Explore your curiosity - Interesting people with fascinating stories.
Life consists of three things:
-The stories we tell others
-The stories others tell us
-The stories we tell ourselves.
Jeff, welcome aboard to the show. So happy to have you here with us today.
Speaker 2:Glad to be here, Ari. Thanks thanks for the opportunity to talk to you today.
Speaker 1:So, Jeff, we we we have had a few national security, people on the show, but I think you're the first FBI agent thirty eight years ago, think it was. Keep me honest here if I'm getting my numbers wrong. You made a move that is very unique at least. When the first day that you were kind of like, you know, joining and going through training Quantico is it? Keep me honest here.
Speaker 1:What was going through your mind? Is like were you thinking like, well, they should what did I do? Or was like, yes. I finally made it.
Speaker 2:You know, it was a little bit of both. So, you know, I left a really good job at a at a major corporation, Xerox, which most people know about. I had a good job making pretty good money, but I wanted to be an FBI agent since I was a little kid. And so I decided to go down that path. As we're going to Quantico, my wife and I just got married, we're driving to Quantico.
Speaker 2:She's dropping me off to be go through all these weeks of training. I'm like, am I doing the right thing? Am I doing the right thing? No. This is what I want to do.
Speaker 2:So it was a little bit of both, Ari, to be honest with you. But I was scared. I was scared out of my wits to go in with all these, you know, these all these people, some from law enforcement, some from military backgrounds, some from variety of different backgrounds. And I came from a computer science background. And I'm like, do I even fit in here?
Speaker 2:So that I had a lot of trepidations about that that time.
Speaker 1:Bunch of bunch of military and the Xerox guy. Wonderful. But you said that you're married at newly married. Yeah. Your wife couldn't have supported this or or or did she?
Speaker 1:What was the what was the other side of this?
Speaker 2:Well, she heard me complain about my my job at Xerox for a long time, so she actually did support it. She goes, you gotta get out of here. You gotta do something you really love to do, and I wanted to be an FBI agent since I was a kid. So she totally supported it.
Speaker 1:Amazing, I can imagine anybody being like isn't that dangerous like why do we want to do this? So that sounds like an amazing support system. You go through a quite a significant amount of time in the FBI, What is maybe the best or worst moment that you can remember?
Speaker 2:I think the best I'll start with the best. The best moment is when we solve cases that bring closure to people that have been victimized or like we get a baby back that's been kidnapped from a hospital, just an eight hour old baby and return it to its mother. That would be like one of the best moments that I experienced in my career. But the worst moments would be just going up to investigate cases where people have been victimized by crimes and they say, if only I had known this, if only I did something different. And and when it comes to cybercrime, you know, that's almost always the case.
Speaker 2:People can stay protected if they do just take a few steps to to to watch out for the bad guys. And and, you know, when you show up at a crime scene, whether cybercrime or anything else, it's always too late. So those are the bad parts of of my job as an FBI agent, you know, trying to help victims that have already been victimized.
Speaker 1:And I want to kind of explore different levels of this, starting from just the general public. What are these things that if I just knew, if I just hadn't done this, I would have been safer? What are these things that people learn after the fact?
Speaker 2:Yeah. Well, when it comes to cybercrime specifically, it's just clicking on the wrong thing and being caught up in emotions. You know, you get an email or a text message or a phone call, something's wrong and you're gonna you have to you have to to change it, do something to before it gets worse. That's always a big red flag for fraud. Right.
Speaker 2:You know, they're trying to elicit an emotional reaction. And when we use emotions, we tend to make mistakes. You know, I tell people, just look at the situation, step back and say, wait a second, does this make any kind of sense that this is happening? So it's the emotional appeal that get gets people to use the wrong part of their brain to make these decisions.
Speaker 1:So would you almost say that if you're doing anything and they're trying to push you into it, you should maybe stop and take a breather because there could be something fishy here.
Speaker 2:A 100%. When they're trying to push you into something, that's a big red flag for fraud. You know, companies that we work with apple, Microsoft, you know, all the companies that provide us software and products, they don't try to scare you into doing something. You know, the criminals try to scare you because they know that you might make a mistake.
Speaker 1:What other psychologies or tactics are criminals basically using to try and try and get us to make these fatal mistakes?
Speaker 2:Generally, what they try to do is say your money's at risk. You've already, they've already gotten into one account, but it's going to get a lot worse than that. And they can get into your, your bank account, your retirement money. And people get really scared and they tend to do really stupid things. I mean, they'll put money in an envelope and have it picked up by a courier because they're trying to keep their bank account safe from criminals.
Speaker 2:Does that make any sense? You know, that is your bank really gonna tell you, well, your money's not safe here. We're gonna send a courier over to take a bunch of cash that you've withdrawn from your bank account and bring it and put it in a safer place. None of that makes sense, but I've seen people victimized by that, that, that people with advanced degrees, we're not just talking about, you know, people that just don't know better, people that have a good education that are smart emotions take over.
Speaker 1:I won't say who this is, but an investor in my very broad circle told to another investor, oh, I'm busy today. I'm trying to get a barrel of gold out of Africa. And my friend was like, what?
Speaker 2:Yeah. Yeah. Actually, that sounds real because I think there are barrels of gold that you can get out of Africa. That's not a scam. Did you know that?
Speaker 2:It's not a scam.
Speaker 1:So, I mean, yeah, it's I it's funny now, but it wasn't funny, you know, when it was happening.
Speaker 2:Right.
Speaker 1:Right. So just beware of emotion. I think that's just a great piece of advice there because it's applicable to so many situations. Correct. So this is happening to the general public.
Speaker 1:This is also happening at the corporate level. What does this look like when we're, you know, as executives, as you know, C suites and even just as employees? What are we seeing at that arena?
Speaker 2:So what we're seeing happening is that people in an organization always want to please their boss, right? So they get an email, a text message, Hey, I'm involved in these secret discussions about a, you know, a corporate. Takeover or thing that we're doing send money to this place. But don't tell anybody else about it. You know, we've seen that happen so many times, you know, an executive will be in a foreign country and don't tell anybody about this because it's a secret negotiation.
Speaker 2:Send money to this place. I'll explain later. And the CFO is answering to the CEO and they don't want to, they don't want to get mad at them. So they just do what they say. It could be a hijacked email account or just a hijacked account of the executives where they're just paying attention to what they think they
Speaker 1:should do. It's kind of incredible that this works because what everybody should be doing is picking up the phone, calling that person, Hey, I just wanted to verify this is you, and just have a short conversation.
Speaker 2:But in part of the message is, Don't call me. I can't talk right now. And because for whatever reason, and so they don't call. All they have to do is pick up the phone. But now Ari, here's the big thing.
Speaker 2:So now even if they did pick up the phone, even if they took that extra step, now they're using AI. The criminals are to try to trick people using real voices and real video to get them to, to to make this next step. Whereas before, you know, they they would call up and I didn't send that email, but now they call up and it's like, yeah, I did send that email, but it's a trick because it's AI duplicating or cloning the voices or video of that individual.
Speaker 1:So, so this is, this is becoming more scary than ever before because you know, an agent is going and researching our history, the person's history, it's coming with real data facts and creating a message that's so custom tailored to us that we're going to be like, oh yeah sure that's my boss. It's not as easy as it was before. I mean I have even recently have looked at stuff and been like, sure and then I do an extra few steps and was like, my god I almost fell for this. And as a you know self proclaimed king of the lemurs expert in you know cyber security if I'm gonna almost fall for these things I'm asking myself what hope does anybody else have? What do we I mean it feels like we're almost a step behind all the time.
Speaker 1:Is this true? Is there any is there any hope? And what does that hope look like?
Speaker 2:Well, I tell people when I go out and do presentations and do webinars on these topics is is that anybody can fall for anything at any given time. It's like, you know, in football, any team could beat a team on any given day, depending on what's happening. You can get tricked even if you consider yourself really smart under the right circumstances. So, you know, the tricks involve, you know, something that resonates in your brain. Maybe you something has happened.
Speaker 2:You know, you got an email from your company that said, we have a special deal for you. And then there's a follow-up phone call that AI has figured out that you, they were sending out these emails to people. And AI has said, I'm going to try to trick this person and follow-up with a phone call. Hey, we sent you an email. And now, now all you have to do is take these next steps.
Speaker 2:Give us access to your, your account. I'll send you a code to make sure it's you that we're talking to. And that's the multifactor authentication code that, that they want to get into your account because they already have your password from a previous breach. You know, just stuff like that.
Speaker 1:Yeah. And it can even sound like your boss because they went and got a whole bunch of YouTube videos of your boss, they faked his voice and now it sounds like he's actually talking so probably the only thing you need to verify in that case that will actually be different is the phone number that they called from So that's kind of the risk factor there, but that, I mean, somebody calls you and sounds like your boss, do you really go and look at the phone number? I don't know if I would do that.
Speaker 2:Yeah. Well, even if it you look at the phone number, they're spoofing the numbers to make it look like it's coming from your boss or from your bank or from another institution. They can trick you that way. You can't rely upon the incoming call. What I recommend is that people hang up the phone and call your boss back or whoever they're.
Speaker 2:It is calling you at a number you know to be for them and say, Did you guys just call me and ask me to do this? And so that would be a better way to handle situations like that.
Speaker 1:Beautiful. So we're, you know, this is, this is, you described it before, right? It's a cat and mouse situation, right? We take a step forward, they take a step or two forward. What is the hope?
Speaker 1:What are the actions? Clearly, you know, the general population can educate themselves and their children. Maybe there's an opportunity here for, you know, even the school systems to add this as a curriculum, but when we look at kind of businesses and maybe more important the operating system for our democracy, what can government do to or is doing today that we might not know about to really help us mitigate this risk for everyone?
Speaker 2:I think awareness is a big thing. It's just general education and making it more difficult to authenticate. You know, know, you use on your phone, you're using biometric authentication. You got your face, your fingerprints, but those may not be good anymore because of, because of AI begin being able to clone those things. So there needs to be extra factors of authentication that's required in the financial industry and to get access to accounts that, that will be able to prevent people from using voice cloning, video cloning, and, and cloning of, of our words in written form to make it look like it's a person that's that we're, what it's not really the person that they're talking to.
Speaker 2:So extra authentication, I guess, should be required. The national institutes of standards and technology, NIST for short, you know, has recommendations for passwords and they used to require, you know, long passwords with, all the, all the, complexity. And now they're just saying go into a pass phrase protocol much longer, but not all the complexity and use a different pass phrase for each account to help authenticate you and ones that can't be hacked as easily through brute force methods.
Speaker 1:If I had to, if I could be king for the day, I would change the law to force, you know there's issues here right if people don't have money but this thing costs $15 or something like that. Just change the law that you know this has to be mandatory and if you don't have a physical token everybody has a phone So just for every financial transaction to have, you know, second authentication on to at least send you an SMS.
Speaker 2:And it's a it's the issue is that financial institutions, they want to make it easy for people to log in. So convenience is a big thing. But on the other hand, they that lessens the security to get in. So they want people to log in easily so they could save money and they can, they don't have to have people go into a financial institution to do this or other. They want to do things electronically.
Speaker 2:If people have more difficult to logging in and have to do all these extra things like getting a little key to put into their computer, they're not going to do it. And then they're going back to the old fashioned way, which is banks, which banks don't want them to do. So, know, it's always a trade off between security and convenience and that's what they're grappling with right now.
Speaker 1:So I heard something weird from one of my European friends that he was kind of pushing towards a, almost an incentive design and culture aspect. I wonder if this is part of the game and what he said, hey if you get basically a fraudulent bill on your credit card you're liable for that to a certain degree. Now here in The States you go, you cancel that, you get your money back, it goes through insurance, pretty much you're protected. But his point was not that oh the American system is better, his point that the European system is better because when the individual citizens have more accountability in that, you know, that quote unquote fine or slap on the wrist that they get, it makes them more secure and more safe.
Speaker 2:Yeah. I think one of the things in the European system and other countries outside of Europe is that they're they're eliminated checks because checks are a huge source of fraud. The United States, people still like to write checks and we have to migrate to people paying things electronically. It's a lot more secure as long as your computer and your mobile device is secure. Paying things via electronic methods is a lot more secure.
Speaker 2:And Europe has always been a step ahead of us in terms of security because they have better hackers over there, right? So they had to be a step ahead of us. Right. We're just kind of catching up here. You know, I'll just give you a quick example.
Speaker 2:So we had this big FBI notification that, you know, pay attention to your to your accounts because the criminals have gotten access to ATM network. They may be able to make clone ATM cards or debit cards and withdraw money from your accounts without limits. So watch your account balances carefully. So it never came to fruition in The U S but I knew they didn't say who the ATM network was that was breached. They didn't say where the hackers were, but I knew it was European hackers or at least not US hackers because US hackers aren't that sophisticated.
Speaker 2:If they're gonna steal money from an ATM network, they're gonna rent a forklift and steal money from the ATM machine by pulling it off the moorings and and trying to take it to their house and break into it. That's what we do in The US. They're way ahead of us in Europe, to your point.
Speaker 1:I don't know if this was in The US, think it was, but what they were doing is they put a transparent barcode over, I think it was the gas pump, so basically, and it's like you can't pay through like iPay, whatever, Apple Pay or Google Pay, but they added a barcode. So people saw that and they're like, oh great, I can pay with Apple Pay. They scanned the barcode, obviously it went somewhere else. So, and I was like, like I would definitely fall for that as I said as a self proclaimed expert. So it's getting tough and I was in a parking lot a month ago up in Boulder and there was this barcode in the wall.
Speaker 1:I'm asking myself, how do I know if this is real? And I just couldn't answer because a lot of times these charge sites are kind of like funky. They're not well designed. You don't really know who the domain is. So even for an expert, it can really get tricky.
Speaker 2:Yeah. Yeah. The barcodes and the QR codes as well. Always look for something that doesn't look like it's an original QR code. Like someone may have taken a piece of paper or plastered it over the QR code that was there before and you scan that and you go, you're sending it to someone else's site.
Speaker 2:You're going there to put in your information. So yeah, you gotta be careful. Even if you know about these things, sometimes we can be tricked.
Speaker 1:And Jeff, at some stage you decided to write a book. Tell us a little bit about the book, but maybe before that, what triggered you to even go down that process? Because it's a lot of work and effort, it's almost like a baby, there's a certain sensitivity to it.
Speaker 2:Well, you know, when I retired from the FBI, I started doing speaking about cybersecurity, identity theft and fraud. And as a speaker, you know, you want to have a book to help, you know, basically give you a little credibility. So, I basically made a book about about what I talk about in real life to people in these speeches. And and, you know, it wasn't it wasn't that difficult for me because the stories are I almost had to just condense it so I can get it into the form of a book. So it wouldn't be like, you know, something that that would be unpublishable as, you know, too big.
Speaker 2:There's so many different tricks out there. So it's based on what I talk about, about the cyber scams, the fraud, and and just how how to stay safe in a very simple way for all types of people.
Speaker 1:What's your favorite story from the book that you can share with us? And give us the book name and where we can find it.
Speaker 2:Sure. It's on my website at thelanzagroup.com. The name of the book is cybercrime, how to stay safe from, from fraud and, and and identity theft and cybercrime is basically the name of the book. But my favorite story is something that happened to me when I was a new FBI agent. Just, you know, as a as a new agent, you know, you you get to put on some kind of grunt work.
Speaker 2:And so I go into this, I go into this room and I'm listening to a wire tap of a mobster's phone. And I put on the headphones and Tony gets a call from Joe. And as we listen to the call, here's how it goes. Now there's there's a lesson to this. So what happens next is Tony gets a call from Joe and Tony says, Joe, I'm really glad you called.
Speaker 2:And Joe says, yeah, why? Tony goes, I got a problem. I think the FBI is tapping my phone. And Joe goes, well, what are you going to do about it? And Tony goes, well, I got a new number.
Speaker 2:So lacking any common sense. Joe says, okay, good. Give me the new number. Now Tony gets a little common sense. He says, I better not, I better not give it to you over the phone.
Speaker 2:I'll meet you for lunch. I'll give it to you then. And Joe says, I can't meet you for lunch. And Tony says, okay, I'll give you the number now over the phone, but I'll give it to you backwards. So we gave him the seven digits in reverse order and the FBI got our best cryptologists on that one right away to figure out the number.
Speaker 2:But it illustrates the issue of common sense. You know, how important is common sense in everyday life when it comes to preventing frauds important to never let emotions manipulate you to do things that you weren't planning on doing, you know, again, that expediacy, do something before it's going to get worse. So they're trying to change our thinking. So we're not using common sense. We're using a different part of our brain.
Speaker 2:And so that story in my book helps illustrate, you know, how they manipulate us and how we could try to stay safe.
Speaker 1:Brilliant. I appreciate that, Jeff. I want to take a step up and kind of look at us, not from the personal or business level, but as United States. It's not just organized crime that's trying to make money off us. There is foreign governments that are trying to attack us.
Speaker 2:What are
Speaker 1:the threat vectors, use a word that you should probably explain, what are they? What do they look like? How do we protect ourselves as America?
Speaker 2:I think 90% least of the attack vectors, the ways they get into us on our systems come through emails. And it generally, when it comes to an email generally happens through an attachment. So if you get an email from an unknown sender, a suspicious sender, one that doesn't make sense, don't click on the attachment. Don't download anything from someone that you weren't expecting. And that can happen in a, in an individual sense, us, you and I, you know, opening emails or in a corporate sense as well.
Speaker 2:There are major corporations, and we hear about these attacks all the time. Gigantic corporations that, some even in the IT business, that have been victimized because someone clicked in the wrong place. They've downloaded malware, it affected their network, and they're holding their computers hostage for huge ransom payments. It happened to the MGM hotel and casino chain happened to Caesars, same thing, hotel and casino chain, because they infiltrated the system based on emails that downloaded this malware to a computer. The attachment is the key.
Speaker 2:If you avoid the attachments, you might be able to stay safe from that type of threat.
Speaker 1:Is there, is there, because I look at these, these serious companies, I mean for crying out loud, it was the, one of the, two of the security companies, one after the other, and these specifically were companies that create vaults for your passwords. They got hacked one after the other, right? And it was in the space of maybe a month or so. And I'm thinking to myself, these companies, the only thing that they do is secure themselves and others. And then I think about kind of local governments, hospitals, know water treatment plants and I'm like what chance in hell do they have to protect themselves?
Speaker 1:And I guess my follow-up question is should we be doing something at the legislation level, Should we be doing something at the political level to make sure that we are protected, that we're not suddenly going to find out that all of our social security numbers just disappear?
Speaker 2:Well, think that the government has done a lot legislatively to, to make sure there's consequences. So for state and local organizations or really any organization that houses our personal information, if there's a breach, they have to report that and announce that and provide services to protect the identities of people who have been victimized. So they've done a lot legislatively. But I think from a perspective of, you know, training is I think is the most important thing. And people still do dumb things inside organizations that that just, you know, could be could have been prevented.
Speaker 2:So I think mandated training, mandated awareness, because even though we've gotten emails that say, hey, click here and see what happens, and that's a test email and then I have to go through training, people are still doing it when the real thing comes, you know? And so I think it's just it's just reminding people and awareness and and, you know, the perimeter security has to be, I guess, know, fortified as well.
Speaker 1:You know, we have laws requiring you to do certain types of training. Keep me honest here, I don't think cybersecurity is a required training in organizations unless you're doing a compliance, a certain compliance like NIST eight fifty three and such. It's just not a requirement. It feels like maybe we should, we should be doing more but you know, the devil's advocate says, well, these things are really expensive and they could actually hamper innovation. So there's there's also a trade off here that's really difficult.
Speaker 2:Yeah. And I think it's it's, you know, when you have the training is like send a test email, see my amount of people click on it. And then, you know, then they, you know, get remanded to do training after that. But then later on, they click on the same email that came from a criminal. So the training is not having an effect either.
Speaker 2:So that's something we have to consider, you know, just, you know, how do we make sure those emails don't even make their way to the end user for them to click on something?
Speaker 1:That's I appreciate that point. Geoff, we've got about four minutes left and we have only one question that we ask every single one of our guests. It's a hard question because it's personal. If you had to go back to the most difficult point in your life, what advice would you give yourself? You know, there isn't one guest that doesn't have an emotional reaction when I finish asking that question.
Speaker 2:So I guess I would say if I went back in time to when I when I became an FBI agent, I wouldn't change a thing because at the time the FBI was, what I aspired to and I and I wouldn't change anything at that point. However, you know, now what's with the things that are happening today? I don't know that I would become an FBI agent today based on, you know, what's happening in, in terms of leadership. So I guess that really doesn't answer your question because I can't change. I wouldn't change anything way back then.
Speaker 2:But if I was to fast forward to this time and I was a new person, I mean, a new applicant to the FBI, I would think twice about, about maybe becoming an FBI agent because things have changed.
Speaker 1:Jeff, thank you so much for joining the show. I appreciate you.
Speaker 2:You're very welcome. Thank you for
Speaker 1:having me.