Skip to content
TrackPodcasts
newsSep 24, 202650:28

404: scam not found.

Hacking Humans

Get every episode summarized

Each time Hacking Humans publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“All right, this is Hacking Humans Episode 404. Where each week we look behind the social engineering scams, fishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world.”From the transcript

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ alongside ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow up from Robert, who wonders why he’s never received a scam call in nearly 20 years of having the same Swedish phone number. Maria covers ACATS fraud, a little-known scam that can move stocks and retirement assets into fraudulent brokerage accounts without the victim realizing it. Dave shares his experience of nearly falling for a social engineering scam disguised as a podcast interview, where the scammers used convincing prep and a fake meeting link to try to get him to install malware. Joe shares the story of a Maryland woman who was nearly fooled by scammers posing as Wells Fargo and San Francisco police, using detailed personal information and threats of arrest to make the scam feel real. Our Catch of the Day comes from Reddit, where one person takes matters into their own hands after a scammer targets their daughter. Resources and links to stories: Several Big Brokerages Leave Customer Accounts Open to Theft, Senators Say Fidelity Money Transfer Lockdown: Block Fraudulent ACAT Transfer Brokerage Scams Protect Your Brokerage Accounts From ACATS Transfer Fraud Maryland woman says Wells Fargo, San Francisco police scam nearly fooled her with fake fraud case Person almost scammed my daughter so I decided to get in one fun and found their location ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠[email protected]⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.

Hosts & guests

Transcript ready

1,087 searchable segments. Every word is indexed and playable.

404: scam not found.

Hacking Humans

0:00
50:28

Full transcript

Hacking Humans — 404: scam not found.. Machine-transcribed; use the interactive transcript above to jump the player to any line.

You're listening to the CyberWire Network, powered by N2K. All right, this is Hacking Humans Episode 404. Oh, podcast not found. Right. Here we go. Hello, everyone, and welcome to the Hacking Humans Podcast. Where each week we look behind the social engineering scams, fishing schemes, and criminal exploits that are making headlines and taking a heavy toll on organizations around the world. I'm Dave Bittner, and joining me is Joe Carrigan. Hey, Joe. Hi, Dave. And our N2K colleague and host of the T-Mine is Space Cyber Briefing, Maria Vermazis. Maria. Hi, Dave, and hi, Joe. We've got some good stories to share this week, but first, we've got some follow-up. What do we got here, Joe? Dave, we got an email from Robert. It came in a couple weeks ago. Hi, Hacking Humans, and thanks for the show. I often hear you talk about what a pest scam calls are.

And that's a thing I often hear from Americans in general. I'm Swedish, I almost said Swedish. I'm going to refrain from doing the silly acts on Swedish. Yeah. And the Montipythan jokes, I'm sure he's heard them all. Now I have to go look up Swedish Montipythan jokes. I haven't seen that one. Maybe I have, I just don't remember it. I have had the same mobile number for almost 20 years, and could say with some certainty that I've never gotten a scam call to that number. I mean, literally zero times. Wow. As much as I'm grateful for that, it makes me wonder how this can be. Of course, Swedish is a comparatively tiny language, which probably shields us from a lot of scam attempts because it's not worth the trouble to try targeting us in our own language. But most of us are pretty decent at English. So that can't be the whole reason. And of course, there are also Swedish speaking scammers. Do you perhaps have any idea why this difference can be so big between the two countries?

And before we get to the answer here, I want to, he says, by the way, I enjoy the Duke silver reference a few episodes back. Because ever since I started watching parks and recreation, this is how I picture Joe. Yeah. And it says, no, no, no, I sloped just my own sloppy gimp work. Gimp is an open source version of software like. Yeah, like Photoshop. Yeah, yeah, yeah. And it's a picture of Ron Swanson sitting at his desk in parks and recreation. The claymore is there, but he's got a. Robert has photoshopped or edited a cowboy hat on him. And he's got two chickens on his desk. One of them is a chick. Yeah, one is a full ball. And yes. And a big Maryland flag right in the middle of the country. A little bit of a black flag with the backpack in the background. I say attention to detail is high. I think it's the ball backpack that you have. It is. It's the wrong color, but it is the model.

Yeah. Wow. Good job, Robert. Yeah. There is also another chicken in the background. Yeah. And he's changed one of the pictures to bacon and eggs. Wow. So let me just say, first of all, say that. My family on my mother's side are all Swedish. Are they? So yes, yes. So I don't know how that's affected me over my life, but I do remember. For example, my parents would not or my mother's side. My mother or my grandmother would not refer to cheese as being Swiss, Swiss cheese. They would say switzer. Switzer. Yeah, they'd say switzer. So we're going to get some switzer while you're there. So I don't know. I might. And I assigned that to the Swedish heritage. I might be all wet on that. Who knows? Right. Well, I think it's Germanic. I think. Yeah. Yeah. Yeah. Yeah. You know, Swedish switzerland and German, of course. Yeah.

All these languages are very closely related. Actually, still so closely related that if you speak one, you can almost understand the other ones. Kind of like Spanish and Portuguese. They're not that far removed. Again, I'm kind of a linguistics nerd. So I have all this crap in my head that I'm ready to just spew out. All right. Well, let's get to the answering the question. Yeah. Why does Robert not get that many scams? I think it might be that there's not a lot of Swedish speaking scammers that they just don't want to call into the country because they don't think there's a big ROI on the time. I don't know. I want to say because freedom. Freedom? Yeah. Oh, yeah. Yeah. We're an amazing sample size, right? We've got the cross section of just about everybody and there's a lot of us. Yeah. So if you're the largest country in population and land mass, deregulated, deregulated up the wasu or down the wasu, whatever. And yeah, if you're looking for a subset of the human population in general, they're here

in the United States somewhere. So you can run an incredible experiment. That's a good point. Yeah. I think there are many reasons that this is the case, but I wonder if Sweden just has their system locked down. Their system might be locked down. That's a good point. I wouldn't doubt that at all. Yeah. That would make sense. I would like to talk to somebody from Estonia to see how many scam calls they do. They get because they do cybersecurity over there. So well. So well. Oh, yeah. Like, if there's a country that you could pick on the globe that doesn't, that does as a country, as a nation that does cybersecurity, the best it would have to be Estonia. You think? Yeah. But also their IT in general, just really amazing. I was an awe. I'm really quite amazed. Well, thank you, Robert, for sending in the kind words and taking the time on the picture of Joe. I have to say it's pretty close. It is. It's pretty close. That mustache is right on. I have a beard right now, not really a mustache. And I cannot grow the ronswans in mustache that what's the actor's name?

It's slipping my head right now. The guy that plays ronswansen. Yeah. I can't remember his name. I can't, I just can't grow that mustache. Yeah, I can. Can you? Oh, yeah. Nice. Yeah. And he's also still have a full luxurious hair head of dark hair. And I have a thinning mat of gray hair on top of my head. Not to brag, but if I worked at it, I could probably grow a mustache like that. That's the Greek genetics. Probably. I haven't tried it. It's amazing. Heritage has its ups and downs. It does. We are a swore-to-herry people. It's true. And that's the name. Oh, over the actor's name. Halfway through the show. All right. You'll just blur it out when it comes to you. All right. We're going to take a quick break here. We'll be right back after these messages. And now a word from our sponsor, Threat Locker. AI coding agents are writing code and reaching outside systems, often without human approval.

OOS calls that risk excessive agency. Threat Locker helps fix it, giving every AI agent only the access it needs, controlling what it can run, touch, and reach on your network. Threat Locker offers ready-to-deploy policies for popular, agentech AI tools. Learn more during our next break. And we are back. Let's get to our stories here. Maria, you have the honors this week. You want to start things off for us? I sure do. So, this one, the headline is the crime that usually happens quietly. That was dumped through the New York Times. This story actually comes to me from a person who I am usually recounting scams to in an effort to help protect her. But in this case, my mom sent me this story. And I never heard about it. So shout out to my mother, genuinely. Because when she messaged me about this not that long ago, I went down the rabbit hole

looking into it and I was honestly kind of shocked I hadn't heard about this. So I figured I would spread the good word, but credit to my mother first. This is something that is going to be of primary interest to our U.S. audience. So apologies to everyone else outside of the U.S. but this is just of interest in general. It is called an ACATS or automated customer account transfer service fraud. Have either of you ever heard of either ACATS or this kind of fraud? This is like slamming back in the day with a long distance service where you just get, you know, somebody calls you. They said they spoke to you and then they transfer your customer service, your long distance service. I think I see where you're going and maybe, yes, I think. Wow. I heard of ACATS. Yeah. I have not. I wouldn't have been, if you would ask me what ACATS was, I don't think I would have been able to tell you. Same. I'm familiar with the mechanism. I didn't know this is what it was called. So the ACATS is basically, this is a financial thing.

This is the mechanism and I'm summarizing this very high level. The mechanism by which a brokerage firm think like fidelity or vanguard transfers brokerage, like ETFs funds from one to another. So say you are rolling over your 401k from one brokerage firm to another. Like you change jobs or you're just going, hey, I don't want my 401k over at this group because this other one I found has fewer fees. The process to move that money over is ACATS. That is my understanding of what that is. So if you've ever moved money, that is not like banking money, but actually ETFs or brokerage stuff. In other words, for a lot of us, literally our retirement savings are life savings. If you've ever moved them from one firm to another, you used ACATS. That's what that mechanism is. So the fraud itself is relatively obscure. It's not brand new. It's been going on for a few years now, but it is increasing in frequency.

And it's essentially a financial account takeover scam that can drain investment and retirement accounts without ever touching a bank account and we're still without the victim even knowing about it until it is too late. Not to freak people out, but I honestly got a little freaked out when I learned about this. So that's why I wanted to share it. This does not start with your account getting hacked. So that's sort of the reason my mother reached out. She's like, have you heard about this because you don't get hacked when this happens? It starts when your identity is stolen because all you need as a criminal is basically your name, phone number, mailing address and social security number to start the fraud. And I don't know about you, but I'm pretty sure all that information of mine is out there. Yes, in the most recent data breach. Yeah, I mean, I can't countless times. It's been breach in my case. And I'm sure for most of us listening at this point. Two weeks ago, I was talking about the one that Brian Krebs found. All that information is in that data breach. Yeah, so at least once.

Right. It used to be that if you wanted to move money from one brokerage firm to another, I actually remember doing this like 25 years ago, you had to write a letter and send a check and wait weeks and weeks and weeks. The vacats process has sped things up significantly where essentially you go to the new firm that you're moving money to, hey, I want you to pull money out of my old one. So the new firm goes, I'm not going to pull money out of your old account. And essentially the criminals will pretend to be a new firm pulling money out of your old accounts. Because this is essentially a largely automated process at this point, unless you know about it happening and stop it in the moment, there's nothing really going to, there aren't many speed bumps slowing a criminal down from pulling that money out, say to a fake e-trade account that they set up in your name. So once the, once the fake account in your name is open and again, it doesn't take much information or verification to do this in many cases. The scammer submits the ACATS transfer request.

The receiving brokerage like it, again, the fake account asks to move the investments over to the, to, from the real account to the newly opened fake one. And that transfer looks legitimate because these account transfers happen all the time. And the account names and personal information will appear to match because not much information again is needed to do all this. As I mentioned at the top of my story, the victim often will not know this request was made. And once the assets are moved from the real account to the scammer account, then the scammers can essentially do whatever they want with your securities. They can move it to cash and then they can just disappear with the proceeds. So this freaks me out when I learned about it. And as you might imagine with the, this kind of scam being rare, but increasing, we have, in the US Senators Elizabeth Warren and Ron Wyden are actually pressing regulators to require stronger protections within major brokerage firms to put in some better safeguards that are at least consistent across the industry because it is super inconsistent about what

kind of protections consumers have. So for example, fidelity and vanguard, which are two huge brokerage firms. Thankfully they offer very easy self directed features that do let customers block these transfers. I actually set this up this morning. I was looking into this because I was like, oh my God, you go, you log into your account if you have fidelity or vanguard and there's like a security section of your profile and there's, there's a very easy option that says basically turn on account locking. And it's just like, you just do it and it's done. But other firms, according to at least this recent story from August from the New York Times says JP Morgan Chase Robin Hood, Weeble and Wells Fargo, in order to put this kind of account lock on, you have to reach out to customer service and then the customer service has to enable it for you. So not super difficult, but it's a little more manual. It's not a matter of just logging into your account and setting it yourself. You got to make a phone call or maybe use a chatbot, I don't know. And then there are other, I'm not going to get into like every single one, but it's just

again, not consistent. And in some cases, putting this account lock on will stop an ACATS transfer and others, it will stop all kinds of transfers, including maybe ones to external banks. So if you're trying to do a withdrawal, it'll stop that too, not super helpful. So that might be why you don't want to put this kind of lock on. In any case, it's not across the board. And in other cases, the senators found and their staff, I should say that some firms also don't notify their customers when their assets are being transferred out. Some do, some don't. So in that case, if you're one of those don't folks, you don't even learn that you've lost your life savings until it's already gone. Which again, made my blood run cold. Yeah. Yeah, because again, this is most people's retirement savings are in firms like this in the United States. So the lawmakers are pushing for Finraw to do more and require automatic alerts whenever an outgoing transfer is requested. And a requirement that customers explicitly approve transfers through an automated login

session before assets can leave an account. So that would be nice. So this is one of those things like if you're an American who is concerned about this, I imagine, as I said, I didn't know about this. You can reach out to Finraw or your senators and go, hey, I support this kind of regulation being put into effect. Let's do this. Reach out to your brokerage firms if you use them and figure out how you can lock this down for yourself. But I was, as I said, I went down the rabbit hole with this and I found a Reddit post from four years ago on the Fidelity subreddit before Fidelity put the locking mechanism in place. And this person basically went, hey, so I just found out $150,000 from my life savings were just disappeared through an unauthorized transfer. What can I possibly do about this? I never found the update about if they got help for that. But I mean, that's, can you imagine just waking up to 150K from your life savings just gone? Yeah. Yeah. Yeah. I mean, it reminds me, I mean, this is something that I think Joe reminds us of all the time

here is like, who should be liable there? Yeah. If you didn't do anything, and the person you've trusted with your money loses it. I shouldn't that be there for all right? Yes. Right. Yeah. I'd be showing. Yeah. And honestly, I think some of the advice that they got in that thread was you need to get a lawyer right away. But it is, it is great. Like I almost, I almost, almost feel bad for financial institutions. And I said, almost because I'm sure this action was in response to consumers going, hey, transferring my assets from one brokerage to another takes weeks and I don't like that. And then so the financial institutions went, we'll figure out a way to make it faster. Isn't that great? And now it's so fast that scammers are going, well, that's awesome. We can steal money from right underneath people's noses without even them realizing it so quickly that they can't even react. So terrifying. So what listeners in the US need to know and potentially other countries, I was trying to figure out if this also applies to our Canadian friends.

I know that their retirement accounts are different, but I know that some of these financial institutions like Vanguard do have Canadian equivalents. So potentially also to our Canadian listeners also, if you have any kind of money in a brokerage, you need to check and see if your account has an ACATS transfer lock or account restriction feature. I should note they are off by default. So again, that's also crazy to me. Why are they not on by default? They're off by default. So you have to go turn them on if they are available to you. I would also advise that basically any alert imaginable in your profile about, hey, money is moving, you should turn that on. You should absolutely turn that on anytime anything in your brokerage is moving in any direction. Be very aware of major identity breaches because again, nobody's hacking your financial account to do this. They don't need your credentials to do this, but all they need is your basic identity info, which again is probably already out there. It is always a good idea to lock down your financial accounts with like two FA, strong,

unique passwords, all that good stuff. Just be aware if you start seeing any kind of noise about a new breach that is affecting you, increase your vigilance. Of course, if you ever receive notice of an account transfer or a login that you didn't request, anything like that, anything even mildly suspicious, get in touch with your brokerage right away. I mean, just take a moment to protect your life savings on us. Because this scam targets brokerage and retirement accounts, which again, I just cannot believe this. I didn't know that your portfolio can be moved super easily without the right controls in place. I took a moment to enable these locks. I highly encourage you if you have these kinds of accounts to do the same. I wonder if on the flip side of this, is there a no-your-customer element of the people who are setting up the fake accounts in your name? You think about like the breach we were talking about recently with all the driver's

licenses. You have an image of someone's driver's license along with their social security number, their address, their phone number, their date of birth, all of that. What else do you need to set up an account online? How do you enhance know-your-customer rules to protect against that? It feels like an impossible arms race at this point. We need and want things to be more convenient as the people who own our money. I just think of this as my life savings as a physical, if it were like a physical thing. I wouldn't want someone to just go, hey, I want Maria's life savings and put it in this duffle bag. I'm just going to walk out of here. I want them to slow down. I want the armed guards. I want the fancy armor truck. I don't go ahead and say this. I do not want this level of speed when I'm rolling over retirement accounts into other accounts.

I just don't want that. Same. But some people clearly do. Well, okay. I mean, how often do you change a brokerage account? You make a good decision on a brokerage firm. You stay with it, right? Yeah. Until, okay, maybe this company does other things that I can buy and I want to move some over there. And then go ahead and do that. But don't be, take the time to do it. This is who asked for this. And I imagine Maria, you're right. Somebody did ask me. Somebody did. When I rolled over, when I left J.U., I had a 403B there and I rolled it over to my IRA. And that was a long and arduous process. And I was happy that that was a long and arduous process. I had to go get documents notarized. At the library, my wife had to agree to the transfer. And they sent a check, but they sent it to a brokerage house. Which I guess they could do in this case as well if someone was being fraudulent. But it took a while.

As it should. And I'm with you. I want this to be slow. And I'm completely with you on this. And I also want to emphasize, this kind of fraud is very rare. This is not like this is going rampant. But it shouldn't be happening at all. Yeah, not yet, exactly. It shouldn't be happening at all. And I am sure our listeners who work at financial institutions are saying, we have a whole bunch of fraud detection stuff that we can't tell you about because we know about the sort of thing. I'm sure there are ways that they tap the brakes internally. That said, there are things that for most of us that we can do to also help this along just low things down and tap the brakes. So I just wanted to put that information out there because I didn't know. So thanks, Mom. Yep. Yeah. Thanks for making a mom. Thanks for making a mom. I'm going to make a mom. Change is on my accounts tonight. Yeah, take it. Yeah, there you go. Me too. All right. All right. Well, we will have a link, a bunch of links that Maria's helpfully put in here about that in our show notes. My story this week actually was sent to us by a listener who said, Dave, have you seen

this? And I said, no, I have not. Please tell me more. So they kindly sent a bunch of screen captures. This centers around a journalist named Joan Westenberg who got booked on a podcast. Imagine that. What? Who goes on those? You're right. What a waste of time. Right. Yeah. Got booked on a podcast and posted on threads that I'll just read it here. They say the podcast I was booked on turned out to be a social engineering scam to get me to install malware. Their prep was impeccable with better interview questions than most journalists. Well, I take issue with that. Yeah. They haven't met. She has met Dave Pittner or Maria. No. I was going to say they just, they just used some AI to just fawn all over you. They didn't ask you the hard questions. That's right. That's right. I'm going to say then the join link asked me to run a terminal command to install their

webinar tool and I bailed immediately. Yeah, that's good. Yeah. So, so let's pause there because we have a bunch of campaigns. This is something that's been running for, I don't know, about a year now. This, this click fix campaign is what it's called. Right. And it's where the bad guys trick you into copying, copying and pasting some code, some instructions, and commands into your computer's command line interface. Be it a Windows machine or a Mac, I guess Linux too, right? Yep. Yeah. And they make it seem as though it's just routine. This is something we need you to do to verify or copy or whatever. But when you do this, you get malware on your system. Right. And that's exactly what they're doing here. They're saying, in this case, they're saying, oh my goodness, I don't know why our eyes are zoom not working. Well here, just run this command and it'll install our custom webinar tool and all will be good and we'll have you on our podcast in no time.

So that's part one and good on Joan for bailing immediately. But it doesn't end there because when Joan bailed, they sent screenshots of themselves on the call to apply pressure. Hey, where are you? We're waiting for you. We booked you on this podcast. We really want to hear from you. Why are you letting us down? Why are you wasting our time? Does that work with guests? Should we try that? No, it's kidding. And goes on and says, never ever install custom software for a meeting or a podcast. Mm-hmm. Every one of these things has a web client that you can just go to a website and record. And if they're not using that, then even if they're legit, I wouldn't do a podcast. Yeah. Yeah, I have to say there, I'm thinking of one, I can't think of it off the top of my head which one it is, but there is a, it's not a podcasting or just like a zoom platform.

It's actually a webinar platform that requires you to have an app. Yeah, there are a few of those. That I have been a part of. So they do exist, but that's a higher end thing that hopefully you're going to know what you're, but still, I mean, is that a case? Is that your, I'm sorry. No, no, in this case, these people, they just seemed like they were legit podcasters. Right. They're on camera. They're, they have the infrastructure. They're saying all the right things. So how would you know what we're saying, Joe? I was going to say, is that app that you had for hosting or for viewing the webinar? For me, it was hosting. So anyone viewing the webinar could do so through a browser, but if you were a host, which is in my case, you know, what I wasn't in this particular instance, then yeah, you had to have an app to be able to have certain, you know, whatever, executive functionality whatever you want to say. There was some follow up when Joan posted this to Threads.

Somebody said, hey, this is exactly how a friend lost a Facebook group with over a million followers. Someone else wrote and said, wait, this just happened to me. I thought it was overreacting because they sent me a weird link and wanted me to download something while setting up a Facebook live event. So this is making the rounds and just I'd say be really careful if someone's asking you to be a guest somewhere or really any situation where they're trying to get you to log on to something and they tell you to install something or run a custom bit of code or copy and paste something into your terminal. That's a very good way that something's going on. Just be wary because these are making the rounds. Yeah. And the URL for the, which I won't repeat, but I'm just looking at the URL that she was given. And even the URL, which is definitely fraudulent, but it's made to look legit with the way that they laid it out. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah.

Yeah. Yeah. Right. They've structured it. It's real sneaky, real real sneaky. Yeah. Yeah. All right. Well, we will have a link to that thread's thread, I guess. It's, it's, there are things on threads. I'm not on threads or things on threads called threads. That would make sense. Yeah. What is threads? It's threads the meta solutions. Yes. The meta version of Twitter. I think so. Yeah. I'm not on any either. I'm not on that at all. People I love are. So, okay. All right. We'll have a link to that. So if you want to check out this thread and your on threads, you can do so. Let's take a quick break here to hear from our show sponsor. We'll be right back after these messages. And now a word from our sponsor, Threat Locker, the workplaces of Alving, AI coding agents are already writing code, managing files, and reaching outside systems on their own,

often without a human approving every step. OOS calls the risk that comes with that excessive agency, an AI agent with more capability than its task actually requires. Threat Locker helps organizations enforce the fix instead, giving every agent only the access it needs and nothing more. That means controlling which programs an AI agent is even allowed to run, restricting what it can touch once it's running, files, other applications, sensitive data, and locking down which systems and websites it's permitted to reach on the network. Threat Locker has even published ready-to-deploy starting policies for popular agentegei tools, so your team isn't building these controls from scratch. Adopting AI doesn't mean giving up control of your environment. Learn how to apply zero trust to agentegei at threatlocker.com slash hh. And we thank Threat Locker for sponsoring our show.

And we are back. Joe, what do you got for us? I got a local story, Dave. It's from Ashley Hinson up at WBAL. Okay. Do you know Ashley? I do not know Ashley. No. No, me neither. Okay. Never a matter. Anyway, the headline of the story is Maryland woman says Wells Fargo, San Francisco police scam nearly fooled her with a fake broad case. Huh. So it's a long one or long headline. The story is actually not that long, but there's some interesting things I'm going to focus on in here. It starts with this woman named Lauren star who Lauren, thank you for coming forward. We really appreciate you talking about this and getting and talking to a news broadcast or giving this story reported. Everybody should know about this and more people to talk about it. The less often this will happen to people. But it began when Lauren received three consecutive calls from an unknown number. Okay. Now, if you get one phone call from an unknown number, you'll ignore it. Two, okay. Three, okay. Now somebody is really trying to get in touch with me.

And Lauren thought exactly what we all thought. She said this might be an emergency involving her family. So she answers the phone. And the caller claims to be from Wells Fargo's fraud department. Of course, that was a lie. The lia is of course continue. And this caller says, someone has opened a credit card in your name. And the card has been used to purchase thousands of dollars in guns and ammunition. Damn. So America. Right. Immediately my response is, okay, this is not my problem. And also, I mean, aside from the fraud here, this guy's done nothing illegal. It's perfectly legal in this country. It owns tons of guns and ammunition. Thousands of dollars in fact. Can we put in a bald eagle screech that's actually a red-tailed pop screech? Yes. Yeah. This is America. I think the battle him of the Republic underneath of the judge. What I'm saying. Okay, sure. Anyway. Then this caller says this bald face lie. If you're from Wells Fargo, Wells Fargo would never say this to you.

The card cannot be canceled until you file a pollution port in San Francisco. Because. What? That now here's why because Lauren said the scam felt real because they had so many details and this is a quote, they were very convincing, gave me the actual credit card number and an address in San Francisco where it had been delivered and the application date. So apparently they have a bunch of information. Well, it couldn't all of that be made up. No, this all matched up with what? With Lauren. With her existing credit card. Someone had a Wells Fargo credit card, the gave her the credit card number. They knew it had been delivered to San Francisco. Oh, I see. Okay. I'm going to know. And they had the application date, which I guess they could have approximated. But. Okay. And if somebody said you applied for this card on this date, I would look and see my look at my card and go, it says I've been a member since three months after that. So I guess I applied for it. Anyway.

It doesn't matter where your card was sent. If you call your credit card company and say, I need to cancel this card. Somebody's gotten access to it. They can do it. Yeah. Right. Sometimes they just do it on their own. Right. Wait a minute. This is for. This is for the mail and you're like, what? Oh, yeah. This is for a fraudulent account that somebody somebody opened in her name. So maybe they're just saying it was shipped to San Francisco. Yeah. So I'm sorry. Maybe I'm this, I'm confusing this here. So you know, if Wells Fargo calls me and says, hey, somebody opened a credit card in your name. I say, I didn't do that. Close the card and they go, well, we can't do that until you file a police report in San Francisco. I'm not doing that. This is not my problem. This is a Wells Fargo problem. Have a nice day. Please don't bother me about this again and don't send me a bill. That's going to be my attitude. But I'm a jerk. So. Um, um, large in the situation quickly escalated because they then transferred her to a man claiming to be a San Francisco police officer.

Oh, congratulations. You've just added another felony to your list here, guys. They Wells Fargo has the, the SFPD on speed dial. Right. Yeah. Yep. They can just get you over there and get you in touch with, uh, officers to then go right away. Right. Um, there's a very old 1970s reference for you. Uh, the man who she's speaking to, pretending to be a police officer, questions her, then moves the conversation to WebEx, which is interesting that they move the conversation to WebEx. That's probably so, uh, Lauren can see that this guy is wearing a, uh, funny baloney police outfit. WebEx is, um, Cisco's, yes, conference. It is now the one that nobody uses. Uh, yeah. They use it where you go to school. You have to say, nobody uses it unless they have to. Right. Yep. And I didn't saw the WebEx app. So, uh, just makes it easier for class because I have one class that's online. Yeah. Um, and then the, they, this guy claimed her information was tied to a federal money

laundering case. Uh, all right. Now, the moment I hear that, I go, okay, time for me to lawyer up. Right. Uh, she sent her, uh, the, the cop, this pretend cop sends her fake police files and says, don't tell anyone, um, threatening that she could be jailed and, uh, extradited to California. Now, this is not how this works. Uh, the cops cannot tell you to not tell anyone a judge needs to put a gag order on that and that's usually on the case. It's in progress, I think. Again, we should have been on here, but you are always entitled to go talk to your lawyer about this. That I do know. Uh, so if you, if you need to have a lawyer and somebody and a police officer says, don't tell, don't go talk to your lawyer because we'll extradite you to California. That is probably not a police officer. No police officer would ever say that to you. And if they did, they wouldn't be a police officer much longer, uh, at least that's the hope. Uh, so there's a good quote in here from Lauren says, I was thinking of all kinds of thing. Oh my God, I have two dogs. I have to get my daughter from New York.

Where can I get a lawyer to deal with the federal cases? Oh my God, I'm not guilty. This is a quote. Uh, I'm, what's going to happen here? I think, uh, I think they do this purposefully to get you disoriented. So yes, that is exactly right. And Lauren is documenting this perfectly. She is, this is exactly the kind of response you're trying to instill in you. They're trying to shut down your critical thinking and activate your amygdala and get you into the flight or flight or flight response response again. Same. I, same promise. That last week triggered in you every time you try to say that phrase. It does. Um, yes, yeah for F. Uh, and once they've got you out of critical thinking mode, they hope to get you under the spell. Uh, I like the, the, uh, psychological hostage analogy. Yeah. That's what they were trying to implement here on Lauren. Fortunately, Lauren realized it was a scam before giving them any critical information, but she worries of vulnerable adults might not be able to recognize the warning signs. And vulnerable here could be anybody.

Yeah. We've seen this, this kind of thing work on people who are younger. Uh, they just call you, pretend to be a cop and, uh, accuse you of all kinds of horrible stuff. And, you know, your first response at any of that stuff is first, the cops, if the cops have information on you enough to arrest you, they're going to come and arrest you. Yeah. You're going to get a warrant and they're going to show up. Right. They don't call you your own. Right. We're going to give you a countdown to three. Yeah. Listen, before we come and arrest you, we just want to make sure you're home. Maybe, maybe the, uh, handle this when they call us go, oh, yeah, that wasn't fraudulent. I got all the guns here. Come get them. Um, um, Mulan Leibay. Oh, no. That's Greek. Um, not, does that mean does that actually mean come and take the marium? Yeah, but that's not how you pronounce it. So that's how do you pronounce it? I don't want to do this. I don't want to do this. I don't want to do this because ancient and I'm going to get like the people who speak

the different versions of ancient Greek yelling at me. I only know the modern Greek pronunciation of the ancient Greek that my dad taught me. So, and he's dead. So you can't yell at him anymore. Okay. So what is it? I was taught from my Greek speaking native Greek dad, Mulan Leibay. So, um, well, I'm glad I said I don't know. I can't even remember, but it's not lab. Right. Well, I am, I am not anybody with a Greek background. And also they died just just for the record. They died. I people forget that. It was the last day in the big guy. Right. Just to be clear anyway. Well, we still remember the Alamo and everybody died there. It's just like they didn't win that one, guys. I think I think they did win that one, but they all died. Yeah. Okay. So they lost the battle, but they won the war. Oh, no. Oh, no. So we'll have a link to Joe's story in the show notes.

Oh, Ron. Joe Maria, it is time to move on. Thank God. Thank God. To our catch of the day. Dave our catch of the day comes from the R slash scam baiting subreddit. This is a long one. So we probably don't want to use the whole thing, but it's called person almost scanned my daughter. So I decided to what? Yeah. The title is as long I decided to get one to get one English is a little wonky. They just they decided to kind of turn the tables on the scammer essentially. I almost scanned my daughter. So I decided to get in one fun. Get in on the fun. I think is what that meant to say. And I found their location. It's very it's actually very creative. But yeah, don't mess with somebody's kid. So. So I made a lead this one off Maria.

Yeah. Maybe the daughter. Yeah, I'll be the daughter. Sure. All right. Here we go. I'm still looking for a babysitter for my child. And I'd love to know a few things before we proceed. First, may I ask, where are you currently located? Moro, Georgia. Where are you living? I have a car so I can drive no problem. Here's my address as well. I'd appreciate it if you could let me know whether you're familiar with the neighborhood. Are you familiar with the area? Yeah, sure. And you live right down the road for me. I'm a parent of two lovely children. And I'm searching for someone with a big heart who truly enjoys being around kids. I'm a parent with two lovely children. And I'm searching for someone with a big heart who truly enjoys being around kids. The role is all about caring for them with warmth, patience, and genuine attention, whether at home or during little adventures outside. I know. I really want to do a Casey Kessum voice. Oh, I think you should do it. You should totally do it. I'm a parent with two lovely children. And I'm searching for someone with a big heart who truly enjoys being around

people with warmth, patience, and genuine attention, whether at home or during little adventures outside. Yeah, you live right by the daycare. Why don't you send the kids there? I want the kids to be taken care in my home. I'm new in the area. I clipped a few of the the bits here because it's a really long one. And it goes on to say, I'm available all the time. If you guys wanted to go on a trip, I could watch them so you could have couple of them. Okay good Monday to Friday, 9 a.m. to 5 p.m. Is that okay? Explanation point. It is. Absolutely. Along with hourly pay, we also offer a holiday bonus and a small shopping allowance as a thank you during the season. Please feel free to share your hourly rate and whether this sounds like a good fit for you. 12 to 15 presumably dollars per hour. I want the best care for my daughters. $20 per hour. Is that okay? Nobody ever does this either. Yeah. I want to pay for your own childcare.

We were also hoping you might be able to assist with a few small party details. We would provide the funds in advance. Oh, there it is. And you'd only need to pick up the items and bring them along when you come, okay? Alrighty. To help us plan better, could you let us know how close you are to places like Walmart, nearby shops or gas stations? That will make it easier for us to decide where to purchase some of the supplies. You can birth the supplies in a gas station. It's gonna be a worth birthday for you ever. I need a pay or five gallon jug of gas. Yeah. I want to get my kid a slim gym. I mean, I'm pretty close to you. I can easily run to Walmart or gas station. Okay, good. If you're available, the items we need help picking up include blue helium balloon party poppers, Xbox gift cards, milk chocolate. Thank you so much. No problem.

If everything feels like a good fit, we'd be very happy to continue working with you on a regular basis as our sitter. Sounds good to me. Would you happen to be available to gather the items today? We'd love to have everything prepared ahead of our arrival, so things go smoothly. Sure. I could do that. How would you send the money? I know if you could do money transfer or money order to Walmart since I'd already be there. Please let us know if you're comfortable doing this. We'll of course cover all costs. If it's easier for you, we can arrange payment in advance by check. By check. Or we can reimburse you in cash when we see you, whichever option works best for you. Okay. They are prepared to do either just take gift cards or do a check floating scam. Yep. These guys are diversified. They are. It's impressive. Transfers through Bank of America. I don't have debit card or credit card to place and order online. That why we want you to help with this. No, I meant you can send money a check to Walmart so I can pick up the money.

It would be immediate transfer. No hold. Walmart won't even look at the check just deposit it. Walmart doesn't take check. Walmart can cash a check for a small fee. No, that cashier check. My husband don't use that. Mobile deposit you'd be making via your Bank of America mobile bank app. Brilliant. She has for or whoever has done this has forced this person off script and now it's all coming out. Yeah. They've broken away from the from the chat. Yeah. Yeah. I could send you my login and you could add the check yourself. I taught you have Bank of America. I do have Bank of America, but they take so long to add the check in with the holiday happening. It's low stuff down. Okay, my husband, we do that for you. It's like this person turned into a caveman. Oh, God. That's right. Simmons looking forward to your reply. Yep. So I should there. Now the person I am reading for has sent a tiny URL, a shortened URL with what appears

to be credentials, a username and a password. Okay. Is that your username at the up? Yes. Okay. Good. Is Sabore a good place to eat or sketch cafe? Anyone. Your husband take you to Oma the spa. Like I said earlier, I'm new in the area. I would love you to take me around when we arrive on Wednesday if you don't mind. Yeah. You are from Iterian, right? What do you mean? That's where you're from, right? In Sabore. Can I have your picture from Stockbridge? Have you been there before? And then there is a picture of what appears to be I would just generalize a West African man waving at the camera. Right. And the response is Stockbridge isn't far from Maro. And okay, I let it trail off from here. Because the language then switches to Yoruba. And apparently the words that are exchanged in Yoruba from this point on are not nice words.

The jig is up. The jig is up. Yeah. So I want to explain when I said, hey, a URL has been sent at this point with credentials. This is something that the scam baiter said. They sent a link through something called Grabify. And then when the scammer clicked on that link, it took him to a fake login page for Bank of America. But when he clicked it, the scam baiter was able to get the scammer's IP address and location and even what phone he was using. Oh, wow. So that's how they narrowed down. Oh, smart. So in the thread, they found that the guy was in Lagos, Nigeria. Not in Georgia. Not in Georgia. So yeah, that made me chuckle. I really liked that thing. Wow. How the turn tables? Yes. Right. All right. Oh, that was a fun one. Yeah. All right. So the show notes, and again, we would love to hear from you. If there's something you'd like us to consider for our catch of the day, you can email us.

It's hackinghumans at n2k.com. A tell you what, let's take one more quick break here before we wrap things up. We'll be right back after these messages. Thank you to Threat Locker for sponsoring Hacking Humans. Turn up for a free demo today and see how you can implement a default deny posture at your organization by visiting Threat Locker.com slash HH. And that is our show brought to you by n2k CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights to keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to hackinghumans at n2k.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Iban.

We're mixed by Elliott Keltzmann and Trey Hester. Peter Kielpie is our publisher. I'm Dave Bittner. I'm Joe Nick Offerman played Ron Swansea. I'm Sarah again. And I'm still Maria Vermauses. Thanks mom. Thanks Maria's mom. Thanks for listening.

More episodes

More from Hacking Humans

View all episodes →