engelsk
Nyheder & politik
Begrænset tilbud
Derefter 99 kr. / månedOpsig når som helst.
Læs mere Hacking Humans
Deception, influence, and social engineering in the world of cyber crime.
772 episoder
SLAM, scam, thank you ma’am.
This week, while Maria is on vacation, Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] and Joe Carrigan [https://www.linkedin.com/in/joecarrigan/] are joined by Michele Kellerman [https://www.linkedin.com/in/michele-kellerman-cissp-b2933378/] as they discuss the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Dave brings us a lively follow-up from his recent theater outing the conversation circles back to chicken talk. Michele also highlights the work of Blood Cancer United [https://pages.lls.org/voy/ma/ma26/mkellerman] sharing insight into their mission and impact. Dave’s story is on the SLAM method, a simple phishing-defense framework that teaches users to evaluate suspicious emails by checking the sender, links, attachments, and message for common signs of deception and social engineering. Michele’s got the story on a potential turning point in online scams, where rising pressure—from revelations that Meta Platforms has profited from fraudulent ads, to banks and regulators like Jerome Powell and Scott Bessent warning about systemic risks—suggests liability may soon expand beyond banks to include social media, telecoms, and other upstream players. Joe’s story is on two cousins, Shray Goel and Shaunik Raheja, who pleaded guilty in a nationwide $8.5 million scheme using fake listings, double bookings, and last-minute cancellations across platforms like Airbnb and Vrbo to maximize profits while deceiving thousands of travelers. On our catch of the day, A Reddit user shares a message they got from a scammer posing as their child. Resources and links to stories: * SLAM Method for a Comprehensive Phishing Prevention Guide [https://www.picussecurity.com/resource/blog/slam-method-for-a-comprehensive-phishing-prevention-guide] * Meta tolerates rampant ad fraud from China to safeguard billions in revenue [https://www.reuters.com/investigations/meta-tolerates-rampant-ad-fraud-china-safeguard-billions-revenue-2025-12-15/] * Banks cannot save the UK financial system from fraud alone [https://www.thebanker.com/content/b19eacbc-2e24-4627-b9eb-986627e03bec] * Bessent, Powell warned bank CEOs about Anthropic model risks, sources say [https://www.reuters.com/business/finance/bessent-powell-warn-bank-ceos-about-anthropic-model-risks-bloomberg-news-reports-2026-04-10/] [https://www.ghanaweb.com/GhanaHomePage/business/Inside-the-alleged-2-5-million-Dubai-Crown-Prince-romance-scam-2020297]Have a Catch of the Day you'd like to share? Email it to us at [https://therecord.media/fin6-recruitment-scam-malware-campaign]hackinghumans@n2k.com [hackinghumans@n2k.com].
Ransomware (noun) [Word Notes]
Malware that disables a system in exchange for a ransom, usually by encrypting the system's data until the user pays for the decryption key. CyberWire Glossary link: https://thecyberwire.com/glossary/ransomware [https://thecyberwire.com/glossary/ransomware] Audio reference link: https://watch.amazon.com/detail?gti=amzn1.dv.gti.d6a9f744-47b0-ac70-aa56-b31fd0f58482&territory=US&ref_=share_ios_season&r=web [https://watch.amazon.com/detail?gti=amzn1.dv.gti.d6a9f744-47b0-ac70-aa56-b31fd0f58482&territory=US&ref_=share_ios_season&r=web]
Who is winning the scam game?
This week, hosts of N2K CyberWire Maria Varmazis [https://www.linkedin.com/in/varmazis/] and [https://www.linkedin.com/in/dave-bittner-27231a4/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] alongside Joe Carrigan [https://www.linkedin.com/in/joecarrigan/] are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. If you thought you could escape chicken talk, you we're wrong, this week Joe shares some more updates on his chickens. Joe’s got two stories this week, one on a New Jersey man arrested while attempting to collect $800,000 in gold as part of a widespread scam targeting elderly victims, and the second is on a new Google-tracked threat group using social engineering and phishing tactics to infiltrate BPOs and steal corporate data for extortion. Maria’s story is on a conversation she had with Sean Colicchio [https://www.linkedin.com/in/seanslinked/], highlighting how trusting human instincts, slowing down, and balancing security training can help individuals and organizations better defend against social engineering attacks. Dave’s got the story on a surge in traffic violation scams now using QR codes in phishing texts to trick victims, alongside ten hard-stop rules emphasizing verification, avoiding links or inbound requests, and slowing down to prevent falling for increasingly sophisticated scams. Our Catch of the Day comes from Reddit, where a user questioned a supposed “Google Play Console partnership” email, and the community quickly flagged it as a likely scam—citing red flags. Resources and links to stories: * Indian in New Jersey on work visa arrested in gold scam, nabbed when he was going to collect $800,000 in gold [https://timesofindia.indiatimes.com/world/us/indian-in-new-jersey-on-work-visa-arrested-in-gold-scam-nabbed-when-he-was-going-to-collect-800000-in-gold/articleshow/130143807.cms] * Google Warns of New Threat Group Targeting BPOs and Helpdesks [https://www.infosecurity-magazine.com/news/google-warns-group-targeting-bpos/] * Traffic violation scams switch to QR codes in new phishing texts [https://www.bleepingcomputer.com/news/security/traffic-violation-scams-switch-to-qr-codes-in-new-phishing-texts/] * [Nepal] Is this “Google Play Console partnership” email a scam? [https://www.reddit.com/r/Scams/comments/1sggme7/nepal_is_this_google_play_console_partnership/] [https://www.ghanaweb.com/GhanaHomePage/business/Inside-the-alleged-2-5-million-Dubai-Crown-Prince-romance-scam-2020297]Have a Catch of the Day you'd like to share? Email it to us at [https://therecord.media/fin6-recruitment-scam-malware-campaign]hackinghumans@n2k.com [hackinghumans@n2k.com].
Service Set Identifier (SSID) (noun) [Word Notes]
Please enjoy this encore of Word Notes. The name of a wireless access point. CyberWire Glossary link [https://thecyberwire.com/glossary/service-set-identifier-ssid]. Audio reference link: SSID Management - CompTIA Security+ SY0-401: 1.5 [https://www.youtube.com/watch?v=wlg4VaEXbrg], Professor Messer, uploaded August 3rd, 2014.
When “opportunity” knocks, don’t answer.
This week, hosts of N2K CyberWire Maria Varmazis [https://www.linkedin.com/in/varmazis/] and [https://www.linkedin.com/in/dave-bittner-27231a4/] Dave Bittner [https://www.linkedin.com/in/dave-bittner-27231a4/] alongside Joe Carrigan [https://www.linkedin.com/in/joecarrigan/] are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Your favorite follow up story is back, this time Sue from Australia discusses why Joe’s hen is losing feathers. Dave’s story is on a sophisticated LinkedIn phishing scam that tricks professionals with fake notifications and counterfeit login pages to steal credentials. Joe discusses a bizarre Everest scam where climbers and Sherpas were targeted with fake rescue schemes, highlighting the surprisingly high number of visitors versus summiters. Maria has the story of IRS and tax-related scams warning taxpayers about ghost preparers, urgent payment demands, and fraudulent contact attempts, with Proofpoint noting the use of remote monitoring tools in 40% of 2026 cases. Our catch of the day comes from Reddit, where a likely “stranded in the woods” scam involving a man named Michael begins to unfold but quickly unravels after he overwhelms the interaction with constant ChatGPT-style questioning. Resources and links to stories: * [https://attack.mitre.org/techniques/T1667/]LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts [https://hackread.com/linkedin-phishing-scam-fake-notificatioms-hijack-accounts/] * Everest guides accused of poisoning foreign climbers to force fake rescues in $20m scam [https://www.independent.co.uk/travel/news-and-advice/mount-everest-climb-nepal-insurance-scam-sherpa-poisoning-b2952027.html] * Surge in sophisticated tax scams reported by BBB ahead of deadline [https://www.newsnationnow.com/us-news/recalls/tax-scams-april-15-deadline-bbb-warning/] * Security brief: tax scams aim to steal funds from taxpayers [https://www.proofpoint.com/us/blog/threat-insight/security-brief-tax-scams-aim-steal-funds-taxpayers] * The Guy in the Woods - Seduction on Scrabble - Part 1 [https://www.reddit.com/r/scambait/comments/1s8p1jj/the_guy_in_the_woods_seduction_on_scrabble_part_1/?solution=d9ec8e59cd30cbd8d9ec8e59cd30cbd8&js_challenge=1&token=bbbe4bf1c9a2b5160829c4be34da58619d8cfe58c234fe2d6d3629d61c58b5ef] [https://www.ghanaweb.com/GhanaHomePage/business/Inside-the-alleged-2-5-million-Dubai-Crown-Prince-romance-scam-2020297]Have a Catch of the Day you'd like to share? Email it to us at [https://therecord.media/fin6-recruitment-scam-malware-campaign]hackinghumans@n2k.com [hackinghumans@n2k.com].
Vælg dit abonnement
Mest populære
Begrænset tilbud
Premium
20 timers lydbøger
Podcasts kun på Podimo
Ingen reklamer i podcasts fra Podimo
Opsig når som helst
1 måned kun 9 kr.
Derefter 99 kr. / måned
Premium Plus
100 timers lydbøger
Podcasts kun på Podimo
Ingen reklamer i podcasts fra Podimo
Opsig når som helst
Prøv gratis i 7 dage
Derefter 129 kr. / måned
1 måned kun 9 kr. Derefter 99 kr. / måned. Opsig når som helst.