
The fine print of fraud.
Maria Varmazis: Hello, everybody; and welcome to Hacking Humans Podcast, where each week we look behind the social engineering scams, phishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. I am Maria Varmazis. And joining me this week is Joe Carrigan. Hello, Joe.
Joe Carrigan: Hi, Maria.
Maria Varmazis: Hello, hello. And also joining us this week is friend of the show, Michele Kellerman. Hello, Michele.
Michele Kellerman: Hi, Maria. Hi, Joe.
Joe Carrigan: Hi, Michele.
Maria Varmazis: And I should note that our friend Dave Bittner is at RSA at this very moment rubbing elbows with one and only Hugh Jackman. So we'll give him a pass for not being here this week, but we'll hold it against him a little bit because, you know.
Joe Carrigan: I'd blow you guys off for Hugh Jackman as well. Just so you know.
Maria Varmazis: Yeah, yeah. Okay. Well, that's good. All right. Well, Hugh Jackman aside, we do have some interesting stories to share this week. But, first, let us get into our follow-up. And I do have some follow-up for us this week. So this one comes from listener named Bruce, and he wrote this. I volunteer with a local group, Senior Center Tech Connect. And also, Bruce, thank you for doing that because that is a very important service. So thank you. I have been listening to most of your podcasts for a couple of years now, as we are always helping local seniors avoid all the scamming, spamming, phishing, etc. Attacks again. Thank you, Bruce. But I was the target of something I've never seen, and our volunteer cybersecurity expert says it may be part of an email bombing attack in retribution for recent attacks on Iran. Yesterday, I started receiving a huge number, several hundred of obvious spam or scam emails. For a period of maybe an hour of panic, selecting large blocks of these emails and sending them to my Gmail junk folder and sending to trash, I was beginning to think they would never stop. And it looked like Google's filters were not working. But after an hour, I reduced the incoming number to a mere trickle. And, by today, I've only gotten an occasional specious email. Most of them are addressed to my personal Gmail account but with multiple periods between the letters of my address.
Joe Carrigan: I see.
Maria Varmazis: Anyone else? Yeah. Has anyone else experienced this type of activity? Our volunteer cybersecurity expert says the local hospital he contracts with had received an even larger amount. I fear that, if any of our local seniors encountered this, they would freak out. Please keep up the good work. Bruce. Yeah. So what are your thoughts on this? Michele and Joe, what are your thoughts?
Michele Kellerman: Well, a couple things. One, it's really interesting seeing some of the, like, roundabout ways that we're feeling the impact from the war in Iran.
Maria Varmazis: Yeah.
Michele Kellerman: I'm a volunteer first responder, and the attack on Stryker took away our ability to get EKGs in the field. Our medics were severely limited without that, which is very frustrating.
Maria Varmazis: Wow.
Michele Kellerman: One of their -- yeah. Their life back that runs a whole bunch of information and monitors was unavailable, some of the functions. So we were not having a good time about that. But, yeah. I also learned about four email addresses for Gmail. If you add periods in between the email address, you can technically create another email address; but it still routes to your email address.
Maria Varmazis: Yeah.
Michele Kellerman: It doesn't change the name. So there's a lot of ways around some of the filters if you are not careful.
Maria Varmazis: Yeah. I use the periods. And, also, you can add a plus after your name or your -- whatever's in front of the at symbol, you can add plus. And then --
Michele Kellerman: Plus one.
Maria Varmazis: Yeah. Or I do like plus spam or plus the name of the service I've signed up for so I can see who's selling -- who's reselling my name and address --
Michele Kellerman: Yeah.
Maria Varmazis: -- as it gets passed around the internet.
Michele Kellerman: I learned that a couple weeks ago.
Maria Varmazis: Yeah. It can be handy, but it's interesting to see that the this attack was iterating on their email address with the sort of period trick. And I'm wondering, Joe, if you have any thoughts about this type of attack also?
Joe Carrigan: Yeah. My concern would be that this is an email bombing attack that's trying to obfuscate something else. So, typically, when you have an email bombing attack, that there may be somebody else in your email. I don't know how this works off the top of my head.
Maria Varmazis: Yeah.
Joe Carrigan: But the message is or the intent is to lose a real message in a flood of spam.
Maria Varmazis: Yes. Like a DoS attack almost. Yeah.
Joe Carrigan: Yeah.
Maria Varmazis: Yeah.
Joe Carrigan: And Bruce is saying that he was selecting large swaths of his emails and just sending them right to spam. It doesn't sound like -- it sounds to me like Bruce knows what he's doing. So he probably has multifactor authentication on his email, so it's probably not somebody else in his email account. It couldn't be exactly what he says. But, whenever you see this kind of thing, that is the first thing you should do. And there's a note in here. I don't know who added this. Did you add, this, Maria?
Maria Varmazis: I added -- yeah. I added the note about subscription bombing. I was going to follow that up --
Joe Carrigan: Okay.
Maria Varmazis: -- about what I found that MITRE covered, sort of the basics about subscription bombing. But -- so, yeah. I -- we'll include this link in the show notes. This is MITRE's own post about what subscription bombing is and how it works. But, as you said, Joe, it usually -- it's like a DDoS. It obfuscates that there's a legitimate email in the middle of the flood that indicates that actually something has happened to an account that's connected.
Michele Kellerman: The other thing, if you get enough of those and you're irritated, you try and hit unsubscribe; and the unsubscribe link is the malicious link.
Maria Varmazis: Oh, yeah. Good point. Yeah. Good point. Yeah. There's a lot -- this -- what I thought was very interesting was that this can also be used as sort of a forward attack before you get an inevitable phone call that then starts this social engineering against you as a target. So it'll say, Hey. I'm calling from whatever service. And, you know, we think that your account's been compromised. And, of course, they're the ones that have done it. So a lot of the advice that I saw about subscription bombing or email bombing was, essentially, if you are the victim of something like this, just assume that you have been involved in a security incident. Change passwords that are -- you know, for sensitive things. Check for fraudulent transactions, you know, with your credit card or whatnot. But also be especially wary of incoming phone calls. And, as Michele said, don't click any links in those emails, even the unsubscribe links that could be fishy -- yeah, yeah. Absolutely.
Michele Kellerman: Like, fear is a very powerful feeling in this game. So is irritation.
Maria Varmazis: It is.
Michele Kellerman: I want -- you're annoying me. I'm not thinking that, like, you're suspicious. I'm going to think that you're annoying.
Maria Varmazis: Yeah.
Michele Kellerman: It works.
Maria Varmazis: Yeah. I would imagine, for those of us who are inbox zero types, this would be especially annoying. But if you have 20,000 unread emails -- yeah. I was going to say, Joe, you're not. So you're like 20,000 unread emails. What's 500 more? Meanwhile, I'm Miss Inbox Zero, and this would drive me insane.
Michele Kellerman: You couldn't talk to me for the day.
Maria Varmazis: You would be done.
Michele Kellerman: I would just -- I would be ruining the vibe everywhere. You could not talk to me for the day.
Joe Carrigan: I think I had 400 unread emails in my work email inbox.
Maria Varmazis: Right now. Yeah. So you wouldn't even notice.
Michele Kellerman: You get paid to read those emails, Joe.
Joe Carrigan: Yeah. But I'm not saying I don't read them. I don't -- it's not that I don't read them. It's just that they are -- I know what they are. And particularly, meanwhile comes in and it's just like one line and I can read the entire line in that little two line preview in Outlook, I don't open it. I got the information. So it's just sits there.
Maria Varmazis: So [inaudible 00:07:48] don't try this on Joe because it won't work. Apparently Michele and I are great victims for this, so send them our way. I don't know why I'm saying -- I'm going to regret that immensely.
Michele Kellerman: I don't want to come back. I'll have problems now.
Maria Varmazis: You're welcome, Michele. Sorry. Well, on that happy note, why don't we get into our story -- do you have follow-up, Joe?
Joe Carrigan: No, no. In my email right now I have 20,832 emails, 20,000 of which are unread.
Maria Varmazis: Oh, my God. How do you function?
Michele Kellerman: You're an untrustworthy individual.
Joe Carrigan: I don't think that's right.
Maria Varmazis: So now that we finished with our follow-up, Joe, why don't we get into our stories? And I believe you're first today so.
Joe Carrigan: I am first.
Maria Varmazis: You are. Go for it, Joe.
Joe Carrigan: I have a story from The Record, And this is from Alexander Martin. And it is a story about the British government has sanctioning a -- a Chinese cryptocurrency marketplace. It's called -- I'm probably messing this up, but it's Xinbi or Xinbi.
Maria Varmazis: Xinbi.
Joe Carrigan: Xinbi. I'm not -- I'm not good with Chinese pronunciations. I mean, first off, Chinese is a very difficult language for someone who grew up learning a -- an Indo-- European language. It's a completely different family of languages. But that's neither here nor there. The British government has sanctioned Xinbi as a global human rights problem. And the foreign ministry, the Foreign Office officially has designated them as a global human -- under its global human rights sanction regime, which Britain is the first country to do this. I'm assuming that in Britain they mean the UK because that's an entirely different thing than Britain. Britain's just the island that contains England, Ireland, and Scotland, Scotland and Wales. And --
Maria Varmazis: I'm only chuckling because, like, yes; you are correct. But I think that level of pedantry is just, okay. But understood. I've -- no. I know.
Joe Carrigan: My super -- my alter ego superhero, Captain Pedantic.
Maria Varmazis: Oh, no. Oh, God. Oh, my God. Let's keep going, Joe. Let's keep going.
Joe Carrigan: In the government's official designation, Xinbi was described as having enabled and profited from the operation of scam centers across Southeast Asia.
Maria Varmazis: Ah. Okay.
Joe Carrigan: We've been talking about that a lot.
Maria Varmazis: Yeah.
Joe Carrigan: And there is a very, very British quote in here from the MP who -- who was talking about this. And he says, Our sanctions today send a clear message. We will not allow British people to become victims of these dreadful scams or tolerate the awful human rights abuses perpetrated in these scam centers. And this is Stephen Doughty. He's the government's minister in Europe, North America, and overseas territories. We must keep the pressure up on dirty money and those who benefit from it.
Maria Varmazis: Dirty money. Yeah.
Joe Carrigan: Yeah. This is not how I would characterize it with words as kind and polite as this, but the Brits are very good at that.
Maria Varmazis: Because we're dirty Americans. That's why.
Joe Carrigan: That's right. The reason they did this is because there's a company out there called Chainalysis, or Chain Analysis that does cryptocurrency tracking. And they were able to demonstrate that this platform has processed 19.9 -- 20 -- let's just say $20 billion in transactions between 2021 and 2025.
Maria Varmazis: Wow. Okay.
Joe Carrigan: So that's -- you know, assuming that this is a growing thing, right, that they didn't -- you can't just divide that number across -- evenly across these four years. You know, it could be as much as, like, $8 billion last year. Or even if it isn't, let's just say $5 billion in processing of these -- they've laundered five billions of -- $5 billion of money a year for the last four years. Huge.
Maria Varmazis: Yeah.
Michele Kellerman: Yeah. But that's a big thing that is -- this kind of scam is shedding a light on is how much dirty money there is because every single time I see one of these stories, it's like, this platform does 20 billion; and this platform does 47 billion, and this platform does 1 trillion. And this platform is evil.
Joe Carrigan: Right.
Michele Kellerman: We can't even calculate the number. As a [inaudible 00:12:24] money coming from --
Joe Carrigan: From scam victims.
Michele Kellerman: I don't think they're [inaudible 00:12:27] on the planet. But, yet, yeah. So you just -- it really shows how much there's so much more to everything than --
Maria Varmazis: And that's just what we know about.
Joe Carrigan: Right.
Maria Varmazis: I mean, that's the crazy thing is that this -- there's got to be -- it's -- this is probably just tip of the iceberg, which is a staggering amount of money even what we do know about. It's --
Joe Carrigan: Right.
Maria Varmazis: It's scary to think about.
Michele Kellerman: That's a country's GDP. What are you talking about.
Joe Carrigan: Yeah. It is.
Maria Varmazis: Yeah. Several countries' GDPs. Yeah.
Michele Kellerman: Yeah. That's -- like, I'm having a hard time with the scope of just how much dirty money there is that we didn't know about but now can at least they put eyes on it.
Maria Varmazis: Yeah.
Joe Carrigan: Last week, I covered an Interpol story where they said it was like half a trillion dollars in global fraud.
Maria Varmazis: Yeah.
Joe Carrigan: And, again, that's just what we know about. Half a trillion dollars. It's so much money.
Michele Kellerman: Crazy.
Maria Varmazis: That is crazy.
Joe Carrigan: The designation that the UK has put on Xinbi highlights the support for their #8 Park, which is a -- Chainalysis says this is an industrial scale scam center compound in Cambodia. So this is one of those ones where they have the human trafficking, bringing people in, keeping them against their will; and -- and then having them scam people in their home country. So there's also a company called Legend Innovations, which is the operator of 8 Park. And two officials that they've named, Tet Lee and Hu -- I'm going to mess this up -- Xiaowei maybe, who are linked to the Prince Group, which is a conglomerate behind many such compounds. So this is like an industrial scale scam operation. So what the UK has done as part of this -- part of this sanction is they've seized a bunch of property from these organizations in the UK, which is pretty much all they can do in terms of -- in terms of -- in terms of -- making --
Maria Varmazis: Jurisdiction, right? Yeah. Yeah.
Joe Carrigan: The value, the biggest value of an asset, they seized an office building worth like $100 million or 100 million pounds, $122 million. And I don't know if that's in this story or any other story I read about this, but it's such a huge thing. And there's a huge -- another problem here, as well, in that, even if you sanction Xinbi, there's nothing that stops these operators of these scam centers from hosting their own wallets, making it --
Maria Varmazis: Yeah. I mean, this is just the nature of crypto at a certain point.
Joe Carrigan: Right.
Maria Varmazis: I mean, it's great for -- listen. I know it has a lot of great legitimate uses, but it also has a lot of really shady uses. And this is sort of Exhibit A.
Joe Carrigan: Absolutely it is. The violence of nature unregulated.
Maria Varmazis: Yep.
Joe Carrigan: And impossible to fully regulate. You can regulate exchanges, and that's just about what every industrialized country has done on the planet. And China, to their credit, has also been cracking down on this because their citizens are some of the most targeted by these scams.
Maria Varmazis: Yes. Yep.
Joe Carrigan: Because Cambodia is pretty close to China. So it's pretty easy to lure Chinese citizens to Cambodia and then just keep them there and have them phone back into China and scam Chinese people out of -- out of millions of dollars. So China doesn't have --
Michele Kellerman: Because China restricts money you can send out of the country, right, for their citizens?
Joe Carrigan: I don't know if -- if -- if it's that or if -- they might do that. I'm not -- I'm not familiar with China's economic policy.
Michele Kellerman: They do. There's -- yeah. There's a limit to how much Chinese citizens can -- can invest elsewhere out of the country. That's why there have been some, like, underground crypto schemes. I'm fairly certain.
Joe Carrigan: Interesting. So one of the things -- the last thing in this article that I wanted to point out was this just -- this -- this designation -- I'll just read from the article. This designation reflects a broader shift towards targeting the backbone of the scam ecosystem, including payment channels and laundering networks, rather than only individual perpetrators. So I don't know how easy that's going to be. This is -- this is like I've -- like we've already talked about that this is going to be a much harder problem to solve. I don't know how you stop this. I don't have any suggestions. This is something that is just an awful situation all around, and everybody just has to be aware of it. One of the reasons we do this podcast is because we want to make sure that these guys don't fool people. And, if they listen to this podcast, I think people are less likely to get fooled by these things.
Maria Varmazis: Amen. Well, it's a great, great story, Joe. So thank you for sharing that with us today. All right. Yeah.
Michele Kellerman: China imposes strict capital controls, equivalent of 50,000 US dollars per person per year can leave China. They do not want their money leaving their country and leaving their economy.
Maria Varmazis: Interesting.
Michele Kellerman: So there's a ton of money laundering going out of China, not for crime, just for rich people wanting to diversify and not be limited to what China is doing.
Maria Varmazis: Yeah. Makes a lot of sense. I can -- we've seen how that's shown up all over the world.
Joe Carrigan: Right.
Maria Varmazis: So, yeah. All right. With that note, Michele, it's over to you for your story.
Michele Kellerman: Yeah. So this one was kind of interesting. It's not based in technical crime, but this is how all of your identity information can be used to steal money, and not even just steal your money but still mess you up financially. So 11 people have been arrested by the FBI in LA for a house stealing operation since 2022, that's been going on since 2022. So --
Maria Varmazis: House stealing?
Michele Kellerman: Yes. House stealing. So apparently --
Maria Varmazis: Picking up a house and walking away with it.
Joe Carrigan: In a big sack with a [inaudible 00:18:26] and a striped shirt.
Michele Kellerman: Yep. I'm getting, like, the cartoon criminal character, yeah, running away. Yeah. So this is targeting specifically elderly homeowners above the age of 70 who have fully paid off homes. And then bad guys will try and take out loans against those fully paid off mortgages. The house is collateral to get access to large loans from banks, and then they steal that money; and then these people's homes are the collateral.
Maria Varmazis: Oh, my God. Oh, wow.
Michele Kellerman: Unreal. Like, there's no safe corner.
Joe Carrigan: Huh.
Michele Kellerman: Yeah.
Maria Varmazis: So stealing -- so, basically, mortgaging out a house from underneath somebody.
Michele Kellerman: Uh-huh. You can get -- you can get large loans, and house gets put up as collateral. The -- there is a 15-count federal case for conspiracy to commit wire fraud, wire fraud, identity theft, and money laundering; or this would be aggravated identity theft probably.
Joe Carrigan: I was about to say this would be aggravated identity theft, Michelle.
Michele Kellerman: It's in conjunction with another crime. So they have -- the ring here, the, like, crime ring has sought $17 million in banks since 2022. They have successfully gotten $6 million.
Maria Varmazis: Dang.
Joe Carrigan: Wow.
Michele Kellerman: And all these high value neighborhoods in LA, the attackers created fake IDs and email addresses with the legitimate owners' names, all because houses are public record. You can find out whose home is paid off. And, with all this information, that's -- your identity being stolen, they can theoretically probably fairly easily create a fake identity and get a mortgage. They were more than -- they were more successful than I would like. It just -- I'm surprised that the banks didn't do more due diligence. Yeah.
Maria Varmazis: I was going to say because this is -- this is fully on the banks to do their work. There's nothing the average person can do to stop something like this because they won't know it's happening, right?
Michele Kellerman: So you can get title insurance. A lot of people get title insurance right when you get the house. So that way, if you buy a house where X -- where you didn't realize it, but there's this other claim to the home, there is some fraud, there's a lien, whatever that you don't know at the time of purchase, you can purchase title insurance. I don't know if you can purchase title insurance for extended periods of time, but I would imagine so because a Millman study for the American Land Title Association found that fraud and forgery claims on mortgage refinances climb to more than 40% of total title insurer losses. It's a significant problem.
Joe Carrigan: Wow. Huh.
Maria Varmazis: My goodness. I was -- for some reason I thought title insurance was mandatory. I don't know why. Maybe that just depends on the loan you're getting.
Joe Carrigan: Yeah.
Michele Kellerman: Some -- there's at least some level, like a small one; but not -- and it's usually only for like a year or two.
Joe Carrigan: Yeah. It's for at least the past, right? It covers -- it covers past transactions. So, if somebody comes up on -- comes up to you after you buy the house and go, Hey. That's really my house, you're covered.
Michele Kellerman: Yes.
Joe Carrigan: But here's my question about this. And I think about -- I think about me being in this situation and somebody saying, Hey. We're foreclosing on your house because you took a loan out and me just saying no and calling an attorney and saying -- issuing a cease and desist letter immediately. And, you know, it also probably opening up a civil lawsuit for this on the bank because, as you both have said, they haven't done their due diligence here. They've -- they've been defunded of their -- of their money, the loan money. But that is -- from my perspective, that is not my problem. You guys -- you guys let somebody take out a fraudulent loan, you guys let them fraudulently use my address as collateral, go -- go figure this out and stop bothering me.
Michele Kellerman: Yeah. You're going to give -- you're going to give a house loan for -- with a fake ID and email address? 20-year-olds trying to sneak into a bar can do that. Where are you -- what are you doing?
Joe Carrigan: Right.
Michele Kellerman: Are you -- what are -- what are you -- you seriously going to tell me that you would get outsmarted by a kid trying to lie to his parents better? What are you --
Joe Carrigan: Right.
Michele Kellerman: What is going on.
Maria Varmazis: Yeah. Wow. I wonder if certain types of financial institutions are more, yeah, like smaller ones that maybe aren't as well-equipped to deal with this, if they're more at risk for getting involved in this kind of scam that, you know, if they don't have people that to -- employed to do that due diligence or do it well. That's --
Michele Kellerman: Yeah. I'm not sure. And you're -- and we're starting to see, even when I was poking around about this story, there are starting to be what looks like some legislative fixes being proposed. So Maine is currently proposing a statute that would make it so that it's, like, victims of fraud would get a break in their taxes for that. So right now, if you get a whole bunch of money stolen but, like, that's still somehow taxable, so you still have to come up with the taxes, to add insult to injury.
Maria Varmazis: Oh, my God.
Michele Kellerman: And Maine has introduced -- yeah. Like, you still -- like, the government's like, hey. That's not a problem. You messed up. Like, that's not statutorily required. Maine just introduced legislation to make it so that scam victims do not need to pay taxes on the money that they lost. So we're starting to see a little --
Maria Varmazis: And Maine is also one of the oldest states in the -- that they have, like, the per capita of some of the oldest -- if I remember incorrectly, like, they've got a lot of old people in Maine.
Michele Kellerman: They do. So that makes sense.
Maria Varmazis: Yeah.
Michele Kellerman: And this came on the heels of the National Council on Aging just put out new guidance on top scans targeting -- top scams targeting older adults. This was not on there, but it kind of is covered under the financial services scam. But definitely like, hey. Just because your house is paid off doesn't mean you have to stop paying attention to it.
Maria Varmazis: Yeah.
Joe Carrigan: Right.
Maria Varmazis: Yeah. Would there be any sign for the average homeowner that maybe they've been caught up in something like this? Is there something they should be looking for?
Michele Kellerman: Not that I can tell because I would imagine that it would show up on your credit report. But maybe they could somehow find a way to not use your -- because it's just the house is collateral.
Maria Varmazis: Yeah.
Michele Kellerman: And, like, if you have a -- if you have a title saying that you have ownership of that, it may not -- there may be a way to, like, snake around, like, the credit reporting side of things.
Maria Varmazis: I was going to say because you could always just put a freeze on your credit. If you've paid off your house, I'm going to bet you probably are, like, I don't really need credit anymore. You could just put a freeze on your credit.
Michele Kellerman: Yeah. My [inaudible 00:24:57] mother does that. She's just like, nobody's touching my stuff.
Maria Varmazis: Yeah. I just -- I don't need it anymore, so freeze it. Yeah.
Michele Kellerman: I don't know how to get a loan anymore.
Maria Varmazis: Yeah, yeah.
Michele Kellerman: Good for you. I love that.
Maria Varmazis: Yeah. It's -- it won't work for everybody. But, if it can work for you, it may not be a bad idea. So, yeah.
Michele Kellerman: Yeah.
Maria Varmazis: That's a -- that's a great one, Michele. I have a few people in my life I need to talk to about this one. So thank you. I've got homework now, but that's a great -- it's good to have stuff to talk to people about this. So thank you. It's a great story.
Michele Kellerman: Yeah.
Maria Varmazis: On that note, why don't we take a quick break; and we'll be right back. All right. So we are back, and now I'm going to be the one telling a story now. This one is kind of a -- it made me chuckle, but it's a legitimate -- it's a legitimate thing. It's a CAPTCHA scam. And it reminded me a lot of -- when I used to play a lot of online gaming, we used to play this trick on people who were new to -- like, when I played World of Warcraft, for example, ages of -- ages and ages ago. You get people who are new to the game who are having problems. And they'd go, How do I get out of this issue? And, of course, the thing we would tell them was, Well, if you're on a Windows machine, make sure to hit Alt F4. And of course you would immediately see that they would log out of the game. And it was ha, ha, ha, ha, ha. So this -- his CAPTCHA scam has been around for at least a year, and it's a little bit similar to this. And it's not the first scam to do this. But the idea is that there's a fake Cloudflare page that sometimes people will see that will instruct victims to complete a CAPTCHA to go -- to proceed to the website they're trying to get to. And the CAPTCHA is the I'm not a robot checkbox, right? But, instead of hitting that checkbox or doing the weird, like, fill in the puzzle or find the fire hydrant, it'll say, To make sure that we know that you're human, I need you to press a series of keys. And it will be something like -- please don't do this. It'll be something like, Windows key plus R and then CTRL V and then Enter. Oh, great. Thanks for doing that. You can now go on to your website. But, of course, what's happening is that, when you are doing those key presses, that opens up a console window in the background, and then the CTRL V is pasting in a PowerShell script. And you are essentially downloading to your machine an info stealer. And the -- the specific one that's going around right now is something -- I think we've talked about this in the show before. It's an info stealer known as SteelC. And this one is an -- is an info stealer. It can also -- it can steal a bunch of gaming info, like your Steam account, as well as crypto wallet data, if you've got it. And it's pretty -- it's kind of gnarly. So it's -- this one is -- it made me chuckle because it reminded me of, like, back in the day when we would do stuff, like, to mess with other gamers. But, if you're just hitting random keys because a website tells you to, please don't do that. Just please, please don't do it. So, if your -- CAPTCHAs should never be having you hit random keys. But it's getting a little hard to know because sometimes you get a test on a CAPTCHA. You're going, is this legit or not? Like, some of the ones where it's like, complete the puzzle or find the horse or whatever, it's just like, I can't believe this is a real thing. So maybe the CAPTCHAs need to calm down a little. But, certainly --
Michele Kellerman: There's so many -- like, this is one of those things where, like, this would not have worked even like three years ago. Like, I feel like the change in internet from now from three years ago versus the previous three years was significantly greater, like a much straighter -- greater standard deviation.
Maria Varmazis: That's for sure.
Michele Kellerman: This would not have worked three years ago because you would like -- to be like, I'm not doing all that. Nothing ever asked me to do all that.
Maria Varmazis: Yeah.
Michele Kellerman: But now with all the crazy, like, multifactor and all the different, like, technologies and all the ways to verify your identity of, you know, like do -- do a fun dance in front of the camera so we know you're real.
Maria Varmazis: Yes. Yes.
Michele Kellerman: It's like you -- you don't have -- like, the threshold is so much higher for, like, that's weird. You shouldn't be asking me to do that many things.
Joe Carrigan: I have never been asked to do a fun dance in front of a camera.
Maria Varmazis: It's going to happen.
Michele Kellerman: You know what, Joe? Today's the day.
Joe Carrigan: I don't have my camera hooked up so.
Michele Kellerman: Get up.
Joe Carrigan: All right. Let me get my camera hooked up, Michele.
Michele Kellerman: This is one of those things where it's just like this would not have worked even just a couple years ago.
Maria Varmazis: I know. It sounded ridiculous when I read -- yeah. It sounded ridiculous when I read it. I'm going, who would do that? But, actually, you're right. I could absolutely see people going, I don't know. The one -- the CAPTCHAs are weird now. And we have to do all sorts of stuff to make sure we're not AI.
Michele Kellerman: Yeah.
Maria Varmazis: So maybe hitting random keys is the way we prove that we're human.
Michele Kellerman: There's some new weird stuff every other day that I'm seeing. Yeah.
Maria Varmazis: Yeah, yeah. Absolutely. And this info stealer is going after a whole bunch of stuff, and it's going to be -- it's pretty nasty. And if you download it directly by doing all the key presses that the -- this not legitimate CAPTCHA say, then it would not be good to have on your machines. So, yeah.
Michele Kellerman: And, again, you're already irritated that you're being asked to do another thing. You're not going to go and then look. You just want the irritation to be over.
Maria Varmazis: Yeah. Irritation as a vector is a really good -- you're definitely onto something there. I really think so.
Michele Kellerman: I remember seeing something, and I was like, why are irritating characters in books so much more hated than the bad guys? And it's like because their crimes are fictitious. My irritation is real. I'm feeling.
Maria Varmazis: I've not been harmed, but I'm annoyed.
Michele Kellerman: Yeah.
Maria Varmazis: That's right. Oh, man. You're onto something there, genuinely, so. All right. Well, that was my story. So why don't we move on now to the Catch of the Day. [ SOUNDBITE OF REELING IN FISHING LINE ] And, Joe, I think you found today's catch. So tell us about it.
Joe Carrigan: I did. It's from the phishing subreddit, and it's an email that came in -- Reddit slash r slash phishing for those of you can't figure that out, like me. I have a -- I would have a hard time.
Michele Kellerman: It's r slash phishing, Reddit slash r slash phishing is redundant Reddits. But thank you.
Joe Carrigan: Okay.
Maria Varmazis: Https colon slash slash www -- okay. Sorry.
Michele Kellerman: Dr. Pedantic over here brought it up.
Joe Carrigan: Yes. So an email that came into somebody, and it says -- I'll just read it. Should I read this, or do you want to read it, Maria?
Maria Varmazis: I would like you to read it, Joe.
Joe Carrigan: Okay. Those letters across the top. By the way, this email is all centered. And it says, Dear -- which, to me, comes off --
Maria Varmazis: That's your beef with it. That's your beef is that it's centered.
Joe Carrigan: It's pretending to be -- it's pretending to be a person who needs help with their Medicare account. And, like, if you send an email to some government organization, are you going to center everything and put a big -- well, okay. Let me just read this.
Maria Varmazis: Just read it.
Joe Carrigan: Okay. Mold on this call. Stop. Dear Medicare representative comma I am writing regarding my access to my online government services accounts. I use the identity verification services provided through ID.me and login.gov to access Medicare services on medicare.gov. And then there's a big login.gov button. I would like confirmation that my identity verification and login access are active and properly connected to my Medicare account. If additional documentation or verification is required comma; and that's the end of the email.
Maria Varmazis: That's the -- and then copyright 2026. Thank you for your time and assistance.
Joe Carrigan: Right.
Michele Kellerman: Who's doing the --
Maria Varmazis: Who is this phishing?
Joe Carrigan: This is a --
Maria Varmazis: A Medicare representative?
Joe Carrigan: Well, the person who received it was not a Medicare representative. They said so in the comments. But it looks like this is just a phishing kit that has been used in a horrible campaign by some tyro --
Maria Varmazis: Newb. Yeah. >> Joe Carrigan -- who just doesn't know how any of this stuff works. And the link goes to -- let me -- the login link, that person hovered over the login link and took a screenshot with it. It's enable dash satellite dash metals dash Smith trycloudflare.com. So trycloudflare.com is probably a malicious domain. Sounds legitimate to me, Joe. I don't know what the problem is.
Michele Kellerman: I really just, like, I'm just, one, disappointed. Two, I feel disrespected. If you're going to try and steal my stuff, like, put in some effort.
Maria Varmazis: Baseline effort. Yeah.
Michele Kellerman: This is, like, AI slop type stuff.
Joe Carrigan: Yeah. Yeah. It is.
Michele Kellerman: It's probably --
Maria Varmazis: I love also that the call to action button literally just says login.gov. That's -- it just -- it doesn't say click here or what. It just says login.gov.
Joe Carrigan: Yeah. It's like a login link.
Maria Varmazis: I mean, it's like a big button in the middle. It's just bizarre, bizarre, bizarre. Like, they don't know how the internet works.
Joe Carrigan: Right. I mean, it looks like --
Michele Kellerman: It does look pretty specific, like, targeted thing. How many people are Medicare representatives? That feels like that you're unnecessarily narrowing your field.
Joe Carrigan: Right? You -- I would hope that these people, these phishers, have a -- have a list of Medicare addresses, email addresses. Maybe they're just trying this out to see how it works. I don't know.
Michele Kellerman: Yeah. It just feels lazy.
Joe Carrigan: It is. Yeah.
Maria Varmazis: It is lazy, lazy. It's messy lazy. Yeah. Love it. But that's a great catch.
Michele Kellerman: Go start -- go start a lemonade stand. Do something.
Maria Varmazis: Do something productive with your life.
Joe Carrigan: You can make a lot more money scamming people.
Maria Varmazis: Sadly. Well, that's why -- that's why we're on the show, aren't we?
Joe Carrigan: Yep.
Maria Varmazis: That's why we're here. Well, thanks for that, Joe. Thanks for that awesome Catch of the Day. Appreciate it. All right. And, on that note, let's take a quick ad break; and we'll be right back. All right. We're back. And, before we close out, Michele, you have something that you wanted to share with everybody. Go for it.
Michele Kellerman: Yeah. Today starts the kickoff for a fundraiser for Blood Cancer United, formerly the Leukemia & Lymphoma Society. My best friend was nominated as a visionary of the year for Boston in honor of her daughter who was -- who was diagnosed with leukemia as an infant. She was nine months old. She is since in remission. She is doing great.
Maria Varmazis: That's wonderful.
Michele Kellerman: And she's been very active in the cancer community, especially for childhood cancer. She was very reliant on community support, so we wanted to really do our best to give back. So I'm on her team for Visionaries of the Year, and we are starting a 10-week campaign. It kicks off today, and anybody can donate. Every dollar counts. More than 70% of each dollar goes to actual research and support resources for the families who are affected. And anything that anybody's willing to give is so appreciated.
Maria Varmazis: Yeah, Michele. Well, we'll put the link in the show notes for our listeners so they can -- they can check it out.
Michele Kellerman: Yeah.
Maria Varmazis: Well, thanks for that, Michele. Appreciate it.
Michele Kellerman: Thank you.
Maria Varmazis: And, well, yeah. And, on that note, thanks for listening. And that's Hacking Humans brought to you by N2K CyberWire. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes, or send an email to hackinghumans@n2k.com. We're privileged that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. We're mixed by Elliott Peltzman and Tr Hester. Peter Kilpe is our publisher. And I'm Maria Varmazis.
Joe Carrigan: I'm Joe Carrigan.
Michele Kellerman: And I'm Michele Kellerman.
Maria Varmazis: Thank you for listening.



