
Defending against unlimited penalty shots. [Hacking Humans Live!]
Dave Bittner: Hello everyone, and welcome to a very special edition of N2K CyberWire's "Hacking Humans" podcast, where each week we look behind the social engineering scams, phishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. I'm Dave Bittner and joining me is Maria Varmazis. Maria.
Maria Varmazis: Hi Dave, good to see you in person.
Dave Bittner: This week, we are coming to you from Zero Trust World in Orlando, Florida, where we are joining security leaders and practitioners from across the industry. Our coverage here is made possible by our sponsors at ThreatLocker, who've brought the community together to talk all things Zero Trust, Resilience, and the future of cybersecurity. We are grateful to ThreatLocker for helping make it all possible. Joe Carrigan was unable to join us this week here in sunny Florida, but we have a very special guest today, host of the BowTieSecurityGuy After Dark podcast.
Rob Whetstine: Yes, there you go. You got it.
Dave Bittner: [laughs] Rob is one of the featured speakers this week here at Zero Trust World and he's going to be sharing highlights from his presentation on phishing. We've got some good stories to share this week. I tell you what, let's just jump in here. We don't have any follow up this week. So, Rob, welcome. Before we dig into you sharing some of your insights on phishing, can you just tell us a little bit about yourself? What's your story of where you started and what brought you to where you are today?
Rob Whetstine: I started as a poor kid who just pulled computers out of trash and figured out how to work on them and kind of repair them. I was an early hacker, when there weren't any laws, right? And then Mitnick got arrested and I got real scared because I was like, oh, you can do real jail time for this now.
Dave Bittner: Right?
Rob Whetstine: It became much more serious. So from there, I've always been just a lifelong tinkerer, playing and building stuff. I build replica movie props in my free time. I worked for Disney for 20 years. I helped build out a lot of their programs, their social engineering program, as well as their security awareness stuff I worked with. And then a lot of securing the technology, like the MagicBand, I worked with those guys.
Dave Bittner: Oh, wow.
Maria Varmazis: Oh, cool. Oh, yeah.
Rob Whetstine: And we got to do a lot of cool stuff for my time there. And now I'm just a boring executive at a Fortune 500.
Maria Varmazis: Womp womp [laughs].
Dave Bittner: [laughs] Well, it's not that boring. I mean, you would have --
Maria Varmazis: The war stories are amazing, I'm sure.
Rob Whetstine: I've got some of the best stories, yeah, that's for sure [laughs].
Maria Varmazis: I bet [laughs].
Dave Bittner: Well, tell us about the podcast.
Rob Whetstine: Yeah, so I started it specifically just to help new people get into technology and understand what the job is really like. I talked to professionals and just asked them how they got into it, how they started. Marie and I were talking before this. Like, we- it's not the same way. Everybody has a very interesting journey into technology and into cyber. And now there is no real path. So I try to educate what the job's really like, how many hours you're going to be spending, the life sacrifice, as well as the constant learning aspects of it, and then lots of advice for new people in technology. So that's one of the biggest things for me, is just helping as many people as we can and then educating them on what the job is like. And that way they don't go into it blind. You know, it's a rough gig. And I think a lot of people who go into technology think it's going to be this constant entertainment and fun, and it's very monotonous, boring work a lot of times.
Dave Bittner: Way to sell it, Rob [laughs].
Rob Whetstine: Hey, look, I'm just --
Maria Varmazis: [laughs] This is realistic though. You got to deal with the tedium, spotted with, like, some moments of huge excitement.
Rob Whetstine: Oh, that's the biggest- every thing- like, let's say you start in, like, a SOC. When I was first doing SOC work, like, it took me literally eight months until I found my first real threat. Right? And once I found my first real threat, it was like the greatest thing ever.
Maria Varmazis: Yeah, yeah, yeah.
Dave Bittner: So you find yourself a mentor?
Rob Whetstine: I do. I spend a ton of time mentoring. It was -- it's definitely something I fell into. I have AuDHD, so like I get very obsessed with things. I had social anxiety disorder, and I had a really hard time with that for the longest time. I found mentoring to be really helpful for me, because it keeps me engaged and then I learn a lot about people. And I get to hear their stories and understand things more. Like, how did that make you feel? Oh, that makes sense. How can I help? You know? Those things have been really beneficial to me in my career in general.
Maria Varmazis: Yeah.
Dave Bittner: Well, you are presenting here at Zero Trust World this week, and your topic is phishing. And when I was running down the list of presenters this week, I saw your name there, and I said, oh, perfect guest for "Hacking Humans".
Rob Whetstine: [laughs] I love it, yeah.
Dave Bittner: You were gracious enough to join us here today. Give us a preview of what you're going to be presenting.
Rob Whetstine: My biggest thing is, I think a lot of security awareness programs focus on the wrong things, which is they focus on click-through rate of a simulation. And that sounds like the right thing to focus on, but really you're training human behaviors, which is, you know, very apropos for the name of your show. Because you're- I want you to know that your job is to kind of hack your employee and teach them behaviors that you want them to have. When you look at things, you're basically, when you send a simulation out, you're bypassing all your own security. You're giving it the literally best chance for success, and many people who are getting the email would never receive an email from an attacker. Like, so the numbers in themselves are skewed, but a lot of them are built off of things like the Verizon Databreach Report and things of that nature where they go, well, Verizon says it needs to be 1.5% click-through rate to be successful. So when I was working for Disney, I said, well, why- where are you getting this number from? Oh, well, we work with one company and we get their information and they work with several others. And I'm like, okay, well, how difficult is the phish? Are you- if you're an international company, are you phishing in their native language?
Maria Varmazis: Yep, yep, yep.
Rob Whetstine: Like, there's so many variables that don't go into it, and I feel like focusing on that number as opposed to focusing on risky human behavior and training behaviors is much more important. So the majority of the talk is just going to be about bucketing your people into high risk categories, and then specifically focusing on the skills that you want them to learn, and then hitting them where they learn. Right? If you're giving somebody a 40-minute or an hour-long phishing thing, the simulation training, no one's paying attention.
Maria Varmazis: Amen.
Dave Bittner: [laughs] I can vouch for that.
Maria Varmazis: Yeah [laughs], I think all of us know, yeah.
Rob Whetstine: They don't care.
Maria Varmazis: Yeah, yeah.
Dave Bittner: [laughs] Right.
Rob Whetstine: So it's a big focus on micro-learning, because as a society, we've really gone into micro-learning and that's where we absorb the most data.
Maria Varmazis: What do you mean by micro-learning?
Rob Whetstine: Two to five minutes.
Maria Varmazis: Okay, yeah.
Rob Whetstine: If you're giving somebody more information than that, they are not retaining any of it.
Maria Varmazis: Yeah.
Rob Whetstine: Your mind's not designed to.
Maria Varmazis: My mind's certainly not designed to [laughs].
Rob Whetstine: [laughs] No, always- especially- yeah, no. That's very much how it- my mind is like, oh, this isn't useful, we'll just trash that.
Maria Varmazis: [laughs] I'm curious what you think about in terms of training people better behaviors.
Rob Whetstine: Yeah.
Maria Varmazis: I- Sometimes it can be a bit of a blunt instrument in terms of how we train the end user and I'm curious about your approach, your thoughts on the approach there.
Rob Whetstine: A lot of people train people with punishment, right? I've found that that's never worked. It just makes them angry. It makes them hate the security simulations. Instead, what I did is I gamified it. I would pop cultural references in my simulations and I would train, and I went across the company, told them I was doing this. So, hey, when you see a simulation, I want you to look for that reference to Mal Reynolds from Firefly. I want you to find that and I want you to message me. And if you do, I'll send you some-
Maria Varmazis: Oh, no, yeah, that would've worked so well on me, I got to tell you. I would be like, "Me!" [Laughs].
Dave Bittner: Yeah, right, you'd be the most well-trained person in the company [laughs].
Rob Whetstine: Right? Right. So, it trained a behavior of analyzing an email before clicking or doing anything. And you reinforce that behavior with- it's very similar to Pavlov's dog, right? So, you reinforce that behavior with good things.
Maria Varmazis: Yeah.
Rob Whetstine: And you don't punish them. And when you have a situation where people have fallen for multiple simulations, you give them a live presentation and you talk about the personal brand damage, making it about them, as opposed to making it about the company. Because anyone listening, no one cares about your company. You do, because you may be the boss, but your employee doesn't care. They just don't want it to hurt them. So, really focusing on brand damage and personal brand damage. And when I worked at Disney, it was easy. Like, hey, if you get compromised, your informant that you have for ABC may not want to work with you anymore. You've spent the last two years cultivating that relationship and now they're scared because they don't know if their identity is safe anymore, and that instantly kills it.
Maria Varmazis: Yeah.
Rob Whetstine: We were able to go from like a 2% to 3%, like people reporting to 50%, 60%, where people started reporting and really putting in the effort because they engaged and they thought it was fun and they- I really empowered them. I deputized everyone that I would do a class with. I'd be like, you are the frontline defense.
Maria Varmazis: Yeah.
Rob Whetstine: You're what catches what comes through the cracks. And there are things that come through the cracks. And that's where you would, you know, maybe test it a little deeper, where you have a red team go in, pull some emails from the outside world that are found in the wild, because hackers are lazy, for the most part.
Maria Varmazis: They lean towards optimization.
Rob Whetstine: 100%. That's a much better way. Yeah. But they want to go through the easiest path, and many of them don't have the technical skills to do anything but the easiest path.
Maria Varmazis: Yep.
Rob Whetstine: And phishing is one of those that has no bar to entry. [ Music ]
Dave Bittner: So there's this notion that, from a company's point of view, it's corrosive for me as the company to be in a situation where I am intentionally trying to deceive my employees.
Rob Whetstine: Yep.
Dave Bittner: That makes a lot of sense to me when it comes to phishing simulations.
Rob Whetstine: I can understand it.
Dave Bittner: But how do you walk the line between effective phishing simulations, let's say, and, you know, we all hear the ones about everybody's getting a raise.
Rob Whetstine: Everybody's getting a raise. Oh, yeah.
Dave Bittner: Or everybody's, you know, Christmas bonuses are here, that sort of thing.
Rob Whetstine: Oh, yeah.
Maria Varmazis: Extra day of vacation. I'd like that one.
Rob Whetstine: Yeah. No. Well, so- when I- I kind of fell into the program because I had talked smack about it and I didn't realize the person who was running it was on the other side of the fence. So like, I was like, this simulation is --
Maria Varmazis: He's right behind me, isn't he? [Laughs].
Rob Whetstine: This simulation is ridiculous. And they go, do you think you could do better? And I'm like, yeah.
Maria Varmazis: Oop [laughs].
Rob Whetstine: So I throw out my first simulation idea and I'm like, cool. Well, we'll just say that we're no longer- we're not going to look at Memorial Day as a holiday anymore and we want people to click on this if they don't agree with it. And they're like, no, that's insane, you'd get a high click-through rate. And I was like, but isn't that what we want to do? And they're like, well, no, we want a low click-through rate. And I was like, then why are you running simulation?
Dave Bittner: Oh, boy. Oh, boy.
Maria Varmazis: Yeah. Oh no.
Dave Bittner: So perverse incentives?
Rob Whetstine: Yeah. So I dialed it back, and really it's about educating people and why you're doing it. And I had a lot of conversations on what I called the security roadshow, where I went around and I talked to a lot of people why we're doing it. I'm not trying to trick you. I'm trying to be there so, if you do fall, I can pick you up easily.
Maria Varmazis: Mm-hmm.
Rob Whetstine: As opposed to losing a promotion, losing, you know, that person, that sponsor that you were trying to work with that you now just sent a phishing email to. Those things can turn off people. So I made it about them and I made it important to them being part of that equation. And we didn't get as much kickback as we thought. There were certain business units that will remain nameless that were like, we will never do that, because we are not going to deceive our users.
Dave Bittner: Okay.
Rob Whetstine: And I can understand that, because in reality, majority of your phishing attempts are going to be stopped at your perimeter if you have even basic security, right? You're running SPF, DMARC.
Dave Bittner: Right.
Rob Whetstine: Let's hope you're doing the basics. And if you are, why are simulations even important? And it's about teaching behaviors and training people to kind of think differently.
Maria Varmazis: I'm curious, when you have these conversations with the C-suite or just executives in general, how you approach it with them.
Rob Whetstine: Oh, man. Those were, I believe, the words I used in the first C-suite conversation I had. Keep in mind, I was a young punk and, like, I'm not a guy who has any sort of pedigree. I somehow fell into security just by being there at the right time and putting in a metric ton of effort, like, high school education, like. So I'm working with people who have been previous DOD, previous FBI. And I go, yeah, I said- and they go, well, the Verizon Data Breach says that 3% should be our click-through rate. And I said, it's garbage. And they go, excuse me? And I was like, it's garbage. I said, can you tell me any of their information? How are they doing their simulations? Where are they sending their simulations? How many samples are they getting? How many samples are being sent? Well, we don't know. So we asked them, we're like, hey, can you tell us? They couldn't.
Dave Bittner: Hmm.
Rob Whetstine: I kept pushing. They said, well, we work with two companies that are, they do phishing simulations for a living, so they work with a ton of other companies, and that's where we get our data.
Maria Varmazis: Mm-hmm.
Rob Whetstine: Well, do you control the simulations they do? No. Do you control the difficulty of those simulations? No. Do you do it in the language that's native to that person if you're an international company? No. So, how is it an accurate number? And I really started to talk about changing the way we look at a click-through rate, as not a negative, but a way that we need to know that we need to do harder simulations.
Maria Varmazis: Yeah.
Rob Whetstine: We need to make things more difficult based on the phishings that are getting through our perimeter and being reported. We need to build those simulations exactly like the attackers are sending.
Maria Varmazis: Yeah, yeah.
Rob Whetstine: And I sold that idea and they bought into it.
Maria Varmazis: Yeah.
Rob Whetstine: And they said, no, this makes sense. So when we would see a consistent two months in a row, a 3% click-through rate, we would then up the difficulty. But it took us a while to go from like, Starbucks gift cards to one that tricked me.
Dave Bittner: Oh.
Rob Whetstine: Like, and I left the program, and I'll tell the story because I have no shame.
Dave Bittner: Go on [laughs].
Maria Varmazis: Listen, we've all gotten phished. It's all- it's had everybody. Yeah, yep.
Rob Whetstine: It's not a matter of if you can be phished, it's just a matter of, are they going to catch you at the right moment?
Maria Varmazis: Yep.
Rob Whetstine: So I'm somebody who's been trained on this. I'm somebody who had built a program and spent the last two years living and breathing phishing emails, reviewing them, clicking on malicious links, detonating malware. And I was obsessed. So I had moved on. I'd become the manager of security engineering. And I got an email at two o'clock in the morning, Docusign for a new employee. I literally had just hired a new employee in the UK. I clicked on it and I saw the simulation notice come up and I go, oh man, they are never going to let me live this down.
Dave Bittner: Oh [laughs].
Maria Varmazis: Yeah.
Rob Whetstine: The second I logged in, they go, we toppled the king.
Maria Varmazis: Yeah.
Dave Bittner: Who watches the watchman?
Maria Varmazis: Yep. Yep.
Rob Whetstine: I was so- But it just shows --
Maria Varmazis: There's nothing but smiles when you saw them the next day. They were like this [laughs].
Rob Whetstine: Yeah. But it proves that anyone can be compromised, right? And it's just catching them at the right time. I always say, security is like being a goalie and they have unlimited penalty shots. They can just keep shooting at you nonstop and you have no choice but to continue defending. So educating people on slowing down was the biggest thing I focused on. I probably investigated a thousand, you know, phishing emails over the several years that I was doing it and every single one of them that clicked was just in a rush.
Dave Bittner: Mm.
Maria Varmazis: Yeah. Yeah. And it's anathema to how we work in the corporate world, where everything's fast all the time. I remember when I got popped in a simulation, thankfully that our company was running, it was in response to a fake email from our CMO of this thing that needed to happen right away. And I was so used to those requests coming in from her that it completely worked on me.
Rob Whetstine: Exactly.
Maria Varmazis: And I remember when I saw that screen come up, and our security analyst just wandering over to my cube with this big grin on his face. Like, gotcha. Because I had just been working on some DBIR stuff.
Rob Whetstine: Oh, yeah.
Dave Bittner: Of course.
Maria Varmazis: So it was like, really? I got- yeah.
Rob Whetstine: We love popping security people. It's literally our --
Maria Varmazis: That's like the joy [laughs].
Dave Bittner: Guilty pleasure.
Rob Whetstine: It is our favorite. And anybody who's in security who gets popped will tell you immediately.
Maria Varmazis: Yep.
Rob Whetstine: They will message you. Because I built that relationship with the group, so they knew who I was, they knew the face behind the simulations, and they could come to me directly to complain or to tell me that, oh, that was a good one.
Maria Varmazis: Yeah, yeah.
Dave Bittner: Right. Drinks are on me tonight.
Maria Varmazis: Yeah. And I'm like, 15 years later, I still remember how it happened to me. I will never forget.
Rob Whetstine: I will never- I was so pissed. I was like, I said, did you- I said, did you plan that? Did you know I had hired someone? Were you specifically targeting me? And they're like, no, just absolute happenstance.
Dave Bittner: Wow.
Maria Varmazis: Wow. Oh, that's what it takes, yep.
Rob Whetstine: And that's just proof. It's like a horoscope, right? A simulation is a horoscope and a phishing attempt is a horoscope. Somebody, it'll relate to.
Dave Bittner: Right. The golden numbers game.
Maria Varmazis: That's a great way of putting it. That's a great way of putting it, yeah.
Dave Bittner: All right. Well, Rob, we are definitely looking forward to seeing your presentation here at Zero Trust World. I tell you what, let's shift gears a little bit and get to this week's stories. And Rob, we'd love to have you participate along the way and let us know as we go.
Rob Whetstine: I'm down. Let's go.
Dave Bittner: Maria, what do you have for us this week?
Maria Varmazis: All right, I'm excited about this one, especially since Rob, you mentioned that you're a fellow tabletop role playing game fan.
Rob Whetstine: Of course.
Maria Varmazis: So it is Thursday as we're recording this, which is normally my night, and I'm missing my session with my friends tonight.
Rob Whetstine: Don't make believe time with [inaudible 00:18:24].
Maria Varmazis: So I thought I'd bring the role playing to us today. And so the story that I have is about a case that's going to the main Supreme Court right now. And I was reading the story, and I'm not telling you too much about it because I want us to role play this a little bit, and my reaction to the story was, what did they expect would happen? So that's all I wanted to tell you. So I want the two of you to be a financial advisory firm. I want you to- you're in charge of other people's money, okay? And I'm going to be your client who has been working with you for 15 years. And I'm just curious how you would react to this situation that an actual financial advisory firm dealt with. Okay.
Dave Bittner: All right.
Maria Varmazis: So I'm calling you up. I've, again, I've been working with you for 15 years. So I have $1.3 million in money with Fidelity and I would like to completely empty that out. Can you help me with that, please?
Rob Whetstine: Why?
Maria Varmazis: Well, I have a really exciting --
Rob Whetstine: Opportunity.
Maria Varmazis: -- opportunity, but it's in real estate. It's in real estate. It's definitely legitimate. And it's a once in a lifetime thing. And I would- I really need that money. And I wouldn't be doing this for any other thing. You guys have known me for 15 years. You know, we have a long, good relationship. I've always appreciated your advice. I'm not going to another firm. I just, this is the only time I will ever have this opportunity, so I just need that money.
Rob Whetstine: I mean, that sounds amazing. Can you tell me more about it?
Maria Varmazis: Yes. So this, this is- and I don't know all the details of this, but assume that I fill in a lot of relevant details here.
Rob Whetstine: Of course. Sure.
Maria Varmazis: And it- everything I'm telling you sounds completely of sound mind and legitimate.
Rob Whetstine: Awesome. No, that's, that's great. How long have you known this person? Are they the King of Nairobia? Like, I'm a bit confused.
Maria Varmazis: Yeah. Yeah. I wish I could follow you down that path on the RP. But yeah, no, this, it's definitely- it's through a realtor who I know really well. And, you know, this is something that my wife and I have been looking into for years and it finally happened. And, you know, again, I wouldn't normally ask for this, but yeah.
Dave Bittner: I agree with everything. In fact, as Rob was saying those words, I was thinking the exact same words. Like, tell me more [laughs].
Rob Whetstine: Well, you don't want to instantly shut them down.
Maria Varmazis: Right. Right.
Dave Bittner: No. No.
Rob Whetstine: They're a customer that's been there for a while, so you want to just kind of buy into their crazy.
Dave Bittner: Right. Would you- I would say --
Maria Varmazis: Don't metagame now. You don't know that I'm crazy [laughs].
Dave Bittner: I would say, as your financial partner, would you be okay with us doing a little due diligence?
Maria Varmazis: I would really appreciate that if you did some due diligence, actually. Yeah. So by all means, go ahead. All right.
Rob Whetstine: All right. So that's where things can- so we do the due diligence and then we say, yeah, no, it looks good.
Maria Varmazis: Yeah. So that would have been amazing, had that happened [laughs].
Rob Whetstine: Oh no [laughs].
Dave Bittner: Oh no.
Maria Varmazis: So, okay. So you both did really well.
Rob Whetstine: Oh, good.
Dave Bittner: Phew [laughs].
Maria Varmazis: I feel a little metagaming did go on, because this is a show about hacking humans after all. So you kind of knew where I was going with it, but you both did very well, I got to say. So let me --
Dave Bittner: Do we get to go onto the next round?
Rob Whetstine: I feel good.
Maria Varmazis: So, roll for initiative. [ Laughter ] Yeah. And I was going to say, I should have brought my dice with me. No, no, that was really well done. And I feel, as the co-roleplayer in that one, I didn't actually have enough to give back to you, but you did really well. So let me tell you a little bit about the story about what actually was going on here and where this roleplayed situation diverged from what actually happened. So there is a firm in Maine, the state of Maine, called R.M. Davis, and they indeed had a 15-year client, a couple named Bruce and Linda MacMillan. And Bruce and Linda McMillan went to their advisory firm and said exactly what I said to you both, hey, I've got my entire life savings, $1.3 million in fidelity funds. I want to wipe it out and it's for a really exciting real estate opportunity. And, to their credit, R.M. Davis did very similarly to what the two of you did, said, tell us more about that because that is quite a request.
Dave Bittner: Yeah, yeah. That sounds a little sus.
Maria Varmazis: Sounds a little sus.
Dave Bittner: Yeah.
Maria Varmazis: Exactly. And indeed it was. And here's where it got tricky for everybody involved. Bruce and Linda lied to R.M. Davis at every turn and said, everything's totally on the up and up. Like, you can do your due diligence and everything that we're going to tell you essentially is a lie. Because, as you would predict, they were being scammed and that money was indeed going to go to Bitcoin crypto scammers.
Rob Whetstine: Oh, wow.
Dave Bittner: I'm sure the scammers told them very specifically to lie also.
Maria Varmazis: Correct. Correct.
Dave Bittner: Which is the- it's very easy when you basically make the people in on the scam with you.
Maria Varmazis: Yes.
Dave Bittner: Because you can convince them that, if you tell these people, they're going to get in on it too and you're going to lose profits. Right?
Maria Varmazis: That's correct. That is exactly what happened. So Bruce and Linda were coached every step of the way by the people who are scamming them and the place where it diverged from what the two of you raised, which is actually, Dave, where you mentioned essentially a red flag type law, which does exist in Maine.
Dave Bittner: It does.
Maria Varmazis: That is a law, a type- types of laws like that exist in about half of the US States, not in all of them, but half the states. It does exist in Maine. And that is actually the reason why there's a lawsuit going all the way to the Supreme court in Maine. Bruce and Linda- actually, Linda has since passed away, but Bruce is suing his financial firm saying, you didn't see all of these red flags that we were throwing your way. We were clearly being scammed and you guys didn't stop the scam.
Rob Whetstine: Hmm.
Maria Varmazis: Whereas the financial firm said, you guys lied to us every step in the way. We tried to stop you. And so essentially when this lawsuit was at a lower level of the courts, there's a phrase in the article that I was reading about this saying, the court's question whether investors have the right to spend their money as they wish, quote, "even if it's stupid". [ Laughter ] Which made me go, there's- this is a really interesting --
Dave Bittner: I see - [inaudible 00:24:20] law students to quote that.
Interviewer: "Even if it's stupid", yeah.
Rob Whetstine: Even if it's --
Dave Bittner: "Stupid".
Rob Whetstine: Yeah, yeah. That's awesome.
Maria Varmazis: So basically the- So yeah, on one side, the clients were saying we were being scammed and there were a whole bunch of red flags that our financial advisor should have caught. And then the financial advisors are going, yeah, but you lied to us when we were trying to do that, and also by the way, compliance and the red flag laws are not mandated, so we were doing the best that we can, but, you know, we did what we could, but it's not, you know, there wasn't a law saying we had to actually- you know, we had to do the best we could, essentially. So, again, on the client side, they never disclosed to the financial advisors that they believed that their accounts had been compromised. And so that is why- so everyone was lying to each other [laughs].
Rob Whetstine: Yeah.
Maria Varmazis: So what do you do in that situation, as a financial advisory firm? You did your due diligence, you did the best you can, but essentially, if the client wants to do something dumb.
Rob Whetstine: I mean, you can't stop them. It's their money, right? And that's the biggest thing. So my hope for them is that they documented it in writing. Because if a lot of this happened verbally, then that hearsay argument is going to be pretty difficult to prove.
Maria Varmazis: Yeah.
Rob Whetstine: And they're- I can understand both sides of it, right? Because a lot of these people who get involved in these scams, they get scared. Right?
Maria Varmazis: Yeah. Yeah.
Rob Whetstine: And there's all kinds of different scams that are going on right now that, especially with AI making things a lot easier to falsify evidence and proof, that can be very scary.
Maria Varmazis: Yeah.
Rob Whetstine: So, especially for an older couple, I'm assuming they are, they got 1.3 million, I'm assuming they've been saving for a bit, when they get targeted, they- it becomes a very simple thing of, like, are they going to resist it and tell the truth and kind of come clean and risk the ramifications of that?
Maria Varmazis: Yeah.
Rob Whetstine: Because a lot of times there's some serious threats. I mean, I engage with attackers all the time as part of my social media stuff where- and I share those stories where I like, I click on a phish or I call back that phone number from the Norton Antivirus they sent me.
Maria Varmazis: Oh, fun times. Yeah.
Dave Bittner: Right [laughs].
Rob Whetstine: And I share what that's like and kind of that experience, and they can get very threatening.
Maria Varmazis: Oh, absolutely.
Dave Bittner: Oh, yeah.
Rob Whetstine: Very quickly.
Maria Varmazis: Like, physical threats.
Rob Whetstine: Yeah.
Maria Varmazis: Yeah, absolutely. Yeah. And another question about the red flag law and this specific situation was, there's a bit of a wrinkle about whether or not a financial advisor can act whether or not they think their clients isn't of sound mind. Like, you know --
Rob Whetstine: [laughs] Like, power of attorney?
Maria Varmazis: Well --
Rob Whetstine: Like, taking it because they're not of sound mind. That'd be rough.
Maria Varmazis: Well, it's also, you know, is- are the people making this decision, are they mentally competent at that point?
Rob Whetstine: That's something they could never actually define.
Maria Varmazis: They can never answer. Yeah. And also, in the case of this couple, Bruce, who is the surviving- the member- the husband who's still alive, he's not mentally deficient, it seems. So, you know, he was- it's not like he had dementia or something. He seemed just fine. So, it's- I'm watching this case with great interest, because this is one of those I was reading through it and I'm going, what did they expect the financial guys to do in this situation when you lied to them?
Rob Whetstine: Well, it seems to me like somewhere in the terms of service with your financial advisor, there should be a paragraph about willful deception.
Maria Varmazis: Yeah. If you lie to us, like, what do you want us to do?
Dave Bittner: Yeah. Right. Right.
Rob Whetstine: I mean, if you think about it though, like a lot of money people take massive risks sometimes. So like, it may not be completely out of the ordinary, or they may say, look, I understand this is a huge gamble, but I'm going to put 500,000 on, you know, this small little company called Apple, right? And then your financial advisor is like, you need to sell everything, they're about to go out of business. And it's like, no, I'm just going to hold, I'm going to hold. And they're like, you're going to lose all your money. And then it turns out to be a huge win, right? Yeah. But for every huge win, there's about a million that are huge losses.
Maria Varmazis: Yep.
Rob Whetstine: And when it comes to crypto scams, like, it's getting more and more just demanding, and they're becoming more and more scary because the information is readily available. I investigated a scam recently where the attacker sent an email, it was your standard sextortion email, where it's like, hey, we saw you on the internet, we saw you going to these nasty sites and we recorded you.
Maria Varmazis: Yep.
Rob Whetstine: But then they took it one level further and they sent a follow-up email the next week saying, why are you going shopping in your blue sedan?
Maria Varmazis: Ooh.
Rob Whetstine: Why do you think you can take your Toyota out and go do these things without my permission.
Dave Bittner: Wow.
Rob Whetstine: You need to pay, or I'm going.
Dave Bittner: Wow.
Rob Whetstine: They literally just looked up open DMV records and found the information online.
Maria Varmazis: Yep, yep. Yep.
Rob Whetstine: But it added that additional scare where I had to talk a customer of mine and somebody I work with from a consulting side, and I'm like, no, no, no, it's still a scam. It's like, well, how do they know it was my car? I was like, I mean, they paid $20 to get that information.
Maria Varmazis: Yeah, you don't realize how much information is readily available online.
Rob Whetstine: An obscene amount.
Maria Varmazis: It's unreal, yeah.
Rob Whetstine: And it's readily available for anyone who's willing to pay a very small amount.
Maria Varmazis: Yeah.
Dave Bittner: Right.
Rob Whetstine: Because a lot of that is public record. Anything that is entered into your home or any of those things, it's very difficult to get those records scrubbed. I've tried.
Maria Varmazis: Yeah, same.
Rob Whetstine: Unless you're within law enforcement, it is not an option.
Maria Varmazis: Yeah.
Dave Bittner: Oh, interesting.
Rob Whetstine: Yeah, yeah. My buddy is in law enforcement. He lives next door to me. So when you go on a Google Street View, it's like, my house, and then black. And I'm like --
Maria Varmazis: It doesn't exist, don't ask. Who's asking?
Rob Whetstine: There's nothing there.
Dave Bittner: We need to ask him to deputize you.
Rob Whetstine: I- totally, right? Let me get that sweet privilege.
Dave Bittner: [laughs] That's right. A blurry house.
Rob Whetstine: But like, that's the thing that makes it really interesting is these scams are becoming easier and easier to do. And people, in general, want to please people. And when, if you add a little bit of fear and a little bit enough to give them social trust, it's over.
Maria Varmazis: Yeah. Yeah.
Dave Bittner: Yeah. Yeah.
Rob Whetstine: It comes in when you can tell them you've got their home address, you've got their car --
Maria Varmazis: Yeah. Here's a picture of your house. That one scares people, understandably. Yeah, yeah. Yep.
Rob Whetstine: Or here's your car. Right? And you could take a photo now with AI from Google Street View. You could say, create this, put this car in a public parking lot, put this car in a Walmart parking lot and create that image. And then you could send that and say, hey, I'm watching you.
Maria Varmazis: Yep.
Dave Bittner: Right. Right.
Rob Whetstine: There's a new scam on eBay that you may have heard about where people are getting items in and then they're tossing them in the AI and they're saying, add a crack to this.
Maria Varmazis: Oh boy.
Rob Whetstine: And then they send it and they go, this item broken in shipping, I'm not paying for this.
Dave Bittner: Wow.
Maria Varmazis: Oh, dang.
Rob Whetstine: So like --
Maria Varmazis: And it's going to be all these small sellers that are getting nailed with that. They're getting crushed. Right? I'm sure they are. Yeah, yeah, yeah.
Rob Whetstine: So where do you go when AI is making scamming incredibly easy? There's really no repercussions for things like this.
Maria Varmazis: Cabin in the woods is my answer to that one a lot of the time. Honestly, bug out, cabin, time to go.
Rob Whetstine: Yeah, no, that's what --
Dave Bittner: Herding sheep in New Zealand was always my out.
Rob Whetstine: That sounds lovely.
Maria Varmazis: Great. I'm hanging out in the Shire.
Dave Bittner: That's right.
Rob Whetstine: I mean, we'll set up an Airbnb.
Dave Bittner: Exactly. Exactly.
Rob Whetstine: Murray and I will come and hang out.
Maria Varmazis: I'm in. That's right.
Dave Bittner: Yeah.
Rob Whetstine: We'll play D&D [laughs].
Maria Varmazis: You'll play D&D? [Laughs].
Dave Bittner: No, of course we will.
Rob Whetstine: Alright, I want to get- I want to go to, like, one of those D&D campaigns, like, in a castle.
Maria Varmazis: I've been wanting to do one of those for ages. Yeah. They look crazy good.
Rob Whetstine: So I found out that you can rent Gary Gygax's original house and his basement on Airbnb.
Dave Bittner: Oh my God.
Maria Varmazis: I'm not sure I'd want to do the smell, man. I'm sorry.
Dave Bittner: I know. Can you imagine?
Rob Whetstine: Oh, I don't know.
Maria Varmazis: It's going to smell like dirty socks and Doritos.
Rob Whetstine: I'm not sure.
Dave Bittner: And probably cigarettes, from that era.
Rob Whetstine: Totally.
Maria Varmazis: Big risk.
Rob Whetstine: I can't wait.
Maria Varmazis: Everybody's mom's basement smell, yeah.
Rob Whetstine: I'm trying to convince my friends to go. I was like, hey, we're going to go here and this is going to be what we're doing for my birthday [laughs].
Maria Varmazis: The rumpus room [laughs].
Dave Bittner: Oh, boy. All right. I'll tell you what, let's take a quick break here to hear from our sponsor. We will be right back after this message. [ Music ] And we are back. We are coming to you from Zero Trust World in sunny Orlando, Florida, thanks to our sponsors at Threat Locker. We appreciate them hosting us this week while we're here and providing the facilities for us to record our podcast live. It's time for my story this week and mine is about malvertising. So malvertising is one of those cyber threats I think most people encounter it many times without realizing it. You know, you visit a perfectly legit website and an ad loads in the background, and suddenly you're redirected to a scam page. And it's an operation, in this case, in this research from the folks at Confiant Security, they identified a threat actor called D-Shortiez.
Rob Whetstine: That's a good name.
Dave Bittner: D-Shortiez.
Rob Whetstine: My favorite is still Charming Kitten.
Dave Bittner: Yes.
Rob Whetstine: That's the best attacker group name.
Dave Bittner: Yes. We had joked that if Canada had a threat group, it would be Apologetic Beaver.
Rob Whetstine: Yes. I'm down.
Maria Varmazis: Angry Moose is the other one.
Dave Bittner: Right. So the folks at Confiant, they've been tracking this group since 2022 and early on their ads pushed fake giveaways, you know, things like, hey, congrats, good news, you're the five billionth Google search today, and they had bogus Amazon prizes that trick people into entering their credit card information. But last year, the researchers noticed some changes. The same infrastructure suddenly began redirecting Windows users to fake tech support alerts that looked like Microsoft security warnings.
Rob Whetstine: Oh, yeah.
Dave Bittner: But while investigating these campaigns, the team stumbled onto something interesting. They found an internal testing page that the attackers themselves were using.
Rob Whetstine: Nice.
Dave Bittner: It was sort of a staging area where the criminals tested their ads before launching them. And of course, for the researchers, this was a gold mine. The page was publicly accessible.
Maria Varmazis: Oh no [laughs].
Rob Whetstine: I love when attackers leave their stuff open.
Dave Bittner: Wait for it. It gets better.
Maria Varmazis: Oh, good.
Dave Bittner: It was regularly updated with the new domains that the attackers plan to use next.
Rob Whetstine: Oh, how convenient.
Dave Bittner: Yeah. So the researchers built some automation to monitor the page and harvest the domains, which meant they could block the infrastructure before the ads ever went live. So a few months later, they discovered a second cluster of infrastructure. This one had an admin control panel that showed all the active campaigns, performance metrics, and targeting data.
Rob Whetstine: That's awesome.
Maria Varmazis: Wow. That's a gold mine.
Rob Whetstine: For the researchers.
Maria Varmazis: For the researcher, yeah.
Dave Bittner: Well, the attackers had added a password.
Rob Whetstine: Oh no.
Maria Varmazis: Oh no.
Rob Whetstine: Is it "password"?
Dave Bittner: One, two, three, four, five, six [laughs]. Oh, nicely done.
Maria Varmazis: Oh no. I was going to go with "Hunter Two", that was the other.
Dave Bittner: Good guess [laughs].
Rob Whetstine: Hacker proof.
Maria Varmazis: Yeah.
Dave Bittner: So the researchers could still keep watching from the inside. They were able to match the campaign IDs and domains to their own scanning systems. And again, they could identify and block these malicious ads before users ever saw them.
Rob Whetstine: That's awesome.
Dave Bittner: They tracked 59 million malicious ad impressions in 2025. About 95% of them were aimed at US users. So, a couple of takeaways here. I mean, first of all, malvertising remains massive and profitable as an ecosystem.
Rob Whetstine: Well, it's not just profitable for the attackers. That's the thing people don't realize.
Maria Varmazis: Yeah, yeah, yeah.
Dave Bittner: Yeah.
Rob Whetstine: Like, I investigate fake jobs and stuff on LinkedIn, which is basically the same thing, it's they're just trying to steal your information.
Dave Bittner: Right.
Rob Whetstine: There's people getting rich off of it. And the companies who put the data out there, I think Facebook recently had a thing where it's like $2.1 billion of their ad revenue is from scammers.
Maria Varmazis: Oh, yeah, we talked about that on the show. We were like, yeah, why would they want to stop when that much money's coming in again?
Rob Whetstine: Right. I had built a bot that would go and validate every URL that was posted and then post a comment that said, like, hey, just want to let you know this website was created in the last 24 hours and is most likely a scam.
Maria Varmazis: Yep.
Rob Whetstine: And they permanently banned me, and then IP banned me, and then banned my name.
Maria Varmazis: Holy shit.
Dave Bittner: Wow.
Rob Whetstine: So like, I was-
Dave Bittner: Meta did this?
Rob Whetstine: Yeah.
Maria Varmazis: And then they found your MAC address and they blacklisted you. Dang.
Rob Whetstine: I was permanently removed and then they added a thing on my account where they --
Maria Varmazis: You need a trophy for that. I would be very proud of that.
Rob Whetstine: Oh yeah. So then they added something to my account where they said, if you want your account back, we need your photo ID and all your- basically, a copy of your driver's license to re-enable your account.
Dave Bittner: Oh.
Rob Whetstine: And I sent them a photo of myself, and at the time it was Christmas, giving the middle finger. And surprisingly, my account never got re-enabled.
Dave Bittner: [laughs] Oh, what a shame.
Maria Varmazis: But it had little Christmas lights on the finger [laughs].
Rob Whetstine: Yeah, but that- the advertising makes companies huge amounts of money.
Maria Varmazis: Yeah.
Dave Bittner: Yeah.
Rob Whetstine: Most of the fake ads, the fake jobs that myself and my buddy Jay, the profiler, like, look into on LinkedIn are all sponsored, meaning that they paid a percentage to get those jobs out there.
Dave Bittner: Right.
Rob Whetstine: And we've had the attackers- so like, whenever you start exposing scammers, you get attacked, and you get attacked a lot. So I get threats all the time. And on top of that, they'll be like, no, we're totally real. And I've invited multiple to my podcast. I'm like, look, if we're wrong, come hang out. Between myself and Jay, we've got probably around 40,000 people, like, come list- we are happy to have a conversation. Surprisingly, no one has ever taken me up on this over.
Maria Varmazis: What? Gosh, maybe they're just camera shy.
Rob Whetstine: Yeah, no, but that's the audacity of these things. And the thing is there's no repercussions.
Maria Varmazis: No, none at all. Yeah.
Dave Bittner: Yeah. Well, obviously, the other thing here is that sort of the break in the investigation came not from the sophistication of the researchers, but from the laziest --
Rob Whetstine: I found that multiple times in my investigation, where they would leave the attacking website open and then I would find an INI file or some sort of configuration file with all of the domains so we could pre-block all of the domains that were associated with the attack. I mean, it- all the time, because majority of attackers- so here's another thing that a lot of people don't talk about is a lot of people doing attacking are not doing it willfully. They are literally enslaved.
Maria Varmazis: Yes. Yeah.
Rob Whetstine: Like they went to a tech interview in Nairobia or some third world country and then they were captured and they have to earn their way out, especially with the lonely heart scams and the pig butchering scams.
Dave Bittner: Right.
Rob Whetstine: So I've talked to these attackers that have told me, like, I don't want to do this, I literally have no choice.
Maria Varmazis: Yeah.
Dave Bittner: Wow.
Rob Whetstine: So as much as I feel bad for them, I also understand that not everyone is malicious. Some of them are victims themselves, and that's the craziest thing about attacking outside the United States. And even in the US, like pig butchering happens here too, it's just people are more afraid of it, but it's very difficult to prosecute. And like, in the instance where- the crypto scam that we talked about, you know, it's like, it's very difficult to kind of get through things like that. Because how do you trace it?
Maria Varmazis: Yeah.
Dave Bittner: Right.
Interviewer: Well, it- what you were just saying about- we used to say a lot of the times that, you know, a lot of times attackers are kind of stupid and, sure, but it was especially with the organized crime and the slavery involved now, it kind of reminds me of those stories from World War II of when people would find shells that didn't have any explosives inside and was written on the side, like, this is the best we could do. It's like maybe now when we're seeing these, this real incompetence, sometimes it's- it could be somebody going, this is the best I could do.
Dave Bittner: Oh.
Rob Whetstine: I can tell you, from talking with these individuals, that is very much what they do. Because their heart's not in it and they don't want to do it. But also, remember, when they send a phishing email that's very easily identified, they do that on purpose because they only want to catch the dumb people.
Maria Varmazis: Yeah.
Dave Bittner: Right.
Rob Whetstine: They don't want to catch somebody who's going to second guess it. They want to catch somebody who's like, oh my goodness, this prince from, you know, Nigeria is sending me a million dollars, all I need to do is this. And we joke about that, but that's still a multi-million dollar profit scam ever year.
Maria Varmazis: It sure is.
Rob Whetstine: It's insanity how much money it makes.
Maria Varmazis: It sure is.
Rob Whetstine: It's like, I'm in the wrong business.
Dave Bittner: I know.
Maria Varmazis: Yeah, the Yahoo boys are doing real well.
Rob Whetstine: Yeah. It's wild.
Dave Bittner: Retirement plan. Retirement plan.
Rob Whetstine: Right?
Maria Varmazis: You can't say that on the internet, Dave.
Rob Whetstine: Well, everyone has that moment when you're an ethical hacker where you're like, is this the moment I turn black hat? I remember I was doing a hack one time and I had gained access to, like, financial records for all of these super high level executives, as well as all the bank account information, as well as all the things where I was like --
Maria Varmazis: This is a lot.
Rob Whetstine: Is this the moment? Is this when I go, you know what, let me just write my own check, let's get out of here. I, of course, didn't do that. But you always have that and that's --
Dave Bittner: Moral dilemma. Moral dilemma.
Rob Whetstine: No, and I try to explain that to people. Like, your hackers are only as loyal until they're not. You know?
Dave Bittner: Yeah.
Maria Varmazis: Maybe we need some more ethics classes for people.
Rob Whetstine: I think it's important.
Maria Varmazis: I think it's really important. Yeah.
Dave Bittner: All right. I tell you what, let's move along here, just for the sake of time. And of course, to our listeners, if there's something that you would like to send us and so we can consider it for the show, please do so. Our email address is hackinghumans@n2k.com. All right, Rob, Maria, it is time to move on to our Catch of the Day. [ Soundbite of reeling in fishing line ] [ Music ] Our Catch of the Day comes from the Scambait subreddit and, Maria, why don't you lead us off here? This is some pretty standard stuff here, but I think entertaining.
Maria Varmazis: All right. Hello, I'm Mavis Wanczyk. Wanczyk? Wanczyk.
Dave Bittner: Your guess is as good as mine. That's a lot of syllables, not very many vowels.
Maria Varmazis: Apologies to our Polish listeners. I'm learning. I'm Mavis from Texas and I'm 65 years and I'm a businesswoman, but my pastor to us on this week about helping the, and it really touched. So that's why I'm here to help other, for a little out of what I have. I'm texting you to see if you need some money to pay off bills or do some other things.
Dave Bittner: Hello, nice to meet you.
Maria Varmazis: And you also send me your number, sir, so I can message you on signal app, sir, so we can cat more better, sir. I can help you with any amount, sir. If you want to buy a car or house or truck, sir, let me know. I can help you with any amount, sir.
Dave Bittner: Hello, Mavis.
Rob Whetstine: That's a lot of sirs.
Maria Varmazis: That's a lot of sirs.
Dave Bittner: Well, Mavis is very polite. To be honest with you, I don't actually need much money. You see, I've already retired to my farm out in the country here and between farming, my pension and my superannuation, I have plenty to get by. My worry is my son, you see. He works out on an oil rig across the country, and between his poor financial choices and some unfortunate incidents, he's found himself in quite the debt. Now, initially, I wasn't going to help him out of it, but since you reached out to me, I thought I might as well solve this problem for him.
Maria Varmazis: You can see, sir, look at the people I help, sir, on TikTok, sir, all day, get their money immediately, sir. So let me know, sir, I can help you with any amount of money, sir. Are you afraid of telling me the amount you need, sir? Question marks [laughs].
Dave Bittner: [laughs] Skip ahead a little bit.
Maria Varmazis: That's a lot of question marks.
Dave Bittner: He says, let's just say $100,000. That should work for the time being. If he needs more than that, he can sort it out himself.
Maria Varmazis: Yeah. Yes. Okay, sir, I will help him with that, sir. So are you the one who is going to help him and collect the money or will he do that himself, sir?
Rob Whetstine: Very polite.
Dave Bittner: Oh, it would probably be best if I get it, then I can pay off his debts for him.
Maria Varmazis: Okay, sir, how you get the money? The one green dot is free at the store. All you need to do is activate it with minimum amount of $50 so I can pay you off immediately.
Dave Bittner: The one what what?
Maria Varmazis: This is the card you are going to get, sir. So I can be a to load the money, okay, it sir. Wow, I don't know what- how to parse that.
Rob Whetstine: That's impressive.
Maria Varmazis: And you go to the ATM around you and take the money out of the card, sir. So when you get the card, you activate it, sir, so I can be able to load the money on the card, sir. And you can go to the ATM around you and take the money out of the card, sir. Question marks.
Rob Whetstine: The question marks really sell it.
Dave Bittner: They really do. I think we can stop there. Like, it goes on.
Maria Varmazis: It's a lot of sirs.
Dave Bittner: But she, Mavis, includes a picture of a Visa debit card, so --
Rob Whetstine: Only $50?
Maria Varmazis: Only $50, yeah.
Dave Bittner: Yeah, so unpack it and help us out here, Rob. What do you think is going on behind the scenes?
Rob Whetstine: I feel like this this might be just a scam to get $50 [laughs]. I'm just saying. I mean --
Maria Varmazis: Just front me 50.
Rob Whetstine: I mean, maybe not. Maybe it's legit. I like, I always like to think that there's like somebody who's been trying to give away their money forever, but nobody believes it's real.
Dave Bittner: Yeah. Right [laughs].
Rob Whetstine: It's like, I just- why can't anyone take my millions?
Dave Bittner: Yeah [laughs].
Rob Whetstine: This is the struggle of a prince. This is what I have to deal with. I feel like that I would love that to be a reality.
Maria Varmazis: I mean, I'm available, if that person does exist. Please pay off my mortgage.
Dave Bittner: [inaudible 00:45:26] @n2k.com.
Maria Varmazis: I would love that. Go ahead.
Dave Bittner: Yeah, I wonder too, like is this, as you were saying earlier, Rob, like they want to find the gullible people to get them on the hook. You start with 50 bucks and then we got a hot one on the line.
Rob Whetstine: Well, sometimes it ends there too. So I've investigated a ton of these because I love investigating scams and kind of messing with scammers, probably to a point of obsession. And sometimes it stops at the $50. And then, but other times what will happen is, so I've given my information away to hundreds of hackers. I have burner phones in my house that rang in like I'm like, ssh, and I like run over and grab the burner phone.
Dave Bittner: Cocktail party at your house is just a joy [laughs].
Rob Whetstine: Totally. Totally. So my kids are always like, what are you doing? I'm like, ssh. Why are you giving them money? Ssh. So like, what it'll start out as is 50. And then what happens is your information gets added to what I call, like, the hacker Rolodex. So a lot of these people share information. It's run by, I would guess, probably maybe 100 or 200 organizations. They're all little small sub-pockets and they share information with each other. And the reason I know this is because I fall for scams purposely and my phones blow up constantly with phishing messages, with scam texts. My fake emails that I've used in scams get tons of like, hey, you need to pay Norton antivirus, because they know once they have one person, then they sell that information to another hacker group. And it's very inexpensive to buy things like that, like, on the dark web, like this- you can buy like a whole trove of people who are just like, you know, whales, so to speak, and you pay like, you know, 50 cents, dollar, because they're just making money on top of money at that point. They've already done the scam, now they're selling your information to make more money. That's how a lot of the job scams are working right now, too, is like, they'll get you with a $25 application fee.
Maria Varmazis: Yeah. Yeah.
Rob Whetstine: One of the ones I investigated recently was brilliant. They said, hey, we would love to hire you, but we need to do a background check. And they send a link. The link goes to a legitimate website for a credit check. And I was like, how are they making money? Like, what is this scam? It was a referral link in the URL.
Maria Varmazis: Oh, so they get a cut.
Rob Whetstine: They send it out to millions of people, they get a cut for every person who signs up. They spend 9.99 for the first month. That person, at the end of that month, gets paid $5 or whatever it may be for that new person that just signed up. You're making literally 500 to a million dollars a year, just sending out fake jobs and sending them a referral link to sign up for the credit check.
Maria Varmazis: Wow.
Dave Bittner: Wow.
Rob Whetstine: And then that's how you streamline it, right? They go, hey, we want to streamline you, but we need to get a background check done immediately. And with so many people struggling to find work in technology --
Maria Varmazis: Oh yeah. Dime a dozen.
Rob Whetstine: It's very easy to get people who will fall for it.
Maria Varmazis: You got to wonder how much of the tech ecosystem right now is being propped up by scam.
Rob Whetstine: I estimate 80%.
Maria Varmazis: Oh my God.
Dave Bittner: Wow.
Rob Whetstine: It is an obscene amount of fake jobs. I have- my buddy Jay, and I've mentioned him before, he's called the profiler on LinkedIn, he's removed 38,000 jobs in the last year.
Dave Bittner: Mm.
Maria Varmazis: Jesus.
Rob Whetstine: I've investigated, in the last two years, I've investigated for mentees, probably maybe 40 or 50 job offers, 99% Of them have been scams.
Dave Bittner: Really?
Maria Varmazis: Wow.
Rob Whetstine: Yeah, man. And they're really good. I had one that was brilliant. They had compromised a recruiter's account that- a well-established account. So it passed my first sniff test.
Maria Varmazis: Yep.
Rob Whetstine: And the account looked good. They've been posting. My friend went for the job interview, and it just seemed a little bit off.
Maria Varmazis: Was it remote? In person?
Rob Whetstine: Remote.
Maria Varmazis: Okay. Yep.
Rob Whetstine: And they wore the recruiters face.
Maria Varmazis: Oh, Jesus.
Dave Bittner: Oh, wow.
Rob Whetstine: They put on a deep fake, which is relatively easy now with some photos, and they wore the recruiters face. And luckily, my mentee, who's been in technology for a while, she goes, can you spin in your chair? Because the mask can't keep- it won't stay.
Maria Varmazis: Yeah. Yeah, yeah.
Dave Bittner: Right. Right.
Rob Whetstine: And they refused. Oh, my chair doesn't spin. Well, that's fine. Put both your hands in front of your face.
Maria Varmazis: Yeah. Yeah.
Rob Whetstine: And that's good now, but we're looking at, maybe six months, maybe even a year, that won't work anymore.
Maria Varmazis: That won't work anymore. Yeah, I know, that cat and mouse game is always being updated.
Rob Whetstine: It is scary. But majority of jobs that I've investigated, majority of roles that are posted or either not real, or they're already filled. Like, companies have to post roles externally. There's a lot of policy around that.
Maria Varmazis: Yep.
Rob Whetstine: So I always hope people who are in the job market who are struggling, I'm like, it's not you. Statistically, that job went to their 10 friends who are unemployed right now.
Maria Varmazis: Yeah.
Rob Whetstine: Like, you just, you have to become one of their buddies. Like, when I got laid off, I hit LinkedIn really hard and I realized that building a social presence was really important. And then I started to get interviews by building a reputation and kind of people started coming to me. But I would fall for scams on purpose. I would get on calls and they would try to drill me for information about my previous company. That was my favorite. Like, I would get a job offer and they'd be like, we want to talk to you. And I joined with five guys and they would start peppering me with questions about Disney and their AI posture and all this stuff. And I was just making up crazy stuff. I was like, yeah, we really invest, our biggest investment right now is AI honey potting. And they're like, oh, wow, tell me more. And I was like, yeah, we do honey pot AI's, and they're like really enthralled.
Maria Varmazis: Taking copious notes.
Rob Whetstine: They literally are, the whole time.
Maria Varmazis: Yeah, yeah, yeah.
Rob Whetstine: And they're like, well, we would love to offer you job. And I was like, oh, that's awesome. I said, but I'll let you know, everything I told you was a lie and I was just wasting your time because clearly you're scamming me. And I posted some of those videos. But like, it's very interesting, because a lot of people who are in a desperate state, and I've been working with people for the last two years in this hiring market, like, they're struggling, and the attackers are taking advantage of it whole heart. Because it's very easy to do and it costs very little. And you can scam a lot of people really, really quickly.
Maria Varmazis: Yeah. And especially if you're looking for a job, that's wasting a ton of your time, which you could be using to find a better job, that exists.
Rob Whetstine: And that's the biggest thing in all of the job networks, not just LinkedIn. All of them are just flooded with fake jobs because there's a lot of value to it. I've had mentees who have signed up for jobs. There's two big scams that I've seen recently that are really clever and just terrible. One is what I call the MSP scam, where they'll hire you, and in your contract, it basically says if you leave within the first two years, you owe them $20,000.
Maria Varmazis: Get out.
Rob Whetstine: Yeah.
Maria Varmazis: Oh.
Rob Whetstine: And then they make it a very inhabitable work environment. You were hired as a security professional, but you're doing desktop support and you're going house to house. And if you quit, you owe them money.
Maria Varmazis: Oh my God.
Rob Whetstine: Because they invested in you, and that's their logic. And people signed it because they have no choice.
Maria Varmazis: Oh.
Dave Bittner: Mm.
Rob Whetstine: And I had one guy who moved across country for a job scam. And it was absolutely- the building was fake, all- he came to me after and I tried to help him recover some of his things, but like, it was rough. It was- it happened so often that it's like not even- when anybody messages me- so, if you're a new person in cyber and you're listening to this and you get a job offer, it's a scam. [ Laughter ] Like, unless you actively know the person, it's a scam.
Maria Varmazis: So go to B-Sides near you.
Rob Whetstine: Yes, yes.
Maria Varmazis: Seriously, go meet people in person. Go to LobbyCon.
Rob Whetstine: Volunteer your time. Don't go as an attendee, volunteer.
Maria Varmazis: Go as a volunteer, yep.
Rob Whetstine: And put the cycles in, because that's how you get noticed. All of my mentees who have listened to me and taken this advice have found jobs for entry level.
Maria Varmazis: Yep.
Dave Bittner: Wow.
Rob Whetstine: Because you have to put in the work. All of us who got into technology and cyber, we basically got into it because we were like the one who just kept breaking stuff.
Maria Varmazis: And showing up.
Rob Whetstine: And showing up.
Maria Varmazis: Yeah.
Dave Bittner: Right.
Rob Whetstine: Like, I hung out long enough that they go, hey, you could probably do this, do you want to figure it out?
Dave Bittner: We might as well start paying you [laughs].
Rob Whetstine: Yeah.
Maria Varmazis: Honestly, yeah. And I've known people who've gotten jobs who are hanging out at the Locksport table at every con.
Rob Whetstine: Yeah.
Maria Varmazis: And it's just like, you make enough conversation with people, they go, you know, your brain works the way we need it to work for the kind of work that we're doing.
Rob Whetstine: 100%.
Maria Varmazis: Yeah. It's amazing, yeah. And cons always need people. They really need volunteers, so --
Rob Whetstine: And I know it's hard for people who are neurodivergent like myself to be social.
Maria Varmazis: And a lot of us are in this space, so --
Rob Whetstine: Almost all of us.
Maria Varmazis: Almost all of us are, so like, you're with friends.
Rob Whetstine: I would say the majority of people in technology. Because you've kind of got to be a little bit OCD and a little neurospicy.
Maria Varmazis: You got to be a little bit spicy. Yeah.
Rob Whetstine: You have to, because the job itself is very, very repetitive, very monotonous. And you have to get kind of obsessed about the world's smallest details.
Maria Varmazis: Yep. And get mad about it.
Rob Whetstine: Like, really upset.
Maria Varmazis: Really mad [laughs].
Dave Bittner: Right.
Rob Whetstine: Like, that you can't find this tiny needle in a haystack. I remember staring at logs for like a day and my daughter comes in. She's like, what are you doing? And I'm like, well, I'm analyzing log traffic. She's like, that's boring. And I was like, yes, it is.
Maria Varmazis: Yes. Yes, it is.
Dave Bittner: Yeah.
Rob Whetstine: But I will find this anomaly if it kills me. The attacker got in somehow and I will find it.
Maria Varmazis: My pattern matching skills are unmatched.
Rob Whetstine: Yeah.
Dave Bittner: For me, that was, as a teenager, debugging code in Basic on my TRSA.
Maria Varmazis: Oh, boy. Oh, yeah.
Dave Bittner: Like, locked in, like, why is this not working?
Maria Varmazis: Yep.
Rob Whetstine: Yeah. No, you get super obsessed. And I think a lot of people because, especially the younger generation, because of the constant on instant knowledge, super fast, kind of ba-ba-ba-ba-ba, they don't know how to dig in deep.
Maria Varmazis: To do the deep work, yeah.
Dave Bittner: Yeah.
Rob Whetstine: I hired an entry level role recently and I asked very basic questions, like basic troubleshooting stuff. I gave people 24 hours, granted, a very short amount of time to prep, and I interviewed 15 people out of the 700 applications I got in the first 24 hours. Because I opened a true entry level role.
Dave Bittner: Hmm.
Rob Whetstine: Like, literally no experience was required, which is --
Maria Varmazis: A unicorn.
Dave Bittner: Wow. That's unheard of.
Rob Whetstine: A unicorn out of Fortune 500.
Dave Bittner: Wow.
Maria Varmazis: Oh, RIP your inbox.
Rob Whetstine: Yeah. Oh, it was nuts.
Maria Varmazis: Yeah.
Rob Whetstine: So I didn't post it on my social media because God, that would have been bad. So I went with mentees, I went with people who were referrals, and we interviewed 15 people. And 10 of them, right off the bat, didn't even research what the role was, didn't do any sort of deep diving into it.
Maria Varmazis: Wow.
Rob Whetstine: One guy was using AI. I totally busted it. Like, bro, I asked you these questions specifically because I know what the prompt's going to give.
Dave Bittner: Mm.
Rob Whetstine: And the other ones just didn't do any basic troubleshooting, and had never done it in their entire life because they don't need to anymore.
Maria Varmazis: Yeah.
Rob Whetstine: Why do you need to troubleshoot when I can just ask AI?
Maria Varmazis: Yeah. So you got to- so, knowing how to do deep work and tinkering and getting into a flow state --
Rob Whetstine: Tinkering, playing, breaking stuff, and failing. Over and over again. That was my greatest teacher.
Dave Bittner: Right, right. Persistence.
Maria Varmazis: Always.
Dave Bittner: Yeah.
Maria Varmazis: Always. Always.
Rob Whetstine: Yeah.
Dave Bittner: All right. We got to wrap up here. Rob, thank you so much for taking the time for us. This is a true delight.
Rob Whetstine: Of course. Thanks for letting me hang.
Maria Varmazis: This was a lot of fun, yeah.
Dave Bittner: No, I'm really glad we got together here. This was really great. And since I butchered it on the way in, I'm going to let you tell people how to find your podcast. Go for it.
Rob Whetstine: [laughs] Yeah. So I'm all over. You could just search BowTieSecurityGuy, all one word, After Dark is the podcast. I also post a lot of content on LinkedIn. Just search BowTieSecurityGuy, one word, on Google or any search engine. The AI will tell you how fantastic I am. I love how the AI is like, a 20-year security veteran with multiple connections.
Maria Varmazis: Is the information correct?
Rob Whetstine: It is! It is.
Maria Varmazis: Oh, okay. It's all hallucinations [laughs].
Rob Whetstine: I'm okay with it being hallucinations too. But yeah, just --
Dave Bittner: Known for his extraordinary good looks [laughs].
Rob Whetstine: Oh my God. His amazing beard. Yeah, but no, it's really fun. But yeah, please, definitely check it out. Anybody who needs help who's listening, if you're struggling in this job market and you can't find anything, I help people for free. I get that you have a ton of listeners and I'm probably going to rest in piece my inbox. I don't care. I'll make time for you, because there's so many people struggling. And if you're in technology and you are employed and you are not actively helping at least one person a week, you are doing a disservice to our community.
Maria Varmazis: Amen to that.
Dave Bittner: Love it. Love it. Yeah.
Rob Whetstine: So please reach out to me. I don't charge anything for it. I'll do resume reviews. I'll look at your LinkedIn. I'll help you do interview prep if you have an interview. I will make time for you, because this market, we need people who are willing to give time and help people, and it's hard. [ Music ] That is "Hacking Humans", brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to hackinghumans@n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. We're mixed by Elliot Peltzman and Trey Hester. Peter Kilpe is our publisher. I'm Dave Bittner.
Maria Varmazis: And I'm Maria Varmazis.
Rob Whetstine: And Robert Whetstine.
Dave Bittner: Thanks for listening. [ Music ]



