ÜBER DIESE EPISODE
In episode two of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough continue their conversation with Aaron Turner — this time tracing a surprising parallel between drug cartels and ransomware groups. Aaron was assigned to the US Department of Justice after 9/11 and spent 18 months working with DEA Special Operations Division under Steve Murphy and Javier Peña — the real-life figures behind Netflix's Narcos. He breaks down why both types of criminal organizations are, at their core, transnational, economically rational actors that rely on stolen or assumed identities to operate. The conversation moves from Pablo Escobar's "plata o plomo" model of corrupting trust, to franchise-style scaling that lets sophisticated attackers hide inside the noise of less-skilled affiliates, to Aaron's later work at Idaho National Lab building some of the first cyber-physical attack simulators — and what that taught him about identity segmentation across IT and OT environments. 🎧 Episode Highlights ●[00:02:00] Aaron's near-miss legal career — dropping out of law school after witnessing partners commit fraud, and how that background led to a lawful-intercept role at Microsoft. ●[00:02:54] Post-9/11, Aaron is reassigned to the Department of Justice embedded with DEA Special Operations Division under Steve Murphy and Javier Peña. ●[00:04:13] Shared traits: both cartels and ransomware groups diversify revenue streams and act as rational, opportunistic economic actors. ●[00:04:42] "Plata o plomo" — Pablo Escobar's money-or-a-bullet model, and how both cartels and ransomware operators use stolen or assumed identities to run their operations. ●[00:07:45] The franchise model — how scaling out affiliates creates more noise for sophisticated attackers to hide inside, and why low-governance safe havens matter to both types of criminal enterprise. ●[00:11:06] Founding some of the first cyber-physical attack simulators at Idaho National Lab to explore the boundary between cyber and OT. Work that reinforced the importance of segmenting identities across IT/OT boundaries and exposed the rise of nation-state "bounty" incentives for crossing them. ●[00:15:58] How specialization inside criminal enterprises mirrors the way any growing company divides labor over time. ●[00:17:00] Why growing up in a high-trust, low-risk environment makes people more susceptible to phishing — and how lived experience shapes a defender's instincts. 🔑 Key Takeaways: ●Drug cartels and ransomware groups are structurally similar: both are transnational, economically rational actors that rely on stolen or assumed identities and operate out of low-governance jurisdictions where they're insulated from law enforcement. ●Franchise-style scaling doesn't just grow a criminal enterprise's revenue — it multiplies the noise defenders have to sift through, letting the most sophisticated actors hide their "sniper" attacks inside a flood of low-skill, low-success attempts. ●The most profitable position in either type of network isn't at the edges — it's whoever controls the "last mile." For the cartels, that was the Mexican plazas; for ransomware, it's whoever holds the decryption key. Disrupting that specific choke point matters more than chasing every actor in the chain. 👤 Guest Spotlight Aaron Turner, IANS Faculty Aaron Turner has spent over 30 years in the security industry, starting as an early penetration tester in the 1990s before joining Microsoft, where he spent eight years working across Active Directory, SQL Server, Windows Mobile, and Xbox Live. Early in his Microsoft career, he helped rebuild a national identity platform for Venezuela on NT4 — a project that led Bill Gates to personally recognize him with a "gold star" award in 1999, one of the company's most selective honors at the time. That recognition gave Aaron the freedom to work across some of Microsoft's most foundational identity and security projects during the internet's early enterprise era. He has since founded his own company and continues to research and speak on Identity Security, attacker tradecraft, and the long-term consequences of decisions made in Active Directory's earliest design days. Stay connected https://www.silverfort.com https://www.linkedin.com/in/aaronrturner https://www.linkedin.com/in/rob-ainscough https://www.linkedin.com/in/roy-akerman