Darknet Diaries · Jack Rhysider

Tanya

November 4, 2025·48 min·3 clips
The 'building malware' incident that caused executive panic and employee breakdowns was actually every person in the Canadian government satellite office streaming the Winter Olympics figure skating simultaneously.
1. Darknet Diaries host Jack Recider interviews Tanya Jenka, an application security specialist focused on helping software developers write more secure code. 2. Tanya Jenka is a former software developer based in Ottawa, Canada, who transitioned into application security after a mentor demonstrated an SQL injection attack on her own team's login screen. 3. The episode traces Tanya's career from her first encounter with hacking through to her role as head of security for a Canadian government agency. 4. Tanya's entry into security began when a mentor bypassed her team's login page without a password, telling her 'the only reason it's going to take so long is because I'm talking' — demonstrating that a well-designed interface can still be trivially vulnerable. 5. Her mentor assigned her to watch YouTube videos about Burp Suite over a weekend and begin testing a client website the following Monday, warning her on the third night that she 'needed to find something' and should 'put on her black hat.' 6. On that third night, Tanya accidentally triggered server-side request forgery by typing arbitrary code into a web form's email field, inadvertently copying and deleting files on the production server and polluting the database — both had to be restored from backup. 7. When she called her boss to report the find, he admitted he had lied about watching her remotely, saying 'that's just something I said to make you feel better.' 8. After transitioning into a government security role, Tanya received a Vice Magazine journalist's email informing her that her agency's data was for sale on Pastebin for the Bitcoin equivalent of $48 Canadian dollars. 9. The breach investigation revealed that Tanya's app inventory was incomplete — the vulnerable application was one she had not known she was responsible for securing. 10. The stolen data turned out to be entirely unclassified and publicly available except for internal record ID numbers, leading Tanya to joke to her furious boss that 'the bigger problem is that it's only $48.' 11. A year-long investigation of database logs showed the attacker had been conducting blind SQL injection attacks exclusively on statutory holidays, exploiting the government policy that employees are never on-call on those days. 12. Tanya only understood the blind SQL injection technique after attending a DEF CON workshop where the methodology — asking yes/no questions rather than extracting data directly — was explained for the first time. 13. In another role as leader of incident responders, Tanya arrived to work after a dentist appointment to find a boardroom full of executives and department directors being advised by a Help Desk technician named Dan to evacuate the satellite office due to 'building malware.' 14. Wireshark immediately showed that every device in the satellite office was connecting to the same streaming site: Canada was competing in the Winter Olympics figure skating, and the entire office was watching simultaneously in violation of government streaming policy. 15. The 'malware incident' was the satellite office effectively DDoS-ing its own network — triggered by an executive who had countermanded the official policy allowing a dedicated Olympics viewing room, forcing employees to stream illegally at their desks. 16. Despite Tanya's repeated corrections, the rumor that the satellite building had been infected with malware persisted for six months among staff who preferred the dramatic explanation. 17. The episode also covers a Help Desk cautionary tale from incident manager Eric: a technician who found child sexual abuse material on a company computer deleted all evidence and reformatted the drive before calling incident response, destroying the chain of custody needed for police prosecution. 18. The episode concludes with Tanya's approach to training Help Desk staff: explicitly telling them that there will never be consequences for a false alarm, and that the only wrong action is not calling. 19. Listeners interested in real-world application security stories, incident response, and the human factors behind security failures — including both attacker creativity and defender errors — will find specific, concrete examples throughout. 20. Listeners seeking technical deep-dives into offensive security tooling or detailed exploit methodology may find the episode more narrative and character-driven than technical.

As heard by us

A patient Darknet Diaries case about SQL injection, database logs, and Tanya noticing the strange pattern inside the noise.

Darknet Diaries' "Tanya" starts in the dry world of corporate security policy, then slides into the kind of case this show does best: an investigation built from logs, small anomalies, and one person refusing to shrug off a pattern that feels wrong.

Read the full review in PlayNext →

Why you'd press play

A security engineering story turns a strange SQL injection into a true-or-false database puzzle.

Read the full recommendation in PlayNext →
Listen to the show on