Go back

WhatsAppening here?

49m 46s

WhatsAppening here?

In this episode of the Hacking Humans Podcast, hosts Dave Bittner and Joe Carrigan, along with Maria Vermauses, discuss recent scams and personal anecdotes. Joe recounts how his wife was targeted by a puppy scam on Facebook after their dog Fred passed away. The scammers demanded a $500 deposit for a miniature poodle, refused to let her visit the dogs, and reduced the price to $250. Joe identified it as a scam, and his wife eventually caught on, avoiding financial loss. Dave shares a strange experience on a road trip to Maryland’s Eastern Shore, where he saw an emu named Dexter wandering on the highway. Dexter had escaped from a local farm and was captured by state troopers after four hours. Joe then presents two news stories: an infographic from WBAL reveals that Americans lost $16 billion to fraud in 2023, with investment scams costing the most at $6.4 billion, followed by romance scams at $1.2 billion. Nevada had the highest per capita fraud reports. Another story from Maine covers Harpswell, a town of 5,000 people, losing $189,000 to a vendor payment scam. The town is strengthening its payment verification policies. Joe emphasizes the need for organizations to implement robust verification processes for payment changes, as these scams are common and costly.

Transcription

8630 Words, 46485 Characters

English
[MUSIC] Hello everyone and welcome to the Hacking Humans Podcast. Where each week we look behind the social engineering scams, fishing schemes and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. I'm Dave Bittner and joining me is Joe Carrigan. Hi Dave. And our N2K colleague and host of the T-Mine is Space Cyber Briefing Maria Vermauses. Maria. Hi Dave and Hi Joe. We've got some good stories to share this week, but first we've got some follow up. Joe, you want to start things off for us? I do. I have an interesting story this week. Okay. My wife. Finally. I what? It's not a chicken update so no. [LAUGHTER] Okay. Okay. Dave, you recall back in October we lost Fred. Yes. Yeah, Fred was a good boy. He was a big dog, but he was a good boy. He was a good boy. And he visited the studio here more than once. He did. He was a very good boy. And he came in and he said hi to Dave and he sat down. Oh, he did. He did nose through the trash because it was, well that's dog. And Fred liked to be pet. Oh yeah, he was very pushy. Very pushy. Yeah. But one of the sweetest dogs I've ever known. He was. So we lost Fred back in October and my, we still have Josie. Yeah, get it because we also have two cats now. Josie and the pussy cats. Okay. Nice to joke. So my wife is like, I think I want to get another dog, but I want to get another miniature poodle or something similar like Kevin. Because Kevin was our first dog and she really loved Kevin a lot. Okay. He was a good boy as well. So she actually starts looking around and she got targeted by a puppy schedule. By a puppy scammer. Oh. Now can you, I'm going to ask both you, can you guess the platform? Guess the social media site. Oh wow. This is hard. What could it be? I don't know. This is the book of the face. It is the book of the face. The Facebook. Right. So she actually engages. She says, where are you guys located? And they say they're located in Pennsylvania. And she says, well, that's great. I love these pictures of these dogs. I'd like to come up and meet them. And they were like, eventually they start telling, they start telling her, yes, well, that's fine. But we don't reserve any dogs until you send it to posit. And I'm like, scam. Because she's talking to me the whole time she's doing this. I'm like, this is a scam. And she goes, are you sure? I'm like, positive. This is a scam. And she says, okay, well, let me see if we can just go up and visit the dogs, right? Because. I don't want to reserve a dog. I just want to come up there and see the dogs you have before sending you any money. And they're like, no, no, we can't do that because that reserves a dog. And we can't reserve a dog. We're very reputable people. We're very, very honest and very, very open about what we're doing here. Right? It constantly saying that kind of thing about it. And I'm like, total scam. And they were like, you can give us a deposit of $500. And I'm like, that's a big deposit. And eventually she's like, no, I really want to come up and see the dog. And then I'll tell you what, we'll come up, we'll see the dog, we'll meet the dog. And if we pick out a dog, we'll write you a check on the spot for $500 for the dog. Right? And they go, how about you send us a deposit of like 250? How about 250? Right. Would you believe? Right. Yeah. They reduce the amount. And eventually my wife, actually, my wife caught on very quickly after I pointed out, oh, yeah, this is a scam. We talked about, we've talked about them on hacking humans. And eventually she said, look, it's obvious to me that you're a scammer. You're not interested in selling, you're not act, there are no dogs. And looking at the pictures, the dogs were all like beautiful little fluffy puff balls. And I'm almost positive they were AI or at least AI enhanced. But, you know, it's another scary reported at the Facebook. I can almost do it. They'll be right on it. Right. Yeah. They've got their best men on it. Yeah. So how did she start her search on Facebook for puppies? I don't know. That's a good question. You may have just gone, looked for puppies, you know, poodle puppies, Facebook marketplace, maybe. No, no, wasn't marketplace. No, yeah, looking for business sites, I think. Or maybe she was on marketplace. I don't know. I don't know. Actually, that's a good question. Dave, I'll have to ask her that. Yeah. Interesting. Well, glad you didn't get scammed. Nope, didn't get scammed. Yeah, lots of, lots of puppies come out of Pennsylvania. There's a lot of puppy mills up there. Yeah. Unfortunately. Yeah, it's not, not great. We got our dog from Virginia, Kevin. Oh, we got him. Yeah. Just he's just some random dog that, you know, some beagle got loose and impregnated a boxer. And so now I have this dog that looks like you do. Yeah. No, this dog that looks like she's made out of spare parts with a little tiny boxer head and a big staunch, beagle body with a beagle tail and long legs. Right. Right. I love it. She made it, she made a trip through that transport mechanism from the movie The Fly. Right. Yeah. I think she's adorable. Of course you do. Right. Yeah. My daughter thinks she's an unugly dog. So your daughter's probably just jealous of all the love and attention she gets. My wife is definitely jealous. There you go. All right. Well, I have a couple of things to share with you and our listeners this week. First of all, I had a very strange thing happen on a recent road trip. I was driving to visit some family on the eastern shore of Maryland, which is about two hours away, my destination. And if you're familiar with this area in Maryland, if you're heading towards the eastern shore, Ocean City, you drive down Route 50. You cross over the Bay Bridge and Route 50 takes you all the way there. Right. So I am most of the way there and I'm driving along my name own business. And I look on the other side of the road and I see that the traffic is backed up, come in the other way. I'm thinking, oh, that's so I look over to see what's causing the backup. Is there an accident or something? There was an EMU running around on my highway. Oh, that's historical. Yeah. There was an EMU. Is this a normal thing that happens where you live? It is not. No. Okay. It's a clear question. I was just say, EMUs are not native to Maryland. Right. It's a nut. We have a very low, very low population of EMUs. Well, it's not zero. It is not zero. Zero. Zero. No, there's a, there's like a children's petting zoo near us that has an EMU. I told you when I was riding the bike around the BWI part, or bike trail, I was, being stared at by an EMU. Right. Which is a misconcerting. Is it missing an EMU? Could that be related to the one? Well, that is in fact what happened. This EMU had escaped from a farm. I learned later when I tried to look up the news story just to make sure that I wasn't hallucinating. That, uh, huh. Yeah. You don't see it. Maybe I'm going crazy. Right. It's like, if there was someone in the car with me, I would have said, you do see the EMU, don't you? Right. Is the EMU in the room with us right now, Dave? Right. No, maybe. Right. So the EMU's name was Dexter. He had escaped from, he had escaped from a local farm. It took the state troopers four hours to capture Dexter. Yeah. But he was taken back safe and sound to recover from his little adventure back at the farm. EMU's are quite wily. They are. And they're fast. Yes. Australia had a whole thing with them. Did I ever tell you about how I found out about the great EMU war? I was, should I say yes? Yes. It's a good. Okay. I was doing a good research with my son on the great Gatsby and I was type in the great. And the first suggestion is EMU war and I'm like, what? Wait a minute. And Joe was gone for the next two hours. I never got back to my son. Yeah. I never got back to my son about the great Gatsby at all. I just got enthralled in the great EMU war. Yeah. No, it's a page turner. It is. I think that's one of those your search habits are influencing what comes up because I tried that and I get the great Gatsby. Really? I'm not getting it. I'm very sad that he did not get the great EMU war. Well, let me try it again. Maybe they're putting it in mind. The great Gatsby. Yeah. Yeah. Gatsby. Yeah. That was a war isn't even on the list. Yeah. Same. Whereas on mine, like the fourth or fifth option is the great Greek. So I'm telling you, it's. There you go. Which is the name of apparently a restaurant in my neck of the woods. I didn't even know. So the EMU was safe and sound, but I also have from my travels a chicken story. By the way, Joe, thank you for the eggs. Yes. Ladies and gentlemen, last week, Joe dropped by the office and delivered half dozen farm fresh eggs from the day before. Yes. They were delicious. They were. I ate them over the course of a couple of lunches and they were delicious. I have to ask Joe, I don't know if I'm imagining this. Is it so that these eggs have a thicker shell than the egg you get in the supermarket? Oh, yeah, they do. Yeah. That's what it felt like when I was cracking them open. I was like, man, these eggs are a hard core. Yes. Yeah. I bought eggs from my neighbor the other day. And I had the exact same exact same reaction. and said, these egg shells are really thick in the eggs were delicious. But yeah, that's so fun you say that. - Yeah, they are thicker. Probably 'cause the eggs in the store are maximized for profit and it's, you know, it's, calcium might be more expensive. I don't know. - Well they grow, yeah, I guess they grow quickly soon, maybe. - Well, who knows? (laughing) - You know, but yeah, but anyway, Delish, thank you Joe, they were delicious. - You're more than welcome. - I appreciate it. But anyway, I got to my destination, visiting a family member out on the Eastern Shore, and she actually has two neighbors who have chickens. And the one right next door has a rooster, ask me how I know. - Yeah. - I know exactly how you know. (laughing) You found out at like 5, 30 in the morning, right? - Right. - Right, right. (laughing) So we're sitting there in the backyard, sitting on, you know, just chatting, sitting on some chairs and the chicken coop is in view. And I see the hens and the rooster walking around. And I see something else in the chicken coop. - Hmm. - What is that? Is that a rabbit? Is it, no, it was a rat. - A rat, oh yeah. - It was a rat, and a chicken coop. - Yep, yeah. - And this rat was just living his best rat life. Like he had didn't have a care in the world. He wasn't trying to hide like Templeton from Charlottesway. - Exactly what I thought. He was like Templeton. And I was surprised that the rooster didn't try to evict him. - No, roosters, rats actually will kill chickens. They are not to be trifled with. - Oh. - They are smarter than mice. I don't know how I know this much about rats, but one of the things that I'm doing is I'm building a new coop, 'cause the current coop is too small. And when we were looking at options, my wife's like, what about that one on the ground? If it's on the ground, just envision the underneath of that teaming with rats. - Right. - And that's what I use every time teaming with rats. (laughing) - Well, this had at least one rat. And I don't know, I think it would be disconcerting to me if I lived next to a chicken coop that also had a rat population. - Yeah. - I might have words with my neighbor, but maybe I'm just being unrealistic about what to expect. - In the words of Jerry Klauer, maybe you need to go out and have a rat killing. - Yeah, there you go. - Right. - Well, rats are the number one reason why I will never have chickens, 'cause I do not, do not ever want to be dealing with that. - Yeah, well I said what this neighbor just needs is a good snake, right? - Yeah, rat snake. - Yeah. - The problem is rat. - I don't know why she swallowed the fly. (laughing) - You need a bunch of snakes because you will never keep up with the breeding capabilities of a rat or a mouse. - Yeah. - Oh, that's what we need. A whole denful of snakes. - That's good. - That's good. - Just gather up all the rat snakes in the state and then take them down to your chicken coop and just let them know. - Sure. - You ever hear the stories about this? - Look at the children, the simpsons where they have like the snake-fashing day. Come on, like, yeah. - And eventually they wait for the gorillas to freeze to death in the winter. - Right. There's another story though. Somebody built a house on top of a garter snake nest like a historic garter snake nesting site. - Really? - Yeah. Thousands and thousands of garter snakes would come to nest underground. They didn't know this when they bought the house. - Right. (laughing) - Anyway, all right. - All right, let's take a quick break to here. - Here from our sponsors, when we come back, we will actually dive into some hacking human story. - Oh my God. - Stay with us if you haven't already left. (laughing) (upbeat music) - Every attacker counts on one thing, environments that trust too much. Threat locker closes that gap with default deny at execution, unknown software blocked. Trusted apps contained with ring fencing, configurations verified with Threat Locker DAC so you stay secure and compliant. Threat Locker delivers the visibility and control CISOs need without adding operational pain, making zero trust real for teams of any size. Stop ransomware at its earliest point. Book a demo at Threat Locker.com/N2K. (upbeat music) - All right, we are back. Joe, I am handing the microphone back to you. - Very good. - Where you got it for us this week. - I have two stories 'cause they're pretty quick, but the first one is coming from WBAL and I saw this in a lot of different places because I think this comes from their broadcast group, which I think is seen player or no horse, of course broadcast. And this is from Demali Ranirez, Ramirez, who is a researcher, a data researcher, for Hertz Broadcasting. And it is a really interesting graphic representation of the fraud losses that Americans have suffered $16 billion last year. And if you scroll down the article, they have some pretty good breakdowns. Of course, the top five costliest schemes, do you guys, if you guys haven't looked at the articles, anybody who want to guess at number one? - I would guess romance scams. - romance scams, good guess, number two, but the number one is malicious investment and investment advice. - Oh, okay. - Six point four. - Billion dollars. - Okay. - romance scams, 1.2, government and postures, three quarters of a billion dollars. Business and postures, another three quarters of a billion dollars. And then job scams and employment agencies, almost half a billion dollars. - Oh, that's going to be rocketting up the charts on the show. - Yeah, absolutely. Because that one is turning out to be very successful. I mentioned I was talking with a recruiter, an actual real live recruiter recently. And he was, I was like, look, I get a lot, you know, I'm sorry, I was so abrupt, but I didn't actually, I don't know if I apologize. Anyway, I owe the guy a call. I said, you know, we got a lot of scams here. I get a lot of scams and he goes, you would not believe the level of scams that I have to deal with in dealing with people and dealing with job seekers. They're all, everybody's scamming. - Yeah. - Both ends are scamming this. - Yeah. - It's awful. - It's terrible. - Yeah. - We're a burrowist. - Yeah. - Yeah. The next article, our next graphic, infographic, and these are interactive infographics, which I really like, which states reported the most fraud, the most fraud schemes at per 100,000 residents. So actually do per capita, which is good. Anybody want to guess at the highest state, the state where you are, where there were the most reported fraud cases per-- - Reported is an important word there. Right. - Mm. - I would guess Florida. - Oh, Florida's a good guess. I would guess California. Florida is a good guess. Florida is pretty high on the list. California is significantly lower. - Okay. - But number one is Nevada that 892 reports per 100,000 people. - Yep. Okay. That makes some sense. - Interesting. - I think. - I think Nevada. - Or why do you say that makes sense, Maria? - Yeah. I think gambling people who are maybe, people who are more primed to be like, "I want to throw some money in the direction of something that could be a good bet." - Okay. - 'Cause yeah. - Yeah. - Sure. Yeah. Maybe. Yeah. I'm not a big gambler. So, I mean, - That's probably the most tricky one. - Other than with sugar, right. - Yeah. - I just can't, I just remember you were talking Simpson's references earlier. There's an episode where they build a casino and Burns of course owns it. And he says, "I've discovered the perfect business model. People shuffle in empty their pockets and shuffle out." And that's how I view casinos. I mean, they don't get to build those big, huge buildings by given money away. - No. - Then there's losses. How much money people lost? And this is amazing. The Arizona has the highest per capital loss of $6.1 million per 100,000 residents, which means that like each person, if you average that out, everybody lost like $61. - Oh. - So that money went. - Yeah. - Blue out of my pocket. - I think this is interesting. Anyway, the, - Where is the owner? - Leave a link in the show notes. I really think this is a great article. Take a look at it. The other story I have, which is really pretty short, comes from Maine, from the Portland press herald, written by Craig Anderson. And this is about a municipality up there called Harpswell. And they lost $189,000 to a vendor payment scam. Now, it doesn't say in this article, whether it was business email compromised, the vendor site, or if it was just an impersonation attack, like with some Gmail address or a local like domain or something, it doesn't say. They just said that they have, they received the email to change instructions, to divert payments for this $189,000 payment to somebody else. And it went, that went through and the money got sent. They very quickly realized it was, they had been scammed, they contacted law enforcement, and they can't talk about it right now because it's an ongoing legal investigation. But one of the things they're saying is, we are now looking at strengthening our policy for these kind of things, the internal payment authorization and verification protocol. - You think? - Yeah. (laughs) Here's what Eardt takes me about this the most. First off, these taxpayers have lost money. That's a lot of money. Yeah, especially for, I get the impression this is a small municipality. Pretty much guaranteed. Right. So it's probably not an insignificant loss. Right. Like the state of Maryland got defrauded out of this much money. Nobody would blink. Yeah. But the time has long, Pat, we've seen these attacks over and over and over again. They've been in the news. Baltimore City was actually hit by one of these. Like two years ago and it's time, it's time, if you work for a municipality or even a company, you need to address this process and how this works because this is a very common vector. So, and that's really the only solution for it is, you're not going to get the, there is no technological solution to this problem because sometimes somebody may in fact change their banking details. They may say, I'm done working with this bank, I'm going to go to another bank and I have to redirect my funds over there. Don't just trust an email on that. That is insufficient. You need to say, oh, okay, well then here's what we're going to need to do and come up with a process. Right. Maybe they have to come in and verify this information in person. Right. It gets some verification from the bank. Right. Right. Our town's on their own. We have to wonder because I googled Harpshole really quick. It's a town of 5,000 people. Oh, wow. So, I mean, it is, that's tiny. That's practically a little more than a village. So I'm wondering, is there something that towns can look to? I mean, 5,000 is really small to sort of copy and paste what the good policy is or, I mean, are they all trying to homebrew this from scratch? I'm going to have to do some research on that. Well, my story has some advice here so we'll wait for that as well. Right. They do have insurance. So, I think they're probably going to be covered for the loss, which is nice. But yeah, still out there, the payment fraud is still going on. Oh, yeah. And just happened. That's a hot one. Yep. All right. Well, we will have links to both of those stories in our show notes. Maria, what do you have for us this week? Well, a story that definitely caught my eye. This one comes in via the Threat Hunter team at Symantec and Carbon Black. So before I jump into the story, gentlemen, I was trying to figure out. What the established metric is for a median dwell time for an attacker to be sort of sitting and waiting and doing their nasty stuff on someone's system. I could not find a consistent answer. It really does depend on who you ask. And just let me pause you there, Maria. What does that mean? The dwell time is basically the time in which an attacker is sitting on a system and either exfiltrating data or trying to establish a footholder. Just being in a place they shouldn't be. Right. They're not instantiating any kinetic effects, except maybe data exfiltration. Well, that kind of not a great thing to be doing. Right. But hanging out in a place they shouldn't be dwelling in it. And it's a number. There's a attached to it. How many days an attacker will be dwelling in a thing. And the idea for a defender is to get that number down. You don't want to an attacker sitting in your system for very long because a longer there, the more damage they're going to do. So we want to be able to find out that they're there as fast as possible. So the goal as good guys is to get the dwell time number down. In any case, I was trying to figure out what a sort of established number is for how long an attacker tends to dwell in a system. And I don't know if either of you have a number for this because I found a bunch. I'm just curious if either of you have heard anything. Last I heard was like 180 days. 180. It's going to, yeah. That's the last metric I remember hearing out. Wow. Maybe that's, I mean, that's really old though. Well, you could be right. I mean, it's, here's the thing. I was seeing things from 10 days, eight days, 14 days. I saw some that said six months. So it does seem to be really all over the place. So 180 is possible. But man, that is a long time. So this wasn't like a quiz to see if you got it right or wrong. I'm genuinely saying I can't find like a consistent number. But let's just say I saw a lot of things in the realm of a week to two weeks on average is often considered like what we're seeing for attacker dwell time in an organization's system. And the reason I'm bringing this up is the story that I'm covering today that comes again from the semantic and carbon black threat, 100 team was about a five month long espionage campaign against a senior executive who was working at a major global stock exchange. And this espionage was specifically targeting this person's outlook account. And again, I want to repeat that the attackers were doing this. They were dwelling, if you will, for five months, which is a long time if we're saying that the average is usually a week or two weeks before they're found out. So five months is, is epically long. And they're working on a stock exchange? Yes. So the target was, it works at a major global stock exchange. Not named, but one can imagine. It's a land full of them. There's only a few. Many bazillions of dollars moving through them. So if this person is a senior executive and five months dwelling on their account and looking at their entire outlook account, so you can just imagine what this person was talking about, who they were talking to, what kind of information they had access to, their contact list, their calendar. I mean, that is, that is the game right there. If you've got that information for five months, I mean, that is a gold mine for an attacker. So, and it's interesting in the post that the threat hunter team put together about this, I'm just going to quote it. They said, we don't normally publish on single victim incidents, but the focus and operational discipline on display here and the central role mailbox theft plays in espionage operations more broadly. Makes this a useful illustration of what a targeted intrusion against a senior individual can look like over months rather than over days. And I really thought the phrase focus and operational discipline was worth highlighting because again, like to carry out an attack against someone like this. And for five months, the attacker was not detected. That 150 days of dwell time is a lot. And it's the blog post goes into a lot of detail. I'm going to do some nutshell. Because we don't need against every step, but y'all can read it if you want. But the attackers basically took a lot of really tiny steps and were very, very patient in making their footprint as small as possible. They didn't get greedy. They didn't, you know, they didn't overshoot like they were, they really took their time and exfiltrated data really bit by bit, drop by drop. And the attackers also hid their traces essentially by using cover from legitimate services to look as legit as possible. So that's how they were able to essentially dwell on that system for five months. So importantly, because I'm sure someone's going to ask, we do not know how the attackers initially got in. So maybe one day there will be an update to this story. So we can, we can conjecture, but genuinely we don't know yet if it was fishing or whatnot. We have no idea. But once the attackers were in and they managed to get a foothold on the victim system, they would schedule tasks with names that looked like legitimate Adobe, Lenovo, or one drive system services, just kind of running as they often do in the background. Because I don't know about you. I don't often look at my task manager just to be like, hey, what's running? Do I recognize all of these things? >> Yeah, I do. Pretty frequently actually. >> Wait, so you actually do that? >> Yeah. >> Really? >> Yeah. >> Do you think? >> Do you think a senior executive? >> No, no. >> No. >> Absolutely. >> Joe is pretty self aware when it comes to these things. >> And Joe, can you tell me that every single thing that's running in your task manager, you definitively know what it is and can identify it? >> Sometimes I Google what the processes are. If I see something I don't recognize, I go, what is that? And I look it up and it's, oh, this is a Microsoft process for indexing or something. But yeah, I don't know. When I go looking, I do some investigation. But I'm a cybersecurity professional. That's what I do for a living and not I don't do exactly this, but I've always been paranoid on this kind of stuff. And I've always wondered, hey, what's running on my system? >> That's a good thing for me. >> For me, I have done this. I do it from time to time. But for me what usually triggers it is that the fans will start spinning up on me. >> Good, sorry. >> Yeah. >> And I'll be like, because I have a MacBook Pro here and it rarely do the fans ever make a peep. So if they start spinning up, I'm like, boy, somebody's lost the plot. >> Somebody's mining Bitcoin using my machine. >> Right, it's going on. But like Joe said, nine times, well, nine times out of ten, every time I've looked it up, I have never found anything malicious. But what I have found is some kind of indexing tool that's just going into town. >> Yeah, I was going to say, you and I are both running on Mac. So for us, it's activity monitor and not task manager. >> Right. >> Same idea. And I always have mine running, but I will absolutely fess up. There are a lot of little things running there. I don't know what they are. And I probably should. But I don't, but I'm just fessing up. >> You're too busy clicking links. >> It's true. And honestly, my machine is probably just a typhoid Mary of all sorts of things. >> That's right. >> It's just, honestly, it's a miracle that I'm even here right now. >> Right. >> But you're on the panel. >> No, patient zero when it comes. And the day comes and they try to figure out what caused the great downfall of Western society. It was me. - Maria's family. (laughing) I did it. You're welcome. - Yeah. - Yeah. So going back to this story and not my terrible security hygiene, the attacker in this case would have these legitimate looking tasks running in the, you know, running in the background and would also re-register these tasks every few weeks during their campaign of data exfiltration so they establish persistence. And then for command and control, the attacker used a persistent instance of Dropbox, which a lot of us have running all the time. And later they also used one drive personal, another completely legitimate tool. And then dripped by dripped, really slowly and tiny little chunks, they would exfiltrate data from the outlook account. And again, I'm gonna emphasize, they did this very slowly. So this was never enough data leaving that would trigger an alert or even downgrade system performance. So no fans were a spinning. Nobody was overclocking their system. It was just like real quiet, real in the background. And nothing that would make the person that who was targeted here actually think to check their task manager and go, what's going on that's taken up like 95% of my CPU. You know, it's nothing like that. So nothing looked suspicious, nothing acted suspicious. So that five months of dwell time makes a lot of sense in that case. So there's no necessarily like take away for the average person here because this was clearly highly targeted espionage. And then if there's anything actionable to be done here, it's for an IT professional. - Right. - So, but it was very interesting that the attackers also really left very little trace of themselves. There was not enough information from the tools that they used or other clues left behind like a system identification info. There was not enough left behind even make a guess about who the attacker might be, which is just like, wow. - I just, I find this story super fascinating. - And I want to mention for the IT pros who maybe listening going, oh, Symantec did actually publish the indicators of compromise. So if this is something that sounds like it might be relevant to you, there are IOCs published on the blog post that you can look at. But I just, very interesting that, you know, slow and steady one the race on this one. And also the attackers were very careful, meticulous and patient. And we don't always see stuff like that. - Do we know what kind of data they X-FUL traded? - I don't, that was not published either. So yeah, I can't imagine it was anything that people want. (laughs) - Well, I've passed, I talked to somebody recently. I can't remember who it was. I was interviewing somebody who was talking about this kind of espionage and how sometimes these people are just looking for the movements of the market. - Right. - Right. They just wanted insider information. - Yep, that is what they use. - Exactly what this screams to me. I don't know what an executive at a stock exchange gets in terms of information. But I'll bet they have better access than the average person does. They might have earnings reports early. I don't know if they do. I, this is one part of the business world, I don't know. - Yeah. - Yeah. - You know, the investing world. I don't know when people find out earnings, or are they at, I know that you have to file these earnings with the SEC. So, you know, if I was a malicious actor, I'd be targeting the SEC for the earnings reports or the filings before they come in. But I think you can time that with public release. I don't know. I wish I knew what. - Well, well, so it sounds like we need to poke around on Paulie market to see if somebody made a pretty penny. - Oh yeah. Yeah, I'll guarantee you, I'll guarantee you, if you look into this, there were some big trades before large earning announcements that people made a lot of money on. And that was probably, that would be my guess is what the outcome of this was. And this is probably some very sophisticated criminal organization. - We did a story about a week ago about, I believe it was a Google engineer who was accused of having access to the, I guess, Google published lists of one of the most popular search terms for the past year, six months, whatever it might be. And this person had access to that before it was released publicly and made a bunch of Paulie market bets on what they would be and one big is he knew what they would be. - Is Paulie market the, Paulie market's the futures organization? - I don't know how you label it as-- - The gamble on everything. - Yeah, yeah, just you bet on, yeah. - But it's not gambling because these are actually investment vehicles and that's how we're getting around the gambling. - You're okay, yeah. - If you say so. - Okay, real aware. - They keep them in an arms length. But anyway, his betting was conspicuous enough that I think that was part of how they tracked them down. See, he was, and I, you know, same thing with the SEC, they've got finely tuned systems for trying to sniff out this stuff. But like, I think as Maria points out, like one of the things about this is discipline and patience. - Right. - Yeah. - And yeah, all right, interesting story. So we'll have a link to that in the show notes. I'll tell you what, let's take a quick break here. We will be right back after this message. (upbeat music) (upbeat music) - Most environments trust far more than they should and attackers know it. Threat locker solves that by enforcing default and eye at the point of execution. With Threat locker allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave. And with Threat locker DAC, defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. Threat locker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives SISO's real visibility, real control, and real peace of mind. Threat locker makes zero trust attainable even for small security teams. CY thousands of organizations choose Threat locker to minimize alert fatigue, stop ransomware at the source and regain control over their environments. Schedule your demo at Threat locker.com/N2K today. (upbeat music) All right, we are back and it is my turn here. My story comes from the folks at Bitdefender. This is a story they shared. It's called the Deepfake Boss Scam, how to verify requests before it's too late. (laughing) So we'll just set this up. Imagine that you get a video call from your CEO and at first glance everything looks right. The face looks right, the voice sounds like them. And they tell you that a confidential deal is underway and they ask for an urgent fund transfer. Would you stop and question it? - Yes. - Only because I'm on this show and I've seen this exact scenario before. - Right. - Right. - Right. Well, according to Bitdefender, this scenario is becoming increasingly prevalent. The bad guys are using AI to create these convincing deep fakes of executives and business leaders. And these personas can appear in video meetings or on phone calls or voice messages. And they are there to exploit the trust that the leader has earned with their employees. Perhaps also fear. - Right. - But they're pointing out that this isn't just a theoretical thing. Hundreds of thousands in some cases, millions of dollars have been lost after the employees were convinced that they were speaking with the leaders of their companies. They pointed out one case where attackers used an AI-generated voice clone to impersonate the CEO and trigger a fraudulent transfer of funds. There was another one where an entire video conference was populated with synthetic versions of executives and colleagues. So not just one person, imagine getting on a Zoom call and there's the board of directors. - Right. - Right. - Like an AI intervention. - Right. (laughing) - Dave, we love you and we care about you. - Oh man, the flop sweat. That's immediately. - Right. - Right. And they were persuading the employees to move large sums of money. And imagine, I would imagine most people today, you think, well, okay, maybe they could scam a one-on-one with my boss, but surely the entire half a dozen people of the whole board of directors, that can't be raked, but according to this article, it can. So they use a lot of things we talk about here all the time, authority, urgency, familiarity, and then they apply pressure for the person to act quickly. Again, we using sensitive financial matters. And people are reluctant to challenge their boss. And they point out that remote work, hybrid work, increases the opportunities for this sort of thing because it's harder to go down the hall and knock on your boss's door and say, "Did you just ask me to transfer $2 million when you're working at home?" - Well, yeah, and also presuming that the executive is in the office, which in my experience is almost never the case, they're usually traveling or in a meeting or whatever. - That's true. Right. All in air quotes. - Mm-hmm. So they point out the effective defense, something we talk about here all the time, verification, confirm these requests through a separate communication channel. - Right. - You should have a multi-person approval process so your organization should require anything above a certain amount of money should it get in front of more than one set of eyes. And then also training your employees to recognize these sort of, sorts of manipulation tactics. They say if something involves money, sensitive data, or access to critical systems, pause, verify, and be sure to follow the established procedures. But you need to have these procedures in place. And they're just emphasizing here that this AI, the capabilities of these AI systems is growing every day, and these deep fakes are getting more and more convincing. They're getting faster. So there's not so much of a pause between a question and an answer when an AI is responding to things. So people really need to, unfortunately, become more skeptical of what they see in here and really lean into these verification processes. What do you guys make of this? - Yeah, I think that the policy angle of this is the key. Similar to the story I did about the company, the municipality, there we go. (laughing) I'm a slimwell, lately Dave. (laughing) Yeah, so the municipality who lost all that money, you really have to focus on the policy and the training. And just be aware that this is out there, that these people are getting scammed. When we first saw this kind of thing happening, it was with email, and the people who were, this is before LLMs were big and popular and available. The people were imitating the language style, the linguistic writing style of the CEO, to get somebody in a distant part of the organization to send millions of dollars for exactly this kind of thing. Hey, we got a secret deal coming, don't tell anybody. - Right, and I would also add to that the gift card scams, where you get a text message from the CEO, that says, "Hey, I'm in a meeting or I'm at a conference, I need you to do me a quick favor." - Right. That, I don't know, that seems like, I mean, that's gonna impact the individual more financially, than it is the company, but you still wanna protect against that, and maybe have the company of the CEO say, "Look, everybody, every manager, it's our corporate policy that we will never ask you to run a personal errand for us." - Right. - And that includes buying us gift cards. - Right. - Right, especially. - Yeah, right. All right, well, we will have a link to that story in the show notes, and again, we would love to hear from you. If there's something you'd like us to consider for the show, please email us. It's [email protected]. All right, Joe, Maria, it is time for our Catch of the Day. (upbeat music) - Dave, our Catch of the Day comes from a listener named Pete from the Netherlands, and he writes, "Hi, Dave Joe, and the one and only Maria." - I promise I didn't pay this person. - Okay. You guys have seen it on the show, fake prints, and it's dubious package tracking links, endless romance games, but I think I have a fun Catch of the Day nomination for you, a cybersecurity consultant who is so desperate for a payday that they're actively trying to bypass the integrity of the entire IT sector. - Oh, I was approached on LinkedIn by a self-proclaimed, quote, "Senior consultant," end quote, offering a massive laundry list of IT and cybersecurity certifications, everything from a CISS P to Salesforce. I have the CISS P, but I've never bothered to get the Salesforce thing. Instead of asking about the coursework, I decided to test her and ask her straight up. Can I just buy them? Her answer was shocking and hilarious. Yes, you can. (laughing) - Colleague, Contains. Can I just buy these certifications? So maybe now I will get that Salesforce. (laughing) - There you go. I've attached screenshots of the conversation. - What it works, yeah. - Yes, screenshots are my laptops, so nobody can judge me by my reception or terrible battery status, why I appreciate that. - Wait, look out for yourself. - Yeah, smart thinking there, Pete. - Yeah, do you want to just get into this? Yes, let's get into it. So Maria, why don't you start off the person getting all this started, it's named Uncasha. So why don't you go ahead and I will play the part of Pete. - Hello, warm greetings. Thank you for adding me to your network, wishing you a wonderful day ahead. Well, I am a trainings consultant for IT and Cybersecurity Certifications. Good heavens, do I need to read all those? - No, I can't. - That is a little-- - This is a copy and paste, basically all of them. - Okay, are you looking for any certification and trainings like (imitates engine) I mean, it is just, you name it, it's in this list. - Yes, yes. - And end with or any other. - Or any other question mark? - Can I just buy them? - Yes, you can. - May I know which certification you are looking for, your profile growth and skill development so that I can arrange details for you? - Sales force. - Yes, we can assist you with sales force training and certification. I will request my training manager to provide you with comprehensive details regarding the certification, training, and the entire process. Please confirm me your contact number so I can arrange the details for you as per your comfortable time. I don't want the training, just the certification. - Okay, is this your right WhatsApp number? Hey Pete, I'm awaiting for confirmation so that we will provide you all the details regarding the certification. - I really don't want to make phone calls about this. - Not for call without any permission, only WhatsApp texting you can. - Not interested anymore. - Okay, no problem. - So Pete goes on, Joe, do you want to read this part where he describes where he says the smoking gun? - Yeah, here's my, he says, here is a quick breakdown of their playbook, the smoking gun. In the second screenshot, she openly admits that I can bypass the exams and just purchase the certificates directly. Official bodies like sales force or Cisco obviously never do this, meaning they are either selling worthless fake PDFs or offering an illegal proxy testing service. The platform pivot, which is when, she wants to go to WhatsApp. As soon as I showed interest, she aggressively tried to move the conversation over to WhatsApp. Is this your WhatsApp number or only WhatsApp texting you can, which I can barely get through is a sentence so bad I can barely get through. - Only WhatsApp texting you can. - Right, that's a classic move to escape LinkedIn's automated fraud detection systems, which is 100% correct. - Yep. - It's the ultimate irony, a scammer attempting to sell cybersecurity credentials through blatant fraud. - Love the show, keep up the fantastic work, Pete. - Wow. - Well, as someone who has a PhD from Harvard, (laughing) let me just say that I was on top of this from step one. - Right. (laughing) - You know what, I think, I might get a fake PhD thing from Harvard or Stanford or something, just hang it up in my office and see if people notice that we have a PhD from Harvard? - No. (laughing) - What's that? - You should make one from all of the Ivy League schools and just rotate them every week. See if anybody notices that your PhD from Harvard became a PhD from Yale, became a PhD. - Yeah. (laughing) - I did go to Dartmouth. - Once. - For about a week. (laughing) - Okay, like, that's one of my favorite things to tell people, I went to Dartmouth. You did, yeah. I went to Vanderbilt too. Just went there. (laughing) - Nice cafeteria. - Right, yeah. - All right, well again, thank you Pete from the Netherlands for sending this in. We do appreciate it. And if you have something you would like to send us, please do. Our email address is [email protected]. (upbeat music) Most environments trust too much and attackers know it. Threat Locker enforces default deny at execution, blocks unknown apps and limits what trusted apps can do. Stop ransomware at the source. Get your demo at threatlocker.com/n2k. And that is our show brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights to keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to [email protected]. This episode is produced by Liz Stokes, our executive producer is Jennifer Iban. We're mixed by Elliott Peltzman and Trey Hester. Peter Kielpie is our publisher. I'm Dave Bittner. I'm Joe Carrigan. - I'm Maria Vermauses. - Thanks for listening. (upbeat music)

Podcast Summary

Key Points:

  1. Joe Carrigan’s wife was targeted by a puppy scam on Facebook, where scammers demanded a deposit before showing the dogs; she avoided losing money after recognizing it as a scam.
  2. Dave Bittner encountered an escaped emu named Dexter on a road trip in Maryland, which was safely returned to its farm after a four-hour capture by state troopers.
  3. Joe shared two stories

Summary:

In this episode of the Hacking Humans Podcast, hosts Dave Bittner and Joe Carrigan, along with Maria Vermauses, discuss recent scams and personal anecdotes. Joe recounts how his wife was targeted by a puppy scam on Facebook after their dog Fred passed away. The scammers demanded a $500 deposit for a miniature poodle, refused to let her visit the dogs, and reduced the price to $250.

Joe identified it as a scam, and his wife eventually caught on, avoiding financial loss. Dave shares a strange experience on a road trip to Maryland’s Eastern Shore, where he saw an emu named Dexter wandering on the highway. Dexter had escaped from a local farm and was captured by state troopers after four hours.

2 billion. Nevada had the highest per capita fraud reports. Another story from Maine covers Harpswell, a town of 5,000 people, losing $189,000 to a vendor payment scam.

The town is strengthening its payment verification policies. Joe emphasizes the need for organizations to implement robust verification processes for payment changes, as these scams are common and costly.

FAQs

The Hacking Humans Podcast examines social engineering scams, phishing schemes, and criminal exploits that impact organizations globally.

Joe recognized the scam when the seller demanded a deposit and refused an in-person visit. His wife eventually realized it was a scam and confronted the seller.

Dave saw an emu named Dexter that had escaped from a farm on Route 50. State troopers captured it after four hours.

The top schemes are malicious investment advice ($6.4 billion), romance scams ($1.2 billion), government impostures ($750 million), business impostures ($750 million), and job scams ($500 million).

Nevada reported the most fraud cases per 100,000 residents, with 892 reports.

Harpswell was scammed through a vendor payment fraud, likely via email, where payment instructions were changed to divert funds. The incident is under investigation.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.