Threats Without Borders - Issue 299
Cyberish-Fraud Investigation Newsletter, week ending August 9, 2026
I recently spoke with the finance manager of a small business, and she hesitated when I asked, “How would you determine if a $25,000 check drawn on your account was fraudulent?” That’s a significant amount for any small business, for any business really, and someone should know right away if that amount is usual or suspicious without needing to check QuickBooks.
A slogan within the computer and network security world is the phrase “Know Normal”. You must know what your computer system looks like in a normal state so you can quickly recognize when something is abnormal. This concept has been popularized by the computer security training organization SANS Institute and is taught in several of their courses. The concept is not hard to grasp and is based on simple common sense. How can you know if an attacker is making changes in your computer network if you don’t know what your computer network should look like? Is that an authorized user? Is that file part of the system, and why is it here? Is that a normal application running inside of Windows? Do we as a business use this software? If you don’t know what should be going on within your network, you will never know when something bad is going on within your network.
This concept is nothing new within the science of policing and has been passed down from one generation of patrol officers to the next. It’s an early lesson taught during the field training program. Maybe not in such a formalized way as SANS instructs it, but a lesson that quickly becomes reinforced by real-world application. I suspect that someone within the SANS organization adapted it, rightly so, to fit the computer network security field.
Police patrol officers are given areas of concern, and whether called a beat, zone, or sector, it’s a geographic area of primary responsibility. An officer will spend a lot of time in that area. Usually eight and sometimes 12 hours per day. That is a lot of time to watch the regular happenings of a small piece of the world. Officers get to know how the area works as a functioning micro community set aside from the larger society as a whole. When the UPS driver comes every day. What time do the businesses open and close? What businesses get early or late deliveries? Who are the vagrants, beggars, and bums, and where do they like to be during the day and sleep at night?
It gets even more granular in the residential neighborhoods. Drive through any neighborhood with a good cop and they can tell you who lives where, who is having marital problems, who stays up late, and who leaves early for work. They know what cars people drive and likewise when a strange vehicle is parked on a given street.
Good patrol officers know what their beat looks like under normal conditions and quickly recognize when something is out of time and place. A vehicle is parked behind a business when it shouldn’t be. A person walking down an alley who is not from the area. When a light is on inside a business that normally is dark at 1 am.
This can easily be adapted to fraud prevention at any organization. The person in control of the finances should know how much gets spent each month. What vendors are being used and how they are paid? Abnormalities and excesses should quickly be spotted. Someone should be asking, “We usually send large cash transfers through ACH wire, why did we just send a Western Union?” Someone should be reviewing employees’ purchases to know who buys what. Sam only charged $350 to his corporate credit last year, what did he just purchase for $3000?
And that $25,000 check was for the new HVAC system we installed and was approved by two people.
As fraud prevention and cybersecurity practitioners, we should all be working within this framework.
And for law enforcement - take the time to educate small businesses and nonprofit organizations as you interact with them daily. Hopefully, pre-victimization so you don’t have to meet them post-victimization.
Know normal - so you know abnormal.
The News
Money laundering is worldwide. This article explains how Balkan countries has become the money laundering center of Europe. https://tol.org/client/article/the-balkan-laundromat.html
All of the Flock cameras in this town were cut down and stolen. I guess we need cameras to watch the cameras. https://www.valleynewslive.com/2026/08/04/every-flock-camera-winona-minnesota-cut-down-stolen-coordinated-theft/
This post claims to be an “18-minute read,” and while you won’t need that much time, it does take a bit longer to digest than a standard skim. Arctic Wolf Labs is tracking a widespread, ongoing phishing campaign they have dubbed “Payroll Pirates.” The attack begins with voicemail-themed emails that lure victims to phishing pages, which proxy legitimate Microsoft 365 authentication flows to bypass multi-factor authentication (MFA). Unlike traditional business email compromise attacks, the campaign avoids overt account modifications and focuses on stealthy mailbox access and reconnaissance to “live in” the mailbox. https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
Ever get frustrated when a company's sign-up page looks suspicious, making you doubt if it's legitimate or a scam? Yeah, Eric Lawrence feels the same way and points out a recent gaff by Cloudflare to show how companies often neglect security in their user interfaces. https://textslashplain.com/2026/08/04/security-is-hard-yall/
Google ends the “send-as” function for third-party accounts using Gmail. https://support.google.com/mail/answer/17101213?hl=en
The Cisco Talos group demonstrates how cybercriminals are leveraging generative AI to bypass model safety guardrails and develop sophisticated attacks. The hackers are using simple jailbreak techniques, such as feigning participation in ethical hacking competitions or creating new sessions mid-task, to bypass restrictions on closed AI models, enabling them to discover vulnerabilities and automate exploits like credential-harvesting platforms. https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/
Romance scammer gets 85 months in prison. I’d prefer 85 years, but a financial scammer being sentenced to any prison time at all is progressive for our criminal justice system. https://www.justice.gov/usao-sdny/pr/ghanaian-national-sentenced-85-months-prison-stealing-more-10-million-romance-scams
Feedback
“Matt, I see you’re speaking at the IAFCI conference. Hopefully, you don’t meet conference speaker guy!” - Jackie
Ha. I’m sure I will. That guy seems to follow me everywhere.
Send Feedback to matt(at)threatswithoutborders.com
dfir
The Arkansas state crime lab reduced their digital forensics turnaround time from 479 days to 70 days. And now hope to reduce that to 30 days. Awesome! https://www.thv11.com/article/news/local/arkansas-state-crime-lab-cuts-wait-times-boosts-digital-forensics/91-7650ed47-1d10-4c04-a132-20cda5c465f9
No ads, no sponsors, no subscriptions. Some nonsense.
Cool Jobs
IT Security Analyst, Baltimore Orioles Baseball. https://www.teamworkonline.com/baseball-jobs/orioles-jobs/baltimore-orioles-jobs/it-security-analyst-2169873
Security Investigator, BMW Group. https://www.bmwgroup.jobs/us/en/jobfinder/job-description-copy.194425.html
Cool Tools
Browser extension to copy text from any image, screenshot, or graphic. https://www.devexthub.com/extract-text-from-image/
Irrelevant
This guy built a better trebuchet, and it just sent a projectile through the supersonic barrier. Now let’s go plaid! https://www.techeblog.com/tom-stanton-supersonic-trebuchet/
Sign Off
I heard the term “Kalshification” this week, which refers to our society’s tendency to bet on anything and everything. Sports, politics, eSports, the Fed, gas prices, what Trump will say… I even saw one market that let you bet on the high temperature for a given city.
A quick search showed just how large the prediction market is. 24 billion per month??!! Crazy.
See you all next Tuesday.
Matt
Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.
Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn’t represent the official viewpoint of my employer or any associated organization. Blame me, not them.
cybersecurity cybercrime aml financial crime fraud investigation cyficrime osint



