Waves of Chaos: From Rogue Signals to The Supervillain Scenario - Tom Van de Wiele

Tom Van de Wiele

Disobey 2026 · Main Stage

Overview

Tom Van de Wiele's Disobey talk, "Waves of Chaos: From Rogue Signals to The Supervillain Scenario," delves into the alarming potential for low-cost, high-impact disruptive attacks that can cripple critical infrastructure and societal functions. Drawing parallels from historical pranks to modern cyber threats, Van de Wiele, an offensive security researcher, argues that many of these "black swan" events are not only possible but are becoming increasingly accessible, yet remain largely unaddressed by conventional security testing and governmental preparedness.

Watch on YouTube

Visual summary for Waves of Chaos: From Rogue Signals to The Supervillain Scenario - Tom Van de Wiele by Tom Van de Wiele
Visual summary for Waves of Chaos: From Rogue Signals to The Supervillain Scenario - Tom Van de Wiele by Tom Van de Wiele

Key moments

  1. 0:00 Welcome to Disobey; Introducing "Waves of Chaos"
  2. 1:45 The 1810 Bernstein Hoax: Overwhelming a city
  3. 2:25 Four rules enabling scalable chaos and denial of service
  4. 4:10 Can we create chaos electronically on an industrial scale?
  5. 5:15 Insights from the declassified Cold War sabotage manual
  6. 6:00 Analyzing real-world outages and untested emergency scenarios
  7. 7:40 Speaker's teenage phone network pranks and social engineering

Waves of Chaos: From Rogue Signals to The Supervillain Scenario - Tom Van de Wiele

Speakers: Tom Van de Wiele

Conference: Disobey

YouTube: https://www.youtube.com/watch?v=g-ovnSRvaWY

Overview

Tom Van de Wiele's Disobey talk, "Waves of Chaos: From Rogue Signals to The Supervillain Scenario," delves into the alarming potential for low-cost, high-impact disruptive attacks that can cripple critical infrastructure and societal functions. Drawing parallels from historical pranks to modern cyber threats, Van de Wiele, an offensive security researcher, argues that many of these "black swan" events are not only possible but are becoming increasingly accessible, yet remain largely unaddressed by conventional security testing and governmental preparedness.

The presentation highlights a critical gap between the theoretical understanding of these vulnerabilities and the practical implementation of robust defenses. Van de Wiele emphasizes that a lack of imagination in scenario planning, coupled with an over-reliance on legal deterrents or outdated security paradigms, leaves nations and organizations woefully unprepared for the "supervillain scenarios" that leverage everyday technology and human psychology for widespread chaos. The talk serves as a stark warning and a call to action for both the public and private sectors to proactively test and prepare for these unconventional threats.

Background

▶ Watch: Welcome to Disobey; Introducing "Waves of Chaos" (0:00)

Van de Wiele opens by setting a historical precedent with the Bernstein hoax of 1810, where a writer flooded a single London address with thousands of unsolicited deliveries, effectively paralyzing a street. This incident, he explains, illustrates four key principles of disruptive attacks: scalability, anonymity, low cost, and focus on an unfixable vulnerability. These principles, he argues, are as relevant today in the digital realm as they were two centuries ago. The concept of "black swan events"—unpredictable, high-impact occurrences—underpins the talk, stressing that simply throwing money at security doesn't guarantee immunity.

He draws a line from playful pranks to serious sabotage, referencing a declassified 1960s Cold War manual that detailed simple yet effective disruption tactics, such as issuing duplicate tickets to cause public anger. Modern equivalents include a prankster causing traffic chaos by carrying multiple phones to spoof traffic data, or people ordering 50 Wimos (presumably a delivery service) to a cul-de-sac only to torch them. Van de Wiele's research focuses on the cost and traceability of such electronic sabotage, concluding that many are feasible but simply untried at scale. Real-world examples reinforce this concern, such as a recent incident where over 42,000 households, including hospitals, lost power for days, and a toll bridge payment system outage in Denmark that led to physical altercations due to a lack of an immediate, common-sense solution. These incidents underscore a systemic failure to anticipate and respond to unexpected disruptions, highlighting the urgent need for proactive testing beyond conventional scenarios.

Key Findings

▶ Watch: Four rules enabling scalable chaos and denial of service (2:25)

Van de Wiele's core findings reveal a disturbing landscape of under-explored vulnerabilities and systemic unpreparedness for hybrid, low-resource attacks:

  1. Feasibility of Low-Cost, High-Impact Attacks: Many disruptive scenarios, from spoofing Wi-Fi hotspots to replaying critical radio signals, are technically achievable with minimal financial investment (e.g., €12 for a fog guard remote, cheap SDR kits) and readily available tools.
  2. Weaponization of Defenses: Existing security measures, such as cloud DDoS protection, can be weaponized against an organization itself by spoofing attacks from anonymous sources (like Tor exit nodes) to block essential SaaS services.
  3. Inadequate Critical Infrastructure Testing: Current red teaming and stress testing methodologies often neglect "corner cases" and highly disruptive scenarios, focusing instead on "battering ram" attacks against primary systems, while ignoring failover mechanisms or the psychological impact of perceived threats. He notes that many critical infrastructure systems are not security-tested at all, or only superficially.
  4. Reliance on "Illegality as a Defense": For many critical protocols (e.g., emergency signals for airplanes, boats, trains), the primary "defense" is simply that it's illegal to broadcast on those frequencies. This provides no technical barrier against a determined attacker.
  5. Public Sector Resource and Talent Gap: Governments and public entities struggle to attract and retain top cybersecurity talent due to uncompetitive salaries and resources, leading to a dangerous lack of offensive security expertise within critical infrastructure protection.
  6. Lack of Coordinated Response: There's a severe deficit in established recourse and 24/7 incident response mechanisms for critical infrastructure, with only a handful of European countries offering such services.
  7. Emerging Autonomous Threats: The rise of AI-driven, vision-based drones and deepfake technologies introduces a new frontier of autonomous, untraceable attacks that current defenses are ill-equipped to handle, demanding a radical shift in defensive strategy.
  8. Need for Proactive, Imaginative Testing: Van de Wiele advocates for a shift towards more imaginative, "Minecraft lab" style testing of hybrid attacks, including those that combine physical and digital elements, to identify and mitigate vulnerabilities before real-world incidents occur.

Technical Deep Dive

▶ Watch: Can we create chaos electronically on an industrial scale? (4:10)

Van de Wiele provides several compelling technical examples of how everyday technologies and overlooked vulnerabilities can be weaponized for disruptive effects:

1. Wi-Fi Hotspot Chaos:

A seemingly innocuous act, like naming a personal Wi-Fi hotspot "I have a bomb," once led to two NATO fighter jets being scrambled after a pilot changed their squawk code to an emergency setting. Van de Wiele points out the ease with which this can be weaponized: microcontrollers like ESP16s, ESP32s, or Arduinos can effortlessly send out beacon frames to spoof numerous personal hotspots with alarming names. The low cost and widespread availability of these devices make this a highly scalable and untraceable threat.

2. Cloud DDoS Weaponization:

A particularly insidious attack vector involves turning a cloud provider's defenses against its own customers. An attacker can compile a list of a target company's essential SaaS services (e.g., Jira, Slack) and their corresponding IP addresses. By spoofing SYN flood attacks—sending a high volume of TCP packets with the SYN flag set—from anonymous sources like Tor exit nodes to these SaaS providers, the cloud's automated DDoS protection will likely block the source IP addresses of the incoming SYN floods. Crucially, if these spoofed source IPs match the target company's own IP addresses, the company inadvertently blocks its access to its own critical SaaS tools, leading to a self-inflicted denial of service. Van de Wiele notes that such disruptive scenarios are rarely tested in red teams due to their high impact.

3. Software-Defined Radio (SDR) Attacks:

The democratization of radio technology through Software-Defined Radio (SDR) kits has opened up a new frontier for physical-world disruption. Cheap adapters can now receive and send on a vast range of frequencies, replacing expensive, protocol-specific PCMCI cards.

  • Distress Buttons and Fog Guards: Wireless distress buttons (often hidden under desks in VIP offices, law firms, jewelry shops) operate on frequencies like 433 MHz or 868 MHz. These transmit to a local box with a SIM card that calls the police. An attacker can replay these signals to generate fake alarms, diverting police resources or creating opportunities for actual crime. Similarly, fog guards used in jewelry shops to fill rooms with smoke during a break-in are often wireless. Instead of reverse engineering the protocol (which might involve buying a €3,000 unit), an attacker can simply buy a €12 remote for the system, analyze its frequency, and replay the "activate" signal in a lab.
  • Emergency Protocols: Critical emergency protocols for airplanes, boats, and railroads are often "protected" solely by the illegality of broadcasting on their frequencies. Van de Wiele highlights that tools like GNU radio, potentially combined with an "AI MCP server" (likely a framework for automated signal modulation and processing), can easily build the necessary filters and modulations to interact with these protocols. This means injecting fake signals for aircraft (like the "Vance One" meme seen on flight tracking sites) or triggering emergency stop signals for trains (a vulnerability that still affects one-third of Europe, as demonstrated in an incident three years prior).

4. Acoustic Weaponization:

Metropolitan areas often deploy gunshot detection systems (civilian or military versions) that use microphones to identify the sound of gunfire. Van de Wiele points out that these systems are often tested with recordings of gunshots. This implies that a bad actor could simply play a high-quality recording of gunshots to trigger a police response, creating false alarms and diverting emergency services. This necessitates secondary controls, such as cameras, to verify acoustic alerts.

5. Drone Attacks:

The talk explores the evolving threat landscape of drones:

  • Disruption by Presence: Simply landing a drone on a critical data center, even without a payload, can prove a vulnerability and cause significant alarm, demonstrating that "the king can bleed."
  • Anti-Jamming Drones: In response to jamming techniques, drones are evolving. Some use fiber optic cables for control signals, or leverage a burgeoning market of repeaters that can guarantee drone control over distances of 80 km.
  • Autonomous AI Drones: The paradigm shift is towards drones using vision-based navigation and onboard AI, eliminating the need for external control signals entirely. Van de Wiele describes a product that allows any drone to fly autonomously using AI and vision, given a destination. He poses a "supervillain scenario" where 500 such drones are programmed to "stay on that building for a week until the parade happens and then find the person with the red hat on and then land on their face," potentially with razor blades or other payloads attached. Stopping such drones would require pervasive physical nets, highlighting a severe defensive challenge.

6. AI-driven Deepfake Attacks ("The Stalker"):

Van de Wiele describes a program he developed called "The Stalker." This program scans Instagram for a specific hashtag (acting as a Domain Generation Algorithm or DGA-like identifier), finds audio of a target person, deepfakes their voice to say something alarming (e.g., "there's going to be a bomb," or humorously, "I love pineapple pizza"), and then spreads this audio across various platforms. The attacker can host this on a prepaid Linux Virtual Private Server (VPS), configured to only access the internet via a Tor node, and prepaid for 10 years, making attribution virtually impossible. This illustrates the coming wave of autonomous, untraceable, and highly deceptive attacks.

Demo / Proof of Concept

▶ Watch: Analyzing real-world outages and untested emergency scenarios (6:00)

While the talk did not feature a live, public demonstration of these advanced attack techniques, Tom Van de Wiele extensively described numerous conceptual proofs-of-concept and lab-tested scenarios, underscoring their feasibility. He repeatedly alluded to having conducted these experiments "in my lab," such as the replay of radio signals for distress buttons and fog guards, or the development of "The Stalker" AI deepfake program.

The essence of the "demo" portion of the talk was to illustrate how these attacks could be executed with minimal resources, rather than performing them live. For instance, he detailed the cost-effectiveness of buying a €12 remote to reverse-engineer a fog guard protocol versus purchasing a €3,000 unit, or the simplicity of using a Raspberry Pi and a cheap SDR kit to generate fake signals. These conceptual demonstrations, backed by his offensive security background, served to highlight the stark reality that these "supervillain scenarios" are not theoretical impossibilities but rather practical, unaddressed threats. The talk itself, therefore, acted as a high-level blueprint for potential attackers and a wake-up call for defenders.

Defensive Implications

▶ Watch: Speaker's teenage phone network pranks and social engineering (7:40)

The implications of Van de Wiele's findings for defenders are profound, requiring a significant shift in mindset and strategy:

  1. Proactive Whitelisting of SaaS IPs: Organizations must actively identify and whitelist the IP addresses of their critical SaaS providers in their firewalls and cloud security configurations. This prevents self-inflicted denial-of-service attacks where legitimate traffic is blocked due to spoofed SYN floods from Tor exit nodes.
  2. Expand Red Teaming Scope Beyond Production: Traditional red teaming often avoids "disruptive" or "production-impacting" scenarios. Defenders need to embrace testing "corner cases" and hybrid attacks in isolated environments, digital twins, or even tabletop exercises. This includes simulating scenarios like primary/backup database desynchronization or the complete loss of external communication.
  3. Rethink "Illegality as a Defense": For critical protocols that are only protected by legal prohibitions on broadcasting, technical countermeasures are essential. Assume that illegal broadcasts will occur and implement detection, interference, or alternate communication methods.
  4. Prepare for Crowdsourced and Just-in-Time Attacks: The "Bernstein hoax 2.0" scenario, involving distributed, untraceable devices (e.g., SDR kits in postal parcels activating signals at random locations), demands a decentralized defense strategy and enhanced intelligence gathering on emerging threat patterns.
  5. Implement Secondary Controls: Relying on a single sensor type (e.g., acoustic gunshot detectors) is insufficient. Integrate and verify alerts with secondary controls like cameras, or even human verification, to prevent false alarms and resource diversion.
  6. Invest in Counter-Drone Technologies and Strategies: Develop layered defenses against drones, including detection (RF, radar, acoustic), jamming (though increasingly circumvented), and physical barriers (e.g., nets). Critically, prepare for autonomous, vision-based AI drones that bypass traditional control signal jamming.
  7. Address the Public Sector Talent Gap: Governments must make cybersecurity roles competitive with the private sector in terms of salaries and resources to attract and retain skilled professionals. This is crucial for building robust national cybersecurity capabilities and exchanging vital threat intelligence.
  8. Modernize Legal Frameworks for Responsible Disclosure: Explore innovative legal approaches, such as Belgium's "hacking is legal" law, to encourage responsible disclosure of vulnerabilities in critical infrastructure without fear of prosecution. This fosters a collaborative environment for identifying and fixing flaws.
  9. Enhance Incident Response and Information Sharing: Establish 24/7 national hotlines and clear escalation paths for critical infrastructure incidents. Foster "Chatham House rules" environments for public and private sector collaboration, allowing for candid sharing of threat intelligence and defensive strategies.
  10. Cultivate a Culture of "Dangerous Imagination": Encourage security teams to think like "supervillains," imagining the most absurd or unconventional attack scenarios. Utilize resources like the ANISA handbook for cyber stress tests and participate in exercises like NATO's Locked Shields to broaden defensive perspectives and test non-traditional attack vectors.

Key Takeaways

  • Low-Cost, High-Impact Disruptions are Real: Many "black swan" attacks, leveraging everyday tech and human psychology, are feasible with minimal resources and are not adequately addressed by current security paradigms.
  • SDR and AI Democratize Advanced Threats: Technologies like Software-Defined Radio and AI-driven deepfakes or autonomous drones are making sophisticated, untraceable attacks increasingly accessible, posing new challenges for attribution and defense.
  • Critical Infrastructure Testing Lacks Imagination: Current security testing often neglects "corner cases" and disruptive hybrid scenarios, focusing on conventional "battering ram" attacks while overlooking critical vulnerabilities in failover systems or the broader societal impact.
  • Defenses Can Be Weaponized Against Themselves: Automated cloud security measures, when misconfigured or targeted with spoofed traffic, can inadvertently block an organization's access to its own essential SaaS services, leading to self-inflicted outages.
  • The Public Sector Needs Urgent Investment: A significant gap in resources and talent exists between the public and private cybersecurity sectors, hindering national resilience against critical infrastructure attacks and requiring competitive incentives.
  • Proactive, Imaginative Testing is Paramount: Defenders must adopt a more offensive mindset, actively testing unconventional scenarios, fostering cross-sector collaboration, and rethinking legal frameworks to anticipate and mitigate the "waves of chaos" before they materialize.

About the Speaker(s)

Tom Van de Wiele is an offensive security expert with a deep passion for technology. He describes himself as one of the lucky few who has been able to turn his passion into his profession, focusing his research on offensive security. Living in Denmark, Van de Wiele brings a pragmatic, attacker-centric perspective to understanding and mitigating complex cyber threats, particularly those targeting critical infrastructure. His work often involves exploring the "non-estable areas" of security, pushing boundaries to understand what truly constitutes a robust defense against unconventional attacks.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Van de Wiele covers a genuinely interesting attack surface — low-cost physical-layer disruption, SDR abuse, cloud DDoS weaponization against your own SaaS stack — and his framing around 'illegality as the only defense' is a point worth making loudly. The problem is this reads more like a curated threat catalog than a research presentation: lots of 'I tested this in my lab' without the lab work surfacing in any reproducible or novel form.

Heather Calloway (CISO) — WEAK

Van de Wiele covers genuinely underexplored threat territory — low-cost, high-impact disruption of critical infrastructure using commodity hardware and AI — but the talk operates almost entirely as a threat catalog without crossing into institutional accountability or actionable governance. The research is interesting; the delivery leaves defenders without a decision path.

→ Top-rated talks at Disobey 2026

All talks from Disobey 2026