
Who is winning the scam game?
Dave Bittner: Hello, everyone, and welcome to "Hacking Humans," where each week, we look behind the social engineering scams, phishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. I'm Dave Bittner, and joining me is Joe Carrigan. Hey, Joe.
Joe Carrigan: Hi, Dave.
Dave Bittner: And our N2K colleague, Maria Virmazis, Maria.
Maria Varmazis: Hi, Dave, and hi, Joe.
Dave Bittner: We've got some good stories to share this week and no follow-up this week, so we're going to jump right into our story.
Joe Carrigan: Shocking!
Dave Bittner: I know. I know.
Maria Varmazis: Not a single chicken email.
Joe Carrigan: I can fill the gap with some chicken updates.
Maria Varmazis: Oh, boy.
Joe Carrigan: Since Sue last week was, like, "Keep it up with the chicken talk," I finally finished the roof of my chicken run.
Dave Bittner: Oh, good.
Joe Carrigan: So now I have a complete domicile for my chickens, and my rooster attacked my wife.
Dave Bittner: What?
Joe Carrigan: He did. Her back was turned, and he jumped up and pecked her twice or three times in the leg, and she has a bruise, you would not believe, on her leg from a chicken. I said, you lost a fight with a chicken.
Dave Bittner: I would say if my rooster had attacked my wife, we'd be having chicken fricassee for dinner.
Joe Carrigan: We're very close, Dave, very close.
Maria Varmazis: Yep.
Joe Carrigan: The only thing keeping this rooster alive right now is the fact that, with his hens, he's a pretty good rooster. He exhibits exemplary rooster behavior around other chickens, around his hens, not so much around people.
Dave Bittner: See, I think what you need to do is first bring in the replacement rooster, and then make an example of the first rooster, so that the second rooster knows what's at stake.
Joe Carrigan: Yeah, make the first rooster, or the new rooster, watch.
Dave Bittner: Yeah, exactly.
Joe Carrigan: Here, watch this.
Dave Bittner: Yeah, this could be you. I'm just telling you. This is a warning.
Joe Carrigan: Don't ever forget it.
Dave Bittner: That's right.
Joe Carrigan: I know your brain only weighs 3 grams, but put this in one of those grams.
Dave Bittner: Yeah. Yeah. [ Music ] All right. Well, let's get to our stories here. Joe, you have the honors this week. What have you got for us?
Joe Carrigan: I do. I've got two stories, because both of mine are pretty short, but I'm going to start with a news story that goes pretty much around the world. Actually, it only goes from India to the United States, but then it jumps all around the United States. This is from the India Times, or Times of India, rather. Or I guess it's actually both of them, because that's the domain name, timesofindia.indiatimes.com, weird. Anyway, the headline is, "Indian in New Jersey on Work Visa Arrested in Gold Scam," nabbed when he was going to collect $800,000 in gold.
Dave Bittner: Wow.
Joe Carrigan: The guy is -- his name is Nigan Bhatt, and he is here in the US on a work visa. Apparently, he lives in New Jersey, but -- I mean, this goes all over the United States. Well, not really all over, but it goes from New Jersey down to Texas, where we were talking about the gold bust of the jewelry stores that were owned down there.
Dave Bittner: Yeah. J
Joe Carrigan: We talked about this. They were the actual endpoint of all the gold. These people would call -- you know, scammers call in to somebody, and in this case, they said, hey, your bank account's frozen. In order to unlock it, your bank account's Social Security benefits will no longer be accessible. In order for you to unlock it, you need to give us all your money in gold for safekeeping. They give you some lie about your bank account being involved in fraud or something like that, and what has happened is people have emptied out their bank accounts, gone and purchased physical gold, and they hand this to these scammers, who then would take it to the jewelry stores, who would then convert it into jewelry and sell it, which is how this scam works and where the payout comes in. What happened in this case was there were detectives in Collin County, Texas, which is where we were talking about with the jewelry store busts, so the Collin County, Texas, sheriffs got word that Bhatt was going to be picking up the gold in Tangipahoa Parish, which you can tell by the name "Parish," is in Louisiana. They called the sheriff's office over there, and on April 7th, instead of picking up gold, Bhatt got arrested, which is good, because I guess he drove from New Jersey down to Louisiana to pick up the gold.
Dave Bittner: Yeah, that's a worthwhile trip.
Joe Carrigan: Absolutely, for almost a million dollars in gold.
Maria Varmazis: I think I'd manage that, yeah.
Dave Bittner: So let me ask you this, I just did a little asking of our good friend, Mr. GPT, because I was curious what $800,000 worth of gold weighs. In my mind, for no particular reason, I pictured kind of like a Dungeons & Dragons dragon sitting on a pile of gold.
Joe Carrigan: Right.
Maria Varmazis: A little horde.
Dave Bittner: Right.
Joe Carrigan: So what's the price of gold right now, like, 4,000 an ounce?
Dave Bittner: Well, before we dig into the actual numbers, just a gut feeling, do you think $800,000 is a lot of gold, or do you think $800,000 is not a lot of gold?
Joe Carrigan: I think that's probably enough gold, or a little enough amount of gold that you can carry around on your person.
Dave Bittner: Okay, Maria?
Maria Varmazis: I'd say it's around $800,000 worth of gold. [ Laughter ]
Dave Bittner: What object do you think -- thank you, smarty pants. What object do you think it would be comparable in size to?
Maria Varmazis: Smaller than a breadbox.
Joe Carrigan: Okay. Hold on. Let me think here, and maybe I'm totally off base here, because I don't know what the price of gold is right now.
Dave Bittner: Currently, between $4,800 and $5,100 per troy ounce.
Joe Carrigan: Around $5,000 a troy ounce --
Maria Varmazis: What the heck is a troy ounce? We will use anything but the metric system. What is a troy ounce? [ Laughter ]
Joe Carrigan: It's from the Trojans.
Dave Bittner: Get Troy on the phone. Ask him.
Maria Varmazis: What is that?
Joe Carrigan: I worked with a guy named Troy. Next time I see him, I'm going to say, hey, you know, I've been meaning to ask somebody --
Maria Varmazis: Ask him about his ounces.
Joe Carrigan: Yeah, tell me about your ounces.
Dave Bittner: Tell me about your gold ounces, yeah.
Joe Carrigan: Right. Let's see, that's $800,000, and that means that there's 5,000, so that's like 160 troy ounces, which would probably be around what?
Dave Bittner: I'll give you the answer: Bowling ball, about the size of a bowling ball, yep.
Joe Carrigan: Okay.
Maria Varmazis: Okay.
Dave Bittner: Now, I don't know about you, but I think it'd be pretty cool to have a solid gold bowling ball. [ Laughter ]
Joe Carrigan: Here comes old moneybags Bittner again.
Dave Bittner: Exactly, a solid gold bowling ball in a silk bag, here he comes.
Joe Carrigan: And he's going to knock all the pins down.
Maria Varmazis: Weirdly, the machine didn't give the ball back. That was odd. After he got that straight, it just disappeared.
Dave Bittner: There's a big crashing sound at the end of the -- I cut a groove down the center of the lane because -- yeah, that's interesting. I wonder if you had a -- because, you know, bowling balls are dense --
Joe Carrigan: Yeah.
Dave Bittner: -- so I wonder if you had a solid gold bowling ball next to a regular bowling ball, and you went to pick up the solid gold bowling ball, would you pull a muscle?
Joe Carrigan: Probably.
Dave Bittner: Probably.
Joe Carrigan: I mean, even if it was just steel, you'd probably pull a muscle, right?
Dave Bittner: Yeah, that's true.
Joe Carrigan: Well, maybe not because kettle bells. I mean --
Dave Bittner: Yeah, that's pretty heavy.
Joe Carrigan: Yeah.
Dave Bittner: Bowling ball, yeah.
Joe Carrigan: Yeah, bowling ball the size of gold.
Dave Bittner: I sent us down a little rat hole there.
Joe Carrigan: Okay. That's fine.
Dave Bittner: So what's next, Joe?
Joe Carrigan: We do that all the time. Next is, actually, from Infosecurity Magazine. This is coming out of Google's Threat Intelligence Group, and they are warning of a new threat group that is targeting BPOs. Does anybody know what a BPO is?
Dave Bittner: I'm not falling for that again. [ Laughter ]
Joe Carrigan: It is a business process outsourcer.
Dave Bittner: Okay. Sure. Sure. Sure, it is.
Joe Carrigan: What a business process outsourcer is, is, obviously, you have some atomic business process that you can just outsource to somebody.
Dave Bittner: Yeah.
Joe Carrigan: I remember the first time I saw this was I went to see a neurologist because of my raging case of Attention Deficit Disorder. He was talking into his computer, and this was like back in the early 2000s, and I said, what are you doing? He goes, "I just make these sound files. They go to some offshore site. They transcribe everything and put it in your notes. It'll be there by tomorrow. I'm like, oh, okay. At the time I was like, oh, okay, but now I'd be like, hey, wait a minute. Where does that data go, right, because all this information that you're using -- that they're using in this business process is all company sensitive business information.
Dave Bittner: Right.
Joe Carrigan: We've seen attackers do this a lot, here they go to an adjacent company and they come into your company via some business process provider that you use.
Dave Bittner: Yeah, your supply chain.
Joe Carrigan: Right. They attack you. I don't know if I'd call it a supply chain attack, but maybe I guess service supply chain. Yeah, you could call it service supply chain, right? They're using a campaign that relies on social engineering and live chat features to send employees to spoof Okta login pages. Of course, they're all fake. They're using phishing kits to bypass standard multifactor authentication stuff. I'm not really sure how they're doing that aside from maybe if it's some kind of code based multifactor authentication like with an RSA token or a soft token on your phone, or perhaps a text message is sent to your phone. All of those are very vulnerable to these kind of attacks. They can just be used as pass throughs if you have an advanced enough phishing kit that will get you access to a system, so I think it's time to, you know, increase that distance of security level between all of those other forms of multifactor authentication and the hardware form of multifactor authentication. Do you understand what I'm saying?
Dave Bittner: Go on.
Joe Carrigan: You look like you're a little confused, Dave. I rank multifactor authentication in -- for the least secure multifactor authentication is a text message that's sent to your phone.
Dave Bittner: Yeah.
Joe Carrigan: That's not secure because that message may not be encrypted, although generally now they are, but actually, I don't think any of the ones that I receive actually are. They're sent in plain text, so somebody could intercept it. Somebody could also SIM jack your phone and then have access to all your codes for login.
Dave Bittner: Right.
Joe Carrigan: The next one is the soft token and the hard token, which are, essentially, pseudo random number generators that will, based on the time, give you a time-based password that lets you access it. Now, unless you have the seed, you can't really predict what the next number is going to be.
Dave Bittner: Yeah.
Joe Carrigan: But all of those forms of multifactor authentication are based on entering a code, which can be socially engineered out of somebody.
Dave Bittner: Right.
Joe Carrigan: Then you go up the next level to the hardware-based authentication, which is, essentially, certificate-based authentication, which has to do with a challenge response and relies on cryptographic primitives we believe are secure. That is much more secure because, let's go with the FIDO Alliance and their model.
Dave Bittner: Like YubiKeys.
Joe Carrigan: Like YubiKeys, right, YubiKeys, Google Titans, and there's a bunch of different ones. That generates a private key based on the website or the server name that you're getting the request from, so if you don't enroll with that server name, the system will not work. If you're getting phished, you're not going to be going to the server that you're enrolled with. You're going to be going to some other server. You're going to derive a completely different private key, which means even if they have your public key, it won't work.
Dave Bittner: Well, I mean, it seems to me at its basic, one of the advantages of a hardware key is that the code itself does not need to pass through a human being --
Joe Carrigan: Correct.
Dave Bittner: -- so that human being cannot be phished.
Joe Carrigan: Cannot -- right, cannot be phished, and I don't think we're aware of any vulnerabilities in the FIDO protocol. So --
Dave Bittner: No, I mean, I guess the problem or the vulnerability there is that once you have a token on your browser, say, that once you authenticated once with it, someone can steal that token --
Joe Carrigan: They can steal the token --
Dave Bittner: -- and use that.
Joe Carrigan: -- and, yeah, use that. That's what we see a lot of, particularly with Discord hijacking, because as you know well, Dave, once you lose your multifactor authentication for Discord, you can't get in.
Dave Bittner: Yeah.
Maria Varmazis: Oh, sorry to hear it, Dave.
Joe Carrigan: Yeah, Dave lost his Discord account.
Dave Bittner: No, I just gave -- I just abandoned it. I was like, look, you're not worth this much to me.
Joe Carrigan: Right, because it was like screaming into the void trying to get Discord's attention on it.
Dave Bittner: Right, exactly. It was, like, well, okay, it's just something I'll have to live without. I'm okay with that.
Joe Carrigan: But if Discord -- I don't think they invalidate tokens when you start coming from a completely different IP address. I don't know what their internal processes are.
Dave Bittner: Yeah.
Joe Carrigan: But, you know, if you're developing a secure app, like a banking -- or a secure website, like a banking website or a banking web app, whatever, that session token should be tied to the source IP address, you know, the IP address of the user, and if that changes, you should invalidate it --
Dave Bittner: Yeah.
Joe Carrigan: -- so that -- because I mean, that's indicative of -- that's exactly what's going to happen when somebody comes and steals your session tokens and logs in from a different location. However, that being said, there's nothing to stop somebody from using, like, a remote access tool to log in from the user's location and then do all kinds of nefarious stuff. So even if you have all of these different tools in place, there's still vulnerabilities --
Dave Bittner: Sure.
Joe Carrigan: -- but they almost always involve attacking the user.
Dave Bittner: What are the recommendations here?
Joe Carrigan: Well, the number one recommendation here, Dave, is implement a FIDO2 hardware security key, believe it or not.
Maria Varmazis: It's almost like you predicted that one.
Joe Carrigan: That's number one. Yes, it is. Monitor live chats for suspicious interactions. I don't know how you do that, maybe with an agent, right?
Dave Bittner: Probably.
Joe Carrigan: Maybe with an AI agent.
Maria Varmazis: Yeah, just an intern who just sits there and watches them.
Joe Carrigan: sits over your shoulder, follows you around.
Maria Varmazis: Hey, whatcha you doing? Whatcha doing?
Joe Carrigan: Who are you talking to?
Maria Varmazis: Tell me more about that.
Joe Carrigan: Educate employees on a specific campaign, on this specific campaign or other campaigns like it. Proactively block unauthorized domains. That, you will find in the indicators of compromise for this specific threat. They're going after somebody that impersonates Zendesk with a fake domain. Then, monitor unauthorized binary execution --
Maria Varmazis: Yeah.
Joe Carrigan: -- which may or may not occur. We're seeing fewer and fewer of these attacks don't involve malware. They do what's called "living off the land" where they just use the existing infrastructure, so, I mean, that's a good piece of advice. You absolutely have to do that for the sake of security, but you should not be relying on that as your sole defense anymore. I mean, it's been decades since that --
Maria Varmazis: Yeah, that's table stakes. If you're not doing that, get on that yesterday.
Joe Carrigan: Right. Regularly audit newly enrolled MFA devices across the organization for unauthorized additions.
Dave Bittner: Right.
Joe Carrigan: That's what people can do to prevent it.
Dave Bittner: All right. All right. Very good. Well, we will have a link to that story in the show notes. Actually, we'll have links to both of your stories in the show notes.
Joe Carrigan: Yeah.
Dave Bittner: Maria, you're up next. What do you got for us?
Maria Varmazis: Well, in lieu of doing a story this week, I actually have an interview to share with everybody. I spoke with Sean Colicchio, who is the CISO at Polara. He's also a psychology professor, and he spoke to me a bit about not just what we can do as human beings in the face of social engineering attacks and social engineering attacks that have been made more nefarious with AI, but what organizations can do to help make training more effective against AI-trained techniques, so here's that conversation.
Sean Colicchio: I'm Sean Colicchio. I'm the global CISO of a company called Polara, a cybersecurity and IT technology solutions company. Basically, what I do is run a security and compliance program for the firm, and I also teach as a professor at a local university called Wilmington University and created a course called The Psychology of a Cyberattacker roughly 10 years ago and continue to teach that several times per year. Previous to these experiences, I also was a field expert performing physical social engineering engagements. I try and do as much as I can to give back to the community with speaking engagements and security conference attendance, as well as mentoring junior professionals that are entering the field.
Maria Varmazis: Yeah, no, and greatly appreciate you coming on, Sean, and I'm really thrilled to be able to pick your brain a little bit. I'm a junior student of all these things that you mentioned, having been in cybersecurity on the vendor side and I've just learned as I go, but experts like yourself, I always learn so much from. I really look forward to hearing your thoughts, especially on social engineering and the accelerant that has been AI entering this world. Before we dive into all that, I know there's a conference talk that you tend to give about the human layer of cyber risk, and I'm asking you a little bit to give me, like, the elevator pitch for your talk. Let's just start there, and then we'll dive in from that point.
Sean Colicchio: Yeah, perfect, so I worked with my team to develop a relatively compelling social engineering lore, but before I get into the detail of that, you know, I think the audience is familiar with the gift card attack and using social engineering via either email or SMS phishing or smishing or even teams calls nowadays to compel real-world actions, so getting somebody to actually go to a pharmacy or a gas station and buying gift cards, rubbing off the number, and then sending the number to the attacker, effectively siphoning funds out from that user. They typically will impersonate a C-level executive or somebody they know, and typically, they'll tell them, hey, don't call me back. I'm really busy, which is one of the ways we try and enable and create an awareness for individuals to verify the legitimacy of these type of requests. They say, I'm in a meeting. I'm very busy, and instead of calling me, can you just do this favor for me, which creates this authority in the request. It also is a familiarity tie-in from a psychological perspective. Then they typically will fall victim to that, going to a pharmacy or what have you, and buying these gift cards. I've even seen personally when I go to buy gift cards for a Christmas present, as an example, that some of these places are now trained. When they see somebody buying 10 gift cards, they ask -- I've personally been asked, "Hey, why are you buying these?" which I thought was odd at the time. Then I realized they're actually being trained now to spot victimization and individuals that are going in to buy these cards. That's kind of the real-world example of the gift card attack. Well, what we did, the team developed a deep fake phishing lure that was a video delivered via email that was impersonating a C-level executive at a company. As an organization, we perform social engineering engagements routinely, and we try and get as creative as possible with some of these engagements. The deep fake lure was actually generating interest to the end user saying, hey, we're going to be meeting at the company meeting soon. Before we meet in person, I want you to do something to prep, which creates this urgency, which is also a tie-in to psychology, which we see all the time with phishing in general. The request was actually creating a paper airplane, and we need you to create a paper airplane, write your name on the wing, and we're going to have a distance contest, so now you've got competition. In this particular instance, it was a sales-focused organization, so you've got individuals that are targeted specifically because the executive thinks they could win, which now creates, again, tapping into that authority, that familiarity, and it creates this compelling reason to act. Then, sure enough, 10% of the victim pool showed up and issued a paper airplane, and we have photographs of a box of paper airplanes that were sent to us to just show how this worked. As interesting as it was to leverage AI to produce the outcome, the psychological principles don't change. I mean, AI is accelerating these attacks and scaling them in a way that's never been seen before, but what really works is that human psychology hasn't really changed too often. That's one of the things that we did and it was well-received, so that was the core part of the talk and showed the example and showed the results and even some takeaways on how to prevent it.
Maria Varmazis: Yeah, and I know that's -- the how to prevent it part, I'm sure, a lot of people are probably chomping at the bit a little bit and I want to get to that, but I thought something you said was especially profound, that the human psychology doesn't change even in the face of AI. I know a lot of people, I mean myself included, we see what feels like -- I'm not sure if it is -- but what feels like an exponential increase in the efficacy of some of these social engineering attacks with AI involved. I often have thought, well, the human psychology hasn't changed so that's why it's going to be harder, but I'm wondering, it sounds a little bit like you're saying that actually is of benefit to us when we're thinking about how we can defend against these attacks, is because those fundamentals on the human side are unchanged. Am I interpreting that potentially correctly?
Sean Colicchio: Absolutely. I mean, I think if listeners remember one thing, it's trust your instincts, and your instincts are in that same biological makeup as the psychological potential exposures that the attackers are trying to capitalize on. It's kind of like the Turing Test in a way where you can be convinced that something is real, but the only way that you're being convinced that something is real, from a computer perspective or from a chatbot or what have you, is because the programming around that technology has been made to produce the outcome that will convince the victim that it's real. So if you're spotting those type of things, and you trust those instincts and the "Spidey sense" as some people call it, you can really try and understand well, is this odd that somebody in an executive position is sending me a text message to get gift cards? Irrespective of the gift cards or the lure, you know, to your point, you can trust yourself and your psychology that does give you that instinct that this is foreign or odd or scrutinize it. By being consistent with our own human nature, you can actually defend yourself because the attackers will inevitably try and emulate that, and that's the pattern that you want to look for.
Maria Varmazis: Is there anything organizationally that we can do to maybe help bolster that Spidey sense on the individual level? I know when I've talked to random people in my life about what we're seeing right now many people feel like they don't even have that Spidey sense really calibrated anymore because they don't know what to trust, what not to trust, how to, you know, trust that gut feeling because I've been tricked so many times. Is there anything we can do, again, if you're thinking more organizationally to help with that?
Sean Colicchio: Yeah, I think that's a really great question. I mean, in general, the short answer is conditioning. I think not just security awareness, right? I'm a big fan of this podcast, and I think that's a running theme, you know, the defensive line is the end users which, from a university perspective, the constituents and the end users and the insider threats, they're all the same user pool. They're all on the same network segments, but the conditioning could take multiple forms. It doesn't have to be, let's call it flash in the pan or very exciting from an AI perspective. It doesn't have to be very novel. It can be consistently predictable, and I think what I've found success in is ebbing and flowing between something that's very sophisticated and something that's table stakes or mundane, if you will, routine. An example might be, you know, one year working through an AI based deep fake phishing lure for an organization and then the next year, when they're expecting something that might be very exciting to find or something that's interesting anecdotally to talk about, and then, that year is really just a QR code drop or USB drop, which now, USBs have to be USB-C and A. You know, you get into all kinds of OS flavors that you have to work through to make that attack type work, which is, I think, less, you know, effective because of that. QR codes are still there and they're still everywhere, frankly, and so that's a great example of, you know, the conditioning can get worn out. If you're constantly just looking for something that's flashy or exciting, you don't think about the QR code sticker that's on top of the menu at the restaurant that somebody might have put on top of the menu to try and capture hundreds of people at a time, and so trying to keep a balance of consistency with the table-stakes threats that are and the basics, as well as keep people guessing with the exciting phishing lures, is a way that you can balance your conditioning and bring it back to muscle memory to make sure an organization is defending against these type of threats.
Maria Varmazis: That's a great, great idea there, you know, the balancing between the hypervigilance and the fundamentals that still remain. I love that. That's fantastic, and I'm wondering on an individual level, because I know many people who listen to our show are the family IT person or, you know, just someone who's trying to raise their own awareness and look out for people in their community, what should they know about, I guess, the current state of social engineering as you see it?
Sean Colicchio: Yeah, I think, you know, you kind of tapped on this a bit a second ago, which was what can people do to spot these things? I think one thing that used to be the easy way to prevent a phishing attack was grammatical error and looking at grammar in a phishing email, if it was off base. Spelling errors, you know, a zero instead of an O to maybe try and evade signature-based email defenses. That's no longer the standard. It's almost the opposite, and you've probably heard this before: If it's too perfectly written, then maybe that, in and of itself, is a red flag.
Maria Varmazis: Oh, yeah.
Sean Colicchio: You know, if it's flawless, maybe some AI model produced that phishing lure, right? I think that there's a balance between reality, and again, back to that muscle memory, and I think when spotting an AI-specific phishing lure, generally speaking, there's some things that I've noticed are common. Most individuals that write an email don't use hyphens in a way that AI does routinely. Typically, somebody might use parentheses or commas to break up an idea in a sentence, and very often AI will use hyphens to separate a segue or a minor idea in a sentence. Seeing hyphens in content and spot phishing. I think another is bulleted lists often don't have periods at the end. Typically, when you write them, they're a fragment of a sentence but AI, most of the time, will add a period at the end. That's another minor thing. It's not, you know, 100% correlated with a threat, but these are just small takeaways that somebody listening can maybe use when they look at the next phishing attack that comes in. I also think when you're conditioning your own small organization, it's very important, and this is something I speak to in the course, as well. It's very important to have red flags baked into the event. If it's too hard to spot the phishing attack or it's too convincing, it's like fish in a barrel. There's no learning opportunity for the end user. The end user wants to walk away with, I could have been better by spotting this one thing or these several things, and so when performing an engagement, it's very important to build those things in, so later on it can become an educational opportunity and not just a punch in the face. Nobody likes getting punched in the face, so that's one of the things we try and preach as well.
Maria Varmazis: That makes a lot of sense, incentivizing as opposed to just punishing. Yeah, that is a wonderful point, Sean. I appreciate that. I recognize we're coming close to the end of our time, so I want to make sure if there's anything you wanted to mention to our audience, anything I missed, that I give you that opportunity to share it.
Sean Colicchio: Yeah, absolutely, I think, just back to the psychological principles, I think it's extremely important to realize we all recognize authority, liking, you know, familiarity; people interact with people they like, and they interact with people that are familiar to them. If you feel something is off, you know, reach out to the person via voice. Even that can be potentially falsified, and people can be impersonated, but my goal today, hopefully, listeners see what's out there a little bit more and why these things matter, and it's really important to think through a problem, and slow down. Most attackers get their success by speeding up and accelerating the engagement and the conversation, and so by taking a beat and taking a breath and really trusting your instincts, that's how we can be more resilient as a community and in the industry, in general.
Maria Varmazis: Brilliantly said, Sean. Thank you so much, and thank you for sharing your expertise with us today. I really appreciate it.
Sean Colicchio: All right. Thank you, Maria. [ Music ]
Maria Varmazis: All right. Dave and Joe, now that you've had a listen, what do you think?
Joe Carrigan: I will go first. I'll tell you exactly what I think about this. This is one of the greatest things that he said in this interview is about trusting your gut. He calls it Spidey senses.
Maria Varmazis: Yeah, yeah.
Joe Carrigan: Right? Yeah, that's exactly right. When somebody calls you, and it seems a little bit off, it probably is a little bit off. That's probably a good judgment.
Dave Bittner: Yeah, I like the part where he was talking about when it came to training, to mix it up some.
Joe Carrigan: Yeah.
Dave Bittner: You know, the difference between edge cases, the fundamentals, everybody when they say, "Hey it's training day," everybody goes, "ugh."
Joe Carrigan: Right.
Maria Varmazis: Yeah.
Dave Bittner: The least you can do is mix it up, keep it interesting, and vary it, and I think it gives you a better chance of stuff sticking.
Maria Varmazis: Yeah, I thought it was really neat that the point he was making is if you have everyone really hypervigilant for really sneaky attacks, that it could actually prime people to miss the really obvious ones that we've become almost inured to. It's good to keep people aware of, you know, the oldies but goodies stick around.
Joe Carrigan: Maybe this really is a Nigerian prince.
Maria Varmazis: Yeah, it's, like, as much as we chuckle about it, right, but, you know, someone -- I don't know about that one necessarily, but, you know, some really basic phishing attacks can still get you if you're just going, oh, whatever, you know, on autopilot because you're thinking about the fancy new AI deep fake attack. It's, like, yes, that exists and so do the old ones. They're all still kicking around at the same time, so you don't want people getting too, sort of, black-and-white thinking, it's either one or the other. It's an and, the thing that I found very validating I don't know about you two, but when I asked him, you know, what's your advice for the individual person? He basically said everybody's got to slow down.
Joe Carrigan: Yeah.
Dave Bittner: Yeah.
Maria Varmazis: I think we say that a lot on this show, and it made me feel much better. I just want to make sure that people channel their inner Mediterranean a little bit. Just slow down, and that will just do a lot for preventing you from instantly reacting out of panic or annoyance or any of the other strong feelings that I think attackers are trying to take advantage of. So, yeah, slowing down, which is a very -- it's always interesting when it comes to these social engineering sets of advice sometimes it sounds very unsexy, like, hey, slow down; trust your gut, but we're talking about attacking humans, so do human things. Like, slow down.
Joe Carrigan: Right, yeah.
Dave Bittner: Yeah.
Joe Carrigan: I think that's the crux of his point in the article, is that these things are your allies. There's a reason you have a gut instinct, and it harkens all the way back to days out in the wilderness. You'd hear something that sounded off, and you'd immediately pay attention to it and be like, hmm, that's not right.
Dave Bittner: The other one that I like to emphasize that I think doesn't get the recognition that it deserves is talk to a friend talk to a co-worker --
Maria Varmazis: Yeah.
Joe Carrigan: Yeah.
Dave Bittner: -- and it goes along with slowing down, because in the process of doing this you'll slow down, but just saying it out loud to another person can often make you realize something's off, right?
Maria Varmazis: Yeah, just -- yeah.
Dave Bittner: The other person's not in that heightened emotional state that you may be in as these people try to manipulate you.
Joe Carrigan: Right.
Maria Varmazis: Yeah, so if you're on the receiving end of that kind of a thing try to be patient. I would rather, you know, my family come to me with these things and use me as a sounding board, than go, "Oh, I don't want to bother her." No. I want people to bother me about that. I want to help, because you're right, just as you're verbalizing it sometimes, mid-sentence you go, oh, yeah, that is kind of silly, isn't it? I'm happy I could help by just standing here and listening to you, but, yeah, sometimes it can be very hard to discern, and yeah, that's great advice, Dave. I like that. My great appreciation to Sean for coming on the show and sharing his expertise with us. I will make sure have links to where you can find him and more information about his paper airplane talk in the show notes because it's a really interesting one, so thanks again, Sean.
Dave Bittner: All right. Yeah, much appreciated, really good stuff. I'll tell you what. Let's take a quick break here to hear from our sponsor. We will be right back after these messages. [ Music ] All right. We are back, and I actually have two stories today, or a story and a list because they're both kind of short. The story I want to touch on, this is from the folks over at Bleeping Computer, and this is about a scam that is making the rounds. I checked with several of my co-workers, and they've gotten tons of these in the past couple weeks. These are traffic violation scams, and the note here is that the scammers have switched to including QR codes in their phishing text messages. Basically, they're sending out these notice of default traffic nationwide, and they're demanding a low payment. Most of these, it's, like seven bucks, right? The goal is not to get the money. The goal is to steal your information to get your credit card.
Joe Carrigan: Interesting.
Maria Varmazis: Yeah, it makes sense, yeah.
Dave Bittner: Toll violations have been around for a while, but the new twist on this is that they're including these QR codes to get you to go to the location where they want you to log in, and QR codes are much harder for defensive measures to unpack, and, you know, they don't look as obvious as a funky looking URL --
Joe Carrigan: Right.
Dave Bittner: -- so it's more likely to make it through both your automated defenses but your personal ones, as well, because I don't know about you guys, but I can't read a QR code by sight.
Joe Carrigan: Not yet.
Maria Varmazis: Not yet. Working on it. [Laughing]
Dave Bittner: let me challenge you to that, Joe. Can you get that in a week? Can you --
Joe Carrigan: No.
Dave Bittner: Let's take advantage of that brain of yours and get you obsessed about something.
Maria Varmazis: Yeah, hyperfocus on it. I'm sure you can make it happen, Joe. Use neuro spice in your favor.
Joe Carrigan: Challenge accepted.
Maria Varmazis: I love it. [Laughter]
Joe Carrigan: QR Code Flashcards with Joe.
Maria Varmazis: Most useless skill ever.
Dave Bittner: Joe's going to be, like, let me see. It says www.joeisa -- wait a minute. [ Laughter ] All right. Well, my other thing I want to share today, this actually came from one of our listeners who is a regular contributor. This is someone who I've mentioned many times who is a friend of the show, a former federal law enforcement officer, and prefers to stay anonymous and so I respect that. I believe he's retired these days, but he sent me along this nice list that he uses for himself and his friends and family. He calls it "Ten Hard Stop Rules for Online Scams," and it's a good list so I thought I'd share it, go through it, and we can talk about it as we go. Number one, caller ID is not proof. Names, phone numbers, email senders, and even verified badges can all be faked.
Joe Carrigan: Yep.
Maria Varmazis: Yes, and easily purchased.
Dave Bittner: Number two, initiate contact yourself. End inbound contact. Outbound contact only. Look up the organization yourself and use official contact details, not anything provided in the messenger call.
Maria Varmazis: Correct.
Dave Bittner: We've talked about this many times.
Joe Carrigan: Absolutely.
Dave Bittner: No codes or passwords from inbound requests. Again, if you didn't start it, don't share credentials or one time codes. Verify inside your account. Access your account by typing the address yourself or using a saved bookmark, not links or prompts because people will send you emails that say "Click here to connect to your bank" and go somewhere else.
Joe Carrigan: Right.
Dave Bittner: No links or QR codes. Type it yourself, related to the previous one. No remote access or device changes. Never grant anyone remote access to your machine. Don't install software. Don't connect to a -- and he puts in scare quotes "secure or AI server." Don't ever share your screen or change any of your settings because someone told you to do it.
Maria Varmazis: That's for sure, yes.
Dave Bittner: Yeah, never bypass protections. Don't use payment options meant for friends and family or anything that removes protections. Don't disable safeguards or take shortcuts to fix or speed up anything.
Maria Varmazis: Yeah, they're there for a reason.
Dave Bittner: Yeah, and I'd say roll into this. You know, don't go to a third location, and that can be a financial location --
Joe Carrigan: Yes.
Dave Bittner: -- or even a different platform. We talk about all the time on "The Catch of the Day," like, people trying to get people just -- "Hey, do you have Telegram?" and taking you somewhere you don't want to be.
Joe Carrigan: Yeah, some unregulated place where they're not watching what you say, like on dating apps. It's really big with romance scams.
Dave Bittner: Yeah?
Maria Varmazis: Yeah.
Dave Bittner: It puts you in a bad neighborhood.
Joe Carrigan: Yep.
Dave Bittner: Number eight, no irreversible payments from inbound requests, no crypto, gift cards, wires, or peer-to-peer transfers. Never send money to reverse, refund, or fix a transaction.
Maria Varmazis: Yes, a big one right there, yep.
Joe Carrigan: When somebody says, "Oops, I made an error here," you say, "Thanks," and leave.
Maria Varmazis: Or, oh, gosh, someone accidentally deposited a whole lot of money in your account that didn't mean to do that. That feels like a go to your bank immediately situation.
Joe Carrigan: Right. I'd like to withdraw all this accidentally deposited money. [ Laughter ] Actually, it's not there.
Dave Bittner: And close the account. it was never there in the first place.
Maria Varmazis: Correct.
Dave Bittner: Yeah, same thing, I guess -- does that apply to things that get delivered to you by accident?
Joe Carrigan: Yeah, I think there's --
Maria Varmazis: Like, Amazon packages you didn't order?
Dave Bittner: I saw this week, somebody got, like, an iPad in the mail that they never ordered. I know, like, legally you are allowed to keep anything that's sent to you that you did not order, but I guess it might be more complicated these days, in that you could ruin your Amazon account, for example, that you've come to rely on if Amazon suddenly had a beef with you and said, hey, send that iPad back, and you said, no Amazon. Then they'd say, okay, no Amazon for you.
Joe Carrigan: Right.
Dave Bittner: So it's a little more complicated than the days of the postal service.
Joe Carrigan: Right. With the Apple thing you're talking about, Apple could just brick your iPad.
Dave Bittner: Well, that's true. Yeah, I guess they could.
Joe Carrigan: They could just say, this is a stolen iPad, and it won't work anymore.
Maria Varmazis: Yeah, I was a recipient of a lot of Amazon packages of stuff I never ordered, and Amazon's whole thing was if it's been delivered to you, you keep it. We don't want it back. There was no way for me to return it. They didn't want it back. It was very, very strange.
Joe Carrigan: Free stuff.
Maria Varmazis: To be honest with you, it was all junk I didn't want. It all went in the trash, so I really resented that it was coming my way. So it's just, like, great, just landfill
Joe Carrigan: Just sell it on Facebook Marketplace.
Maria Varmazis: Like I don't have enough to do in my life, someone's giving chores.
Dave Bittner: Nobody has time for that, yeah, yeah, yeah. All right. Getting back to the list here, number nine, secrecy is a stop signal. Don't tell anyone or -- if someone says to you, "Don't tell anyone," or they pressure you to keep something quiet, stop.
Joe Carrigan: Right.
Dave Bittner: That means it's time to tell someone.
Maria Varmazis: That's right.
Joe Carrigan: That's isolation.
Dave Bittner: Right, exactly, they're trying to isolate you. Then the last, but certainly not least, pause before any financial action. If it feels urgent, slow down.
Joe Carrigan: There are those two words again, slow down.
Dave Bittner: Yeah, and real organizations will give you time to verify.
Joe Carrigan: Absolutely.
Dave Bittner: They'll appreciate it.
Maria Varmazis: Oh, my gosh, yes. Yes, they will. Two years ago, I bought the house I'm in right now, and every transaction I did that was legit got flagged for fraud every step of the way. We almost missed closing, and I appreciated the diligence.
Dave Bittner: Really?
Maria Varmazis: Yes. We had to go through so many hoops and so many in-person conversations within the bank, and again, we almost missed closing on our own house because Fraud was doing what it should be doing, which was slowing it down and checking, yeah.
Joe Carrigan: Right. Right. Well, I mean, that's how you avoid having your house sold from underneath you.
Maria Varmazis: Yes, yes, it was one of those things. It was, like, I'm very glad this is happening. I really wish that in the case of that transaction we had known that we needed to build that in. I wish we had realized that would happen, but the financial institutions are doing exactly the diligence they should have been doing, so I appreciated it.
Joe Carrigan: That's good. I think they've lost enough money on this.
Dave Bittner: It's a really good point because it's another place where we can all slow down, because I know, probably once a week, I find myself going security is such a pain in the butt, right?
Maria Varmazis: You, Dave Bittner?
Joe Carrigan: Screaming like a Muppet.
Maria Varmazis: Arms a-flailing.
Dave Bittner: Usually it's because I have to get up off of my couch, go get my YubiKey, bring it back, plug it in. You know, whatever, and I don't want to be slowed down, but when that happens, I remind myself to talk myself off the ledge. This is a good thing. Security is a good thing. It's a pain in the butt. I'm angry about it right now, but in the end, this is easier than getting my stuff stolen.
Joe Carrigan: I will tell you this, Dave. More often than not, when I go to open my password manager at home, I have to stop what I'm doing and walk upstairs and get my backpack which has my YubiKey, and then bring my backpack back downstairs and plug in my YubiKey.
Dave Bittner: For anybody who's seen Joe's backpack, that's no small task.
Joe Carrigan: Right, because when I come in, put it in the dining room, much to my wife's chagrin. "Don't leave this here."
Dave Bittner: Yeah, the whole house shifts.
Joe Carrigan: Right, yeah, everybody knows when I'm home. They can feel the vibration, but then, you know, I go downstairs and I'm, like, oh, I should probably pay this bill or check on my college webpage, so I can see how my grades -- oh, I need my YubiKey to open my password manager. Yep, got to go back upstairs. I always mean to bring it back downstairs, but I just don't.
Dave Bittner: Yeah.
Joe Carrigan: Again, that's the ADD talking.
Dave Bittner: Just this past week, I had my -- what do you call it -- my ATM card got flagged.
Joe Carrigan: Really?
Dave Bittner: Yeah, it's my own stupid fault. It's a long story. Let me just cut it short by saying Facebook was involved and leave it at that. I was trying to set something -- anyway, so --
Joe Carrigan: Were you trying to buy some of their cryptocurrency, Dave?
Dave Bittner: No, no, I was just trying -- I was trying to do -- all good intentions, and no good deed goes unpunished. We'll leave it there, so I ended up having to go to my bank to get my card reinstated. Fortunately, I didn't have to get a new card, which meant I didn't have to go, you know, renew all my things that my card was signed up for.
Joe Carrigan: Right. That's nice.
Dave Bittner: But what struck me was the ladies who were helping me at the local branch, they were very kind and wonderful customer service, but they were also apologetic. Like, oh, sorry you had to go through this. I was, like, no, no, no, no. It's fine.
Joe Carrigan: No, this is suspicious activity.
Dave Bittner: Right. This is all working the way it should, no problem at all, so they appreciated that. All right. I will have a link to that story from Bleeping Computer in our show notes, and of course, we would love to hear from you. If there's something you'd like to share with us, you can email us. It's hackinghumans@n2k.com. Joe, Maria it is time for our Catch of the Day. (SOUNDBITE OF REELING IN FISHING LINE) [ Music ]
Joe Carrigan: Dave, our Catch of the Day comes from r/scams on Reddit. This is an email that's coming to somebody who has 39% of their battery left. [ Laughter ]
Maria Varmazis: Charge your [beep].
Joe Carrigan: There's just so much information on your screen that you don't need to share. you know,you can crop this a little a bit better.
Dave Bittner: Why does this person have two signal strength meters.
Joe Carrigan: That's a good question. I was wondering that myself. Not only do they have two signal strength meters, but they're also on the WiFi, and it's apparently WiFi 6.
Dave Bittner: I'm missing out on something here. I'm feeling a little wireless FOMO. I don't know.
Joe Carrigan: Yeah, it's 6:39 in the evening or afternoon. You can't tell. It's 6:39 somewhere.
Dave Bittner: Let me ask you this Joe. At what point in the battery charging world do you start to feel anxious? What number do you get to?
Joe Carrigan: I get upset if my battery goes below, like, 50%.
Dave Bittner: Really?
Joe Carrigan: Yeah, my phone -- I don't use my phone that much, or at least I think I don't use my phone that much. Maybe I use my phone way too much, and when I see it below 50%, like in the evening, I'm, like, what's going on? Is my battery dying? Am I using this too much? Something's up.
Dave Bittner: How about you, Maria?
Maria Varmazis: Oh, I let it go down to probably 10% before I charge it.
Joe Carrigan: I couldn't do that.
Maria Varmazis: But I frequently keep it on -- [ Multiple Speakers ] I frequently keep my phone on a charger throughout the day, though, so it depends. I mean, I have it right now on my desk charger, so it's probably topped up. Yeah, easily, it'll go down to 10% if I'm out and about, and I'm fine with it. It's cool.
Joe Carrigan: The subject on this email is "App Publishing Revenue Share Opportunity for You." Let me see. Somebody who's already published an app is going to share their cash with me.
Maria Varmazis: Wow, free money. Why would that be a scam?
Dave Bittner: It's from someone named "Gerard Great."
Joe Carrigan: He sounds awesome.
Maria Varmazis: That sounds like a real name.
Dave Bittner: Yeah, it goes like this: "Greetings, since November 2023, Google has passed a new policy for new app and game developers to pass a 14 days' closed testing mandatory test. This has hindered the growth of private app and game monetizers to earn with their apps. At Keeve Gaming Hub we're requesting for your partnership in hosting and managing of our apps and games for fixed and recurring fee. Also includes tester accounts due to our technology upgrade. If you're interested in this offer, kindly reply to this email with your WhatsApp contact and out regional managers will reach out very soon. CEO Enger Levi Keeve Gaming Hub International.
Joe Carrigan: This sounds like you're going to get sucked into some Eastern European mafia kind of thing. That is my fear here. You're going to be mulling apps around the internet, and they're going to be using your Google account. That's what this smacks up to me. It could just be sideload this malicious app on your phone, which --
Maria Varmazis: Is less bad? Which one is worse?
Dave Bittner: Well, let's unpack it bit by bit. Let me ask you, Maria. At its core, what do you think this is about?
Maria Varmazis: I mean, to me it sounds like an account takeover attempt. They're asking you to go to WhatsApp. I mean, it starts with an email, but then it goes to WhatsApp, and I'm sure they're going to say, hey, we need your account for some nefarious, totally innocent-sounding thing. Yes, I can't imagine anything good would happen once you do that.
Dave Bittner: I think I'd be suspicious, too, to what Joe is saying. This is some kind of app laundering sort of thing, where they get someone who's got an IP address in a favorable nation, as opposed to Russia or something, to be the one submitting the app to the app store, so that it doesn't maybe raise as many red flags. Who knows, but yeah, I'm sure this is taking you down a path that will not end well for you.
Joe Carrigan: Right.
Dave Bittner: All right. We will have a link to that in our show notes, and again, we would love to hear from you. If there's something you'd like us to consider for the Catch of the Day, please do email us. It's hackinghumans@n2k.com. [ Music ] That is our show today, brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cyber security. If you like our show, please share a rating and review in your favorite podcast app. Please fill out the survey in the show notes or send an email to hackinghumans@n2k.com. This episode is produced by Liz Stokes. our Executive Producer Jennifer Eiben. We're mixed bye Elliot Peltzman and Tré Hester. Peter Kilpe is our Publisher. I'm Dave Bittner.
Joe Carrigan: I'm Joe Carrigan.
Maria Varmazis: And I'm Maria Varmazis.
Dave Bittner: Thanks for listening. [ Music ]



