loader from loading.io

Surviving a Ransomware Attack

Easy Prey

Release Date: 01/14/2026

Love, Lies and Locked Up show art Love, Lies and Locked Up

Easy Prey

What sounds like the plot of a crime thriller was Sharon Armstrong’s real life. An online romance drew her into an elaborate web of lies involving overseas contracts, invented emergencies, and several people playing carefully planned roles. By the time she arrived at an airport in Argentina with five kilograms of cocaine hidden inside her suitcase, she still believed she was carrying business documents for the man she loved. Sharon was arrested and spent more than two years in an Argentinian prison before returning home without a conviction. During that time, she had to confront the truth of...

info_outline
The Recruitment Trap show art The Recruitment Trap

Easy Prey

Everybody is searching for ways to increase income. Unfortunately, MLMs often look like an easy way to start a business without taking on the cost of a traditional company. The pitch sounds simple. Buy the product, follow the plan, and put in the work. The numbers behind those promises often tell a different story. Today’s guest, Stacie Bosley, has spent years studying what really happens inside MLMs. She is a professor at Hamline University in Minnesota and holds a Ph.D. in applied economics. Her research covers multi-level marketing, consumer protection, income claims, and pyramid scheme...

info_outline
Convincing Deepfakes show art Convincing Deepfakes

Easy Prey

A familiar voice on the phone or a recognizable face on a video call used to offer some reassurance that you knew who you were dealing with. AI has changed that. Voice cloning, face swaps, and real-time video impersonation now allow scammers to convincingly pose as executives, job candidates, romantic interests, or even family members. Understanding how these attacks work and where they may be headed is a central part of Tom Cross’s work as Head of Threat Research at GetReal Security. Tom has spent more than 30 years studying cybersecurity threats, software vulnerabilities, and the methods...

info_outline
When Trust Becomes a Trap show art When Trust Becomes a Trap

Easy Prey

Most people use technology all day without giving much thought to what is happening behind the screen. We trust routers that may not have been updated in years, depend on internet systems few of us understand, and now turn to artificial intelligence for everything from travel plans to home repairs. That convenience comes with tradeoffs. In this episode, we look at the weaknesses built into our connected world and what happens when our technical knowledge fails to keep pace with the technology surrounding us. Sherrod DeGrippo leads threat intelligence for Unit 42 at Palo Alto Networks, where...

info_outline
Scam Compounds show art Scam Compounds

Easy Prey

When most people think about online scams, they picture criminals sitting behind a screen and stealing from victims around the world. But in Southeast Asia, many of the people sending those messages are victims too. Some were promised legitimate jobs, flown across borders, trapped inside guarded compounds, and forced to scam others while trying to survive.  In this episode, I talk with Ivan Franceschini, a lecturer in Chinese Studies at the Center for Contemporary Chinese Studies Asia Institute. After years of studying labor rights, civil society, and Chinese investment in Cambodia,...

info_outline
Sports Betting show art Sports Betting

Easy Prey

Sports betting is everywhere now. It is in the commercials, on the apps, wrapped into game broadcasts, and sold as a fun way to make sports more exciting. But behind the easy sign-ups and “risk-free” offers is an industry built on odds most people do not fully understand, fine print that can cost real money, and a business model that depends on customers losing. In this episode, I talk with Danny Funt, an investigative reporter and the author of Everybody Loses: The Tumultuous Rise of American Sports Gambling. His reporting on sports betting, politics, news, and sports media has appeared...

info_outline
Google Maps Scams show art Google Maps Scams

Easy Prey

Most people are not thinking clearly when they need a locksmith or a plumber. They are locked out, water is leaking, something broke, and they just want somebody nearby who can fix it. So they open Google, tap one of the first businesses that comes up, and assume the listing is real. Unfortunately, that is exactly the kind of situation scammers count on.  In this episode, Mike Blumenthal, co-founder and analyst at Near Media, talks about fake local business listings and the ways bad actors have learned to game Google Maps. Mike has been following this problem for years, going back to the...

info_outline
Job Recruiter Scams show art Job Recruiter Scams

Easy Prey

Job hunting is hard enough without having to stop and ask whether the recruiter in your inbox is even real. My guest today, Jay Jones, ran into that problem firsthand after being laid off in December 2023. With his daughter due to be born just weeks later, Jay began receiving messages from recruiters that looked promising at first, but quickly turned out to be fake. Jay, also known as The Profiler, decided not to ignore what was happening. He started investigating the patterns behind these scams and has since identified and helped remove thousands of fake profiles, fraudulent companies, and...

info_outline
Bail Bonds Scams show art Bail Bonds Scams

Easy Prey

Getting a call that someone you love has been arrested is scary enough. Getting that call from someone who sounds official, knows just enough to seem credible, and says you have to send money right away is exactly the kind of moment scammers are counting on. Julie Henderson is the president of the North Carolina Bail Agents Association and has spent 24 years working in the bail bond industry.  She started in the field almost by accident after applying for what she thought was a legislative assistant job, and she has stayed because she cares about helping people get through one of the most...

info_outline
Confessions of a Fraudster show art Confessions of a Fraudster

Easy Prey

Technology keeps changing, but many of the most effective scams still come down to something very human: trust. My guest today is Tony Sales, co-founder of We Fight Fincrime and Underworld TV. Tony has a perspective most people in fraud prevention will never have. Earlier in his life, he was involved in organized financial crime and was once described in the UK press as Britain’s greatest fraudster.  After years in that world, and after serving time in prison, Tony made the decision to use what he knew to help stop the very crimes he had once been part of. Today, Tony works with...

info_outline
 
More Episodes

A ransomware attack doesn’t always announce itself with flashing warnings and locked screens. Sometimes it starts with a quiet system outage, a few unavailable servers, and a sinking realization days later that the threat actors were already inside. This conversation pulls back the curtain on what really happens when an organization believes it’s dealing with routine failures only to discover it’s facing a full-scale cyber extortion event.

My guest today is Zachary Lewis, CIO and CISO for a Midwest university, a 40 Under 40 Business Leader, and a former Nonprofit CISO of the Year. Zachary shares the inside story of a LockBit ransomware attack that unfolded while his team was still building foundational security controls, forcing real-time decisions about recovery, disclosure, negotiations, and whether paying a ransom was even an option.

We talk about the shame that keeps many cyber incidents hidden, the emotional weight leaders carry during these moments, and the practical realities that don’t show up in tabletop exercises from buying bitcoin to restoring systems when password managers are encrypted. It’s an honest, grounded discussion about resilience, preparedness, and why sharing these stories openly may be one of the most important defenses organizations have.

Show Notes:

  • [04:05] Zachary Lewis explains why the absence of an immediate ransom note delayed suspicion of an attack.
  • [06:00] The first technical indicators suggest something more serious is unfolding.
  • [07:45] Discovering encrypted hypervisors and realizing recovery won’t be straightforward.
  • [09:30] Zachary outlines when data exfiltration became a real concern.
  • [11:05] Receiving the LockBit ransomware note confirms the organization has been compromised.
  • [12:55] The 4:30 a.m. phone call pushes leadership into full crisis mode.
  • [14:40] Zachary reflects on managing fear, responsibility, and decision fatigue mid-incident.
  • [16:20] Executive expectations collide with technical realities during the breach.
  • [18:05] Why “doing most things right” still doesn’t guarantee protection.
  • [19:55] Cyber insurance begins shaping early response decisions.
  • [21:35] Bringing in incident response teams and legal counsel under tight timelines.
  • [23:20] Zachary describes working with the FBI and understanding jurisdictional limits.
  • [25:10] What law enforcement can and cannot realistically provide during ransomware events.
  • [26:50] Opening communication channels with the threat actors.
  • [28:35] The psychological pressure behind ransomware negotiations.
  • [30:10] Attacker-imposed timelines force rapid, high-stakes decisions.
  • [31:55] Zachary walks through the practical challenges of acquiring cryptocurrency.
  • [33:40] Why encrypted password managers created unexpected recovery barriers.
  • [35:15] Determining which systems could be restored first—and which could not.
  • [37:00] Lessons learned about backup integrity and offline recovery.
  • [38:45] The importance of clear internal communication during uncertainty.
  • [40:25] Balancing transparency with legal and reputational concerns.
  • [42:10] How staff reactions differed from executive responses.
  • [43:55] Zachary discusses the stigma that keeps many ransomware incidents quiet.
  • [45:40] Why sharing breach stories can strengthen collective defenses.
  • [47:20] MFA gaps and configuration issues exposed by the attack.
  • [49:05] Why tabletop exercises fall short of real-world incidents.
  • [50:50] Long-term security changes made after recovery.
  • [52:30] Zachary offers advice for CISOs facing their first major incident.
  • [54:10] What preparedness really means beyond compliance checklists.
  • [56:00] Why resilience and recovery deserve equal priority.
  • [58:30] Final reflections on leadership, accountability, and learning in public.

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review. 

Links and Resources: