Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

Many professional scamming operations, especially in post-Soviet states, are state-adjacent. These "patriotic hackers," often former intelligence agents, are given freedom to operate against foreign targets as long as they avoid domestic ones, acting as a reserve force for state cyber warfare.

Related Insights

AI has transformed scamming into a highly efficient business. Research shows cybercriminal organizations deploying AI generate 9x the volume and 4x the revenue of their peers. Leveraging generative AI for hyper-personalization, they operate like sophisticated, profitable businesses, effectively weaponizing technology for fraud.

Cloudflare's CEO observes that powerful nations like Russia avoid direct cyberwar with the US due to a "mutually assured destruction" vulnerability. Instead, they use other global conflicts, such as Israel-Hamas, as cover to launch attacks while disguising their origin, making attribution difficult.

A sophisticated threat involves state-sponsored actors from the DPRK using AI interview tools and virtual backgrounds to pass hiring processes. They get hired, receive company laptops, and then operate as insider threats, creating a significant and often undetected security risk for organizations.

In a major cyberattack, Chinese state-sponsored hackers bypassed Anthropic's safety measures on its Claude AI by using a clever deception. They prompted the AI as if they were cyber defenders conducting legitimate penetration tests, tricking the model into helping them execute a real espionage campaign.

The problem of fake job applicants has escalated from an HR nuisance to a national security issue. State actors, like North Korea, are weaponizing AI to submit thousands of applications for remote IT jobs to infiltrate corporate systems, forcing companies to treat recruitment screening as a security function.

Sophisticated fraud operations function like rational businesses with supply chains, training, and P&Ls. They target areas with the highest potential return on investment, such as crypto, and will pivot to new opportunities as technology like LLMs lowers their operating costs.

Beyond typical IP theft, North Korea runs a program where state-backed operators secure remote tech jobs in Western companies. Their goal is not just espionage but also earning salaries to directly fund the regime, representing a unique and insidious state-sponsored threat.

CrowdStrike has found hundreds of North Korean state actors getting hired as remote developers at US companies to gain insider access and steal trade secrets. They are so effective that one manager asked if they had to fire the operative because "he did such good work," highlighting a severe remote work vulnerability.

The motivation for cyberattacks has shifted from individuals seeking recognition (“trophy kills”) to organized groups pursuing financial gain through ransomware and extortion. This professionalization makes the threat landscape more sophisticated and persistent.

Large-scale fraud is not run by individual hackers but by organized 'factories' that resemble corporations. These entities have specialized departments, division of labor, performance KPIs, and even employee services like cafeterias and clinics, operating with high efficiency.

State-Sanctioned "Patriotic Hackers" Operate Scams with Impunity Against Foreign Targets | RiffOn