Showing posts with label scam. Show all posts
Showing posts with label scam. Show all posts

2026-04-07

AI calling your parents

Image from Unsplash

Have you ever had no time (or no desire) to call your parents? Then there’s now a handy service that everyone will benefit from!

This is about a company offering a rather unusual AI service. They actually call your elderly parents. So you don’t have to. On their website you’ll find a photo of the Czech founder with his mother, accompanied by the story of how he lived abroad but wanted to stay in touch with her. Different time zones, a demanding job, and “the unpredictability of life” kept getting in the way. And so the idea for his company was born. It helps people feel “remembered, connected, and valued,” they say.

A bit more information from their website. “Mary” calls the elderly person and asks how they’re doing. She also remembers what you tell her. Incredibly handy, of course: if you tell her today that you need to see the doctor, she’ll ask you tomorrow how it went. She also makes use of 1,400 “life story questions”something like a database full of opening lines. On top of that, she sprinkles interesting little facts throughout the conversation to help keep the mind sharp.

Before long, the older person will likely no longer realise they’re talking to AI. Simply because AI sounds so natural. I’d bet that you and I wouldn’t hear the difference either. And once you start considering Mary a friend, you’ll probably tell her the same things you’d tell a real friend. For example, about your healthsomething older people talk about quite often. The company proudly displays the logo “HIPAA compliant” on its website. HIPAA is U.S. legislation concerning the privacy and security of medical data. But it’s less strict than our GDPR. In the EU, medical data is considered special-category personal data, which is subject to extra stringent rules.

Older people are particularly vulnerable when it comes to cybercrime. Recently there are a lot of stories about fake police officers showing up to collect money and jewellery, supposedly because some great danger is looming. Criminals could easily piggyback on a service like this. For example, by pretending to be Mary and asking clever questions to manipulate their victim. Because they trust Mary, there’s a greater chance they’ll go along with the story. You can basically wait for this to happen, sad as that may be.

In your work, you may sooner or later get a phone call from a fake Mary as well. These scams already happen. Three years ago, an American named Brianna was supposedly kidnapped. Her mother received a call and heard her daughter speaking. Or so she thought. Because with AI, a few seconds of audiostolen from social mediais enough to make someone sound lifelike while saying anything you want. The same could happen with your manager, for example, asking you to email certain data. So if you get a strange request over the phone, call the person back on the number you know to verify that it’s legitimate.

And as for Mary? I prefer to call my mother, who turned 93 today (happy birthday!), myself. Much nicer that way.

 

And in the big bad world…

… a training course got in the way of filling this section.

 

 

2025-02-14

From Asia with love

Image from Unsplash

They didn't mention it in the eight o'clock news, but the fact that the report was broadcast on the eve of Valentine's Day could hardly be a coincidence. It was about a man who got in touch with a certain Julia on this dating app. Could this finally be the one for him?

They chatted for a while, and after a few days Julia wrote: “Guess what I was just doing!” And she sent a screenshot of an impressive graph, showing that she had just made a lot of money trading cryptocurrencies. And she was quite willing to explain to our anonymous love seeker how that worked. So he received a link to a trading app. But he didn’t realize that he had fallen into the hand of scammers. Nothing was traded via that app. His entire investment – first a thousand euros, then ten thousand, a total of one hundred fifty thousand – disappeared straight into criminal pockets. When the thugs realized that there was nothing left to be gained, Julia abruptly ended the budding romance. Our Romeo found himself in a difficult time, in which he lost confidence in everyone – including himself.

In many presentations I give, there is this folk wisdom: if something seems too good to be true, it usually is. It once started with that Nigerian prince, who sent you of all people an email, promising you mountains of gold if you helped him free up a large sum of money. Lawyers from faraway countries, who told you that a large inheritance was waiting for you, were a variation on that. The only occasion when I believe a statement like that is when it is on a chance card in Monopoly. But the scams are becoming increasingly shrewd and the criminals are putting more time and effort into getting the loot. Where that prince used to target a large group in one go, hoping that a few people might fall for it, they are now investing in a good relationship with the individual victim.

The news also showed where all that misery is coming from. No longer mainly from Nigeria and the surrounding area, but from Southeast Asia. From there, some thirty scam centers operate: apartment buildings full of Julias, who together have already earned some 75 billion dollars from people who were too gullible. Many of those approximately three hundred thousand Julias do that work involuntarily. They have been lured there by human traffickers under false pretenses. They live in captivity and if they don’t perform well, they receive corporal punishment.

Last week’s blog included a link to an article saying that Thailand had cut off internet and power to the border region with Myanmar in an attempt to cripple the scam centers. That shows how powerless you really are in the fight against criminals operating from a country that doesn’t put the slightest obstacle in their way. The article didn’t say anything about the extent to which the scam centers were dependent on Thai services, but by now they will have found a way to continue operating. That probably doesn’t apply to innocent citizens and businesses in the border region, who have also been affected by this well-intentioned measure.

Cybercrime in this form is only possible thanks to technology that was never conceived with this purpose in mind. With the help of translation services such as Google Translate, Julia was able to chat with her victim in perfect Dutch. Artificial intelligence is also increasingly being used for evil. I will once again make the comparison with dynamite: when Alfred Nobel invented it in the 19th century , he did not foresee that it would be used to blow up bank vaults and soldiers. And dating apps were also not set up as a platform for crime with a romantic prelude.

If the crime is not tackled, then its potential victims must be made resilient. Unlike a street robbery, you do have a chance to escape from those fraudulent practices. It is actually quite simple: if a new contact suddenly brings up money as a topic, you have to be careful. Take off your rose-colored glasses and look at what is happening through a magnifying glass. Discuss your doubts with someone you have trusted for years; not with Julia, because she knows all sorts of ways to reassure you. Just say firmly that you are not interested. You are using that dating app to find love, not to get rich.

If necessary, print out that piece of folk wisdom and hang it above your screen.

 

And in the big bad world…

 

2024-10-04

The Sandman

 

Image from Pixabay

In some countries in the world, criminal organizations kidnap poor devils and force them to send out scams seventeen hours a day, said Nathaniel Gleicher, global head of counter fraud from Meta this week at the annual ONE Conference in The Hague.

Meta, the parent company of Facebook, Instagram and WhatsApp, among others, is not exactly the darling of privacy-minded citizens. But what Gleicher had to say at this conference matters. Because let the above sink in for a moment: people are being held against their will to bombard you, with bags under their red-rimmed eyes, with deceptive messages. In my world, scam refers to deception via false messages. For example, that text message about a troubled delivery, a WhatsApp message that starts with "Hi dad, I have a new phone number" or an email in which "the bank" announces a security check for which they need your cooperation. In short, pretty much everything that can be classified as phishing.

The reprehensible activities of cybercriminals are a problem for Gleicher, because they abuse his platforms. And apart from the moral obligation to do something about it, Meta also has a clear business interest here: if users are confronted with fraud on Instagram over and over again, they will eventually stay away, or at the very least they will become so suspicious that they will no longer click on anything, not even on bona fide contributions. And that means loss in revenues.

Meta divides fraud and scams into three types of problems: actors, behavior, and content. Actors include everything that has to do with false identity: you think a message is from a friend or a celebrity, but in fact there is a criminal behind it. Behavior includes everything a criminal does: deception, spam, even playing on your (romantic) feelings. The content type of problem encompasses celebrity bait, financial deals and charity, to name a few.

Gleicher wants to combat this vigorously, but his billions of normal, well-intentioned users should not suffer too much from it, because that would be bad for business. And so he focuses on the malicious ones. An important part of that is taking down fake accounts as quickly as possible. To do that, they look at the behavior of an account. For example, if a biography states that you live in the Netherlands, but all activity comes from a country far away, that is a red flag. And they use artificial intelligence to detect whether someone is misusing photos of celebrities. Think of a photo of Elon Musk with a golden tip to purchase bitcoins 'via this link' .

Criminals use mechanisms that are intended for honest people. Did you forget your password? Then click on a link and you can set a new password via the email sent to you. But if a criminal has hacked your email, he can do so on your behalf (it is therefore important to realize that your email is by far your most important account). Meta is trying to put a stop to this with innovative developments. For example, they are currently piloting a new method for account recovery: you have to supply a new selfie, which they compare to photos in your profile. The idea behind this is that criminals cannot simply get a fresh selfie of you.

Scams run across multiple layers, such as social media and banks. This makes it difficult for one party alone to recognize scams. At the ONE Conference, Gleicher announced the FIRE program ( Fraud Intelligence Reciprocal Exchange), in which British and Australian banks provide information to Meta. In an earlier phase of the program, this had already led to the removal of some 20,000 fake accounts.

The British talk about throwing a spanner in the works, the Americans throw a wrench, but the Dutch throw sand. Hence the title of this blogpost: Meta throws as much sand as possible in the works of internet criminals. You could say that Gleicher is the sandman of social media.

 

And in the big bad world…

 

2023-06-09

Pippi Longstocking

 

Image from Pixabay

“Pippi Longstocking follows you and invites you to connect.” If you don't recognize this text, then you are one of the few readers who are not on LinkedIn, I think. If you are a member, then I have two questions for you: how do you respond to such invitations and how would you respond better?

For your convenience, the invitation mentions that you and Pippi have some mutual friends: Tommy and Annika. That should serve as a kind of reference. However, I don't trust that, especially since I once asked a colleague how he knew such a Tommy or Annika. “Who?” was his telling response. Many people blindly click the button to befriend the new contact.

LinkedIn, the Facebook for professionals, like all social networks, benefits from a growing number of members. They therefore make it extra tempting to click on 'yes': Pippi only asked if you wanted to be friends, LinkedIn added Tommy and Annika on their own initiative. But who is that Pippi anyway? You can already view her profile before accepting her friendship. If Pippi Longstocking, as we all know her, were on LinkedIn, her profile would look something like this. Job Title: Boss. Company: Villa Villekulla. Education: none. Knowledge: everything. Skills: being strong and rich. Number of connections: millions.

On LinkedIn I found three accounts under the name Pippi Longstocking. Those accounts have a lot in common: one or no followers, never posted a message, no photo and a very empty profile at all. One of them claims that she graduated from Harvard Business School in 2016 and is the founder of a candy factory in Kansas. Number two is the boss of a sportswear and accessories company in California and the third is a self-employed menu planner in England.

I have no idea what the point of these accounts is, but I do have an idea of what one can do with fake accounts. The platform has been reported as a highly prominent tool of phishing cybercriminals. LinkedIn explains it this way: “Fraudsters may use a practice called phishing to try to obtain your sensitive data such as usernames, passwords, and credit card information. These fraudsters impersonate legitimate companies or people, sending emails and links that attempt to direct you to false websites, or infect your computer with malware.” And they provide even more information and examples of LinkedIn-related phishing.

The three Pippi accounts I found are far too bare-bones to be used for phishing purposes. Real fake accounts usually contain an impressive profile, which makes them appear realistic. The photo shows a pretty young lady rather than an ugly guy. And often those photos are fake too: last year, researchers at the Stanford Internet Observatory discovered more than a thousand artificial intelligence-generated profile photos on LinkedIn. Sigh – now you not only have to recognize phishing mail, but you also have to learn to recognize AI photos. And that's not easy, especially with stamp-sized photos. In addition, fake accounts paint the image of a highly experienced professional in your field. Basically, you see someone you'd like to add to your stamp collection.

Incidentally, phishing is not the only thing you can do with this. Connecting via LinkedIn can also be used more broadly for social engineering – hacking the human – with the aim of getting someone to get information or do certain things. At first there may be just be some (professional) chitchat, and then gradually move on to topics that your employer might prefer you not to talk about.

Back to the questions at the beginning. Do you blindly accept connection requests? And if so, what do you think about it after reading this blog? I handle them this way: I always accept requests from colleagues (after checking whether they are really colleagues), and I only accept other people if I have met them in real life before. That's what it says in my profile. Not everyone reads that – I decline some connection requests every week. Very rarely will there be a criminal among them, but at least I keep them out this way, too. Does that mean I have fewer connections? Yes, but so what? And if you would like to read the Security (b)log on LinkedIn, you can simply follow me.

And so, dear intranet editor-in-chief, Pippi Longstocking made it into a work-related blog (-;

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...