fake spokesperson for a synthetic band. My name is Tim Boucher. I live outside of Quebec City. For the last 10 years, I've worked in what we call online trust and safety, and that involves thinking through problems that come about from user-generated content and having to do content moderation, write policy, enforce policy. And then on the other side, I am an artist and author, and I've been using AI pretty significantly for, I guess, probably about three years now.
15:07I've used AI to write or sort of co-author and illustrate a bunch of short e-books, around 125, I think, is my last count. Tim's projects bend and blur reality. Previously, he's hoaxed the art world. And as we were about to discuss, recently, he hoaxed the media, pretending to be the spokesperson for the Velvet Sundown. So can we trust anything, he says? You know, I've gone through this a lot. And what can I do to tell people that I'm telling the truth? You know, like, should I make some kind of like sworn affirmation, you know, on a Bible? Should I get a notary to sign a letter? You know, like it's what brought me into the story of Velvet Sundown is this idea of what are really the signals of authenticity and how can we validate them?
15:58So is there an element of sort of caveat emptor with this interview? Buyer beware, form your own view. I think everyone should always be highly sceptical and critical and think through things and try to find proof. But at the same time, I will give you the sworn affirmation, you know, with my hand in the air, that the things I'm telling are true to the best of my knowledge and ability to tell the truth, you know. So how did Tim come up with the idea to build a hoax around the Velvet Sundown? It began, he says, at the end of June when he spotted coverage of the controversy around this seemingly AI band that was taking off on Spotify.
16:37When I saw that, the first thing I saw in an article was that there was not a shred of evidence that someone was saying to support that this band was human. So I had the mischievous idea of what if I created shreds of evidence, you know? I had an old unused Twitter account and changed the username to velvet underscore sundown. And because I did that before the band ever was on Twitter, I started getting followers very quickly. Posing as the band's social media channel, he started criticising journalists for not approaching the band for comment. And he also started denying what everyone thought was true.
17:17My story in the beginning was that we're not AI generated. And this was something that was really driving people crazy on Twitter because it was so clearly AI generated. You know, like all the images are clearly AI generated. The music sounds AI generated. The text sounds AI generated. but on Twitter I kept being like we're not AI generated we're not AI generated just because I know that that's like that's how you make people crazy is by saying the opposite of something that's obviously true. Having stoked that anger Tim decided it was time for a plot twist and in an interview with Rolling Stone under the persona of Andrew Freeland band spokesperson he confessed the Velvet Sundown was an AI powered art hoax.
17:57It was a good scoop for the Rolling Stone but it was short-lived. Not long after, Andrew Freeland confessed again. He was gaming the media. He didn't have anything to do with the Velvet Sundown. And I wrote this kind of like tell-all confession on Medium as Andrew Freeland. And, you know, I admitted that, you know, I'm not part of the band. I'm not associated with them. I don't, I'm not part of the process, all this stuff. But who was Andrew Freeland? With a bit of online sleuthing, I'd figured out his identity shortly after that post. But a couple of weeks later, Tim outed himself and explained why he'd done it all.
18:37You revealed your own identity as Andrew Freeland in a blog post. And there's a kind of summation of why you did all this in that article. Yeah. And you talk about the sheer and utter collapse of reality. Tell me about that. Well, I mean, I think it's easy to see on one hand, you know, it's like when everyone is on their phone or their computer almost all day long, every day, it's becoming increasingly easy for us to be misled. But now that we have AI that can make photos and video and audio of basically anything, in my view, we're kind of in a free fall. So part of what I've aimed for is just to like, how can we reach people where they are and show and expose these tricks and these techniques in the wild and sort of trigger the cultural immune system with the hopes of fortifying it.
19:40and giving people the tools and the motivation to go out and be like, look, I did some research and this is fake, or I didn't find any proof, or things like that. So that's Tim Boucher. But of course, there's still the big question, Chris, who actually are the Velvet Sundown? Yes, that is the million dollar question. Well, the band now admit they're AI. But as to who created them, the short answer is we still don't know. Spotify might, but they aren't saying anything. Tim Boucher says he's still trying to figure out who's behind it. He denies it's him. But he's experimented with AI in the past.
20:15And on his blog, you can read about a failed effort to use AI to generate pictures and music of a Canadian hairband called Synonym. A really big hoax would fit his modus operandi, wouldn't it? This is what he said when I put that to him. It does fit my modus operandi. And when I saw it put together, I was just like, oh my god I wish that I had done this I wish that I was responsible I'm not I'm not responsible we've talked about like how do you prove a negative you know like how do I prove to someone that I that I'm not part of this band and if it were me I think I would benefit a lot by unmasking myself as the real person behind the band I've not done that because it's not me Tim Boucher there speaking with his hand raised so you know he's telling the truth Hmm, I hope so.
21:04Thank you so much, Chris Valance.
21:09A little earlier, I promised to tell you my own mini adventure with tech. I recently went swimming in the sea off Swanage, a town on the south coast of the UK. I took off my jewellery and I put it all in my sunglasses case. But when I later put everything back on, something was missing. It was my grandmother's wedding ring, which I've worn ever since she died 35 years ago. My dad, her Her son, who is also no longer with us, had given it to me. I was in bits. I really thought it had gone. I thought it was lost in the sand somewhere and that was it. Luckily, my sister put out an old school SOS appeal for help on the local Facebook group.
21:46And within minutes, a lovely man arrived on the beach with a metal detector. His name was Doug Hamlin and he managed to find the ring for me. Doug was also kind enough to agree to be interviewed by me about this mini adventure with tech. And there was only one way I could begin. well first of all Doug thank you so much for answering my sister's SOS on Facebook and saving the day for me that's no problem it's always a pleasure to help people home was it a coincidence that you spotted her message I mean it was such a lovely day that day I'm surprised that you weren't in the sea as well or you know off doing something well I was just about to light the barbecue up and before I let the barbecue I had a quick look at the phone and we'd get a terrible signal there but for some reason the message popped in that I've been tagged on Facebook for a lost ring.
22:35Was it easy to find the ring? It was good that you knew roughly what area it was in and just by chance I happened to do a couple of sweeps and hit the right spot straight away. Were you confident? Did you think you'd get it? With a small area like that to search it was always a good good chance and also that no one else had had the chance to go and look for it in the evening or not look for it but just you get some detector as they comb the beach there and just pocket anything they find so it was good that I could get out there quickly. Do you do a lot of this sort of thing? In about the last six weeks I've probably recovered six different very sentimental items for people.
23:21This time of year, you tend to get more people that are losing stuff. I've done a few over the years, but this is the best result over the last six weeks. What sort of stuff do you tend to find? Is it always jewellery? A lot of the time, yes, it's jewellery. One of them was a car key for a couple that had lost their car key. We think the little one had thrown it in the sea and it had washed back in. So that That was lucky. But it still actually worked when they put it in the car. Oh, it still worked? They were very lucky then. It certainly was. Why do you do it? I mean, I would love to be able to say thank you, but you told me to just pay it forward, didn't you?
24:01Yes, yes. I do the detecting because I enjoy it. It helps me relax. But if I can do something like this to return, it doesn't matter if it's copper band. It's just that sentimental value is worth so much to people. And if I can put a smile on somebody's face, it's a good day. Are you on Facebook a lot? Because, you know, there's a sort of sense that people aren't really using Facebook anymore. And yeah, it really saved the day, certainly for me, didn't it? Yeah, the Swanage Matters Facebook page and the Swanage page, if somebody does lose something, they usually post on there. And then a lot of the times I do get tagged now.
24:38So I keep my eye out. And yeah, if I can come down, if I'm available, then yeah, it's great. I'm always here to help. this feels like it could be a business idea it could be but i'd much rather get the uh payment from the people's smiles can i just ask you a question about your metal detector what what is it how long have you had it what make is it um it's a deus two and that was only the second time i had used that one oh it's a brand new one yes yeah i just upgraded on the wednesday i had uh just had a try just to see what sort of signs we got from different metals and then on the Saturday that was the first first sort of action with it in anger well I feel very fortunate to have given it a decent test run for you and I'm really very grateful that that ring is back on my finger because it meant a great deal to me thank you yeah I'm so glad to get it back on there for you and that was Doug Hamlin with his metal detector saving the day for me
25:48Well, I hope you liked my seaside mini-adventure with tech. If you have your own mini-adventure to tell, it doesn't have to be big. It could be something as simple as finding your lost luggage with a little tracker device. We want to hear about it. Email techlife at bbc.co.uk or WhatsApp us on plus 44 330 1230 320. Please include your name and where you live. Today's show was produced by Tom Quinn edited by Monica Soriano and presented by me, Zoe Kleinman
From the publisher
Singapore is experiencing an increase in cyber threats, and its critical infrastructure was targeted in a cyber attack. We speak to the country's Commissioner of Cybersecurity.
Also in Tech Life this week: we hear the real voice of a fake spokesperson for a synthetic band. And presenter Zoe Kleinman has a mini tech adventure involving social media and a metal detectorist.
You can contact us by emailing techlife@bbc.co.uk or send us a Whatsapp message or voice memo on +44 330 1230 320. Please include your name and where you live.
Presenter: Zoe Kleinman Producer: Tom Quinn Editor: Monica Soriano
Image: Hands are held over a computer keyboard as screens display computer data. Credit: Getty Images.




