
Hacking Humans
772 episodes — Page 15 of 16

S2 Ep 71The ability to fundamentally deceive someone.
Joe has the story of a convincing scammer who makes an innocent woman doubt herself. Dave describes an online utility that helps users delete unwanted user accounts and also rates the difficulty of doing so. The catch of the day requests help in an investment scam (but lacks punctuation). Our guest is Henry Ajder from Deeptrace Labs on their research on Deep Fakes. Links to stories: https://www.walesonline.co.uk/news/wales-news/swansea-mum-scammed-out-1000-17065476 https://backgroundchecks.org/justdeleteme/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 70The fallacy of futility.
Dave describes a ponzi scheme that bought up legitimate investment firms. Joe shares research into deep fakes. The catch of the day includes an invitation to join the illuminati. Ray [REDACTED] returns with followup from his prior visit, along with new information to share. Links to stories: https://13wham.com/news/local/feds-in-rochester-to-detail-multi-million-dollar-ponzi-scheme https://nakedsecurity.sophos.com/2019/10/09/deepfakes-have-doubled-overwhelmingly-targeting-women/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 69Don't trust ransomware to tell you its real name.
Joe describes online redirect scams, URL encoding and the clever combination of the two. Dave shares delightful satire about Russian brides and Nigerian princes, together at last. The catch of the day involves a student getting the best of scammers, getting them to send him money. Our guest is Fabian Wosar from Emsisoft, well-known for decrypting ransomware. Links from today's stories - https://waterfordwhispersnews.com/2019/09/25/hot-woman-in-your-area-marries-nigerian-prince-whos-email-you-ignored/ https://www.thesun.co.uk/tech/10052181/student-limerick-online-scammer-charity/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 68The ultimate hacking tool.
Joe reviews highlights from a Proofpoint report on the human aspects of cyber attacks. Dave describes the FTC's cases against online dating site Match.com. The catch of the day comes straight from Her Majesty the Queen. Carole Theriault returns with an interview with Corin Imai, Senior Security advisor at DomainTools, about phishing attacks they’ve been tracking in the UK. Links to stories: https://www.helpnetsecurity.com/2019/09/10/cyberattacks-human-interaction/ https://techcrunch.com/2019/09/26/dating-app-maker-match-sued-by-ftc-for-fraud/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 67The usefulness of single sign on.
Joe outlines online threats from social media. Dave shares a story of scammers try to scare a community into purchasing security products. The catch of the day features a promise of riches from Facebook's Mark Zuckerberg. Our guest is Yaser Masoudnia from LastPass who addresses listener questions about Single Sign On. Links to stories: https://info.phishlabs.com/blog/how-social-media-is-abused-for-phishing-attacks http://www.pressandguide.com/news/police_fire/email-scam-trying-to-convince-dearborn-residents-crime-is-up/article_249b1f2c-cb34-11e9-a5b0-cf725769167a.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 66Algorithms controlling truth in our society.
Special guest host Graham Cluley joins Dave while Joe takes a short break. Dave shares the success of the FBI's reWired campaign which has apprehended alleged scammers around the world. Graham describes a website hoping to spare users the hardship of multifactor authentication. The catch of the day involves a generous soccer star. Our guest is Matt Price from ZeroFOX with insights on Deep Fake technology. Links to today's stories: https://www.fbi.gov/news/stories/operation-rewired-bec-takedown-091019 https://dontduo.com/ https://www.smashingsecurity.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 65An ethical hacker can be a teacher.
A listener updates us on "notice of arrest" policies. Dave notes increased instances of Google Calendar spam. Joe shares a claim that AI voice mimicry was used to dupe a company out of nearly a quarter million dollars. (Dave is skeptical.) The catch of the day accuses the target of naughty behavior. Carole Theriault interviews ethical hacker Zoe Rose. Links to stories: https://www.popsci.com/google-calendar-spam-what-to-do/ https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 64Think before you post.
Follow-up from down under. Joe shares the story of a Mom scammed out of Gaelic Football League tickets. Dave describes a bounty hunter hoaxing suicide threats to get location information from mobile providers. The catch of the day requires a response from the grave. Our guest is Ben Yelin, senior law and policy analyst from the University of Maryland Center for Health and Homeland Security. He digs in to a particular Facebook scam that refuses to die. Links to stories: https://m.independent.ie/irish-news/news/im-just-broken-up-mother-devastated-as-shes-scammed-out-of-money-while-trying-to-buy-allireland-final-tickets-38446401.html https://www.thedailybeast.com/feds-say-bounty-hunter-matthew-marre-used-suicide-hoax-to-con-verizon-t-mobile-out-of-customer-data Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 63Securing your SMS.
Dave shares a story of digital voice assistants being channeled toward scammers. Joe tracks scammers taking advantage of social tools on the Steam gaming platform. The catch of the day involves South African kickbacks. Our guest is researcher/technologist Ray [REDACTED], who shares his expertise on scammers targeting SMS. Links to stories: https://nakedsecurity.sophos.com/2019/08/20/scammers-use-bogus-search-results-to-fool-voice-assistants/ https://www.bleepingcomputer.com/news/security/steam-accounts-being-stolen-through-elaborate-free-game-scam/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 62Backups backups backups.
Joe describes a primitive (but effective) phishing scheme being tracked by Bleeping Computer. Dave shares news from a Black Hat presentation on phishing stats from Google. The catch of the day is a friendly invitation from Hawaii. Our guest is Michael Gillespie from Emsisoft describing the ID Ransomware project. Links from today's stories: https://www.bleepingcomputer.com/news/security/beware-of-emails-asking-you-to-confirm-your-unsubscribe-request/ https://www.fastcompany.com/90387855/we-keep-falling-for-phishing-emails-and-google-just-revealed-why https://id-ransomware.malwarehunterteam.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 61Swamping search results for reputation management.
Dave shares the story of a small community hospital dealing with a ransomware attack. Joe reviews the different types of extortion emails. The catch of the day is an inheritance scam from Canada. Carole Theriault interviews Craig Silverman from Buzzfeed about online reputation management companies. Links to stories: https://www.azcentral.com/story/news/local/arizona/2019/07/30/how-4-technicians-saved-arizona-hospital-hacker-ransomware-wickenburg-community-hospital/1842572001/ https://www.bleepingcomputer.com/news/security/extortion-emails-on-the-rise-a-look-at-the-different-types/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 60Positive pretexting on the rise.
Joe shares a cautionary Facebook tale from his own life. Dave has the story of an Australian IT company put out of business by scammers. The catch of the day tracks the response writer and comedian Dave Holmes had to scammers pretending to be from the IRS. Rachel Tobac from Social Proof Security returns with voting security information and the latest scams she's been tracking. Links to today's stories: https://www.crn.com.au/news/it-suppliers-forced-to-close-after-procurement-scam-528609 https://cheezburger.com/719877/troll-comedian-gets-a-scam-call-and-decides-to-play-along https://www.vampirecaveman.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 59Images are the language of the brain.
Dave outlines a church donation scam. Joe shares reporting from Ars Technica on romance scams coming out of Africa. The catch of the day is courtesy of London comedian James Veitch Our guest is Garry Berman from Cyberman Security who's developed a cyber security comic book series to help raise awareness. Links to this week's stories: https://www.churchlawandtax.com/blog/2018/june/what-to-know-about-new-donation-scam.html https://arstechnica.com/information-technology/2019/07/im-not-100-with-anybody-ars-dissects-a-nigerian-twitter-catfish-scam/ https://www.boredpanda.com/funny-phishing-scam-emails-dot-con-james-veitch/ https://www.cyberheroescomics.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 58Looking after Dad.
Joe shares a story on the market economy of phishing. Dave explains how gamers are being taken advantage of on popular chat app Discord. The catch of the day included a little bit of showbiz razzle-dazzle. Our anonymous guest this week shares his efforts to keep his father from falling for online scams. Links to stories: https://blogs.akamai.com/sitr/2019/06/phishing-factories-and-economies.html https://twitter.com/Splatter_Shah/status/1143556723266994176 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 57The skills gap disconnect.
Dave shares a listener story of scammers calling drug stores to try to gather customer rewards points. Joe describes federal contractors being scammed out of over $10 million of hardware, some of it classified communications equipment. The catch of the day starts with a bank email scam and ends with a Rick roll. Carole Theriault speaks with Michael Madon, head of security at Mimecast about the cyber security skills gap. Links to stories - https://qz.com/1661537/us-defense-contractor-falls-for-3-million-email-scam/ https://www.newshub.co.nz/home/entertainment/2018/01/man-sets-up-rick-astley-hotline-to-rescue-people-from-annoying-salespeople.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 56Know and spot the patterns.
Joe shares the heartbreaking tale of a catphishing case that leads to murder. Dave describes a shoe company using an unusual method to trick engagement with an online ad. The catch of the day engages a Nigerian scammer promising a fortune in precious minerals. Dave interview Michael Coates, head of Altitude Networks and former CISO at Twitter. Links to this week's stories - https://www.nbcnews.com/news/us-news/after-alaska-teen-s-murder-cybersecurity-experts-warn-catfishing-predators-n1019536 https://medium.com/shanghaiist/chinese-shoe-company-tricks-people-into-swiping-instagram-ad-with-fake-strand-of-hair-54d8a2d8ec1d https://www.419eater.com/html/user_subs/godfather/godfather.htm https://altitudenetworks.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Encore — Separating fools from money.
We're taking a break for the Independence Day holiday in the US, so enjoy this episode from the early days of our show. Dave shares a story of airport penetration testing with high degree of yuck-factor. Joe explores research on protecting passwords from social engineering. The catch-of-the-day comes courtesy of Graham Cluley's email spam box. Dave interviews Wired's Security Staff Writer Lily Hay Newman on her article tracking Nigerian email scammers. Thanks to our show sponsor KnowBe4.

S2 Ep 55Be wary of all emails.
Dave shares the story of one Katie Jones, the fake online persona used to gain the confidence of high-status individuals. Joe describes the tragic case of Christine Lu, a Harvard Medical professor who was scammed out of her life savings. The Catch of the Day warns recipients not to trust the FBI. Carole Theriault interviews Akamai's Larry Cashdollar about scammers using Google Translate to obfuscate web sites. Links to this week's stories: https://www.apnews.com/bc2f19097a4c4fffaa00de6770b8a60d https://thispersondoesnotexist.com/ https://www.nbcboston.com/on-air/as-seen-on/Woman-Scammed-Into-Giving-Away-Life-Savings_NECN-511108952.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 54The knowledge / intention behavior gap.
Joe shares the story of an elaborate check fraud scam involving HR impersonators. Dave reads an email from a listener who got phished by his own company, and has questions about authorization app vs. hardware keys. Our catch of the day involves an orphan looking to share her inheritance. Dave interviews author Perry Carpenter, who's new book is Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us about Driving Secure Behaviors. Links to stories: https://twitter.com/sigalow/status/1138918411394781185?s=12 https://www.yubico.com/2019/01/yubico-launches-the-security-key-nfc-and-a-private-preview-of-the-yubikey-for-lightning-at-ces-2019/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 53Just because I trusted you yesterday doesn't mean I trust you today.
Dave describes researchers spotting scammers on dating sites using AI. Joe shares a phishing scheme that asks users to manage undelivered mail. The catch of the day involves cute puppies and Mogwai meat. Dave interview Avi Solomon, director of information technology for Rumberger, Kirk and Caldwell, an Orlando, Florida litigation firm. Links to today's stories: https://www.bbc.com/news/technology-48472811 https://arxiv.org/pdf/1905.12593.pdf https://www.bleepingcomputer.com/news/security/new-phishing-scam-asks-you-to-manage-your-undelivered-email/ https://www.419eater.com/html/tommy_mark.htm Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 52The best way to break in is to walk through the front door.
Joe describes one of history's great con artists, Victor Lustig, who sold the Eiffel Tower. Twice. Dave shares a story from a listener involving a UPS tracking number scam. The catch of the day involves am attempted romance scam on the XBOX platform. Dave interviews Sherri Davidoff, CEO of LMG Security and is the hacker named "Alien" in Jeremy Smith's book, "Breaking and Entering." She has her own book coming out this summer, "Data Breaches: Crisis and Opportunity." Links to this week's stories: http://mentalfloss.com/article/12809/smooth-operator-how-victor-lustig-sold-eiffel-tower https://community.ebay.com/t5/Archive-Shipping-Returns/Seller-Scam-UPS-Tracking-Shows-Delivered/td-p/26206551 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

S2 Ep 51Be willing to admit you don't know everything.
Dave reviews Google's recent security report on basic account hygiene. Joe describes passive social engineering, including USB charging stations at airports. The catch of the day exposes a trunk box scam involving ill-gotten war profits. Carole Theriault speaks with the head of a group that call themselves Scam Survivors. Links to stories: https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html https://www.forbes.com/sites/suzannerowankelleher/2019/05/21/why-you-should-never-use-airport-usb-charging-stations/#4116498a5955 https://scamsurvivors.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 50People aren't perfectly rational.
A listener writes in with the results of his phishing attempt on his wife. Joe describes research from F-Secure on the most dangerous email attachment types. Dave shares the story of scammers impersonating local hospitals to scare a response from their victims. Our catch of the day involves a LinkedIn scam impersonating a fighter pilot. Joe interviews Elissa Redmiles, an incoming assistant professor of computer science at Princeton University. She studies behavioral modeling to understand why people behave the way they do online. Links to stories from today's show: https://labsblog.f-secure.com/2019/05/08/spam-trends-top-attachments-and-campaigns/ https://www.nbc15.com/content/news/Text-message-scam-impersonates-local-hospitals-509615981.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 49Live at KB4CON 2019.
It's a special edition of the Hacking Humans show recorded live at the KB4CON conference in Orlando, FL. Join Joe, Dave and their special guests Stu Sjouwerman, KnowBe4's CEO, and Kevin Mitnick, world-famous hacker and KnowBe4's chief hacking officer, as they discuss malicious scams making the rounds and how to protect yourself and your organization against them. Dave describes a late-night phone call scam, Joe explains a Social Security scheme, Stu shares deadly catch of the day, and Kevin shares stories from his own hacking experience, and takes questions from the audience. Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 48A data-driven approach to trust.
Joe describes a church scammed out of millions of dollars. Dave shares good news about a group of scammers being apprehended and arrested. The catch of the day involves a Vietnamese investment offer that's almost too good to pass up on. Dave speaks with Dr. Richard Ford from Forcepoint about the models of trust. Links to stories in today's show: https://www.grahamcluley.com/hackers-steal-1-75-million-from-catholic-church-in-ohio/ https://www.justice.gov/usao-sdny/pr/nine-defendants-arrested-new-york-florida-and-texas-multimillion-dollar-wire-fraud Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 47Twitter bots amplifying divisive messages.
Followup from listeners on Google search result scams. Dave describes the city of Ottawa sending $100K to a fraudster. Joe shares results from the FBI's Internet Crime Report. The catch of the day involves a dating site and an offer to be someone's "sugar daddy." Our guest is Andy Patel from F-Secure, describing how Twitter bots are amplifying divisive messages. Links to storys: https://www.cbc.ca/news/canada/ottawa/city-treasurer-sent-100k-to-fraudster-1.5088744 https://threatpost.com/fbi-bec-scam-losses-double/144038/ https://www.ic3.gov/media/annualreport/2018_IC3Report.pdf https://labsblog.f-secure.com/2019/04/03/discovering-hidden-twitter-amplification/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 46Let's play, "Covered by cyber insurance — true or false?"
Dave and Joe answer a listener question about a mysterious Netflix account. Dave describes a service for Airbnb scammers. Joe explains a particularly "nasty" Instagram scam. Carole Theriault interviews cyber insurance expert Martin Overton from OMG Cyber. Links to stories: https://www.bleepingcomputer.com/news/security/the-nasty-list-phishing-scam-is-sweeping-through-instagram/ https://krebsonsecurity.com/2019/04/land-lordz-service-powers-airbnb-scams/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 45I have been practicing honesty and truthfulness my whole life.
Followup from an Australian listener. Dave shares a Paypal scam leveraging Google ads. Joe describes TechCrunch reporting on a spam service that was left out in the open. The catch of the day promises a lifetime supply of gold. Dave interviews Asaf Cidon from Barracuda Networks https://techcrunch.com/2019/04/02/inside-a-spam-operation/ https://www.barracuda.com/spear-phishing-report Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 44Scammers have no ethics whatsoever.
Joe describes a study of people's perceptions when presented with a magic trick. Dave shares the story of fake boyfriend app. Our catch of the day involves the promise of millions from a bank in Africa. Dave interviews Chris Parker from WhatIsMyIPaddress.com. Links to stories: http://nautil.us/issue/70/variables/a-magician-explains-why-we-see-whats-not-there https://youtu.be/vJG698U2Mvo https://www.pedestrian.tv/tech/fake-boyfriend-app/ https://whatismyipaddress.com/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 43Girl Scouts empowering cyber security leaders.
Dave describes a survey of call center security methods. Joe explains a spam campaign raising the specter of a flu pandemic to scare people into enabling macros in an Office document. The catch of the day highlights a Facebook scammer promising a prize-winning windfall. Carole Theriault returns with a story about special badges Girls Scouts can earn for cyber security. Links to stories: https://marketing.trustid.com/acton/attachment/32513/f-0039/1/-/-/-/-/TRUSTID_2018_State_of_Call_Center_Authentication_Survey.pdf https://www.bleepingcomputer.com/news/security/fake-cdc-emails-warning-of-flu-pandemic-push-ransomware/ http://blog.girlscouts.org/2018/07/girl-scouts-introduces-30-new-badges-to.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 42Pick a persona to match the goal.
Followup on remotely previewing websites. Joe has the story of scammer bilking Facebook and Google out of millions. Dave reviews best practices for deleting data on devices you dispose of. The catch of the day is an offer of criminal partnering with the CIA. Our guest is Jeremy N. Smith, author of the book Breaking and Entering - the extraordinary story of a hacker called Alien. Links from today's stories: https://urlscan.io/ https://www.theregister.co.uk/2019/03/21/facebook_google_scam/ https://blog.rapid7.com/2019/03/19/buy-one-device-get-data-free-private-information-remains-on-donated-devices/ https://www.amazon.com/dp/B0789KP775 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 41Kids are a great target.
A listener recommends an online tool for safely previewing web sites. Dave shares research on what time of the work week is best for scams. Joe explains credential stuffing. Our guest is Frances Dewing, the CEO and co-founder of Rubica. They recently published a report on how crooks are accessing parents’ mobile devices via apps their kids load. Links to stories mentioned in today's show: https://screenshot.guru/ https://www.aarp.org/money/scams-fraud/info-2019/phone-scams-peak-time.html https://www.digitalnewsasia.com/insights/how-lose-money-credential-stocking-stuffers https://rubica.com/wp-content/uploads/2019/02/Rubica-Report-Cyber-Crime-Privacy-Risks-in-Free-Mobile-Kids-Apps.pdf Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 40When we rush we make bad decisions.
Joe tracks the surprising number of malicious links hosted on legit websites and why it's dangerous. Dave describes an extortion scheme targeting podcasters. Our catch of the day involves a lonely Russian woman promoting a dating site. Dave interviews Gary Noesner, author of Stalling for Time: My Life as an FBI Hostage Negotiator. Links to stories mentioned in today's show: https://www-cdn.webroot.com/9315/5113/6179/2019_Webroot_Threat_Report_US_Online.pdf https://rebelbasemedia.io/podcast-review-extortion/ https://www.amazon.com/Stalling-Time-Life-Hostage-Negotiator/dp/1400067251 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 39Don't assume younger people get it.
Followup on last week's TLD discussion. Dave shares a sextortion scam with a tragic ending. Joe highlights conveyance scams that rely on certain days of the week. Our catch of the day features a wealthy Londoner hoping to pass on her fortune. Guest Dale Zabriskie from Proofpoint has results from their State of the Phish report. Links to stories: https://www.dailymail.co.uk/news/article-6744421/Army-veteran-PTSD-committed-suicide-targeted-prison-inmates-sextortion-scam.html https://www.todaysconveyancer.co.uk/main-news/law-firms-wising-up-conveyancing-scams/ https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/45597.pdf Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 38Delivering yourself to a kidnapper.
Joe describes fraudsters taking advantage of top-level domain name confusion. Dave explains how a Google Nest security system shipped with an undocumented microphones. Our catch of the day involves a postcard missed package campaign. Our guest is Matt Devost from OODA LLC describing their work protecting high-net-worth individuals. Links to today's stories: https://rebootcamp.militarytimes.com/news/your-air-force/2019/02/13/watch-out-for-fake-dod-websites-like-this/ https://nakedsecurity.sophos.com/2019/02/21/sorry-we-didnt-mean-to-keep-that-secret-microphone-a-secret-says-google/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 37Stop and think before you click that link.
We've got followup from a listener on cognitive dissonance and behavioral science. Dave shares a listener story about a University Dean's List scam. Joe shares statistics from a government agency phishing test. Our catch of the day involves funds from the FBI, the IMF, and yes, Nigeria. Dave interviews Crane Hassold from Agari with phishing trends they've been tracking, plus his experiences as a former FBI agent. Links to stories in today's show: https://fcw.com/articles/2019/02/11/cyber-phishing-oig-fhfa.aspx Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 36The trauma is multifactored.
On this Valentines Day edition of Hacking Humans, Joe and Dave examine romance scams, including the sad tale of woman bilked out of hundreds of thousands of dollars. There's a silly, non-murdering catch of the day, and Dave interviews Max Kilger from UTSA on the six motivations of bad actors. Links to today's stories: https://www.bbb.org/article/news-releases/17057-online-romance-scams-a-bbb-study-on-how-scammers-use-impersonation-blackmail-and-trickery-to-steal-from-unsuspecting-daters https://www.aarp.org/money/scams-fraud/info-2015/online-dating-scam.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 35Make it seem like the real answer is impossible to know.
Dave shares a bank spoofing scam with a reminder to mind those links, especially on mobile devices. Joe describes a case of someone turning the tables on a Twitter scammer. Our catch of the day involves a clumsy claim of physical harm. Dave interviews author Dave Levitan about his book Not a Scientist: How politicians mistake, misrepresent and utterly mangle science. Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 34The excitement of tricking someone wears off quickly.
We've got followup on bank scams and ransomware. Joe describes a highly sophisticated multinational business scam. Dave shares a story about private school parents falling for a Bitcoin discount scam. Our guest is Jordan Harbinger, host of The Jordan Harbinger Show, with insights on influence and social engineering. Links to this week's stories: https://www.cpomagazine.com/cyber-security/cyber-fraud-by-chinese-hackers-makes-headlines-in-india/ https://www.bbc.com/news/uk-england-tyne-46920810 Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 33Opening your eyes to the reality in which we live.
Dave reviews tips on protecting yourself from ransomware. Joe describes a clever way to trick people into enabling macros. An attempt at celebrity friendship is our catch of the day. Carole Theriault returns and speaks with Dr. Jessica Barker from Cygenta about effective training techniques. Links to stories mentioned: https://www.csoonline.com/article/3331981/ransomware/how-to-protect-backups-from-ransomware.html https://myonlinesecurity.co.uk/agent-tesla-reborn-via-fake-order/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 32Prisoners have nothing but time.
Joe shares the tale of a prisoner running a variety of romance scams from the inside. Dave outlines direct deposit scams. The catch of the day is a clever variation from (where else?) Nigeria. Our guest is Sam Small from ZeroFox. Links to stories: https://hubpages.com/politics/The-Games-That-Inmates-Play https://ogletree.com/shared-content/content/blog/2018/january/diverting-employees-payroll-direct-deposits-the-latest-wave-of-phishing-scams https://www.kansas.com/news/local/crime/article223873805.html Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 31Trained humans are your strongest link.
Dave warns of scammers gaining access to homes by pretending to be workers from the local utility company. Joe shares a story of a sophisticated bank transfer scam in the UK. Our catch of the day outlines an attempted email scam targeting an architectural firm. Carole Theriault is back with the second part of her interview with the pen tester who goes by the name freaky clown. Links to today's stories: https://www.wxyz.com/news/michigan-energy-company-warns-of-increase-in-imposters-trying-to-enter-homes https://inews.co.uk/inews-lifestyle/money/lost-19960-life-savings-phone-scam-natwest Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 30At some point you're probably going to have to do some running.
Joe describes a reply-all scenario gone wrong. Dave explains the criminal use of steganography in memes as a command and control technique. Our catch-of-the-day features alluring photos texted to an unimpressed listener. Carole Theriault interviews physical pen tester Freaky Clown. Links to stories mentioned in this week's show: https://blog.trendmicro.com/trendlabs-security-intelligence/cybercriminals-use-malicious-memes-that-communicate-with-malware/ https://www.cygenta.co.uk/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter

Ep 29Truth emerges from the clash of ideas.
We follow up on critical feedback of last week's show. Dave describes how online extortionists have pivoted from sex to explosives. We've got an auto-responding catch of the day from one of Joe's colleagues. Guest is Sean Brooks, Director of the Citizen Clinic and a Research Fellow at the Center for Long-Term Cybersecurity at UC Berkeley. He shares their research into online attacks of politically vulnerable organizations. From our EV certs follow-up: https://www.troyhunt.com/extended-validation-certificates-are-dead/ https://casecurity.org/2018/12/06/ca-security-council-casc-2019-predictions-the-good-the-bad-and-the-ugly/ Bomb threat catch of the day: https://www.zdnet.com/article/extortion-emails-carrying-bomb-threats-cause-panic-across-the-us/ Sean Brooks interview: Report: http://cltc.berkeley.edu/defendingpvos/ Clinic: http://cltc.berkeley.edu/citizen-clinic/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 28A pesky problem that doesn't go away.
Joe describes a Nigerian gang called London Blue that focuses on business email compromise. Dave shares surprising Cyber Monday phishing statistics. Guest Chris Bailey from Entrust Datacard teaches us how to detect lookalike sites online and better protect ourselves from fraud. Links to today's stories: https://www.agari.com/insights/whitepapers/london-blue-report/ https://www.zscaler.com/blogs/research/cyber-monday-biggest-day-cyberattacks-not-long-shot Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 27Bringing trust to a trustless world.
Listener follow-up on a URL issue. Dave describes an elderly couple scammed out of savings. Joe wonders if it's wise to unsubscribe. Guest Andre McGregor from TLDR Capital describes his work as a former FBI agent, and his experience consulting on Mr. Robot. Bank account transfer scam: https://abc11.com/troubleshooter-durham-couple-loses-$8900-in-computer-virus-scam/4782799/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 26Be very aware of your desire to be right.
Joe explains URLs and DNS. Dave has tips to prevent holiday skimming. A bogus bank barrister is the catch of the day. Writer Ben Yagoda explains cognitive biases. Links: Wikipedia page on URLs - https://en.wikipedia.org/wiki/URL Tips to prevent skimming - https://www.social-engineer.org/newsletter/social-engineer-newsletter-vol-07-issue-96/ Ben Yagoda's article from the Atlantic - https://www.theatlantic.com/magazine/archive/2018/09/cognitive-bias/565775/ Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 25CEOs can be the weakest link.
Listener feedback on the "Can you hear me?" scam. Dave shares an ongoing Elon Musk Bitcoin giveaway scam. Joe describes the malicious use of a compromised DHL email address. This week's catch of the day comes from down under. (Apologies to the fine citizens of Australia.) Carole Theriault returns with an interview with MimeCast's Matthew Gardiner. Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 24Human sources are essential.
Joe gathers open source information online. Dave wonders if a tow truck driver got the better of him. A listener shares a possible custom app scam. Former FBI agent Dennis Franks shares his experience developing human intelligence sources. Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.

Ep 23Scams are fraud and fraud is crime.
We get listener followup on the church pastor scam. Dave explores a phony investment web site. Joe explains phishing, spear phishing and whaling. Fake federal agents are featured in our catch of the day. Carole Theriault interviews Max Bruce from Action Fraud UK. Have a Catch of the Day you'd like to share? Email it to us at [email protected] or hit us up on Twitter.