Logo

    124: Synthetic Remittance

    en-usSeptember 20, 2022
    What is Warren Buffet's investment strategy focused on?
    How long did Facebook take to become profitable?
    What tactic did Evaldas Rimasauskas use to scam Facebook?
    Why are businesses at risk of Business Email Compromise?
    What measures can companies take to prevent BEC scams?

    Podcast Summary

    • The Importance of Patience and Hard Work in Investing and ProfitingWarren Buffet's strategy of investing in wonderful companies at a fair price and Facebook's success of becoming profitable both took time and effort. Scams like Rimasauskas' prove that success requires significant effort, and nobody gets rich quick without hard work.

      Warren Buffet's investment strategy to invest in wonderful companies at a fair price requires patience and perseverance over time to gain significant returns. Facebook's success of becoming incredibly profitable and making $5 billion in revenue took more than five years. There is no such thing as an overnight get-rich-quick scheme. Evaldas Rimasauskas' curiosity and fascination with how checks work led him to scam Facebook by stealing a small, but significant percentage of their money, proving that big-time deals require big-time efforts to gain significance, and nobody gets rich quick without putting in the work.

    • The Power of Social Engineering in BEC ScamsScammers can gather information from seemingly insignificant details to successfully execute social engineering attacks, emphasizing the need to be vigilant when handling financial transactions and verifying email communications. Knowing a company's partners or contractors can also provide an entrance point for social engineering attacks.

      Social engineering can be a powerful tactic in gathering information about a company's internal operations. Scammers like Evaldas can piece together seemingly insignificant details to make a successful attack. Knowing a company's partners or contractors can provide an entrance point for social engineering as well. In the case of Evaldas, his team's slow and steady approach to social engineering ultimately led to a successful BEC scam. By posing as Quanta Computer and faking an invoice, they were able to convince a Facebook employee to send large payments to their bank account. This emphasizes the importance of being vigilant when handling financial transactions and verifying the authenticity of email communications.

    • Protect Your Business from Email ScamsIt's important for businesses to be vigilant against BEC scams, as even the most sophisticated security teams can be outsmarted. Tools like domain reputation checking can help prevent fraudulent emails and protect against financial losses.

      Businesses should take protective measures to defend against Business Email Compromise (BEC) scams that aim to trick them into sending payments to the wrong person. While such attacks are not new, they are becoming increasingly popular, causing significant financial losses to many businesses. The incident involving Evaldas shows that even the most sophisticated security teams can be outsmarted by small, clever teams that meticulously plan their attacks. As such, it is everyone's responsibility in a company to ensure security is maintained and risks from BEC scams are mitigated. Employing tools such as domain reputation checking and quarantining suspicious emails can help identify fraudulent emails from lookalike domains and prevent payments from being sent to the wrong person.

    Recent Episodes from Darknet Diaries

    149: Mini-Stories: Vol 3

    149: Mini-Stories: Vol 3

    In this episode we hear EvilMog (https://x.com/Evil_Mog) tell us a story about when he had to troubleshoot networks in Afghanistan. We also get Joe (http://x.com/gonzosec) to tell us a penetration test story.

    Sponsors
    Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet.

    Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free.

    Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.

    Darknet Diaries
    en-usSeptember 03, 2024

    148: Dubsnatch

    148: Dubsnatch

    Ever wondered how far a fan would go to get a sneak peek of their favorite artist’s unreleased tracks? In this episode, we uncover the audacious story of some teens bent on getting their hands on the newest dubstep music before anyone else.

    Sponsors
    Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet.

    Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free.

    Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.


    Darknet Diaries
    en-usAugust 06, 2024

    147: Tornado

    147: Tornado

    In this episode, Geoff White (https://x.com/geoffwhite247) tells us what happened to Axie Infinity and Tornado cash. It’s a digital heist of epic proportions that changes everything.

    This story comes from part of Geoff’s book “Rinsed” which goes into the world of money laundering. Get yours here https://amzn.to/3VJs7pb.

    Darknet Diaries
    en-usJuly 02, 2024

    146: ANOM

    146: ANOM

    In this episode, Joseph Cox (https://x.com/josephfcox) tells us the story of anom. A secure phone made by criminals, for criminals.

    This story comes from part of Joseph’s book “Dark Wire” which you should definitely read. Get yours here https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691.

    Darknet Diaries
    en-usJune 04, 2024

    145: Shannen

    145: Shannen
    Shannen Rossmiller wanted to fight terrorism. So she went online and did. Read more about her from her book “The Unexpected Patriot: How an Ordinary American Mother Is Bringing Terrorists to Justice”. An affiliate link to the book on Amazon is here: https://amzn.to/3yaf5sI. Thanks to Spycast for allowing usage of the audio interview with Shannen. Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet. Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    144: Rachel

    144: Rachel
    Rachel Tobac is a social engineer. In this episode we hear how she got started doing this and a few stories of how she hacked people and places using her voice and charm. Learn more about Rachel by following her on Twitter https://twitter.com/RachelTobac or by visiting https://www.socialproofsecurity.com/ Daniel Miessler also chimes in to talk about AI. Find out more about him at https://danielmiessler.com/. Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet. Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    143: Jim Hates Scams

    143: Jim Hates Scams
    Jim Browning has dedicated himself to combatting scammers, taking a proactive stance by infiltrating their computer systems. Through his efforts, he not only disrupts these fraudulent operations but also shares his findings publicly on YouTube, shedding light on the intricacies of scam networks. His work uncovers a myriad of intriguing insights into the digital underworld, which he articulately discusses, offering viewers a behind-the-scenes look at his methods for fighting back against scammers. Jim’s YouTube channel: https://www.youtube.com/c/JimBrowning Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. This episode is sponsored by Intruder. Growing attack surfaces, dynamic cloud environments, and the constant stream of new vulnerabilities stressing you out? Intruder is here to help you cut through the chaos of vulnerability management with ease. Join the thousands of companies who are using Intruder to find and fix what matters most. Sign up to Intruder today and get 20% off your first 3 months. Visit intruder.io/darknet. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    142: Axact

    142: Axact
    Axact sells fake diplomas and degrees. What could go wrong with this business plan? Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    141: The Pig Butcher

    141: The Pig Butcher
    The #1 crime which results in the biggest financial loss is BEC fraud. The #2 crime is pig butchering. Ronnie Tokazowski https://twitter.com/iHeartMalware walks us through this wild world. Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. Support for this show comes from Drata. Drata streamlines your SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR & many other compliance frameworks, and provides 24-hour continuous control monitoring so you focus on scaling securely. Listeners of Darknet Diaries can get 10% off Drata and waived implementation fees at drata.com/darknetdiaries. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    Related Episodes

    SQUAWK BOX, MONDAY 9TH AUGUST, 2021

    SQUAWK BOX, MONDAY 9TH AUGUST, 2021

    Rising commodity prices weigh on China’s post-pandemic economic recovery with factory gate prices beating expectations, going up 9 per cent. The U.S. Senate inches towards passing the largest infrastructure spending bill in more than a decade. A couple of big earnings reports are in focus. On Wall St., Warren Buffett buys back a record $25m of Berkshire Hathaway stock after posting a 21 per cent in Q2 income. In the energy sector, Saudi Aramco is set to increase supply capacity after second quarter earnings surged by 288 per cent. However, crude is down on concerns of a drop in demand.

    See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

    Ep. 214 - Human Element Series - Augmented Reality and Thought Suppression with Dr. David Rawaf

    Ep. 214 - Human Element Series - Augmented Reality and Thought Suppression with Dr. David Rawaf

    Today we are joined by Dr. David Rawaf. Dr. Rawaf is a surgeon, researcher, technologist, innovator and policy developer. As well as studying and working in both UK and US, David is involved with Imperial College WHO Collaborating Centre (for Public Health Education & Training), as well as medical writing, research and hosting conferences. David has a role as Surgical Skill Faculty and is Centre Accredited by the Royal College of Surgeons. In addition, he is an abstract and content reviewer for a number of institutions including the Institute for Health Metrics and Evaluation amongst a number of other scientific societies. In addition, David is the Clinical Excellence Lead for Inovus Medical, the world-leaders in high-fidelity medical and surgical simulation, and beyond this is also heavily involved in medical device & software consulting, including validation, accreditation and approval through bodies such as the FDA. David is a Co-Executive Director for the International Organization for Reconstruction for war torn-countries, and a Director for QCapital Ventures specializing in tailored start-up advice including investment acquisition, financial & business-strategy and scale up methods. [June 12, 2023]

     

    00:00 - Intro

    00:34 - Intro Links

    -          Social-Engineer.com - http://www.social-engineer.com/

    -          Managed Voice Phishing - https://www.social-engineer.com/services/vishing-service/

    -          Managed Email Phishing - https://www.social-engineer.com/services/se-phishing-service/

    -          Adversarial Simulations - https://www.social-engineer.com/services/social-engineering-penetration-test/

    -          Social-Engineer channel on SLACK - https://social-engineering-hq.slack.com/ssb

    -          CLUTCH - http://www.pro-rock.com/

    -          innocentlivesfoundation.org - http://www.innocentlivesfoundation.org/                                               

    03:18 - Dr. David Rawaf Intro

    05:01 - From Studies to Startups

    07:22 - Practice Makes Perfect

    09:16 - How do you "simulate" surgery?

    11:48 - Simulation Benefits

    14:47 - Redefining Fidelity

    19:16 - Augmented Over Virtual

    20:30 - Minority Report

    23:08 - Google Glass 2.0

    25:48 - Depressing Desire

    29:39 - Stop Thinking!

    35:33 - The Value of Support

    41:17 – Mentors

    -          Professor Adrian Wilson

    -          Professor Fares Haddad

    -          Father

    -          Late Uncle

    46:33 - Book Recommendations

    -          The Genius Zone - Gay Hendricks

    -          The 15 Commitments of Conscious Leadership - Jim Dethmer, Kaley Klemp & Diana Chapman

    50:02 - Find Dr. Rawaf online

    -          LinkedIn: linkedin.com/in/davidrawaf/

    -          Twitter: twitter.com/DavidRawaf

    -          David’s Paper: Effect of Suppressing Thoughts of Desire to Smoke on Ratings of Desire to Smoke and Tobacco Withdrawal Symptoms

    50:51 - Guest Wrap Up & Outro

    -          www.social-engineer.com

    -          www.innocentlivesfoundation.org