Threats Without Borders - Issue 298
Cyberish Fraud Investigation Newsletter, week ending August 2, 2026
I was recently asked about my favorite podcasts. There are many excellent options out there, so don’t read too much into whether I included or omitted any. These are simply the podcasts I find insightful and entertaining enough to listen to more than once, depending on the topic of the week or guest. Some of them I tune into for every episode.
In no particular order:
RiskyBiz (Risky Business Podcast & Between Two Nerds) – One of the best cybersecurity podcasts for security professionals, covering weekly security news, major vulnerabilities, and industry trends with really good analysis. Between Two Nerds complements it with more in-depth discussions on cyber strategy, intelligence, and the geopolitical implications of cybersecurity. https: //risky.biz/podcasts/
Talking Bout News from Black Hills Infosec. I try to consume this every week, but sometimes there will be so many guests on at the same time it gets chaotic, so I’ll just screen through and only watch when John Strand talks. https: //www.youtube.com/playlist?list=PLqz80p7f6dFugKrYpMhl7bRPqX3kk-Hiv
Click Here – The Click Here podcast explores how cyberattacks, surveillance, online influence, and emerging technology affect everyday people. They tend to avoid being too technical and focus on human stories about the real-world impact of technology. https://therecord.media/podcast
Darknet Diaries – A storytelling podcast featuring true stories of hackers, cybercriminals, penetration testers, intelligence agencies, and digital investigations. The episodes build like a documentary, and make complex cybersecurity topics engaging and accessible for the rest of us.
Fraud Forward – Hailey Windham and her guests focus on fraud prevention, financial crime, and identity theft with an emphasis on banking. She lands some great guests, and the conversation is always insightful. https: //podcasts.apple.com/us/podcast/fraud-forward/id1744207174
The Perfect Scam (AARP) – The show uses real-life scam stories told by victims, investigators, and law enforcement, to break down how criminals manipulate trust and exploit human psychology. https: //podcasts.apple.com/us/podcast/the-perfect-scam/id1362050907
Ahead of the Threat – FBI Cyber Podcast – Produced by the FBI, this podcast features cyber agents and subject matter experts discussing current cyber threats, major investigations, and practical advice for individuals and organizations. Meh. But it offers an insightful look at how the FBI approaches cybercrime and national cybersecurity. https: //www.youtube.com/playlist?list=PL_kAiN4FbpOuxZVKbnfjCD1Qs194aBvd0
Mac Power Users – One of the few podcasts I absolutley make time for every week. MPU will help you get the most from your Macs, iPhones, iPads, and the Apple ecosystem. It covers productivity workflows, automation, apps, hardware, and tips for both casual and power users. https://relay.fm/mpu
Accidental Tech Podcast – Can you tell I’m an Apple fanboy? The ATP hosts discuss Apple hardware, software, programming, and technology news with a mix of technical analysis and a good dose of humor. https://atp.fm/
What do you listen to? Send me a suggestion or post a comment below.
Can’t truss it
I have been working on an educational piece explaining why screenshots can’t be used as evidence. This demonstration and blog article by Henk Van Ess of Digital Digging might do the job even better.
He demonstrates how AI can be used to manipulate Google Earth to show landmarks and map features that aren’t actually present. Alter the map, take a screenshot, and now there is “proof” of a nuclear reactor operating in downtown Detroit.
Van Ess fact-checked claims made by Google when they introduced the new AI feature added to Google Earth:
Two claims in there are checkable, so I checked both. Refugees at a border, a nuclear plant in Iran, a fatal crash on an Amsterdam street, a hospital with a bomb crater in Gaza. Nothing was refused, nothing was softened, and nothing suggested I try a different prompt.
Google responded and pulled the feature within 24 hours of this blog post going live, but the result is the same. This technology exists and can be added to mapping tools to manipulate reality.
The News
Minnesota bans crypto kiosks after it determines over 1 millions dollars has been stolen from victims. And they are only basing that on 134 complaints so the actual number is probably tenfold. https://www.kimt.com/news/minnesota-bans-crypto-kiosks-after-1m-stolen-from-residents/article_2737b382-bfb3-4982-abef-87d0d2e8a521.html
This report by DarkAtlas probably won’t help you understand the device-code phishing workflow, but it’s a damn nice report giving one hell of an effort. https://darkatlas.io/blog/the-code-is-real-the-device-is-not-the-definitive-guide-to-device-code-phishing
And speaking of device-code phishing, this write-up by Abnormal details the ARToken phishing-as-a-service platform that exploits Microsoft OAuth 2.0 to steal access and refresh tokens without requiring fake login pages. It bypasses phishing detection controls and remains effective even with MFA enabled. Small organizations without dedicated security teams and regular awareness training are so cooked. https://abnormal.ai/blog/artoken-the-device-code-phishing-platform-built-for-full-microsoft-365-takeover
And speaking of email phishing, it remained the top initial point of access in Q2 according to the most recent Cisco Talos Incident Response Trends report.
https://blog.talosintelligence.com/ir-trends-q2-2026/
Regarding phishing, IBM published its 2026 Cost of a Database Breach Report. It shows that the worldwide average breach cost has now reached $4.99 million. For those in financial security, the breach cost has increased to $6.29 million. Specifically, the average cost of a breach due to an email phishing attack is $5.29 million.
The CEO of MoneyFlip was arrested in Miami and faces federal charges for converting $750,000 in suspected drug proceeds into crypto for undercover agents and paying $40,000 in cash and USDT to have a Mexican businessman kidnapped and killed over an unpaid debt. https://www.justice.gov/usao-sdca/pr/ceo-cross-border-currency-exchange-business-arrested-murder-hire-plot
This woman was sentenced to 76 months in federal prison after pleading guilty to embezzling over $1.1 million from four different employers. Wait, what? Yeah, FOUR. Her crimes spanned multiple victims, including an engineering firm where she stole over $51,000 on credit cards, $188,000 in false reimbursements, and $426,000 via overpayments, as well as a later employer where she forged checks for nearly $500,000. https://triblive.com/local/clairton-woman-sent-to-prison-for-embezzling-1-1m-from-former-employers/
Coinbase warns that scammers are targeting cryptocurrency holders with a sophisticated physical mail scam involving fake letters that appear to come from the IRS, urging recipients to “enroll” in a non-existent “Digital Asset Compliance Portal (DACP)” by scanning a QR code. The scammers use unmarked envelopes and official-looking formatting to direct victims to a convincing fake website designed to harvest data on their crypto exchanges, wallet types, and estimated holdings. https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam
Feedback
“Matt, I also shared some time in the back of a UPS 53-footer. Sometimes when i get stressed by my caseload, I think at least I’m not in the front of a box “building a wall”. - JK
“I just went through a video interview and the author of that X post summarized my feelings perfectly. I’ll eat cat hair and then floss it out with human hair from the shopping cart wheel before I’ll go through that again.” - SamB
For Reference:
Send Feedback to matt(at)threatswithoutborders.com
dfir
This could also be a cool tool section… Kevin Pagano has updated his Forensic StartMe page. https://www.stark4n6.com/2026/08/forensics-startme-updates-august-2026.html
Cool Jobs
Senior Manager of Cybersecurity Operations, NFL. https://job-boards.greenhouse.io/nflcareers/jobs/5374548008?gh_src=384ee6888us
Senior Investigative Partner, QVC. https://qvc.wd5.myworkdayjobs.com/QRG/job/Pennsylvania-Remote/Senior-Investigations-Partner_R82560
Cool Tools
PhotoRec is free, open-source file recovery software that can recover lost files from various storage devices, even if the file system is damaged. It uses read-only access to prevent overwriting lost data. https://www.cgsecurity.org/wiki/PhotoRec
Irrelevant
Mercedes CEO admits they “forgot about the customer” when they removed buttons. https://www.thedrive.com/news/mercedes-forgot-a-little-bit-about-the-customer-when-it-got-rid-of-buttons-ceo
Sign Off
We hired another Matt at my organization. That makes eight. Good for him; he seems like a great guy, but it’s a little more difficult for cybersecurity. The auto-complete function on the To: line in MS Outlook is an information security killer. You meant to send that spreadsheet to Matt Jones in finance, but Matt Dotts was the last Matt you emailed, so when you start typing M…A… into the address bar, a “Matt” pops up and you hit enter, never bothering to check which Matt you’re actually emailing. And suddenly I get a spreadsheet of corporate data I should never see.
We focus on all of these software vulnerabilities, and that one lives in every organization every day for years.
Have a great week and I’ll see you all next Tuesday.
Matt
Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.
Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn’t represent the official viewpoint of my employer or any associated organization. Blame me, not them.
cybercrime cybersecurity financial crime investigation osint aml cyfycrime



