Security Confidential S16 E6 Brett Johnson

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to former US Most Wanted turned Good Guy, Brett Johnson. Brett, also known as “The Original Internet Godfather,” was a key figure in the cybercrime world for over 20 years, founding ShadowCrew—the first organized cybercrime community. Brett was Convicted of 39 felonies and placed on the U.S. Most Wanted List, his expertise in identity theft, fraud, and hacking was unmatched—until he turned his life around. Now a leading cybersecurity consultant and speaker, Brett uses his past to educate companies, law enforcement, and individuals on how to protect themselves from the criminals he once worked alongside. His journey from cybercriminal to cybersecurity expert has been featured on CNN, NBC, Vice, Wired, and more. 

00:00 Introduction

01:32 Our Guest

05:05 “I call myself a criminal”

18:40 I like Ebay a LOT

24:02 Victims will be judged

38:00 What are companies getting wrong?

39:58 Why don’t we see employers educating employees?

55:46 Connect with Brett

Transcript

Manoj Tandon (00:01.048)
Hello everyone, this is your host Manoj Tandon Welcome to another episode of Dark Rhiino Security, Security Confidential. Today we have a phenomenal guest on the show, Mr. Brett Johnson. And if you guys want to see more people like him, please hit the like and subscribe button. As crazy as it sounds, show us a little love and YouTube will show us a little love too and so will Spotify and everybody else. So appreciate it. Thanks for watching guys.

Brett really doesn’t need much of an introduction, especially for all you guys who are in the cybersecurity world, probably know a lot about him. But for those of you who are listening who don’t come from cybersecurity, Brett is one of the most well-known hackers out there in the industry. He spent 20 years, ended up on the US Marshals most wanted list at one point in his life, evaded those guys for quite a bit of time. And I really want to know how you do that, because that…

identity, you know, you know, he was one of the founders of shadow cast and shadow crew, I’m sorry, not shadow cast and, you know, pioneered some techniques and mass scale, identity fraud. And, and now he is, a real good guy spends a lot of its time as a keynote speaker, as a consultant, to major corporations, to law enforcement and,

is trying to help all of us out and we’re honored to have him on the show. So Brett, thank you for joining us.

Brett Johnson (01:33.518)
Hey, that’s a hell of an introduction. And I just want to thank you for taking the time to talk to me. I appreciate it.

Manoj Tandon (01:40.546)
Well, you know, it’s not every day we get someone that’s as well known as you. And boy, do we want, we want, it’s like getting a chance to ask the magician his secrets, but I don’t know what you’ll let us in on, but it’d be good, because all of us are curious how things get stolen. But before we start that, let’s just do the quick 30 second on your background. Like, how did you get started in all this?

Brett Johnson (02:08.123)
Ha, the third.

Manoj Tandon (02:08.406)
And by the way, I want one thing you need to put in there. What was your first computer? What was your first computer? Because you and I are about the same age and I’m just curious what…

Brett Johnson (02:12.165)
Okay, what?

Brett Johnson (02:20.796)
I am 55 as of last week. How old are you?

Manoj Tandon (02:24.782)
55 as of last July. Yeah.

Brett Johnson (02:26.34)
All right, so we’re right there. Last July, okay, so we’re right at it. So my first computer was a Texas Instruments TI-9948. That was it. I remember, I had a Trash 80. I used to play that, there was a, you you had the Zork, yeah, the text adventures. Then they had a Star Trek text adventure that was available on the Tandy system. I don’t know if you remember that or not.

Manoj Tandon (02:36.563)
Wow, I had the trash AD.

Manoj Tandon (02:45.684)
Yeah.

Manoj Tandon (02:54.263)
I remember that.

Brett Johnson (02:55.644)
I spent a lot of time doing that shit that I, my mom, my mom opened up a credit card and somebody else, not a credit, a Sears account in someone else’s name. And that got me, I’d had a Vic 20, but that got me a Commodore 64. But we could not afford, yep, yep, yep. We could not afford the disc drive. So for those who don’t know, used to.

Manoj Tandon (03:13.358)
Brett Johnson (03:23.164)
If you were just absolutely dog shit poor, Commodore had a tape drive where you would put cassette tapes in and it would record the game or what have you onto that cassette tape. And then to upload it would take, I don’t know, three hours. Yeah. If it didn’t mess up. And usually it would mess up. So that was me. Yeah.

Manoj Tandon (03:39.18)
Yep, I remember that. That’s right. So you go back to that time. That’s fantastic. How did you start off in the world of hacking? I mean, for me, I remember it was the first thing was the old phone lines, the long distance. Everybody got in on that one.

Brett Johnson (04:05.244)
So, and I want to clarify something. I don’t call myself a hacker. All right. I call myself a criminal because I am. I’ve still got the criminal mindset. I still have the temptations. I just choose not to break the law. And even when I was in computer crime,

Manoj Tandon (04:15.168)
Okay.

Brett Johnson (04:25.5)
I don’t know if anyone, don’t know, I honestly don’t. Nowadays they do, but back then no one called themselves a hacker. Why am I a hacker? Nah, nobody said that bullshit. So, you know, they would say, well, I’m a Carter. Excuse me. I saw some smoke coming out of my system.

Manoj Tandon (04:34.99)
The word wasn’t there.

Manoj Tandon (04:45.995)
Yes.

Brett Johnson (04:48.152)
So they would call themselves, you know, a credit card, a Carter, somebody that would launder money. They would say that I’m, you know, a launderer or something like that, but they would never say a hacker. So just to clarify that now, when we’re talking about hacker, I am not a coder. I can code a little bit, but I’m not like that. but here’s the thing. Back then, you didn’t need to be. And today you don’t need to be.

You don’t. The way, and we’ll get to my story and how I got involved with it in just a second, but I wanted to just clarify this. For cybercrime to succeed, or an attack to succeed, three things have to take place. You have to gather data. So that’s the credentials, that’s a stolen PII, that’s any tool that you may need to launch that attack. Once you gather the data, you commit the crime, you attack, and then finally you have to be able to cash that attack.

Manoj Tandon (05:23.606)
Yeah, absolutely.

Manoj Tandon (05:31.949)
Okay?

Brett Johnson (05:46.596)
or that crime out, either through, and that means information, access, data, or cash. One of those four things or a combination of those four things. All of those things need to work in conjunction. If they don’t, that attack, that crime fails. Now the problem, and it’s a huge ass problem, the problem is that a single attacker typically can’t do all three things. He can do one, sometimes two, but not all three. So that’s why,

Manoj Tandon (06:04.642)
Okay.

Brett Johnson (06:13.754)
you see the dark web markets, the forums, they exist so that that attacker, that criminal can network with other criminals who are good in those areas where he is not. Okay, so that’s why you have these environments. They exist primarily to network. And there’s a couple of reasons that that attacker can’t do all three things. Maybe it’s a skill gap. He simply doesn’t know how to do it. He can’t launch a man in the middle of attack.

Manoj Tandon (06:38.359)
Yeah.

Brett Johnson (06:41.872)
He can’t steal credit card data. He doesn’t know how to do efficient, what have you. Or he does, but someone else is better at it than he is. And he will rely on the marketplace to fulfill that one necessity. That’s one of the reasons. The other primary reason is there’s a problem with geographic location. That attacker is simply in an area where he can’t fulfill one of those three necessities. And typically that goes into the cashing out, into the money laundering aspect of crime.

Manoj Tandon (06:55.714)
Okay.

Brett Johnson (07:10.512)
So you take a lot of criminals during the pandemic. They were in the Ukraine, they were in Russia, and they were eating the unemployment benefits systems alive across all 50 states, all right? Now, that’s great from Ukraine and from Russia. You can file the claim. You can get the claim processed and fulfilled and deposited onto a Chime account or a Cash App account or onto a prepaid debit card. But guess what? If you start to try to withdraw that money from Ukraine,

Manoj Tandon (07:39.256)
Yep.

Brett Johnson (07:40.58)
or from Russia, you may get a few dollars out, but sooner or later that account is gonna be shut down. So criminals understood that. So what you had to do is you had to network with people in the United States that could cash those accounts out for you. And they would charge anywhere from 30 to 40 % of whatever was on the account at that point in time. And it worked, it was highly successful. So that’s why it’s typically not a single attacker.

that seeks to victimize you or your organization. So I just wanted to clarify that. Now you asked me how I got involved in all this and the short version.

Manoj Tandon (08:15.778)
Yeah.

Brett Johnson (08:20.548)
if there is a short version. I grew up in a family that committed a lot of fraud. When I was 10 years old, I found out that my mom was a fraudster. And the way that I found that out, my mom had left my dad and my mom used to go out and party all the time. And she would leave me and my sister at home for days at a time. We didn’t have any food in the house. Mom is gone for a few days. I’m 10. My sister Denise is nine.

She walks in one day, she’s got this pack of pork chops in her hand and I’m like, where’d you get that? She’s like, I stole it. And I’m like, show me how you did that. So she takes me over to A &P and she shows me how she’s stealing food and the way you steal food when you’re nine and 10 is you stuff it down your pants. So we started doing that, look across the way, well, there’s Kmart there. Kmart’s got a hell of a lot more than food. So it becomes this perverted form of Maslow’s hierarchy of needs.

Manoj Tandon (08:52.269)
Yeah.

Brett Johnson (09:16.826)
books, games, jewelry, music, toys. Yes. Until mom comes home, sees all the stolen loot. Really, she saw me playing the Intellivision that I had shoplifted, asked where it came from. I tell her, hey, we, we, we found it. She’s like, no, you didn’t find that. My sister, Denise, she was, the girl was nine years old and she stands up and she, she was half proud about it. She’s half pissed off about it. She was like, we stole it. And my mom,

My mom looks at my sister, show me how you did that. And she starts running these little shoplifters and she picks up the phone and calls her mother to join us as well. That’s where my life of crime begins. And here’s the thing, and I’m adamant about this. I do not blame my childhood on my choices as an adult. People have had much worse upbringings than I have.

Manoj Tandon (09:48.984)
Ugh.

Brett Johnson (10:12.644)
My sister, for example, had the exact same upbringing that I did. She, other than one shoplifting experience, she doesn’t break any more crime. She doesn’t commit crime or break the law. She goes off to be a good citizen, a parent, teacher. She’s got anger issues, but she’s a good person. I’m the guy that just kept on going. And I chose, when I became an adult, I had the opportunity to choose to do the right damn thing. And I didn’t. I continued on that life of crime.

So, and that family, it wasn’t just my mom, know, I’m the guy that kept on going with this. I found out that, you it wasn’t my mom and my grandmother, it was every single member on that side of the family that was involved in some sort of hustle. You know, you didn’t call it a fraud, you called it a hustle. And so I grew up knowing how to do insurance fraud. So faking accidents, faking stolen cars, burning homes for cash, charity fraud.

Manoj Tandon (10:55.906)
Wow.

Wow.

Brett Johnson (11:11.194)
Document forgery, disaster relief fraud, these days it’s FEMA, I don’t think it was FEMA back then. Illegally strip mining coal, trafficking drugs, I mean there’s a whole host of different crimes that I grew up knowing how to commit.

Manoj Tandon (11:26.67)
How could you, how did you get away with it for such a long time? And this is not like one crime sector. This is, you’ve mastered several and yet no one can get you.

Brett Johnson (11:38.34)
No, no, no, no, no, let’s be fair. Let’s be fair. I would not call, just because you’ve done it doesn’t mean you’ve mastered it. Okay, so, and here’s the thing too. mean, there are a lot of people don’t understand this, but you said, how did you get away with it? A lot of the times you don’t get away with it. So a lot of the times, and over the span of my career, before I got involved in cyber, I got many visits from law enforcement.

Manoj Tandon (11:47.586)
Okay.

Brett Johnson (12:07.494)
but they never did anything. You they would, you gotta pay these people back. You can’t be doing this shit. They would say stuff like that and talk harshly to you. Same thing for my mom. mean, she would get visits every now and then, but typically what you learn when you get caught from, you know, security or law enforcement or what have you is, well, how did I mess that up? How do I fix that so that doesn’t happen again?

You learn from it, adapt, overcome, and go on with it. And that’s typically, that’s a lot of the problem today with the attacks. You know, I work on the good guy side of things these days. And one of the things I’ve noticed, and I’ve worked with a lot of companies, and a lot of companies, they will be able to identify the attacker. Absolutely they will. In the case of like Microsoft, for example, Microsoft has actually paid some of these guys a visit. Absolutely they have.

Manoj Tandon (13:03.83)
Really? In Ukraine? In China?

Brett Johnson (13:05.218)
yeah, yeah, but Microsoft, well over in Europe, they had a guy, is before, Microsoft brought me in at one point to be a consultant, I was consulted with them for a few months. They told me a story of a guy who ripped them off of several million dollars doing advertising fraud. Microsoft back then, this is five or six years ago, had a huge issue with advertising fraud. So this guy rips them off in Germany of several million dollars in advertising fraud.

Manoj Tandon (13:16.286)
Okay.

Brett Johnson (13:34.118)
They go over to prosecute the guy, talk to the judge. The judge, no shit, the judge tells them, hey, you guys are Microsoft, you can afford it. Okay, so yeah, yeah. So Microsoft, the guys from Microsoft, they were like, well, maybe we can just go on and knock on this guy’s door. So they go knock on the door, tell the guy they know who he is. The guy evidently had never committed crime before, had not spent any of the money.

Manoj Tandon (13:36.814)
Okay.

Manoj Tandon (13:44.952)
Huh?

Brett Johnson (14:03.592)
and agrees to send the money back to Microsoft so they don’t prosecute. Now, what a lot of these companies do is they won’t be able to identify you. They will never prosecute. Now, why wouldn’t they prosecute? The reason a lot of companies won’t prosecute is there’s the CEO of Under Armour at one point, he said that trust is gained in droplets, but it’s lost in buckets. So if you’re a company that’s experienced a breach that’s been defrauded,

Manoj Tandon (14:07.054)
you.

Brett Johnson (14:33.454)
and that comes out in the press. What does that tell all of the legitimate customers that you’ve got? This company’s got some security problems. This company’s got issues. This company lost all this money to fraudster, all this bad presses about them. So a lot of trust is lost quickly that took a long time to build among your clients. So a lot of companies absolutely refuse to do that. And that’s one of the major problems with fraud and crime.

is the lack of prosecution, the lack of reporting. For example, the first real Internet crime that I committed, I had faked a car accident to get the money to get married. This was 1994, 95 ish. So I had faked accident to get the money to get married, moved from Hazard, Kentucky to Lexington, Kentucky to go to UK, go cats. I’m the guy, Jesus, I’m the guy. I get the worst parts of my mom and my dad.

Manoj Tandon (15:17.582)
Okay.

Brett Johnson (15:31.782)
dad. get my dad was this kind of this cook kind of guy, not much of a back. I mean, I love my dad, but tell the truth, he didn’t have much of a backbone, not much drive or anything else. And he was scared to death. My mom was going to leave him all the time. So if she wanted to commit a crime, he would co-sign off on it. If she wanted to abuse someone and she was hell, she’s still alive. She, if she wanted to abuse someone, he wouldn’t stand in the way. So what happens is, is

Manoj Tandon (15:58.144)
Okay.

Brett Johnson (16:02.32)
Yeah, yeah, he became that enabler. So I get the worst parts from both of them. My dad, I get that fear of being abandoned. I’ve historically been that guy that thinks that that’s scared of the people that I love leaving me. And add on to that, I have never really been able to show love in a healthy way in a relationship. it’s been, instead of trying to be healthy with it, it’s been like, my love is worth this expensive crap I’m about to give you.

and I would try to buy love like that. I’m not talking about strippers and escorts. I mean, I did that too, but I’m talking about the people who were really valuable to me. So I get that part from my dad and I get the criminal mindset from my mom, you So, you you mix those together and you’ve got this guy who ends up making the United States Secret Service Most Wanted list at the end of

Manoj Tandon (16:39.747)
Understood.

Manoj Tandon (16:57.792)
It took them a while to get you on that list. It didn’t happen overnight. What precipitated it?

Brett Johnson (17:00.782)
It did. Yeah, it did.

All right, so I was talking about my first Internet crime. I had faked that had faked that accident to get married. And I was running these little scams, physical scams around Lexington, Lexington, Kentucky. I had worked at a telemarketing firm and I like stolen their phone list in order to set up my own charity to defraud people. And I got caught doing that. Of course I did. Once I get out of that, I spent three months in a county jail for that. And once I get

Manoj Tandon (17:09.1)
Yep.

Brett Johnson (17:35.152)
got out of that problem, get out, get a computer, and not really knowing how to make money, figure I can, finally I find eBay. And I liked eBay a lot, a lot. I figured, hey, there’s gotta be some way to make money on eBay, didn’t know how. And back then, Bill O’Reilly, that former Fox News host that got his ass in all that trouble,

Manoj Tandon (18:01.26)
Yeah, yep, yep.

Brett Johnson (18:03.642)
He used to host Inside Edition. So Inside Edition is a 30 minute TV news tabloid show.

Manoj Tandon (18:08.576)
And I think all of us, yeah. Seen it.

Brett Johnson (18:11.324)
Yeah, so the one show they were having that night was on Beanie Babies. So for those who don’t know, Beanie Babies in the mid to late 90s were these little stuffed animals and they were highly collectible and highly valuable. And the one they were profiling that night was called Peanut, the Royal Blue Elephant, and it was selling for $1,500 on eBay.

Now that elephant when it came out was about $8. So I’m sitting there watching the show and I’m thinking to myself, Brett, you need to find a peanut. So I skipped class the next day and I was very naive. I figured that, hey, I’m in Kentucky. There’s gotta be one. People don’t know what’s going on in Kentucky. There’s gotta be one in a bin somewhere. So I skipped class the next day, go around to all little shops in the area looking for peanut, takes more on here.

about three hours, about three hours to figure out no idiot, he’s not in the bin, he’s on eBay for $1,500. But they did have these little gray beanie baby elephants for $8. The exact same elephant, just a different color. And I’m sitting there going, so what do you do? Well, you buy that gray one for $8. You stop by Kroger on the way home, pick up a pack of blue writ dye.

Manoj Tandon (19:08.471)
Okay.

Brett Johnson (19:34.672)
You go home and try to dye a little guy. And it turns out they are made out of polyester. They don’t hold dye very well. When you get them out of the bath, they look like they’ve got the mange. But here’s the thing. And they do, they do. mean, so here I am, my dumb ass, I had this big yellow mop bucket. I put the RIT dye, the warm water in there, put the animal in there and it floats to the top. So then I get the spatula out of the drawer and I’m sitting there stabbing the animal down in the water.

Manoj Tandon (19:34.977)
Yeah,

Manoj Tandon (19:46.146)
Yeah.

ehh

Brett Johnson (20:03.132)
pull it out and all the dye is running off of it. And I’m like, shit, this is not gonna work. What I did was I ended up ripping a lady off of $1,500. I found a picture of a real one online. I posted it. She thinks I’ve got the real thing. She wins the bid. As soon as she wins the bid, social engineering kicks in. social engineering is one of these necessities of successful attacks or successful crimes online. I became a social engineer as a child

Manoj Tandon (20:18.63)
Brett Johnson (20:33.02)
because I had to understand the adults in my circle in order to survive. It was a survival mechanism. I had to understand it and be able to manipulate them if I was going to be okay. Once I became an adult, I used those tools to victimize other people. And that, am not uncommon in that. You will see a lot of the more skilled cyber criminals that are very good social engineers and they become those social engineers as children. So with this victim that I have.

I did not want to be on the defense of that conversation. I wanted her on the defense. So what I did was, is I sent her a message and the message was basically, hey lady, congratulations, you win the bid. Here’s the thing, you and me, we’ve never done any business before. I don’t know if I can trust you. So what I need you to do, what I need you to do is I need you to go down to the US Postal Service.

Manoj Tandon (21:15.16)
Yeah

Manoj Tandon (21:22.988)
Okay.

Brett Johnson (21:29.872)
pick up a couple of money orders totaling $1,500. They’re issued by the United States government. They protect you. They protect me. You send those to me, I’ll send you your animal. Well, she believed that. She sends me the money orders. cash them out. I send her this creature in the mail and I immediately get this phone call. This is not what I ordered because dumbass here had committed that crime in my own name. So,

get this phone call, I didn’t order this. And my response was, lady, you ordered a blue elephant. I sent you a blue-ish elephant. And the point of that story, there’s a few points. The point of that story is that if you delay a victim long enough, you just keep putting them off, a lot of them, they get so exasperated, they throw their hands in the air, they walk away, you don’t hear from them again.

Manoj Tandon (22:05.24)
You.

Brett Johnson (22:25.582)
and they don’t complain to law enforcement. That’s like a running little thing all the way through the running line, all through these cyber crimes. They don’t complain to law enforcement. They don’t, it’s embarrassing. All right, if you’re an individual, you’ve got mass media, you’ve got family, you’ve got a lot of companies out there that blame the victim. And we’ve even got lines about it, right? Why would you click on that? Why?

Manoj Tandon (22:38.033)
Well, it’s embarrassing.

Brett Johnson (22:53.296)
Why would you send money to someone you don’t know? Who would ever think of gift cards? So there are lines where we’ve got them in our collective consciousness where we blame the victim. Victims, as you pointed out, they’re embarrassed. They know they’re going to be judged. Matter of fact, a lot of law, a lot of local and state, I’ve even seen feds do it. They will laugh at the victim. Maybe not to their face. I’ve seen it happen to their face as well, but certainly behind their back. Can you believe that?

That person was that stupid. Stupidity’s got nothing to do with it. You’re dealing with someone, this is their career. This is what they do. They are better at it than you, and they understand the technology and the psychology enough to manipulate you into giving up information, access, data, or cash. That’s the way these crimes actually happen. So that’s really the first main lesson of cybercrime. But that Beanie Babies, absolutely, but that Beanie Babies story,

Manoj Tandon (23:47.49)
Social engineering.

Brett Johnson (23:51.576)
is also kind of a microcosm of the way most of these scams work. If you think about it, that woman wanted something. She had a desire for something. That desire, that need allows me as an attacker to more easily get her to react emotionally instead of rationally or logically. If I can get you to react emotionally, that’s your ass. All right, that’s what I’m looking for. Absolutely.

Manoj Tandon (24:15.982)
Well yeah, but that’s the basis of all the retail too, Brad. I mean, most buys are impulsive buys, right? So if…

Brett Johnson (24:22.264)
Absolutely. You got somebody that wants to believe and then what do you do as an attacker? have in order for me to defraud you either as an individual or a company, I have to establish trust with that potential victim. If I can’t get you to trust me, you’re not going to give me that information, access data or cash.

Manoj Tandon (24:42.798)
But if I think I can get what I want and it satisfies an emotional need, then I’ll quite, I’ll give it away. I mean, that’s kind of the foundation even of a retail economy. Like I said before, I mean, that’s how you walk into Target. You went in there to buy a bar of soap and out you come with $100 worth of stuff.

Brett Johnson (24:53.02)
That’s it.

Brett Johnson (25:06.396)
That’s me every trip to Sam’s Club. Or Costco, yeah. Right.

Manoj Tandon (25:08.77)
There you go, right. Or Costco or whatever, right? It’s the same thing. It’s an impulse. You really don’t need the item, but you’re like, yeah, that looks cool, man. I’m gonna buy it.

Brett Johnson (25:18.96)
Right. And as long as you make so on the crime side, as long as you make it somewhat believable and we see that where that’s most applicable today is in the crypto vertical. All right. You’ve got there’s a let’s be honest, you’ve got a lot of fraud. I am not a crypto fan at all. You’ve got up to 90 percent of all the volume on crypto is faked through bots, through wash trading, things like that. So you’ve got this. But at the same time,

You’ve got a lot of media out there, even paper play media that that tells people you’re going to become rich. You’re going to become rich. Look how much money we’re making. Look how, look what this token did. Look what this token did. And it allows people who already want to believe it allows those people to buy into that fantasy, even though over 99 % of them are going to lose their ass.

Manoj Tandon (26:08.322)
But Brett, how many times have have we heard the old saying if it’s too good to be true, it probably is. And yet everyone keeps falling for it. mean, your crypto definition falls right into that.

Brett Johnson (26:14.864)
And that’s true.

It is, but I understand, and I’m adamant about this. It is never, it is never the victim’s fault that they have been victimized. It is always the criminal’s fault. It takes an active choice every step of the way on the part of the criminal to victimize that person. Now, that being said, that being said, if you are in a bad neighborhood,

and you leave your door open and in the foyer there where everyone can see you’ve got three Rolex Daytonas and then you put a sign out in front yard saying I ain’t got no security I’m going to be gone for the next week. You probably you probably are going to lose your shit. There has to be and I’m trying I’m trying to to

figure out where that line is. But there has to be a line where that person is somewhat responsible for their own security. There has to be. And the reason I say that, you take these like Zell fraud, for example, you you’ve got a lot of payments fraud that’s out there. In the UK, they have, they’ve got to the point where they’re saying, okay, financial institutions,

for victims of the Zelle type fraud. For those who don’t know what Zelle fraud is, you’ll get like an email saying you owe me money or you’ll get somebody that’s selling something on Facebook Marketplace or whatever and they’ll say, hey, send me this much money through Zelle. Or they’ll pretend to be your power company or the IRS or some bullshit like that. They’ll say, send me this much money. You should, you should, but that’s not always the case.

Manoj Tandon (27:51.124)
Okay. Well, that one you should know by now that you don’t do. Yeah.

Brett Johnson (28:02.588)
So, and especially, and so take this, you say you should know, but say I go on the dark web, I buy your complete identity profile for say $70. So I know everything about your background that I possibly need. At the same time, maybe I’m able to find some banking information about you, some of the transactions that you’ve done. What I’ll do is I’ll spoof the phone number of your bank. I’ll either call you directly or I’ll send you a text message saying, hey, did you approve this transaction on your card?

Of course you didn’t. So you’ll say, no, I didn’t. And immediately you get a phone call from me. It looks like it’s coming from your bank. And I’ll start quoting stuff back to you. Hey, the last where your social is this. Hey, you live here. You’ve been here this minute, this many years, blah, blah, blah, blah, blah. That’s enough. Remember I said I had to build trust with that potential victim. That’s enough to get you to trust me for me to convince you that I am that financial institution. All right. So then what will I do? Well, then I’ll say, well,

Let me check and make sure everything’s okay with your account. I’ll pause, act like I’m accessing your account and I’ll say, now you’re logged into your account right now, right? No, I’m not. You’re not? Well, someone’s logged into your account right now. We need to secure your account before it’s all stolen. What you do is quickly send this out of money over to Zelle. That way we get it out of that account. We put it in a temporary account and we will protect you. Okay? So done. You’re done at that point in time. That is a very common type of fraud.

A lot of the victims.

Manoj Tandon (29:28.116)
It’s amazing that people would fall for that though. mean, and Zelle has a limit. Like, and I think it’s like 2,500 bucks a day, something like that. Yeah.

Brett Johnson (29:31.012)
It is.

Brett Johnson (29:34.716)
It’s like 2500 a day. So, but a lot of people fall for that fraud, but here’s the thing. If you’re in the UK and you fall for a similar type of fraud, the UK has passed legislation where, the financial institution is going to reimburse you for that. That’s not the case in the United States. In the United States, it’s the choice of the financial institution if they reimburse you or not, and most of them won’t. All right? So that victim is then out of money. Now, where does

that line fall as to what that victim is responsible for and what the victim, because there’s two victims, there’s a financial institution and then there’s the person, that individual. So where is the responsibility? Where does that lie at? then, and it doesn’t, obviously it’s not completely with the financial institution, but it’s not completely with that victim either because that financial institution is much more privy to the information that’s going, that the payment.

that’s going along those rails. They are able to see when the account was set up, who it’s being sent to, who’s received money, blah, blah, blah, blah. Is there potential fraud on that account already? They’re able to see these things that that individual victim isn’t. So there has to be a line of responsibility that that incorporates both of those victims. And so far, we’re not seeing that. But we need to figure that stuff out. We absolutely do.

Manoj Tandon (30:58.766)
That is a difficult problem. I think people getting educated and not being so impulsive with this stuff. I mean, I’ll tell you, Brett, had what the story you were describing with a bank calling you back and doing this, I had a very similar thing happen to me. people try and hit me up all the time because what’s better than screwing over a cybersecurity guy? That’s the ultimate.

Brett Johnson (31:00.751)
It is.

Brett Johnson (31:25.54)
Right. I got him. Yeah.

Manoj Tandon (31:27.766)
Yeah, they just want to do it for the shit of it, right? Right? And the guy was good enough that for a second, I absolutely was like, mmm. And said, you know what? I’m hanging up. And I hung up and then I called my bank. And I said, connect me to the fraud department. And did you guys call me? Because he started asking, just like you were saying, you know,

This is your home address. This is your last four year social security number, blah, blah, blah, blah, blah, blah, blah. I said, you know what? I’m hanging up now because my bank would never call me.

Brett Johnson (32:00.956)
Hmm?

Brett Johnson (32:10.16)
right.

Manoj Tandon (32:11.18)
Right? Now, in case there’s a micro chance, you know what? I’m gonna call them. And I’m gonna see what the hell was going on. It turned out it was a total fake scam.

Brett Johnson (32:20.41)
Right. And, and bear in mind, you did the exact right thing, but a lot of people aren’t well enough versed in understanding how that specific fraud works. And it’s not just, so I’ll give you another example. And this, this is something that happened, Jesus is two or three years ago. Cause I helped, talked to some reporters about it. We’ve worked on that together. So there was, there was an instance where you would have what looked like a doctor’s office call you. Okay.

And if you’ve ever wondered what stolen medical records can be used for, this is one of the things. Yeah, there’s tons of stuff. I know, right?

Manoj Tandon (32:55.836)
I can think of it. Well, have you ever seen the pres… The prescription fraud thing is the one where I think there’s a lot of money is at,

Brett Johnson (33:03.654)
So what was going on here, someone would go on the dark web or they would find somebody who had stolen medical records. They would buy those records. We’re looking for Medicare records is what we’re looking for. So you get Medicare records. You then find a doctor willing to sign off on a bunch of shit, okay? And you’ll find out what that shit is in just a second. And then you’d find a lab that could conduct some tests for.

So what you do is you’d open up a call center, start calling all the people with these medical records. You’d call them up and say, hey, are you Bob Roberts? Well, look, Bob, this is George over at Dr. Petro’s office. And we were just going through some of your past history. And it looks like that you may be susceptible for one specific type of cancer. And what we’d like to do is we’d like you go into the lab and just have this test done. Now, look, it doesn’t cost you anything at all. The test itself is maybe five, 10 minutes. You’ll be in and out. That way we can

make sure that you are okay and you’re not, you know, have the potential to get this cancer in the future. How’s that sound to you? And of course, because it’s not gonna cost you anything, it’s only gonna cost five or 10 minutes. Okay, I’ll do that. Goes into the lab and that test, Medicare pays about $22,000 for that test. Now all of that’s fraud. Every bit of that. The doctor is culpable of that. The lab knows what’s going on as well.

And then you’ve got the call center and you’ve got the stolen medical records, extremely profitable. And the exact same thing that I’m talking about with the financial institutions, you’ve still, you’ve got that, that building of trust, convincing the victim that you’re real. And then finally the payday at the end of it. So all of this stuff is kind of interrelated as we go along. There really is, when you’re thinking about all these attacks that are out there, there’s very few new types of attacks.

They’re just innovations on existing types of attacks.

Manoj Tandon (34:57.71)
That’s interesting. What would possess a doctor to want to do get themselves into criminal jeopardy? You’re getting prayed pretty well as it is.

Brett Johnson (35:05.649)
Well.

Brett Johnson (35:09.976)
Are you though? Okay, so I’m a speaker. I make decent money. Okay, so most general practitioners, they’re making 100, 150 grand a year. That’s good money. It’s good money. Okay, but if just by signing off on some orders, I can add another two to 300,000 on that per year, would I do it? A lot of doctors will. Absolutely they will.

Manoj Tandon (35:19.384)
Sure. Okay.

Manoj Tandon (35:33.574)
of course there is. I remember back in Cleveland, was a whole, I was, yeah, back in Cleveland, I remember there was, many years ago, it was like two decades ago, there was a group that was passing off Percocets and they were making cash hand over fist on that deal.

Brett Johnson (35:37.176)
Especially when they think, you who am I hurting?

Brett Johnson (35:55.834)
Yep. Yep. My cousin, and you can look him up, his name is Butch Chaney in Hazard, Kentucky. He got indicted for Oxycontin Fraud. He had opened up his own pharmacy. And I don’t know if you’ve ever seen the videos of Oxycontin Fraud in Eastern Kentucky, but you would literally have a line of people circled around. It’s like a movie theater line. You have a line of people circled around the doctor’s office going in, getting their scripts.

going across the street to the pharmacy, filling the OxyContin and going home. So yeah, very common.

Manoj Tandon (36:31.672)
Well, they needed a doctor to sign off on that. You got one.

Brett Johnson (36:35.088)
Yeah, you got one. Then he owns a pharmacy too. So you, hey, good to go.

Manoj Tandon (36:40.844)
You’re good to go. And it’s better than buying from a drug dealer, because now you’re getting pharmaceutical grade stuff. It’s not cut with a-

Brett Johnson (36:42.427)
Yeah, and, and.

Brett Johnson (36:46.778)
You are, and at the heyday, right, at the heyday of Oxycontin, those tablets sold for, on the street, they sold for a dollar a milligram. So an 80 milligram tablet sold for $80. That was good money in Eastern Kentucky. Yeah, it was good money today.

Manoj Tandon (37:05.848)
That’s amazing. What are companies getting wrong, Brett? Keep talking. When you talk about cybercrime here, what in their cybersecurity programs should they be doing that you’re not still seeing them do?

Brett Johnson (37:21.852)
I’m a big Reddit fan. I don’t know if you are or not. I’m a big Reddit fan. And today…

Manoj Tandon (37:27.264)
I end up on there at least once a day because some search puts me onto that thing.

Brett Johnson (37:30.629)
Okay.

Right. So today there were people that were bitching about Elon Musk having access to all these systems, all these servers. All right. And evidently one of the I think it was you said had denied Musk and his associates access because they did not have security clearances. All right. And of course Musk gets his ass in there, locks them all out of the building. And someone pointed out that, hey,

at the end of the day, if you don’t have the executive side up for you, you don’t have anything. So, and I see this, this is common across all verticals where you will have security or you’ll have the fraud team, but the executive branch, you know, hey, the fraud team is basically known as the no team. We don’t even really want them in our meetings. And those cyber guys, man, they want this, they want that, and they want this, and it’s just gonna cost too much friction for our

Legitimate customers, let’s set them to the side. Everything is going to be okay at the end. We’ll wait until we’re hit. Then we’ll worry about it. I think that’s a common thing of you’ve got security that wants to do the right thing, that continues to preach about it, but management is more worried about other things. And to be fair, you’ve only got so much money.

You know, for economics people, that’s either guns or butter. What are you going to choose? And a lot of people, choose not the guns. don’t go for security. They go for the butter approach. You know, we’ll worry about security when we need to worry about security. And that thought process of not putting security as a foundation of your company is a huge problem.

Manoj Tandon (39:24.302)
I would agree with that. I’m smiling a little bit because I did a talk last week in San Antonio to a bunch of electrical contractors. And I paraphrased what you just said. you know, was like, you know, if you guys are pawning cybersecurity off to the IT people, well, good luck with that. Have fun.

Brett Johnson (39:39.506)
All right.

Manoj Tandon (39:49.56)
Good luck with that. That’s not protecting your brand. It’s not gonna protect your revenue chain, because you’re not fundamentally understanding how, as a bad guy, someone’s gonna innovate to get into your organization. And that gets back to the thing. Brett, what about, why don’t we see, and I’ve bitched about this on this show in 160 plus episodes, and it’s still, I’m gonna bitch about it again. Why don’t we see,

Brett Johnson (39:50.94)
Yeah.

Brett Johnson (40:01.084)
You’re not.

Brett Johnson (40:11.056)
Hahaha!

Manoj Tandon (40:17.57)
the employees being brought in as part of, as a main pillar of a cybersecurity program and educating them on all the things you’re talking about. Example after example, and those stories are so powerful that I think instead of being the department of no, if people understood it, they would know, these guys aren’t saying no to me. They’re telling me what behaviors can get all of us in a lot of trouble.

Brett Johnson (40:47.654)
Sure. So, so, so think about it from, and I’ve seen engineers, I’ve, I’ve been, I’ve actually sat in on these conversations. So you, you’ve got engineering that they’ve been working their asses off on some brand new product or service and they’re proud of it. It’s high tech. They’ve convinced, and they’re right. They’ve convinced management, Hey, we are going to make a lot of money. No one else is doing this right now. It’s fantastic. So management is, they’re, they’re excited. Engineering is excited because they’ve done their job. And then all of a sudden,

Manoj Tandon (40:53.912)
Okay.

Brett Johnson (41:17.58)
Over in the corner, you’ve got some numb nuts from fraud or security that’s sitting there going, you can’t do this. You can’t do this. Don’t you know they’re going to eat you alive? So all of a sudden you’ve got negative Nancy over there saying, Hey, I know that we’re going to make a lot of money, but we can’t do this because it is going to be eaten alive with fraud. What do you want to hear? Because you’re trying to provide, you know,

profit for your shareholders. Everyone wants to eat.

Manoj Tandon (41:48.662)
Yeah, but that’s on a quarterly basis. So what I’m thinking is, look, maybe I got two more quarters here. So can I make my bonus cash out, pay for the condo in Miami? I’m not saying every.

Brett Johnson (41:59.802)
And let’s be fair. mean, so, so right, but, you’ve got, you’ve got a lot of, of companies that, know, Hey, all these accounts that are being set up. Yeah. A lot of them may be fraudulent, but there’s still accounts. You we’ve still got all of these users, even though one third of them or more may be criminal users. We’ve still got all these users on our platform. We’ll just worry about, you know, getting rid of the bad actors later.

So that matters, it matters. It’s disappointing, it is. We shouldn’t be like that as a society. We shouldn’t, we should. I made a post today and I talk about this frequently of doing the right damn thing regardless, regardless of anything else that’s happening on the planet. And we live in a society today where a lot of people, they will not,

They will not point out anything that’s wrong. They will not speak up or speak out or act on anything because they’re upset. They’re scared of upsetting someone, losing a contracted job, losing a friend, anything else like that. And we should not be like that as a society. We should be the people who we want people to call out wrongdoing. But you know what? The truth of the matter is we live in that world that if you are a whistleblower, if you are someone that’s pointing something out that no one wants to hear, you are going to face negative consequences.

That’s more often than not, that’s the way that story ends. Yeah.

Manoj Tandon (43:32.365)
especially as a whistleblower. Those whistleblower protection laws really don’t work as being evidenced in the media on a daily basis. So I gotta ask you this, how did you change your identity or how did you evade the cops for such a long time? Because you did.

Brett Johnson (43:37.243)
Now.

Brett Johnson (43:40.774)
Right.

Brett Johnson (43:53.914)
Well, got, so, you I pointed out that, you know, I started crime when I was 10. And over the years, I had visits from law enforcement. It wasn’t like I didn’t. But each time, I would learn from those visits and I would become better. And, you know, like with the Beanie Baby thing, I did that under my own name. I got away with it, kept going, and got better at understanding how internet fraud and crime should operate.

one of the core principles at Shadow Crew that I taught on Shadow Crew is that all crime should begin with identity theft. Now back then, we had access to the Texas driver’s license database, had access to the Indiana State Sex Offenders Registry, to the California Death Index, things like that. I would use a lot of identity, I used a lot of identities from all three of those databases.

For my identities, I would either use the Texas driver’s license database or the California State Death Index and create identities around that. It was very easy at that point in time. Not that it’s not easy today. They’re dead. No, sir. No, sir. The system, the way the system works, not even today, two degree. All right. So, so state indexes don’t reference

Manoj Tandon (44:59.82)
That person’s already dead. The system should shut.

It didn’t. I know back in the day it didn’t.

Brett Johnson (45:15.686)
federal indexes and vice versa. So you can be registered as dead in a state index and the federal index never know that. And there are cases and the reason that happens are cases where, the state doesn’t know what they’re talking about. This guy’s alive, he’s doing fine, he’s healthy, everything. I’m not dead yet. He’s all that. Yet the state thinks he’s dead, the feds, they don’t. All right, and then trying to convince the state.

that you’re alive can be a pain in the butt all of a sudden. And you can read about this, you can Google this stuff. There’s stories upon stories of that happening. So back then, the way the feds knew you were dead, prior to 1997, if you had passed away, it took the family to file for a social security death benefit. Only paid about $218. Once you filed for that benefit, that informed the federal government that that individual was dead. Well, it took the family

1997 and prior to file for that. Most families wouldn’t do that. They were distraught. They were in grief. They didn’t need $218. You can keep your damn money, all that, all right? Or they didn’t know about it. So the federal government, their indexes, their databases, they don’t know that a lot of these people are actually dead. They’re just, hey, what happened to them? So those identities on a federal level, easy enough to use. Now, after 97 from 1998 prior to today,

the funeral home or the hospital can file for that Social Security death benefit. So they’re much more accurate these days. What I used to do, so when I found the Social Security Death Index, I mean not Social Security, but California Death Index, my initial idea was, I wonder if I can file for Social Security benefits on these individuals that the federal government thinks may still be alive.

So I tested that, tried it out. Turns out that those numbers have been dormant for so long, they wanted you to come in for a physical interview. Well, no, I’m not going to do that. So the next idea I had was, well, I wonder if you can file tax refunds for these individuals. And it turns out you absolutely can.

Brett Johnson (47:37.252)
So I’m the guy that, and there’s nothing to be proud about this at all, I’m the guy that created this thing called Social Security, not Social Security, but Tax Refund Identity Theft. The reason your all’s returns are delayed every single year is this asshole right here talking to you today. And I stole a lot of money doing that, and it’s a crime that continues to be committed today.

Manoj Tandon (47:59.01)
There were a lot of people in prison who were doing it right from their jail cells.

Brett Johnson (48:03.164)
There were lot of people prison doing it right from their jail cells. Yeah, a lot. Yeah. And it’s a, it’s a, you know, and here’s the thing. I I, I, I was the exact same way. I didn’t, I didn’t give a damn about my victims. didn’t care. I, you know, it started with dead people and, understand that there are victims in because you’ve got the families, the surviving members of the families that, when they find out that they’re, they’re, they’re, they’re loved one who passed away a few years prior is, is, know,

Manoj Tandon (48:08.174)
I remember that.

Brett Johnson (48:33.73)
being used by some criminal that that causes an emotional response that you have a victim there. But it wasn’t just dead people with me. It got to the point that, I would steal someone’s identity and file a tax return on them. And you’re not just harming or stealing money from the government. You’re harming that individual that needs that tax refund. A lot of people, they wait for that tax refund to to buy appliances, to survive everything else. And the problem is, is that when you steal that money,

It delays their tax returns sometimes for months. So you’re harming individuals. And, you know, when I was a criminal, when I was committing crime, you’d make excuses. Well, I’m just stealing from the government. They’re going to get their money. Everything’s OK. That still goes on today. You go on telegram on the dark web and you sleep. You’ll see these people that have these excuses that say stuff like that. And the truth of the matter is, is that.

it’s not just the government you’re harming. It’s not just financial institutions you’re harming. You’re harming real people that need that credit, that need those refunds. it’s…

It’s just a horrible life to lead when you’re victimizing someone so that you can benefit.

Manoj Tandon (49:52.44)
Can’t disagree with that. So was it that, it’s very true. So was it that they didn’t know who was actually doing it because these were actually legitimate people, so they couldn’t track you down. That basically.

Brett Johnson (49:54.233)
No, it’s true.

Brett Johnson (50:04.004)
Right. Right. And we see that today. mean, the same thing is going on today. When I stole identities, had, you know, you would either make your own fake driver’s license or you’d buy one. I got people to send me fake driver’s licenses all the time. And, you know, that idea of continually being on the move, continually switching identities, it’s hard to locate someone like that. At the end of the day, they absolutely did.

you know and i got what i needed i i needed to be imprisoned

Manoj Tandon (50:34.03)
Yeah, but they really wanted to find you. If they didn’t really want to, they probably would have just given up just like some of the victims have, right? So now you mentioned some of those identities were so old that they wanted you to come in in person. What today prevents that happening with a Zoom call with a deep fake?

Brett Johnson (50:41.105)
Bay dead.

Brett Johnson (51:03.384)
Nothing. Nothing.

Manoj Tandon (51:04.29)
with an AI.

So do you see that?

Brett Johnson (51:07.888)
Yeah, so I see a huge problem with deepfakes. we’re getting to the point, we’re not quite there yet, but we’re getting to the point where a deepfake can be done in real time, audio and video. When that happens, when it happens, it’s not if, but when it happens, we stand a real chance of getting to the point as a society where we don’t know.

what’s real and what’s not. And I don’t think that people really appreciate that yet. And I can’t say that we need to, that we can rely on a security company to protect us from them. Because right now it’s cat and mouse. mean, it’s reaction and proaction. It’s the criminal coming out with a deep fake. A security company may or may not be able to recognize it as a deep fake. If they don’t, they tweak their algorithm to find it.

criminal goes back, tweaks his, so it’s not found anymore, bang, bang, bang, bang, bang. across. I really think that, you people talk about AI a lot. Once AI gets good, the late half of 25, once that happens, you know, I think AI is going to get to the point where it’s fast enough that a security company’s no longer able to realistically determine that those things are.

Manoj Tandon (52:19.374)
you

Brett Johnson (52:33.894)
deep fakes in an amount of time that helps us. So what do you do at that

Manoj Tandon (52:38.54)
Yeah, well, I mean, well, it happened, right? We had that big bank in Hong Kong or China where the guy gave away 15 million, right? And he thought he was on a conference call.

Brett Johnson (52:48.303)
Right. Right.

Brett Johnson (52:53.18)
But it wasn’t real time, right? Those responses were delayed responses. What happens when it’s real time? When you’ve got, hey, get on FaceTime with me and the CEO is telling you that you’re a dumbass, that you had better send this money to where I tell you to send it to or I’m going to fire you right now. Well, yeah, you’re going to send that money because that’s the CEO.

It’s not a blurry picture, it’s not a delayed response or anything else. That’s the CEO in real time telling you, do this now.

Manoj Tandon (53:23.362)
Yeah, but that says that we need to put more military-like checks in. What would prevent someone from faking the president of a nuclear power and ordering his generals to launch something nefarious?

Brett Johnson (53:36.38)
Nothing. mean, we had a deep fake of Zelensky when the Ukraine war started out saying that Ukraine had surrendered. Nothing’s to stop that. Nothing’s to stop the CEO of a company saying that they’re not meeting profits and they lost several billion dollars. Nothing is to stop that at all. Nothing’s to stop.

Manoj Tandon (53:54.584)
Well, that would be a good one because you could profit on that short the stock for a couple hours cash out.

Brett Johnson (53:59.908)
Right. And if you understand why attacks happen online, is it status cash ideology? deep fakes are ideological too. you’ve got, know, remember during the pandemic, we had a lot of cities that were burnt down because police officers evidently love to shoot unarmed African-Americans. I don’t know why, but they do. So, but you know, imagine that deep fake where a video is released of law enforcement shooting an unarmed man in the

back. And then all of sudden the city blows up. Three days later it comes out. Well, that was a deep fake. He was actually armed. He was shooting back at law enforcement. It looks like it was just faked where it, you know, it didn’t show that. Well, yeah, the truth is out, but the city’s already burnt down at that point in time.

Manoj Tandon (54:48.398)
on that somber note, well, I was going to say on that somber note, we’re at the hour, but I do want to give you a minute. That went by way too fast, Brett, and we didn’t get much of anything. We just started this conversation, but that’s okay. No, this was fantastic. But you have the floor. What do you want our audience to know about anything upcoming? They want to reach out. Are you going to be making any appearances?

Brett Johnson (54:50.469)
I think that’s our future.

Brett Johnson (55:05.116)
Sorry.

Brett Johnson (55:15.984)
Look, look, look. Yeah, so look, you can Google me, you can find me on LinkedIn, I’ve got some YouTube stuff out. That’s all fine and dandy. What I would like to say is protect yourself. And what I mean by that is understand your place in the cybercrime spectrum. The way that someone like me will attack you absolutely depends on who you are and what you do. If you understand that, if you understand what that attacker wants and why they’re attacking you,

design security around that. Now for individuals that are out there, the three most important things that I can tell you to do, freeze the credit of every single person in the house, including your children because children are the number one victims of identity theft. 25%, one in four will be victims. So freeze the credit. Credit freezes are free. They’ve been free since 2018. Today there’s only 12 % of the population that has a credit freeze in place. Please, if you don’t do anything else today,

freeze the credit of every person in the house. That means contacting all three credit bureaus, notifying them that you want that freeze. A credit freeze stops all new account fraud. We as adults, we have existing accounts, so you have to number two, monitor accounts, place alerts on those existing accounts. So that’s every account. That’s your credit, your retail, your email, financial institutions, everything else. That’s number two. Third,

And here’s the big one, and we all know this, that are in cybersecurity. How many people out there use the same or similar login credentials across multiple websites? And the number is 80%. 80%. So, yeah, good password security. Those three things. Then you can look at multi-factor. You can look at other things from that point on. But those three things should be the foundation of your personal security.

Manoj Tandon (56:47.586)
my God.

Manoj Tandon (56:54.22)
I didn’t know that. 80%.

Brett Johnson (57:07.836)
Okay, that’s what I’d like to say.

Manoj Tandon (57:11.032)
Sage advice from someone who knows. Brett, it’s been a pleasure having you here. Thank you for doing what you just did.

Brett Johnson (57:17.446)
Thank you. Thank you. Yes sir, I appreciate it. Thank you for having me on.

Manoj Tandon (57:21.784)
Thank you. That was great.

Read more about Brett on his LinkedIn

Visit his website

Check out the vCISO bot we created

Check out the other episodes in Season 16:

Ep. 0 Jim Love – Company Data on ChatGPT: Why What You Share Could Stay Forever

Ep. 1 Ken Underhill – Breaking Into Cybersecurity: Job Hunting Tips and Ghost Job Realities

Ep. 2 Allie Hunter – The Dark Side of Online Gaming

Ep. 3 Purandar Das and Ken Foster – “Delete My Data” Doesn’t work

Ep. 4 Tammy Klotz – Communicate properly with your team

Ep. 5 Sandra Estok – My Identity was Stolen

Ep. 6 Brett Johnson – Inside the Mind of a Former Cybercriminal

Ep. 7 Darren Mott – “Hackers Aren’t Breaking In—They’re Logging In”

Ep. 8 Stacey Champagne – “Red Flags in Cybersecurity Coaching”

Ep. 9 Craig Taylor – Phishing, Encryption, and Cybersecurity Training

Ep. 10 Christopher Rees – Will AI Change the Way We Learn

Brett Johnson on Dark Rhiino Security's Security Confidential

Brett Johnson, once known as “The Original Internet Godfather,” was a key figure in the rise of cybercrime, founding ShadowCrew—the blueprint for today’s darknet markets.

Convicted of 39 felonies and placed on the U.S. Most Wanted List, his expertise in identity theft, fraud, and hacking was unmatched—until he turned his life around.

Now a leading cybersecurity consultant and speaker, Brett uses his past to educate companies, law enforcement, and individuals on how to protect themselves from the criminals he once worked alongside.

His journey from cybercriminal to cybersecurity expert has been featured on CNN, NBC, Vice, Wired, and more.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top