From Dead Drops to Data Breaches: A Former FBI Counterintelligence Officer’s Warning
For decades, espionage looked like something out of a spy novel: secret meetings, dead drops, foreign officers posing as diplomats, and painstaking months-long efforts to recruit an insider. Today, that entire playbook has been compressed into something that takes about ten minutes and requires no travel outside Moscow, Beijing, or Tehran. All it takes is a well-crafted email.
That’s the central insight from a recent episode of The Human Code, featuring a former FBI counterintelligence and counterterrorism operative who spent years catching spies before pivoting to fight cybercriminals. His journey from psychology student to FBI agent to cybersecurity entrepreneur offers a fascinating lens on how the science of catching people who want to deceive you hasn’t changed — but the tools have evolved dramatically.
The Old Way: Human Relationships as the Attack Vector
Traditional espionage relied on patience. A foreign intelligence officer might spend weeks or months cultivating a friendship with a government employee, eventually asking for a small, seemingly harmless favor. That favor was often the opening move in a long game of recruitment and compromise.
The New Way: The Virtual Trusted Insider
Now, that same outcome can be achieved almost instantly through a spear-phishing email that impersonates someone the target trusts. This creates what’s described as a “virtual trusted insider” — an employee who remains loyal and unaware, while their hijacked account is quietly used to cause damage. The unsettling truth highlighted in the conversation is that the difference between a cyber spy and a cyber criminal today comes down to one thing: intent at the finish line. Spies want to steal data quietly and erase their tracks so no one ever knows they were there. Criminals want to get paid, so they destroy everything, encrypt it, or threaten to leak it.
Ransomware Has Evolved Into Something Closer to Extortion
One of the most striking points in the discussion is how ransomware tactics have shifted. Because most organizations now have solid backups and cloud infrastructure, simply encrypting data isn’t as effective a threat as it used to be. Instead, attackers are focused on stealing data through compromised privileged accounts and then threatening exposure — publishing sensitive files, alerting customers to a breach, or even mining a company’s own cyber insurance policy to determine exactly how much ransom to demand. It’s a chillingly business-like operation, complete with “customer service” reassurances that stolen data won’t be leaked if the ransom is paid.
Why Cybercrime Is Now the Third-Largest Economy on Earth
The scale of this problem is staggering. Global cybercrime is estimated to generate more than $12 trillion a year, a figure that would rank it as the third-largest economy in the world, trailing only the United States and China. Much of this activity happens in countries with no extradition agreements with the US, where sophisticated cybercrime syndicates operate with tacit approval from intelligence services — as long as their targets remain in the West. Many of these criminal groups even employ intelligence officers moonlighting for extra, tax-free income. It’s an ecosystem where crime pays extraordinarily well and carries far less risk than traditional violent crime.
AI Is a Double-Edged Sword
Artificial intelligence has become a tool for both attackers and defenders. On the offensive side, AI helps criminals with reconnaissance, crafting highly convincing phishing attempts, scanning for network vulnerabilities, and identifying which employees are most likely to fall for a scheme. On the defensive side, organizations can use AI to detect anomalous behavior, such as unusual login times or unexpected data downloads, and flag it for human review before serious damage occurs.
The episode also explores the risks of deploying AI tools like Microsoft Copilot without first understanding data access controls. One real-world example discussed involves a company that turned on an AI assistant company-wide without first segmenting sensitive information. An employee used the tool to search for documents mentioning his name and inadvertently discovered a confidential layoff plan, triggering a wrongful termination lawsuit that could have been avoided entirely with proper data segmentation.
Real-World Fraud Case Studies
Two case studies bring these risks to life. In one, a city government lost over half a million dollars after criminals infiltrated an email thread between the city and a contractor, intercepted a payment request, and redirected funds to a fraudulent account using a nearly identical domain name. In another, far larger case, a finance manager in Hong Kong was tricked into wiring $25 million after joining what appeared to be a legitimate video call with his company’s CFO and colleagues, all of whom were later revealed to be fabricated.
Practical Defenses Every Organization Should Adopt
Despite the alarming scale of the threat, the conversation strikes a hopeful note: none of this is unbeatable. Several concrete steps come up repeatedly:
Segmenting and compartmentalizing data so that not every employee has access to everything is one of the most effective first steps any organization can take. Eliminating ghost accounts — logins left active after an employee departs — closes a common and often overlooked vulnerability. Moving away from passwords entirely in favor of two-factor or multi-factor authentication removes one of the weakest links in most security systems. Verifying any change in payment instructions through a phone call, never relying solely on email, can prevent costly wire fraud. Restricting AI tool access to sensitive repositories until proper data governance is in place is also critical.
The PAID Method: A Four-Step Framework for Staying Safe
Perhaps the most actionable takeaway from the episode is a simple, memorable framework distilled from years of FBI counterintelligence training: PAID.
Prepare ahead of an attack rather than waiting for a crisis. Assess continuously, treating your security posture like an active radar system rather than a one-time checklist. Investigate any red flags, whether that means a suspicious email, an urgent unexplained request, or pressure to act quickly without time to verify. Decide to act, because freezing or waiting for someone else to handle a threat is often the costliest mistake of all.
This cycle, repeated consistently, applies just as well to personal safety as it does to enterprise cybersecurity.
The Bottom Line
The conversation ultimately circles back to a simple but powerful truth: people, not systems, remain the weakest link in cybersecurity. Cybercriminals have effectively become spies, using the same psychological manipulation tactics that intelligence agencies have relied on for decades, just accelerated by technology and AI. The good news is that awareness, preparation, and a handful of practical safeguards can dramatically reduce an organization’s exposure to these evolving threats.