# Chris Kubecka

> Mediated Wiki article. Canonical URL: https://mediated.wiki/source/Chris_Kubecka
> Markdown URL: https://mediated.wiki/source/Chris_Kubecka.md
> Source: https://en.wikipedia.org/wiki/Chris_Kubecka
> Source revision: 1356658522
> License: Creative Commons Attribution-ShareAlike 4.0 International (https://creativecommons.org/licenses/by-sa/4.0/)

American computer security researcher

Chris Kubecka Kubecka in 2024 Occupations Author, security researcher, speaker, adviser Employer(s) HypaSec NL, Aramco, Unisys Known for Re-establishing Saudi Aramco international business networks and establishing security after a cyberwarfare attack

**Chris Kubecka** is a Puerto Rican [computer security](/source/Computer_security) researcher and [cyberwarfare](/source/Cyberwarfare) specialist. In 2012, Kubecka was responsible for getting the [Saudi Aramco](/source/Saudi_Aramco) network running again after it was hit by one of the world's most devastating [Shamoon](/source/Shamoon) [cyberattacks](/source/Cyberattacks). Kubecka also helped halt a second wave of [July 2009 cyberattacks](/source/July_2009_cyberattacks) against [South Korea](/source/South_Korea).[1] Kubecka has worked for the [US Air Force](/source/United_States_Air_Force) as a [Loadmaster](/source/Loadmaster), the [United States Space Command](/source/United_States_Space_Command) and is now CEO of HypaSec, a security firm she founded in 2015. She lives and works in the Netherlands.

## Early life

Kubecka’s mother, who was Puerto Rican, worked as a robotics programmer. Due to financial constraints, she often brought Kubecka to her workplace instead of using daycare. Kubecka said she "fell in love with programming" when she programmed a haunted house on the screen to say "boo". At 18, she began working for the [US Air Force](/source/US_Air_Force) as a military aviator.[2][3][4][5]

## Career

Kubecka worked at Saudi Aramco until the mid-2015, before she founded HypaSec.[6] Kubecka is considered an expert on cyberwarfare and has been a keynote speaker at trainings,[7] and conferences on [cyber espionage](/source/Cyber_espionage),[8] [security information and event management](/source/Security_information_and_event_management),[9] [Industrial Control Systems](/source/Industrial_Control_Systems) [Supervisory Control and Data Acquisition](/source/Supervisory_Control_and_Data_Acquisition) (ICS SCADA), IT and IOT security topics.[2][10] Kubecka was the keynote speaker at Security BSides security conference in London in 2017[11][12] and a featured speaker at OWASP's Global AppSec Amsterdam 2019.[13]

## Saudi Aramco security work

In 2012, [Saudi Aramco](/source/Saudi_Aramco)'s network experienced one of the worst hacks in history and Kubecka was then contracted to get the company's systems back up and running. Kubecka explained that the Saudi Aramco network was flat so hackers were able to roll through quickly and infected close to 35,000 of its computers.[14][15][16][17] Facing the emergency and immediately following the hardware attack, Saudi Aramco purchased 50,000 computer [hard disk drives](/source/Hard_disk_drives) (off a production line).[18]

## Cyber terrorism work

In 2014, Kubecka fixed an email and [rootkit](/source/Rootkit) attack on the Royal Saudi Arabian embassy in [The Hague](/source/The_Hague), [Netherlands](/source/Netherlands).[19][20] The first phase of the attack was caused by a weak email password of 123456 used on the official business embassy email. An Embassy [insider](/source/Insider_threat) and [ISIS](/source/Islamic_State_of_Iraq_and_the_Levant) collaborator attempted to [extort](/source/Extortion) money from [Prince Mohammed bin Nawwaf bin Abdulaziz](/source/Mohammed_bin_Nawwaf_bin_Abdulaziz), [Sumaya Alyusuf](https://en.wikipedia.org/w/index.php?title=Sumaya_Alyusuf&action=edit&redlink=1) and from the Royal Saudi Arabian embassy of The Hague. During the second phase of the attack, the insider sent an extortion demand of 25,000 USD each from several Middle Eastern and Turkish embassies. The third phase of the attack was caused by the [Diplomatic Corps](/source/Diplomatic_corps) sending a warning notification to all The Hague embassies via email using CC not BCC, exposing the other official embassy email accounts to the attacker. During the fourth phase of the attack, the insider taunted the Diplomatic Corps, The Hague embassies and hacked into the Secretary to the Ambassador of Saudi Arabia personal Gmail account. The attacker rose the extortion demand to $35,000,000, then to $50,000,000 saying ISIS would destroy the [Kurhaus of Scheveningen](/source/Kurhaus_of_Scheveningen) during the planned National Saudi Day celebrations to which over 400 dignitaries had been invited.[*[citation needed](https://en.wikipedia.org/wiki/Wikipedia:Citation_needed)*]

After the Shamoon attack and Dutch embassy hacks, the Kingdom of Saudi Arabia and Saudi Aramco made security a top priority. Stanford University signed a [memorandum of understanding](/source/Memorandum_of_understanding) with one of the security colleges of Saudi Arabia in 2018.[21][22][23]

## Works

- *Down the Rabbit Hole: An OSINT Journey* (2017). [ISBN](/source/ISBN_(identifier)) [978-0-9956875-4-7](https://en.wikipedia.org/wiki/Special:BookSources/978-0-9956875-4-7)

- *Hack the World with OSINT* (2019). [ISBN](/source/ISBN_(identifier)) [978-0-9956875-9-2](https://en.wikipedia.org/wiki/Special:BookSources/978-0-9956875-9-2)

- *Santa AI 2.0* (2023). [ISBN](/source/ISBN_(identifier)) [978-0-9956875-9-2](https://en.wikipedia.org/wiki/Special:BookSources/978-0-9956875-9-2)

- *How to Hack a Modern Dictatorship with AI: The Digital CIA/OSS Sabotage Manual* (2025). [ISBN](/source/ISBN_(identifier)) [978-19164666-9-2](https://en.wikipedia.org/wiki/Special:BookSources/978-19164666-9-2)[24][25][26]

- *The Drone Wars: OSINT Field Guide to Russian Drone Footage & Verification* (2025). [ISBN](/source/ISBN_(identifier)) [978-17384762-2-0](https://en.wikipedia.org/wiki/Special:BookSources/978-17384762-2-0)[27]

- *The Hacktress Intel Brief: FPV Doctrine: From Swarms to Psychological Warfare* (2025). [ISBN](/source/ISBN_(identifier)) [978-17384762-4-4](https://en.wikipedia.org/wiki/Special:BookSources/978-17384762-4-4)

## References

1. **[^](#cite_ref-PSU_EDU_1-0)** ["PSU@Shamoon"](https://web.archive.org/web/20190722065811/https://sites.psu.edu/psy533wheeler/2019/04/14/saudi-aramco-crisis-and-critical-infrastructure/). sites.psu.edu. Archived from [the original](https://sites.psu.edu/psy533wheeler/2019/04/14/saudi-aramco-crisis-and-critical-infrastructure/) on 2019-07-22. Retrieved 2019-09-07.

1. ^ [***a***](#cite_ref-APPSEC_2-0) [***b***](#cite_ref-APPSEC_2-1) ["APPSEC Cali 2018 - Women In Security Panel"](http://archive.org/details/youtube-56ze8cggM3c). March 19, 2018 – via Internet Archive.

1. **[^](#cite_ref-Interview_with_Paul_3-0)** ["Paul's Security Weekly #498 - Chris Kubecka"](https://www.youtube.com/watch?v=MUORUW9BcIo) – via www.youtube.com.

1. **[^](#cite_ref-Ventures_4-0)** ["How A 10-Year-Old War Dialer Became A Top Cybersecurity Expert"](https://cybersecurityventures.com/how-a-10-year-old-war-dialer-became-a-top-cybersecurity-expert/). July 11, 2019.

1. **[^](#cite_ref-5)** ["About, Chris Kubecka"](https://www.hypasec.com/). *www.hypasec.com*. Retrieved 2026-02-06.

1. **[^](#cite_ref-Ladies_Def_Camp_6-0)** ["Ladies in Cyber Security by DefCamp"](https://ladies.def.camp/speakers.php). *ladies.def.camp*.

1. **[^](#cite_ref-sans_7-0)** ["SANS Institute: Summit Archives"](https://web.archive.org/web/20190926004959/https://www.sans.org/cyber-security-summit/archives/not-found). *sans.org*. Archived from [the original](https://www.sans.org/cyber-security-summit/archives/not-found) on 2019-09-26. Retrieved 2019-09-07.

1. **[^](#cite_ref-auto_8-0)** ["NATO explores the rules of cyber spying"](https://news.sky.com/story/nato-explores-the-rules-of-cyber-spying-10914604). *Sky News*. Retrieved 2019-09-25.

1. **[^](#cite_ref-9)** [*28C3: Security Log Visualization with a Correlation Engine (en)*](https://www.youtube.com/watch?v=P9x7P4dqEEE), retrieved 2019-09-25

1. **[^](#cite_ref-Log_Visualization_10-0)** ["28c3: Security Log Visualization with a Correlation Engine"](https://www.youtube.com/watch?v=j4pF9VUdphc). *[YouTube](/source/YouTube)*. December 29, 2011. Retrieved 2017-11-04.

1. **[^](#cite_ref-11)** ["Cybersecurity pros: We'd help the government, but can't"](https://news.sky.com/story/cybersecurity-pros-wed-help-the-government-but-cant-10909362). *Sky News*.

1. **[^](#cite_ref-12)** ["Naming Russia as a perpetrator offers cybersecurity its #MeToo moment"](https://news.sky.com/story/naming-russia-as-a-perpetrator-offers-cybersecurity-its-metoo-moment-11254385). *Sky News*. Retrieved 2019-09-25.

1. **[^](#cite_ref-13)** ["I've got a working title: The woman who squashed terrorists: When an Embassy gets hacked"](https://ams.globalappsec.org/program/keynotes). *Global AppSec*. Retrieved 2019-09-27.

1. **[^](#cite_ref-Pagliery2015_14-0)** Jose Pagliery (2015-08-05). ["The inside story of the biggest hack in history"](https://web.archive.org/web/20150808020211/http://money.cnn.com/2015/08/05/technology/aramco-hack/index.html). Archived from [the original](https://money.cnn.com/2015/08/05/technology/aramco-hack/index.html) on August 8, 2015. Retrieved 2012-08-19.

1. **[^](#cite_ref-TripWire_15-0)** ["Black Hat USA 2015 Highlights"](https://www.tripwire.com/state-of-security/off-topic/black-hat-2015-highlights/). *The State of Security*. August 11, 2015.

1. **[^](#cite_ref-Tech_Target_16-0)** ["Black Hat 2015: Rebuilding IT security after a cyber disaster"](https://searchsecurity.techtarget.com/news/4500251309/Black-Hat-2015-Rebuilding-IT-security-after-a-cyber-disaster). *searchsecurity.techtarget.com*. 10 February 2016. Retrieved 2019-09-07.

1. **[^](#cite_ref-Darknet_Diaries_17-0)** ["Shamoon – Darknet Diaries"](https://darknetdiaries.com/episode/30/). *darknetdiaries.com*. [Archived](https://web.archive.org/web/20190127150430/https://darknetdiaries.com/episode/30/) from the original on 2019-01-27.

1. **[^](#cite_ref-18)** Pagliery, Jose (August 5, 2015). ["The inside story of the biggest hack in history"](https://web.archive.org/web/20150808020211/http://money.cnn.com/2015/08/05/technology/aramco-hack/index.html). *CNNMoney*. Archived from [the original](https://money.cnn.com/2015/08/05/technology/aramco-hack/index.html) on August 8, 2015.

1. **[^](#cite_ref-19)** ["Extortion and alleged ISIS threats: A Saudi embassy learned the hard way about email security"](https://www.cyberscoop.com/saudi-arabia-email-extortion-chris-kubecka/). *CyberScoop*. August 8, 2019.

1. **[^](#cite_ref-csoonline_20-0)** J.M. Porup (7 August 2019). ["Inside the 2014 hack of a Saudi embassy"](https://www.csoonline.com/article/3386381/inside-the-2014-hack-of-a-saudi-embassy.html). *CSO Online*. Retrieved 2019-09-07.

1. **[^](#cite_ref-spa_21-0)** ["Prince Mohammed bin Salman College of Cybersecurity and Stanford University Sign MoU The official Saudi Press Agency"](https://www.spa.gov.sa/viewfullstory.php?lang=en&newsid=1778091). *spa.gov.sa*. Retrieved 2019-09-07.

1. **[^](#cite_ref-22)** Yang, Daniel; Knowles, Hannah (April 25, 2019). ["Despite political tensions, Stanford's Saudi partnerships continue with little scrutiny"](https://www.stanforddaily.com/2019/04/25/despite-political-tensions-stanfords-saudi-partnerships-continue-with-little-scrutiny/).

1. **[^](#cite_ref-saudigazette_23-0)** ["Prince Muhammed Bin Salman College signs key pact with Stanford University"](http://saudigazette.com.sa/article/537401). *Saudi Gazette*. 23 June 2018. Retrieved 2019-09-07.

1. **[^](#cite_ref-DictatorshipRG_24-0)** Kubecka, Chris (2025). ["How to Hack a Modern Dictatorship With AI: The Digital CIA/OSS Sabotage Manual"](https://www.researchgate.net/publication/391452490_HOW_TO_HACK_A_MODERN_DICTATORSHIP_WITH_AI_THE_DIGITAL_CIAOSS_SABOTAGE_MANUAL_CHRIS_KUBECKA). *ResearchGate*.

1. **[^](#cite_ref-DictatorshipDOI_25-0)** Chris Kubecka (2025). ["How to Hack a Modern Dictatorship with AI: The Digital CIA/OSS Sabotage Manual"](https://doi.org/10.5281/zenodo.15342994). Zenodo. [doi](/source/Doi_(identifier)):[10.5281/zenodo.15342994](https://doi.org/10.5281%2Fzenodo.15342994).

1. **[^](#cite_ref-EuroDIG_26-0)** ["EuroDIG 2025 – WS 08: How AI impacts society and security: opportunities and vulnerabilities"](https://eurodigwiki.org/wiki/How_AI_impacts_society_and_security:_opportunities_and_vulnerabilities_%E2%80%93_WS_08_2025). *EuroDIG Wiki*. European Dialogue on Internet Governance. 13 May 2025.

1. **[^](#cite_ref-DroneWarsRG_27-0)** Kubecka, Chris (2025). ["The Drone Wars: OSINT Field Guide to Russian Drone Footage & Verification"](https://www.researchgate.net/publication/394355297_The_Drone_Wars_OSINT_Field_Guide_to_Russian_Drone_Footage_Verification_A_Field_Intelligence_Handbook_for_Investigators_Journalists_Defenders_in_Conflict_Zones). *ResearchGate*.

## External links

- [Chris Kubecka de Medina](https://medium.com/@SecEvangelism) - [Medium](/source/Medium_(website))

- [Chris Kubecka interviewed on Paul's Security Weekly Episode 498](https://www.youtube.com/watch?v=MUORUW9BcIo)

- [Chris Kubecka answers readers questions on goodreads](https://www.goodreads.com/author/17044584.Chris_Kubecka/questions)

- [How to Start a Cyber War - Lessons from Brussels, by Chris Kubecka (powerpoint on Research Gate)](https://www.researchgate.net/publication/332877673_How_to_Start_a_Cyber_War_-_Lessons_from_Brussels)

---
Adapted from the Wikipedia article [Chris Kubecka](https://en.wikipedia.org/wiki/Chris_Kubecka) by Wikipedia contributors ([contributor history](https://en.wikipedia.org/wiki/Chris_Kubecka?action=history)). Available under [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/). Changes may have been made.
