Behind the NBC report that Olympic visitors can expect to be hacked: all attacks required user interaction, could happen anywhere
Details Behind the NBC Honeypots: Part 2 — Recently, I was asked by NBC to participate in an experiment to deploy honeypots in Moscow, Russia, to see how fast they would be compromised.
Context & Ripple Effects
This is Trend Micro's methodological footnote to a broadcast story it helped create: NBC enlisted the firm to deploy honeypots in Moscow ahead of the Sochi Games, and Engadget amplified the segment with a 'visitors should expect to be hacked' video on February 5. Two days later Errata Security called the resulting coverage misleading, arguing the experiment showed nothing specific to Sochi.
Trend Micro's own writeup effectively concedes the critics' core point — every compromise required user interaction, meaning the devices were exposed to ordinary internet-borne threats anywhere, not to an Olympic-targeted campaign. The story nonetheless travelled unusually far for a vendor demo, picked up by NBC Nightly News, PC Magazine, The Verge, Business Insider, Techdirt, Softpedia and others within days.
First-order effects
- Travelers weighing whether Sochi carries special device risk get a muddier answer than the headlines suggested: the only demonstrated attacks succeeded because someone clicked or accepted something, a condition identical in any connected city.
- Trend Micro gains mass-market visibility from the NBC tie-up, but its own disclosure hands ammunition to researchers like Errata Security who argue the segment overstated a Games-specific threat.
Second-order effects
- Broadcasters staging security experiments around major events now face immediate technical peer review — Errata Security's rebuttal landed within a day of the segment, forcing follow-up explainers rather than letting the claim stand unchallenged.
- Security vendors see both the payoff and the cost of TV-ready demos: broad syndication, but with the fine print (user interaction required) becoming the story itself in the trade press.
Third-order effects
- If the pattern holds, big-event cyber coverage will keep being shaped by staged honeypot demonstrations whose methodology is contested after the fact, leaving the public's threat perception set by broadcast framing more than by event-specific attack data.
The trend: Olympic cybersecurity coverage is increasingly driven by vendor-run demonstration experiments that travel wide through mainstream syndication while their real-world specificity is disputed by the research community.