Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Monday, January 5, 2026

Word of the Month for January 2026: Holographic Case Law

Given the speed that tech goes these days, this might seem a little behind the times but it's something that needs to be brought up again and again.  

See, back in 2024 (yeah, a lifetime ago), I started using Chatgpt.  

Then around early 2025, as I started cranking out a whole lot of legal research and blog content, I became acquainted with holographic cases which quickly became synonymous with how Chatgpt and other LLMs (i.e. Large Language Model) treated attorneys and case law.

Before we get into the meat of this blog, let's define what I mean by Holographic case law and why it happens.  

HOLOGRAPHIC CASE LAW is/are fictitious legal cases generated by a large language model (LLM) that appear to be real, complete with

  • Case name

  • Citation / authority

  • Page numbers

  • Court jurisdiction

…but do not actually exist in any legal reporter or database.

So, picture it - you're researching a legal topic and you hop over to Chatgpt or Grok or Gemini or Claude or DeepSeek or Perplexity or any of the other few dozen LLMs in Internet-land, and you run a search on that legal topic.  In the course of your searching you see references to several legal-esque cases.  

Problem is that when you try to find those cases via the Internet or try to cite check the cases (like what any 1st year law student should have learned to do), you can't find those cases.

The reason you can't find the cases is because they don't exist.

Wait, doesn't exist?!  

How or why is that even possible?!?  Why might an LLM crank out a case that doesn't exist?

Funny thing, but I had that exact same question and I posed it to Chatgpt which responded with:

That’s a great question — and it’s one of the most important issues when using AI for legal research.

ChatGPT (and other LLMs) sometimes return cases that don’t exist because of the way large language models work:

  • Pattern Matching, Not Databases:
    I don’t have a built-in legal case database. Instead, I was trained on lots of legal writing and I generate responses by predicting what looks like a plausible answer. If you ask for a case citation, I try to produce one that fits the pattern of a real case — correct reporter, volume, page — even if it’s made up.

  • Pressure to Be Helpful:
    If you ask for “a case where X happened,” I try to fulfill that request. If I don’t have a known case in memory, I may invent one that sounds right rather than say “I don’t know,” especially if your prompt suggests that such a case must exist.

  • Legal Citations Are Predictable:
    Because case citations follow a rigid format (e.g., Smith v. Jones, 123 F.3d 456 (9th Cir. 2020)), I can generate something that looks very convincing — even to experienced lawyers. But if you check the reporter, the case might not exist.

  • Contextual Merging (Hallucination):
    Sometimes I blend real cases. For example, I might take facts from Case A and a holding from Case B and give it a citation that matches neither. This is not intentional — it’s a statistical artifact.

This problem is exactly what led to the high-profile Mata v. Avianca (S.D.N.Y. 2023) case — where lawyers used ChatGPT to write a brief, it cited six fake cases, and the court sanctioned them.

Best Practice When Using AI for Legal Research:

  • Treat all AI-supplied case names and citations as leads, not authorities.

  • Verify every case in a trusted source (Westlaw, Lexis, Fastcase, Casetext, etc.) before using it.

  • If you can’t find it in an official reporter or database, assume it doesn’t exist.

While it's nice that Chatgpt admits that it screwed up, what's problematic is that it does so so nonchalantly - as if it's just another day in the rain and it's not problem and that so what, I screwed up - what you gonna do about it?!?
 
And that's the rub, isn't it?  It's not that you can sue an LLM for returning holographic case law - or can you?  I mean, here you are against a deadline and you run a search in an LLM for a "Motion for Summary Judgement with 4 cases on point" and you submit the results to the court only to discover at your hearing for sanctions that the 4 cases on point don't exist (because they're holographic).  
 
Yeah, you could have cite checked the cases before you submitted your motion but you were against a deadline and what self-respecting attorney actually cite checks their work, right?!?
 
As it turns out, existing lawsuits against AI companies focus primarily on copyright infringement, where authors, artists, and news organizations allege their protected works were used without a license to train the LLMs. These cases are distinct from those arising from "hallucinated" case law in legal filings. 
 
Ultimately, the consensus in the legal community is that the onus remains entirely on the human attorney to verify AI-generated work before it is submitted to a court.
 
I mean, it's a novel idea (to sue an LLM instead of cite checking your work before filing with the court) given these days that no one wants to take responsibility to screwing up because it's always someone elses fault, right?
 
You know, as this is a new year and a time for new resolutions, maybe this might be one of your resolutions - to stop blaming Chatgpt for everything wrong with the world.
 
Yes?....No?....can I at least get an Amen?
 

Monday, November 3, 2025

Word of the Month for November 2025: Social Engineering

Have you ever gotten emails from people you've never met asking for information that you don't think you should give out?

Maybe a "friend" casually asks you for your user name/password to see what funny stuff you've posted on social media.  

Maybe you're searching online at work when, out of the blue you get an email or text from someone you don't know about something like:

Subject: Urgent: Your Amazon account has been compromised! 

Dear Customer,

We have detected suspicious activity on your Amazon account. To protect your information, please verify your account by clicking the link below:

[Link: Verify your account here: malicious-amazon-login.com] Failure to verify your account within 24 hours will result in account suspension. 

You click the link, you computer screen starts to flicker and it shuts off....OR 

Nothing happens but a few days later you discover that your username/passwords have been changed making it impossible to  access any of the accounts stored in your account manager (you know, where you have been storing your usernames/passwords for the last few years), OR

You get a visit from IT/HR saying that email you clicked from someone you've never met or heard of released a virus into the computer network and it's going to cost the company hundreds of thousands of dollars to fix and, oh yeah, you're fired.

Ever happen to you?   If this scenario has happened to you, you, my friend, have become a victim of social engineering.

I remember one time years before the word "social engineering" was even coined, I got a call from an official sounding guy.  There were sounds of people talking in the background, typewriters going, secretaries taking dictation, and such.  

Sounded legit.

Guy started in asking me questions like can I spell my name, where I lived, how old I was - that sort of thing.  Then he asked for my social security number.  

Just as I started to say the first number, something caught my attention and I'm like why do you need my SS#?  He started saying something and I got the BS feeling in my gut and hung up.

Don't know what the BS feeling is?  Essentially, it's if it looks like a duck and flies like a duck but smells like Bulls**t, it's probably not a duck.

Anyway, turns out social engineering happens to LOTS of people and organizations worldwide.  In fact, globally, social engineering attacks (including phishing, impersonation, etc.) cost businesses approximately $4.8 billion in 2024—up from about $4.2 billion in 2023.

Wait, what?!

Before we get too deep into this, let's define what Social Engineering is:  
Social engineering is a trick used to fool people into giving away private information or doing something they shouldn’t, usually by pretending to be someone they're not in order to gain the  trust of their victim(s).
Social engineering manipulates or deceives people into divulging confidential information or performing actions that compromise security (either to the private individual or a corporation).  It often relies on psychological manipulation - exploiting human emotions and instincts rather than technical vulnerabilities (like what you might expect from a computer hack). 

The success of social engineering lies in the fact that humans are prone to error and therefore fall for manipulative tactics. According to a social engineering attacks survey, “Social engineering attacks are one of the insidious and pervasive threats that compromise the individual’s privacy and security.  These malicious strategies exploit an individual’s tendency to trust digital resources...One of the primary causes of social engineering attacks is human error and emotional responses to factors such as greed, fear, empathy, and curiosity.” 

Social engineering is often the gateway to technical breaches (e.g., phishing leads to ransomware), but it doesn’t always get the credit—or blame—it deserves. It's less flashy, more human, and harder to track.  So, while attacks on computer systems get better press, using social engineering is often more readily employed as it is easier to exploit human weaknesses such as trust, a sense of safety, and the tendency to help others or seek the most convenient path than to go to all the trouble of hacking a computer network.

So, what are some of the more popular ways social engineering happens?

1. Phishing

Fake emails, texts, or messages that look legitimate but trick you into clicking links, downloading malware, or entering personal info.

Example: You get an email that looks like it’s from your bank, asking you to “verify your account.”

 2. Vishing (Voice Phishing)

Phone calls where someone pretends to be from tech support, a bank, or government agency to get sensitive info.

Example: “This is Microsoft. We’ve detected a virus on your computer…”

 


 3. Smishing (SMS Phishing)

Phishing via text messages. Usually includes a suspicious link or urgent message.

Example: “Your package is delayed. Click here to reschedule delivery.”

 4. Pretexting

The attacker creates a fake identity or situation (a “pretext”) to get you to trust them and share info.

Example: Someone pretends to be HR asking for your Social Security number to “update your file.”

 5. Impersonation

The attacker pretends to be someone you know or someone in authority (like a boss or IT support).

Example: A “CEO” emails asking you to urgently wire money for a business deal.

 6. Baiting

Luring someone with a tempting offer—like free software, a USB drive, or music downloads—that actually contains malware.

Example: A USB drive labeled “Employee Salaries” left in a company parking lot.

 7. Tailgating / Piggybacking

Physically following someone into a restricted area by pretending to be an employee or visitor.

Example: “Oops, I forgot my badge—mind holding the door?”

 8. Quid Pro Quo

Offering a service or benefit in exchange for information.

Example: “I’ll fix your printer if you give me your login credentials.”

These methods all rely on exploiting human trust, fear, curiosity, or helpfulness—not just technology. That’s what makes social engineering so powerful and dangerous.

So, how might a social engineering attack  play out in real life:

Scenario: "The IT Support Scam"

Target: An employee at a company
Attacker’s Goal: Gain login credentials to the company’s internal system

  1. Pretext (The Setup)
    The attacker calls the employee pretending to be from the company’s IT department.

    "Hi, this is Mike from IT. We’re doing urgent maintenance on the login system, and I noticed your account has been flagged."

  2. Creating Urgency and Trust
    The attacker uses technical jargon and time pressure.

    "If we don’t fix this now, your access could be locked and flagged for audit. I can help you reset it quickly."

  3. Information Gathering
    The attacker asks a few harmless-seeming questions to gather details:

    "Can you confirm your username and the last four digits of your employee ID?"

  4. Exploitation
    Then comes the real request:

    "Now I just need your current password to manually reset the system on our end. After that, I’ll send you a temporary one."

  5. The Hook
    The employee, stressed and believing they’re helping IT, provides the password.

  6. Execution
    The attacker immediately logs into the employee's account and accesses sensitive company data or plants malware.

What just happened?  The attacker didn’t hack any system—they hacked human trust. That’s social engineering in real time: manipulating someone into voluntarily giving up secure information.

Have you ever had this happen to you?  I'll bet it has but you didn't know it. 

So, what can you do to protect yourself?  Turns out there are a number of things you (or your company) can do to prevent (or, at least, delay the inevitable attack), like:

Recognize the warning signs

  • Unexpected phone calls. If you get a call you weren’t expecting, especially if the caller says they’re from a bank, insurance, or an IT company, chances are it’s a phishing attempt. 
  • Suspicious email sender’s address. If something feels off about an email you got, always check the sender’s email address because it may be a spam email.
  • Unusual requests from someone that you may know. If your boss or a manager contacts you with urgent requests for money, credentials, documents, and other information when they've never done that before, it could be a phishing attempt. Always verify.
  • Urgent requests or demands. Phishing attempts have a sense of urgency to them, such as “pay now” or “act quickly,” all designed to make you feel pressured, distracted, and overwhelmed into acting NOW!
  • Unexpected links or attachments. Do not open attachments or click on links in emails you were not expecting. They could be malicious, and lead to dangerous sites. 
  • Unusual layout and spelling. Incorrect grammar and spelling, strange sentence structure, and inconsistent formatting are strong indicators of a phishing attempt. 
  • Generic greetings/signature. Greetings that don’t include your name, such as “Sir/Maam,” and signatures without contact information (or contact information that does not make sense) are strong indicators of a phishing email. 
  • Offers that seem too good to be true. If an offer seems too good to be true, such as large amounts of money for seemingly useless information, it could be a phishing attempt.
  • Requests on social media from someone you don’t recognize. Be wary of messages from people or entities you don’t know.

Implement multi-factor authentication

Multi-factor authentication, specifically phishing-resistant MFA, is a security method that requires users to verify their identity using two or more different types of proof, like a password and a code sent to your phone. The requirement of two or three extra steps lowers the risk of a breach even if attackers already have your credentials.

Train employees on awareness

Regular organization-level training is important to ensure the safety of your employees and data. Employees should be informed about and be taught to use defensive measures such as multi-factor authentication, the importance of  the use of strong passwords, and the use of firewalls.

Operate under the zero-trust mindset

Essentially, don't trust anyone. Always assume all incoming communications are social engineering attempts, and proceed with caution.  Always be looking for clear evidence that the message is legitimate.

Avoid sharing personal information online

Monitor your social media profiles keeping them private and ONLY share access with people you know personally. 

Like  the old timey radio show The Shadow instilled in baby-boomers everywhere: Who knows what evil lurks in the hearts of men? 

Who, indeed!?

Your best bet is to keep your personal information close to your vest and trust no one because everyone is out to get you (insert evil laugh, here).

Monday, October 6, 2025

Word of the Month for October 2025: DeepFake

The other day, as I was perusing through Internet-land, I came across an article about a CEO who had been the target of a deepfake.

Wait, what?!  What's a deepfake?

A DEEPFAKE is media in which a person’s face, voice, or body is digitally altered to make it appear as though they did or said something they never did. For example:

  • A video of a politician giving a speech they never gave.

  • A celebrity’s face swapped into a movie scene.

  • An audio clip mimicking a person’s voice to scam someone.

So, back to CEO.  Apparently, CEO allegedly sent out an voicemail to all his employees to get them to send him their personal information.

Seemed sketchy since CEO hadn't  made this types of request before.  Turns out he didn't and that the email was a outed as deepfake before anyone lost any data.

Sounds pretty funky, huh?  Think I'm making this all up (because who can mimic another person's voice and mannerisms.).  Well, turns out these deepfakes happen a LOT.  For example:

AI Voice Fraud — Executive Impersonation Leading to Wire Transfers

  • UK Energy Firm (~2019): Scammers used AI to clone the voice of a German parent company’s CEO, perfectly mimicking accent and “melody,” and convinced the UK-based CEO to wire €220,000 (approximately $243,000 USD) to a fake supplier.

Deepfake Video Conference — $25.6M Hong Kong Scam

  • Hong Kong (2024): In a highly sophisticated scheme, employees participated in a video conference featuring deepfakes of their CFO and other colleagues. This led to HK$200 million (~$25.6 million USD) being transferred to fraudsters.

Deepfake Voice — $35M Bank Heist in Hong Kong

  • Hong Kong (2020): A bank manager received what sounded like a phone call from a director using AI-generated voice, instructing a $35 million transfer for a supposed acquisition. The fraudulent request was combined with emails from supposedly real associates, making the scam convincingly authentic.

Rising Trend of Executive Deepfake Scams

  • Several major companies have been targeted by voice or video deepfake scams aiming to extract sensitive information or payments. Details include:

    • Ferrari (2024): A deepfake impersonated CEO Benedetto Vigna in a video call to authorize a fraudulent wire transfer. An executive assistant foiled the scam by asking a security question only the real CEO would know.
    • Arup (2024) Fraudsters impersonated the CFO in a video call and convinced a finance employee to transfer $25 million 
    • WPP advertising group (2024): A deepfake of CEO Mark Read, using a voice clone and public photos, was used in a scam to solicit money and details from a senior executive. The attempt failed due to employee vigilance.
    • LastPass (2024): An employee received an AI-generated audio call and WhatsApp messages impersonating CEO Karim Toubba. The employee became suspicious due to the "forced urgency" and unusual communication channel, and reported it.
    • Crypto Exchange (2023): Binance warned about deepfake impersonation scams after its executives were targeted. In one case, a deepfake video of a CEO was used to steal credentials. 
    • UK Energy Company (2019): An employee wired $243,000 to a fraudulent account after being tricked by a deepfake audio clone of their CEO

 


While the law is still catching up, major concerns involving deepfakes include privacy, defamation, fraud, and harassment. Ramifications vary by context:

  1. Defamation / Reputation Harm

    • If a deepfake falsely portrays someone in a damaging way, they may sue under defamation laws.

  2. Fraud & Identity Theft

    • Deepfakes used to impersonate someone (e.g., voice cloning for scams) may lead to wire fraud, identity theft, or securities fraud charges.

  3. Harassment / Nonconsensual Pornography

    • A large portion of harmful deepfakes involve placing individuals’ faces into explicit content without consent. Many states are passing laws criminalizing this.

  4. Election & Political Law

    • Some states (e.g., Texas, California) have statutes restricting deepfakes in election advertising or political campaigns.

  5. Intellectual Property

    • Using a celebrity’s likeness without permission may violate right of publicity laws.

  6. Federal & International Movement

    • In the U.S., there’s no single federal “deepfake law” yet, but bills have been proposed.

    • The EU’s AI Act and China’s regulations require labeling or banning certain deepfakes.

So, who is/are creating these deepfakes and why?  Money aside, it depends on who you ask and the intent of the entities.  Essentially, there are two groups: Malicious actors and Non-malicious creators.

Malicious actors
  • Individuals and groups: Malicious individuals can create deepfakes for purposes such as extortion, revenge, or harassment.
  • Fraudsters and scammers: These criminals use deepfakes for financial fraud and phishing attacks. Recent high-profile cases have involved impersonating company executives on video calls to deceive employees into transferring large sums of money.
  • State-sponsored groups and political actors: Foreign intelligence operatives and political parties use deepfakes for disinformation campaigns, election interference, and undermining public trust. 
Non-malicious creators
  • Content creators and artists: Artists use deepfakes for creative expression, to create memes, or for satire and parody of public figures.
  • Researchers and academics: These individuals develop and experiment with deepfake technology to advance AI and machine learning, and to create detection methods for malicious deepfakes.
  • The entertainment industry: Filmmakers and visual effects artists use deepfakes for high-tech digital effects, such as de-aging actors or creating digital clones. 

My next question would be (and is, since this is a legal-related blog) how have different jurisdictions handled (or have started to handle) these deepfakes?

Minnesota — civil & criminal deepfake protections

  • Civil cause of action (nonconsensual sexual deepfakes): Minn. Stat. § 604.32 — “Cause of action for nonconsensual dissemination of a deep fake depicting intimate parts or sexual acts.” (Defines “deep fake,” creates private cause of action, remedies).
  • Election-related criminal prohibition: Minn. Stat. § 609.771 (as amended by HF1370/2023) — criminalizes knowingly using deepfake technology to influence an election under specified timing/intent rules. (See HF1370 enacted language and SOS overview.).

California — private right and expanding statutes (nonconsensual digitized sexual material)

  • Cal. Civ. Code § 1708.86 (existing right / cause of action for digitized sexually explicit material) — California already had statutory civil remedies for digitized/“deepfake” sexually explicit material; recent legislative action (AB 621 / AB 2839 and related bills) expanded and clarified definitions, added remedies and presumptions against deepfake-porn services. See AB 621 committee analysis for text and changes
  • Criminal/other provisions: Recent California updates (and Penal Code cross-references) explicitly treat AI-generated intimate material in various contexts.

Texas — election deepfake statute

  • Tex. Elec. Code Ann. § 255.004 (from SB 751, 2019) — one of the earliest state statutes addressing “deepfakes” in election communications (text focuses on video misrepresentations in campaigns). Texas has also passed other bills addressing AI-created intimate imagery.

Virginia — nonconsensual intimate image / deepfake pornography

  • Va. Code § 18.2-386.2 et seq. — Virginia’s statute criminalizes creation/distribution of nonconsensual sexually explicit images, and has been applied to deepfakes (statute text and practitioner summaries describe penalties and elements).

New York — amendments to intimate image dissemination law

  • NY legislation (e.g., S.1042/A. proposed amendments) — New York bills and amendments explicitly fold “digitized”/deepfake images into unlawful dissemination of intimate images; see NY Senate amendment language (S1042A) that inserts deepfake/digitization language into the statute. (Check final compiled bill text where enacted.)  

OK, OK, so the statutes in place don't actually deal with people stealing personal data or squeezing someone for money - rather for sexual gratification and election interference - which  are both important but given the rate at which cyber criminal are expanding operations, it's easy to see that governmental entities are lagging behind the times.

This is not to say that there has not be any action in the courts.  In fact, there are a number of cases that have dealt with deepfakes in recent years.

Lawsuits related to non-consensual deepfake pornography

  • City of San Francisco vs. Deepfake Websites (2025): The City Attorney's office sued websites that generate nonconsensual explicit deepfakes, resulting in a settlement with one company, Briver LLC, for $100,000 and a permanent injunction. The city is continuing litigation against the remaining defendants, some of which are located internationally.
  • Kyland Young vs. NeoCortex, Inc. (2023): The reality TV star sued the developer of the deepfake software Reface, alleging the app violated his right of publicity under California law. This case highlights how deepfake apps can be misused. 

Cases concerning intellectual property and likeness

  • George Carlin Estate vs. Dudesy Podcast (2024): The estate for the late comedian sued the Dudesy podcast for using AI to create a deepfake comedy special titled George Carlin: I'm Glad I'm Dead. The lawsuit was settled quickly, but it brought attention to using AI to replicate an artist's likeness and voice.
  • Disney & Universal vs. Midjourney (2025): Major studios filed a lawsuit against the AI image generator Midjourney for the "wholesale appropriation" of their characters, such as Darth Vader and Minions, to train its AI. The suit alleges copyright infringement and dilution of their intellectual property.
  • Amazon vs. Illinois Biometric Privacy Class Action (2025): The facial recognition startup Clearview AI agreed to a $50 million settlement in a class-action lawsuit for scraping billions of facial images from the internet without user consent. The suit was brought under the Illinois Biometric Information Privacy Act (BIPA). 

Lawsuits involving election interference and misinformation

  • New Hampshire Robocall Case (2024): A political consultant was charged with orchestrating a deepfake robocall campaign that used an AI-generated voice mimicking President Biden to deter Democratic voters from casting ballots.
  • X (formerly Twitter) vs. California (2025): Elon Musk's social media company X challenged and won a legal victory against a California law restricting election-related deepfakes. A federal judge blocked the law, citing concerns that it could lead to censorship of protected political speech, such as parody. 

Other ongoing deepfake-related litigation

  • Elon Musk vs. Tesla Wrongful Death Lawsuit (2023): As part of a wrongful death lawsuit involving a Tesla, the company's attorneys questioned the authenticity of a video showing Musk making statements about Tesla's self-driving safety. Musk was ordered to testify under oath to determine the video's authenticity, highlighting how deepfakes can affect the admissibility of evidence in court.
  • Mark Walters vs. OpenAI (2025): A radio host sued OpenAI for defamation after ChatGPT generated a false summary that accused him of embezzlement. The court granted summary judgment in favor of OpenAI, ruling that ChatGPT's output was not a factual assertion given the known fallibility of the technology.

and the list goes on and on and...  The point to all this is that while AI is helpful, it can also be a pain in the neck because if you can't believe your own eyes, what can you believe in?

 


I guess the bottom line to all this is stay informed, be aware of your surroundings, and know that everyone is out to get you.

That's not paranoia, that's just gut-reaction common sense.

Thursday, July 31, 2025

Lot of sneaky buggers out in cyberland

Once upon a time, I was a legal researching God working in a law library.  The library in which I worked was, essentially, divided in half with state materials on one side of the wall and federal and general materials on the other.  

Another key feature of the library in which I worked was that it was not sound-proof.  What this means is that if you spoke over a whisper, you could be heard on the other side of the building.

Can you see where this is going?

One day, as I was going about my business I noticed an attorney conversing with his client.  They were in the middle of a deposition and attorney was relaying attorney/client privilege stuff to his client.  

NOTE:  That's privilege as in they wouldn't want anyone to know what they were saying.

The problem was that attorney was speaking louder than a whisper and opposing counsel (who was situated on the other side of the building) could hear what was being said and was taking copious notes.  I mentioned this to attorney annnnnnnnnnd attorney became upset stomping over to and started arguing with opposing counsel.

Of course, all this could have been avoided had attorney implemented safeguards to protect his client's interests such as lowering his voice to a whisper.

Back in the day, simply keeping your voice down was enough to safeguard secret client information.  These days, however, low volume is not enough.

Picture it: Paralegal, “Sarah,” receives an email from “Attorney Michael” at your firm on a busy Thursday afternoon.  The email reads:

Subject: URGENT: Client Wire Instructions Needed
From: michael.attorney@gnnail.com (looks similar to your firm’s domain)

Hi Sarah,

We need to send out the wire for the Johnson closing today.  Please open the attached PDF for the updated instructions and confirm you can process this ASAP so we don’t delay the client’s funding.

Thank you,
Michael

An attachment named “Johnson_Wire_Update.pdf” is included.

As it happens, Sarah knows Michael is working on the Johnson file.  While the message feels rushed, that’s normal on closing days so she clicks the attachment without verifying that Michael actually sent the email. 

As soon as she click's the attachment, malware capturing Sarah’s keystrokes installs to her computer sending her Office 365 credentials to the attacker.  The attacker then logs into Sarah’s email, monitors communications, and sends modified wire instructions to the title company directing $150,000 of the client’s funds be wired to a fraudulent account.

Sound far fetched?  I mean, things like this don't actually happen, right?


Turns out it happens all the time.  There are a number of ways hackers (i.e. bad actors who steal people's information from their computers) can access data illegally.  Following are some of the more popular methods:

Phishing

  • Fraudulent emails, texts, or messages tricking victims into clicking malicious links, opening infected attachments, or giving personal information.

  • Variants: Spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice calls).

Pretexting

  • Attacker creates a fabricated scenario (pretext) to obtain information, e.g., pretending to be IT support or a bank representative to get login credentials.

Baiting

  • Attacker leaves malware-infected devices (USBs, CDs) in public places hoping someone will use them out of curiosity.  When the USB drive is inserted in an unsuspecting computer, the malware installs its self and facilitates the stealing of information.

Quid Pro Quo

  • Attacker offers a benefit (e.g., free software or IT help) in exchange for sensitive information.

So, in the example above involving unsuspecting Sarah, the method used was a phishing attack.  There were a few things Sarah could have done to protect herself.

Red Flag #1 was the slight misspelling in the sender’s email domain (gnnail.com).  It's looks close to "gmail" but is not quite right.  Spider senses should be tingling.

Red flag #2 would be that it was contained urgent, pressure-filled language.  Even if it was urgent that action be taken, there's always time to step back and look at the big picture.  

Finally, Red Flag #3, think whether the sender would normally send wire instructions.  If this is not a normal occurrence, then maybe wait to verify before acting.

So, what could Sarah have done to protect herself?  Sarah could have used her mouse to hover over the sender’s email address to verify the email's authenticity.  She could have confirmed with Attorney Michael in person or by phone before opening the attachment - especially for financial transactions.

History is replete with examples of organizations that have been attacked.

Example 1: In 2020, Grubman, Shire, Meiselas & Sacks (one of the premier entertainment and media law firms in the country) was attacked when an employee reportedly clicked on a phishing email, allowing REvil ransomware attackers to access the firm’s network.  Consequently, the law firm experienced a theft of 756 GB of celebrity client data and a $42 million ransom demand.

A ransomware attack typically involves malware that locks users out of their computer files, systems, or networks, demanding a ransom payment for their restoration.  Ransomware attacks involves a “one-two-punch” (1) cybercriminals lock your system; and (2) cybercriminals steal your most sensitive information. 

This was what happened in the attack on GSMS.  The REvil group demanded a ransom payment to release encrypted files as well as an additional payment to permanently remove stolen information from their own system.  Increasingly, even when a ransom is actually paid, these attackers still release small pieces of stolen data to their website and make it available for purchase by the public to encourage payment.

Example 2: In 2019 at a mid-sized real estate law firm in Texas, an employee clicked a phishing email that led to credential harvesting.  Hackers accessed the attorney’s email and modified wire transfer instructions for a real estate closing, diverting client funds (about $150,000) resulting in a malpractice claim filed which was resolved with cyber insurance payout.

Example 3: In 2020, Goldman, Campbell,  Brain and Spine fell victim to a ransomware attack when employees fell victim to a phishing email, allowing ransomware to encrypt the medical law firm’s systems.  The type of information stolen included names, Social Security numbers, medical codes, postal addresses, telephone numbers, email addresses, dates of birth, and gender.

Example 4: In late 2024, Cloud security firm Wiz faced a deepfake attack. Criminals used AI technology to clone CEO Assaf Rappaport's voice and then sent voicemails to dozens of employees asking them for their credentials.

Example 5: Lee Enterprises (February 2025):  Attackers using Qilin ransomware targeted the media company, disrupting production and claiming they stole 350 GB of data.  The company was warned of imminent leaks if the ransom payment wasn’t made.

Example 6: Medusa Ransomware on Critical Infrastructure (March 2025):  Over 300 organizations across sectors (healthcare, education, manufacturing, government) were attacked by Medusa, using spear phishing and unpatched software vulnerabilities to steal and encrypt data, then threaten leaks (double extortion).

Example 7: Ingram Micro (July 2025):  Ransomware detected on internal systems of the global IT supplier Ingram Micro, causing multi-day outages that disrupted customer orders and operations. Investigations and law enforcement notification are underway. Knowing that there are hackers and thieves out in cyberland, what can you/we do to protect yourself?

Whether you are a CEO, law firm, or regular, everyday person, you can protect yourself using simple, time tested methods such as:

  1. Do not (as in never) click unfamiliar or suspicious links or attachments.  If you do not recognize the sender of the email, don't click on any attachments.  In fact, send straight to spam.
  2. Always verify wire instructions via phone using known numbers.
  3. Use strong, unique passwords for each system.  A strong password is one that is designed to be hard for a person or program to guess.  It's long and uses a mix of uppercase and lowercase letters, numbers, and symbols, and avoids common words or personal information. A strong password should also be unique to each account.  

A good rule of thumb is to create strong passwords that are longer than 12 characters (some corporate passwords are 50+ characters that are changed every 3 months).  The problem is, how can you remember a unique 12+ character password with upper/lower case letters, numbers, etc?

Actually, there are a few techniques you can use to help remember a long password.

You could use a passphrase.  Maybe a sentence of words like what you can remember.  Maybe something like:

My dog Spot loves to chase squirrels, especially in the park!123@

ThisIsMyP@$$word!

You could also try using a mnemonic devise like an acronym.  If you have trouble coming up with something, you can try using Chatgpt.  Suggested examples might include:

  • SysAdm!n2025_Pro (This example combines a common abbreviation for "System Administrator" with a special character, a year, and an abbreviation for "Project,")

  • Cyb3r$ec.Net-Guard (a play on Cybersecurity)

  • Innov8@ion.Hub+XYZ (This blends "Innovation" with a number, a special character, and a generic identifier

  • Glob@l.Biz_SoluTns (This example blends "Global Business Solutions")  

You could use a password manager to store all your user names/passwords like what most browsers offer.  The problem with that is that if your system is ever hacked, the hacker now has access to all your passwords.  

Finally, and I can't count the number of CISO's who'll flip out on this, but you can just write your passwords down on paper.  Just be sure to put the list somewhere not publicly accessible (i.e. not just sitting out for everyone to see).

One Caveat:  NEVER use "password" or "12345678" (or any related derivatives) as your password as they are the most used passwords and are the first thing cyber criminals try when trying to break into a network.

Yep, there are a whole lot of sneaky buggers out in cyberland.  Best to keep a weathered eye out for bad actors so that you don't become an easy mark and lose all your data.

I'm just sayin.