Theme 1: Skepticism about attribution and possible scapegoating
- “I would be inclined to doubt it based on the history of the group. Its more likely he is just a fall guy” – vablings
- “I wouldn't leap to the conclusion that they have the right people; I would wait for evidence. They seem to have found them with incredible speed - how often has an attack been resolved this quickly? It would not be the first time the wrong person was arrested (and smeared) in a high pressure situation.” – mmooss
- “A Jordanian teen is behind ShinyHunters? I don't know if this is impressive or just a sad commentary on the state of security at the organizations they ransomed.” – SoftTalker
Theme 2: Critique of modern security as superficial/check‑box and reactive
- “I think more modern security is an "emperor has no clothes" situation than people think. The LLMs are gonna have a field day.” – ocdtrekkie
- “Outside of a few cases, it's always been a box checking exercise. If you're fortunate, the boxes are kept up to date / written by somebody that knows what they're doing. If you're like most, the box hasn't changed since the 90s when "complex passwords, changed quarterly" was in vogue.” – baby_souffle
- “Companies always prioritize features/capabilities up until shit starts hitting the fan, but even then the culture and requirements makes everything just a job of trying to patch a sinking ship if you're lucky.” – whizzter
Theme 3: Discussion of the group’s self‑imposed rules of engagement and geopolitical constraints
- “yeah otherwise why would their rules forbid targeting PRC/DPRK/Russia/Belarus companies but not Jordan…” – ShinyLeftPad
- “interesting "rules of engagement" they have, including "no PRC companies"!” – trhway
- “including "no PRC companies" It could be practical.” – JumpCrisscross