Container-2.svg
How to Stop AI-Powered Attacks:

Season 1, Episode 9

How Ransomware Groups Run the Cartel Playbook: Inside the DEA with Aaron Turner

In part one of our two-part series with Aaron Turner, the IANS Faculty member and former Microsoft Senior Security strategist took our co-hosts back to the 1990s to unpack the origin of Active Directory.  

Part two picks up where his time at Microsoft took him next. After 9/11, Aaron was told to stop coming to work and instead go help the government with whatever they needed—which turned into 18 months with the DOJ working with the DEA Special Operations Division under Steve Murphy and Javier Peña, the real-life agents behind what you may know from Netflix’s Narcos.  

What he experienced gave him a framework he still uses today: drug cartels and ransomware groups have surprisingly similar operating models. As Aaron puts it: “Both organizations have to use identities, sometimes stolen, often misused, to start their criminal enterprise.”  

This candid conversation gives you a new way to talk about trust, access, and segmentation—and makes it clear why identity is worth defending like the asset it is.  

Key takeaways include: 

  • How cartels and ransomware groups rely on the same tactics to move past defenses built on trust 
  • What Aaron’s later work at Idaho National Lab building some of the first cyber-physical attack simulators taught him about identity segmentation across IT and OT environments 
  • Why disrupting the “choke point” in the attack chain matters more than chasing every step the threat actor takes along the way 
00:00:00,110 –> 00:00:03,150 Let’s take a look at drug cartels and ransomware groups. 00:00:03,390 –> 00:00:06,910 Both of them are transnational criminal organizations. 00:00:06,990 –> 00:00:13,790 When 9/11 happened and the US government came to Microsoft and said, we need help, I got told, don’t come to work anymore. 00:00:13,950 –> 00:00:15,870 You go work at the government and you do what they say. 00:00:15,950 –> 00:00:20,190 Well, in the 1st place I went to go work was DEA Special Operations Division. 00:00:20,270 –> 00:00:24,590 And DEA SOD was being run by a guy named Steve Murphy. 00:00:24,670 –> 00:00:29,870 And so he and Javier Pena were my bosses as I was essentially a hacker on the loose 00:00:30,070 –> 00:00:33,430 thinking about breaking open encrypted sessions to do interesting things. 00:00:33,550 –> 00:00:37,190 Spent a lot of time basically breaking a lot of the stuff that I had built. 00:00:37,470 –> 00:00:45,950 From a defender perspective, as defenses improve and we learn from things like MFA bombing and we improve our defenses, they pivot their approach. 00:00:46,030 –> 00:00:48,270 And I think similarly you’ve got with the cartels, right? 00:00:48,270 –> 00:00:53,710 The supply of something gets cracked down on, pivot, supply something else, do something different, still achieve your goal. 00:00:53,870 –> 00:00:59,990 Identity isn’t just an operational problem, it’s a security one and most teams are figuring out in real time. 00:01:00,350 –> 00:01:10,430 This is the podcast where we reverse engineer the meaning of identity security, sharing candid conversations about the people building, fixing and rethinking identity security from the inside. 00:01:10,510 –> 00:01:11,270 I’m Roy Akerman. 00:01:11,270 –> 00:01:12,750 And I’m Rob Ainscough. 00:01:12,990 –> 00:01:13,789 Let’s dive in. 00:01:14,030 –> 00:01:14,670 Let’s do it. 00:01:20,520 –> 00:01:24,600 Before I joined Microsoft, I thought I was going to be a lawyer and I actually went to law school. 00:01:25,870 –> 00:01:33,630 I got involved in some kind of shady stuff in law school, and so I ended up dropping out because I knew people were in trouble. 00:01:35,070 –> 00:01:40,509 And the two of the partners that I worked with did federal jail time because they were essentially stealing money from people. 00:01:40,509 –> 00:01:41,950 So I was like, I didn’t want to do this. 00:01:41,950 –> 00:01:44,950 I think it’s going to be more ethical to be a hacker than an attorney. 00:01:45,229 –> 00:01:46,270 So I drop out of law school. 00:01:46,390 –> 00:01:46,750 Okay. 00:01:46,990 –> 00:01:52,150 So, but when I get to Microsoft, they find out that I have this legal background. 00:01:52,910 –> 00:01:53,310 So 00:01:54,990 –> 00:02:00,670 when the US government comes calling to say, hey, can you help us run wiretaps on MSN Messenger? 00:02:00,710 –> 00:02:09,990 Or can you help us, you know, read people’s Hotmail e-mail or anything that Microsoft would come to me and go, hey, Aaron, you know, you dropped out of law school, but you know how a lot of this stuff works. 00:02:09,990 –> 00:02:11,510 So can you help us get the interface? 00:02:11,510 –> 00:02:15,230 So it’s like lawful interception to, yeah, okay. 00:02:15,470 –> 00:02:16,829 lawful intercept, right? 00:02:16,829 –> 00:02:18,910 So that was the beginnings. 00:02:18,910 –> 00:02:23,990 And then also I had helped the FBI cart lab and the US Secret Service forensics lab get started. 00:02:24,030 –> 00:02:26,270 So I was helping them write forensics tools. 00:02:26,670 –> 00:02:30,510 And so I was sort of a good interface between Microsoft and those places. 00:02:31,150 –> 00:02:39,470 when 9-11 happened and the US government came to Microsoft and said, we need help, we need technical assistance to think about how we’re going to deal with this terror networks and everything. 00:02:39,790 –> 00:02:46,030 Basically, I got told in August of 2001, excuse me, September of 2001, 00:02:47,190 –> 00:02:48,430 don’t come to work anymore. 00:02:48,590 –> 00:02:50,590 You go work at the government and you do what they say. 00:02:51,070 –> 00:02:58,230 So I literally was seconded to the US Department of Justice and spent 18 months dealing with all sorts of interesting people. 00:02:58,230 –> 00:03:02,750 And the first place I went to go work was DEA Special Operations Division. 00:03:02,830 –> 00:03:11,270 And DEA SOD was being run by a guy named Steve Murphy, who is now famous because of his role in killing Pablo Escobar. 00:03:11,270 –> 00:03:14,110 And he’s now famous because of the Narcos Netflix series. 00:03:14,550 –> 00:03:17,110 And so he and Javier Pena were my bosses. 00:03:17,870 –> 00:03:27,550 as I was essentially a hacker on the loose for DEA answering questions like, well, if we think that the cartel is buying heroin from the Taliban, how do we get in the middle of that? 00:03:28,670 –> 00:03:34,910 And so thinking about breaking open encrypted sessions to do interesting things. 00:03:35,350 –> 00:03:39,630 And so spent a lot of time basically breaking a lot of the stuff that I had built. 00:03:40,510 –> 00:03:42,950 for my day job, for my previous job. 00:03:42,950 –> 00:03:44,230 And so did that for 18 months. 00:03:44,230 –> 00:03:45,270 And that’s great. 00:03:45,270 –> 00:04:06,670 So like I’m curious to see like what lessons can our followers like learn from A, the way that cartels use technology in order to run their like fluent operations and from the other side, how identity can be manipulated, like compromised, doubled when it comes to the law enforcement side. 00:04:06,830 –> 00:04:09,550 These will, it seems that we’re building like a very interesting 00:04:09,790 –> 00:04:10,710 Interesting episode over here. 00:04:10,710 –> 00:04:11,070 Interesting. 00:04:11,070 –> 00:04:11,390 Yeah. 00:04:12,830 –> 00:04:17,950 So let’s take a look at drug cartels and ransomware groups, right? 00:04:18,269 –> 00:04:22,029 Both of them are transnational criminal organizations, right? 00:04:22,029 –> 00:04:23,390 They operate above the law. 00:04:23,390 –> 00:04:25,870 They operate outside of the boundaries of jurisdictions. 00:04:26,510 –> 00:04:27,870 What are commonalities there? 00:04:28,190 –> 00:04:30,070 They are both super rich, right? 00:04:30,230 –> 00:04:33,870 If you think about who holds a ton of cryptocurrency today, 00:04:34,270 –> 00:04:36,430 the ransomware groups because that’s the way they get paid, right? 00:04:36,590 –> 00:04:39,710 They have direct access to massive amounts of cryptocurrency. 00:04:41,070 –> 00:04:42,830 The drug cartels, massive amounts of cash. 00:04:42,830 –> 00:04:59,390 So essentially, they have the economic resources to operate above the law through corruption of corrupting local law enforcement say, hey, don’t look here, don’t investigate me because in the Narcos Netflix series, there’s a line that Pablo Escobar says where you get to choose Plata or Plomo, right? 00:04:59,950 –> 00:05:04,270 Plata is silver, right, money, or plomo is lead, a bullet. 00:05:04,430 –> 00:05:06,670 So do you want money or a bullet, right? 00:05:06,670 –> 00:05:11,790 So both ransomware operators and drug cartels give local law enforcement that choice. 00:05:12,510 –> 00:05:28,110 And so if you think about the way that identity comes across this from the analog world to the, of cartels to the digital world of ransomware operators, really the way that cartels operate is that they assume human identities to do their smuggling, right? 00:05:28,110 –> 00:05:31,870 They get a badge to go into the airport a certain way. 00:05:32,110 –> 00:05:32,590 They do that. 00:05:32,590 –> 00:05:34,270 Well, how do ransomware operators work? 00:05:34,270 –> 00:05:39,630 Well, they assume a digital identity that gives them the privileges they need to basically deploy their ransomware tools. 00:05:39,870 –> 00:05:42,390 So that’s the beginning of the commonality is 00:05:42,470 –> 00:05:49,230 Both organizations have to use identities, sometimes stolen, oftentimes misused, to start their criminal enterprise. 00:05:49,670 –> 00:06:02,030 Yeah, speaking about ransomware gangs, like in Quillen, for example, like if you’re familiar with other ransomware gangs, like do you see any emerging patterns that are kind of like the same of the ones that you just described? 00:06:02,910 –> 00:06:03,150 Oh yeah. 00:06:03,310 –> 00:06:07,390 If you think about the way that cartels work and ransomware operators work, 00:06:08,670 –> 00:06:11,310 both diversify their economic opportunities. 00:06:11,390 –> 00:06:19,550 So for example, a cartel, they will diversify to go into human smuggling or other aspects of criminal enterprise. 00:06:20,070 –> 00:06:22,030 the same thing holds true for ransom operators. 00:06:22,030 –> 00:06:32,430 Like they won’t just hold you ransom, they’ll exfill your data, they’ll participate in industrial espionage, you know, they’ll participate in extortion as a service and DDoS and that sort of thing. 00:06:32,670 –> 00:06:34,830 And so that’s another aspect that you think about. 00:06:34,830 –> 00:06:40,590 These are both rational actors who are in it for the money and they’re going to opportunistically go after that. 00:06:40,909 –> 00:06:48,909 I think it’s an interesting parallel where you’ve got, you know, when you look at initial account compromise and the methods that are used to do that. 00:06:49,670 –> 00:06:52,630 And often that’s specialized away from the ransomware groups now, right? 00:06:52,630 –> 00:06:56,990 It’s about those initial compromise and initial access brokers. 00:06:57,630 –> 00:07:11,630 You know, from a defender perspective, as defenses improve and we learn from, you know, things like MFA bombing, right, or people getting got via SMS and we improve our defenses, they pivot their approach. 00:07:12,270 –> 00:07:14,510 And I think similarly, you’ve got with the cartels, right? 00:07:14,510 –> 00:07:17,070 Like the supply of something gets cracked down on. 00:07:17,750 –> 00:07:21,070 Pivot, supply something else, do something different, still achieve your goal. 00:07:21,390 –> 00:07:23,590 So I think there’s always this game of cat and mouse, right? 00:07:23,590 –> 00:07:29,470 This game of invention and chasing and the pivots that you see in approach is really interesting. 00:07:29,550 –> 00:07:37,310 Yeah, so like I guess this battle of attrition, like we have the pivoting or like the evasion techniques that we’re seeing. 00:07:37,750 –> 00:07:45,550 Any other interesting evasion techniques that you know are comparable when it comes to cartels, ransomware gangs? 00:07:45,790 –> 00:07:47,870 Let’s draw two more parallels real quick. 00:07:47,870 –> 00:07:53,230 The first one is both have to operate in low governance situations, right? 00:07:53,630 –> 00:07:58,630 They both only are successful where they can be physically and not have to worry about getting put in prison, right? 00:07:58,630 –> 00:08:06,990 So that’s the reason why so many live in Russia or Myanmar or some place where they don’t have to worry about the cops. 00:08:07,430 –> 00:08:09,150 And then also, 00:08:09,710 –> 00:08:13,230 These organizations are smart to where they want a franchise model. 00:08:13,710 –> 00:08:16,830 They want to scale through saying, hey, I built this core set. 00:08:17,150 –> 00:08:20,270 Oh, I can make more money if I build it into a franchise. 00:08:21,190 –> 00:08:22,910 And that’s the way the drug cartels work, right? 00:08:22,910 –> 00:08:26,350 The plazas, the Mexican plazas, the different Colombian cartels. 00:08:26,350 –> 00:08:28,750 And so I think you see those commonalities. 00:08:28,750 –> 00:08:31,550 Now, from an evasion perspective, how does that help them? 00:08:31,550 –> 00:08:37,230 Well, with more franchisees, now there’s a ton more traffic, attack traffic, and you just blend in, right? 00:08:37,470 –> 00:08:46,030 You can have the super noisy, stupid ones causing all the nuclear noise, and the super smart ones are going in with their sniper attack, and they’re hiding in the noise. 00:08:46,390 –> 00:08:46,830 And so 00:08:47,510 –> 00:08:50,950 It’s a very elegant way to increase the noise by their franchise model. 00:08:51,950 –> 00:08:53,310 Oh yeah, I remember that. 00:08:53,590 –> 00:09:14,590 as like former government like that, one, well, as I said, even if there’s not a very big level of sophistication from a specific attacker, he can win by points, meaning they will destruct the, you know, the list of resources that we have by bombarding us with falsely weak attacks that will probably will not succeed. 00:09:14,750 –> 00:09:17,390 We will get the full sense that we are succeeding 00:09:17,790 –> 00:09:22,070 95% of the times, but it takes only one right to be compromised. 00:09:22,070 –> 00:09:30,990 And then exactly like Aaron said, like in a sniper gun, you will just get hit and you’ll still feel fine, but you’ll get compromised. 00:09:31,710 –> 00:09:40,150 This is like- On that point, on that point, so in 2006, I left Microsoft and joined a US government laboratory at the Idaho National Lab. 00:09:40,310 –> 00:09:42,110 And we were tasked- You’ve been in INL? 00:09:43,390 –> 00:09:47,430 I helped found that in 2006, 2008. 00:09:47,470 –> 00:09:49,550 I was in the simulator in 2009. 00:09:50,030 –> 00:09:50,230 Wow. 00:09:50,270 –> 00:09:51,670 So that was what I built. 00:09:51,830 –> 00:09:54,190 And I don’t know what you guys are talking about. 00:09:54,990 –> 00:10:00,470 Yeah, like it’s like, yeah, you know that’s better than me, but DOE and then like found Idaho. 00:10:00,470 –> 00:10:03,950 And I know that they have a lot of simulators like nuclear, like power plant and other things. 00:10:04,510 –> 00:10:13,150 And they actually build simulations in order to help, probably not just defenders, but defenders to practice with detection, response, IR and others. 00:10:13,150 –> 00:10:18,350 So think about SCADA systems, but in the days that nobody spoke about that, pre-Stuxnet or whatever. 00:10:18,670 –> 00:10:27,350 So you would come there and like have a simulation of a power plant or like what was it like a water purifying like factory or whatever. 00:10:27,350 –> 00:10:30,590 Water, we had cell towers, we had nuclear power plants. 00:10:30,830 –> 00:10:33,790 You’re stuck in Idaho, all you have to do is security, right? 00:10:34,390 –> 00:10:36,030 and eating by the Snake River. 00:10:36,510 –> 00:10:39,470 And then you’re playing blue team, red teams, and white teams. 00:10:40,230 –> 00:10:46,030 When the government topping and see what exploits are you using, like gathering 0 days and things like that. 00:10:46,270 –> 00:10:47,030 So sorry, go ahead. 00:10:47,030 –> 00:10:47,870 That was really exciting. 00:10:47,870 –> 00:10:50,030 We probably crossed pathways for sure. 00:10:50,110 –> 00:10:50,270 Yeah. 00:10:50,830 –> 00:10:51,950 So I. 00:10:52,230 –> 00:10:52,710 Double mirrors. 00:10:52,710 –> 00:10:59,750 Oddly enough, in a weird circle of the universe, I was born in Idaho and graduated from high school there in town. 00:11:00,190 –> 00:11:00,430 Right? 00:11:00,670 –> 00:11:03,670 And so they didn’t know I was from there when they offered me to come back. 00:11:03,670 –> 00:11:05,470 And so I played, I was like, oh, I don’t want to go to Idaho. 00:11:05,470 –> 00:11:06,550 You’re going to have potatoes. 00:11:07,550 –> 00:11:09,390 And so I ended up back in Idaho. 00:11:09,390 –> 00:11:21,630 And when I was there, it really was an opportunity for me to go, okay, how can I think about blowing up a lot of the stuff that I had built at Microsoft? 00:11:21,870 –> 00:11:25,150 How do I actually take advantage of a lot of the holes that I knew about? 00:11:25,630 –> 00:11:32,750 And it was this really great opportunity to let ourselves loose and go, okay, here’s the new territory. 00:11:33,070 –> 00:11:38,270 And our goal was to cross the boundary between cyber and OT, right? 00:11:38,270 –> 00:11:41,470 So like, how do you take a cyber exploit and blow up a power plant? 00:11:41,630 –> 00:11:46,350 How do you do physical damage and destruction from a simple, 00:11:47,310 –> 00:11:49,390 zero day, a simple software exploit. 00:11:49,750 –> 00:11:54,830 And I think that taught me a lot about the importance of segmenting identities. 00:11:55,550 –> 00:12:09,710 You want to have really clean cuts between an identity that logs into a nuclear power plant’s water processing system and the pumps that are involved there and what you’re using to read e-mail or do whatever you’re doing in your day job. 00:12:10,190 –> 00:12:17,190 And I think that was an opportunity for me then to take a look and say, okay, how do criminal organizations play into that? 00:12:17,190 –> 00:12:23,390 And what’s been interesting over the last 20 years is to watch how the Chinese and the Russians and others have essentially 00:12:24,030 –> 00:12:27,950 motivated through economic means of people crossing those boundaries, right? 00:12:27,990 –> 00:12:35,470 Of paying people to say, hey, I want you to think about taking out this water system, or I want you to take down the cell network or whatever. 00:12:35,750 –> 00:12:45,390 And so I think that’s something we’ve got to think about is you’ve got now this almost bounty program that’s being paid to get identities that cross those boundaries. 00:12:46,430 –> 00:12:47,510 Yeah, that’s interesting. 00:12:47,510 –> 00:12:59,150 And I mean, again, we’re, I’m going back in my mind, like to the cartels, like by the end of the day, they’re forming a lot of like layers of trust or like, nodes of trust, right? 00:12:59,230 –> 00:13:03,790 I believe that Escobar did not really operate everyone around, right? 00:13:03,790 –> 00:13:10,670 Like he held a very small circle around him, you know, with a very small, like strong form of trust, monitoring, whatever. 00:13:10,990 –> 00:13:15,070 But then there were like the execution layers, the strategic layers, like the partners and everyone. 00:13:15,630 –> 00:13:23,230 And I think that breaking that chain is exactly as we’re pivoting across, as we’re thinking defenders should think, right? 00:13:23,230 –> 00:13:26,270 Or attackers should think about pivoting across levels of trust. 00:13:26,710 –> 00:13:27,430 And how can you keep that? 00:13:27,430 –> 00:13:28,590 And they did this very well. 00:13:28,590 –> 00:13:30,190 I mean, it was very hard to break. 00:13:31,070 –> 00:13:32,430 You’re such a security guy. 00:13:33,150 –> 00:13:33,510 Oh my God. 00:13:33,630 –> 00:13:35,390 Escobar is a set of nodes. 00:13:35,870 –> 00:13:36,470 But what would you? 00:13:36,470 –> 00:13:37,150 It’s a graph. 00:13:37,150 –> 00:13:38,510 It’s a graph for sure. 00:13:39,990 –> 00:13:43,390 And you gave him the identity as like the IAM person, right? 00:13:45,070 –> 00:13:58,430 But if you take that example of, if Escobar was sort of an initial point on the graph, what he did is he built a model by which people could clone that operating environment, right? 00:13:58,670 –> 00:14:07,310 And so, and that’s the reason why the Mexicans really took over, is the Mexicans were much more ruthless, and they knew that the last mile mattered. 00:14:07,630 –> 00:14:13,910 Escobar thought that he could always be sort of separate, and in fact, Escobar wanted to be president of Colombia, like he thought. 00:14:14,030 –> 00:14:21,830 He had these delusions where he was going to be like president of Columbia and he could somehow wash himself of all this crime that he’d been involved in. 00:14:22,030 –> 00:14:24,750 But it was the Mexicans who really took it to the next level. 00:14:24,830 –> 00:14:30,350 Mexicans said, Hey, if we own the last mile and do that work, then that’s what matters. 00:14:30,350 –> 00:14:38,910 And to your previous point about whoever holds the cryptocurrency, they have the most upside in a ransomware event. 00:14:39,310 –> 00:14:40,670 And so if you take a look, 00:14:42,510 –> 00:14:55,430 We now see these massive funnels around ransomware of info stealers, identity brokers, access brokers, but it all ends up the people who make the most money are the ones who do the last mile, who actually control the switch to go, oh, you’re going to pay me. 00:14:55,430 –> 00:14:56,910 I’m going to give your files back. 00:14:57,230 –> 00:14:59,070 They’re the ones who make the most money right now. 00:14:59,110 –> 00:15:05,790 And they are the Mexicans of, so if you were to compare the Colombians versus the Mexicans from the cartel world, 00:15:06,390 –> 00:15:10,070 Those people who own the switches to turn the files back on, they’re the Mexicans. 00:15:10,230 –> 00:15:10,950 They own last file. 00:15:12,750 –> 00:15:12,870 Wow. 00:15:13,310 –> 00:15:14,550 Any additional thoughts about this? 00:15:14,550 –> 00:15:21,790 Well, I was just thinking that I took the, you know, I have a very traditional background for being in identity. 00:15:22,510 –> 00:15:24,590 I did a degree in economics and politics. 00:15:26,030 –> 00:15:32,750 That was where I started and then worked in kind of operations and things like that before I went into identity. 00:15:33,230 –> 00:15:35,550 But economics was always my thing. 00:15:35,950 –> 00:15:48,350 And so much of this is driven by humans being just rational economic beings taking the path of least resistance to the most gain that they can and just… 00:15:48,750 –> 00:15:50,190 completely rational. 00:15:50,390 –> 00:15:57,710 And you can explain, whether it’s cartels or whether it’s cyber criminals, you can kind of explain them all through that one thing. 00:15:58,190 –> 00:16:00,590 It just comes back to those really simple premises. 00:16:01,870 –> 00:16:05,630 And I was thinking it’s no different to how a big company operates, right? 00:16:05,630 –> 00:16:07,790 Over time, roles get more specialized. 00:16:07,790 –> 00:16:09,950 So this is what we see in identity. 00:16:09,950 –> 00:16:15,510 We see, you know, credential brokers going into ransomware specific groups, right? 00:16:15,670 –> 00:16:18,590 All of those different specializations that they’re building up 00:16:18,910 –> 00:16:20,870 It’s just like a company as it grows, right? 00:16:20,870 –> 00:16:22,430 To get more specialized. 00:16:22,830 –> 00:16:23,390 Interesting. 00:16:23,390 –> 00:16:25,950 I think like, so we’re different people for sure. 00:16:26,390 –> 00:16:37,630 So like for me, if something is like too much of a good, like have too much of a good of economics behind it, if something goes pretty smooth and well, I feel that I live in simulation, right? 00:16:37,870 –> 00:16:39,910 Like it’s like something really bad is happening. 00:16:39,910 –> 00:16:41,790 And like, you know, I came to a restaurant. 00:16:41,790 –> 00:16:43,870 I’m not the person who eats on the dish. 00:16:45,950 –> 00:16:53,630 But I think that by the end of the day, you’re probably right, identity and economics are like speaks together. 00:16:53,790 –> 00:16:58,910 But I think there is a very good way to look at culturally about your two perceptions, right? 00:17:00,190 –> 00:17:08,589 So having lived and worked in Latin America, right, in some very tough places, you have a different view of the world, right? 00:17:08,589 –> 00:17:12,150 So you having grown up in Israel, right, you have a different view of the world. 00:17:12,349 –> 00:17:14,470 If things are going smoothly, something’s wrong. 00:17:14,990 –> 00:17:15,310 right? 00:17:15,550 –> 00:17:18,710 But that’s your perception is because you grew up in that environment. 00:17:18,869 –> 00:17:23,950 When I lived in Mexico, if things were going smoothly, I was looking over my shoulder like, who’s messing with me? 00:17:24,109 –> 00:17:25,390 Like, who is messing with me? 00:17:25,670 –> 00:17:26,030 Exactly. 00:17:26,030 –> 00:17:43,310 And whereas folks who grew up and did not have that experience in a hostile environment, this is one of the reasons why fishing is so successful is because most Americans, Canadians, Brits, Western Europeans have never had to live in a bad place. 00:17:43,950 –> 00:17:48,430 They’ve been in a nice, soft, cozy, everything’s okay, the police are going to protect me. 00:17:48,670 –> 00:17:50,110 Why would someone ever lie to me? 00:17:50,390 –> 00:18:00,830 And that’s why phishing works, is because people are, most people in high economic value countries have never had to worry about looking over their shoulder. 00:18:01,310 –> 00:18:09,070 Another good topic about the cultural aspects of different mindsets of identity or identity management or 00:18:10,030 –> 00:18:10,990 reality perception. 00:18:10,990 –> 00:18:14,350 But let’s leave it for like the, for another episode. 00:18:14,750 –> 00:18:29,430 So I’m actually surprised about like the lessons that we can learn from, not just like from the cartels, but from the way that they’re being taken down, taken down like the weak spots over there and the lessons that could be learned from for like identity protection in general. 00:18:29,430 –> 00:18:30,110 That’s interesting. 00:18:30,510 –> 00:18:37,470 I mean, probably top of the list of things I didn’t think I’d be talking about today was cartels. 00:18:38,110 –> 00:18:43,830 economics and the link to identity theft and ransomware groups and things like that. 00:18:43,830 –> 00:18:45,350 But it’s been super interesting. 00:18:45,350 –> 00:18:48,550 Yeah, so now you have something to watch on your way back to London, right? 00:18:48,550 –> 00:18:52,430 Like I’ve downloaded a lot on Netflix already. 00:18:52,430 –> 00:18:53,470 I’m full, I’m full. 00:18:54,790 –> 00:18:55,710 Thanks so much, Aaron. 00:18:55,950 –> 00:18:56,750 Yeah, same here. 00:18:57,070 –> 00:18:59,470 That’s it for this episode of Identity Decoded. 00:18:59,710 –> 00:19:05,830 If this conversation changed anything that you thought about identity security, share it with someone who’s working through the same challenges. 00:19:05,830 –> 00:19:09,550 And don’t forget to follow the show so you don’t miss what’s next.

Identity Decoded

with Roy Akerman & Rob Ainscough

Subscribe so you never miss a new episode.