Easy Prey
Identity theft is usually framed as an external threat. Hackers, data breaches, anonymous criminals operating somewhere far away. This episode looks at a much harder reality to face: identity theft that happens inside families, often quietly, over many years, and without immediate detection. The damage isn’t just financial. It reshapes trust, relationships, and a person’s sense of stability long before anyone realizes what’s happening. My guest is Axton Betz-Hamilton, an associate professor of financial counseling and planning whose research focuses on familial and child identity theft....
info_outlineEasy Prey
Security failures rarely come from cutting-edge attacks or sophisticated tools. They happen in ordinary moments when someone holds a door, follows an instruction without questioning it, or finds a workaround that makes their day easier. Those small, human decisions are often the real entry points, and they tend to compound over time. This episode picks up the second half of our conversation on exploiting trust with FC Barker, a veteran ethical hacker and physical security expert known for legally breaking into banks, government buildings, and high-security facilities around the world. With...
info_outlineEasy Prey
Most security failures don’t start with a dramatic breach or a mysterious hacker sitting in a dark room. They usually start quietly. Someone assumes a system is locked down. Someone trusts that a door shouldn’t open, or that a machine “just works,” or that no one would ever think to look there. Over time, those small assumptions stack up, and that’s where things tend to go wrong. Today’s guest is FC Barker, a renowned ethical hacker, social engineer, and global keynote speaker with more than three decades of experience legally breaking into organizations to expose their blind...
info_outlineEasy Prey
A ransomware attack doesn’t always announce itself with flashing warnings and locked screens. Sometimes it starts with a quiet system outage, a few unavailable servers, and a sinking realization days later that the threat actors were already inside. This conversation pulls back the curtain on what really happens when an organization believes it’s dealing with routine failures only to discover it’s facing a full-scale cyber extortion event. My guest today is Zachary Lewis, CIO and CISO for a Midwest university, a 40 Under 40 Business Leader, and a former Nonprofit CISO of the Year....
info_outlineEasy Prey
Why do smart, capable people fall for scams even when the warning signs seem obvious in hindsight? In this episode, Dan Ariely joins us to examine how intuition often leads us in the wrong direction, especially under stress, uncertainty, or emotional pressure. A renowned behavioral economist, longtime professor of psychology and behavioral economics at Duke University, and bestselling author of Predictably Irrational, The Upside of Irrationality, Misbehaving, and Misbelief, Dan has spent decades studying why rational people consistently make choices that don’t serve them. We talk about...
info_outlineEasy Prey
In a world where we’re told to carry our entire lives in our pockets, we’ve reached a strange tipping point where the very devices meant to connect us have become windows into our private lives for those who wish us harm. It’s no longer a matter of looking for the "shady" corners of the internet; today, the threats come from nation-state actors, advanced AI, and even the people we think we’re hiring. We are living in an era where the most sophisticated hackers aren't just trying to break into your phone, they’re trying to move into your business by pretending to be your best...
info_outlineEasy Prey
The intersection of AI and cybersecurity is changing faster than anyone expected, and that pace is creating both incredible innovation and brand-new risks we’re only beginning to understand. From deepfake ads that fool even seasoned security professionals to autonomous agents capable of acting on our behalf, the threat landscape looks very different than it did even a year ago. To explore what this evolution means for everyday people and for enterprises trying to keep up, I’m joined by Chris Kirschke, Field CISO at Tuskira and a security leader with more than two decades of experience...
info_outlineEasy Prey
Publicly available data can paint a much clearer picture of our lives than most of us realize, and this episode takes a deeper look at how those tiny digital breadcrumbs like photos, records, searches, even the background of a Zoom call can be pieced together to reveal far more than we ever intended. To help break this down, I’m joined by Cynthia Hetherington, Founder and CEO of The Hetherington Group, a longtime leader in open-source intelligence. She also founded Osmosis, the global association and conference for OSINT professionals, and she oversees OSINT Academy, where her team trains...
info_outlineEasy Prey
Sometimes we forget how much trust we place in the little things around us like a lock on a door or a badge on someone’s shirt. We see those symbols and assume everything behind them is safe, but it doesn’t always work that way. A person with enough confidence, or the right story, can slip through places we think are locked down tight, and most of us never notice it’s happening. My guest today is Deviant Ollam, and he’s one of the rare people who gets invited to break into buildings on purpose. He talks about how he fell into this unusual line of work, the odd moments that shaped his...
info_outlineEasy Prey
Fraud today doesn’t feel anything like it used to. It’s not just about somebody skimming a credit card at a gas pump or stealing a check out of the mail. It has gotten personal, messy, emotional. Scammers are building relationships, earning trust, and studying the little details of our lives so they can strike when we’re tired, distracted, or dealing with something big. And honestly, most people have no idea how far it’s gone. My guest, Ian Mitchell, has spent more than 25 years fighting fraud around the world and leading teams in the financial sector. He’s the founder of The Knoble,...
info_outlineSome people are willing to hand over their identities for cash, while organized fraudsters are lining up to buy them. What used to be a matter of stolen credit cards has turned into a global marketplace where personal details fuel large-scale fraud. Now with AI, automation, and deepfakes making impersonation easier than ever, it’s becoming much more difficult to protect identities.
To understand how we got here and what can be done, I spoke with Ofer Friedman, Chief Business Development Officer at AU10TIX. Ofer has spent more than 15 years in the identity verification and compliance world, working with companies like PayPal, Google, Uber, and Saxo Bank. He’s seen the evolution from basic ID checks to today’s sophisticated fraud-as-a-service platforms, where attackers can buy stolen data cheaply, sometimes for just a few dozen dollars, and use it to launch real-time, undetectable attacks.
Ofer explains why traditional approaches like uploading a photo of your ID are no longer enough, and why privacy, in practice, is already gone. He walks through the “minefield strategy” of fraud prevention, where businesses must layer multiple defenses like device, network, and behavioral indicators. We also talk about the rise of digital IDs, the coming challenge of quantum computing, and why regulators and service providers, not consumers, are now the ones who must shoulder the responsibility of protecting identities.
Show Notes:
- [01:00] Ofer explains his role in forecasting fraud trends and designing solutions, drawing from years in identity verification and compliance.
- [03:32] The conversation turns to people selling their identities, with fraudsters buying because impersonation is easier than ever.
- [05:18] Ofer describes how sales happen in encrypted channels like Telegram or Discord, often targeting desperate individuals.
- [07:07] He calls these sellers “identity mules,” noting they only receive a few dozen dollars per transaction.
- [08:20] With billions of stolen data points in circulation, there’s more identity data than people, making personal data cheap and plentiful.
- [09:00] Regulations require minimal information, often just basic ID details and a selfie, which makes fraud easier to attempt.
- [11:00] Deepfakes and injection attacks undermine even live ID checks, giving rise to fraud-as-a-service platforms that automate attacks.
- [13:00] New age verification laws in the US and UK highlight the growing tension between privacy and regulation.
- [15:53] Ofer outlines the “minefield strategy,” where layered defenses (ID, device, network, behavior) are needed since no single tool is sufficient.
- [18:46] The discussion shifts to how fraud is global, not just American, and why digital IDs may offer better protection though not without flaws.
- [21:45] Fraud is evolving quickly with automation, enabling fraudsters to launch massive, randomized attacks.
- [29:03] Ofer explains the three lines of defense: live checks, collateral risk factors, and behavioral monitoring.
- [31:40] He stresses that privacy is effectively dead, as the balance between privacy and security always favors security.
- [34:47] Consumer education won’t stop fraud—technology and companies must take the lead in identity protection.
- [39:14] Identity verification and cybersecurity are merging into one process that scrutinizes users everywhere online.
- [45:34] The rise of agentic AI could reduce friction in transactions, but desensitization means people accept more scrutiny over time.
- [47:24] Ofer argues regulations need to evolve, calling for service providers to be rated and held to higher standards.
- [50:36] He reflects that we’re moving into a new era where deepfakes and impersonation will affect not just finances but media, politics, and trust itself.
- [52:05] Ofer closes with advice on evaluating identity verification vendors, emphasizing layered defenses and transparency.
Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.