Google has changed the way it refers to and assigns names to hacking groups, according to TechCrunch, which spoke with one of the world's foremost experts on tracking hackers to explain the thinking behind the shift.
If you follow cybersecurity news even casually, you've seen the results of these naming conventions: state-backed spies and criminal crews rarely get referred to by a plain description. Instead they get codenames, handed out by the security companies that track them.
TechCrunch's interview with Google's top hacker hunter is aimed at answering a question most readers have probably wondered about at some point — why do companies give hackers codenames at all, rather than just describing what they did and who they work for?
The short version is that naming is a tracking problem before it's a marketing one. Investigators need a stable label for a cluster of activity — the tools, infrastructure and behaviors they keep seeing — long before anyone can say with confidence which government or gang is behind it. A codename is a placeholder for evidence that's still accumulating.
Google's decision to overhaul that system is notable because of the company's scale. Google's threat intelligence work touches an enormous share of the world's email, phones, browsers and cloud infrastructure, so the names it picks tend to propagate into news coverage, government advisories and corporate security briefings.
Why it matters: the labels a company like Google puts on hackers shape how governments, businesses and the public understand who is attacking them — so changing the naming system changes the shared vocabulary everyone uses to talk about digital threats.