Easy Prey
Chris Parker, the founder of WhatIsMyIPAddress.com, interviews guests and tells real-life stories about topics to open your eyes to the danger and traps lurking in the real world, ranging from online scams and frauds to everyday situations where people are trying to take advantage of you—for their gain and your loss. Our goal is to educate and equip you, so you learn how to spot the warning signs of trouble, take quick action, and lower the risk of becoming a victim.
info_outline
Brushing Scams with Venkat Margapuri
02/26/2025
Brushing Scams with Venkat Margapuri
Scams come in many forms but receiving a freebie from a scammer doesn’t make sense. If something shows up at your door that you didn’t order, should you be worried? Brushing scams are becoming more common and while they may seem harmless at first they can be a gateway to fraud, identity theft and financial loss. Today we’re diving into how these scams work, why they exist and the real dangers behind them. Our guest is Dr. Venkat Margapuri, an assistant professor of computer science at Villanova University. His research focuses on AI applications in agriculture and healthcare but he’s also spent time studying online fraud and digital security. He’s here to help us understand what’s really going on when scammers send you something for free and most importantly what you should do about it. Show Notes: [00:44] Venkat is an assistant professor in the department of computer science at Villanova University. A lot of his research is focused on artificial intelligence, image processing, and security. [01:53] Brushing scams are where you receive products that you haven't ordered. It's a fraudulent e-commerce scheme. They try to get reviews or add additional sales for their product. [04:48] Venkat explains why it's not a good idea to scan those QR codes in products. You don't want to put your credentials into the website. [05:41] This is where brushing leads to phishing scams by getting people to enter information into a fake website. [06:20] The major risk of receiving these packages is identity theft. [09:30] Scam charges on Amazon can be used to verify stolen credit card credentials and overconfidence often leads to being scammed. [10:52] We discuss where these scammers find people's addresses. [13:05] A lot of scammers are really smart people who got into the wrong business. Key qualities include narcissism and psychopathy. [17:05] When you receive these packages just dispose of them. Don't scan the QR codes. [21:25] A scam where they send emails with the link to free Apple Gift Cards. Be careful about what you post on social media. [22:43] Assume unsolicited contact is a scam. [23:50] Don't share personal information. Look out for things that are out of the norm. [27:04] Venkat talks about advance fee scams. [28:14] Being careful about geographic perceptions. [31:18] Be cautious if you are being rushed. [32:18] Whenever you suspect something isn't right, err on the side of caution and don't do it. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/35314315
info_outline
Ransomware, Phishing and Fraud
02/19/2025
Ransomware, Phishing and Fraud
Cybersecurity isn't just a concern for large corporations. It's vital for businesses of all sizes. It's essential for companies to know how to protect sensitive data, restore from backups, and regularly test their systems with internal pen tests to keep their teams safe. Today's guest is Bryce Austin. Bryce is the CEO of TCE Strategy, a cybersecurity advisory firm. They provide vulnerability scans, penetration tests, fractional CISO services, and incident response services. He is also a professional speaker on ransomware. Bryce is the fractional CISO to many companies, including one on the S&P 500. We talk about the key aspects of cybersecurity for businesses, and how to be proactive with patching, training and strong password management. He shares his experiences with major cyber incidents including ransomware, phishing and the Target breach, and how defense in depth, backups and financial controls are key. Bryce also mentioned the use of password managers, regular vulnerability scanning and external monitoring to increase cyber resilience. We share practical tips for all businesses to protect against ever changing cyber threats. Show Notes: [00:59] Bryce started TCE Strategy in 2016. It's their goal to keep their clients one step ahead of cybercriminal risk. [01:32] He has a degree in chemistry. Technology was just for fun. He ended up working in the payroll space which was ripe for cyber security concerns. [03:00] He was really pushing cybersecurity and then their company was purchased by Wells Fargo. It ended up being amazing training for starting his own cybersecurity business. [05:24] Bryce shares how he was affected by the Target security breach. He ended up unemployed and was deeply affected by food stamp requirements for his family. [07:34] He wanted to make sure he would never go through this again and started his company. [08:19] His public speaking began in 2011. [09:17] He was indirectly affected by the Target breach, and he also shares his indirect personal one. [12:59] Bryce was actually spearfished in 2018. [14:36] Incident response is when something happens from a cybersecurity standpoint and damage has occurred. Oftentimes data is encrypted. This is a ransomware attack. [17:18] Bryce tells the story about how a hotel was hacked and a large payment was able to be intercepted. [18:31] Phishing attacks are where someone clicks on a bad link. [20:38] His biggest Christmas gift was none of his clients getting hacked. [21:05] They also had a ransom demand where they had to pay a million dollars. [23:02] If they would have been looking harder this wouldn't have happened. [26:26] Issues with hooking up to the Internet and having default passwords. [28:07] Why it's impractical to make ransomware illegal. [31:12] Even criminals have a reputation to uphold and usually hand over the encryption key. [33:56] Bryce talks about some of the preventative things that people can do. [34:47] Be proactive and have diligent patching. [35:37] Don't use the same passwords over and over. Use a password keeper. [36:54] Have offline backups. [38:09] Follow all processes and procedures when moving money. Use unique passwords. [39:27] It's important to encrypt your backups. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources: (612) 730-9897.
/episode/index/show/easyprey/id/35083040
info_outline
CISOs: The Ultimate Stress Test With Jill Knesek
02/12/2025
CISOs: The Ultimate Stress Test With Jill Knesek
The CISO role is constantly changing. With all the shifts in cybersecurity, it's crucial to find ways to attract new talent to close the growing skills gap. CISOs now juggle complex systems managed at multiple levels and handle burnout amongst many other responsibilities. Today's guest is Jill Knesek. Jill is the Chief Information Security Officer for Blackline, a company that does financial SaaS solutions. It’s based out of the Los Angeles area. She’s been there almost three years now as the CISO, running the information security team. She previously served as Chief Security Officer for BT Global Services. She has more than 15 years' experience directing security programs, including service as a special agent for the FBI assigned to the Cyber Crime Squad in Los Angeles Field Office, where she was involved in several high-profile cases, including Kevin Mitnick. In this episode, we cover the CISO role evolving from low visibility to a C-level position, managing multi-cloud infrastructures and aligning with other teams and the ongoing cybersecurity skills gap and burnout. Jill also talks about incident response and crisis management and collaboration within the cybersecurity community to fill the blind spots and strengthen the defenses. Show Notes: [01:23] She's now the Chief Information Security Officer for Blackline, a company that does financial SaaS solutions. [02:00] She was also an FBI special agent for 3 and 1/2 years working cybercrime. She was super excited, because this was her lifelong dream. [03:35] She loved the FBI, but she knew she could do more for the industry on the private side. [04:21] Jill talks about how the CISO role has evolved. It's now a C-level position. [06:26] Some of the boards were very interested in what was going on with security. There has to be a balance with funding and proving your success. [07:39] Now complexity is an issue. [09:03] The cloud adds so many connecting services. [11:45] CISOs are getting more responsibility and need more qualified people in their teams. There's a gap with not enough people coming into the cybersecurity industry. [12:30] How the idea of stress and working nights and weekends can deter some graduates from the cybersecurity industry. [15:15] Boards and executive committees expect the CISO to be right in the middle of things. They want real-time updates and to know what everyone is working on right now. [17:47] The importance of keeping a calm level-headed view when something goes wrong. [21:41] We learn about the flow of straightening out curves or incidents. Learn during the small incidents and practice the process. [23:57] The importance of not scolding the team for being too quick to react. It's better to have a false alarm than to ignore a serious problem. [25:10] Jill does a one-to-one with everyone on her team each quarter. She tries to Mentor them with some of the things that she's learned. [30:29] We hear about a couple of incidents where ransomware got into the environment. [35:01] When someone else reported that something weird was going on in the network. [38:27] To help with the talent gap, we need to start introducing cybersecurity at the high school level. [42:15] It's important for CISOs to be connected with other groups and events. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/35048340
info_outline
AI, Automation, and the Future of Cybersecurity With Mike Lyborg
02/05/2025
AI, Automation, and the Future of Cybersecurity With Mike Lyborg
With the increase in targeted cyber attacks, it's more important than ever for organizations to quickly identify and respond to threats. AI is helping security teams by acting as virtual analysts, handling much of the investigation work. However, human oversight is still essential for the final steps and judgment. Today's guest is Michael Lyborg. Michael is the Chief Information Security Officer at Swimlane. Prior to taking his current role, Michael was Global Vice President of Advisory Services, a highly sought-after expert by the world's largest Fortune 500 companies and global government agencies to advise on the creation and operation of industry-leading security operations. In this episode Michael shares his experience and wisdom on today’s cybersecurity challenges. We talk about the balance of automation and human oversight, the risks and rewards of putting AI into security operations, and defense in depth strategies. Michael also covers how military style threat assessments can help with cybersecurity, how AI is evolving for threat prioritization and analysis, and the need for continuous testing and monitoring to prevent automation failures. If you want to know how to stay ahead in a complex cyber world, this episode is full of practical advice. Show Notes: [01:06] Michael has been with Swimlane for about 7 years mainly focusing on larger enterprises, government clients, and partners. He's helping with the automation journey and experience. He also built security programs for other companies and was a Marine. [02:07] Prior to the Marines, he did IT and network security. Michael is originally from Sweden. [04:22] Operational risk management or conducting a limited threat assessment. He's always thinking like a hacker and looking for gaps in security. [06:29] Michael tells a story about his wife's recent experience with a cybersecurity scam. [12:11] How a company decides what level of friction is appropriate to implement proper security. [13:59] Michael talks about balancing what is and isn’t automated. [16:16] Michael shares the story about his early days of automation. [17:23] Continuously review and monitor your automations. [18:41] Starting with documentation is a good first step. [21:45] Michael talks about how awesome it is being able to work in security and automation and help businesses grow and achieve outcomes. He believes in automating the mundane tasks. [22:26] We learn about AI being involved in the defensive side of cybersecurity. [24:50] AI can also bridge the gap between the security team and non-technical people. [26:33] We discuss places where AI probably shouldn't be used. [27:58] Find where AI works for you and then think about incorporating it in your security services. [31:01] The importance of having controls in place when using AI whether it's for security or data analysis. [33:00] Risk can be reduced by training on specific tasks. [34:18] Michael shares the value of mixing human and artificial intelligence through Swimlane. [39:08] The importance of bridging gaps and getting rid of silos. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/35048130
info_outline
Cybersecurity Training from Boring to Engaging With Howard Goodman
01/29/2025
Cybersecurity Training from Boring to Engaging With Howard Goodman
The landscape of cybersecurity training and collaboration is changing, interactive education sessions and cross team communication is key. Building a security culture and staying ahead of the modern threats has never been more important. Today’s guest is Howard Goodman, Senior Technical Director at Skybox Security. With over 20 years of experience Howard has become a well known figure in the cybersecurity world, he combines strategic planning with hands-on application across many industries. In this episode we talk about; security culture, the evolution of cybersecurity training and how Howard got phished during COVID. We also cover organisational challenges, best practices and the future of cybersecurity. Show Notes: [00:48] Howard has a doctorate in cyber operations from Dakota State University. Besides working for Skybox Security, he's also an adjunct professor teaching graduate courses about cyber security. [01:48] Howard shares a phishing experience when he and his wife were selling on eBay during COVID. [03:34] If the pros can fall for something, regular people can too. We need to be on our game 100% of the time. [04:53] We talk about opportunities for adversaries to get in when companies have large cybersecurity teams with a lot of moving parts. [05:29] A lot of people ignore phishing attempts instead of reporting them. [06:04] It comes down to organizations training their people properly. Cyber security training is becoming more interesting, because the boring stuff just doesn't hold people's attention. [10:13] When talking about threats, they focus on the exposure side and the exploitability side. With most businesses, functionality comes before security. [12:47] Formal testing is required before upgrading security patches to make sure that they don't break down the whole system. [13:47] The importance of being able to leverage other security controls while testing patches. Teams need to be able to communicate and act fast. [14:52] Knowing about potential risk is the only way to be proactive. [16:36] Looking at costs and gaps in technology. Failures are often due to a breakdown in communication. [19:33] The approach of starting out security first. [25:08] Best practices include cross-training. Working together and training together. Organizations need to run simulations and see how they react as an organization. [31:06] Skybox talks to organizations about gaps in security. [35:57] We discuss the loss that can happen from not having proper security measures in place. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/34658070
info_outline
Next-Gen Account Security with Christiaan Brand
01/22/2025
Next-Gen Account Security with Christiaan Brand
With phishing and password breaches on the rise, passkeys could offer a more secure, user-friendly solution that could reshape how we protect our online identities. Today's guest is Christiaan Brand. Christiaan is the co-founder of Entersekt, a financial services security firm and a key player at Google in their security and identity teams. A respected voice in cybersecurity, Christian co-chairs the FIDO2 technical working group focusing on standardizing robust online security protocols in advancing the use of passkeys. He has been at the forefront of the shift toward more secure, password-free systems. We’ll hear his insights on the challenges and opportunities of implementing passkeys to create safer online environments for users and organizations. Show Notes: [00:52] - Christiaan is part of the security team for Google accounts. He's been with Google for 9 years. Prior to that he had a startup. [01:30] - He joined the FIDO Alliance around the same time Google joined in 2013. When he joined Google, he was able to continue with the same type of work. [02:35] - Each of the big tech companies represents a portion of the market when it comes to how we interact with the web and apps. [04:06] - He became interested in security when he started thinking about what could go wrong with new technology solutions. He wanted users to be able to access their financial information in a safe and secure way. [05:06] - 2FA began gaining traction with Google in 2011. It coincided with the launch of Google Authenticator. 2FA was also used by a gaming company. [07:54] - Usability is important, that's why having an app that displays the codes was one of the first forays into making the technology more accessible. [08:34] - Passkeys allow us to move beyond passwords, leaving the extra hassle of traditional multi-factor authentication behind. [11:05] - Key fobs were one of the earlier ways to try and bring usability to security. Now the technology is being moved to smartphones. [12:33] - Passkeys are a replacement for a password manager. [13:35] - Passkeys are extremely long and asymmetric in nature. You and the site you're going to both have the passkey. [14:27] - The service will have the public part of the passkey, and you'll have the private part. Even if the public part leaks out, your passkey will still be secure. Passkeys can never be revealed to phishing sites. [15:47] - FIDO brings the second authentication step in. The service also has to identify themselves. [20:04] - Password managers try to balance security and convenience. Logging in or accessing a passkey is a unique challenge for providers. [22:20] - Phone numbers are a way to get users back into their accounts. [25:19] - Single device users have extra challenges. [26:08] - There are pros and cons to external sources of identity. [29:44] - The FIDO website has many certified solutions. [33:21] - To get passkeys into daily users' lives, we need to start using them on daily applications where we log in frequently. [35:49] - Hopefully this passkey solution will stand the test of time. [37:34] - Attacks are beginning to shift to session hijacking. [38:24] - DBSC or device-based session credentials is a new standard parallel to FIDO. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/34588710
info_outline
5 Key Cybersecurity Elements with Kelly Hood
01/15/2025
5 Key Cybersecurity Elements with Kelly Hood
How do phishing scams, AI-powered attacks, and strategic governance intersect? Together, they're redefining the future of cybersecurity. Organizations are navigating a mix of challenges and implementing innovative solutions to proactively address today's threats. Today's guest is Kelly Hood. She is the EVP and cybersecurity engineer at Optics Cyber Solutions. She is a CISSP who specializes in implementing cybersecurity and privacy best practices to manage risks and to achieve compliance. She supports the NIST cybersecurity framework and serves as a CMMC registered practitioner, helping organizations strengthen their cybersecurity posture and develop effective risk management strategies. Show Notes: [01:06] - Kelly is a cyber security engineer at Optic Cyber Solutions. It's her job to help companies protect themselves. [02:17] - Don't be embarrassed if you fall for a phishing scam. [03:01] - These attempts are getting more realistic. Kelly shares how she was briefly fooled by a phishing scam that looks like an email from her mother. [05:25] - The NIST Cybersecurity Framework is a voluntary framework for defining cybersecurity. An update was put out in February of 2024. They also added a new function. [06:01] - The five functions that organize a cybersecurity program have been to identify, protect, detect, respond, and recover. They recently added the govern function. [06:38] - The govern function is about defining your business objective and then putting protections in place that makes sense for those objectives. [09:01] - The identify function is focused on knowing what we have. [09:40] - Protect includes everything from identity management, authentication, training, data security, and platform security. [10:12] - Detect is looking at what's happening around us. It's continuous monitoring and knowing what happens if something goes wrong. [11:00] - Respond is knowing what the plan is when something does happen. [12:01] - Recover is about getting back to normal after something happens. [16:22] - Data centers want to make sure that they have redundant power supplies. [17:33] - We discuss some of the things that people might forget when identifying cybersecurity assets. Data and people need to be thought about as well as systems and hardware. [21:00] - We need to write things down and understand what systems and data connections we have. [23:10] - We talk about the importance of being aware of the physical space and who is actually supposed to be there. [24:46] - Data is one of the assets that often gets overlooked for protection. There are many new requirements that require data to be protected. [27:54] - Monitoring to understand what traffic you should expect and what is and isn't normal activity is also important. [31:10] - Transparency and communication are paramount for creating trust. [33:51] - Sometimes recovery doesn't mean 100%. Get up and running and prioritize the systems that matter most. [36:56] - With governance, you really want to look at what you're trying to do with the business and then translate cybersecurity to fit that objective. [37:27] - Have guidance documentation in place and have oversight. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/34588675
info_outline
Identity Crimes (Theft, Compromise & Misuse) with Mona Terry
01/08/2025
Identity Crimes (Theft, Compromise & Misuse) with Mona Terry
When you search for customer service numbers online, you might come across a scammer’s number instead. It’s important to be cautious when sharing personal information, and to verify identities before responding to requests for sensitive data. Today’s guest is Mona Terry. As Chief Victims Officer at Identity Theft Resource Center, she navigates the complexities of identity protection and identity crime recovery and management of multi-million dollar federal grants. She analyzes victim experiences to create ITRC’s Identity Report and to provide information about new and ongoing trends in identity crimes. Show Notes: [0:55] - Mona describes her role as Chief Victims Officer at Identity Theft Resource Center and how she found herself in this job. [3:18] - Identity crimes include theft, compromise, and misuse. What’s the difference? [4:26] - The number one recorded compromise is through scams, where people give their information to someone else. [5:30] - It is also becoming more common for someone to search for a customer service number and come across a scammer’s number instead. [7:01] - Some of the strategies in detecting fake websites are not helpful any longer with scammers using AI tools to make things look more legitimate. [10:10] - Misuse is when someone else takes over your account and is making charges or establishing new accounts in your name. [11:41] - Account takeovers don't only include credit cards. Social media account takeovers can be just as dangerous and more common. [13:28] - Identity theft is what it sounds like—stealing information with the intent to misuse it. [15:24] - If you suspect something is compromised, Mona recommends freezing your credit account. [16:45] - Freezing your account and checking credit reports is easier than it used to be. [19:32] - Mona describes how the Identity Theft Resource Center walks victims through the steps in resolving problems. [21:23] - Some situations are harder to resolve than others. [23:51] - Team members at Identity Theft Resource Center are not therapists, but they are trauma informed and listen to victims as they are guided through a process. [26:27] - When working with the Identity Theft Resource Center, clients get a recovery plan. [29:08] - If victims have tried something or don’t feel comfortable with something, ITRC can step in and help. [31:50] - Don’t be afraid to check for problems. Sometimes problems don’t show themselves immediately. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/34108611
info_outline
Why Resolutions Fail with Dr. Leslie Becker-Phelps
01/01/2025
Why Resolutions Fail with Dr. Leslie Becker-Phelps
We often put off changes and schedule them to start on January 1st. Many of these idealistic resolutions fail shortly after beginning, so it is important to be thoughtful when planning so that you can set yourself up for success. Today’s guest is Dr. Leslie Becker-Phelps. Leslie is a noted psychologist who authored a number of books, including Insecure in Love, The Insecure in Love Workbook, and Bouncing Back from Rejection. She writes the Authentically You Blog and the Psychology Today Making Change Blog. Additionally, she is a national speaker and hosts a YouTube channel. Show Notes: [1:00] - Leslie describes what she does in her career as a psychologist and author. [2:32] - Throughout her work, Leslie continued to go back to the question, “What makes it so hard for some people to change?” [5:47] - There’s nothing wrong with New Year's Resolutions. But waiting to start making a change till a specific day is not effective. [7:02] - You can feel good about yourself and recognize that change is good to move towards. [8:23] - When people are insecurely attached, they have a negative sense of self. What is driving them forward is negativity. [9:58] - It takes a lot of work to be able to be compassionate with yourself. [11:49] - Leslie discusses some small changes she made for herself that allowed her to be consistent. [15:04] - Leslie explains the Michelangelo Effect. [17:47] - Relationships you are in have an impact on your self-esteem. [19:02] - Just because it feels true, doesn’t mean it is true. [20:17] - Adding in the word “yet” gives us an idea of a future that will be different. [21:24] - Setbacks will happen, but they are not failures. [24:18] - You have to be persistent in making changes you want to make. [26:47] - If you can’t seem to make a change, you have to get into the micro parts of yourself and find out why. [28:32] - Leslie suggests making different levels of goals. [30:15] - Prepare yourself for good days and bad days. How can you support yourself on a down day? [33:10] - When you are having really good days, you can clearly remember the days you struggle. Write a letter to your future self on a down day. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/34108396
info_outline
Erasing Your Digital Footprint with Jeff Jockisch
12/18/2024
Erasing Your Digital Footprint with Jeff Jockisch
Data is continuously being collected and this information can lead to misleading conclusions about an individual. Without proper context, behavior can be misinterpreted. This underscores the need for data privacy laws and stronger protections against data brokers. Today’s guest is Jeff Jockisch. Jeff is a passionate data privacy researcher dedicated to exploring the evolution of technology, our search behaviors, trust dynamics, and safeguarding of our information. As Managing Partner at ObscureIQ, he specializes in advanced data removal and privacy risk mitigation for enterprises and government organizations. Show Notes: [0:58] - Jeff describes his career and what he does in the field at ObscureIQ. [3:35] - Instead of taking his career into the compliance field, he took his expertise to the intersection of data privacy and data science. [4:40] - Jeff explains what a data broker does and breaks down a recent data breach. [5:40] - The legal definition of what a data broker is is very narrow. [6:42] - The data that is collected by data brokers can literally be anything, like health care data, drivers licenses, and viewing habits online. [7:32] - One of the worst types of data that is collected is cell phone location data. [8:46] - Data tells a story, but pieces might be missing. Data can paint an inaccurate picture of someone. [10:18] - Data can be interpreted in different ways. [12:41] - Your digital footprint can be deleted. But in addition to deleting it, your behavior needs to change. [13:50] - Apps track data automatically for ads. [16:31] - All of these companies are collecting our data, but they’re not securing it. [19:42] - What can someone do with collected data? The possibilities are endless. [21:38] - Data that is collected can also show other people who are connected to you. [23:10] - Some things can be deleted, including public records. [25:09] - The problem is that the data brokers are massively powerful. [27:15] - Check out the links below for resources that Jeff recommends on the steps to take in order to delete the data you are leaking. [29:57] - Jeff shares an experience of almost being a victim of a scam. [33:10] - Scammers sound totally reasonable in the moment, even when we reflect and feel stupid for making a decision. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33995112
info_outline
Executive Recruiter Scams with John Sidoti
12/11/2024
Executive Recruiter Scams with John Sidoti
When a recruiter contacts you, it’s essential to do your homework, verify their sources, and trust your instincts. If something seems too good to be true, it probably is. While it can be frustrating to be this skeptical, being cautious can protect you and your finances. Today’s guest is John Sidoti. John is the Senior Director of Information Technology at Social Current. He has over 30 years of experience as an IT generalist with wide and varied experience across all aspects of the IT spectrum. Show Notes: [0:50] - John shares his background and discusses his extensive and varied career in IT. [3:32] - Even as a director, John keeps hands-on projects going to keep working in the field. [4:45] - John describes an experience of himself falling victim to a scam on LinkedIn. [7:56] - At some point in the process, John realized that something seemed off. [9:40] - After speaking with this scam company, he continued to receive copied and pasted messages from other “recruiters”. [12:21] - Although the copy and website look and sound very legitimate, there are some things we can look for that raise red flags. [14:13] - Many scammers create fake profiles that look very professional and well done. But take the extra step and research the company and individual. [15:57] - In the grand scheme of things, the people who have been victimized by these types of scams are vulnerable and desperate for employment. [18:22] - Anyone can purchase a domain name and pull together a website using a free or cheap template that all look very legitimate. [20:05] - Once you know the markers, you can see them coming. [21:07] - Look at the domain names and how long they have been registered. [22:30] - Don’t assume it is just an email world. If a company does not have a legitimate phone number, it is a red flag. [24:02] - Another red flag is when a recruiter has been working with just one single company in their career. [26:45] - Recruiters should not be asking for personal information. The company will do that, not a recruiter. [29:43] - It’s okay to be a little cynical about this in order to protect yourself. [31:34] - There are other places that need to be looked at closer as well, specifically Facebook Marketplace. [34:16] - When you look closely at sponsored posts that seem too good to be true, you’ll notice that they are all from bots. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33929232
info_outline
Human Hacking with Peter Warmka
12/04/2024
Human Hacking with Peter Warmka
Today’s threat actors and social engineers leverage social media to observe individuals’ patterns and habits. They encounter you at a coffee shop or another familiar spot. They begin to establish trust, which makes you more susceptible to their tactics. Today’s guest is Peter Warmka. Peter is a retired CIA officer with over two decades of breaching the security of organizations overseas in pursuit of intelligence. He is the founder of The Counterintelligence Institute, author of two books, conference speaker, consultant, and educator on the dangers of human hacking. Show Notes: [0:56] - Peter shares his background and what he has done in his interesting career. [3:27] - The Counterintelligence Institute helps organizations and individuals understand what types of information threat actors are trying to steal. [6:08] - Peter discusses the surprise his friends and family experienced when learning he had been working for the CIA. [9:13] - There are some skills that Peter had to learn when going into this career, but other skills came more naturally. [11:15] - Trust is different in various societies, and Americans are particularly vulnerable. [13:31] - Peter explains how he developed trust with others. [16:00] - There are ways to leverage trust in this type of work. [19:32] - Peter discusses international breaches and the types of intelligence breaches from other governments. [23:11] - The internet has made information so readily available to everyone, including information you may not want them to have. [25:19] - There are different types of information found on the different kinds of social media platforms that all come together to paint a whole picture. [28:09] - Human hacking, or social engineering, can be accomplished through five different communication channels. [31:21] - Peter describes a very powerful and common in-person scenario. [35:53] - We have to get away from the silo-approach, thinking that breaches are only coming from the IT network. [37:24] - Peter wrote a book in the early days of Covid-19 for organizations. He then wrote a book geared more towards individuals. [39:41] - Privacy and security settings are great, but platforms can still be hacked. [41:56] - It shouldn’t be “trust, then verify.” It needs to be “verify, then trust.” [44:27] - AI tools have made things even more complicated for victims and easy for threat actors. [46:37] - LinkedIn specifically is overwhelmed with fake accounts. [48:50] - Workplace education on this topic is backwards in organizations since they are seen as compliance training. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33467367
info_outline
Digital Deception: What Lies Ahead with Perry Carpenter
11/27/2024
Digital Deception: What Lies Ahead with Perry Carpenter
Creating habits of healthy skepticism when receiving texts or emails can prevent you from clicking on phishing links. Everybody is vulnerable online, especially when distracted or in a hurry. But cultivating critical thinking and self-awareness can enhance protection against manipulation. Today’s guest is Perry Carpenter. Perry is an award-winning author, podcaster, and speaker with over two decades in cybersecurity, focusing on how cyber criminals exploit human behavior. As the Chief Human Risk Management Strategist at KnowBe4, Perry helps build robust, human-centric defenses against social engineering-based threats. His latest book , tackles AI’s role in deception. Show Notes: [1:02] - Perry shares his background and what his career has entailed. [4:01] - Regardless of how much people say, spend, or do on security-related issues, the people side of things is hard to control. [5:25] - Perry has always been interested in deception and misdirection. [6:59] - Even as a security professional, Perry has experienced enough distraction to click a phishing email. [9:43] - It is easier to be distracted and not follow usual healthy security habits than being on a computer. [12:24] - We fall into habits easily, especially when the behavior is simple and easy. [16:00] - Technology based deception is more available to anybody than in any other time in history. [18:10] - Security professionals and often pushed in the roles of giving advice. [19:40] - Reflection questions like “Why is this in front of me?” might prevent someone from falling victim to a scam. [26:58] - Everybody is vulnerable. Even though cybersecurity professionals know more on the topic than some others, it is still possible for them as well. [30:40] - Pig butchering and crypto scammers sometimes actually do send money back as a tactic to earn trust and increase hope. [34:42] - We have to have a healthy skepticism of the information environment that we live in. [36:39] - There are very few situations in life where you won’t benefit from slowing down and thinking things through. [38:41] - Perry suggests a family activity that will help boost understanding of pressure tactics. [40:17] - The narratives or tells that work for someone might raise a red flag to others. [43:25] - As a society, we’ve gotten to a point where we don’t like to introspect. [45:59] - Perry discusses the content of his most recent book and how it is information without the “easy way out”. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources: by Perry Carpenter
/episode/index/show/easyprey/id/33409182
info_outline
Rethinking Online Anonymity with Lance Cottrell
11/20/2024
Rethinking Online Anonymity with Lance Cottrell
In a world of cybersecurity and online privacy, anonymity seems to be the key. VPNs are often promoted as the cure-all to our internet needs. Let’s talk about some of those misconceptions. Today’s guest is Lance Cottrell. Lance founded Anonymizer in 1995 and is an internationally recognized expert in cryptography, online privacy, and internet security. He is the principal author on multiple internet privacy and security technology patents. Lance stayed on as Chief Scientist as Anonymizer was acquired by Intrepid, and now advises start-ups through his platform. Show Notes: [1:09] - Lance shares his background and how he spent the start of his career and into founding Anonymizer. [3:03] - To continue destigmatizing being a victim of a scam, Lance shares his own experience as a victim himself. [5:38] - In-person scammers are very believable. They learn through building a relationship the things that you want. [9:47] - There are two reasons why people commit treason - revenge and justice. [10:42] - Prior to founding Anonymizer, Lance had fantastic access to the internet in the early 90s and became involved in the open-source community. [13:58] - Lance describes how Anonymizer did business-wise and where it capped. [17:40] - There are different types of customers for Anonymizer, general consumers as well as government entities. [20:30] - There were certainly times where someone would come to Anonymizer and they had done something that was really pretty dire. [23:28] - Anonymizer was able to develop some new technologies that Lance describes. [25:35] - If you need to trust someone, research who that someone is and understand if you can. [27:11] - The biggest mistake is thinking your IP address is the important thing. [29:19] - Actually achieving anonymity or pseudonymity and maintaining overtime is incredibly challenging. [31:09] - Human behavior tends to give away anonymity. [33:47] - People don’t think anywhere near enough on the threat model. [34:58] - When are VPNs actually beneficial? [37:32] - Be very specific about what you want to protect. [40:05] - Obsession and trying to run your life around trying to be anonymous is not helpful. [41:41] - Lance discusses some of the interesting aspects of the psychology of criminals. [43:10] - Lance shares some parting advice and the basic things to do to stay protected. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33358852
info_outline
AI: Double-Edged Sword for Cybersecurity with Vincent LaRocca
11/13/2024
AI: Double-Edged Sword for Cybersecurity with Vincent LaRocca
Cybersecurity is more crucial than ever. It’s essential that we proactively safeguard our data and recognize that no one is immune to attacks. We are all vulnerable. As malicious actors continually enhance their tactics, we must stay one step ahead by consistently improving our defenses. Today’s guest is Vincent LaRocca. Vincent is the CEO of CyberSecOp with the commitment to protecting sensitive data and mitigating cyber threats. With over two decades of experience, Vincent has successfully steered CyberSecOp to become one of the world’s fastest growing managed security providers, specializing in cybersecurity assessments, breach management, and risk management consulting. Show Notes: [1:15] - Vincent shares his background and how he found himself working in cybersecurity. [2:40] - Even the experts are vulnerable. Vincent shares an experience he had with fraud at his bank. [4:16] - Cyber threat trends are moving to AI. [6:19] - As consumers, we need to be aware of how AI is using our data and what we give it permission to have access to. [8:19] - AI isn’t going anywhere. It will continue to grow and develop. [9:16] - Threat actors are unfortunately usually one step ahead of defenses. They are using AI to exploit vulnerabilities. [11:54] - AI gives threat actors even more reach. The number of incidents and scams are extremely high and will multiply. [13:59] - Small organizations and business owners are hit pretty hard by breaches since they often do not have a cybersecurity team. [16:09] - Vincent shares some of the traits and qualifications that are good to look for in cybersecurity professionals for small businesses. [19:07] - Defenses are built against things that we know about, not things we don’t know about. [21:27] - There are things that can be done that are free or more cost-effective. [23:40] - There’s no point in putting a fancy lock on the front door if there’s nothing protecting the back door. [27:06] - Even if an organization has invested in cybersecurity and knows how to keep data safe, if their partners or vendors do not, it means very little. [28:31] - There are so many breaches that have happened that we don’t even know about and our data is out there mixed in with so much more. [30:31] - We are a part of an AI revolution currently and the landscape of AI will be completely different in just a few years. [33:58] - The tools for cybersecurity, including machine learning, are improving every day as well. [37:09] - Don’t turn a blind eye and assume you can’t afford protection. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33315662
info_outline
Understanding and Avoiding Triangulation Fraud with Soups Ranjan
11/06/2024
Understanding and Avoiding Triangulation Fraud with Soups Ranjan
As consumers, we may realize the need to be vigilant by using two-factor authentication and password managers, but there are so many scams out there that can impersonate legitimate organizations, websites, and people. We really can’t let our guard down. Today’s guest is Soups Ranjan. Soups has over 18 years of experience in software engineering, data science, and risk management. He is the co-founder and CEO of Sardine. This behavior-infused platform offers fraud prevention, compliance, and payment solutions for various industries including banking, online marketplaces, FinTech, crypto, online gaming, and gift card exchanges. Previously, Soups led the Risk and Data Science teams at CoinBase, where he scaled the platform and enabled millions of users to buy, sell, and store cryptocurrency securely and efficiently. Show Notes: [1:15] - Soups shares his background and information about his company, Sardine. [4:30] - He has not been a victim of a scam online but did experience an in-person scam. [6:57] - Sardine works with a diverse set of clients. Trends differ based on the industry. One major trend is an increase in triangulation fraud. [9:07] - Once they have card details, they can pretty much do whatever they want with it. [11:40] - Even on a contactless card, using tap-to-pay, be careful. Don’t hand over your device. [12:43] - It is becoming increasingly difficult to verify the identities of merchants. [15:21] - There is a big rise in scams as a result of the demand for real-time money transfers and exchanges. [17:45] - Some scammers are instructing victims to install screen viewers and recording tools. [19:50] - Machine learning is used to help protect clients. [21:41] - There are intrinsic behaviors that Sardine monitors to watch for unusual activity. [24:41] - Soups describes some of the other types of data that is observed in addition to behavior. [27:08] - Soups explains 3D Secure and what the benefits of this system are. [30:41] - Dollars lost to scams have far surpassed the dollars lost to fraud. [33:37] - The United States is behind in regulatory measures. [35:59] - It is best to work with banks that take fraud and scams very seriously. [37:15] - Soups lists some of the red flags and be on the lookout for. [39:44] - It is extremely important to protect your email address in the same way you protect your bank account. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33280277
info_outline
Finding Small Business Fraud with James Ratley
10/30/2024
Finding Small Business Fraud with James Ratley
There are a shocking amount of businesses that ultimately fail because of fraud. Many managers and business owners are unaware of their losses because they do not have the systems in place to look for fraud and it may not be their primary concern. Today’s guest is James Ratley. Jim graduated from the University of Texas at Dallas with a bachelor’s degree in Business Administration. In 1971, he joined the Dallas Police Department as a police officer. He was on numerous task forces with a concentration on major fraud cases. He joined a major forensic accounting practice and was in charge of fraud investigations. In 1988, he was named the Program Director of The Association of Certified Fraud Examiners and in 2006, became the President. In 2011, he became the CEO and he retired in 2018 after 30 years there. James has been an adjunct professor, published author, and named by Accounting Today as one of the top influencers multiple times. Show Notes: [1:14] - James shares his background and the way his career panned out over 30 years. [3:35] - When the ACFE was established, there was no information or education around it at all. [5:09] - The average organization loses 5% of their revenue to fraud. Out of every ten people hired, statistically, six of them will steal from you. [6:46] - Fraud can be prevented and strategies to reduce fraud are typically inexpensive. [8:40] - It’s important for business owners not to be afraid to call it fraud. [10:25] - Fraud perpetrators believe they deserve what they’ve taken. [13:26] - It’s important for businesses to have strong management and leadership. Training is crucial. [14:18] - James discusses the most common types of fraud and how even the seemingly minor things could be detrimental. [18:24] - Fraud perpetrators are really good at hiding what they are doing and making the business owners believe it could never be them. [20:15] - Another strategy is to separate tasks out and be strict about them. [21:37] - Surprise cash counts is another good strategy. [23:13] - There are no small frauds, only frauds that have not had time to reach maturity. [25:44] - You impact rationalization through education. [29:16] - James lists some of the red flags that could indicate something more going on. [31:31] - There should be policies and regulations that purchasing officers are held to. [36:30] - Auditors must be completely independent. [40:10] - Some business owners will deny the problem is happening because it is hard to deal with and accept that someone they trust could be stealing. [44:35] - Many small organizations go out of business due to operating at a loss. Most of the time this is because of fraud. [47:25] - Never judge someone by the standards you have for yourself. [51:12] - Something to remember is that most fraudsters will steal in even numbers. [53:11] - In most cases that James has worked, the manager had seen all the signs, but never thought anything about it. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33142307
info_outline
Truth and Lies with Mark Bowden
10/23/2024
Truth and Lies with Mark Bowden
Now that so much of our communications are digital, such as texts, emails, and chats, we miss out on the tone and facial expressions to help us understand the intent and content in communication. It’s important to know ourselves well enough to know what areas we’ll be more easily influenced and are susceptible to being deceived. The greater our desire for something to be true, the easier it is for us to be scammed. Today’s guest is Mark Bowden. Mark is a world-renowned body language expert, keynote speaker, and best-selling author. He is the founder of the communication training company, TruthPlane. Mark is also a member of The Behavior Panel on YouTube. Show Notes: [1:08] - Mark shares his background and what motivated him to specialize in human behavior. [2:34] - There are parts of the brain that are activated when we first meet someone new. [3:56] - Think about how many people you see on a regular day. Some you will notice and some you will not. [7:03] - There are certain parts of the brain that can overwrite natural instinct. [10:02] - Mark demonstrates how body language changes when there is perceived risk. [14:50] - Body language signals can be perceived inaccurately. People can also change their body language to send different signals. [17:15] - So many signals that our brains rely on in communication disappear when we cannot see the person we’re talking to. [19:16] - Mark gives an example of how the human brain perceives the bait of a scam. [22:48] - The first step in critical thinking is to suspend judgment. [25:58] - “You can only con a greedy man.” Think about what you want so much that if it were offered, you lose your sense of judgment. [28:33] - If anyone ever tells you that something seems like it isn’t true, suspend judgment and look into it. [30:32] - It’s a risky world. There are people who have dedicated their lives to deceiving others. [35:13] - Part of critical thinking is asking other people whom you trust about what they think. [39:56] - Sometimes we will set people up to see how they will respond. [43:11] - It is best to have an open mind and be willing to see things for what they are over what you want them to be. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33129497
info_outline
The Update That Broke America with Gabe Dimeglio
10/16/2024
The Update That Broke America with Gabe Dimeglio
Many industries are reliant on software and if the software becomes corrupt or an update fails, it may require hands-on support. Do you have your infrastructure set for repair and recovery? Today’s guest is Gabe Dimeglio. Gabe is a 20-year veteran of information technology and security for private and public sector organizations. He is a results-driven leader, specializing in security services and solutions for mission-critical, complex enterprise platforms. His expertise includes strategic consulting services, risk analysis/risk mitigation, and compliance. Mr. Dimeglio serves as Vice President & Executive Advisor, Security, Office of the CTO at Rimini Street. He is responsible for oversight of the GSS organization that provides tailored consulting and advisory security services to prospects and clients, in collaboration with Rimini Street sales, client engagement, and retention functions. Show Notes: [1:18] - Gabe shares his background and what he does in his roles at Rimini Street. [2:38] - Anyone can be a victim of a scam. That includes Gabe. [4:03] - Scams are very sophisticated and techniques have come a long way in the last decade. [5:23] - Gabe describes what happened with the update that shut down much of the United States’ systems and infrastructure. [8:30] - To complicate things, the platform could not be restarted with this update in effect. [10:42] - Updates are sideloaded continuously and are processed by this kernel driver. The thought process is interesting because it has happened before. [12:37] - This was the biggest problem caused by Crowdstrike. [14:47] - One mistake out of 10,000 updates is a low error rate, but there is a lot of reputation damage done in this event. [16:50] - In the case of Crowdstrike, turning off auto-update was not an option. [18:43] - Any time software, programs, or data are introduced, you’re also introducing risk. [21:04] - Part of the solution to fixing this massive problem was hands-on support on every box. [26:13] - One problem is that there are some industries where technology is very outdated. [27:23] - People are selling their solutions and the solutions are cloud-managed. This is scary due to frequent cloud breaches. [31:10] - There are still businesses that have no security professionals or teams managing client data and safety. [32:53] - The skills gap is crushing most businesses. [35:03] - Security has come a long way, even if there are still areas of lack. [37:01] - For the last couple of years, security has been something that there is a budget for in most businesses. [40:49] - Don’t ever let anyone convince you to shortcut anything. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33040887
info_outline
A Lesson in Crisis Management with Jeremiah Grossman
10/09/2024
A Lesson in Crisis Management with Jeremiah Grossman
It’s not always easy to determine the value of digital assets. The potential of overestimating or undervaluing your data can make it difficult to establish how much protection you need for a cyber intrusion. Today’s guest is Jeremiah Grossman. Jeremiah has spent over 25 years as an InfoSec professional and hacker. He is the Managing Director of Grossman Ventures. He is an industry creator and founder of White Hat Security and Bit Discovery. He has his black belt in Brazilian Jiu-Jitsu and is an avid car collector. Show Notes: [0:53] - Jeremiah shares his background and what he does as the managing director of new venture capital, Grossman Venture. [1:55] - When he was 24, Jeremiah’s business was victimized by a data breach. [5:30] - This experience taught him that if you treat your customers with integrity and have their best interests in mind, they will keep doing business with you. [7:43] - These things happen to countless businesses. It is important to keep customers and clients informed. [10:27] - Cybercrime is one of the only crimes where the victim doesn’t always know they’re a victim. [13:30] - When it comes to solving these problems, we have to narrow in on the problems that are worth solving and then work for a solution. [14:53] - Doing an asset evaluation is a good starting point. There is no algorithm to determine the value of digital assets. [19:18] - What role does AI play in this and what should people be wary of? [20:31] - How do we raise the cost on the adversary? [23:12] - There are ways to bait adversaries as well which is an inexpensive solution. [25:17] - These days, adversaries are nowhere physically near the data. They access it all through digital means. [27:28] - Jeremiah is optimistic about AI and in his perspective, AI is a tool that will help us determine solutions. [28:07] - Currently, cyber insurance has become compulsory. [30:48] - Jeremiah explains how things work in venture capital and the problems that are common. [34:11] - There are many things that we can do better in this space. [35:46] - Jeremiah shares advice for small and medium-sized businesses. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/33040582
info_outline
Pig Butchering Is Getting Worse with Erin West
10/02/2024
Pig Butchering Is Getting Worse with Erin West
Pig butchering is worse than just manipulating someone and taking their money. It leaves them with emotional anguish. Once their finances have been drained, they lose their financial security and they no longer trust people. Today’s guest is Erin West. Erin has been with the County of Santa Clara for 26 years and is a Deputy District Attorney. She specializes in cryptocurrency investigations and prosecutions. Show Notes: [0:46] - Erin shares her background and what her role is as a Deputy District Attorney in Santa Clara County. [3:20] - Five years ago, Erin found herself working on prosecutions regarding SIM swapping and cryptocurrency hacks. [4:35] - The emotional impact of “just a financial crime,” is staggering. [7:38] - You never know who around you is a victim of some of these crimes. [8:18] - Erin describes the experience of being convinced to click a link herself. [10:32] - Scammers will think about different things that would trigger someone into clicking a link. [13:40] - Pig butchering involves building trust with a victim and showing them a false plush lifestyle. [16:08] - A red flag is a text or social media message you may receive that seems misdirected or to a wrong number. [19:21] - It feels like the right thing to do when we feel the need to respond to the scammer with a “you’ve got the wrong number,” but that’s how they start a conversation. [22:29] - In many cases, scammers bulk text a massive amount of phone numbers. But some people are specifically targeted on social media. [24:23] - Covid really accelerated this type of scam due to loneliness. [25:40] - A misconception is that these scams target the elderly. But it is not based on age at all. [27:03] - Unfortunately, law enforcement is not set up to be able to handle this type of crime. [28:18] - Erin explains that law enforcement doesn’t tend to always lead with empathy when this type of crime is reported. [30:12] - It is important to report the crime to local law enforcement, but there are other places that the crime can be reported to in addition. [32:50] - Victims should be able to speak to a detective. [34:33] - Victims should be very wary of third party recovery programs. [37:26] - On the other side of things, a scammer could also be a victim of human trafficking and being forced to scam others. [39:40] - Scams are being operated on a massive scale and have a front of a corporate business. [41:14] - Initially, most of the cases seemed to have money moved out of the country. However, recently scammers have been found to be operating in the US. [44:04] - There is some hope and opportunities in recent months where money laundering has been intercepted. [46:41] - Progress in education and advocating for less victim shaming is moving in the right direction. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32863137
info_outline
Protecting Parents with Terri Proctor
09/25/2024
Protecting Parents with Terri Proctor
Sometimes people only share their stories after they’ve gone through a challenging time. But it’s also important to learn from those in the middle of a scam to learn how people are manipulated and how vulnerable our loved ones can really be. Today’s guest is Terri Proctor. Terri’s elderly mother has been scammed by romance scammers over the last three years. In trying to get help from different recommended services, she realized that no one was really interested in helping. She started the non-profit Stop Elderly Scams to educate and bring awareness to the community. Show Notes: [0:53] - Terri shares her background and how she was thrown into her situation. Her experience led her to founding a non-profit. [2:28] - Over the course of a year, Terri’s mother lost about $100,000 to a romance scammer. [3:30] - Terri’s mother was not treated like a victim. She was treated as a willing participant. [6:01] - There were many reasons why Terri’s mother was vulnerable to manipulation, including loneliness. [8:23] - It is sad to see the comments online about victims of scams. [10:23] - The shame and embarrassment a lot of victims feel causes them to not talk about the problem or seek help. [11:57] - In the beginning, Terri admits that she had a lot of anger and frustration that was also focused on her mother. It is better to listen and try to reason. [14:54] - Terri’s mother was stopped by a store manager from buying more gift cards. The manager has expressed concern that she is not the only one. [16:51] - Part of the vulnerability of Terri’s mother is loneliness. [18:47] - Other types of scams tend to target the elderly. It is hard to keep up. [24:08] - How can we help our loved ones without taking away their independence? [26:21] - People should feel free to talk about these issues. Terri shares how her non-profit is helping educate and make a difference. [28:46] - It is challenging to find the balance in helping loved ones and making sure they have their autonomy. [29:59] - When you think you’ve learned about one thing or one scam, another problem pops up. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32776912
info_outline
Technology Regulation is Outdated with Bruce Schneier
09/18/2024
Technology Regulation is Outdated with Bruce Schneier
Regulators have to invest a considerable amount of time in keeping legislation and policy up to date regarding technology and AI, but it’s not easy. We need floor debates, not for sound bytes or for political gain, but to move policy forward. Today’s guest is Bruce Schneier. Bruce is an internationally renowned security technologist called The Security Guru by The Economist. He is the author of over a dozen books including his latest, A Hacker’s Mind. He has testified before Congress, is a frequent guest on television and radio, has served on several government committees, and is regularly quoted in the press. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a lecturer in Public Policy at Harvard Kennedy School, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. Show Notes: [1:40] - Bruce shares what he teaches at Harvard and the current interest in policy. [4:27] - The notion that tech can’t be regulated has been very harmful. [6:00] - Typically, the United States doesn’t regulate much in tech. Most regulation has come from Europe. [7:52] - AI is a power magnification tool. Will the uses empower the already powerful or democratize power? [9:16] - Bruce describes loopholes and how AI as a power magnification tool can mean something different in different situations. [12:06] - It will be interesting to watch AI begin to do human cognitive tasks because they will do them differently. [13:58] - Bruce explains how AI collaboration can be a real benefit. [16:17] - Like every text writer, AI is going to become a collaborative tool. What does this mean for writing legislation? [17:18] - AI can write more complex and detailed laws than humans can. [21:27] - AI regulation will be skewed towards corporations. Bruce explains how public AI could work. [23:46] - Will AI help the defender or the attacker more? [26:19] - AI can be good against legacy, but we need some sort of infrastructure. [29:27] - There’s going to be a need for proof of humanity. [32:29] - It is hard to know what people can do to help move regulation along. Ultimately, it is a political issue. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32542632
info_outline
Threat Emulation with Andrew Costis
09/11/2024
Threat Emulation with Andrew Costis
Security risks are dynamic. Projects, employees, change, tools, and configurations are modified. Many companies utilize PEN testers on an annual basis, but as quickly as systems are revised, you may need to implement threat emulation for regular monitoring. Today’s guest is Andrew Costis. Andrew is the Chapter Lead of the Adversary Research Team at Attack IQ. He has over 22 years of professional industry experience and previously worked in the Threat Analysis Unit Team at Firmware, Carbon Black, and Logrhythm Labs, performing security research, reverse engineering malware, and tracking and discovering new campaigns and threats. Andrew has delivered various talks at DefCon, Adversary Village, Black Hat, B Side, Cyber Risk Alliance, Security Weekly, IT Pro, Bright Talk, SE Magazine, and others. Show Notes: [1:14] - Andrew shares his background and what he currently does in his career at Attack IQ. [3:49] - At the time of this recording, there has been a major global security panic. [6:06] - There are many programs that we use on a regular basis that we don’t always consider the security of. [8:09] - Historically, companies would pay for an external pen test. Andrew describes the purpose of this and how they usually went. [9:33] - Pen tests and threat emulation do not need to be limited to just once a year. [10:45] - Andrew’s team is in the business of testing post-breached systems. But they preach prevention. [11:55] - Attackers are lazy in the sense that they will reuse the same strategies over and over again. [14:13] - Many programs we use may be caught in the crosshairs of attacks and vulnerabilities in other companies. [16:41] - Andrew discusses the frequency of really critical CVEs. [19:01] - What do attackers go after when they’ve breached a system? [21:04] - The priority for attackers is to get in quickly and make the victim’s data unavailable. [22:24] - A lot of people are under the impression of vulnerability testers. “Fire and forget it” is not a beneficial mindset. [24:56] - If we run every test, the amount of data will be overwhelming. [27:03] - In his experience, there has been client testing that has been overwhelmingly easy to breach. [29:07] - There are also organizations that have done a fantastic job. However, vulnerabilities will still be found. [30:18] - The red team is not going to be able to cover your entire organization. [32:15] - Threat emulation and pen testing are technically the same thing. Andrew explains how she sees the difference. [33:50] - How are vulnerabilities and tests prioritized? [36:19] - Andrew describes the things his team works on and their objectives for customers and clients. [38:34] - The outage at the time of this recording had a big impact. It gave a really good idea of what could happen if it were a real security breach. [41:37] - There are a ton of free resources out there. The primary resource at Attack IQ is the free Attack IQ Academy. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32542482
info_outline
Ransomware: To Pay or Not To Pay? with Amitabh Sinha
09/04/2024
Ransomware: To Pay or Not To Pay? with Amitabh Sinha
Ransomware may not be on your machines due to your negligence or mistakes. It could be there because of third-party software you are utilizing. Do you know what to do if this happens to you? Today’s guest is Amitabh Sinha. Amitabh has a PhD in Computer Science and more than 20 years of experience in enterprise software, end-user computing, mobile, and database software. He co-founded Workspot in 2012. He was the General Manager of Enterprise Desktop and Applications at Citrix Systems. In his five years at Citrix, he was the VP of Product Management for XenDesktop and VP of Engineering for the Advanced Solutions Group. Show Notes: [1:03] - Amitabh shares his background and current role and contributions at Workspot. [4:35] - The first sign of ransomware in an organization is widespread blue screens and Microsoft machines shutting down. [5:40] - How does ransomware find its way to a device? [6:59] - Ransomware in your organization is not necessarily your fault. [10:37] - Amitabh describes how he has helped client organizations back up and running after having been infected with ransomware. [13:11] - Typically, it is not recommended to pay the ransomware, but it may be a viable option for some organizations. [15:59] - Most small companies are not prepared to prevent or handle ransomware. [17:34] - In most large companies, not all PCs are up to date on security patches. [20:41] - Cloud storage is much safer and can be accessed on other physical machines in the event that ransomware shuts down an organization. [24:41] - For those who work from home, sometimes multiple machines makes things even more complicated. [27:35] - What are you willing to pay to not have something happen? That’s how ransomware takes advantage of people. [31:20] - For small companies, there is typically an architectural solution, but that isn’t always viable for large organizations. [33:14] - Consider the critical functions of your organizations and what a plan could be if computers were not accessible. [34:37] - These types of attacks are more and more frequent. [36:44] - Amitabh is confident that AI will make preventing ransomware even more challenging. [40:38] - Most people have accepted that a lot, if not all, their information has already been leaked on the internet. But businesses are particularly vulnerable. [42:30] - A whole organization can be drastically impacted by just one machine being hit by ransomware. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32542257
info_outline
Firewalls Don’t Stop Dragons with Carey Parker
08/28/2024
Firewalls Don’t Stop Dragons with Carey Parker
We all use technology. Things like internet browsers, search engines, instant messaging, and payment apps. But we aren’t always aware of the data being collected. This information can not only impact your privacy, but those around you as well. Today’s guest is Carey Parker. Carey is the author of , a step-by-step guide to computer security and privacy for non-techies. He also hosts a podcast by the same name. He recently retired from a career in software engineering to focus on teaching others how to defend their digital devices and protect their personal data. Show Notes: [0:53] - Carey shares his background and what provoked the motivation for a career shift. [4:07] - If we all did the small things that protect privacy, we would all be stronger. [5:20] - Even if you have already shared a lot of your information online, it is not hopeless and it’s not too late. [6:32] - Your security and privacy overlap with other people’s. [8:35] - We need to be protecting privacy for all of us, not just ourselves as individuals. [10:17] - Carey explains why and how apps and companies collect data. [11:48] - Foreign governments would love to get their hands on the data that is collected by countless companies and apps. [13:53] - Data is valuable to software developers for honest reasons. Collecting data isn’t inherently bad. [17:16] - When determining what connection to use, you are trading off who you trust - your ISP, the public wifi connection, or a VPN. [23:10] - Carey shares some easy things you can change right now to protect your privacy. [25:25] - Companies love to get your email address and your phone number. These become unique identifiers. [27:05] - Search engines collect data as well. This is important to remember. [28:05] - Payment apps are another obvious type of website that collects data. Which ones should you avoid? [30:32] - There is value in social media. Make sure the things you post are not public by default. [32:19] - Metadata and location tools are used on any social media image. [34:37] - Messaging apps collect data and share it. There is a gold standard app though that Carey suggests. [36:31] - Email is trickier because it is open standard. It wasn’t designed with encryption in mind. [38:55] - Carey discusses automated AI systems like Alexa. [41:26] - When using AI tools, assume that the information is collected and could be public. [42:35] - Car privacy is horrible and there is almost nothing you can do about it. [46:18] - It is not true that you need to give up privacy for security. Carey discusses the differences. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32218217
info_outline
Stopping Robocalls with Aaron Foss
08/21/2024
Stopping Robocalls with Aaron Foss
Finding a solution to stop spam calls to you, your family, or your business isn’t easy. We may not win this war, but we don’t want the government making this decision for us. We can make it more manageable in the meantime. Today’s guest is Aaron Foss. After winning the FTC Robocall Challenge in 2013, Aaron started Nomorobo. Since then, Nomorobo has stopped billions and billions of unwanted robocalls and spam texts from reaching our phones, and it was acquired by Applause group in August 2023. Aaron has been featured in The New York Times, Wired, CNN, CNBC, Fox News, and countless other media outlets. He has testified in front of Congress, not once, not twice, but three times. Show Notes: [1:14] - Aaron shares his background as a serial entrepreneur in the intersection of technology and business. [3:57] - At the beginning, Aaron didn’t even know what a robocall was. [6:47] - Robocalls have this negative connotation. They can actually be good. But there are many that are unwanted. [8:13] - There are different types of robocalls and there is a differentiation between spam and scam calls. [10:08] - Aaron explains why spam emails are easier to block than robocalls. [12:20] - There are some robocalls that are necessary and helpful for some people. That is one reason why not all robocalls can be blocked. [13:40] - Not answering the phone is not a plausible solution. [15:50] - Nomorobo is basically a series of bots talking to other bots. [16:50] - Aaron describes caller ID and how spoofing a number is possible. [19:42] - This is such a big problem because the barrier of entry is low. [21:08] - It is amazing that we can call anyone in the world. But that also means that scammers can, too. [22:53] - This is a complicated problem, and the future solution is a combination of government regulation, companies like Nomorobo, and AI. [26:29] - We are never going to win the war, but we can keep it manageable. [29:45] - What is the role of the carriers when it comes to robocalls? [31:47] - Keeping scammers on the phone does not make the problem go away. [33:52] - Some scams are seasonal and some are evergreen, like Medicare calls. [36:26] - Aaron explains the different ways these scams can be done and the range of damage they can do. [39:56] - At best, this is an annoyance. But there are people in our lives that are vulnerable and less protected. [44:42] - Sometimes, Nomorobo users have to turn it off for specific reasons and specific calls they’re waiting for. [47:56] - This problem is an example of “death by a thousand papercuts.” [49:30] - There are some red flags and things you might notice if you answer robocalls that could indicate that they are scams. [50:46] - This seems like an easy problem to solve, but it is far more complicated than most people think. [52:00] - Aaron describes what it was like to testify in front of Congress. [56:43] - Listen and educate yourself. Talk to other people about these things. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32197022
info_outline
Safety Can’t Be an Afterthought with Kris Burkhardt
08/14/2024
Safety Can’t Be an Afterthought with Kris Burkhardt
Most businesses rely on some type of software, either for scheduling, payment, banking, customer lists, or something else. It’s important to know where this information is stored and what would happen if that software was hacked or you weren’t able to access it. Today’s guest is Kris Burkhardt. As Accenture’s Chief Information Security Officer, Kris leads a team of over 800 security experts charged with protecting company client and customer data. Show Notes: [0:49] - Kris describes his role at Accenture and what Accenture is known for in the security industry. [2:26] - Part of their program is sending phishing tests and Kris has failed one before as well. It happens, especially when we are in a rush. [5:39] - We are so highly connected that when something goes down, it impacts us in ways we never considered. [7:10] - Many small businesses rely on software service providers because there is a lot of good about them. But what happens when they go down? [9:56] - Defenders have to get it right all the time. [11:13] - The last ten years have seen an immense amount of growth in how we store data. We have to stay ahead of change when it comes to security. [13:59] - It is hard to understand how much we rely on technology. [17:34] - Kris describes a time when the CEO of Accenture was used in a deep fake and the threat actor was very clever. [21:17] - Kris believes that advances in technology will make it harder to pretend to be someone else. [23:20] - Children are growing up in a technological world and are naturally more skeptical and cautious as a result. [25:49] - Safety has always been an afterthought. [27:15] - Kris shares what he thinks scams and deep fakes will look like in the near future. [30:12] - Pay attention to things that don’t seem consistent. [32:57] - People feel like there is a trade off when it comes to efficiency and security. [39:37] - Having a plan ahead of time is absolutely beneficial in staying ahead of security problems. [44:25] - As deep fakes become more and more of a problem, Kris suggests having code words with family members. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32180522
info_outline
Child Safety Tips with Steve Lazarus
08/07/2024
Child Safety Tips with Steve Lazarus
Is it right for parents to be the ones to have to put limits on their children’s screen time or to monitor the content they consume? Knowing the impact of social media and kids can influence the decisions that are made. Today’s guest is Steve Lazarus. Steve is a retired FBI agent, crime fiction author, and Instagram influencer specializing in personal and child safety topics. Show Notes: [0:42] - Steve shares his background and his career history in the FBI and the military. [4:02] - For a long time, Steve was anti-social media. However, since the publication of his book, he has garnered a significant social media following. [5:50] - He started his Instagram with posts of things that he would never do as a retired FBI agent. [7:08] - Steve describes the post that went super viral on TikTok and Instagram. [9:00] - Parents need to know what their kids are looking at on the internet and control the amount of access they have online. [10:40] - Sextortion is a very real and serious problem, especially for young boys. [12:27] - Always report any case of sextortion or sexual content involving a minor. Law enforcement becomes involved immediately. [14:09] - Steve lists some of the things to look for when children and teens that could be red flags. [16:01] - The internet is on almost every device in your home. A child’s access is not limited to just a computer. [17:59] - Covid did not help the increasing amount of time children spend online. [20:52] - We’re asking kids to have good judgment without teaching them how. [22:13] - The first question that needs to be asked by anyone, but especially a child is, “Do I know this person?” [26:07] - To deal with the digital world now, common sense is crucial and we can’t take everything at face value. [27:56] - A relatively new issue is AI generated images that are very convincing and look so real. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/32180447
info_outline
Fraud: Not Going Away with Steve Lenderman
07/31/2024
Fraud: Not Going Away with Steve Lenderman
Synthetic IDs can be used to open fake accounts, but without a person to file the fraud claim, how should companies deal with this type of deceit? There is no crime where someone doesn’t need to pay for the loss. Either way, the loss is passed on to the consumers in some way or another. Today’s guest is Steve Lenderman. Steve is currently the Head of Fraud Solutions North America at Quantexa and has over 25 years of experience in financial crimes investigation. His previous roles include being the Senior Vice President of Fraud Prevention Investigations at Bank Mobile Technology, the Director of Strategic Fraud Prevention at ADP, and the Fraud Operations Lead for PayPal Business Loans. He is a certified fraud examiner and actively contributes to the anti-fraud community. Show Notes: [1:07] - Steve shares his background and what his current role is at Quantexa. [4:04] - For those who are interested in a career path in cybersecurity or fraud, Steve has some tips. [6:07] - What is synthetic identity? Steve describes what it is and why we should be concerned about them. [8:59] - Although still mostly built around financial data, synthetic IDs have also morphed into other nefarious uses. [10:56] - All fraud in general is underreported, but synthetic IDs are extremely underreported, so data is not accurate, although still very high. [12:37] - Synthetic IDs can be used to open a credit card and then after several purchases, fraudsters leave the card open and unpaid. [14:21] - Some think that synthetic IDs and fake accounts are victimless. [18:59] - To understand how fraud works, Steve had to create synthetic IDs. [22:15] - Over the years, it has gotten even easier to do, which is alarming. [25:13] - Credit repair using a CPN is illegal fraud using synthetic IDs. [26:40] - Synthetics are all built around data and the ease of collecting data in the last few years has increased the ease of creating them. [27:57] - Criminals have learned that they can use synthetic IDs in more ways and in more industries. [31:04] - Small businesses are particularly easy targets for synthetic ID use. [33:16] - It is possible for synthetic IDs to also be used to create a new business. [34:53] - Technology has also made it possible for a deep fake to be created to match a synthetic ID. [36:49] - A lot of synthetic IDs are created with unused credit. Thanks for joining us on Easy Prey. Be sure to and leave a nice review. Links and Resources:
/episode/index/show/easyprey/id/31839962