Episode 105: Leak And You Shall Find

You turned on MFA, you finished your security awareness training, and you think you’re covered. You’re probably not…

Five years after his first visit, Donovan Stevens from SpyCloud is back to show us how much of our digital lives is already sitting in the criminal underground, and how little it takes to piece it all back together. Starting from nothing but a name, he can work his way to phone numbers, old email accounts, home addresses and family members. Our “secure” logins are handing attackers the keys after we’ve already passed MFA. And somewhere, a new hire at a household-name tech company isn’t who their resume says they are. They may not even be in the country.

We get into the phishing kits that make MFA irrelevant, the bots watching your inbox for the word “invoice,” and one of the strangest insider threat stories we’ve ever heard on the show. Nic also asks the question everyone should be asking: who gets to use data like this, and how do we know it’s the good guys? Stick around to the end, because there’s good news too.

Donovan Donovan is a Principal Solutions Engineer at SpyCloud. He spends his days in the criminal underground’s data: breaches, phishing kits, infostealer logs and thousands of invite-only Telegram channels. You can connect with Donovan on LinkedIn.

Prefer video? check us out on YouTube: