Cybersecurity Strategies to Combat Online Scams with Patrick McNeil
Patrick McNeil, cybersecurity strategist for GuidePoint Security, dives into what’s ultimately needed to protect individuals and organizations from online scams involving, for example, the Super Bowl or Valentine’s Day.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with Patrick McNeil, who's the cybersecurity strategist for Guidepoint Security, and we're talking about all these scams we see lately, and they seem to be related to some sort of cybersecurity attack in one form or another.
Most recently we had the Super Bowl, and then we had Valentine's Day, and there's all kinds of holidays coming up ahead, and it's gonna be more of the same. Patrick, welcome to the show. Thank you very much.
Thanks for having me. What do all these things have in common? Uh, they feel fairly sophisticated and there's a lot of effort being put into them.
Are they generally successful? Are people giving up millions of dollars to these people? I mean, how pervasive is decision?
Yeah, it's a, it's a, it is a very pervasive issue, and I think with the Super Bowl, they, the, the scammers were pretty much preying on people's emotions and establishing a sense of urgency to do something. I think you'll see a little bit less of that around Valentine's Day, you know, unless, unless it's, uh, you know, right up the last part of, uh, the, the day and maybe somebody will get caught. But, uh, we're seeing a lot of these, these new scams as being AI enabled.
So because generative AI is now being brought in, there is a greater reach for their campaigns. They can hit more numbers, hit more email addresses. Uh, they're more effective because they can craft a message that even if they're not an English speaker, really looks legitimate.
And then they're more complex, so they can involve more medias or even have the AI do that initial interaction with you if you respond back to a text or an email. Is there any way to detect these? 'cause to your point, they are more sophisticated and they're also increasing in volume and asking mere mortal end users to catch every one of these seems like an impossible mission.
So how do we kind get in the middle of this thing and protect people? Yeah, it is, it is challenging sometimes and, and even an expert can, uh, occasionally fall victim. So it's really a matter of, you know, making sure that if they are establishing a sense of urgency, that you take a breath and actually reread that again, um, you know, anything last minute.
And instead of obviously clicking links, like they say they're from a sports betting site or flower company or something like that, don't click on the link. If they say the company they're from, you can just go directly to the website. There would typically be the same sale that they're texting you about, and if there's a discount code or something that they sent you, it's going to be available on the website.
If you just type it in, things will happen and, and you will mess up. So if you've put your payment for whatever it is on a credit card, you at least have the fraud protections to, to kind of back you up and, and help with that. Definitely don't use a, a debit card.
And if they're asking for something like cryptocurrency, that is almost certainly a scam. So To your point, um, it seems like there are two tells. One is there's a, some sense of urgency, but two is they're typically asking me to enter some sort of sensitive data into some system somewhere, and assuming that, um, I'm gonna do that for whatever reason.
Do people kind of need to have, like, maybe we all just need a personal gut check here before we go do these things. And this is, is is it really a matter of education E Exactly. It is a matter of education and, uh, kinda like I said, stop and take a breath.
Exactly. It's a gut check and you need to rely on those instincts a little bit. We are also seeing, uh, AI enabled scans on the HR or employment front as well.
One of the, uh, partners that, that, uh, I work with in the, the incident response industry has actually seen an uptick of people that as soon as they changed their, uh, LinkedIn profile, no kidding, 24 hours later, the scammers have correlated their identity with a phone number that they've got from a data broker maybe, and they're sending them texts from, you know, the CEO that would never contact a, a first time employee, and they've gotten more sophisticated. So they're not asking for, you know, uh, go to the store and get me Apple gift cards. That's long gone.
Now they're actually asking for, can you send me our customer list or other sensitive information? And even adding it a little, this is highly confidential. It, it has something to do with the m and a process.
So you really can't share this with anybody to try to scare you into not reporting this to your IT department. As we kind of play around with this, should we get to the point now where we just tell people to not trust anything and just assume that everything is fake and then work backwards from there? Almost?
Yeah, I mean, it is possible to impersonate or spoof some of the phone numbers that things come from. So if they know that you have a relationship with somebody else at your company, it might be possible. I think in that case, uh, using an encrypted messaging app like Signal, um, you know, establishes a little bit more trust because of the fingerprinting of the user's device.
Of course, they also take your credit card and your debit card. I feel like they're also getting more adept at, um, bleeding you a little bit, right? They're not just smashing and grabbing and taking a lot of money in one throw.
They're kind of setting up something where, um, you know, they're hitting you up for, you know, 40, 50 bucks at a time and you might not notice. Yeah, it's, it's fairly common as, as I'm sure you know, to see a small dollar transaction. And then later on they'll, you know, uh, send some more transactions.
And there's also, you know, the, the typical cryptocurrency pig butchering schemes where they work on the relationship and, you know, suggest investments and stuff like that and try to get you to incrementally invest over time. Honestly, the, the easiest thing that we can do to prevent that transition from a low dollar to a high dollar transaction is to use the temporary credit card numbers that many of our credit card companies make available to us. A lot of this, I feel, goes unreported 'cause a lot of people are, you know, they're embarrassed and they don't wanna share that they got conned.
And so do we have to make this, uh, less of a, you know, an emotional issue and identify what it is? It's hardcore crime. Yeah, definitely.
We have to try to make the stigma go away, right? gov. And they'll, they'll take the report and they're tracking different groups and the different scams that are going on.
And what can law enforcement do about all of this? I mean, it seems like every time they break up one ring, five boards spring up, It That is definitely true. I know for a fact that the FBI works with our international partners to, you know, try to track these types of scammers down.
We've seen in Europe, there was a whole betting scam going around, uh, the UEFA soccer championships and they managed to shut down, uh, I wanna say it was something like 800 different scammers in multiple call centers all at once. So they, they where there are appropriate law enforcement, um, you know, extradition and relationships and stuff like that, they will go after them. But it, it does take a lot of time to, uh, investigate and break up those groups.
Of course, the bad guys are already using AI to clean up their language and make them seem like they are legit. Can we use AI to defend ourselves from these folks? Yeah, I mean, there, there are some, uh, consumer and enterprise services that you can subscribe to that will analyze text messages and the numbers that come from and the wording and stuff like that and classify them as spam for the actual attacks that are coming to your email, to your website.
You know, the, certainly the anti phishing systems that a lot of companies pull in have been incorporating ai and I actually had a report from a customer the other day that their amount of phishing emails had gone down drastically. And the only things that they're really seeing are the very highly crafted, sophisticated spearfishing attempts against their executives. So we are being somewhat successful, at least in, in the enterprise environment, at targeting some of that to your home email address you that you may have a harder time with that And the folks who run our telecom networks help us out here, or maybe they are and we just don't know it.
They, they are, um, there are, uh, stir and shake in protocols to actually authenticate some of the handoffs, you know, from trucks so that they can block some of the spam that goes on. But, you know, for the large part, uh, unless it's being spoofed or maybe it's a, uh, a highly volumetric campaign where they're sending out thousands of texts at once, they are gonna kinda let that through because it's not really up to them as to whether or not something is, you know, a phishing attempt or not. And the bad guys, are they hiring people who are essentially professional odd men and ladies who are engaging in what we, you know, like to call social engineering attacks, but ultimately they are basically cod Um, uh, does, do they hire more of these people as time goes on?
Or are they automating all this stuff with a handful of people? Yeah, I mean, there's definitely a mix. There's certainly some automation and grooming of that initial contact so that you can get somebody to engage further and then they transition to a human.
There are some call centers in areas where it's very difficult to find employment. So people are going to those places because they don't have a choice. That's the only job they can get.
And in some cases they are human trafficking, so they're, they're finding people in another country where they can't find employment, Hey, come to come to my country. There's lots of jobs. And they take their passport and put them to work in their call center where they have very minimal living facilities and are essentially home hostage because they can't go anywhere without their papers.
So this is clearly not a victimless crime. In fact, some of the people who are perpetrating the crimes are victims themselves. Exactly.
Yeah. And they may have incentives or targets that they have to meet, uh, you know, in order to even stay employed there. So Is there any discussion among the governments, among the world to kind of combat this stuff?
Are they kinda helping each other out a little bit to get to the root cause of this stuff? 'cause a lot of those people you talk about are not sitting in Alabama, they're sitting in someplace halfway around the world, right? Yep.
I, I personally have not seen anything at a, we'll say a government level, and it's, but it has been pretty much partnerships through law enforcement to, you know, collaborate and gather evidence and, and take them down. Should companies be educating their employees and having some training program, or is this some sort of civic course that we should be giving people, or both, You know, it would be really great if we could just assign that training to everybody, have your county send you to the, uh, phishing education session or something. But yeah, all, all companies really should be doing some level of training.
As we know, a lot of companies have, uh, phishing campaigns to try to catch you on that. And most of them are really targeted towards the enterprise types of things. You know, oh, this is the fake Okta login page or something.
However, you know, I think they should probably also look at things like betting scams and, you know, other types of things that employees would want to interact with on their personal time. Me, I'm voting for, they should teach this in the schools and starting maybe in A hundred percent. Yeah, the Grammar school and everybody can get a, a notion of it and maybe the kids will come home and teach their parents and this might be the way to go.
Kids are already teaching their parents so much, right. So it would be great if they could do that. Right.
And kids, especially the younger ones, when they see this stuff, they get outraged and they wanna do something about it. Maybe we get we're just a little too old and we've been had one too many times, so we don't quite get as been outta shape about it. I, I think I've, I've, as I've gotten older, I've gotten more suspicious of everything, especially being in the security field, I, you see so many things that are scams.
It's hard to trust anything that's legitimate sometimes. There you go. Hey, scammer, get off my lawn.
All right. Hey Patrick, thanks to me on the shop. Yeah, thank you Mike.
Have a good one. Talk to you. All right, bye to you guys.