Geoff White on The BEYOND Podcast: the investigative journalist who explains how cybercrime organised itself into a global industry
The Field Guide
Geoff White, the investigative journalist covering organised crime and technology, joins host Aleksandra King on The BEYOND Podcast to explain how cybercrime stopped being a technology story and became an economy: government hackers, crime gangs and activist hackers blending, ransomware run as a franchise, targets researched like acquisitions, and money laundering holding the whole structure up.
| Featured guest | Geoff White |
|---|---|
| Organisation | Independent |
| Source media asset | Geoff White: How Cybercrime Became a Global Industry (The BEYOND Podcast) |
| Core topic or methodology | cybercrime |
| Key fact | Ransomware's affiliate model pays the operative 80% of the ransom, with 20% kicked back to the gang that loaned the virus. |
Geoff White is an investigative journalist covering organised crime and technology. His work explains how hacking, fraud and money laundering fit together, and who the people behind them actually are; his own site describes a career spent reporting on cybercrime and financial crime across books, broadcast and podcasts.
On this episode of The BEYOND Podcast he speaks with host and producer Aleksandra King about the industrialisation of cybercrime: the three groups behind the hacking, the ransomware franchise economy, criminal due diligence, and why money laundering is the part that makes all the rest possible.

Key takeaways
- Three once-separate groups do the hacking: government hackers, organised crime gangs and activist hackers, and they are blending.
- Government hacking is the new face of espionage, and in Geoff White's account it is allowed, warranted and necessary rather than something he condemns.
- The criminal hackers largely learned to think in video games, where the skill is finding what the other side did not expect.
- Ransomware runs as a franchise: the gang loans the virus and the affiliate keeps eighty percent of what the victim pays.
- Crime gangs commission due diligence on targets the way a corporate acquirer would before a takeover.
- Money laundering is the load-bearing structure: without it, he argues, none of the rest would happen.
Who is actually doing the hacking?
Geoff White, the investigative journalist covering organised crime and technology, starts with a taxonomy. On the cybercrime side there are, roughly speaking, three groups of people. Government hackers first: the UK has them at GCHQ, the US has them, and most governments worth their salt employ good hackers, because adversaries keep their secrets on computers and espionage has moved to where the secrets are. He is explicit that this layer is allowed, warranted and necessary; his phrase for it is the new face of espionage, and it is a description, not an accusation.
Most governments worth their salt have government hackers, have good hackers
Then come the organised crime gangs, and the activist hackers who sit around the edges of the video gaming world. The three used to be separate. What he has watched happen is a blending: governments borrowing techniques from activists, and crime gangs getting hold of the kind of cyber weapons governments use and turning them to making money. That blending, in his telling, is why cybercrime is now so big.
Why are video games perfect preparation for hacking?
Asked where the skill comes from, he points at the video gaming community. Young people who live their lives online learn to think from the left field, to find the thing the designer did not expect: press three buttons in a particular order and suddenly you can fly, or walk through walls. That habit of thinking around corners, he says, is perfect preparation for hacking.
The exchange in the room is direct. “What is what’s their skill?” Aleksandra King, the interview podcast host, asks of the activist hackers who sit around the gaming world. “So a lot of young people live their lives online, and in the video gaming community particularly, these people will be spending hours and hours of their time online,” Geoff White answers, and the skill grows out of the hours: games teach you to think from the left field.
Constantly thinking, what's the thing that they haven't thought of?
The application is direct. A target has built its website expecting it to be used one way; the attacker types commands nobody expected, and the site crashes in a way that makes the data behind it available. The skill is not the machinery, it is the imagination about what the other side has not thought of.
How does ransomware run as a franchise?
Ransomware is the plainest business model in the conversation: break into the computers, scramble the files, charge the owner to unscramble them. What has changed is the structure around it. The gangs have built affiliate networks, so that anybody can now enrol as a ransomware operative: the gang loans out the virus, the affiliate infects a victim, and when the victim pays, the split is set.
if the victim pays up you get 80% and 20% kicks back to the ransomware
Aleksandra King's comparison in the room is Starbucks, Burger King, McDonald's, and he does not resist it: it is proper business practice. The virus writers, he thinks, are largely based in the Russian Federation, but the people using the virus could be anywhere, which is exactly the shape of a franchise: the product is made in one place and operated everywhere.

Why do crime gangs research a target like an acquirer?
The section of the conversation most useful to anyone who runs a business is about preparation. There are, he says, a lot of parallels between the way organised cybercrime happens and the way organisations work, and the first parallel is research. He compares it to a hostile takeover: before anything technical happens, you want due diligence. How many employees, in what roles, earning what, with which email addresses; the market value; where the offices are.
There's a lot of parallels actually between the way organised cyber crime happens and the way just organisations work
He has seen crime gangs pay researchers to do exactly this work, the way a corporate acquirer pays a due-diligence firm. The obsession with technology misses where the attack actually starts: with business process, a sheet of paper, and a map of where value moves through the organisation.

Why does money laundering hold the whole economy up?
The biggest claim of the episode is about the part nobody films: laundering. We think about drug dealing, robberies, hacks and frauds as the crimes, he says, but without money laundering there is an argument that none of it would happen. Crime at scale is a bit white collar; it runs on spreadsheets.
Without money laundering there's an argument to say none of it would happen
He walks it through in the first person: go into business selling drugs on the street, make a million pounds in cash, and the million is not yet a payday. You cannot spend it on the car without explaining it. The problem every successful criminal enterprise shares is getting dirty money somewhere safe, and that problem is what keeps the rest of the economy of crime viable.

Where does the cash go?
The answer is wherever cash still lives in society. He is careful with this point, and the care is worth preserving in full: cash-intensive businesses, a builder's merchant, a pawnbroker taking in jewellery, are useful to a launderer precisely because cash flows through them, and they are not all dodgy, not all criminals by any means. Criminal interest in a category is not criminality in the category: wherever you see lots of cash, criminals are going to be interested in it, not necessarily because they have penetrated it.
So wherever you see lots of cash, criminals are going to be interested in it
The mechanism itself is one sentence: take the dodgy cash and mix it with clean cash. That is the whole trick, and it is why the final stage of a digital crime is so often physical, local and mundane. His closing advice on the YouTube interview podcast is equally unglamorous, and he gives it as consumer advice: the criminals go after the low-hanging fruit, so a bit of patience and a bit of scepticism, refusing the urgency a fraud depends on, will see us right.
About the Guest
Geoff White is an investigative journalist covering organised crime and technology. He appears on The BEYOND Podcast as the guest of the cybercrime episode, published 1 July 2026.
Beyond the episode
People, Organisations and Things in this article
The transcript, in full
Preserved verbatim and visible by default. Server-rendered, no JavaScript, crawler-accessible. This is the citable layer; the editorial framing above sits on top of it, never a flattening of what was said.
The problem with cyber crime is you've not only been digitally burgled, you have no idea what window they got in and whether they're going to come back tomorrow night and the night after and the night after. Imagine that. Imagine getting burgled and you have no idea how they got in. We started to see cyber crime gangs get hold of the sort of cyber weapons that the governments use and actually using those to make money. A lot of them have ended up coming from a video gaming community. [Voiceover]: Meet Geoff White, the investigative journalist who digs into what really happens after you're hacked. Geoff reports for the BBC, Channel 4 and the Sunday Times. I have interviewed fraudsters and money launderers the world over. I've chatted online with North Korean spies. So we are talking about a generational industry that's been around arguably
30 years now. So that's ransomware gangs made more than a billion. The cost of the wonderful world of tech we live in is that we have to be a bit more suspicious. Everything has its price. It does. Work. The company got taken for $625 million, dollars, which they
Transferred out in 1 minute 36 seconds. It is happening. I'm not I'm not flamming this up. It is happening. So we all need to know about
This. We all need to be aware. The kind of people I investigate, I do not want them to know where I live. You can find out today, in today's times, you can, I think. It's quite– Go on then. Yeah, you can't find out my home
Address. What's the sort of mindset that's going on here? It's interesting. I've interviewed various criminals over the years.
Out of all the scams, which ones are the hardest to spot?
This is where we get into sort of the AI problem. The criminals always go after the low-hanging fruit. Just one thing you can do to pull yourself up the tree to those higher branches. They're going to go after the low-hanging fruit and that's not going to be you. Patience. This idea you have to make a decision now, you have to click on it now, you have to deal with it now. Don't companies want us to make quick decisions? Yeah. Push back on that. You take your time. Bit of patience, bit of scepticism, that will see us right. Episode
It's lovely to have you in the studio. Thank you for coming. When you your friends ask– you, you know, people you meet at a at a networking event or whatever, at a party, and they go, w "What is it that you do?"– you've just explained it beautifully, you know, for our trailer and all that, but what do you say to the average person in the room? What do you do?
Well, that's getting a bit easier nowadays, because increasingly people are victims of frauds, they're victims of computer hacks. A lot of people have either been a victim themselves or know somebody who has. So what I'll do is often say, "Oh, you know those dodgy emails you receive, those dodgy phone calls you get? That's the kind of thing I cover. But I cover the people, the organised crime gangs, who are on the other side of that, who are actually doing it."
Who are these people? We need to find– we're going to find out. We're going to find out. So when I was thinking about how would like how to approach this, what questions to ask, I thought, let's just start from– let's look outwards and then go inwards to these baddies and enter their their land where they lurk and cause trouble. Okay, so in terms of types of crime, right, cyber crime– how many different types are there? Are there different types, or is it just cyber crime? How do you even categorise this world?
So on the cyber crime side, yeah, you've got roughly speaking three groups of people, very roughly. You've got government hackers. We have them in the UK, they work in places like GCHQ. Got them in the US. Most governments worth their salt have government hackers, have good hackers. So it's allowed and warranted and necessary. And why wouldn't you? You know, your enemies, your adversaries have got secrets, you want to find them out. Those secrets are probably on a computer somewhere. Why wouldn't you hire somebody who can break in and steal them? It's the new face of espionage. So hacking is good? Can be used for good, depending on your definition of good. So in the UK, you know, we don't want countries to declare war on us or declare war on our allies, so we want to try and stop that. But we also want the UK to do well, so we want the UK to make a decent amount of money, to be a safe place to work. So the government's got a vested interest in having its sort of cyber spies. But you've also of course got organised crime gangs, who've increasingly realised that rather than robbing a bank with a gun and getting maybe 10 years inside, if you can hack into a bank, steal the money, but then never get caught because you're in a different country, that's probably a better way of doing things. So you see an explosion in organised cyber crime. And obviously, you know, you will have your money online, probably in an online banking situation, investments online. Increasingly our finance, our wealth, has shifted online, so the crooks have just followed it there. And the third group I'd point to is sort of what you might call kind of have-a-go hackers, sort of what you might call bedroom hackers. These people, activist hackers. So these are folks who are generally younger, generally male, it has to be said, who who like a challenge. They often come from the video gaming community and they end up in the shallow end of computer hacking. Those people are probably less technically skilled than the government hackers, but they know exactly how to run a hack, they know how to do maximum damage, they know how to do PR damage to a victim, to really embarrass them. And so that's what those activist hackers are extremely good at. Wow. What we start to see is these three groups used to be sort of separate, and we're starting to see them increasingly come together. So we're starting to see governments looking at what the activist guys are doing and thinking, well, that's quite good, we can borrow from that. We've started to see cyber crime gangs get hold of the sort of cyber weapons that the the governments use and actually using those to make money. So we're starting to see a blending of those three different groups, and that's why cyber crime is so big now. That's It's it 's a different scene.
No wonder they need you to investigate all this. Goodness me. So these– these ha what are they called again? Hacker– the activists, the activist hackers? I haven't heard this term before. Activist hackers, basically. Yeah, activist hackers. So they're sitting around, they're almost like lone snipers and they're doing their thing, but they bo what are they? Very, very good programmers, or what what is what's their skill?
Yes. So f a lot of young people live their lives online, and in the video gaming community particularly, th these people will be will be spending hours and hours of their time online. Totally. The thing about video games that's interesting is it teaches you to think from the left field, think around corners. So in every video game there'll be something you can do your opponent's not expecting. Sometimes the video game makers program that in– if you press three buttons at once in a particular order, suddenly you can fly or you can walk through walls. Constantly thinking, what's the thing that they haven't thought of? Wha How do I think around the corners here? That's perfect preparation for hacking. If You want to hack into an organisation, you want to win, you want to get in and you want to use different tactics and think of the thing they haven't thought of. Maybe this victim has built their website in a way that if I type in some commands they're not expecting, the website will crash– but crash in a way that makes all of their data available. So video gamers and hackers have this kind of symbiotic relationship. Most of the hackers I've met– hackers on the good side, but also hackers on the bad side– a lot of them have ended up coming from a video gaming community. Video games seem to prepare these people for a life of hacking.
Interesting. You could probably say the same thing about chess, although I wonder how many of them are– pl well, they're probably chess.com.
Yes. Chess. Also lockpicking. There's a big lockpicking crossover, because learning how to pick a lock is actually quite similar to learning how to break into computer networks. Like, okay, I've got through that bit, I've got through that bit, there's certain things you do in lockpicking. So there's a big lockpicking hacker kind of crossover as well, strangely enough.
It's just a shame when it's used for evil. But okay, it doesn't always have to be evil, because you can– yeah, governments use it to protect us. So it's not all bad. But there is a lot of bad. And we'll get into it. So in terms of– so w what are the types? So we've got the groups, and I suppose the question was, what are the types of cyber crime? How can we categorise the different groups of it? I mean, we know more or less, like, these phishing emails, right? So it's those emails made to look like they come from your bank but they're really not, and they're very hard to to spot. And w like what else? Like wha wha How would you categorise them?
There's various sort of phenomena in the cyber crime world. The one that's big– by the way, that's making huge amounts of money and that really keeps a lot of cyber crime afloat– is this thing ransomware, which you'll have heard of in the news. It's been big news in the UK recently. Marks and Spencer's obviously fell victim to this. It's It's delightfully easy to explain ransomware, which is one of the the few good things about it. A hacker breaks into your computer, scrambles all your files and charges you a ransom to unscramble them. It's just blackmail, it's as simple as that.
Harsh. Exactly. Harsh, harsh. But if you can get in, it's it's the most direct way really to target a victim. You know, you've you get
Access to their networks, you don't have to think much about what to do next. You go, right, let's scramble the data and just blackmail them. You know It's a very front-end, straightforward thing. That's making hundreds of millions. I In fact, ransomware had its first billion-dollar year a couple of years ago. So ransomware gangs made m more than a billion. And by the way, that's a conservative estimate, that's just the ransoms we know about. Yeah, but but
I mean, I was taught never negotiate with someone that's blackmailing. I don't know, like, well, they do it once, they do it again, you'll just– un you'll get out of it, they'll just re-blackmail you. They will retarget you, yeah. And
Also, yes, you're right, we really shouldn't negotiate with criminals, we really shouldn't pay ransoms. But if your entire business was going to go under within 3 days unless you paid, and the amount that they're charging you is maybe 10% of your revenues, because they probably know what you're able– They do. They definitely know. They've hacked into your systems. And often what they'll do is they'll look at your revenue, they might, if you're a public company, look at your market capitalisation. And the other thing they might do is look at your insurance certificate, because if you've got insurance against a cyber attack, they can say, you're insured for a million, we know you can pay a million, the ransom's a million. Oh, awful. Yeah. And so a lot of victims do end up paying. It's it 's an awful decision. There is no good outcome to this.
Okay, so that's one terrible bucket. What else is there? The other thing is obviously trying
To get hold of people's passwords. Passwords are the awful thing that we put in the internet in the beginning, that we still have, that we probably should have designed a better solution, but it's too late now. You know. You will have many passwords to your different things. So as soon as you're trying to get hold of people's passwords– people break in, they steal this valuable data. As soon as I've got somebody's password, that's a great way in. So I can then get access maybe to their online banking, maybe get access to their email. And once I'm inside somebody's email, it's a treasure trove of information. And If you think about all the stuff you've sent to people over the years, you will have, you know, maybe applied for a mortgage– that's all of your bank details. And also if I want to use that to impersonate you, well, I've got everything about you that I need to impersonate you. I can phone up your bank and every question they ask me to clear security, well, I know the answer, because it's probably in your emails somewhere. So taking over somebody's identity, I can then apply maybe for some loans, for some credit cards, using that. But the other thing is, even if I don't know how to do this, even if I get lucky, Aleksandra, I guess your password and then I break into your inbox and I'm like, I've no idea what to do with this, I can sell that access to somebody else who knows exactly what to do with it. There's a huge marketplace for people buying and selling this kind of personal data.
Gosh. Any other buckets of evil?
The other thing that's that's interesting is the crossover between cyber crime and fraud. So in my world those are treated as two separate things, it's often two teams of people who will try and defend against those things. But what I see is the cyber crime and the fraud sort of coming together. I mean, when somebody sends you a phishing email and says, you know, your Amazon delivery is late or your tax is overdue, click here, and you click and then you have to enter your password– well, that's kind of a cyber attack, but it's also kind of a fraud, because it's like somebody coming Yeah. To your door and saying, oh I'm from British Gas. You know, I need to check. Pipes. It's deception, it's dishonest. Yeah, exactly. So you see this crossover between cyber crime and fraud. And so one of the other things that's big, and actually I think is making more money than ransomware, is what's called business email compromise, which is a horrible phrase, but it's the phrase. Let's listen to this. The way this works is, I would phone up– let's say you're a big business. I phone up your accounts department and I say, hello, I'm calling from company X, we supply your, I don't know, paper or toiletries or wh whatever. You usually pay us into this bank account, but we've now changed bank accounts, here's our new bank details. So the next time you pay us, please pay us into this new bank account. Of course, I'm a fraudster and the account number I've just given is my own account, or one of my accomplices' accounts. So the business, time comes to pay the invoice, it's £100,000 or whatever, they pay into the new bank account. And then it takes a couple of weeks for the real supplier to come along and say, you haven't paid us this month. And of course the victim company says, yes we paid you, we paid you into your new bank account. And the supplier says, what new bank account? And suddenly they work out– it's been two weeks, the money has just gone. That makes billions of dollars for crime gangs every year. But again, is it a cyber crime or is it a fraud? But it's sort of done often via email, but equally it can be done by somebody who's phoning up. And there's loads of different permutations on this. There's CEO fraud, where a a a gang will contact a company, maybe the finance director, and say, I'm the CEO, you know, we've got to authorise this payment, I'm on holiday. Of course, CEOs like everybody else, they put on social media, you know, their their trip to some to the Virgin Islands or whatever. The hackers look for that, the fraudsters look for that, and think, ah, the CEO is away, I will phone up the company pretending to be them. You can use deep fake software to do this now, you can impersonate somebody's voice.
Yes, you can. And I've heard of things like this. I have heard of it very close to home. Yeah. Tens of millions has been taken out of companies. Shivers. So that's the other one that's sort of making money.
Yeah. But what what's interesting is, y you know, you can spend tens of thousands of quid of your company's money trying to defend against this, but ultimately it's about people understanding that this can happen. Everybody in your company, if you run a big company, needs to know that if they get a phone call from somebody out of the blue– even these days a video call– and it involves money, think twice.
Yeah, anything to do with money. Yeah, anything to do with money. Yeah, but it's not just– is it? It's It could be at the pretext of pretending to be relationships and then it's to swindle money. That's always something.
Yeah, the romance fraud element. The romance one. Any other buckets that we need to know about? Well, since we're mentioning romance fraud, obviously that's a big issue. What they call elder fraud in the US. Classic tactics: somebody's on one of these dating apps, gets chatted up by somebody, you know, beautiful or handsome, and then there's this long story told, and previously it would have ended up with a, well, I need some money to help me out of this situation. That still goes on, romance fraud still goes on. What's happening now is it's being crossed over with investment fraud. Okay. Cryptocurrency, as you know, has surged. Particularly under the new Donald Trump administration. And so what the scam becomes is they contact you kind of from a romance fraud perspective. You might have had this on WhatsApp, as a random message from somebody saying, oh, is that Kathy? Or John? And when you reply and say, no it isn't, they come back, and say, oh sorry, but how's your day going? And they get you into conversation. Surprisingly effective, this. This really works, because of course the profile photo is beautiful, the person is friendly, and they just get chatting to you, and there might be a bit of flirting. But in the end they'll say, oh I'm just jetting off, you know, to Dubai, business class, I'm I'm just I booked into the you know the the Marriott there, you know, obviously got the suite. And then you start to think, well, how are you making this money? And they say, oh, crypto investment, I've got a really good tip and I'm making loads of money. So it starts out with a flirty romance thing but it ends up with an investment fraud, crypto fraud thing. That's making loads of money. Do you know what, it must really be beneficial if you're one of those people that's just not very trusting. There's like a
Life hack. Yeah, just don't– Yeah, man, just don't trust any anyone that's talking about money to you. And anyone that's also– anyone that's flaunting money in that way is a red flag anyway. But can be, yeah. Dodgy. I don't like it. So in terms of region– so we know about the different the the groups or the individuals sitting in the little rooms being, you know, conjuring up all these evil things. It's And then we've spoken about the types. What about regions? You know, some more or some more active in in doing the b the bad side of it? How How does that look globally?
In terms of government hacking, pretty much every government worth its salt is hiring government hackers. Obviously wealthier countries like the UK, the US, European countries, western European countries particularly, can just afford to pay more money to, you know, hacking teams. However, there'll be hacking teams in poorer countries, you know, Pakistan, Bangladesh for example, you know, Brazil, Colombia. You know, they will be hiring people and they will be skilful operatives. So every government is trying to sort of work out what the other other governments are doing. So in terms of regions on a government level, it's going to be the classic, you know, America wants to know what China's up to, China wants to know what Russia's up to, you know, the big players. And then the smaller players around the edge trying to trying to get in. So that shouldn't really surprise us. In terms of the cyber crime side of it, the sort of organised crime side of it, we know it's a big nexus around the Russian Federation. After the fall of the Berlin Wall there was an explosion among a minority, but a significant minority, in Russia who were looking for credit card information, online banking information. And those are the guys who are now doing ransomware. So they've evolved. Interesting. So we are talking
About a generational industry that's been around arguably 30 years now. Knowledge is being passed and shared. Generational. And they're evolving and they're getting better. If you can survive– if you can survive in crime for decades, you learn. You learn how to do things right, you learn how to avoid prison, you learn the things you did wrong. So these are very experienced folks. A lot of the ransomware is coming out of that sort of territory. But what's interesting is these ransomware gangs have created a kind of affiliate network. So effectively anybody can sign up now as a ransomware operative. They will effectively loan you the ransomware virus, you then go
And infect a victim, if the victim pays up you get 80% and 20% kicks back to the ransomware. It's
Proper business, yeah. Movement going on. It's like Starbucks, Burger King, McDonald's, yeah. Business practice. Yeah. Whilst the ransomware gangs and virus writers largely, we think, are
Based in the Russian Federation, the people who use that ransomware could be anywhere. They will be distributed around the world. So we start to see the sort of federations, affiliate networks being created around the cyber crime side. In the fraud side there has been a big nexus around West Africa. There is a cliché about sort of Nigerian f fraud gangs. Unfortunately there is truth in that cliché. Okay, look, vast majority of people living in Nigeria have nothing to do with this, but again, tiny minority but significant minority around West Africa, Ghana, Nigeria, have pioneered a lot of those romance fraud tactics. Yes, for sure. It's famous now. What we're now seeing is in Southeast Asia, the gangs around places like Myanmar, Laos, Cambodia, s that's in the Philippines, setting up operations to do this thing we talked about earlier, this romance fraud, investment fraud mix. So that's all coming from those Southeast Asian networks. However, we're starting to see those spread around. They're springing up in the Middle East, in South America and so on. Because these tactics, once they succeed, other criminals look and go, well, that's a great idea, I'm going to do that. And you can just set up shop. You need some phones, internet access, some employees, but there's no reason why you can't set up one of these operations. So in terms of regions, you can say some things about where the regions are and what's going on, but increasingly we're looking at an increasingly globalised picture.
Yeah. Oh, there's some parts of the world that are better at at protecting themselves than others. I would say the US probably is really good. Or are we pr how does the UK stand?
The UK and the US obviously have quite a lot of money to throw at cyber defence and cyber security. On the other hand, they also have a lot of money. You know, if you talk about who's going after who in terms of crime, poorer people go after richer people, so that's always the flow of of of traffic. However, the richer folks have, in the US, in the UK, western Europe, probably more money to put into cyber security. They also have a lot of cyber security companies, because of course you know rich, powerful western companies want to get protection. So company X sets up and says, oh, I'll sell you some software that will stop this ransomware, you know. So you get this industry sort of evolving. So definitely in terms of the defence side, the richer countries will have more money to spend on defence, but conversely will also be more of a a target for those gangs.
Yeah. But in a way that's why you need it. It's like it's like being a celebrity and you need your bodyguard to to walk around with you. Yeah, and they might get through the gates, but then you need you need some sort of added security. So you might need that. I, at my level of fame, do not. So you would have to pay money for that. I would not have to pay money for this. It's interesting, the more profile you get, the richer you get, the more you have to spend of it on
Defence. And and companies get caught out often because– I don't know about you, I I suspect that in the boardroom conversations, if you're making money, it's going really well, you want to spend money, you want to hire talent, you want to hire some offices, do some more marketing. If you put your hand up and say, can we take 10% of that and spend it on cyber security, I don't think that's going to be a very popular conversation, because around the table people think, yeah, we could spend that money on other stuff. So again, companies tend to fall behind on their defensive spending, because it's defensive spending, It doesn't doesn't hit the bottom line, it's not exciting. Yeah, and it doesn't make profit, like
Cyber security defence spending. So, well, how's that going to make us a profit? And the argument is, well, it'll stop us losing a
Shitload of money. But that's not the same as saying it will make– it Exactly, you see what I mean? It's not attractive
As a profit. Okay, so now let's go into this now. So who's like the ultimate prize target? Who's their favourite kind? Well, obviously we have the different types, but out of all those types and all those things, who's like the best of the best for them to target? In terms of sort of organised crime gangs going after whoever, whoever of the groups, whoever of the the targets, like, what's the favourite? Back in the old days it used to be the case that you were going after the most senior people. So if you're doing
Espionage, if you're doing crime, you wanted to hit the boss, You wanted because the boss had the access, they have the passwords, they have the keys to the safe. It's the bank manager who's going to have the keys to the vault, right? So you have to get to the bank manager. So that's previously how it's gone. These days that's not quite so much the case. If you think of most organisations, most employees will have access to like the shared drive, the SharePoint or whatever you use, OneDrive, whatever you use. And that's brilliant, because everybody can work on projects together. Sure. But what that means is it's no longer so much the case that there's the one senior person in the organisation who has the key. Increasingly lots of people have the keys. And so for hackers, yes, getting through to the chief executive or the finance director is good, for government spies getting through to the head of MI5 or MI6 or, you know, the CIA might be good, but frankly anywhere you can get in is worth having a go. Because if you can get onto one person's machine, they might have access to the stuff you need. And even if they don't, if you can get access to that one person's machine and send an email from their machine to somebody more senior saying, oh, here's this document, could you click on it– yeah, you get access. You're more likely as a senior person to click okay on something that's come from your own organisation than some hacker who sent it from a Gmail. So again, are we saying it's corporate crime? That's the favourite? In a way it's
Getting into these companies that have these banks of money and whatever information. Well, money. Yeah, that's what they want, is this money. So it's it is corporate crime, that's the number one thing. Corporate
Crime is definitely surging at the moment. We've seen ransomware attacks and and and business email compromise attacks at large targets. However, However, the other end of the marketplace is what you might call the spray and pray attacks. So you're trying to trick people into downloading a virus that hits their machine, you send out a million emails to people, you know a lot of them aren't going to even look at the email, let alone click on it, tiny percentage do. But as long as that tiny percentage infect their computers, then you can sell access on. So there's the sort of what you might call big game hunters at one end, who are going after, you know, the VWs of this world, the M&S's of this world, you know, the the the the big organisations. At the other end you've got people who are basically just trying to hit everybody and sort it out. Just hit
Anyone. Because I'm just wondering, curious– that so people watching us now, just a reg it's a regular person watching, you know, they, they have a nice job, they lead their life, they're not causing trouble for anyone. How how much are they a target? Like, I'm sure they've all received a phishing email or something like that, but how much are they being targeted? At the heavy end, when we talk
About the big game hunting, the people who are going after these really big juicy targets, frankly, if you're a junior employee in a big organisation, you might get targeted, you might get phishing emails. But if I'm working on a big target as a hacker or as a as a fraudster, I want to kind of narrow down my fire to the people who are really going to get me access and really going to get me the big bucks. However, in general life, in our daily life, just as individuals outside of work, we're all constantly inundated with these phishing emails. Hacking emails. Phish being sent. Exactly. We're constantly, you know, got people trying to send us text messages saying your delivery's overdue. So you've got the two levels. There's the what's called spear phishing attacks, where you're going to a particular target, but you've also got the sort of spray and pray attacks.
Yeah, I've got things from pretending to be the bank, or like this this this one in my spam. This Tristan person who's been made for years, Tristan, saying, oh, these are the photos, click here to to see the latest ones or something like that. All these weird silly things. Or like, oh mum, it's me, can you can you reply? Like, and you think, you know. Or hi, hey. Of course there's DMs and things, which you know. But it's yeah it's ju that's a lot. So I think the regular person is getting a lot. I mean, my parents get it, elderly parents, they get all sorts of things, phone calls, pressure. And you just think, well, listen, well, anything with money or anything suspicious. Actually everything you receive is suspicious. Yes, everything should shouldn't be trusted, which is crazy. There's an element of that, yeah. It's a bit of a depressing– We'll come to this maybe at the end, but it's okay–
No, we have– life is absolutely amazing in the 2020s, in the 21st century. And I know saying this at this time in history, probably. But look, I mean, the stuff we've got: mobile phones, electric cars, laptops, central heating. Life is immeasurably better than it has been for many thousands of years arguably in human history, and part of that's technology. It's great technology. The flip side of that unfortunately is the fact that everybody's able to communicate with everybody everywhere around the world, pretty much all the time, is brilliant, it's amazing. It also means that bad people can use that communication. So unfortunately it's the cost, the cost of the wonderful world of tech we live in is that we have to be a bit more suspicious, take our time a bit more.
Everything has its price. It does. But in a way you can get the leg up, whereas if you know that they they're doing all this sinister stuff, then you adapt, you know. We also adapt, that the both sides will adapt in order to balance out, I guess.
Precisely, yeah. So the whole thing. Okay, so let's just say they're planning a cyber attack, okay, on a big company, and it's already
In work. What's. What's sort of been going on behind the scenes?
First thing you need is research. There's a lot of parallels actually between the way organised cyber crime happens and the way just organisations work. Y Let's compare this to you wanting to take over another business. You know, you want to do a hostile takeover or semi-hostile takeover. First thing you do is you research. You want due diligence on this. How many employees, where are they, what roles, what are they earning, what are their email addresses, what's the market value of the company, where are they based, offices, all of that. And actually I've seen cyber crime gangs who actually pay researchers to go out and just do that research, like you would pay a corporate due diligence company. Just find everything about this company. And what you're looking for– and this is the interesting thing, people get obsessed with cyber crime and technology– actually it starts with processes, business process. Put this company on a sheet. You can get a sheet of paper and just write it down. Right, here's this company, CEO there, the board here, the finance director. You start to draw the linkages, and what you're looking for is the bits where value is moving in that organisation. And when I say value, you think about money and bank balances, yeah, could be that, or it could be valuable information. This company turns out has a load of data about mental health, people's mental health, maybe it's a psychology company, or they have loads of information on people's credit cards, for example. So there's the money I can look at, but there's also value being stored in organisations. What's valuable in that organisation? Great. Now I've got some options. I've mapped out the organisation, I can see where value is, money maybe or sensitive data. Right, now where does that stuff, that information, that the money, or or where does the person data where is it moving between in the organisation? Does it move from department to department? Who's in charge of that? Who's the person who actually owns that database? That's the person. Right, now I want their email address, their phone number, their home phone number, their work phone number. I can go after them. Because I know if I get that person's password, that entire database of credit card data, let's say, will be mine. So there's a lot of reconnaissance goes on before the actual eventual phishing attack.
Oh, they do their research properly, don't they? They do. And what this means is when the message arrives, the phishing message arrives, it isn't a kind of click here to
See funny photos or click here for penis enlargement, it's more targeted. Oh, you know, the classic car show you were at last week, and we're doing another one in the future, and we're offering free tickets to valued members, click here to to claim that offer. The other thing that's happening is it used to be a one-and-done effort. They would send you a phishing email, if it worked it worked, if it didn't, boo hoo. These days there's a lot more effort goes into– if you've got a million pound payday at the end of it, you've got to put some effort into this. So you might send your message on LinkedIn first of all. And that's useful, because you look at LinkedIn and it's not your work email address, so your workplace doesn't control your LinkedIn security, that's you, that's your l personal LinkedIn. So I send you a message there and say, oh I loved, Aleksandra, what you did with the podcast, it was great, you know, got a few guest ideas for you, can I message on WhatsApp? So now they've got your LinkedIn, your WhatsApp. I'd love to give you a call about this, you know. But obviously I don't want to use your work email because it's a personal– ma have you got a personal email address? Or I got a bounce back from your work email, have you got another email address that I can use? I'm trying to get as many contacts for you as I can, and I'm trying to contact you in many different ways, to work up the trust. So finally when I'm ready to send you the virus that's going to really kill you off, I know exactly how to send it, because I know that your home laptop is less defended than your work laptop, and I know exactly what lure you're going to respond to. And you're going to respond to me because I've already built the trust with you. So it's a long-term exercise. Oh, it's
Violating.
I know, but it take might take me 6 months to do this. But I'll find out how many if I take you for a million, how many years' worth of pay is that for me? You know what I mean? It's it's worth me putting in the effort if I know I'm going to get the result at the other end. Oh, it's horrible. Sorry about this, but you need to know. I mean, this is the game, you know. You need to know what the game is. Knowledge is power. Aleksandra. No, no, I speak to a lot of people, I have
So many LinkedIn conversations, obviously there's guests, I mean, you know. You, you d Oh yeah, okay. It's just disturbing, that's all. Sorry. No, no, no. I want you to say– but we all need to know about this, we all need to be aware. We've brought you on so you can open our eyes. And it is happening. I'm not flamming this up, it is happening. It is literally happening.
And one of the organisations I spoke to, they had a hacker broke in, the hacker again did exactly what I've described. What I described is not cloud cuckoo land, it's not theory. They found a software developer in this company that they knew, if they got hold of that software developer and hacked them, they could hack the whole company. So they offered the software developer a job.
Which is brilliant. Like, oh, this job's great for you, mate, loads of loads of perks, great salary. And of course it was
Great, because they'd made the job up, to to attract this person. They did four video interviews with this person for a job that didn't exist, by the end of which of course this person's convinced there's a job there. And so when the final thing comes to say, just one last thing, in this job you're being hired for they use this particular kind of software, we need to just check you can do this, click here to download the software and we'll test you. You click to download the software. It's really– yeah, it it seems quite– because I was going to say, there's no ways if it's something about money or, you would just
Completely say no. But that that isn't– that's legit. And of course the brilliant thing about this scheme was that the employee who fell for this, even if they figured out that they'd been hacked,
Are they going to go back to their employer and say, boss, I got hacked, I'm really sorry, because I was applying for this job and they interviewed– Yeah, well, you're applying for a job, you see. So job hacking, recruitment hacking, is a brilliant way of doing it, because lots of people are not going to confess to their employer that they were trying to find a job. It's a great way of keeping it under the radar. And that happened, and you know, the company got some the company got taken for $625 million, at the time one of the biggest hacks of all time. Okay. Which they transferred out in 1 minute 36 seconds.
But how can how could a f how could that software developer have protected himself? I mean, it's l you know, you will be looking for jobs, you will be speaking to recruiters, you will be doing online video interviews. It's just the download link, yeah. I suppose it's
Suspicion, unfortunately. It's suspicion. And the awful thing about this is enduring suspicion. Getting approached about a job out of the blue, you might want to be suspicious about that, you probably should be suspicious about that, because if that person's going to use that to send you a virus, you know, via email, that's bad. But with this there was trust building went on, more and more interviews, more and more work. We as human beings want to trust. Not trusting people is quite taxing psychologically. Having a guard up all the time is quite an effort. So as human beings we're sort of engineered to, as we trust people, to let our guard down, because it saves us brain energy. Listen,
Did you watch that that Meet the Fockers? Did you ever watch, many years ago? Yeah. Do you remember that circle of trust? Yes, it's
Small. And. That that that that that That's it, really. So unfortunately again one of the costs of modern life is remaining suspicious and keeping a level of suspicion all the way along. Even as you start to trust somebody, still having in the back of your mind the fact of, I just heard from this person out of the blue six weeks ago and now they're asking me to download this thing or to make this transfer. It's just that tiny bit of suspicion that unfortunately we need. I've said to my parents, and this is kind of what I follow, is obviously with money, anyone pressuring you, money, anything with money is immediately like something you shouldn't trust. Like, immediately red flags. But
Also anything download, click here, is also completely red flag. Is there anything else easy peasy that you can give us to help us? I think that's really good advice. Yeah, anybody asks about money, yep. Any request online to download anything or click anything. But also time pressure is the
Thing. A lot of cyber crime that's targeting vulnerable people, elderly people, but individuals in general, there's always this time pressure. You know, your tax is overdue, your delivery's out but we need to get this sorted. Time pressure. Anything where there's time pressure. There's very few things in life where you have to respond immediately. And again I think one of the things we can learn is there's this is s scheme, Take Five, in the UK. Just take 5 seconds, just count for 5 seconds, maybe go make a cup of tea or coffee, and just have a think about that. Yeah, we need to slow down. The technology companies are getting us to speed up, you know, respond to this now, click on this now, notifications now, buy now, buy now. We need to push back and slow ourselves down so we can engage the better bits of our brain that might spot the scam. I think the one that you just made me
Think of it now, but shopping, shopping online, buying things, that's when you are clicking on things a lot. And maybe so you're not downloading anything but you have to click to open, to and those can get infected. But so it's quite tricky, because you trust your Amazons, you trust your whatever, wherever you shop, your clothing retailers, whatever. Yeah. But I suppose you just go to the website that you know and you just follow that, and you don't buy off unknown sites. Yes, yeah. So going to respected
Sort of outlets, and also going to the the website address, you know, this whole thing of redirecting people to a website that might look like Amazon or eBay or whatever. You know, if if in doubt, type in www.ebay.co.uk. You know, don't necessarily click on the link that takes you to something that looks like eBay. I mean,
But even when you do shop at reputable retailers– I mean, I had something the other day, I bought some clothes at Sweaty Betty in Beaconsfield, in Buckinghamshire, you know, as you do. I just bought some s clothing, and then I get an email saying, sorry, we've been hacked, you know, blah blah blah. And, like okay, interesting. Yeah, they've been hacked. Yeah. And and this is the thing. It There is this awful thing where companies get announced– of c companies announce
Hacks quite a lot, and there's this thing of the for the for the consumers of, well what do I sort of do? Yeah, what do you do? I don't have a clear answer to that, because one of the things that's frustrating is there are different types of hacks. So for example a company might get hit with ransomware, the hackers have scrambled all their data. Well, as a consumer it affects you because you can no longer use that service, because y their computers are all scrambled, but doesn't really affect you in terms of your personal data. But some ransomware gangs will steal data as well as scrambling it. So in that case the company says, well, we've been hit by ransomware, our computers are down, but also we've lost your email address, Aleksandra, and your password you used on this site. So that's an issue for you. Sometimes they will break in, they will steal a password, but it's scrambled, it's encrypted, so you might think, well, an encrypted password can't help them much. But sometimes they might have got hold of email address, home address or bank account number. So I think organisations just need to do a lot better job of, when they contact people, being as f as clear as they possibly can about what's gone missing and also what they expect customers to do about that. You know, if your password for Sweaty Betty has been leaked or hacked or whatever, fine, you can change your password. If you use that password for all the other sites, you've got to change it on all of the other sites. That's different to them contacting you and saying they've got your credit card, they've got your home address. See what I mean? Understanding what's happened.
What will they do with your home address? They've got data about you that they can
Potentially use to impersonate your identity. So once they've got your home address, if I'm asked to fill in the postcode as part of sort of identity check, I know what your postcode is. In extremis, you can know most people's postcodes, I mean, it's quite easy to do. It's It's not a brilliant thing to do, to steal somebody's home address, but it's just an extra piece of data that the hackers might want. And also for me m frankly, I'm more bothered about my home address than I am about my credit card. I can get a new credit card, can't move home. And the kind of people I investigate, I do not want them to know where I live. Yeah, I don't want anyone to know. So there's there's a hack? You can find out, though. You can find out today, in today's times. You can, I think. It's quite–
Go on then. Yeah, you can't find out my home address. No, no. So this thing– yes, you're right, for a lot of people home
Address might not seem to be the most critical thing, but actually there is for some people, particularly people like myself, a real risk in that the home address– hilariously, the the BBC was involved. They weren't directly hacked but a supplier of theirs was hacked a few years ago. Okay. And what this meant was that very sensitive records of BBC employees, there was a risk to that, some details went missing. So of course I phoned up and said, look, you know, I investigate North Korean hackers and Russian cyber criminals, I don't really want my address to be out on the internet. And so they said, that's fine, the BBC were very good, they put me in touch with the the HR and the security people. And I said, right, so what address have you got on file for me, because that's the main thing. Hilariously, because the BBC is such such a bureaucratic organisation, they didn't have my current address or my previous one, they had the one before that. Okay, so I thought, that's great, you know, if some North Korean, you know, North Korean agent turns up, he's going to go to some house in Leeds and then knock at the door, hello, it's Mr Geoff here, you know. Like Yeah, so
I mean, we're laughing, but like I had a private investigator on here the other day who said, look, it's worth knowing what your social footprint is, you know, online, what you've done over the years, what's you know what you'd like which you might not remember, or mistakenly or whatever. So they're they have these programs, apps, whatever, that you can use to check your data, because any well a lot of employers are going to look at your social footprint. Yeah, have
A little look. I mean, some people are more prominent on social media than others, but yes, it's it's a good way to to check it. You can check it yourself and you can check your credit rating. So, but can you check– could you do a like a little search and say, what places have
My address? Is there anything like that that checks it, do you know? That I don't know. It would be good to, if whoever's thinking of creating– stuff. I mean, that would be good, just to see if it's been somehow compromised, or and then you can remove it somehow, or pay to, r I don't know. I don't know if this helps, but the way I run it is
I have a public profile and a personal profile. My public profile, as well, you know, because you managed to contact me, is very, very big. You go on the internet, you will see my mobile number, my email address, loads of videos of me, you'll see tons of stuff about me. And I know that my work inbox is somewhere that anybody can get to. It It's like having a front door that opens onto the street, anybody can shove anything through the letter box there. My mobile number, a any texts I get, I know this this could be anyone on the internet. So I know that I've got this big public profile where anybody can contact me, they can see loads of stuff. I do have a private life and a personal life, and I try and keep that as small and as contained as possible. So what that means is on my personal phone, my personal inbox, yes, I'm aware that there's risks there, but it's far less risky than my public persona. I don't know if that helps, but I think maybe it might help people to think, right, here's my public, here's everything that's public, I'm going to put that all over there, that's going to be out, at least I know there's someone emails me on that email address, it's out there. And then I'm going to have a private thing that's just for me. In your case you're talking about
Separate laptops, separate phones, separate internet connection. All It's completely hived off. Oh yeah, absolutely. Everything is firewalled. You are taking things to another level here. If it goes wrong, if
It goes bang in my public life, which it might well do, I can burn all of that and replace it. I can't move house, I can't, you know, ditch my family, I can't get a new bank account, you know. So I have to I silo off the personal and keep that extremely separate in a little box over here, and then I have this big public profile over there. And my hope is if people attack me they'll go for the public profile, because the private profile is very hard to find.
Wow. And you've done that because obviously you've seen what you've seen and you know how easily they can come in and destroy your your your life and steal your information, everything. So literally separate internet, separate– I mean, I have a separate email, I have my personal email, I have my work email, sometimes they they m they do merge, be as they do, but yeah. But I didn't think of that, yeah. Separate email, completely separate laptop, separate. It's heavy end. But you know, also I think actually there's an argument
To do this from a corporate point of view. If you work for a company and you have a phone and a laptop, which most people do, yeah, that should just be work stuff. You shouldn't be doing personal stuff on there, partly because if your company gets hacked, you don't want the hacker to get into your personal stuff as a personal person, but also from a sort of data protection point of view, you know, y your kids' photographs, your family's photographs shouldn't be on a work devi device. And I know for a lot of people it's a faff, carrying two laptops and two phones is is is a faff, I get that. And also some companies say, well, you've got a phone, just use that. But I do think there's an argument to push back and say, no, you want me to be a worker for you, you give me a work device, a laptop and a phone, and that's just work, and y you start to silo those two things apart. I think it's maybe something people could look at doing, at least you then you know the risk. You know,
Yeah. Yeah. No, you're making me think, you're making me think a lot about this. I mean, you oh it's sort of it's common sense, isn't it? And you do normally get a work laptop, and you know and that's fine, it's just that the the lines become blurred pretty quickly, don't they? And keeping the lines separate is– it yeah. It's work, you have to consciously think about it and manage it
In that way. So are your work colleagues– your whi you know, your work colleagues, do they sit in your home phone or your work phone? Do you– ma you know, so the boundaries start to get quite interesting, of who's a work colleague and who's a friend. There are two people in my personal phone who are also in my work phone, and that's it. Everybody else, i you're either personal or you're work, that's it.
Gosh. Yeah, boundaries. Changes your friendship network, yeah. You've got really good– but I guess you've got to have them if you're going to protect yourself against these people. Okay, let's talk about modern money laundering. What does that look like?
Yes, modern money laundering. So money laundering is interesting. I think money laundering is a bit like cyber crime in that people know of it, they might have seen– did you see Ozark? Yeah, I did see, I love those, I love it as well.
My husband said he sometimes feels like the guy in that. But sorry, carry on. Or he's involved with drugs? No, no, no, no, no. But the emotion, you know, like sometimes when you feel like the world is upon you and you're trying to solve all these problems, you know how sometimes. Yeah, yeah. Yeah, it's a brilliant series. And what I loved about that was it did introduce people to this concept of money laundering.
But I think people feel about it a bit like cyber crime, it's quite complicated, it seems a bit geeky and a bit white collar, spreadsheets. And also, when you money launder, it's sort of, why would you do that? We think about drug dealing, we think about robberies, and we think about hacks and frauds. Without money laundering there's an argument to say none of it would happen. Yeah. So let's say we go into business and we start selling drugs on the street and we start making millions in cash. A lot of drug deals on the street are still in cash. Great, we've got a million quid, That's. That's a good payday, fantastic. So we want to go and spend that ourselves on something, maybe a nice car, Be you know, a couple of yachts for us, you know, something like that. Fine. Okay, you walk into a car dealership with a million in cash. By the way, my friend did this, he tried to pay for a car in cash because he thought he could get a discount, and the car and the guy in the car dealership was horrified, freaked out and told him to go away. So he had to get the tube back with his £60,000 in cash. You can't spend cash in these places because they know cash is– Exactly. So then we've got to launder it. Okay, so think about that and just map that out. Every major organised crime gang on the planet that's making serious money, you know, they need laundering facilities. They can't spend the money unless they've laundered it. So you don't make the money unless you can spend it, and if you can't spend it unless you launder it, you need laundering services. It is absolutely the glue that holds this thing together– What's their main laundering services? So you've got three stages in your classic money laundering. First stage is what they call placement. So again going back to our cash example, we've done well, we have our drug deals. Placement is getting that money into the financial system, a bank usually. Again, you can't take a suitcase of a million into a bank, they're going to ask some questions about that. So then you say, oh, well actually I run a cash business, taxi driver or hairdresser, nail bar. Nail bar, DIY, you know, tradespeople get paid in cash. So you pretend to have that business. And you say
Check, and they say check, reconciliation check, which nail bar, where is it, what's your– They can. But again, if you've hired somebody who pretends that you co-own the nail bar with them, you give them a bit of the money and then you say, look, I'm going to
Deposit this cash, if anybody comes sniffing you tell them it was our– You know, yeah. And this is why businesses businesses that don't have prices on the walls are always interesting, because one of the things the bank might do might do is go and say, well, you said you cut like 10 people's hair last week, which would have given you a profit at £10 a cut of £100, but you're bringing in, you know, £1,000. So that's why not having prices on the wall– Can I ask
You a question actually about this? Is it a red flag if there's always cash only on a nail bar?
Cash-only businesses are a bit confusing. It used to be the case that if you took card payments you got charged a fee on the card payments, and there's still a fee involved in processing card transactions, but most businesses now have got to the stage where they're like, so many customers want to pay with card, there's the arguments against taking card payments have ebbed away. Yet there are cash-only businesses. There's an argument about access to finance, that there are people who live in a cash economy. If you work in a restaurant or a café and they pay you in cash, well then you've got cash, you know, you d you know, you might want to pay in cash. But again, y most people can get a bank account and some kind of payment card. So the reasons why you might be a cash-only business start to get harder and harder to justify. It's not necessarily a guaranteed red flag, but it it is right to ask, you know, why are you only accepting cash, what's the reasons for that?
The same business, if they're always cash and always very busy, and then if you don't have the cash and you don't have a card– I mean, you don't have a card to go and get the cash from. Oh, it's just across the road, that bank machine, go and get some cash. And You're like, oh well, I don't have my card so I can't withdraw money. And then they say, oh, we'll just pay it onto this bank account, and it's a personal bank account. What what what does that s mean? Is that some sort of– It sounds like this has been personal experience for you. And it would be, I think that would be odd. On the other hand, I was a sole trader for a
Long time and I just had a personal bank account that people used to pay into. So using a regular personal bank account to receive payment isn't necessarily itself a red flag. For a hairdresser for example, what people don't realise is often the hairdressers will just hire out a chair to somebody to cut hair, so the person who's cutting hair is effectively just an individual who's sort of freelancing in that business, so they might have their own their own bank account. It's not necessarily dodgy, but I would want to ask some questions and sort of say, you know, is there a reason why you've not got a card? You know, you can take a payment into a direct bank account, but you've not got an iZettle machine or a company bank account. It's it There would be an odd one, but it's not necessarily absolutely dubious. Good.
So but you're saying some of these nail bars, some of these places, might be involved in this money laundering thing?
Some. Of If you've got a lot of cash– and and a lot of particularly drug, street-level drug crime is still cash orientated– y you're going to end up with scads of cash, just wads and wads and wads of stuff. You've got to find some way of sticking that somewhere safe. If you If you stash it in your house, stash houses get raided a lot by other crime gangs, because as soon as they find out where you keep your money, yeah, they're coming after you. Police, if they come, they'll just seize the money, it's obviously proceeds of crime. So you've got to get that money somewhere safe, you've got to get it in the bank. So So that's why a cash-intensive business, y you know, as in someone like a builder's merchant, somewhere where cash, you know, people who bring in jewellery and they pawn it and they get paid cash, cash-intensive businesses are useful. They're not all dodgy, they're not all criminals by any means, but if I had a load of cash, I'm looking for where in society cash lives, so I can take my dodgy cash and mix it with clean cash. So wherever you see lots of cash, criminals are going to be interested in it. Not necessarily they've penetrated it, but they're going to be interested in it.
Mm. Okay, so let's get into their mind. So so w how do they see what they do? They just see it as legitimate business, about, you know, that's their job, and they don't have any guilt, remorse? Or Obviously depends on the person, but in general, what's what's the sort of mindset that's going on here?
It's interesting. I mean, I've interviewed various criminals over the years who've been involved in these big schemes, and one thing I find really fascinating is in general quite a lot of them have an explanation for how and why they got caught that somehow attributes blame elsewhere. My associate screwed up, or often one of the things is, the police didn't follow procedure properly, you know, it was a f it was a fit-up. Or there's always some explanation for it. So immediately what that tells me is the criminals that I've spoken to, and also read about and also read the reports of, there's a bit of their brain that just doesn't want to take responsibility for that. Right, so immediately there's this thing of, it wasn't me, I was as a fit-up, you know, or if the police had, you know, not done this, I'd you know, be a free man etc, free woman. So there's that. So I think there's a part of them that wants to deny responsibility, and another way of doing that is to pass this off as a legit business, is to say, oh, I'm just in business, you know. So some of the fraudsters that have been interviewed about these frauds that they do– we've talked about the fact that some of these romance frauds, quite a lot of romance frauds actually are coming out of West Africa particularly, it has to be s minorities of people in Nigeria and Ghana, not the majority, minorities of people in those countries. But some of them have been interviewed and have made a really interesting point. They've said, well, the West, particularly Britain in Nigeria's case, they stiffed us, you know, the West has caused us these problems, this is reparations. When I'm taking money off of somebody it's payback, I've been deprived of the opportunities by these western countries, so by targeting these western countries. Now, is that true or is it bullshit? Is it self-convincing? Bullshit? I don't know. But I know that this happens in other crime communities as well. So for example, I've been investigating ransomware gangs recently, this phenomenon where they scramble your data and charge you a ransom. Those gangs have a really interesting way of describing themselves. Okay, they call themselves post-paid security testers. So the idea is, as a company you can pay a security tester to come in and test your security. Oh, stop it. Yeah, yeah. So what they say is, we've done a security test on you by hacking you, you've failed the security test because we've hacked you, you now pay us the same you would any other security researcher. You didn't agree this pre-payment thing. We've helped you though, wouldn't you rather know? That's how they describe themselves. Now again, that could be self-delusional, bullshit. But they are so entrenched in this. They d they deal with this. If you're going to go in and target victims day in, day out, and in ransomware and in fraud you are speaking to your victims, you've got to pull off a hell of a psychological trick not to go home– You must do. I mean, to be selling drugs to people, you've got to pull off a hell of a psychological trick, because you know very well what you're doing. So how in your brain do you reconcile that? One way is saying I'm a business person. It's a disgusting, horrible thing to do, and two wrongs don't make a right,
And it's just lack of values, just really bad upbringing or some sort of psychological problem. I think It's there's absolutely no justification whatsoever of being a criminal, liar, and of course anyone selling drugs and anyone doing this, is n on no planet is it okay. If they're listening, yeah, it's just madness. You
Know, there are also often factors in the person's background. You know, they'll have come from difficult family situation, often have mental health problems, drug problems, alcohol problems, or have them in their family. And so there's that issue as well, that people bring up. Again, I'm not excusing this, I'm just explaining that, there's I say, t to to do something that you know is horrible, and has consequences, you have to build up a sort of bulwark in your mind of reasons. And so often these get called upon. And look, I you know, there are some people I've spoken to where I can see where they're coming from and I have sympathy, and they had a rough upbringing frankly, and it's all very well for me to say, well, you shouldn't have got into crime. I didn't have that upbringing so I didn't have to make that decision. So, you know.
You know, I I've interviewed people that have come from poverty and I've interviewed people that have rough backgrounds and they've been in prison. I had a guy the other day. You know. Also, it's just– y you can choose your path, you know, you can choose your path. But I suppose if they've not been shown a path, I you know. S Yeah, but yeah, there's also societal factors to go around it. So
You know, we can look at this in Britain, but if you're living in for example Lagos, or you're living in Moscow, you know, you're living in Medellín in Colombia, the d the environment in which you're making your decisions are very different to the environment we're making them in here in London. So anyway, yeah. But you know, I do think that values are values though around
The world. I think I would hope that most people on this planet, on any corner of the planet, know the difference between wrong and right, and they can tell themselves stories, but they know. They do know.
They can. But there's another thing to throw into this which is a really interesting point, which again came out of some of these interviews with some of these West African scammers. Corruption is a key to this, and that's why I talk about the different countries around the world. We're lucky in the UK, and we really do not acknowledge this luck often enough, that we live in a relatively low corrupt corruption society. Not saying there isn't, but you know, compared to other places in the world. If you live in a corrupt place, everybody's on the make, you know, police officers will shake you down, politicians will shake you down. Put yourself in that position. You, Aleksandra, I'm sure would every day wake up and want to just do the right thing and be good. And then you watch everybody around you doing much better than you, and their families doing better than you, and their kids going to better schools, and them having better food, because they're doing the wrong thing. You're now doing the right thing, you're the mug in that environment. It's very hard not to think, I am depriving my family of decent food and education because I'm trying to stick to the right side. Do you see what I mean? That's the sense that comes out. And that's why I talk about the environment in which these decisions are made. If you're living in a corrupted environment, it's very hard to stay on the good side, because you're depriving yourself while everybody else enriches themselves. And this is why fighting corruption around the world is really important, because it's corrosive. As soon as corruption creeps in, everybody's got their nose in the trough.
Also why values are so incredibly important. I mean, my my mum's dad was offered a a job. Actually c that they weren't that well off, my mum's side of the family, but my dad my mum's dad was did pretty well as an accountant, he was he did all right, you know. But he had an offer to turn– it back we we're talking about a long time ago now– he had an offer to turn to the Communist Party and do the accounting for them, and got offered so much money, Mm. It's total apartment, you know. Where was this, in which country? In Poland. Poland, okay. So you know, y offered all this stuff. And And his best friend actually said, do it, because you you'll you'll really better, you know, you'll have such good circumstances. And he just said absolutely not. It's hard to do that. It's a really brave decision, to do absolutely not. Yeah, but I think it's, you know, it's the right decision. And I'm– sometimes you'd rather eat dust. Yeah.
But to have the to have the fortitude to stay right when everybody else is wrong and doing well out of it, but also really hard. How could
You possibly then enjoy the fruits of your labour, because there is something like guilt. And even if it might not be so obvious, at some point you'll be eaten by it. At some point, everything, what comes around will go around. Which is why this self-delusion thing is so important, is that's how you defend against that. You're right, you
Defend against the guilt by saying, well, everybody else is doing it, I'm just a business person, this is, you know, reparations, all the things we've talked about in terms of the s the justifications that go on. You know, oh, the police are corrupt, so you know, if they catch me I'm not really committing crime. All these justifications people build up in their minds are exactly tackling the guilt problem you've talked about. You know, in your heart of hearts it's wrong. Yeah, I would hope that most people
Do really, although some people, they thrive in their delusions and they start to believe them, which is a dangerous thing and a a totally different thing. And And they do convince themselves that their way is is right, even though probably deep inside, if you really cut that open, right, the core, maybe just maybe, they would know that it's not quite– if someone stole it really seriously. Twenty sixteen up until that point I think I'd struggled to get cybercrime on the news agenda because there's lots of other things going on and suddenly we end up at this point where well this can actually influence politics. At that point obviously the public to a certain extent get interested but politicians really get interested and so you start to see this uptick in interest in this. The sort of high tide mark f really at that point was the 2016 U_S_ presidential election Donald, Trump's first term of course. There were multiple sort of cyber activities going on around that and I think it's interesting to sort of look at how they worked out. For a start there was a massive hack on the Democrats obviously opposing Trump. The hackers broke in. These were according to the U_S_. They were Russian government hackers. But what was interesting is we talked earlier about how these different types of cyber crime groups are borrowing from each other's tactics Previously. You might have broken into a political party, stolen some information, used it in quite a healthy cunning way, they didn't. They just dumped the lot online. They dumped it on WikiLeaks. So everybody could go through the Democrats' emails one by one. And it was toxic explosive stuff. The Democrats lost and this was this was at their conference where they were supposed to be choosing their candidate who was gonna be Hillary Clinton and this would propel her towards the White House. Instead they lost I think their I think it's their chief exec chief marketing officer chief financial officer that it was a bloodbath. That seriously harmed the Democrats' campaign. Did it stop Hillary Clinton getting to the White I don't know how you'd measure that, I don't know, but it's it did them serious harm If. You listen to people in the Democrats at that time, it it was b it was pandemonium. The other thing that happened was of course manipulation of Facebook, which again is this whole Cambridge Analytica story, people's personal data being used to target ads at them. What was really interesting about that was f frankly in hindsight, lots of m media organisations, particularly left-wing media organisations got quite obsessed with this of oh my gosh, Cambridge Analytica, that's what one the U_S_ presidential election. There's multiple things about that that can be challenged, and one of the main things that came out was you were talking about a few thousand ads on Facebook in the end. It wasn't actually a giant campaign list. And what was really interesting was the ads, when they looked at these ads that had been placed by dodgy, you know, Russian government operatives apparently, they weren't pro-Trump ads. There's this idea that the Russians intervened in the twenty sixteen presidential election to get Trump into power. That might or might not be true, but a large part of it Mm-hmm. Was sowing division in U_S_ society. Exactly. If you want to weaken another country, one way of doing it is getting the person you want in power, but another way of doing it is just weakening the the the the narrative. And that's, you know that's what I think the game has become. People think about election interference as being getting your guy into power your person into power. There's two other things you can do Firstly. You can stop the other person getting into power You. Can do vote suppression You. Can tell people polling station's closed today, or there's riots outside the polling station, or they're asking for passports at the polling station and turning people away, people go oh, I can't be bothered to vote, or just saying to people there's no point voting, they're all this in that stuff to stop people voting can achieve an equal result to forcing people to vote. Yeah. Yeah. Yeah. Yeah. It's a it's a very good power tool that can be used, and it's possibly what's happening now, well, not possibly, but in Europe, like Europe just being destabilised, you know, just shake it up a little bit, cause some problems and yeah, very interesting to have. Mm-hmm. Had set up Facebook ad accounts so you could track them down. I remember trying to research a campaign after that that had erupted on Twitter around Brexit, the Brexit vote. 'Cause obviously there was this idea that the Brexit vote was also somehow interfered with online and so on. And it's a really interesting case that I looked at which was about football shirts with y with in and out on them. So vote in, vote out, leave, remain football shirts. It's b it seemed like that that campaign had initially been set up by somebody trying to influence the vote in one particular direction. But what was interesting was there was a bot on Twitter that was looking for contentious content and reposting it and putting advertising on it. So this automated system that I don't think was either pro-off or anti-Brexit picked this stuff up, amplified it, which then the pro- and anti-Brexit campaigns got hold of. So I I looked this, I thought if this is a political influence campaign, the chances of working out where it began, who was in charge of it, And separating that out from the rest of the noise that just erupted around social media was impossible. And that's when I realised that this is, you know, the political interference thing, the tactics are gonna get more subtle, they 're gonna get harder to spot but, they're also gonna get harder to separate out from the fact that we all argue online now, you know. Yeah yeah, yeah. You know, how much danger am I in? Well, I can tell you exactly that, because I had an incident with– You can have a look at what I– if I could, yeah, look, at you stole my phone, you took– yeah, go on. Yeah, go on, let's start on my phone. Okay, first thing we do– Here we go. Gmail. That's the first thing I'm going to hit, Gmail.
So with Gmail as well, what I'd be looking to do, if I did get the phone, it was unlocked, what a hacker would do is is try and get the Gmail and try and download the entire thing. So even if you manage to lock the phone remotely, it's fairly boring. But but okay, do you want to have a look through? Should we say that I won't do that. But somewhere in– as I say, it if you've applied for a bank account, if you applied for a credit card, if you've applied for a mortgage, it's all it it will all be in there. Also in your Gmail, client data. Client data. Exactly. I presume for this podcast you sometimes pay for the studios– that will all be in there. So what I'll do is I'll contact the studio here and say, hi, it's Aleksandra, you normally pay me into this bank account, could you pay me into this new bank account? Now instantly I've got some money out of you.
Do not, do not, do not do that. Do not. So that's instantly something I can do. The other thing is, now I've got your Gmail, I can send emails as you to people. Oh, stop it. So immediately I've not just got this phone, I've now got access to all of your contacts. I can start sending them
Spam. So I can immediately sell that access to somebody who wants to spam people, or I could just spam all of your contacts, say, oh, Aleksandra, I've got this new podcast, PDF document attached, download it, it's got loads of details in it, or sign up here, whatever. And the email is coming from you. So that's just the sort of instant things that you can do off the back of it. So you might want to lock the screen on that. I'm going, yeah, yeah, lock it. I will not send you weird download links. Okay. And this is the thing, for your information, this is why there's the phone snatching theft exploded. Getting an unlocked phone is just gold. Yeah, it locks after like a minute, I
Think, which is probably not good enough, is it? I mean, just keep locking them. And particularly– it's particularly so awful to say this– but particularly people walking
Around, you know, walk on the shop side of the pavement, don't walk on the street side of the pavement, keep your eyes about you, look around, if in doubt stop, go into a doorway, use your phone and move on. An unlocked phone is gold dust for these people. Immediately you can sell the phone. Bank account here, my bank here, although you have to put a PIN. Yeah, you've got your TikTok, you've got Instagram. Yeah, so let's say y your bank sends you a a text message with the PIN, so I can't log into your banking because you get a text message with the PIN to log in. So what I need to do is take over somehow your text messaging. Well, again, if I've got your phone unlocked, I can get access to your PIN. Holy– So unlocked phone is absolute gold dust. And I think people– I've only realised in the past year or so how quite how damaging an unlocked phone can be to your life. It is really important. What about the
Fact there's a lot of people, and I'm guilty of this myself, so I will hold my hands up right now and say that I'm one of these people that goes, yeah, but I mean, like, I'm not, you know, doing anything that other people can't know about. And what are they going to do, find out my health records? Please, knock yourself out, gee whiz. Do you want my blood test results? I can give them to you. It's not it's a no big deal. Maybe my address, I'm please don't visit me. Yeah, not interested. But you know, w you don't have anything to hide sort of thing, right? Yes. As
Soon as you've been through a a cyber or fraud incident, you will understand how disruptive this is to your life. So I had an incident with my personal phone about a year ago. It was months, they kept coming back, because once they've got access to your phone they're going to keep trying. So there were waves of the attack, trying to work out what happened, when w was it was a complete nightmare. I work in cyber security and organised crime, you would have thought I'd get to the bottom of this like that. We couldn't work out how they got access to the phone, we couldn't find the malware on the phone, we don't had no idea what was wrong. This by the way was a personal phone that I no longer use. So It wasn't the end of the world. But it it's very easy for people to think, oh well, you know, I've got nothing to hide, it's all fine, what's on my phone doesn't matter. As soon as you have one of these incidents you suddenly realise how much you've got on your phone. It's a violation. It's like a robbery, it's a house robbery actually. And this is the interesting thing, you know, with a robbery you can fit better padlocks, you can fit CCTV, a lot of people beef up their security after a robbery. Don't get me wrong, burglary is an incredibly invasive crime, people do suffer from it. The problem with cyber crime is you've not only been digitally burgled, you have no idea what window they got in through, what door they got into, and whether they're going to come back tomorrow night and the night after and the night after. Imagine that. Imagine getting burgled and you have no idea how they got in. So what do you secure? Well How do you stop that? That's why this cyber crime and fraud stuff is so important. You
See, so like my you know my husband, he loves all this digital stuff, and he sold his digital marketing agency and that was bought by another PR company, and he's he's in that whole world of of that stuff. So he loves it, he doesn't mind putting quite a lot of data actually online and using whatever. However, what he does do, and it's I've only just sort of it's only just clicked to me now when you were saying this, is he is quite paranoid and strict and meticulous about always deleting our cards, changing banks, moving, like constantly, you know. And I said, can't we just– like, no, we should– let's, it's time to you need to now cancel that card, you never know. Just. Literally restart It's not a bad idea. Restart, if you can go through the– if you're not worried about going through the hassle of doing it. Yes, because obviously if somebody's got your card. With different things that he's using, it makes me– he makes me do it, I just follow, he goes, trust me, trust me, trust me. Just so, it's quite a– c I suppose it's a good good practice maybe.
Yes, yeah, it can be. There are downsides obviously, in that you know, you build up a credit history, people with places and so on. But yeah, I it moving around actually is not a bad thing. And and in my life I've moved address quite a few times, and and for some reason that makes me feel more comfortable, in that if somebody does get hold of an address for Geoff, probably going to be an old address for me. So yeah, it's it's there's a hassle factor to it, but it's it's not a bad thing to do. It's not a bad thing, is it, yeah. But if you go home and he's moved house, Aleksandra, that might be a different– No, the house thing, I mean, I must say, it's not nice. You don't
Want anyone appearing at– and obviously with this podcast and everything, and you become more, you know, in the public eye or whatever, you sort of, you don't want– yeah. Out of all the sort of everyday scams that, you know, most people will encounter, which ones are the hardest to spot, or which ones are the the sort of ones to keep an eye on as well simultaneously?
Well, this is where we get into sort of the AI problem. To to to sort of convince somebody to send money, to convince somebody, you know, to do a cyber crime on somebody, trick them, or to c to commit a fraud against them, the first thing you need is a way to contact your victim, and the second thing you need is a story to tell them. Those are the two things you need, right. Th The way to contact somebody used to be the front doorbell. Ring your front doorbell. And the way you convinced a person was you'd have a British Gas uniform or some other utility, Scottish Power, whatever, you'd have a clipboard, hi-vis jacket, and the story would be, oh, you know, there's been road works down the way, we're worried about the supply here etc. So you need a way to contact somebody and a s a story to tell. Story, yeah. The way to contact somebody, as we've discussed, increasingly people's email addresses, phone numbers are just going to be out there, The b your Facebook account, LinkedIn. You know, we want to be contactable, and we want to contact people, there's just way more contacting going on and communication going on. What that means is, for Mm-hmm. Fraudsters who want to contact you and cyber criminals who want to contact you, they've just got many more ways of doing that. The second thing you need is a convincing story. So it's your tax is overdue, your Amazon parcel's out for delivery, you know, click here, you know, we've changed suppliers. There's there's there's a convincing story that goes behind it. The thing that's going to be hard in the future is that AI is going to make those stories more convincing. At the moment I can't contact you, or previously have not been able to contact you and pretend to be your husband on the phone or by or by Skype call or FaceTime. Increasingly you can do that now, particularly folks like yourselves who've got a higher profile, there's lots of video out out of you on the internet. You can create a deep fake of Aleksandra, or the voice certainly. So So increasingly that's going to be the thing that's going to be hardest to spot. I hate saying this because it's it's a bleak lesson, but suspicion is unfortunately going to have to be our capital in this. We are going to have to just up our levels of suspicion. And we've also got to reassure other people that, you know, if I ask if it's you and I ask for some extra way of proving it's you, don't be offended. Employees and companies have to be told, if the boss phones you up and tells you to do something, it's okay to say, I don't believe you're the boss. We have to let people be suspicious. And let suspicion, you know, doubt and scepticism, it's good. It's like, you wouldn't just open your door to anyone, so this is what it is. You wouldn't just, because someone's out there
In hi-vis, it doesn't mean you open the front door.
Precisely. So yeah,
Just don't. Yeah, guilty until proven innocent. I mean, you know, my mum and I– my mum's getting on in years, she's in her 80s– and we've had the conversation, look out for the a elderly. What we've agreed is, you know, there's a thing from when I was a kid, which is a stupid thing I used to say as a kid, and anything to do with money, anyone phones up, I will not be offended, Mum, when you ask me what's that thing we said as a kid, and I will be able to come out with it. So just ask me, always ask me, you know. And we– again, I had to reassure my mum and say, don't worry, I'm not going to get offended. That's what we have to do, we have to start putting in these kind of proof networks and allowing people to to do them and to say them and to have them.
Yeah. So I I mean, we– you've answered this question already about how being in this field and investigating what you've
Investigated, seen what you've seen, and you've spoken with literal hackers and the guys doing it, it's I it has fundamentally changed the way that you operate, function.
Yeah, from from the earliest days of investigating this I realised that you have to have good boundaries, and you have to have good b g boundaries from the beginning. So for example, that the famous example is that there's a guy called Ross Ulbricht who set up a website called Silk Road. It's a dark web website, so it's on a hidden part of the internet. Sold drugs, mainly drugs, some other stuff as well, illegal stuff. So the FBI finally found him, and the way they found him was that years before he set up this website, he was trying to learn how to build a website and do coding, so he'd gone on this forum and he'd said, hey, can anybody help me with this, my email address is rossulbricht@gmail.com. He had subsequently then been– the f that account had been the first account to post a link to Silk Road. So he didn't realise it, but he'd given away his email address years ago, got hacked, and then as he got more– he thought he was secure, but as they followed the trail back there was that one thing at the beginning. So being– having really good boundaries in the beginning. So from the very beginning I've had this whole thing of, Yeah. I need a private life, I do need to escape, the stuff I cover is pretty heavy, I'm going to keep that very private, and very small and very hidden. I will have to have a public life so I'll make that as big and as noisy as possible and all the contact details will be out there, but at least I know my risk, I know where I'm most at risk: my work inbox, my work phone, my work LinkedIn. What if
You haven't done that from the beginning? Start now? Never too late to start. Yeah, exactly. My geography teacher always said better late than never, when I used to pitch up at geography class late. So for anyone listening that feels overwhelmed by these hacks and these scams and the deep fakes, wh what rule what what th thing, in what information can you impart to them that will comfort them and give them empower them a little bit? Yeah,
Firstly don't worry. This stuff's happening all over the place, it's quite likely you won't get affected by it, right. So So you don't have to be incredibly paranoid every day to stop this stuff. You also don't need to have like CIA, MI5 levels of of skill to stop this. Anything you can do, any bit of work that you do, helps, because the criminals always go after the low-hanging fruit. I own a nice bike, and when I park my bicycle what I'm looking for is the other bikes that are quite nice but have a rubbish lock. And so I park my bike next to that, because I know the crook's going to come along, look at that and think, that's a nice bike but it's a good lock, that's a nice bike but– it's and I know they'll go after the other one, and that's what they'll lose their time on. The point isn't to be, you know, Edward Snowden or some super spy, the point is just to be a bit more secure than your next door neighbour, and they will be the one that gets hit. I d I hate to say that, but that is true. Yeah, we don't want the neighbour to get hit. You don't, but you know. But you're smart,
You're calculating everything. Exactly.
And there's two things I think that have come across massively in the discussion that we've had. The first one is bit of suspicion, bit of scepticism, and and just to make that part of your sort of daily routine. I don't like saying it because we do want to trust each other as humans, but increasingly we just need to sort of double down on that. So being a bit sceptical, being a bit suspicious, prodding back and saying, is this email from that person? Well, you say you're, you know, you say you're called, and you know, you're from the bank, but you know, pushing back. Yeah, push back. And secondly, patience. Again this idea you have to make a decision now, you have to click on it now, you have to deal with it now. Don't. Just take five, go away, make a cup of tea or coffee, come back, have another look at it. And what's interesting is, to do those two things we have to sort of push back on where we're being driven. Technology companies want us to decide things really quickly and act really quickly. Companies want us to make quick decisions. Yeah, push back on that. You take your time. And also we're driven as human beings to want to trust and trust more, again we have to push back on that. It's not an easy thing to do, but bit of patience, bit of scepticism, that will see us right. It's actually an old saying that I grew up with, it's in Polish so I
Won't repeat it in Polish, but it is one about that. Well, it's in English as well. The English version version is, devil makes haste. Yeah, yeah, that's right. So that I suppose that's the translation. Precisely. So yeah, thank you so much, it's been incredibly informative. Yeah, it's been good, thank you. Scary, but we all need to hear this, so I appreciate it. As I say, I don't want to make people freak out, be paranoid, but these risks are out there. I'm not making this stuff up. And like I say, just a little bit, anything you can do, just one thing you can do to pull yourself up the tree to those higher branches. They're going to go after the low-hanging fruit and that's not going to be you. Okay. Actually I will say it in Polish for you. Devil makes haste. Fantastic. Thank you so much. Thanks for having me. Thank you. Thank you.