Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.
|
My theme this week has been to be more frugal, with both my time and my money. On the money side, I have not had a credit card for over a decade. I just use debit. This week I went a step further and started paying with cash instead of tapping my card, and it has made a real difference. When you have to hand over cash, you cannot spend on autopilot. You slow down and actually think about what you are buying, instead of just tapping for the convenience of it. I am going to keep doing that. On the time side, I have been more picky about what I read and what I give my attention to. That is what gave me the idea to change how this newsletter is put together. So hopefully this helps you too. From now on, I am laying each story out as a few dot-point facts and then a short, conversational take on the story or the insider risk behind it. If a story grabs you, please go and read the article links. I always recommend that. If you are interested, dig in. Do not take my word for it, and do not take anyone else’s. If it is a news article, try to find the original source. The high-level points and a take should be enough for you to decide whether a story is worth more of your time. Headline: The Insider Threat Division’s Own Insider
We have seen this in cybersecurity for years. A new threat emerges and we start to forget the old ones, even though most of what shows up in the security roundups is still just poor hygiene. Insider risk is going the same way. Everyone is focused on AI as the huge new insider risk, with data leaving organizations through models and agents, while the simplest factors still work. Someone loads data onto a USB, or prints it out, and walks out the door. Insider Scoop: Selling Access for $15,000
I am honestly not surprised to see access going for as little as fifteen thousand. We are living through a cost of living crisis, with huge inequality and very little stability. A lot of people do not have a home they own, or even rent they feel safe in. Fifteen thousand dollars goes quickly, but it buys a bit of the security that their job and their career are not giving them. This will not slow down until governments and organizations do a better job of giving people stability. Stability is what builds loyalty, to an employer and to a country. Without it, these offers will keep finding takers. Source: Insider Threat Report: Dark Web Recruitment & Access Trends (Flashpoint) Crime RoundupTrading Ahead of the Numbers - Jesse Mitchell, 48, was a senior finance director at the ad-tech firm The Trade Desk. - Prosecutors say he saw the company’s earnings before they went public and traded on them. - The scheme ran through his role in financial planning and made him about $338,000. - He is charged in New York with two counts of securities fraud. Source: Ex-Trade Desk Finance Director Accused Of Insider Trading (Law360) A CFO’s $1 Million Card Habit - Tina Feuerstein, 53, was the CFO of a Pennsylvania company. - A Chicago jury convicted her of eight counts of wire fraud. - Over five years she put more than $1 million of luxury furniture, designer clothing, and everyday spending on the company card. - She hid it by deleting more than 3,800 charges from the books and faking the financial statements. Source: Former CFO of Chicago-Area Company’s Subsidiary Convicted of Embezzlement (DOJ) Philips X-Ray Secrets to China
This is one of the industries China is targeting to become self sufficient by 2030 and beyond. Most of what they go after is semiconductors, AI, and advanced manufacturing, and those usually carry military links. Healthcare is the interesting one, because it does not. China simply has an aging population it wants to sustain, and that alone is enough to make medical technology a target for trade secret theft. AI Insider Threat Watch: The Flaw Is in the Harness, Not the Model
Once again we are hit by the lethal trifecta. All three conditions are here. The agent and its harness have access to sensitive data, the secret keys. There is exposure to untrusted content, through an unprivileged outsider opening a GitHub issue. And there is a way to communicate out, back through that same issue and the logs, so the keys can be taken. When all three line up in one system, this is what you get. I wrote about this last year in one of my insider threat advisories at DTEX, on organizations building their own AI systems and agents. Since we started talking more about the lethal trifecta, we keep seeing it, again and again. That is the value of the framework. When you look at an AI system or agent from a risk perspective, the trifecta gives you the questions to ask. It shows you how an attacker, or even a normal user, could exploit it, misuse it, or trip it by accident into a data loss event. Source: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets (The Hacker News) Mitigation Corner: Don’t Take Your Eyes Off the Basics
The fix is not to choose one. Watch your AI agents like privileged insiders, and keep watching the old routes too. Removable drives, printing, personal email, and the gap at offboarding are all still wide open. Give the new threat your attention, but do not take it away from the basics that still cause most of the damage. Source: Your Next Insider Threat Won’t Be Human: The Risks Of Agentic AI (Forbes) Trusted Profession Watch: The Fiduciary Who Robbed the Vulnerable
This one is just disgusting. A trusted profession like this exists to help vulnerable people who can no longer manage their own finances. Usually that is an older generation who have lost the ability or the mental capacity, and who are just trying to live out the rest of their years in peace. Instead, someone in that role takes advantage of them. It is the same exploitation you see aimed at any vulnerable community, and it is really sad to see. TriviaNathan Laatsch handed over documents using a “dead drop.” In spy tradecraft, what is a different method known as a “brush pass”? A) Leaving material hidden in a public spot for later pickup B) A quick, discreet handoff between two people passing in a crowd C) Turning a target into a source using blackmail D) Sending coded messages over shortwave radio (Answer at the bottom.) Corporate News: Google’s AI Secrets and a Split Verdict
There is a wider point that goes beyond this case. Even when data leaves an organization by accident, and not as espionage, it can still end up in the same hands. Once information is outside the walls, it is exposed. If a nation state wants it, there is a good chance they will eventually get it. That is the real risk in any data loss event, not only the ones that begin as theft. Source: Former Google engineer convicted of stealing AI trade secrets (Yahoo Finance) What’s OnInsider Risk: When Trust Becomes the Attack, an Everfox FoxForum webinar.
Trivia AnswerB. A brush pass is a brief, choreographed handoff, where two people cross paths and exchange an item without breaking stride, so it looks like nothing happened. Option A describes the dead drop that Laatsch used. |
Every week I go through DOJ press releases, vendor research, and breaking news to find the insider threat and fraud cases worth knowing about. Then I explain why they matter and what they mean for your program. No vendor pitch. Just the cases, the numbers, and the lessons.