Field Notes – We mistook fluency for judgment, and the gap is now generational (aka the security skills gap is now YOUR problem)

A free malware service built and used by teenagers is the cleanest proof yet that growing up online never taught anyone to read it.

On the WeedHack portal there is a suggestions page: users submit feature requests and vote on them, the way you might upvote a dark-mode toggle in a note-taking app. Among the proposals currently collecting votes: ransomware, microphone access, support for more game clients. The people doing the voting appear to be teenagers. So, in many cases, are the people they are spying on.

Since January, a malware service distributed through Minecraft mods has infected more than 116.000 machines, and McAfee’s researchers say it is still adding two to three thousand a day. It costs nothing to start: lifetime access is $24.99. The numbers are the easy part to report, right? The harder thing underneath them is a security skills gap that no firewall closes.

The headline more or less writes itself: clever malware preys on kids who play the world’s biggest game.
That version is true, and it is also the least interesting thing here; and what should make us all stop is that the operators and the victims are drawn from the same pool, and the tool they pass around comes with a leaderboard, a documentation portal, and a product roadmap. It was built for people who have never known software that wasn’t this “frictionless”, and it is being used by exactly those people.

For about 25 years we have called this cohort digital natives, and we quietly assumed that growing up inside these systems made them safe inside them. WeedHack is the cleanest evidence I have seen that fluency and judgment are not the same faculty.
A teenager who can install a modded client, sideload a JAR file, and click past an antivirus warning has demonstrated fluency – the same teenager disabling the antivirus because a well-produced video told them to has demonstrated the absence of judgment. Both live in the same set of hands and we kept counting only the first one.

The skill that matters here was never technical

Judgment online is a learned suspicion. It is the small voice that says a free tool asking you to switch off your defenses is not actually free. That voice does not arrive through exposure. It is taught, usually the hard way, usually late.

The people who carry it in any depth tend to have earned it.
They ran their own mail servers, reformatted their own machines after a bad download, and lived through the years when the internet was openly hostile and looked the part. That tacit sense of when something is too convenient is concentrated, right now, in people in their fifties and sixties: the sysadmins and early-web survivors drifting toward retirement. And it is barely being passed on, because we decided it did not need to be, and the young were supposed to come with it pre-loaded – spoiler: we failed at it!

In more households than you would expect, this produces a quiet inversion: the most security-literate person at the dinner table is the one closest to a pension. The parents in between, often younger, and in plenty of families less technical than the grandparents, cannot model the instinct because they do not hold it either. Three generations at one table, and the threat judgment is sitting at the wrong end of it.

In the work we do, the consistent finding is the same one: the moment of compromise is almost never the click itself. It is the small, earlier decision to trust (the one nobody was ever taught to interrogate); the security skills gap we keep describing as a hiring problem starts long before anyone is hired.

The infection count is the part that gets reported.
What it means takes waaaay longer.

For the families inside it, the trust contract changes without anyone signing anything: a child learns that watching a classmate through their own webcam is a five-dollar upgrade with a spot on a leaderboard. The capability arrives first; whatever moral frame might have governed it arrives later, if at all, and usually from adults who do not know the capability exists.

We are funding the worlds and not the literacy

For governments, there is a blind spot worth naming plainly: public money is flowing into games as an industry on a scale that is easy to miss. Italy runs its First Playable Fund and a tax credit, and treats the sector as a pillar of its creative economy. The UK has just doubled its games fund inside a wider growth package. Canada and France have offered generous development tax credits for years. Every one of these is justified in the language of jobs, exports, GDP, and cultural standing.. flags flown on a global stage.

All of it funds the supply side: the studios that build the worlds. None of it, as far as I can find, treats the platform as the other thing it plainly is: the place where a generation forms its first instincts about trust online, and where some of them are currently learning that surveillance-as-a-service costs less than a cinema ticket. The spending makes more of the medium.
Nothing in it reaches the judgment of the people who will live inside the medium. That is not the failure of any single ministry. It is a category error: we file games under culture and fund them as culture, and the security literacy of the players falls into the gap between the culture ministry, the education ministry, and the cybercrime unit that turns up only after something has already happened.

Those 116k machines belong, disproportionately, to your future workforce.
The fifteen-year-old whose judgment we assumed and never built will be onboarded in a handful of years, and the colleague who would have trained that instinct into them, out of war stories and scar tissue, is clearing out a desk. The old shorthand that younger staff are lower-risk because they are good with computers was always thin. It now points the wrong way in a specific sense: fluency with consumer software can simply mean someone does the wrong thing faster, and with more confidence. That is the security skills gap arriving in your onboarding queue, already several years in the making.

The kids on that leaderboard are not a different species: they are doing what every generation does with the tools handed to it before anyone explains the stakes.
The only thing that changed is that we told ourselves this one arrived with the explanation pre-installed.
Nobody arrives pre-installed.
The instinct that keeps you intact online was always taught, always a little too late, and usually by someone who had already paid for the lesson themselves, we just stopped noticing that we had stopped teaching it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top