Mikko Hypponen Keynote: Three Decades in Cybersecurity

Black Hat USA 2025 · Day 1 · Briefings

Overview

Mikko Hypponen, one of the most recognized figures in cybersecurity, used his Black Hat 2025 keynote as both a historical retrospective and a farewell address — announcing his departure from the cybersecurity industry after 34 years to join a drone defense contractor. Drawing on a career that spans floppy-disk boot sector viruses, ILOVEYOU, Stuxnet, WannaCry, and the ransomware era, he argued that despite daily headlines suggesting otherwise, security is genuinely better today than it has ever been — and that the industry's biggest challenge is making that invisible progress visible. ---

Watch on YouTube

Visual summary for Mikko Hypponen Keynote: Three Decades in Cybersecurity
Visual summary for Mikko Hypponen Keynote: Three Decades in Cybersecurity

Key moments

  1. 6:00 Historical: Brain virus authors (1986) never expected global malware epidemic
  2. 13:59 Nation-state malware authorship now confirmed for Stuxnet, WannaCry, NotPetya
  3. 19:59 WannaCry attributed to North Korea; funded missile program with ransomware proceeds
  4. 27:59 Key prediction: AI will write and deploy malware autonomously within this decade
  5. 36:01 Hypponen's Law: any sufficiently smart device will eventually be compromised
  6. 43:59 Stat: cybercrime economy now exceeds GDP of most nations except top five
  7. 50:00 Russia using criminal ransomware gangs as state proxies with deniability
  8. 56:00 30-year retrospective: defenders now winning at scale but adversaries also scaling with AI

Three Decades in Cybersecurity

Speaker: Mikko Hypponen — Chief Research Officer, WithSecure (departing); Incoming Security Researcher, SensoFusion

Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas

YouTube: https://www.youtube.com/watch?v=H14EhT-DRJ8

Reading time: 7 min

Type: Keynote

TL;DR

Mikko Hypponen, one of the most recognized figures in cybersecurity, used his Black Hat 2025 keynote as both a historical retrospective and a farewell address — announcing his departure from the cybersecurity industry after 34 years to join a drone defense contractor. Drawing on a career that spans floppy-disk boot sector viruses, ILOVEYOU, Stuxnet, WannaCry, and the ransomware era, he argued that despite daily headlines suggesting otherwise, security is genuinely better today than it has ever been — and that the industry's biggest challenge is making that invisible progress visible.

Introduction

Mikko Hypponen joined a small Finnish antivirus startup as a programmer in 1991. Within months, he was reverse-engineering MS-DOS viruses spreading on floppy disks, analyzing what was then the entire universe of known malware — roughly 150 samples — one by one. Thirty-four years later, standing on the Black Hat keynote stage, he used that arc to deliver something rare in the security industry: an optimistic argument, carefully qualified, about how far the field has come.

The talk covered the full history of malware — from teenage pranksters to nation-state weapons to ransomware unicorns — and landed on AI as the next major inflection point. But Hypponen's closing act was the announcement that this keynote marks his final professional engagement as a cybersecurity industry insider. He is leaving WithSecure to join SensoFusion, a defense contractor building drone defense systems, drawing a direct line between fighting programmable threats in cyberspace and fighting programmable threats in airspace.

From Floppy Disks to ILOVEYOU: The Prankster Era

▶ Watch: Early Viruses and the ILOVEYOU Outbreak (18:04)

Hypponen opened with a physical prop: a 3.5-inch floppy disk, introduced to the audience as "what USB thumb drives used to look like in the 1990s." In the early days, viruses were written by teenage boys for no monetary gain. They made no money, had no message, and never became famous. The goal was pranks — animations, music, a walking figure across the screen on a specific date. Despite being more prank than weapon, many caused serious damage to corporate networks, which drove the market for antivirus software.

The most vivid case study was ILOVEYOU, the email worm that Hypponen's company was the first in the world to receive a sample of, at 9:41 AM on May 4, 2000. The worm arrived as an attachment titled "LoveLetterForYou.txt.vbs" — a Visual Basic Script disguised as a text file. Clicking it sent the same email to every contact in the victim's address book. His team spent 48 hours trying to contain it and ultimately failed. ILOVEYOU infected 200 million computers worldwide and remains the largest email worm outbreak in history.

Today, at WithSecure's Helsinki offices, the company has opened the Museum of Malware Art, commemorating outbreaks like ILOVEYOU with original works — including "Click for Love," an installation of computer mice painted pink to form a heart.

The Shift That Changed Everything: Money Enters the Picture

▶ Watch: 2003 — The Year Cybercrime Became a Business (32:06)

Hypponen identified 2003 as the single most important inflection point in cybersecurity history. Two things happened simultaneously: the first money-making malware appeared (spam botnets, banking Trojans, keyloggers for credit card harvesting), and governments were first traced as the source of offensive cyber operations.

Network worms like Blaster (2003) illustrated the pre-hardening era starkly: Windows XP Service Pack 1 shipped with its firewall disabled by default, meaning every Windows machine on the planet was exposing all open ports to the internet. Blaster exploited port 135 TCP, shut down flights and train services, and prompted the U.S. Nuclear Regulatory Commission to issue a warning after the Slammer worm hit nuclear plant internal networks.

By 2005, malware had spread to mobile: Cabir and Comwarrior infected Nokia Symbian phones via Bluetooth, spreading automatically to any device within range. WithSecure built Faraday cage RF labs to safely analyze these wireless threats without risk of escape.

WannaCry, NotPetya, and the Government Malware Era

▶ Watch: WannaCry, NotPetya, and State-Sponsored Ransomware (36:06)

Hypponen drew a clear distinction between criminal ransomware — which maintains brand integrity by decrypting files if paid — and government-authored malware. WannaCry (2017) was North Korea's attempt to collect Bitcoin to address a budget deficit, spread via EternalBlue, an SMB exploit developed by the NSA, stolen, and sold online for 750 Bitcoin before ending up in Pyongyang's hands. It infected hundreds of thousands of machines globally, spreading automatically as a worm — behavior criminal ransomware avoids precisely because it generates unwanted publicity.

NotPetya arrived a month later. Authored by Russian intelligence and targeting Ukraine via the MeDoc accounting software update, it escaped its intended theater of operation and hit global shipping giant Maersk catastrophically. In a video clip shown during the keynote, Maersk's chairman described reinstalling 4,000 new servers, 45,000 PCs, and 2,500 applications. "Everything falls apart around you," Hypponen noted. "None of your tools work. Your computers are crashing. You can't communicate with your teams because your systems are down. It doesn't really matter how much you train and do tabletop exercises when suddenly your team is in a state of shock."

The criminal ransomware ecosystem that followed — LockBit, ALPHV, Conti, and dozens of others — has industrialized around branding, customer service, and affiliate models. Hypponen showed LockBit's dark web victim list live on stage, scrolling through hundreds of targets from every country and industry. "The reason why it looks so random is that it is random," he explained. Attackers find an unpatched VPN server, scan the entire internet for vulnerable instances, and work through the resulting list. It looks like a shotgun blast because it is.

Ransomware's power, Hypponen argued, is fundamentally enabled by cryptocurrency. Bitcoin transformed money into data — programmable, borderless, resistant to legal seizure by design. "Math doesn't care about your laws." Criminal groups like Malone Lam, arrested in September 2024 with multiple Lamborghinis, Ferraris, Rolls Royces, and a Pagani among his seized assets, demonstrate the financial upside that continues to recruit new operators.

Security Is Better Than It's Ever Been (Even If It Doesn't Feel Like It)

▶ Watch: Progress in Security and the Hypponen Law (50:08)

The counterintuitive core of Hypponen's talk was an argument that security has genuinely improved — dramatically — over the past 15 years. He pointed to the elimination of Java and Flash browser plugins that enabled drive-by exploitation via exploit kits like Black Hole. He cited the Hypponen Law — "if it's smart, it's vulnerable," now listed on Wikipedia — while acknowledging the inverse: devices that aren't connected can't be hacked, and the advance of restrictive operating systems like iOS, Android, and ChromeOS has raised the baseline cost of exploitation substantially.

His most pointed example was the Xbox One. Released 12 years ago, the console has never been successfully jailbroken, despite being a Windows computer that owners physically possess and can do anything they want with. "If it costs $100,000 to hack your phone" — as with Pegasus, which is sold exclusively to intelligence agencies at that price point per target — "that's not a security failure. That's a security success story."

He also pushed back on the "user is the weakest link" framing that dominates security awareness culture. "If there's a link that the user must never click, why is the link on the user's computer to begin with? We really should stop putting responsibility on end users who can't handle the responsibility, and put the responsibility to where it belongs." That responsibility, he argued, belongs to the security professionals in the audience.

AI, Cybersecurity Tetris, and the Farewell

▶ Watch: AI, Invisible Success, and Hypponen's Transition (56:10)

On AI, Hypponen was carefully measured. He acknowledged that LLMs have begun discovering zero-days — over the past two years, a couple dozen have been found by language models, compared to zero in 2024 — but noted that all known cases so far have been by researchers, who can then patch the vulnerabilities. When attackers reach that same capability, the calculus changes. "Right now I would claim we are ahead. It will change."

He introduced "cybersecurity Tetris" as a metaphor for the industry's visibility problem: in Tetris, your successes disappear (a complete line vanishes) while your failures pile up. "Rarely is anyone thanked for stopping a disaster that didn't happen." He quoted Ken Keeler: "When you do things right, people won't be sure you've done anything at all."

The keynote closed with a personal announcement: Hypponen has resigned from WithSecure. His notice period ends the following Tuesday. He is joining SensoFusion, a drone defense contractor. Living two hours from the Russian border, he cited the drone-heavy nature of the ongoing war in Ukraine — UAVs, marine drones, ground drones — and drew a direct parallel to his career: "I've been fighting programmable threats all my life, threats which are trying to avoid detection, and we're trying to detect them. That's exactly the same scenario in drone defense."

"I am here because of you," he told the audience. "Thank you for giving me a home for thirty-four years."

Notable Quotes

"In 1991, when I joined Data Fellows, if somebody would have told me that eventually I won't be fighting teenage boys writing boot sector viruses, but that we would be fighting organized online crime gangs making millions, or fighting foreign militaries or intelligence agencies — I wouldn't have believed that. That would have sounded like science fiction."

— Mikko Hypponen [[58:10]](https://www.youtube.com/watch?v=H14EhT-DRJ8&t=3490s)

"If you want to make money with malware and you're on the front page of CNN, you failed."

— Mikko Hypponen [[24:05]](https://www.youtube.com/watch?v=H14EhT-DRJ8&t=1445s)

"If there's a link that the user must never click, why is the link on the user's computer to begin with?"

— Mikko Hypponen [[54:09]](https://www.youtube.com/watch?v=H14EhT-DRJ8&t=3249s)

"When you do things right, people won't be sure you've done anything at all."

— Ken Keeler, quoted by Hypponen [[56:10]](https://www.youtube.com/watch?v=H14EhT-DRJ8&t=3370s)

Key Takeaways

  • 2003 is the hinge year of cybersecurity history. The simultaneous arrival of money-making malware and government-sponsored offensive cyber operations transformed the threat landscape from hobbyist pranks to organized crime and state conflict.
  • WannaCry and NotPetya destroyed the ransomware brand. Both were government-authored malware that failed to deliver decryption keys, undermining the trust model that criminal ransomware gangs had spent years constructing. The lesson: criminal groups are disciplined about not generating front-page news; governments are not.
  • Ransomware is a cryptocurrency story. Bitcoin made extortion scalable, borderless, and legally resistant. As long as programmable money exists and remains difficult to regulate, ransomware economics favor the attacker.
  • Security has improved more than the headlines suggest. The elimination of browser plugins, the hardening of operating systems, restrictive platforms like iOS and ChromeOS, and the rising cost of exploitation (Pegasus at $100,000 per target) are real, measurable gains. The industry needs better frameworks for communicating invisible success.
  • AI is the next era, and defenders currently hold a narrow advantage. LLMs are beginning to discover zero-days and automate attack components, but defenders are ahead — for now. Ransomware groups are already deploying AI for negotiation and targeting. The gap will narrow.

Slides: No slides PDF was listed in the bundle for this keynote.

Reviews

Dr. Zero (Offensive Security Researcher) — ACCEPTABLE

Thirty-four years of Hypponen distilled into one walk down memory lane, and he actually says something true that few people have the nerve to say: security is genuinely better today than it was fifteen years ago. The cybersecurity Tetris metaphor earns its keep. As a farewell keynote it works; as a technical talk it doesn't exist.

Heather Calloway (CISO) — MUST SEE

Mikko Hypponen closed 34 years of security work with an evidence-based argument that defenders are currently ahead on AI, that the threat landscape has become more diverse but not more dangerous, and that 'the user is the weakest link' is a lie invented to excuse our own engineering failures. He is one of a handful of people qualified to make this argument, and he made it with enough specifics to hold up under scrutiny.

→ Top-rated talks at Black Hat USA 2025

All talks from Black Hat USA 2025