Security Confidential S12 E6 Peter Warmka

This week on Dark Rhiino Security’s Security Confidential podcast, host Manoj Tandon welcomes back Peter Warmka! Peter is a Keynote Speaker, Author, Cybersecurity/Insider Threat Consultant, Founder of the Counterintelligence Institute, and a retired senior intelligence officer with the U.S. Central Intelligence Agency (CIA). He was on previously to talk about his book “Confessions of a CIA Spy” and now he’s here to promote his new book “Why Are You Messing With Me? – Senior Survival Guide on Fraud, Privacy, and Security”.

00:00 Introduction

00:19 Our Guest

02:06 ChatGPT and Generative Ai: How they’re used

06:14 Evil ChatGPT

07:16 How do we remain secure with Ai?

12:18 Why you shouldn’t be giving out your SSN

13:35 Sim Swapping Case 

16:26 U.A.E Voice Cloning Case

23:07 What measurements does the CIA take?

25:55 Facial recognition

27:03 Educating the Public

29:38 Why are you messing with me? – Senior survival guide

43:28 More about Peter

Transcript

Manoj (00:00.926)
Hello, everyone. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhino Security, Security Confidential. Today, we are honored to welcome back an alum of this show, Mr. Peter Warmka. Peter was on earlier. If you don’t remember his intro, I’ll brief you in a little bit here. You know, he is a keynote speaker. You can find him online. He is author of multiple books, and he’s going to talk about one of them today. You know, he’s an in cybersecurity insider threat consultant.

And you know what? He was a former real life CIA agent who was specialized in human intelligence. So we’re honored to have you back, Peter. Thank you for being here.

Peter Warmka (00:42.538)
Manoj, thank you so much for inviting me back. This is a great, I mean, we have a great time and it’s like having a conversation and hopefully we’re able to share something of value to others, which I’m sure we are, but we have a good time in doing it.

Manoj (00:55.078)
Yeah, we do. Maybe that shouldn’t be allowed. I don’t know. Everybody wants a very cyber security. That’s a serious, serious conversation. But, you know, and it is, but it’s good to take it a little bit, you know, laugh at yourself a little bit and take it for what it is. So.

Peter Warmka (00:59.83)
Hahaha

Peter Warmka (01:16.234)
Well, one thing that’s interesting about the industry is that it’s not constant. It’s constantly evolving. You have to really keep up with what’s going on from a technology as well as even say a psychology standpoint of what’s going on in the industry because things are always, always evolving. And, you know, if you step away maybe for a month or two, you come back, wow, where did that come from? I never heard of that. And that’s been, oh.

You know, it’s been out there already. So it’s really important, I think, for individuals at all levels, whether you’re, you know, a Cicely and a company, or even someone that’s, uh, retired and sitting at home and thinking, well, what, you know, why do I need to learn anything about this? I mean, anybody that uses the telephone and uses a computer needs to understand the things that we, we talk about. So sometimes I don’t even like to refer to it as cyber.

Manoj (02:13.118)
very true.

Peter Warmka (02:15.342)
Because cyber is kind of this nebulous topic, which I’ll get back into later. What my book is, I like to break it down to, it’s basically a telephone and computer. That’s where we interact with the cyber world, really.

Manoj (02:29.758)
Very true. And your point about rapid changes is very apropos. When did chat GPT come out? It hasn’t been that long.

Peter Warmka (02:36.83)
Well, it was worked on a long time, but it came out November of 2022.

Manoj (02:41.81)
Right? And now we have generative AI and we have the wonderful world of all kinds of fraudulent possibilities that exist out of that. I’ll kind of start to pick up a little bit from where we last left off there, Peter, you know, on the.

Peter Warmka (02:52.347)
Oh man, I’m in…

Peter Warmka (02:56.814)
Yeah, because there’s been a lot of developments. I think the last time I spoke at Link with you about social engineering and the methodology that’s utilized by various threat actors, criminal groups, industrial competitors, and intelligence services, et cetera, and how they use that to basically penetrate a company by manipulating humans that are insiders in those companies. So we talked at Link about that.

But what I’m seeing now, starting with the chat GPT and other aspects of artificial intelligence, how it is really, really up the game. Like I think I explained to you the process of obtaining initial information. If you’re targeting somebody or an organization, you’re gonna try to collect as much information and advance as possible. So I went through some of the different, I mean, there’s a lot of different places where we can pull together. It’s time consuming. Pull together this information.

But now with ChatGBT, it’s a tool that can rapidly increase the ability to pull together information, pull more information together, and make it much more efficient. Even though if you go on ChatGBT, they’re going to say they have their own parameters, they’re not going to allow you to do deep searches on individuals unless they’re maybe politicians or…

actors, people of notoriety, right? Where you can build a lot of information. But the regular individual like you and me, not going to, it’s not going to be pulling up all these things that it can, you know, aggregate all this information on the internet to give it out as a product. That is because it is not, it hasn’t been programmed to do so. However, the same technology in the hands of an adversary, a thread actor can pull all that up. And that’s, it’s going to be an incredible tool that’s going to enhance.

Manoj (04:31.647)
Yeah.

Peter Warmka (04:52.246)
the amount of information that individuals are going to be pulling up when they start, when they want to target an individual or an individual person or an individual company. So that’s the first aspect. Think about, you’ve also heard, wow, this is great to use this tool because it can write better than me. Right? I mean, it can write very good, clear, what do you call, pros, and especially for individuals. We talked before about how…

Manoj (05:09.354)
Well.

Peter Warmka (05:20.962)
fraudsters can generate how they can formulate fake profiles on LinkedIn and other platforms. And a lot of these people are ones that maybe are from overseas or they don’t, English is not their mother tongue. And so you might come across profiles that are a little bit awkward in their wording. There might be grammatical errors and they might be in some cases either very weak with not much substance or otherwise they’ve been copy and paste from somebody else’s profile. However, with now,

Manoj (05:25.045)
Yes.

Peter Warmka (05:50.826)
with ChachiBT, they can create very robust and logical narratives of their profile and use that, whether it’s putting it into a LinkedIn profile to make it stronger, or they can use that better written prose when they’re sending emails out, whether it’s a attempted phishing attack, or whether it’s a BEC that they’re using, trying to…

Impersonate being the boss and writing the email communication to an underlying for making a wire transfer. So these are all tools that really they’re force multipliers in trying to do the same things that I’ve been talking about regarding social engineering. But it’s taking it. It’s lowering. It’s lowering the barrier to getting in and doing these things. And it’s also increasing the quality of the fraud.

Manoj (06:42.482)
So are you aware of a evil chat GPT version, for lack of a better term? That’s the thing.

Peter Warmka (06:51.282)
I haven’t seen it, I heard of one. Yes, I mean, these things, they definitely are out there. I mean, you can have a patent on your particular product, but you don’t have a patent on this type of technology. It gets into the hands of anybody basically that wants it, desires it. So it’s not only the good people, people that wanna use it for an inferior intent can use the same technology, whether it’s creating…

Manoj (06:53.936)
Okay.

Peter Warmka (07:18.57)
you know, either using Chap’s UBT to create narratives or using programs such as Dali and others where you can create images from text. I mean, that’s all also in my hands and being utilized by individuals who want to manipulate people.

Manoj (07:38.654)
Wow. So, you know, one of the things that with generative AI that also that occurred to me was like things like captchas, it might be possible to defeat those with generative AI. Right. So

Peter Warmka (07:52.302)
That’s a good point. I think so.

Manoj (07:55.678)
Right, so the security features that we inherently rely on might have to be re-examined here. It would be advent of what’s happening. And with generative AI also, if I can mimic your voice and I can mimic your facial characteristics, that might present a lot of issues.

Peter Warmka (08:03.963)
Oh, what?

Peter Warmka (08:23.274)
Yeah, I mean, think about when biometrics came out, that was like, whoa, this is the most safe thing that’s gonna protect all of us, right? Because everybody is a one of a kind fingerprint, one of a kind voice, one of a kind. I mean, now with this technology, those can all, they can, almost all of them can be circumvented. I mean, so far identity theft, I mean, it’s allowing these individuals to take on the identity.

of individuals when they try to log in, maybe logging into their bank account or logging into their employer’s IT network. This is a big problem. I mean, we really have to go into multi-factor authentication more now than ever. I mean, this is crucial. That is one of the things that we’ll definitely have to do. I mean, there’s a lot of other issues too. What about evidence? What’s gonna happen in the court when evidence is produced? How are they gonna be able to verify

That evidence hasn’t been defaked. I mean, so this is going to be a problem. It’s going to be already a big problem for the insurance industry. Look, before COVID, a lot of insurance companies had their adjusters, individuals that would go out to see the damage. They would physically see it and write their reports. Then with COVID, a lot of it turned into, well, we can’t send these people out anymore. Let’s start using an app where individuals can take their own pictures.

Manoj (09:34.854)
Right. Yeah.

Peter Warmka (09:48.91)
or video and then upload it. But now we got, there’s a problem with and how easy it is to defake these and how the fraud in the case of insurance claims can become astronomical because of this sort of tool. No.

Manoj (10:02.158)
I had not thought of that. That’s pretty interesting.

Peter Warmka (10:07.73)
Yeah, I mean, it really is scary. Think about some of the other applications. Once again, these are things.

Manoj (10:14.002)
Well, I could fake a death. That’s what I’m thinking. Like if I want to cash in on a life insurance policy, hell that, you know, I’d just scam the whole thing. I hate saying that too, because how people get ideas is like, damn, that’s a good one.

Peter Warmka (10:21.378)
Ha ha!

I think.

Peter Warmka (10:29.943)
Well, look at these virtual kidnappings. I mean, you’ve heard of, I mean, I’ve seen these kinds of things going on for a long time. I lived in Latin America and those were going on well before they started here. Somebody will call up, you know, the spouse and say that, you know, this individual is kidnapped or a child and it gets you all, you know, they play upon your emotions, but you’re just going by what they say.

And many times it’s still enough. They can get you to go out and get money by calling cards and give them the PIN number. I mean, they were running these things out of the prisons in Brazil. The criminal groups went inside the prisons. Yeah, but now think about it, because you did mention earlier about the voice. This is a huge advance in the use of social engineering vishing to successfully manipulate people because this is even more important with…

Manoj (11:06.707)
Really?

Peter Warmka (11:24.942)
With DeepFakes, we can fake photographs, images, we can fake videos, but videos still take some time to do. It used to take weeks or months. Now it’s down to days or hours, but it’s not instantaneous. Voice is instantaneous. So when someone receives a telephone call, and they hear the voice of the person that they recognize that voice, for them that’s enough. They believe that’s really the person.

So there’s corporations that are having this problem as well as individuals. In the case of corporations, you get someone, you know, it gets an incoming call. There’s a caller ID number that’s been spoofed. They hear, you know, maybe it’s coming from their boss supposedly. Then they hear the voice of the boss. Who is going to argue with that individual? You know, they’re the boss, right? They’re mine. But this is all, all being done through, um, through the cloning the audio.

Manoj (12:13.834)
Right.

Peter Warmka (12:21.342)
And it’s instantaneous, same way that individuals can be called. There’s been a lot of grandparents scams where they get called and the person’s imitating the voice of the grandchild who’s in distress, maybe he’s been, you know, it’s being arrested or kidnapped or whatever. So, I mean, these are things now that affect a lot more people than just a handful maybe that we’re concerned about this insecurity world, right?

Manoj (12:48.822)
Do you have any ideas on how do we create a solid identity?

Peter Warmka (12:58.514)
Oh boy, solid idea. No, we have to pretty much get off the internet entirely. I mean, it’s too late. We can do things, but there’s still going to be a…

Manoj (13:10.246)
Yeah, so you’re saying that the solid would be your person walks into a bank to do a transaction.

Peter Warmka (13:19.498)
Mm-hmm.

Manoj (13:20.03)
That’s a solid identity. It’s hard to fake a total human being, right? But if it’s…

Peter Warmka (13:26.442)
Well, yeah, and that’s the point. So much of this, I mean, the vast majority of this, that we’re talking about the digital world, that we’re talking about, yeah.

Manoj (13:32.146)
digital world, right? And our social security numbers, I don’t know why the federal government has not caught up on this, but that, there has to be a way to change that if it’s been compromised.

Peter Warmka (13:48.915)
Oh, the actual number. I think there is a process, but it’s very difficult and not many people are able to do it, but I think there is a process for changing one social security number. But now, and still this upsets me, it upsets me how readily people give their social security number out. Like even when you go to the doctor and you fill out those forms, whether it’s the first time or the annual review of your records, they’re asking for your social security and I don’t put it there.

Manoj (14:12.479)
Yep.

Peter Warmka (14:17.426)
I just say, why are you asking for this? I’m not providing this number, you know? But we’ve been giving it out. We’ve given it out to everybody, it seems. And it’s almost like also our phone number, our cell number has become almost our ID number because most people keep that same telephone number forever. Most people keep their same email addresses forever too. I mean, so once a fraudster gets their hands on some of these critical components, it’s like, they got you.

He really got you.

Manoj (14:48.094)
They absolutely do it. And you know, there was a case that was just recently settled. It was a $20 million ripoff that happened. And it went down with sim swapping. And for those who don’t know about it, essentially sim swapping is where you can assume the sim of another person who’s the target of the fraud that one is committing. So…

What that case settled was the individual who was deprived of their monies sued the telecom carrier that they are at fault for allowing the transfer of my SIM to somebody else when they didn’t do the necessary verifications that needed to be done. And

what the court actually ruled in the favor of the telecom company. And they’re off the hook as far as SIM swapping goes. So now you can go and pay off an employee, and it’s not going to cost you that much to do it, who works at one of these telecom carriers. And you can say, well, I want this guy’s SIM. And there goes MFA. Bye bye. Now you need another, you need a more reliable second factor.

That’s not your phone.

Peter Warmka (16:16.198)
Yeah, that’s a shame because that’s been one of the biggest uses of, I mean, for multi-factor, was going to incorporate the telephone to do that, right?

Manoj (16:24.026)
Yeah, I’ll, I don’t remember the case offhand. I just read it recently, but I will search it and I’ll, we’ll try and include it in the show notes. Cause I think that was kind of like a big deal. Cause if the, if you’re AT&T Verizon or T-Mobile and you’re, you know, your operator or whoever your employees are decide, oh yeah, this sounds like Peter. Peter’s requesting that this SIM be moved to another device. And with eSIMS,

Peter Warmka (16:33.163)
Okay, good.

Manoj (16:53.598)
This is even much more easier to do. At least with a physical SIM, you had to go into the store or somebody had to mail it to you. There was some kind of a trace. But with eSIMs, there’s nothing. It’s just a logical SIM that someone punches in on a keyboard somewhere in a dark room and it instantly changes the IMEI code it’s associated with. And there you go.

Peter Warmka (16:56.267)
Mm-hmm.

Peter Warmka (17:23.67)
Well, I can top you on the amount of damages. You said what, 20? What was that, 20 million? 20 million. This is really.

Manoj (17:27.094)
20 million. The guy got scanned for $20 million. They took it. He didn’t even send it. They assumed his identity and willfully transferred those monies.

Peter Warmka (17:32.823)
This is.

Peter Warmka (17:41.102)
Wow. Well, there was a case in 2020. Are you familiar with this case? I mean, it’s been mentioned a few times the use of voice cloning. There was a bank manager in Hong Kong who took care of a lot of high net worth clients from the UAE and from everywhere. He received a phone call from who he believed was his client in the UAE.

Manoj (18:00.438)
Okay?

Peter Warmka (18:08.634)
caller ID number, which was spoofed, but it showed the number of his client, and then he heard the voice. It was the voice. He was convinced it was the voice of the client who requested $35 million in wire transfers to handle various acquisitions. Now, this amount of money and acquisitions was not necessarily a weird thing because they would do it, but to further substantiate the scam,

Manoj (18:24.667)
Wow.

Peter Warmka (18:35.074)
they created a few, some email traffic between the client and the client’s attorney showing, you know, this money was gonna be used for this acquisition and that. So the bank manager sent the 35 million out. And then when the client found out within hours or days, they launched an investigation by the UAE authorities. And once that money is gone,

It’s gone. Good luck if you can even track part of it. They found at least $400,000 in a centenium bank in the United States. I presume they probably got that back, but that’s only a little bit out of $35 million. So this is sort of, sometimes people refer to this as a BEC scam, but it’s not quite, BEC stands for Business Email Compromise. So think of this now, instead of being an email, it is a voice, I mean, it’s a telephone call.

Manoj (19:14.41)
Wow.

Manoj (19:18.102)
Wow.

Manoj (19:24.603)
Real compromise, yeah.

Peter Warmka (19:32.074)
with the voice of being scammed. So it’s almost like a business telephone compromise or you know what I mean? But it’s kind of the same concept, but these are really, really beginning to take off. A lot of them.

Manoj (19:35.306)
That’s…

Manoj (19:42.678)
See.

Manoj (19:46.302)
Oh, and you know, there’s one thing that comes to mind. I’m not gonna mention it on the air because I don’t wanna be the one that let the cat out of the bag in terms of how to use this. But that voice compromise is a real problematic thing. And we need to go to, we, just like you can lock your credit, Peter, I think there should be a way to lock your identity that says,

There must, I know it’s hugely inconvenient, but there must be physical verification.

of some kind on a large sum. So maybe you have the ability to lock your identity on.

funds larger than X number and you get to pick that X number. But otherwise, just like you talked about right now, millions and millions of dollars are at risk. And it’ll be very, very hard to hold the people who make the mistake even accountable. Cause how do you know? I don’t know who’s on the other end of that line. To me, it seems like a legit number. It’s your phone number. It’s coming from that and

Peter Warmka (20:44.802)
See ya later.

Manoj (21:00.742)
And the fact that I can swim sim swap now without huge implications.

Peter Warmka (21:12.586)
Well, I mean, I just don’t know if we can, I mean, it’s an interesting concept, right? I locked down the identity. I think it’s going to be very difficult, but there are some things that I think are in the works. First of all, from the standpoint of a bank or a company is sort of having in place some best practices. The first is going to be training of all their employees from, you know…

And the training can be, I mean, it probably shouldn’t be just the same training for everybody. I mean, it’s got to be at the lowest level training for everybody. But then, but then for some individuals, depending where they are in the in the company, they have to incorporate some additional things. It’s creating that awareness for them to understand of why and how these things can surface. In addition to that, they need to have, we need to lock down with compliance. We need to let lock down that certain things. There’s a protocol. You are not.

And under any circumstances, going to act and send a wire transfer based on a phone call. In no circumstances. It’s going to have to be another way of verifying this request. And that’s going to have to be part of the protocol, as well as any sort of, or even not just making wire transfers. Even like say, depending on the type of company, you have some very sensitive places in your facility.

Manoj (22:22.247)
Yep.

Peter Warmka (22:36.546)
And same thing can happen. Someone could be calling as a boss and saying, we need urgently this visitor access pass to be issued to this individual. I mean, a wrong person in a very sensitive area can cause damage. Or someone calling in and convincing somebody that they need to have their password username reset to gain access to a database. I mean, it’s kind of like there’s a number of different things that fall into the same.

Manoj (22:52.059)
Oh, they can wreak havoc.

Peter Warmka (23:04.174)
I think it’s not just wire transfers, it’s anybody taking on an action that if fraudulent could have dire consequences for that company. So we need to have those procedures, right? But we also need to rely upon AI tools to detect AI frauds. And that’s already being worked on. I mean, and because, I mean, there’s people that talk about, oh, you know, this is how you can detect a deep fake.

Manoj (23:12.278)
Whoa, let me at you.

Peter Warmka (23:33.926)
of image. This is what you should look for in a deep fake audio. I’m sorry, deep fake video. But those things are really, really going away. These little imperfections, now they’re producing these videos near perfect without any flaws. At least, no flaws that are detectable to the human eye, right? Or voices that are detectable to the human ear. The only

for absolute certainty is going to be using AI tools. And there are some already software programs that are in the works being developed to be able to detect these things. And I think that’s what’s going to have to rely upon those as well.

Manoj (24:21.37)
So you were in the CIA. What if somebody wanted to try and walk into Langley or some establishment? What what were the good hygiene measures that were implemented to make sure that you a visitor badge is not issued and the urgent basis or there’s some verification of who the hell is it that’s walking through that front door?

Peter Warmka (24:47.466)
Well, there’s probably been a lot of enhancements since I left, I left in 2010. And I probably should talk too much about how, I mean, all of us.

Manoj (24:59.13)
Whatever you can share, I know. Just like common sense things that they do that everybody could have done.

Peter Warmka (25:06.218)
Well, I mean, you have your standard access badges that are issued, that are read when you’re going through an electronic reader. So those are verified along with your picture. Those are credentials that are used. And you can only have that badge, of course, if you have a security clearance. So it’s not like anybody can just walk in there.

with a badge, they can’t obtain that badge unless they have a security clearance. Those, then there are individuals who can get in who are invited, right? Once again, they have to undergo a certain, we call it background check to ensure that they don’t have a criminal record and things like this. They’re not, you know, they don’t have to have a… Calling the background check guy. They, oh. There you go.

Manoj (25:53.558)
Ha ha ha!

Peter Warmka (25:59.21)
So they have some of these protocols that a lot of the companies will as well. Before they can issue a pass for someone to come in, that individual inside the entity is gonna have to put in a request to make sure that they’re gonna be escorted around the premises. They’re only gonna have access to a few pre-approved areas. So it’s very secure in that area. Probably the cameras, I mean, I don’t know. The cameras also, we have the capability now that cameras can read facial recognition, right?

I would be surprised if everybody that goes into the facilities maybe have their already their face captured on facial recognition and that could be a tool as far as who is authorizing who might not be authorizing.

Manoj (26:41.862)
I think they might need to go deeper than that. I mean, they might need to do the IR image and see what the blood flow looks like underneath because that’s hard to fake, right? The image stuff, I could build a nice mask. I mean, those masks are pretty good. I mean, we heard about the robberies out west where people look like the former presidents or some. I forget how it went down, but facial recognition by itself may not be the…

Peter Warmka (27:11.39)
Not anymore, not anymore. I mean, I was just blown away a few years ago when I went to China and I saw how facial recognition was used there, but now, once again, fortunately, I guess China is gonna have some of the same challenges as we do when it comes to these things. I mean, you know, we’ve got the silver bullet yet.

Manoj (27:13.043)
Yeah.

Manoj (27:22.827)
Yeah.

Manoj (27:28.262)
Well, maybe we’ll all go back to the old way. You walk into an establishment, you hand them your ID and you and you talk to them and you know the people you’re doing business with. How what a novel concept that is. You know.

Peter Warmka (27:43.27)
Yeah, it’s very difficult to go back to. Once again, most people say, I don’t got time for this. This is a big problem for a lot of these companies, especially banks, credit unions. They want to have the safest, the best security in place, but at the same time, they’re trying to balance it to not inconvenience the customer. Being convenient, having a great, what do you call it, experience for the customer is like the number one thing.

Manoj (27:46.612)
Ok.

Peter Warmka (28:12.33)
And unfortunately, sometimes security takes a backseat to this. It’s unfortunate. It’s what this is all a little part of the educational piece, right? Educating people inside the companies. You should also be doing a better job at educating the public. If the public really understood this problem, they would, I think they would forgo some of this, you know, you know, create experience to, Hey, I want to make sure that my financial assets are secure, my identity is secure.

Manoj (28:12.559)
Absolutely.

Peter Warmka (28:41.026)
So I think we need to go a long way. And there’s been a failing, I don’t know where he was saying what it’s coming from, but for failing and educating the public on this.

Manoj (28:50.942)
Yeah, and the public is also highly complacent, right? I mean, you look at the average person, it’s all about the convenience. I want the app, I want to transact, I want to, and I want to do whatever it is, I want to do it now, right? Not five minutes from now. And that lack of patience is a perfect way to create compromisable processes. So.

Peter Warmka (29:13.654)
I mean, we talked about, we were just even mentioning, we talked about on the show, I’m sure, before, how easy it is just to lock down your credit. It takes 10 minutes and it’s easy, and it only takes you maybe five minutes to unfreeze it if you wanna request another credit line. But with locking it down, no one is going to be able to pull out, request additional credit lines in your name. I mean,

Manoj (29:22.503)
Yeah.

Peter Warmka (29:43.134)
It’s incredibly simple, but yet so few people do it. Really, very few people do it. To me, it’s just amazing.

Manoj (29:49.854)
Well, it’s inconvenient because now when you go to buy a new phone or a new car, you won’t be getting it on that day. You’re going to have to sit and wait and it’s going to take a couple of days to verify the credit.

Peter Warmka (30:03.466)
You know what the problem might be? I’m thinking, I thought about this for a while. Not the problem, but it’s a consideration. Insurance. People always, I’m gonna be covered. If something fraudulently happens with my credit card, whatever, the bank’s going to take care of it. I’ll get reimbursed. The banks and other organizations think, well, I know, yeah, cybersecurity is important, but at the end of the day, I got insurance. It’s always, I’m gonna be covered if something happens to me, right? Someone’s got my back. Not realizing that, hey.

Assurance companies also make profits and the only way they make profits are increasing the premiums on all of us So at the end of the day, who are we fooling, right?

Manoj (30:41.97)
Yep, absolutely, absolutely. Well, I wanna give a chance here. We can, there’s so many other questions I wanna ask, but I wanna talk about your book. Why are you messing with me? And given that August is Senior Citizen Month, tell us a little bit about what was the impetus for this documentation and this story that you’ve put together in a great book.

Peter Warmka (31:12.158)
Oh, thank you. My first book, Confessions of a CIA Spy, The Art of Human Hacking was more, it was written for everybody, but more of the, I thought the more of the use or market for the book interest was for organizations, for organizations to understand these problems. And so I kind of walked the methodology, using the methodology, walking through how a threat actor as a social engineer would target an organization and penetrate that organization. Because after all, I did that for.

20 plus years when I was working for the CIA, legally, overseas not legally, but in the United States legally. So I thought that was a great resource for companies. And for those, the companies would be training, right? They’re employees. But there’s a certain demographic of our population that didn’t have access to that set of information, guidance, and yet is the most vulnerable

and victimize segment of the population when it comes to fraud. Right? And that is the… I mean, we can talk about them as seniors, mature adults, elders, pretty much our older population that is the prime target for fraudsters. We talk about a number of reasons and also very susceptible for a number of reasons. So I decided… I don’t know if you can see it well, but…

It’s kind of similar to my first cover, but it shows the fraudster behind with a phone, you know, and I did to the world and preying upon the elder person. So it’s a senior survival guide for on fraud, privacy and security. Right. So that’s the focus of the book. And, but not just, okay. I didn’t want this. There’s other books that are out there that talk about cybersecurity for seniors. And to me, it’s not just.

Manoj (32:40.46)
Yes, we can.

Manoj (32:48.41)
and someone with their hands in their head.

Peter Warmka (33:09.79)
I didn’t talk about cyber security. I talked about a lot of different things, including cyber, but within the realm of security. So like, for example, in the first chapter, I talk about we’re going from wealth, from trying to generate wealth all our lives to now trying to protect our wealth, right? Because imagine, right, working for 30, 40 years, you know, and…

Manoj (33:31.09)
Well, generation to wealth preservation, right.

Peter Warmka (33:38.238)
Saving and saving and saving, it takes a long time. And you have this wealth, you’re hoping to live out a good retirement. And then all of a sudden, the wrong decision, wrong mistake, because of something coming in that you were manipulated by, all of a sudden you lose a significant part, in some cases, your entire savings. And I see a lot of these, a lot of these cases. So it’s, it’s focusing on how do I protect my wealth, uh, from it being taken away by somebody else.

So I go through a number of different areas of security. I initially talk about physical security, okay? And even security in your home, because there have been cases where individuals have let in individuals into their homes, trusting that they are who they say they are, for them to rob them or even to kill them. Sorry, what’s the term, but yeah, there’s people that have lost everything or have been seriously injured or even died.

Manoj (34:14.742)
Okay.

Manoj (34:29.187)
Wow, that’s horrible.

Peter Warmka (34:34.998)
because of not having necessarily best practices in place to protect them inside their home. Then I go to the next step, well, how do you protect yourself when you’re on the street, right? And I give a lot of examples, even there’s something called, I don’t know if you heard of it, jugging? This is going on for a few years now where we’re seeing are especially targeted when they go to the bank or the credit union. A lot of them prefer to deal with cash.

Manoj (34:51.736)
I don’t know what that is.

Peter Warmka (35:03.938)
than to use their credit card. So they go to the bank, pull out a couple hundred bucks in cash, and then they maybe go back to their house or they go somewhere to use the cash to pay for something. So these criminals will be at the bank, they’ll be either inside of the lobby or they’ll be outside in their vehicle watching somebody go in and come out or watching somebody go into the ATM machine and going out and then they will follow them.

because they know this individual has the cash on them. They will follow that individual to their house, or even they’ll follow the individual to their first place because maybe they’re going to a third area, and they will intercept them. Well, as soon as they park, they will intercept them and shake them down and take the money from them. Or even if they go inside, sometimes individuals will leave that envelope on the council or on the seat next to them, and all it has to do is smashing Graham.

Crab. But there’s a lot of issues regarding situational awareness when you’re on the street. Also, not just this juggling, which is becoming a common practice in some areas, but being able to assess your surroundings and how to protect yourself, which is good for everybody, but especially for seniors. Then we go into some of the other areas of concern, identity, protection, and how to use, I don’t talk about cybersecurity, but I talk about telephone.

how to use the telephone, how to use the laptop. I mean, how are you approached by these criminals? What are some of the ploys that they’re using? And it might be just to collect information, or it might be most of the times is getting that individual to provide them with money. You know, some of these scams, imposter scam, they will impersonate being somebody from the IRS or social security. You know, almost all of this is over the telephone, right?

Manoj (37:00.35)
And it’s surprising that people still fall for that. I mean, that

Peter Warmka (37:03.67)
They will, but it’s just that there’s a couple of things. First of all, even though a lot of these organizations, entities will put out, you know, we will not contact you by telephone. It will be in writing. And they do this, they put it out in writing that this is their practice. Don’t trust these incoming phone calls. But seniors will unfortunately still trust, I guess it’s two aspects here. One is fear.

The fraudsters will play upon fear to motivate someone to take an immediate action. There’s a problem and in order to solve it, you need to resolve it right now. If you wait long, if you wait, you know, if you, if you do not take care of this at this moment, it’s going to become even a bigger problem. So, you know, we can solve this by, by paying right now via credit card or what have you. So it’s the fear factor. It’s also that a lot of these individuals are, you know, they’re isolated.

they’re living in their homes, some of them are living all by themselves. They welcome social interaction. And so when someone calls them up, they may seem strange, but they welcome that interaction. And so they have, we might be hanging up the phone right away if we detect that it’s something that’s kind of weird and we’re not interested in it. We might not even answer the phone, let it go to voicemail. But most seniors, they’re gonna pick up that phone.

and they’re going to listen and that individual is going to get their attention. They’re going to know how to manipulate them to undertake this action. You know, actually the number one, the number one scam, uh, this past year was the IT scam. Uh, I think you’re probably aware of it. You know, they’re called by someone saying there’s an issue with their Microsoft account, you know, and, uh, the computer has a, it has a virus or we, you know, we can take care of this right away.

Manoj (38:50.294)
With your computer. Yeah. Thanks for watching.

Peter Warmka (38:57.782)
By the way, it’s the fear. Oh my gosh, if I had this, you know, I know nothing about technology. This guy can help me, you know, let’s resolve it right now. And even worse, they’re charging that amount of money to fix it, but they now they probably penetrated your computer and got to be downloaded more things that they can come back anyway.

Manoj (39:05.566)
Yeah, and he’s gonna charge me 500 bucks for it.

Manoj (39:18.262)
They got credit card information or they, you’ve sent them Walmart gift cards and you’re, I mean, they’re in business now. That’s a huge scam.

Peter Warmka (39:26.002)
Yeah, so the IT thing is big, also which is really big, and it kind of surprised me with the romance scams. Because I thought the romance scams, especially when it comes to the online dating and meeting people online, I thought that was more of a thing for the younger generation or middle-aged individuals, but it’s really, really common now amongst elderly, because once again, maybe their spouse has passed,

Maybe they didn’t get online right away, but a few years have passed, they’re getting lonely. They get online, maybe they’re not actively looking for somebody, but there are those predators out there. Then they will look at those Facebook accounts and they will enter into a virtual relationship with that senior. And that senior once again is lonely and this person will readily start speaking about, oh, how much they’ve.

They like this person, how much they love this person, give this person hopes that maybe this could turn into a romance or getting married. They will give them a scenario that they have two children, three children, and these children also have needs. And so they slowly extract money from the elderly person. Elderly person wants to help them out. They might even think it’s a short-term financial need. And they keep on dragging this out little by little, asking for more and more and more money.

where all of a sudden the seniors will be, you know, putting on a second mortgage of their house, cashing in their life insurance policies to be able to send the money to these broadsters. And it’s kind of the same thing. These broadsters will try to move them from whatever social media platform they were on to another secure channel, so the media and WhatsApp or whatever, another means to communicate, but they will never communicate to them live, like using their image, their video. They will only use pictures.

Right? Yeah, exactly. It really should be a clue. And, but unfortunately it’s amazing. Even if the loved ones of that elderly person, say the children, they can see through it and say, wow, mom, you are, this is looks, this is a serious scam. You know, we need to verify this person. The person that’s in love just doesn’t see it. This doesn’t see it.

Manoj (41:20.533)
And that should be a clue.

Peter Warmka (41:48.43)
how could that person do that to me? We’re in love, you know? So even if someone tries to rationalize with them and it’s someone they trust, these romance scams really gain hold of these persons, victimizes them to the point of there’s been cases where they’ve lost everything. Everything. I remember my hometown in Beaverdam, Wisconsin, going into a Walgreens.

And they have these kiosks where you can get pictures printed. And I think the same kiosk also has Western Union payments you can make. So I went in there. I wanted to print out some pictures. And there was this elderly gentleman in front of me. He was kind of taking his time. And so I was kind of like, nothing else to do. I was watching what he was doing. And I saw that he was at Western Union. And he was trying to send some money and ask you to the country. And he did.

send money to Nigeria and somebody from my hometown, Midwest, 15,000 people, unlikely has a good friend in Nigeria. And so I raised it with the person that was working there and I said, listen, I’ve seen so many of these cases where people have been defrauded and they’re sending money to them. And I see in this case, he’s trying to send money to somebody in Nigeria. And I don’t really want to interrupt him.

Maybe there’s something that you might be able to do. And right away she stopped him and said, sir, how are you doing? Everything going okay? What are you trying to do? Da da da. And then she said, but this person, do you know this? How well do you know this person? And he just smiled, oh, we know each other very well. And what are you gonna do? They’re convinced that the person is legitimate. They’ve talked to them. They really believe that they know who this person is.

And so these types of scams are just, they’re really increasing, unfortunately. And there’s been cases of even, I mean, literally there’s been cases of suicide. So it’s more than just robbing them of substantial sums of money. It’s taking everything, including their lives. And especially, now think about, we’ve got another complex, well, another aspect of it. A lot of individuals suffer from dementia. And these are people that can be even more manipulated, right, by these individuals.

Manoj (43:52.714)
Wow.

Manoj (44:09.113)
Oh yeah.

Peter Warmka (44:11.226)
I mean, of cases of these lotteries, the Jamaican lottery, where they will contact individuals and convince them that they won the lottery, but they need to send the money. You need to send some money to be able to pay for the processing, this and that. And once that is all taken care of, they’ll send them this huge amount of money, right? And they keep on asking for more and more documents, and individuals will keep on going back and they’ll send money, send money because they believe that this…

All this money is going to be coming to them and they’re going to be able to help their children, help their grandchildren. I mean, they’re all in a very noble cause. They want to they really want to do good things. And unfortunately, they all these things are leveraged by the fraudsters. Right.

Manoj (44:56.502)
You know, it reminds me of an old adage, you know, if it’s too good to be true, it probably is. And people just hearing you describe some of these things, a lot of things come to me as like, this can’t be, this doesn’t make any sense.

Peter Warmka (45:15.566)
I mean, we talked earlier about those voice cloning, right? About how people can try to defraud an organization of hundreds of thousands of dollars or millions of dollars. This is also becoming very, very common now. We call these grandparent scams, meaning that the fraudsters will telephone the grandparent and then try to make the grandparent believe that their grandchild is in trouble.

Manoj (45:20.539)
Yeah.

Peter Warmka (45:43.806)
Maybe they’ve been kidnapped, maybe they’re about to be arrested for a DUI or something, and they will even put the grandchild on the phone. Of course, it’s not the grandchild. Grandchild doesn’t even know what’s going on. They’re not even involved in this, but they’ll put the grandchild on the phone, the voice of the grandchild, and they will have a very short conversation and sound distressed and beg for the grandparents’ help. And so the grandparents looking right away, how can I take care of this? How can I help my grandchild? And

You know, you can talk about this, you can make the grandparents, you know, the individuals aware of this, but when it comes down to that instant when all of a sudden they’re just all taken in. I mean, I’ve seen these virtual kidnappings or distress going on for years in other parts of the world, but now when you can use the voice cloning aspect of that loved one, that becomes a very serious concern. So what I recommend,

and is that families have this discussion, the entire family, siblings with their grandparents, with their grandchildren, so that they can understand that these types of frauds can take place against any family member. Let’s put in place a code, a safe word, a word that we can use in a conversation to verify that this is real. This is a real issue I’m dealing with right now. And if I don’t come up with that word,

that means is it’s fraudulent, right? It’s a simple code word or simple phrase. Everybody agrees to it. And that’s sort of our, it’s our code that we use for our families. Not hard.

Manoj (47:15.077)
Yep.

Manoj (47:22.142)
You know, that’s a great idea. That’s, and I hope the listeners take that back and they can implement this in their own. We’re also at the hour actually. So I wanted to give you a chance. Where can people get a copy of the book? Why are you messing with me? Where is it available?

Peter Warmka (47:41.45)
It’s available, the easiest place to get it would be going on Amazon. All right. It’s available in print and it’s available in Kindle ebook. And eventually it’s going to be, there’s going to be an audio version. Uh, but that’s the easiest way to get it.

Manoj (47:53.706)
Fantastic. Well, Peter, it’s been a pleasure having you. Don’t be a stranger. Thanks for coming back and sharing your wealth of knowledge. I know we’ve only scratched the surface here. So there’s a lot of… There’s a lot more questions. We’re going to have you back to continue the conversation.

Peter Warmka (48:09.742)
I think you might notice that, I really appreciate it.

Peter Warmka (48:17.958)
I’m always happy to come back and thank you for the opportunity and for all you and all your listeners, stay safe, verify, then trust.

Manoj (48:26.614)
Great last words, take care. See you, thank you.

Peter Warmka (48:29.218)
Thank you too. Thank you.

Peter Warmka’s Linkedin

Peters’ Book: WHY ARE YOU MESSING WITH ME?: Senior Survival Guide on Fraud, Privacy, and Security

Peters’ Book: Confessions of a CIA Spy: The Art of Human Hacking

$24M AT&T Sim Swapping Case

Voice Cloning U.A.E Case

Check out the other episodes in Season 12:

Ep. 0 Dark Rhino Security – The IT Security Money Pit

Ep. 1 Marius Poskus – Tech talk overwhelms the nontechnical

Ep. 2 Robert Black – Who is responsible for Cybersecurity?

Ep. 3 Eric Allard – Your Guide to SBOMs

Ep. 4 Ryan Leirvik – Understand, Measure, and Manage Cyber Risk

Ep. 5 Dan Wachtler – Building Awareness About Your Startup

Ep. 6 Peter Warmka – A Seniors Survival Guide

Ep. 7 Susan Bennett – More than the Voice of SIRI

Ep. 8 Frank Riccardi – The Human Factor is the Weakest Link

Ep. 9 Dmytro Bielievtsov – What is Vishing?

Ep. 10 Chris and Rory – Bourbon Breakdown

Peter Warmka on Dark Rhino Security's Security Confidential podcast

Peter Warmka is a former senior intelligence officer with the U.S. Central Intelligence Agency (CIA) specializing in clandestine Human Intelligence (HUMINT) collection. Following his CIA career, Mr. Warmka has made it his personal mission to help U.S. Government departments, NGOs, major corporations, and academic institutions understand and effectively combat the ever-increasing threat of security breaches resulting from the artful manipulation of insiders by those seeking to steal proprietary information and personal data.

Warmka is a Certified Fraud Examiner (CFE) and Certified Protection Professional (CPP). He is a certified instructor with the CIA-U and an adjunct professor with Webster University where he lectures on social engineering, intelligence, and counterintelligence in the Master’s in Cyber Security program.

Warmka has authored numerous articles for publications within the fields of security and fraud and presented on these topics at various global conferences.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top