Easy Prey
A counterfeit handbag may leave someone disappointed. A counterfeit medication, airbag, or child’s car seat can do far more damage. Fake products now reach into nearly every part of daily life, and many of them arrive through online stores that look completely legitimate. Kari Kammel saw the danger firsthand when a pharmacist overseas offered her several versions of the same medication. Some were authentic, while others were openly described as counterfeit. That experience stayed with her. She now directs the Center for Anti-Counterfeiting and Product Protection at Michigan State University,...
info_outlineEasy Prey
A convincing lie no longer needs to look suspicious. It can appear in a familiar social media feed, come from someone who seems real, or arrive as a video that looks almost impossible to fake. By the time doubt sets in, the post may already have been shared thousands of times. Few people understand that online environment better than today’s guest. Nina Jankowicz has spent more than a decade studying what she calls the bad things that happen on the internet. She is an internationally recognized expert on disinformation and online harassment. She was also named one of Time magazine’s 100...
info_outlineEasy Prey
It is easy to say you would never fall for a scam when you are looking at the situation from the outside. In the moment, though, things can feel much less obvious. A request may sound reasonable, the person may seem trustworthy, and saying no can feel awkward enough that you go along with something you would normally question. Today’s guest studies exactly why that happens. Vanessa Bohns is the Bronstein Family Professor and Chair of Organizational Behavior at Cornell University’s ILR School. Her work focuses on social influence, compliance, and the pressure people feel to cooperate, even...
info_outlineEasy Prey
A drink can be out of your sight for only a moment, but that may be all it takes for someone to tamper with it. Spiking can happen in bars, restaurants, festivals, and even among people who already know and trust each other. It also goes far beyond alcohol. Drinks, food, vapes, cigarettes, and other substances can be altered without someone’s knowledge, leaving them vulnerable before they fully understand what is happening. Dawn Dines has spent more than 20 years working to change how people understand and respond to spiking. She is the founder and CEO of Stamp Out Spiking, a UK charity...
info_outlineEasy Prey
What sounds like the plot of a crime thriller was Sharon Armstrong’s real life. An online romance drew her into an elaborate web of lies involving overseas contracts, invented emergencies, and several people playing carefully planned roles. By the time she arrived at an airport in Argentina with five kilograms of cocaine hidden inside her suitcase, she still believed she was carrying business documents for the man she loved. Sharon was arrested and spent more than two years in an Argentinian prison before returning home without a conviction. During that time, she had to confront the truth of...
info_outlineEasy Prey
Everybody is searching for ways to increase income. Unfortunately, MLMs often look like an easy way to start a business without taking on the cost of a traditional company. The pitch sounds simple. Buy the product, follow the plan, and put in the work. The numbers behind those promises often tell a different story. Today’s guest, Stacie Bosley, has spent years studying what really happens inside MLMs. She is a professor at Hamline University in Minnesota and holds a Ph.D. in applied economics. Her research covers multi-level marketing, consumer protection, income claims, and pyramid scheme...
info_outlineEasy Prey
A familiar voice on the phone or a recognizable face on a video call used to offer some reassurance that you knew who you were dealing with. AI has changed that. Voice cloning, face swaps, and real-time video impersonation now allow scammers to convincingly pose as executives, job candidates, romantic interests, or even family members. Understanding how these attacks work and where they may be headed is a central part of Tom Cross’s work as Head of Threat Research at GetReal Security. Tom has spent more than 30 years studying cybersecurity threats, software vulnerabilities, and the methods...
info_outlineEasy Prey
Most people use technology all day without giving much thought to what is happening behind the screen. We trust routers that may not have been updated in years, depend on internet systems few of us understand, and now turn to artificial intelligence for everything from travel plans to home repairs. That convenience comes with tradeoffs. In this episode, we look at the weaknesses built into our connected world and what happens when our technical knowledge fails to keep pace with the technology surrounding us. Sherrod DeGrippo leads threat intelligence for Unit 42 at Palo Alto Networks, where...
info_outlineEasy Prey
When most people think about online scams, they picture criminals sitting behind a screen and stealing from victims around the world. But in Southeast Asia, many of the people sending those messages are victims too. Some were promised legitimate jobs, flown across borders, trapped inside guarded compounds, and forced to scam others while trying to survive. In this episode, I talk with Ivan Franceschini, a lecturer in Chinese Studies at the Center for Contemporary Chinese Studies Asia Institute. After years of studying labor rights, civil society, and Chinese investment in Cambodia,...
info_outlineEasy Prey
Sports betting is everywhere now. It is in the commercials, on the apps, wrapped into game broadcasts, and sold as a fun way to make sports more exciting. But behind the easy sign-ups and “risk-free” offers is an industry built on odds most people do not fully understand, fine print that can cost real money, and a business model that depends on customers losing. In this episode, I talk with Danny Funt, an investigative reporter and the author of Everybody Loses: The Tumultuous Rise of American Sports Gambling. His reporting on sports betting, politics, news, and sports media has appeared...
info_outlineMost security breaches don't begin with sophisticated code or elaborate technical exploits. They begin with a phone call, a convincing email, or someone at a help desk who just wanted to be helpful. The human layer is often the weakest link, and the criminals who understand that are the ones causing the most damage.
My guest today is May Chen-Contino. She's the CEO of Unit 221B, a threat disruption company that delivers actionable intelligence to enterprises, law enforcement, and government agencies. Her background spans cybersecurity, fintech, and SaaS leadership at companies like PayPal and eBay, and she brings a distinctly mission-driven lens to the work, shaped equally by a career in business and a background as a Krav Maga instructor.
Unit 221B operates less like a typical security vendor and more like a specialized investigative unit, with a team that includes tenured ransomware experts, incident responders, and former law enforcement, all focused on one outcome: criminal arrest. May has seen firsthand how ransomware gangs operate with their own codes of conduct, how a younger generation of cybercriminals is throwing those rules out entirely, and why paying a ransom is increasingly a bet that doesn't pay off.
We talk about why social engineering has overtaken technical hacking as the dominant attack vector, what organizations and individuals should never do in the aftermath of a breach, and how crimes against children online often go unreported for the worst possible reasons. May also shares a story from her own experience being scammed on eBay, and what she did about it, which tells you everything you need to know about how she approaches this work.
Show Notes:
- [1:28] May shares her background and how she came to lead Unit 221B, a threat disruption company serving enterprises, law enforcement, and government.
- [1:41] May traces her path into cybersecurity, explaining how a lifelong sense of justice and a friendship built through Krav Maga training led her to a team of investigators doing real criminal work.
- [5:55] May recounts being scammed while selling luxury shoes on eBay, describing how a fraudulent PayPal email convinced her the sale had failed after she had already shipped the item.
- [8:22] Rather than accepting the loss, May engaged the scammer directly, intercepted her own shipment through FedEx, and used a photoshopped payment screenshot to flip the situation on him.
- [11:36] The story ends with May recovering her shoes, followed by a candid note that this approach carries real risk and is not something she would recommend to others.
- [12:57] May outlines Unit 221B's core work, including criminal investigations, threat intelligence, pen testing, and incident response, all oriented toward federal prosecution and criminal arrest.
- [16:52] The evolving threat landscape, contrasting professional ransomware organizations that tend to honor agreements with a younger generation of cybercriminals who operate without limits.
- [18:44] May describes this younger criminal group in detail, noting members are predominantly 14 to 26 years old, English-speaking, and motivated as much by social status as financial gain.
- [21:49] May explains why wiping systems and restoring backups after a breach is one of the most damaging mistakes an organization can make, eliminating evidence and removing any path to prosecution.
- [23:04] She walks through Unit 221B's incident response process, covering digital forensics, insider threat identification, and determining who is behind an attack before advising on next steps.
- [26:32] May addresses the ransom payment question directly, recommending against paying as a default while acknowledging that knowing your adversary is essential to making the right call.
- [28:04] The discussion covers the legal and PR dimensions of a breach, including notification obligations and why some organizations choose to go public about what happened.
- [31:08] May pushes back on the perception that law enforcement doesn't help, explaining that federal agencies are understaffed and must prioritize cases, but are genuinely committed to the work.
- [34:08] The issue of victims deleting evidence before reporting, and how frequently this forecloses any possibility of investigation or prosecution.
- [34:55] The conversation turns to crimes targeting children, including sextortion, and why open dialogue between parents and kids is critical to getting victims to come forward before lasting harm is done.
- [37:18] May reflects on a keynote she gave at Harvard's Bold Conference for young women, describing the tension between advice to build an online presence and the real safety risks that come with it.
- [38:51] May shares practical security guidance for young people online, including being mindful of what appears in video backgrounds, using strong passwords, and enabling two-factor authentication.
- [40:35] May identifies AI-assisted attacks and social engineering as the two most significant forces reshaping the threat landscape, with technology now available to both attackers and defenders equally.
- [43:45] May describes Unit 221B's invite-only intelligence platform, which brings together top investigators, law enforcement, and private sector experts to collaborate and move cases forward.
- [45:10]Listeners can find Unit 221B at unit221b.com and on LinkedIn, and anyone facing a threat or needing guidance can reach out.
Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.