The Lazarus Heist
by Geoff White
A gripping true-crime read on state-backed hacking — strong on narrative, light on technical depth.
- Status
- Read · March 2025
- Bought
- March 22, 2025
- For
- Security engineers who want threat-actor context · Anyone curious about state-sponsored cybercrime · Readers who like true crime with a tech angle
The one-paragraph verdict
White takes a decade of headline cyber incidents and threads them into one coherent narrative about a state that treats hacking as a revenue stream. The reporting is the strength: he tracks money through casinos and crypto exchanges, and the Bangladesh Bank chapter alone is worth the price. It reads like a thriller, which is also the trade-off — when you want to understand how the intrusions actually worked, the book stays at altitude and leans on metaphor instead of mechanism. If you already follow threat intel, some of the Sony material will feel like a recap rather than new ground.
Who should read it
Security engineers and anyone adjacent to threat modeling will get a useful mental model of a financially motivated state actor and why attribution is so hard. It’s also a clean on-ramp for non-specialists who want to understand why “nation-state” shows up in incident reports. Skip it if you’re hunting for IOCs, malware analysis, or anything you’d cite in a detection rule.
Where it earned its place
It permanently changed how I read breach headlines: I now ask who profits and where the money goes, not just which CVE got popped. That follow-the-money instinct is the most portable thing the book gave me, and it survives long after the specific incidents date.
Skip it if…
You want a technical reference. This is journalism, not a teardown — if you already know the Lazarus Group story chapter and verse, there’s little new here.