This Is How They Tell Me the World Ends
The Cyberweapons Arms Race
by Nicole Perlroth2021Bloomsbury Publishing
Nicole Perlroth spent a decade covering cybersecurity for the New York Times, and this book is her account of the market she watched grow up in the shadows — the trade in software vulnerabilities that governments buy to break into phones, power grids, and everything in between. It reads as reportage: hundreds of interviews with hackers, brokers, spies, and officials, stitched into a narrative history of how the United States armed itself with digital weapons and then lost control of them.
The central argument is that Washington helped invent a market it can no longer contain. When agencies like the NSA started paying hackers for zero-day exploits — flaws unknown to the software vendor — they turned bugs into a commodity. Prices rose. Buyers multiplied. What began as a quiet American procurement programme became a global bazaar in which Russia, China, North Korea, Iran, the UAE, and a long list of private brokers now compete for the same tools. The tools leaked, were copied, were turned back on their inventors, and eventually against hospitals, city governments, and pipelines.
Perlroth walks through the specific episodes that shaped this world. She traces the origins of the market through figures like the Argentine hacker known as the Grugq and the boutique broker Zerodium, and through firms such as Vupen and the Italian outfit Hacking Team. She reconstructs Stuxnet — the joint US-Israeli operation that damaged Iranian centrifuges at Natanz — and follows the fallout into Iran’s retaliatory attacks on Saudi Aramco and American banks. She details the Shadow Brokers leak that dumped NSA exploits online, and how those tools powered WannaCry and NotPetya, the latter of which crippled Maersk and inflicted roughly ten billion dollars in global damage. Later chapters cover Russian intrusions into US electric utilities, the SolarWinds compromise, and the targeting of American state and county election infrastructure in 2016 and beyond. Throughout, she keeps the human scale in view: the researchers who sell to governments and the ones who refuse, and the vendors caught between defending customers and cooperating with intelligence agencies.
The book sits alongside works like Andy Greenberg’s Sandworm and Kim Zetter’s Countdown to Zero Day, but Perlroth’s angle is the marketplace itself — how vulnerabilities are priced, brokered, hoarded, and eventually weaponised — rather than any single operation. It is useful for readers trying to understand why offensive cyber capability has proliferated so fast, why defence keeps losing ground, and why an American strategy built around stockpiling flaws has left the country’s own critical infrastructure exposed. For anyone tracking the intersection of software, statecraft, and modern conflict, it is one of the clearer maps of how the current arms race actually works.
Read the longer summary
Nicole Perlroth spent a decade as the lead cybersecurity reporter at The New York Times, breaking stories on Chinese intrusions into American newsrooms, North Korean strikes at Sony, Russian operations against the 2016 election, and the leaks that exposed the National Security Agency’s own arsenal to the world. This Is How They Tell Me the World Ends, published in February 2021 by Bloomsbury, is the book she wrote when she stopped filing daily copy long enough to argue that the individual stories added up to something the field had been slow to say out loud: the United States had, over three decades, quietly built a global market for offensive cyberweapons, become its largest customer, lost control of parts of its own stockpile, and left the country that pioneered digital-network warfare among the least prepared to be hit back. The book landed in the immediate aftermath of the SolarWinds compromise, in which Russian intelligence services rode a trusted software update into the U.S. Treasury, State, Homeland Security, Commerce, Energy, and a large share of the Fortune 500. That timing gave the argument an unusual force. Perlroth had been trying to warn readers for years; the newspaper of record had put those warnings deep on the page. The book was a chance to say it once at length, in a form policymakers were more likely to finish.
The core argument runs on two rails. The first is that the market for zero-day exploits — flaws in commercial software that even the vendor does not yet know about, sold to whoever can pay — was not an inevitable feature of the internet. It was built. In the late 1990s and early 2000s, a handful of American brokers, mostly former hackers and defense contractors, discovered that intelligence agencies would pay six and eventually seven figures for a reliable way into a common piece of software. The NSA, and later the CIA and every peer service that could afford the entry fee, became the anchor buyers. As long as the customers were friendly Western services, the industry had a rationale it could live with. Over time the buyer base widened to include the Emiratis, the Saudis, the Turks, the Mexicans, and eventually anyone with cash and a story about counterterrorism, and the same flaws that let American operators into a Chinese network let a Gulf state read a dissident’s WhatsApp. The second rail is that offense pulled ahead of defense inside the American system itself. The NSA’s Tailored Access Operations unit, in Perlroth’s telling, was the crown jewel of American intelligence — extraordinary at breaking in, and structurally incentivised to keep its finds secret from the American companies whose products contained the flaws. That trade-off was tolerable while the vulnerabilities stayed in Fort Meade’s vault. It stopped being tolerable in 2016 and 2017, when a group calling itself the Shadow Brokers began dumping the agency’s tools onto the open internet, and hostile services turned them into the raw material of the largest ransomware and wiper attacks the world had yet seen.
The book is organised into seven parts, each a stage in that arc. It opens in Ukraine, where Perlroth uses the December 2015 and December 2016 attacks on the country’s power grid to establish the stakes: a nation-state now had the reach to turn off the lights in a foreign capital in winter, and had chosen to demonstrate the capability rather than hide it. From there the narrative loops back to the beginning of the exploit market — a set of chapters titled around the mission, the capitalists, the spies, the mercenaries, the resistance, the twister, and finally the boomerang. Each part is anchored by scenes and interviews Perlroth conducted personally, often with people who had never spoken on the record about what they built. The book closes back where it started, with the same power grids and the same American critical infrastructure, and asks the question its title gestures at: when the people who understand the system best say the world ends this way, why is so little changing.
The concrete material is the strongest part of the book, and it is where a reader with only a headline-level familiarity with the field will learn the most. Perlroth walks through the origin of the modern exploit trade in the work of a small circle of Argentine and Eastern European hackers who realised in the late 1990s that a working remote-code-execution bug in Microsoft Windows or Internet Explorer could be sold once to a Western agency for more money than a year of legitimate security work. She profiles the American brokers who made that market — figures like the founders of iDefense and the later, more openly commercial operations at Endgame and Immunity — and the French firm VUPEN, later rebranded as Zerodium under Chaouki Bekrar, that turned the auction of iPhone jailbreaks into a public price list. She reports the interior culture of the NSA’s TAO, including the career of James Gosler, one of the small number of people credited with teaching American intelligence how to write offensive code, and the awkward, only-partly-honoured Vulnerabilities Equities Process by which the U.S. government was supposed to decide when to tell Microsoft or Apple about a flaw and when to keep it. She retells the Stuxnet operation against the Natanz enrichment plant, and — more usefully — she treats it not as an isolated marvel but as the moment other governments realised the ceiling had moved and began recruiting for it.
Then the boomerang. The Shadow Brokers leaks, whose provenance remains contested but which almost everyone in the field now traces at least in part to Russian intelligence, put working NSA exploits, including the Windows SMB flaw called EternalBlue, into the hands of criminal groups and North Korean and Russian state operators. WannaCry, launched by North Korea in May 2017, took down parts of the British National Health Service and stopped car plants in Japan and rail networks in Germany. NotPetya, launched by Russia’s GRU a month later against Ukraine, spread past its intended target and cost Maersk, Merck, FedEx’s TNT subsidiary, and Mondelez billions of dollars in a single afternoon; Perlroth is precise about how a wiper disguised as ransomware, built on top of an American-authored exploit, could reach a shipping terminal in New Jersey through a Ukrainian tax-filing utility. She reports the 2015 attack on the Office of Personnel Management, in which Chinese operators walked off with the security-clearance files of more than twenty million Americans, and she is unusually clear-eyed about the mismatch: American cyber policy for years treated Chinese intrusions as a matter of intellectual-property theft to be raised at trade summits, while the same operators were quietly compiling a demographic map of the U.S. national-security workforce.
Two threads run under all of this and give the book its argumentative shape. One is the vulnerability of American critical infrastructure — power, water, pipelines, hospitals, elections — most of which is privately owned, chronically under-invested in security, and often reachable from the public internet through remote-access software installed by a vendor a decade ago and never patched. Perlroth spends time in Idaho at the national laboratory where the Aurora Generator Test in 2007 first demonstrated, on camera, that a large diesel generator could be destroyed with nothing more than well-timed packets, and returns to the point that the industries that would have to defend against a serious campaign have been told this for more than fifteen years and have moved slowly. The other thread is Russia’s willingness to use the tools it has, in ways that other capable states — China, Israel, the United States itself — have generally not. The Ukraine grid attacks; the doxing of the Democratic National Committee and the Clinton campaign chairman John Podesta; the manipulation of social platforms by the Internet Research Agency; the near-destruction of the Winter Olympics opening ceremony in Pyeongchang by a GRU wiper disguised to look Chinese and then North Korean; the poisoning of a water plant in Oldsmar, Florida, that came to public attention while the book was in production — all get treated as data points in a pattern.
The book won the 2021 Financial Times and McKinsey Business Book of the Year Award, and was widely reviewed in the general press. Inside the security field the reception was more mixed. Practitioners with long service inside the agencies argued that Perlroth over-attributed the shape of the market to American choices — that Russia, China, and Israel would have built comparable capabilities regardless of who bought the first zero-day, and that the counterfactual in which the NSA had disclosed every flaw to Microsoft is not a counterfactual in which Russian and Chinese services also disclosed theirs. A subset of technical reviewers took issue with specific characterisations of exploits and operations, and with the emotional register of some passages, which they read as tilting toward alarm where a colder telling would have served the argument. The rebuttal from Perlroth’s defenders was straightforward: the book is written for policymakers, boards of directors, and voters, not for offensive-security researchers, and the field’s difficulty communicating the stakes to those audiences is part of why the boomerangs keep landing. In the years since publication, subsequent incidents — the ransomware shutdown of Colonial Pipeline three months after the book appeared, the Kaseya supply-chain attack, the Microsoft Exchange ProxyLogon campaigns attributed to a Chinese group, the continued grinding cyber dimension of Russia’s full-scale invasion of Ukraine — have made the argument harder to dismiss on its central claims, whatever one thinks of the framing.
For a reader building a shelf on cyber conflict, the book sits in a particular place. It pairs naturally with Kim Zetter’s Countdown to Zero Day, still the definitive account of Stuxnet, which Perlroth cites and defers to on the technical detail of that operation. It pairs with David Sanger’s The Perfect Weapon, which covers much of the same period from the perspective of a national-security correspondent close to senior policymakers, and with Ben Buchanan’s The Hacker and the State, which supplies the academic frame — the argument that cyber operations are less a substitute for war than a new theatre of statecraft — that Perlroth’s reporting implicitly rests on. It is less useful as a technical primer; readers who want to understand how a specific exploit chain works, or how modern endpoint detection actually behaves, will need to go elsewhere. What Perlroth offers that the others do not, in the same measure, is the voice of the market itself: the brokers, the buyers, the researchers who quit, and the operators who cannot say what they did. The book is at its best when it is quoting them.
What is likely to age well is the central through-line. The market for offensive tools is now global, priced in the millions, and reaches customers the American brokers of the 1990s would not have accepted. The imbalance between American offensive capability and American defensive posture, especially in privately owned infrastructure, is a structural condition, not a moment. And the willingness of certain states to use these tools coercively — against grids in winter, against hospitals during a pandemic, against pipelines feeding a fuel-dependent population — has, if anything, deepened since the book went to press. What has dated fastest is inevitably the specific incident list, which now reads as the state of play as of late 2020, and some of the policy prescriptions in the closing chapters, which assumed a Biden administration would move faster on public-private partnership and mandatory reporting than it has. The reader who picks it up in the middle of the decade will need to supplement the last hundred pages with more recent reporting. The rest of it, and the reason it belongs on the shelf, is the accumulated weight of a decade of interviews that no one else in the field managed to do at that scale and put between two covers.
Publisher's description
Publisher data is pending — Google Books quota deferred until 2026-08-19T14:55:00.799479+00:00.
Last researched .