
Is this the real life? Is this just fantasy? A company in Hong Kong suffers a sophisticated deepfake duping, be one your guard from pig butchers as Valentine’s Day approaches, and spare a moment to feel sorry for poor ransomware gangs.
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Lianne Potter from the “Compromising Positions” podcast.
Warning: This podcast may contain nuts, adult themes, and rude language.
Show full transcript ▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Hello, hello, and welcome to Smashing Security episode 358. My name's Graham Cluley.
Great pleasure to invite them to the show, Lianne Potter of the Compromising Positions podcast.
We're a new podcast and our aim is to interview non-cybersecurity people about cybersecurity. So it's kind of part therapy session, part deep dive into how do we do things better.
So basically every week I get someone in from a non-cybersecurity background. Every week we have a different topic.
I have lots of really nice takeaways for people working in cybersecurity to take away and make their security controls actually work, which is what we really wanted to happen.
So yeah, the reception has been great. We were big in Denmark for a week. Don't know how, don't know why, but for a week in Denmark we were charting in the top 20.
Let me take you by the hand and lead you through the streets of Hong Kong, where a multinational firm has, well, one of its many offices all around the world, but they've got a significant presence in Hong Kong, shall we say.
And we are told that a massive fraud has recently taken place. According to Hong Kong police, a company has lost 200 million Hong Kong dollars.
And for those of you not familiar with the exchange rate, that's about 25 million US dollars, or in British pounds, let me work that out. That's about 900 billion at the moment.
So it's a lot, it's a lot of money. After one of its staff fell victim to a scam.
Now, this particular employee worked in the finance department at this Hong Kong branch of this big multinational.
I wonder why that might be. Really?
If they were after data, if they were after information about your personnel, then they might go for the HR department.
But if they're just strictly after the money, why not go to the finance department, particularly in these days of business email compromise and CEO scams and those sort of things?
It's not that uncommon.
So in the middle of last month, in the middle of January, this person in Hong Kong received a message from what they believed was their UK-based CFO, the Chief Financial Officer, asking them to transfer some money.
Now, you know, instantly we have multiple alarm bells going off.
Like if it's a normal occurrence that the guy goes, throw 10K into this account pronto, chop chop, like, you know, you wouldn't bat an eyelid if he made that request.
There may be a little bit more double checking.
Why can't I have it this easy?
And so I put my expense claim in for my cat to go into a cattery because I was going — it was a nightmare. Couldn't get them to pay for my cat. Was I being unreasonable?
I don't know.
I'm just about to put my dog through doggy daycare and I'm thinking about claiming back on expenses through that.
Anyway, so this request came through claiming to be from the UK-based CFO.
And I think probably at this company, 'cause it's a big multinational, there were rules about this kind of thing. This person was working in finance.
They thought, oh, you know, I have to be sure because this could be a fraudulent email.
So maybe they're using Teams, maybe they're using Zoom or whatever, where they could have a chat to describe what was going on.
And we have described many times before how it's possible to create fake videos of people saying what someone else wants them to say. So deepfake videos.
So you have to be careful on a video call. But a video call, I would argue, is perhaps a little bit more convincing because you're having a conversation with somebody.
What do you need £1,000 for?
Possible to create fake videos. You know the TV game show Countdown on Channel 4?
She picks, you know, 3 big ones and 2 small ones, and can you make them all count up to 793 or something, right? And Rachel Riley is a maths wizard.
And 5 years ago, 5 years ago, you think deepfake is a new thing? Poppycock!
5 years ago, HSBC made a video showing how it was possible to make Rachel Riley say that she was bad at maths, and that answers to tricky maths puzzles were being fed into her earpiece.
They wanted to warn their staff, and indeed they wanted to warn customers as well about the dangers of deepfaked video and how this was possible and how you shouldn't necessarily trust someone just because you can see them saying something.
Look, my leg's pumping out blood, you know, and you'd have to show that in order for people to believe you? I don't know.
I'm going to join this Zoom call.
But what allayed their fear is when they joined the video call, they found it wasn't just with the CFO, it was with multiple other people inside the organisation, other senior members of staff and some outsiders as well.
And according to the cops, the company employees on this call looked and sounded like people the targeted employee did recognize inside the organization.
You're wrong.
So I imagine if I joined one of these calls with all these people jabbering on, I'd be like, ooh, okay, this is serious.
He says that in previous cases, the scam victims have been tricked in one-on-one video calls. And this, of course, was a multi-person video call. And everyone that they saw was fake.
They said the scammers were able to generate convincing representations of targeted individuals that looked and sounded like the actual people.
I don't know what's going on. February. But you know, you would notice. You would just notice. That's a lot of money. Most people would notice.
So the police say that they've carried out an investigation and they have found that the meeting participants had been digitally recreated by the scammers, as I described, using publicly available video and audio footage of those individuals.
And they imitated the voice of their targets reading from a script. So it's quite sophisticated, this, what they've done here.
And apparently on the call, they asked the victim, you know, when you go around, you say, "Okay, if everyone can introduce themselves." And so they got the victim to introduce themselves, but they didn't interact with them at that point.
And the meeting ended rather abruptly after they gave the instructions. But it was enough to dupe them. But here's my actual question. I said, is this Hong Kong phooey?
How do the police actually know that what they're saying happened happened? They haven't made any arrests. How do they know that these were deepfakes?
How do they know that, for instance, it wasn't the real CFO and his colleagues telling this employee to move the money into these bank accounts?
Because what a wonderful— it's a bit like saying, "We were attacked by a state-sponsored hacking group, and therefore we don't have to admit—" It's super serious.
Yes, it was a very, very— it's very convenient, isn't it? Say, "Oh well, it was deepfakes."
Anyway, the police say if you're not sure if someone is a fake or not on a video record, they've come up with some advice. Uh-oh.
And their advice, they said, is ask the person to bobble their head around a bit. Now, I don't think that's— I don't think that's going to always work.
I think if it's a pre-recorded video, maybe it would work.
But these days with deepfakes, you could have an actor actually playing the part and then having a deepfake face munged on top of them to fool you. So they could bobble their head.
So put your head right into your chin, roll around, just get everyone in the meeting to do that. And then you've got a nice workout as well.
We can enter the details of an account and see if it is connected to past scam activity. They call it the one-stop scam and pitfall search engine.
But a little word of warning, because last year scammers sent messages to people saying, oh, you know, we're the police. We've recovered more than $50 million from a past scam.
If you want to check whether you're one of the people who are going to get your money back, go to this link.
Go to the fake version of the Scam Eater app, which will steal your money and your personal information as well.
Turns out that payments have dropped down to a new low of 29%.
Now, when they first started tracking this trend, it was at 85% were choosing to pay these ransomware gangs.
But however, they said in a recent analysis of the data in the last quarter of 2023, 29% dropped to a brand new low.
So from 85% to 29% in just in the space of a few years, which is— that's pretty good.
And obviously there's lots of moral and ethical questions about whether you should pay or not, which, you know, you've gone through on the show many a time.
But what this report suggests is the reason why these payments are going down is due to awareness, which, you know, pat on the back everyone with the messages getting out there.
People are listening and it's awareness in the sense that people are understanding that ransomware or being hit by ransomware is not a question of if, but a question of when.
And, you know, as such, people are starting to take heed to the things we've been saying for ages, which is more robust backups.
So is it that these companies don't care if the data is released because there have been so many data breaches?
Everyone's had their personal information exposed in the past and what's a little bit more?
But if you watch the trends of companies that have had a breach, it kind of just goes back to normal quite quickly.
And by quite quickly, I mean in the space of sometimes weeks, sometimes months.
Or sometimes it even does better 'cause then people think, oh well, actually they're reinvesting into security.
So, you know, you see the likes of Uber who, you know, quite a lot of breaches and then lots of job adverts the next day come out for cybersecurity professionals.
So you can kind of see how that might be a thing.
But this article suggests that unfortunately it isn't the security team people are listening to about that message of have good backups.
It's actually just because mainstream media, which is great.
So not your likes of your cyber publications or your tech publications, you know, the things like your BBC News, your Guardian, etc., making cybersecurity issues and ransomware headline news.
And in particular, what's really kind of convincing people that they're, you know, less likely to pay is because of the stories where ransomware groups are not returning the data after it's been paid.
So they're not keeping up to their end of the bargain.
So I feel really sorry for these legitimate quote-unquote ransomware gangs who do have good practices of managing and keeping up to their end of the bargain.
And it's just a few of these bad ransomware gangs that are just really letting it down for everyone else. And as a result, there's this big drop in ransomware payments.
Then we'd know, maybe each ransomware gang could have a, you know, a points out of 5, 5-star rating or something, say, look, we're really trusted, whereas the bad guys wouldn't be trusted.
And so you'd know that you were likely to get your data back or likely to have them destroy it properly.
You know, when there's a new restaurant that's open, it has really good reviews and all the restaurants around it wanna kind of compete and up their game a bit. Oh, right.
That'd be really good for ransomware gangs to kind of up their game and rebuild the trust back into the community, into businesses that, you know, when they do ransomware, that we're actually gonna get what we paid for back.
There'll be layoffs in the ransomware world. Oh, bless them.
Because you know, the whole idea of it is, you know, ransomware is really low cost, really great return on investment.
And if that's not working, what's the next thing that they're gonna turn to that has such a good return on investment?
And that's probably where you're gonna see, I'm going to say it 'cause it's not been really said yet, AI and things like that. You mentioned it. I mentioned it.
Phishing test, AI and things like that into the mix to make it still, you know, low cost, high gains for them.
But what was also interesting about this article was there was a second part of the section which says the person who's done the study, so Coveware, said let's enjoy this downturn naturally because one of the other conversations people have been having is about banning ransomware payments altogether.
Now, they say that according to their research, when places like Florida, which I wasn't aware actually that Florida has banned ransomware payments, and they have done so since 2022, they've not seen any noticeable difference in the number of attacks they've got.
So that's a number of attacks, not payments.
And according to this article, that they're saying if we ban it then it just shows the cybercriminals that we're unable to look after ourselves.
Whereas if we keep it as is and people keep practicing this good security hygiene, then slowly it might fizzle out on its own accord anyways. I'm, oh God, I'm so cynical today.
Or is it Saint Valentine's Day? What do you say?
But the whole idea that the entire country has to go out to an Italian restaurant and book a table, that doesn't seem terribly romantic to me.
Much more romantic, obviously, just to, you know, sort of slob around on the sofa and put something in the microwave and say, there you go.
So having another day where you have to just surround yourself with hearts and flowers, and like you say, Graham, overpriced special Valentine's Day menus.
You know, you could be going to your favorite restaurant, but oh, they've added a surcharge on top of that.
And with ransomware payments the way they are these days, I don't know if I can afford it.
In my case, do I buy the Yeti eraser, right? Is that a good gift? He obviously doesn't have one.
Some of us are single, and Valentine's Day may not be the holiday you most look forward to. Unless you use it as a springboard to hop back into the dating saddle.
So I don't know about you, I have a number of friends right now, extended family, that are suddenly getting back on the dating scene.
I don't know if it's a New Year's resolution, or to avoid a solo Valentine's Day, but people seem to be refreshing wardrobes, hitting the gym, updating their profile you know, they always are catching a big fish or climbing a steep mountain, shuffling along a beautiful beach.
The stuff we couples do all the time, let me just assure you. Yep, all the time.
It's never someone sitting on a sofa eating, you know, family-sized bag of Cheetos or whatever. But the first port of call these days is you go online.
You don't tend to go down to your local Superdrug, see someone cute, and then approach, because it could be pretty dangerous depending on what they're trying to buy.
I don't know if conversation opener of 'Hi, you itchy?' is a good idea.
You'd probably, Graham, you'd be looking for someone who looks like a dead actress from the '50s, I'm sure.
And if you start now, maybe in a week's time when Valentine's Day is upon us, you might already be starting to feel that warm sparkle feeling, you know, of a budding relationship.
Well, I'm here to say stop right there, people. Because according to Lloyds Bank this past weekend, romance scams have increased more than 20% in 2023 compared to 2022.
And I have a few questions for you just for fun. So what age group do you think reporting losing the most money?
So averaging £13,000 on average in this age group, almost doubling the average across all romance scam reports in the UK.
We're looking for love, we're looking for that dance partner to really take us onto that nostalgia train.
It's a thirst trap. No, is that not what's happening?
According to the Canadian Anti-Fraud Centre, romance scams cost 945 victims more than $50 million, an average of $53,000 per victim. We're way too trusting, Canadians.
Way too trusting.
You know, the Hollywood actor Mark Ruffalo? Who's the Hulk or something.
And her friend is completely hook, line, and sinkered and ready to give them a fortune. Completely convinced. And she was saying, what can I do about this? It's horrendous.
And you can imagine people giving a huge amount of money because they think, oh, but it's going to be love.
So in your case, right, this may have gone on for months. And it might carry on until he asks for money.
And usually the claims are family issues, medical bills, needing money to arrange to meet up because their money's all tied up.
And what douchebag wouldn't help out a brand new potential partner? Especially when you've been talking daily for months and want to meet. Have you heard this term pig butchering?
In contact with romance scams? I hadn't heard it. Shows you how much security—
And they do it online now because that's where everyone spends their time. And scammers take advantage of this.
And perhaps, I don't know, do we need to lean on dating sites to do more? Is that the problem here, that we can't trust them?
I mean, if they're using images that are already taken from somewhere else on the web to use as their dating pictures.
And the scam is really occurring when people begin chatting though, isn't it? It's not necessarily even on the dating site.
The dating site is the initial hook, but then they're chatting to you on WhatsApp or whatever it is, and it may be months and months down the line before they say, "Oh, I've got this great investment in cryptocurrency.
You should really do it too, 'cause I love you so much. Why don't you put some of your money in? I'll do it for you if you like.
If you don't know how to do it, just wire me this money." And bam.
But one of the things he mentioned is I create a new profile on Instagram, I go out and try and lure in as many women as I can that fit the profile that I'm trying to get.
And then I need to get them off Instagram as soon as possible. Because if someone finds out and reports it, the account gets taken down.
And then I've lost contact with all the other people I've worked on.
You really want to establish a second means of communication quickly, which could be a warning you know, if you're talking to someone. But it's kind of scary.
So during this romantic time, keep your wits about you. If you meet someone new, don't not tell your friends and family.
So at least in your case, what you were reporting earlier, Graham, they've told a friend and family, but they're not listening to the friend and family saying, take heed.
And it's really hard to convince people otherwise because when they say, you know, you make first impressions within the first microseconds of meeting someone, it's really hard actually then to go back on that.
And yeah, that's how come they're so successful. It's just, it's so sad when even when you actually see the signs, you just cannot convince the other person that it's not true.
A comfortable distance away, and then say something romantic. When they walk out, say something "Hey, did you get what you came for?" And wink or something.
Yeah, she found her guy at the zoo.
Wouldn't it be great if a device which lacked compliance or lacked security was denied access to your organization's SaaS apps and other resources?
Because this would mean that the hackers who had nabbed the unlucky employee's credentials, for example, could not gain access to your assets. It would effectively lock them out.
Welcome to Kolide, a world where access is only given to approved, secure devices. As the administrator, you can manage every operating system, even Linux, from a single dashboard.
Another bonus of Kolide: employees can often fix their own problems without involving IT support, meaning less resources are needed to effectively operate a more secure environment.
Kolide is the device trust solution for companies with Okta. Kolide ensures that if a device is not trusted or it's insecure, it is denied access to your cloud apps.
Learn more at kolide.com/smashing. That's k-o-l-i-d-e.com/smashing. And huge thank you to Kolide for sponsoring the show.
Expanding the scope of your security program with Vanta's market-leading compliance automation, saving your business time and money.
Vanta has over 5,000 customers around the globe who are saving over 300 hours in manual work and up to 85% of their costs for SOC 2, ISO 27001, HIPAA, GDPR, custom frameworks, and more.
And with Vanta's 200+ integrations, you can easily monitor and secure the tools your business relies on.
From the most in-demand frameworks to third-party risk management and security questionnaires, Vanta gives SaaS businesses of all sizes one place to manage risk and prove security in real time.
And as a special bonus, Smashing Security listeners can get a stonking 20% off Vanta. Just go to vanta.com/smashing to claim your discount. That's vanta.com/smashing.
And thanks to Vanta for supporting the show. And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week.
Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they like.
It doesn't have to be security related necessarily. Better not be. Well, my Pick of the Week this week is not security related. I am trying to stop my brain turning into mush.
Started a bit late. Well, yes, possibly, possibly. But I realised I need to do more than just play chess badly.
So I've also been playing a little bit of Sudoku, which I'm sure you guys have all played in your time.
But I, you know, I was doing a bit of Sudoku and I thought, I'm not entirely happy with this app.
So I went into the App Store and I was looking at Sudoku apps and I was trying them out.
And they've got bad user interfaces or they've got intrusive ads or they're really unforgiving because if my fat fingers happen to press the wrong button or the wrong square, it goes, "Oh no, you've made a mistake.
Oh, if you make another mistake, you're going to, you know, forfeit the game." And it's like, no, I do know. I know what I was trying to do. I just pressed the wrong button.
Don't be so mean, I'm thinking. Why should I?
And it can handle— sausage finger compliant. And I found it at sudokuexchange.com, which is a lovely, beautifully designed little website with lots of sudoku exercises.
It suits all of my requirements. I'm very happy using it. I'm not very good at sudoku. I've got to get up to speed. My partner, much faster at it than me.
But I like this little website, so that's what I'm using. So my pick of the week is sudokuexchange.com.
Every morning when they wake up, they both have the same— two copies of a Sudoku book, and they race each other. Oh my goodness. Oh my God. They go, okay, we're doing number 59, go.
And that's what they do before they do it.
Yeah. Carole, Graham, picture this, right? You're both on stage and the crowds look at you and the host of the event says, now, how do these two people know each other?
So you and Graham, and the voices in the audience all call out, but one's louder than the rest, and they say coworkers. Great. So the host nods and then asks another question.
So where do they work? And then you hear a choral sound, and the sound is, in an abattoir, they demand.
And then the host then turns to you and says, right, you're both coworkers who work in an abattoir. Begin your scene in the style of a 1950s musical.
How would you both feel about that situation?
So for the past two years, I've been spending my time getting used to situations like that, not working in an abattoir, which is the most requested place of work in a scene. Really?
Absolutely. Gross.
But I've been performing as part of an improv group, and I couldn't have done it without my pick of the week, which is the Laugh at Leeds Stand-up and Improv Comedy School.
And I've always been a fan of shows like Whose Line Is It Anyway since I was a kid, and I was always in awe of their ability to kind of think on their feet, you know, and I guess even more so be totally unfazed when a joke bombs or doesn't land.
I don't know if you've watched any of that show recently, revisited or anything like that. Whose Line Is It?
So for a decade I've been keep saying to myself, I'm going to do a course in improv one day.
I've been putting it off, putting it off until I actually met someone in real life who was— who'd done the course several times and said how amazing it was.
So I went along and did it and I've had the bug ever since. And the way it works is that they run courses really regularly in 6-week blocks.
So you start off absolutely terrified, I'll be honest with you, and then by the end of the 6 weeks you're actually performing on stage in front of people doing improv. Wow.
It's really great and it's amazing to see your peers, people you're on the course with go from really nervous, just as nervous as you are, and to be this really confident, funny individuals.
And it's got to the point now where I actually regularly perform as part of my own improv troupe, Roll With It. So I've learned some real amazing practical skills.
It's really helped with my public speaking, how I approach work, you know, how to be cool with, you know, coming off script, you know, injecting a bit of humor into proceedings and things like that.
So, ah, we've been breached, huh? Let's have a joke.
I think that's almost the skill is you need to take in and also come up with something.
So one is listening, and then the other one is a principle called "yes, and." Now, "yes, and" means that you embrace the scene, so you take in whatever suggestions.
So abattoir, for example, and 1950s musical. It wouldn't matter if you didn't know anything about a 1950s musical. You just have to roll with it. And it's just a really great thing.
And what I think we could learn from in cybersecurity about it as well is that yes and principle is, yeah, when people come up to you in the business and say we want to do something, instead of just saying no, we can't, yes and maybe we can look at it from this security angle would be a really useful thing to do.
So that is my pick of the week. Learn improv if you can, and if you can learn it at Laugh at Leeds.
So I did go on one, and at the end they were going around everyone and saying, you know, you were really good at this, you were good.
They said, and you, they said, point to me, you're really good at bullshitting. They said, you're really good at just—
I wanted something extremely anti-Valentine's-y, right, to counterpoint my story that I've mentioned earlier. So this is a TV series, not a new one.
I think it came out, first aired in 2017, called Mr. Mercedes. It's based on a famous trilogy by a horror god, Stephen King. Now, as a kid, I read a lot of Stephen King.
I really liked— me too. Yeah, right? I just loved it. Anyway, so this book, Mr. Mercedes, is what King calls his first hard-boiled detective story.
So you have this retired detective, Bill Hodges, played by Brendan Gleeson, who is haunted by his old unsolved case, Mr. Mercedes.
And this is where a nut job stole a Mercedes and drove it through a line of job seekers at a local jobs fair, okay, killing 16 people. Horrible, right?
And we have a retired detective who is curious about tying loose ends up and starts asking questions, giving this Mr. Mercedes a brand new person to toy with.
And the game goes pretty dark pretty quickly. I cannot underline enough how dark this is. I could not watch scenes at all.
I even had— My husband and I, last night, we were watching the last episode, literally, where I was humming. He was reading the text to himself.
He wasn't telling me, and I was humming, and my eyes were shut, and my fingers were in my ears, 'cause I just— The scene was just too disturbing.
But the best thing for me is the soundtrack. It's so good.
So, your detective has a mixtape moody blues soundtrack that's always playing, some old country, really gorgeous stuff, curated so well.
And your psychopath is more into the alternative indie rock with punkish overtones, stuff from the '90s. And both of them, great tunes. I loved it, loved it, loved it.
So if you want something super dark and non-romantic at all, my pick of the week, Mr. Mercedes, currently streaming on Disney+.
Lianne, I'm sure lots of our listeners would love to follow you online and find out what you're up to. What is the best way for folks to do that?
And you can also listen to me every Thursday on my podcast, Compromising Positions. We accept listeners from anyone outside of Denmark as well.
And don't forget to ensure you never miss another episode, follow Smashing Security in your favorite podcast apps such as Apple Podcasts, Spotify, and Overcast.
For episode show notes, sponsorship info, guest list, and the entire back catalog, more than 357 episodes, check out smashingsecurity.com.
Hosts:
Graham Cluley:
Carole Theriault:
Guest:
Lianne Potter – @Tech_Soapbox
Episode links:
- ‘Everyone looked real’: multinational firm’s Hong Kong office loses HK$200 million after scammers stage deepfake video meeting – South China Morning Post.
- Countdown’s Rachel Riley is deepfaked by HSBC – Vimeo.
- Scameter – Cyber Defender HK.
- Warning as scammers fake police Scameter app – The Standard.
- Ransomware payment rates drop to new low – now ‘only 29% of victims’ fork over cash – The Register.
- New Ransomware Reporting Requirements Kick in as Victims Increasingly Avoid Paying – Coveware.
- Romance scam reports rose by a fifth in 2023, says Lloyds Bank – The Independent.
- What is a ‘pig-butchering’ scam – and why is it on the rise? – BBC.
- Pig butchering mining scams: What they are and how to stop them – SC Media.
- No love for romance scammers in 2024 – Consumer Advice.
- Romance scammer reveals how he tricks women after failing to fool Go Public reporter – CBC.
- Sudoku Exchange.
- Learn Improv at Laugh at Leeds.
- Mr Mercedes – Disney+.
- Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
Sponsored by:
- Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky at @smashingsecurity.com, or on Mastodon, on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.


