Runa Sandvik
@runasand.bsky.social
10K followers 50 following 170 posts
Founder of Granitt, securing journalists and at-risk people around the world.
Posts Media Videos Starter Packs
runasand.bsky.social
I’ve followed various coverage of Havana Syndrome over the years; still interesting to hear what @jenniferpforde.bsky.social and @bungey.bsky.social uncovered in their podcast ‘Havana Helmet Club’ (and I loved ‘West Cork’ from a few years ago). www.bbc.com/audio/brand/...
BBC Audio | Havana Helmet Club
Listen to the latest episodes of Havana Helmet Club on BBC Audio
www.bbc.com
runasand.bsky.social
Been really enjoying this new book about Gunvor Galtung Haavik, a nurse turned secretary for the Norwegian MoFA in Moscow — and KGB spy for 30 years. The KGB used her to get closer to Americans, including Marion Peacock, Lloyd Eddenfield, Bernie G. Britain, and Roy Rhodes.
runasand.bsky.social
Spent the last week in Taiwan! Such a beautiful country and lots of delicious food. Would love to visit again! 🇹🇼
runasand.bsky.social
I followed the news in Norway, glad you’re doing ok!
runasand.bsky.social
No, L1, first jump after ground school.
runasand.bsky.social
Working on my skydiving license in between security assessments, keynotes, and research. Here’s my first jump in Empuriabrava, Spain with two instructors and my own parachute.
runasand.bsky.social
Thanks to ODA-Nettverk for inviting me to keynote Inspiration Day yesterday! Really enjoyed being back in Oslo and talking about the importance of end-to-end encryption.
runasand.bsky.social
Had the pleasure of being a guest on the Adventures of Alice & Bob Podcast recently! Check out the interview for stories about my work with journalists and high-risk people — and that one time I hacked a smart-rifle in 2015. www.beyondtrust.com/podcast/ep-7...
Ep. 79 - Hacking Rifles and Protecting Reporters //… | BeyondTrust
BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen credentials, and misused privileges
www.beyondtrust.com
runasand.bsky.social
The Kaspersky researchers who discovered Careto more than a decade ago privately concluded that the group was run by the Spanish government. Careto relied heavily on phishing emails impersonating Spanish newspapers. techcrunch.com/2025/05/23/m...
runasand.bsky.social
I’ll be in Stockholm in mid-June! Available for consulting, presentations, workshops for journalists and security folks. Also planning on spending some time in the wind tunnel. 🥳
runasand.bsky.social
A team of journalists in Norway spent a year secretly monitoring a credit card fraud gang to uncover who's behind it and how they operate. Here's the story -- in English -- of how they unmasked Darcula and the crime-as-a-service software Magic Cat. www.nrk.no/dokumentar/x...
The scammers have tricked millions through text messages:
Who are they and how do they scam us?
www.nrk.no
runasand.bsky.social
On my list and can’t wait to read it!
runasand.bsky.social
The article refers to victims of a specific 2019 campaign and the database isn’t up to date, so that’s why. You’re not missing anything!
runasand.bsky.social
News articles often focus on spyware victims who had their devices checked and opted to go public. We rarely hear about those who didn’t. New court documents from WhatsApp v. NSO shed some light on the true scale of the targeting in a 2019 campaign. techcrunch.com/2025/04/09/c...
Court document reveals locations of WhatsApp victims targeted by NSO spyware | TechCrunch
The list of 1,223 victims in 51 countries hints at the “true scale of the spyware problem,” per one researcher.
techcrunch.com
runasand.bsky.social
Thank you! See this guide as a starting point. Happy to chat about what else/what more is needed for specific contexts. bsky.app/profile/runa...
runasand.bsky.social
Good question! I’d like to think we learn a thing or two from each other.
runasand.bsky.social
More of this, please. bsky.app/profile/prop...
propublica.org
D.C., we keep on trucking. 🚚

If you are or were a federal worker, our Signal tipline is always open and actively monitored: 917-512-0201.
Two Black women, dressed in pink, stand in front of a mobile billboard truck outside of the Ronald Reagan Building and International Trade Center. On the side of the truck, a LED screen reads: Are (were) you a government worker? ProPublica journalists want to hear from you. Signal: 917-512-0201. propublica.org/tips. A black mobile billboard truck drives along the exterior of USAID’s former headquarters at the Ronald Reagan Building and International Trade Center. The road ahead shows the U.S. Capitol. On the side of the truck, a LED screen reads: "Are (were) you a government worker? ProPublica journalists want to hear from you. Signal: 917-512-0201. propublica.org/tips." The back of the truck also has text that begins with "Do you have a tip for ProPublica?" The rest of the text is not clearly legible in the photo. Wide shot of dozens of people gathered outside the Ronald Reagan Building and International Trade Center in D.C. To the right of them is a parked mobile billboard truck. On the side and back of the truck, a LED screen reads: Are (were) you a government worker? ProPublica journalists want to hear from you. Signal: 917-512-0201. propublica.org/tips. Multiple demonstrators stand near USAID’s former headquarters at the Ronald Reagan Building and International Trade Center, some holding a giant white flag with the USAID logo. Behind them is a a parked mobile billboard truck. Text on the side of the truck begins with: "Are (were) you a government worker?" The rest of the text is partially covered by the demonstrators, but shows contact information for ProPublica.
runasand.bsky.social
Proton is free, though some may hesitate to use it. Tor is also free, though not exactly the same as a VPN. Do consider paying for one if that’s what you really need.
runasand.bsky.social
If you’re interested in aviation security, check out this fantastic 2013 talk from Hugo Teso on leveraging ADS-B, ACARS, and on-board systems to attack virtual airplanes systems. www.youtube.com/watch?v=wk1j...
#HITB2013AMS D1T1 Hugo Teso - Aircraft Hacking: Practical Aero Series
YouTube video by Hack In The Box Security Conference
www.youtube.com