/
© 2026 RiffOn. All rights reserved.

Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

  1. Complex Systems with Patrick McKenzie (patio11)
  2. LLMs and the economics of Evil, Inc., with Manish Goregaokar
LLMs and the economics of Evil, Inc., with Manish Goregaokar

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11) · Aug 13, 2026

LLMs are supercharging fraud. Experts discuss how 'Evil, Inc.' uses AI for sophisticated, personalized scams and how you can defend yourself.

LLMs Make Sophisticated, Personalized Fraud Economically Viable at Scale

LLMs automate the labor-intensive parts of complex scams, like creating fake websites, conducting personalized communication, and monitoring victims. This dramatically reduces the cost, enabling attackers to target a much broader audience with highly tailored cons previously reserved for high-value targets.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

Treat Large-Scale Scams as Rational Businesses to Predict Their Next Moves

Sophisticated fraud operations function like rational businesses with supply chains, training, and P&Ls. They target areas with the highest potential return on investment, such as crypto, and will pivot to new opportunities as technology like LLMs lowers their operating costs.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

Single Sign-On (SSO) Solved Password Reuse But Created a High-Value Single Point of Failure

While Single Sign-On (SSO) solved the problem of users reusing passwords, it created a new "one ring to rule them all" vulnerability. Compromising a single identity provider account, like a Google or Apple login, can grant an attacker access to an entire ecosystem of connected high-value services.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

LLMs Enable Scammers to Shift from Quick Attacks to Long-Term Victim Surveillance

LLMs make it cheap for attackers to monitor a compromised account (e.g., email) for months. Instead of quickly selling credentials, they can now act as "persistent threats" against individuals, building a detailed profile and striking at the moment of maximum financial opportunity, like a house sale.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

Poor UX in Legitimate Financial Apps Makes Users Vulnerable to Scams

Users are conditioned to clunky experiences from legitimate financial and government websites. This creates a dangerous paradox where a broken or janky phishing site doesn't seem suspicious; it feels authentic, lowering the user's guard because it mimics the poor quality of real services.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

State-Sanctioned "Patriotic Hackers" Operate Scams with Impunity Against Foreign Targets

Many professional scamming operations, especially in post-Soviet states, are state-adjacent. These "patriotic hackers," often former intelligence agents, are given freedom to operate against foreign targets as long as they avoid domestic ones, acting as a reserve force for state cyber warfare.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

A Reliable Defense: Only Trust Communication You Initiate to a Known Endpoint

Attackers can easily spoof incoming communication like email addresses and caller IDs. The only reliable security practice is to never trust inbound requests for sensitive action. Instead, always initiate your own communication to a verified endpoint, like the phone number printed on your bank card.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

Scammers Re-Victimize Targets by Recruiting Them into a Criminal Enterprise

In an insidious tactic, scammers re-contact previous victims pretending to be investigators. They then offer a "work from home opportunity" which is actually a role as a money mule, tricking the victim into using their personal bank accounts to launder stolen funds.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago

Financial Institutions Train Users to Ignore Security by Using Third-Party Domains

When legitimate institutions use unbranded, third-party URLs for processes like mortgage applications, they erode a critical security habit: checking the domain name. This trains users to trust unfamiliar URLs, making it easier for scammers to create convincing phishing sites for financial transactions.

LLMs and the economics of Evil, Inc., with Manish Goregaokar thumbnail

LLMs and the economics of Evil, Inc., with Manish Goregaokar

Complex Systems with Patrick McKenzie (patio11)·4 hours ago