Episode 01

An FBI Lesson in Verifying Identity

Most applications that pass a background check are exactly what they appear to be. This episode covers the exceptions. Eric O'Neill, the FBI investigator who caught Robert Hanssen, explains how bad-faith actors get hired using stolen identities that come back clean, which independent checks can catch them, and why verifying someone once is not the same as knowing them. Recorded with host Maureen Lally for organizations that onboard at volume.

Key Topics

Hide

  1. The Hanssen case in plain terms
  2. High-volume hiring, wider door
  3. What bad-faith actors see at onboarding
  4. The AI-built applicant
  5. Who pays when an identity is misused
  6. What a one-time check can’t see
  7. Verification as culture
  8. Day-one advice for gig platforms
  9. The PAID method
North Korea has a new revenue stream: getting fake employees hired at American companies. They use stolen IDs, flawless LinkedIn profiles, and AI to do the work — while pocketing the salary.
Eric O'Neill, Security Strategist

Download the Identity Verification Checklist

Download Checklist

Stay Informed

Sign up for our newsletter to get all the latest updates at First Advantage. What you'll get:

  • New podcast episodes
  • Valuable tools & resources
  • Timely information

Transcript


Welcome to Know Your People from First Advantage, a show about trust in a changing world.

The rules, the technology, the way people work, what customers expect, all moving at once. Trust has to keep pace, and it’s two way. Organizations trusting the worker, the worker trusting organizations, and consumers trusting the provider, and it’s always changing. Trust is established on the first job and reearned on every job after.

This isn’t a show that hands you answers. We sit down with the people who live it, trust and safety leaders, those working in regulation, and the experts chasing fraud. The honest version, not the easy one. Let’s get into it.

Hello. I’m Maureen Lally, and I’m the chief marketing officer at First Advantage. And I am pleased to welcome you to the First Advantage Know Your People podcast. My guest today has spent his career on an important question.

How you tell if the person you work with is the person who belongs or who only appears to?

The Story of Robert Hanssen
Eric O’Neill began an FBI counterintelligence as an undercover operative. And in two thousand and one, he helped catch Robert Hewson, the most damaging spy in US history, a man who was exactly who he claimed to be.

Eric told his story in Gray Day, and it was also featured in a Hollywood film entitled Breach.

He is now a security strategist working on impersonation and synthetic identity, And his latest book is spies, lies, and cybercrime.

Eric, welcome to the show.

Yes. It’s certainly good to be back together again in this format. It was wonderful to be on stage for you speaking about spies, lies, cybercrime, and and how cybercrime is changing us, not only as a society, but is threatening all of our wallets.

Okay. Well, that’s a great way to start. So for anyone who does not know it, who was Robert Hanson, and what was your job?

Robert Hanson was a twenty five year veteran of the FBI. He was a decorated supervisory special agent, working in counterintelligence, which is the science of stopping foreign intelligence services from stealing our deepest and darkest secrets.

But for twenty two years of that twenty five year career, he was also the most damaging spy in FBI’s history and quite possibly the most damaging spy in US history. He meticulously stole information from computer systems at the FBI that were never built to defend against a trusted insider, someone already within the circle of trust.

And he got them to the Soviet Union and then the Russian Federation. He spied for so long, twenty two years, that meant he spied for every spy agency in the Soviet Union and the Russian Federation and survived the collapse of the Soviet Union and the reformation. So he was one of the most notorious, but also one of the most successful spies in history. And during that time, he gave some of the most damaging secrets that have ever been given to a foreign power.

Consequences of Espionage
Here are just a few highlights. Our nuclear weapons program, what we would do if there was a nuclear war, who we would fire out, where we would fire, our continuity of government plan, where we would send the president and vice president and cabinet and everybody who matters in politics if there was a catastrophic event, but also our undercover operations, billions of dollars of operations that were failed and fizzled before they even got off the ground. Undercover operatives whose covers were blown and then could not work anymore, and even our spies, those who were working for us primarily during the time of the Soviet Union.

And during the years of eighty four and eighty five, which was right in the middle of the Cold War, we lost every single asset in Russia, and a good part of that was because of Robert Hanssen giving up the names of those individuals. And, hey, back in the Soviet Union time and probably today still in Russia, they didn’t have these grand trials and defense attorneys and you you put the spy, you know, in a court of law. They just flew you back to Moscow and put a bullet to the back of your head. So Anson was a pretty bad guy, a notorious spy, and very, very difficult to catch.

He was known as the legendary spy Graysuit.

So he passed every check for two decades because he genuinely was who he claimed to be. What did catching him teach you about where trust actually breaks?

Lessons on Trust from Catching a Spy
Yeah. That’s a great question. Hansen Hansen’s success was because of a a couple of factors.

One, the FBI really wasn’t looking in the places they should. They weren’t looking into their data. They didn’t understand the flow and the processes of their data intrinsically. Computerization was still very new to the FBI, and Hanson was a hacker.

He was able to insert himself in the seams between technology and security by understanding it intrinsically and knowing where he could steal without getting caught. He was like a bank manager who knows all the security codes stealing from their own bank. And if no one’s auditing, that happens. And so what did I learn?

Well, you know, one thing I learned and the broader FBI learned is that you need to understand not only your data and who has access to it and where it is, but your people. And you need to understand that intrinsically. You can’t be asleep at the wheel. And if you’re not looking, you are never going to find the spy or the cybercriminal or the trusted insider or the disgruntled employee or the mole or the fake employee who’s working for you but actually has allegiances to somewhere else and you just don’t know it.

Undercover Operations and Identity
So you went undercover as yourself with no fake identity. What did that teach you about how thin the line is between real and fabricated?

Yeah. When I went undercover, it was a very unique case. In fact, the most unique case the FBI has ever run.

Not only was I undercover as myself, you know, which I didn’t feel comfortable, but the operation was entirely encapsulated in FBI headquarters. I think it’s the only case like that has been run-in FBI headquarters. The FBI, a very small group of agents at the beginning, run run out of the Washington field office, built an entire new section in the FBI, in FBI headquarters under a directorate of cybersecurity, a brand new directorate of cybersecurity. And that section was the information assurance section, and the mandate was to analyze and determine how to improve cybersecurity for the FBI.

And they put Hansen in charge of it. The entire thing was a mousetrap, and they needed someone who knew how to hunt a spy and turn on a computer. And that happened to me. Be me to go in, gain his trust, learn where the evidence was that was going to lead to his arrest, and then find it.

So what do you learn from that? You learn that sometimes it takes very bold actions in order to have these great wins, these big wins.

That you need to hunt that threat. And what I say in both of my books is you have to hunt the threat before it hunts you. If you’re passive, if you’re reactive, you never win. You have to actively pursue your security. And here cybersecurity for for most organizations, because if you’re not actively pursuing cybersecurity, if you’re not constantly looking for the threat, that threat will be in your systems. It will compromise your people. It will fool your people, and you’ll never see it coming.

A lot to consider.

The Impact of Remote Work on Security
Espionage was the elite version of getting an untrusted person inside.

Why do platforms like gig platforms that hire faster and in higher volume open the same door wire?

Yeah. I love that question because it is pointing right at a massive problem we have today.

And believe it or not, not a lot of people know about.

Espionage is incredibly clever. Spies are always at the cutting edge. They never rest. They don’t rehash the same old things. They are always innovating and always seeking to find ways in.

There’s this dichotomy between espionage and security. In fact, there’s a the same between crime and security. Security tends to usually be reactive, which means there’s a threat, security learns a lot about the threat and acts to neutralize and stop the threat and then finds ways to prevent the threat from happening. That is a long lead tale from start to finish.

And during that time, the spies pivot and they change their tactics. They find a new way in. So that reactive posture of security never really helps. But what’s happening today with one of the biggest innovations that intelligence services have learned and cyber criminals are copying them too, is that they understand that in this new work environment that has been thrust upon us by COVID and that we’ve graduated into and we’re never going back, right?

Where it’s hybrid first. That means that people have the option to work from home or wherever they are in the country or the world.

And we even have to accommodate work from home if everyone’s gone back to the office. That’s why you see that if most of the team is in the office, someone might be working in North Carolina and so you have to have a Zoom screen for them, right? Or Teams or whatever you like to use.

Well, the espionage or the spies know this, the criminals know this. And what they’ve done is they’ve created a system where they are using criminals in the United States, people who own property, who can set up a server for them, and using complex VPNs in order to make it look like they are applying from US states. They have impeccable resumes. They have they create entire social media profiles that are just total avatars.

They don’t exist. And they are banking on the fact that most organizations do not properly vet their employees. They do a very basic screen, which is, you know, the ten dollar criminal check. And because these individuals that are created whole cloth are actually using stolen identities as the basis for their social security number, all of their information that’s gonna be run through those those very basic identity criminal checks, it comes up clean because they’re not gonna use a dirty identity.

They’re gonna use a nice clean one. And and they’re getting hired because they have these incredible credentials. And then, you know, what’s happening is the HR department after the criminal check comes clean, they’re doing their own diligence. Like they look on LinkedIn, oh look, you went to this college.

But they’re not going to the college to make sure that that’s true. Right? They’re not doing all of the critical diligent steps that can lead an organization to know that this person isn’t who they say they are. That is so important for any hiring.

And what happens is these individuals get hired and they don’t know how to do the job.

Right? And they might be working dozens of these positions at the same time a day. But they’re using AI agents to do all the work for them, and it is just enough to pass reviews. And they make the salary and they’re stealing the salary, is why North Korea loves this.

They love to seed these people into companies because they are making money. These poor guys don’t get paid anything. Right? And girls, you know, it’s it’s men and women that are that are launching these attacks.

North Korea steals all the money and they’re making millions and millions off the backs of American business. They are also finding access to systems and stealing. That’s why they’re they’re very focused on IT positions and roles, which for any organization, you need to vet just as carefully as you would someone in a c suite.

Okay. That’s amazing. There’s a lot to unpack there. So maybe I’ll just break it into smaller little pieces.

Challenges in Remote Onboarding
When people are onboarded remotely, because you’ve just said after COVID, we’re not kind of going back in terms of more in face or in in office meetings. But when people are onboarded remotely in the thousands, even over a weekend, what does a bad actor see that a hiring team doesn’t?

Well, what happens when people are onboarded, if the organization is not doing the diligence I talked about, if they’re just doing the basic checks and believing what is presented to them by, in in this case, the criminal or the spy, then they’re not gonna catch it. Because once again, are clean identities and they manufacture these brilliant backgrounds using primarily social media. Because where do we all go when we’re trying to verify people or we’re trying to learn about them? We start with LinkedIn, right?

LinkedIn is perfect. It’s all right in front of us. We’ve got their educational history. We have all the places that they worked.

You know, they will even provide references.

And here’s where it gets a little sneaky. They will provide references for companies. They will provide you the phone numbers and the emails.

And the phone numbers and emails are completely fake. Right? So you are calling them and you’re talking to maybe their AI avatar. Right?

If you wanna do it on screen or or over the phone. You know, I and this happens across all industries. I recently got a email from a marketing person who serves speakers. Right?

And it was presented very well. I looked at her background. It was impeccable on LinkedIn. And she put together this incredible proposal for getting my new book Spy Size and Cybercrime out into more hands.

And I read through it and I thought, you know, she did an amazing amount of work and and that actually sounds like a very good plan. It was it was all geared to up up the profile on Amazon, which you know, which is where a lot of get sold. But, you know, I practice what I preach. Right?

If it looks too good to be true, it probably is. So always do your diligence. Always investigate. And so I did.

I asked for some references And she gave references for three authors that she said she had worked for, but they were Gmail addresses. Now that is a clue. Right? You know, I I don’t use a Gmail address for my professional stuff.

I have eric at ericoneal dot net. Right?

And so I did an email. I did research to find out what the actual contact information was for these authors. I contacted them outside of the information that was provided me by, you know, the person online unsolicited and they’d never heard of this person. So I knew that the entire thing was a scam. How does the scam work? Well, you sign a contract and you pay and then they disappear.

And that’s how they’re making money, scamming people like that. It’s the same thing with employment. It all looks very good. You call the references and if you just follow the numbers that they provide you, the information they provide you, you’re talking to some other criminal who says, yes, they’re impeccable.

They’re amazing. They were the best. Right? And then you hire them based on you check the boxes that your workflow tells you to check.

Check social media. Look at their education. Make sure they have the commensurate amount of years of education, look at where they worked before, call two references, make sure that that the references are good, and then hire them. Yay.

Because you got your your ten dollar criminal check back, and you just hired a spy. What should you do?

The Role of AI in Employment Fraud
Call the references independent of the numbers that they gave you. Right? Don’t follow along there. Follow do that.

Verify education. You can verify education through a number of different ways that that are independent of just looking at LinkedIn and assuming that it’s true. Anybody can put whatever they want there and and all the other steps. So you just can’t rely on, you know, using your internal resources that are not trained to do this for the most part and and those terrible little criminal background checks that just don’t work.

Okay. So with AI doing the work now, how convincing is a fake candidate and what still gives them away?

Right. Well, AI makes this all easier for the spy or the cybercriminal. And remember, this happens with corporate espionage too. We’re not all friendly here in the US as well. There are companies who employees into other companies doing this and try to mask where they have worked before and that they actually work for the competitor.

They can, you know, intellectual property theft and they can cause mayhem and they can cause disruption. This actually happens in the real world. So you do have to be very careful. And so some of the things that you you need to worry about with AI is the fact that it makes it very easy to scale.

It it it lowers the bar of entry for anyone who wants to commit this crime. It also allows you to create, for example, if I want to say that I am a professional systems administrator, I’ve worked for a number of companies, I can create complete companies that don’t exist. Entire websites in moments using AI with phone numbers and contact information. So you think you’re going outside of the information given to you by the prospective employee to verify and you’re going to the website of this fictitious company that didn’t even exist. So have you even looked at whether that company that they’re giving you in a reference exists?

They can have credentials that are created online. AI can create bodies of works and writing and make it look like they published a dozen op eds, right? Or that they have patents for two or three things that make them look very attractive. So you have to be very careful where you’re going because AI can build all this. Now, course, the other thing that AI does, and China, North Korea are very notorious for this, is they use AI avatars.

AI avatars that speak perfect English, right, that don’t have those inflections and problems that might trigger some questions.

They can look like they’re anywhere in the world, and they can say whatever the criminal wants them to say. It’s getting better and better, and it’s getting much harder to detect.

So just as you’ve described, deep faked interviews, stolen synthetic identities, how mainstream is this already versus how mainstream people may assume?

It’s it’s growing. Right now, it is very targeted. There is there is some work that has to be performed in order for a very adept cybercriminal to put this together. It’s much easier for espionage.

And, of course, espionage is targeting the bigger enterprise companies where they can not only get get paid a lot of money in salary, but also steal high tier intellectual property. But what we have seen, what I and what I’ve what I’ve portrayed and and proven over years of writing and thought leadership is that anytime a espionage, a foreign intelligence service, a spy agency becomes adept at something, cybercriminals begin to copy. So I I think that this is a new attack of the future in cybercrime. And cybercrime is something that every organization has to worry about no matter how big or small you are.

Know, spy know, espionage is a little bit less, but once the cyber criminals continue to copy this and show to other cyber criminals who wanna jump on the bandwagon how successful it is, we are going to see a plague of it. So it is like I say in my book, prepare ahead of the situation.

Know the threats that are coming down the pipeline and prepare ahead of it by putting policies and practices in place before this happens to you.

The Gig Economy and Identity Theft
Okay. Thank you for that. That’s great observation and a great, judgment in terms of going forward. I’m gonna shift a little bit to the gig marketplace. As you know, it’s one of the largest kind of ways in which people are working.

When a gig worker’s identity is stolen or rented out, who carries the cost? The worker or the company that hires them?

Right. And, well, it’s it’s it really goes down to the consumer because it it costs it costs money when things go wrong and the prices across that entity go up. So if it’s a driver or a or a delivery person, you know, that those deliveries or the cost of those rides is gonna go up. But it it really in the in the end of the day, I I would say, know, putting a legal hat on would be the company because the company is responsible for ensuring that the people they hire are the people they hire.

Right? Just because an identity was stolen, they got fooled by a cyber criminal doesn’t mean that they’re not liable for ensuring that the person who is driving your loved one is vetted and is the person who’s driving your loved one or that the food actually makes it to your house when you order from DoorDash or so many other examples. So it behooves that industry to be far more careful in ensuring that those people that are contractors, right, are are outside contractors are actually going to perform the work to the level and the sophistication that is required of that company.

Okay. So you argue the weak point is almost always human.

Where does it really sit? The worker, the recruiter, or the leader who treats verification as a box to check?

Right. Yeah. The weak point is the human and you cannot put this on your employees.

Statistically, just statistically, no matter how much training you give, the best training in the world, you tell every single one of your employees, you have to read Eric O’Neill’s book, Spies, Lies and Cybercrime. That’ll get you to like ninety percent. Right? But and then you take training and then you do constant cybersecurity training.

Twenty five percent of people will click on that link or open that attachment or make the mistake with the the impostor or the confidence scheme attack that’s being launched at them because they’re getting so incredibly clever and because criminals and spies use an art called reconnaissance to learn everything they can about that vulnerable employee and they build something so deceptive that any one of us would be fooled. And in fact, I start my new book, Spies, Eyes and Cybercrime with an example of how I got fooled, completely taken in. And it wasn’t till the last second that I realized, oh my god. This is an entire scam. I gotta pull out. I ended up not being out of pocket a cent, but I lost a lot of time. Makes a great story.

It’s right in the front of the book. It’s a little embarrassing, but it’s so I can say if it can happen to me, it can happen to you. So who’s really responsible? It’s the organization. The organization has to have a culture of security and cybersecurity.

Organizational Responsibility in Cybersecurity
It has to have, from the top, right, at the c suite right up to the CEO, that person has to have a open door policy where if someone receives a email, a text, a FaceTime call, a Zoom conference where the CEO is telling them to do something, the CFO is telling them do something, they should feel completely comfortable saying, give me a second, hanging up and calling the person directly and not getting chewed out for wasting their time. And say, did you actually ask me to send this wire for five million dollars? I’m just verifying. Right?

That verification, levels of verification are critical. And in recruiting, same thing. When we’re talking about these fake employees, recruiting is really responsible there. You have to make sure you’re doing your vetting.

You you know? And if you don’t have like I say to every organization, particularly when I’m talking about cybersecurity. Right? Organizations that don’t have a CISO, you have to have an outside consultant to come in and do the vulnerability assessment to stand in the shoes of that security team that you don’t have.

Same thing with recruiting. If you don’t have the capacity inside to do the diligence and investigation and make sure your employees are who they say you are, you need help from outside. You need to go to help from outside. You cannot just go to some vendor who will, you know, do a batch one thousand criminal investigation searches, which just just look at a database and those databases are wrong all the time.

That is not going to cut it. In today’s world of remote work, deep fakes, AI, you have to have something far deeper.

Continuous Verification of Employees
So, where our comp so maybe I’ll check change this a little bit. So now companies that are still treating identity as a one time check at the door, what does that miss once somebody is already inside?

Well, it misses the person. So let me give you an analogy. Robert Hanson was hired by the FBI, and he was hired, you know, a little bit before they started polygraphing people for their, you know, for their top secret SCI clearances. But at some point that was instituted and he had a number of deficiencies.

He was caught once upon a time putting pulling Ethernet cable from a ceiling to try to give himself his own separate Internet connection. You know, that’s suspect. He was also caught putting a key logger on a computer, which logs all the keystrokes so he could get a password. And when he was caught, he said, oh, I was just trying to get the password of the color printer because it takes too long to get IT out here to do it.

Right? And he was forgiven both of those things.

But what was the real key failure of the FBI is that he was not given routine background investigations each time he had his clearance renewed every five years. In fact, the first time he ever got a polygraph exam was after he was arrested, which is just a complete failure. It was a mistake. It was it was dropping the ball. Organizations do this too. They don’t vet their people when they’re onboarding them, and then they don’t then they onboard them and then they never look at them again.

And that that can be a mistake. People change. People’s beliefs change. People’s inclinations change. Someone might be a very quiet disgruntled employee that is just a ticking time bomb where you’d go off. Now you don’t wanna be overly suspicious and paranoid about your employees, but it is good to do a cursory check now and again, especially in key employees.

And, when we’re looking at cybersecurity, there’s where you might wanna have someone come out come from the outside if you don’t have a security team and tell you who those key employees are that you really need to lock down and ensure that you are preserving the data around them because that those are the individuals that attackers will target.

That’s great. So building security into culture, not just technology, What does that look like for a team that hires and onboards all day?

Building a Security Culture
Yes. Certainly. Building security in a culture is a holistic action that the entire organization has to take. And right now, the most critical threat to any organization is a cyber attack that is launched at a person.

It’s an impostor attack. It’s a confidence scheme. So when you’re looking at teams, and and not just recruiting, this is every team in a company, everybody has to buy into security. Everybody has to buy into the idea that we’re all in this together, and every one of us serves a role in protecting the organization from external threats.

You you know, there are a lot of different ways to do this. I I like the carrot rather rather than the stick. I’ve never been a proponent of of penalizing people who make mistakes.

I I went and spoke for an organization once, and I’m going through their security operations center, a very, very big organization, huge enterprise, one of the one of the bigger companies here in the US.

And I was talking to the CISO, and and, you know, as we’re walking through their security operation center and, you know, different cubicles, this was before everybody started working from home, I saw that everybody had Swedish Fish lined up on their cubicle. It was just really weird. I’m like, why is candy everywhere in this place? I think it was a huge pharmaceutical company too.

I’m like, aren’t you supposed to be looking at health and that kind of thing? She laughed and she said, you know, I can’t get them to eat them. And I said, do you mean? She said, well, you know, a lot of organizations, when someone fails one of the red team phishing tests, you know, where you get a an email that is trying to trick you into clicking something you know you shouldn’t, You’re supposed to report it to IT, and if you don’t, you get penalized by having to sit through, like, three hours of cybersecurity training.

What she did is anytime someone reported it, she would show up personally and give them a individual package Swedish Fish. Right? Because they won. And people worked so hard to get those Swedish Fish and they line them up on their cubicle as sort of badge of honors.

And it reduced spear phishing attacks in the company by a huge percentage.

So that sort of all in security, people engaged, people wanna be part of it, and there’s clever ways to do that. And, you know, if you don’t have that security team, HR can be right behind that in enforcing that and making sure that people are all in. But if if people aren’t in, if people are lazy, if people are disengaged, if people are disinterested, then they’ll be fooled. And that is the single best point of attack for an external threat.

Great. Yeah. That was a great visual identity that you just described. Okay. We’re gonna talk a little bit about the future, which is going to be very hard to predict. So if you could, three years out as AI cuts both ways, good AI, bad AI, does verifying who someone is getting harder or easier?

Future of Identity Verification
Yeah. Three years out, verifying someone might be quite difficult if you’re trying to do it solely with a visual interview. Now for so many for many many years for for quite some time, that visual interview was critical as sort of the last chance to make sure that the person is not only who they say they are, but going to be functional in the company. Right? You can learn a lot with an interview and especially if they’re the sort of person who has to be very professional in how they appear and how they speak. Yeah. For part of the role.

And that interview more and more is online.

Now there is a there’s a very high probability that in three years, a AI avatar, the fidelity in a Zoom box is going to be equal or surpass the fidelity of a person behind a camera in in terms of not only the video, but the speech.

There will be real time typing and speaking. Right? So someone who’s very clever and a quick typist can type whatever they want, and that person will say it. And we may have a, you know, dark web AI agents who are able to just do it.

Just have this conversation like I’m having with you right now, Maureen, without a pilot telling them what to say. You will tell the AI agent, land this job, And the AI agent will do it very professionally with an entire history of humanity to draw from in order to fool that recruiter. That’s very dangerous. And so the technology is being developed right now to detect AI and it it wins and loses sometimes.

But I think in the future, we are all going to have to have an AI detection technology that helps our people in security and recruiting in all aspects of a business identify when someone is using AI or not. And we’re hoping that, you know, the only AI we’re gonna identify is, you know, like Paul who dialed into the call and is using an AI avatar because he didn’t feel like shaving or changing out of his pajamas. And not a North Korean spy that’s that’s using an AI avatar every single time they communicate with the company to hide the fact that they’re not in Arizona, but they’re in fact in North Korea.

Okay. Just two more questions, then we we’ll be able to move on. If you were to advise a gig economy company right now that would be starting today, what would you build in from day one?

Cybersecurity in Startups
Certainly. I would build cybersecurity from the ground up. That’s one thing that many organizations miss. They wait to do the prepare phase in cybersecurity until much later. They think it’s not as important. What I’ve seen in in working as a cybersecurity adviser for countless small businesses in my my company, we we focus on small, medium, and growing businesses, is that if you wait to focus on cybersecurity, you’re leaving the door open to bankruptcy because a a one single ransomware attack against a small or medium sized growing business can bankrupt you.

The the costs can be extraordinary, especially if you’re in a gig economy because, you know, you rely on the customers that are relying on you. And if they lose faith in you, if you have to send every one of them, you know, as a as a startup, as a small business, a notice that we have been breached and your information has been lost and may lead to identity theft, then you need to pay for every one of those people to have identity theft protection. And you have to deal with all the legal repercussions that are gonna happen that might end your company. So building good cybersecurity right from the start gives you two things. One, it helps protect you from that ultimate ending to your company.

But two, it also gives you the tools to be resilient if there is an attack and survive it. Because the bad guys will find a way in. The trick here now in cybersecurity is making sure that when they find a way in, they have a tiny little football foothold. You have the tools to find them quickly, to see where they go, to stop them, kick them out, and minimize the damage to the smallest amounts possible. And that’s kind of where we are now right now with cybersecurity.

Because you’ve sort of described this dark web economy that’s coming, how close are we to a person’s identity being the main thing that’s being bought and sold?

Identity Theft on the Dark Web
Yes.

On the dark web, identities are routinely bought and sold. A a fake identity a a true identity used in a fake way is the main way that attackers are performing these high level and sophisticated confidence schemes where they’re using somebody who you believe is real and true, but they’re actually a complete scam, and imposter schemes, which is just a confidence scheme that happens very quickly. Right?

You know, these fake identities are also how the attackers get paid.

You know, most people are not going to send a wire or, send money that for something that they believe is a legitimate invoice or a vendor scam or or paying an employee by by trans translating it into crypto. Right? Through some exchange. That’s a pretty red flag. So what criminals do is they use identities bought and stolen off the dark web to create what’s called drop accounts. They will steal your identity, Maureen, which is probably on the dark web somewhere. All of our identities are at this point because it’s been lost by companies and breaches or just hoovered up by data brokers who were breached and now it all gets gets on there.

And they use to say your identity that’s bought off the dark web or stolen to open a bank account. And then they change the name from your name to whatever business they’re pretending it is. And that is what they use in the confidence scheme to get businesses to send, you know, trillions of dollars a year to these fake drop accounts. And once they have it in the drop account, they move it into cryptocurrency and make it disappear.

So there are a number of ways that a identity can be very dangerous, and it is a nightmare for the person whose identity has been lost when they find out that they’re that they are now party to fraud, and they have to go through all the legal steps to say this wasn’t me. My identity was stolen, which is which is not a simple process. So what’s the solution there? You have to have identity monitoring.

It’s something that we all have to have. It’s like having a virus scanner. It’s like having cybersecurity protection. We have to have identity monitoring.

Good news is most of us get it free because somebody got breached and they have to give it to us for two years.

But you have to have it because you need to be able to see that your identity was just used to open a bank account somewhere and you can quickly reach out and say, this wasn’t me and protect yourself from a long line of hassle.

Well, thank you so much, Eric, for your fascinating overview of what’s going on in the market right now. And I have to say, while you provide a very realistic understanding of what’s happening, you always provide optimism as well as an approach to move forward in a productive way. So we really appreciate your insight. And perhaps at this point, you can maybe provide us with a few key takeaways for companies that are hiring at scale and who are bringing new employees on board or contractors on board and how you sort of manage their identity throughout their employment life cycle.

Key Takeaways for Hiring Practices
Certainly. In terms of hiring, do your diligence. Don’t pass this off to someone who’s unqualified. Make sure that you have the policies and the processes and the technology and know how or someone from the outside who can help you to make sure that when you’re vetting prospective employees, they are who they say they are. Make sure that you know exactly who in your organization are those key employees that you have to ensure that you can trust.

And also examine your cybersecurity when things are chill. Make sure you do it before you’re in the middle of a fire. What I always say is don’t wait till a pressure situation to examine your security. You do it now when it’s gonna be one x.

In a pressure situation, it costs ten x. So make sure that you’re taking those steps now. In my book, I have a methodology called paid. It’s prepare, assess, investigate, and decide.

And this can you be used for security. It can be used for recruiting. It can be used for any time that you’re trying to find the spire, the cybercriminal, lurking in the shadows within your organization.

You prepare ahead of the event. You make sure that you’re ready for these different threats that are coming down, like the fake employees that intelligence operations and cybercriminals are trying to seed in your organization. You are constantly assessing. That doesn’t mean it’s set and forget. Hire the employee? Great. Make sure that you’re reassessing from time to time so that you’re catching those changes in their ideology or their decisions or whether they become disgruntled.

If your assessment says, hey, we’ve got a problem, investigate. Either you have the internal ability to do it or you bring in someone externally that you’ve got on speed dial very quickly to conduct that investigation. And finally, decide. Decide to act.

Don’t put your head in the sand. Don’t think it can’t happen to me. It can happen to you. Decide to act now when you can save yourself from one of these major events.

Don’t wait till the future when your house is on fire.

Okay. Well, thank you for that great summary and those key takeaways. And now I thought you could share a little bit more with us about your book, Spies, Lies and Cybercrime.

Overview of Eric’s Book
Certainly. My new book, Spies, Lies and Cybercrime is a brand new bestseller. It was a week one bestseller. It is more than a cybersecurity book.

It reads like a spy thriller. I did that in purpose. I want people to have fun reading it. If you love true crime, you’re gonna love this book.

But it will also, as you’re having fun reading it, teach you concrete steps that you can use to protect yourself from cyber attacks. Now the other thing it does is it protects you from scams. It protects you from people who are trying to fool you, who are trying to gain your trust and exploit it. It is incredibly useful for your children.

Read it with your teenager. It will help them survive a very dangerous online platform that is coming after not only their identities, but, their personality and their psychology. It’s great for anyone in your family who loves to call you for advice on computer systems and scams. And it is a really fun read and I think an important read in trying to make the world safe from cyberattacks.

So I hope that you will check out the book. If you loved hearing my voice, I record the audio version. You can listen to that too. And if you do buy it, please drop me a review on Amazon.

It helps an immense amount in telling that algorithm, get this into the hands of others who maybe can get saved from a cyber attack.

Closing Thoughts on Trust and Identity
Eric, thank you. I think the thing that I will take away today is that the question has changed.

For a long time, we asked whether we could trust what someone had done. The harder question now is whether we can trust who they are, and you have spent a career proving how much rides on getting that right.

For anyone who wants more, Eric’s latest book, is really the best place to carry on where we’ve left off today.

Eric, it has been a pleasure having you. Thank you so much.

Maureen, very appreciated, and it was a privilege to talk to you today.

That’s it for this episode of Know Your People. Everything we covered is in the show notes. Follow wherever you’re listening so the next episode finds you. Know Your People from First Advantage. Trust in a changing world.

Did You Know?


For anyone who wants more, Eric's new book, Spies, Lies and Cybercrime is really the best place to carry on where we've left off today. It's available on Amazon.


This content is offered for informational purposes only. First Advantage is not a law firm, and this content does not, and is not intended to, constitute legal advice. Information in this may not constitute the most up-to-date legal or other information.

Readers of this content should contact their own legal advisors concerning for their particular circumstance. No reader, or user of this content, should act or refrain from acting on the basis of information in this content. Only your individual attorney or legal advisor can provide assurances that the information contained herein – and your interpretation of it – is applicable or appropriate to your particular situation. Use of, and access to, this content does not create an attorney-client relationship between the reader, or user of this presentation and First Advantage.

Host

Maureen Lally
Maureen Lally
Chief Marketing Officer, First Advantage
Special Guests

Eric O'Neill
Eric O'Neill
Security Strategist
About First Advantage

Along the candidate journey HR teams choose First Advantage for consistent screening, fast verifications, and support of compliance regulations.

  • 200M screens annually
  • 1B+ records in proprietary databases
  • 200+ countries and territories
Learn More

Grow Confidently With Client Service Excellence

View All

Background Check Resources

Trustworthy information to assist you with strategies that empower business growth, enlighten leadership and help you face the future with confidence.

Now Available!

2024 Trends Report Reveals Latest Insights