
Advertise on podcast: Hacking Humans
Rating
4.6from
This podcast has
765 episodes
Language
EnglishPublisher
N2K NetworksExplicit
No
Date created
2018/05/30
Latest episode
2026/04/23
Average duration
32 min.
Release period
4 days
Description
Deception, influence, and social engineering in the world of cyber crime.
Unlock Hacking Humans podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Social media
Check Hacking Humans social media presence
Podcast episodes
Check latest episodes from Hacking Humans podcast
SLAM, scam, thank you ma’am.
2026/04/23
This week, while Maria is on vacation, Dave Bittner and Joe Carrigan are joined by Michele Kellerman as they discuss the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Dave brings us a lively follow-up from his recent theater outing the conversation circles back to chicken talk. Michele also highlights the work of Blood Cancer United sharing insight into their mission and impact. Dave’s story is on the SLAM method, a simple phishing-defense framework that teaches users to evaluate suspicious emails by checking the sender, links, attachments, and message for common signs of deception and social engineering. Michele’s got the story on a potential turning point in online scams, where rising pressure—from revelations that Meta Platforms has profited from fraudulent ads, to banks and regulators like Jerome Powell and Scott Bessent warning about systemic risks—suggests liability may soon expand beyond banks to include social media, telecoms, and other upstream players. Joe’s story is on two cousins, Shray Goel and Shaunik Raheja, who pleaded guilty in a nationwide $8.5 million scheme using fake listings, double bookings, and last-minute cancellations across platforms like Airbnb and Vrbo to maximize profits while deceiving thousands of travelers. On our catch of the day, A Reddit user shares a message they got from a scammer posing as their child.
Resources and links to stories:
SLAM Method for a Comprehensive Phishing Prevention Guide
Meta tolerates rampant ad fraud from China to safeguard billions in revenue
Banks cannot save the UK financial system from fraud alone
Bessent, Powell warned bank CEOs about Anthropic model risks, sources say
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Ransomware (noun) [Word Notes]
2026/04/21
Malware that disables a system in exchange for a ransom, usually by encrypting the system's data until the user pays for the decryption key.
CyberWire Glossary link: https://thecyberwire.com/glossary/ransomware
Audio reference link: https://watch.amazon.com/detail?gti=amzn1.dv.gti.d6a9f744-47b0-ac70-aa56-b31fd0f58482&territory=US&ref_=share_ios_season&r=web
Who is winning the scam game?
2026/04/16
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. If you thought you could escape chicken talk, you we're wrong, this week Joe shares some more updates on his chickens. Joe’s got two stories this week, one on a New Jersey man arrested while attempting to collect $800,000 in gold as part of a widespread scam targeting elderly victims, and the second is on a new Google-tracked threat group using social engineering and phishing tactics to infiltrate BPOs and steal corporate data for extortion. Maria’s story is on a conversation she had with Sean Colicchio, highlighting how trusting human instincts, slowing down, and balancing security training can help individuals and organizations better defend against social engineering attacks. Dave’s got the story on a surge in traffic violation scams now using QR codes in phishing texts to trick victims, alongside ten hard-stop rules emphasizing verification, avoiding links or inbound requests, and slowing down to prevent falling for increasingly sophisticated scams. Our Catch of the Day comes from Reddit, where a user questioned a supposed “Google Play Console partnership” email, and the community quickly flagged it as a likely scam—citing red flags.
Resources and links to stories:
Indian in New Jersey on work visa arrested in gold scam, nabbed when he was going to collect $800,000 in gold
Google Warns of New Threat Group Targeting BPOs and Helpdesks
Traffic violation scams switch to QR codes in new phishing texts
[Nepal] Is this “Google Play Console partnership” email a scam?
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Service Set Identifier (SSID) (noun) [Word Notes]
2026/04/14
Please enjoy this encore of Word Notes.
The name of a wireless access point.
CyberWire Glossary link.
Audio reference link: SSID Management - CompTIA Security+ SY0-401: 1.5, Professor Messer, uploaded August 3rd, 2014.
When “opportunity” knocks, don’t answer.
2026/04/09
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Your favorite follow up story is back, this time Sue from Australia discusses why Joe’s hen is losing feathers. Dave’s story is on a sophisticated LinkedIn phishing scam that tricks professionals with fake notifications and counterfeit login pages to steal credentials. Joe discusses a bizarre Everest scam where climbers and Sherpas were targeted with fake rescue schemes, highlighting the surprisingly high number of visitors versus summiters. Maria has the story of IRS and tax-related scams warning taxpayers about ghost preparers, urgent payment demands, and fraudulent contact attempts, with Proofpoint noting the use of remote monitoring tools in 40% of 2026 cases. Our catch of the day comes from Reddit, where a likely “stranded in the woods” scam involving a man named Michael begins to unfold but quickly unravels after he overwhelms the interaction with constant ChatGPT-style questioning.
Resources and links to stories:
LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts
Everest guides accused of poisoning foreign climbers to force fake rescues in $20m scam
Surge in sophisticated tax scams reported by BBB ahead of deadline
Security brief: tax scams aim to steal funds from taxpayers
The Guy in the Woods - Seduction on Scrabble - Part 1
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Advanced Encryption Standard (AES) (noun) [Word Notes]
2026/04/07
Please enjoy this encore of Word Notes.
A U.S. Government specification for data encryption using an asymmetric key algorithm.
CyberWire Glossary link: https://thecyberwire.com/glossary/advanced-encryption-standard
Audio reference link: papadoc73. “Claude Debussy: Clair De Lune.” YouTube, YouTube, 6 Oct. 2008.
Who’s logging in? [OMITB]
2026/04/07
Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts N2K Networks Dave Bittner and Keith Mularski, former FBI cybercrime investigator and now Chief Global Ambassador at Qintel.
Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we discuss findings from the Sophos Active Adversary Report 2026 by Sophos, highlighting how identity-related weaknesses like compromised credentials and gaps in MFA continue to drive a majority of security incidents. The conversation explores how attackers are moving faster, often operating after hours, and how a growing number of threat groups is adding to the complexity.
The fine print of fraud.
2026/04/02
This week, Maria Varmazis and Joe Carrigan, joined by friend of the show Michele Kellerman, dig into the latest social engineering scams, phishing schemes, and criminal exploits making headlines. Dave Bittner is tied up covering RSA, but will be back next week. First up, a follow-up from listener Bruce, who was hit with hundreds of spam emails in what looks like a subscription bombing attack, overwhelming Google’s filters before tapering off; his local hospital saw an even bigger wave, showing how alarming these attacks can be for seniors and other vulnerable users.Joe’s got the story of the UK sanctioning Xinbi, a Chinese-language cryptocurrency marketplace accused of profiting from scam centers in Southeast Asia, marking Britain’s first action against the platform. Michele shares the FBI’s takedown of 11 people in Los Angeles who ran a $17 million “house stealing” mortgage fraud scheme targeting elderly homeowners, highlighting the rising risk of title and refinance fraud for seniors. Maria dives into a new fake CAPTCHA scam that tricks Windows PC users into downloading malware, showing how even simple web prompts can be weaponized by cybercriminals. Our catch of the day is an email on Medicare, but what makes it fake? Tune in to find out!
Resources and links to stories:
Email Bombing
UK sanctions crypto-linked marketplace Xinbi amid crackdown on Southeast Asia scam centres
UK sanctions Chinese crypto marketplace tied to scam compounds
FBI arrests 11 in LA over alleged $17m real estate, loan fraud
Don’t Press Those Keys! How to Spot the New “Captcha Scam”
Windows PCs targeted by hackers in a fake CAPTCHA scam to spread malware — Outlook account credentials are at risk
Blood Cancer United
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
The evolving face of AI deepfakes.
2026/03/26
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow up on what else? Joe's chickens! Oh Dottie! And he also shares a fun LinkedIn translator from Kagi. Dave shares a site that writes phishing emails to your chosen targets including famous and fictional people to helps users learn what to look for in phishing attempts.
Maria discusses a new spin on pig butchering scams to recruit people to be AI face models and use them at scale. Joe shares INTERPOL's Global Financial Fraud Assessment and the current trends that AI is enabling at a rapid pace. Dave's story is about the evolving and increasingly more lucrative practices of refund fraud. Our Catch of the Day comes from Reddit about a overly insistent scammer to be.
Resources and links to stories:
Kagi translating service
The Future of Phishing
‘100 Video Calls Per Day’: Models Are Applying to Be the Face of AI Scams
INTERPOL report warns of increasingly sophisticated global financial fraud threat
The Refund Fraud Economy: Exploiting Major Retailers and Payment Platforms
Reddit: Jessica – Sometimes I just can't be bothered with these idiots.
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
When AI wears a suit and tie.
2026/03/19
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. We start with some follow up on aggravated identity theft and how it ties to crimes like wire fraud, along with a quick look at shared mailboxes and why sharing login credentials can create security risks. Joe’s got the story of a vishing attack on an Ericsson vendor that exposed sensitive data of over 15,000 people, highlighting the risks of third-party security gaps. Dave’s story is on Meta removing millions of scam ads and accounts while facing scrutiny over whether it profits from fraudulent advertising, highlighting the growing scale of social media-driven scams and pressure from lawmakers to crack down. Maria has the story on how scammers are using AI to impersonate government officials through deepfakes, fake websites, and voice cloning, making fraud more convincing and harder to detect while stealing money and personal information. Our Catch of the Day comes from Reddit where a user has an intriguing conversation with Elon Musk, where he professes his love in a very record amount of time.
Resources and links to stories:
Ericsson US Discloses Data Breach as Hackers Steal Employee and Customer Data
That random call saying “you’ve won a prize” is a scam
Meta says it culled millions of scam ads amid accusations that it profits from them
Watch out for AI-generated government impersonators
Grammarly Is Facing a Class Action Lawsuit Over Its AI ‘Expert Review’ Feature
Warren Buffett didn’t make this video about Canada-U.S. tensions. It's fake and there will be more
How to Fix a Sticking Door
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Domain Naming System (DNS) (noun) [Word Notes]
2026/03/17
Please enjoy this encore of Word Notes.
A system that translates text-based URLs to their underlying numerical IP addresses.
CyberWire Glossary link: https://thecyberwire.com/glossary/domain-name-system-dns
Audio reference link: HistoryHeard. “History Heard: Paul Mockapetris.” YouTube, YouTube, 5 Apr. 2009.
Defending against unlimited penalty shots. [Hacking Humans Live!]
2026/03/12
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner head to Orlando to attend ThreatLocker's Zero Trust World 2026 (ZTW). There, they discussed the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Joe Carrigan was unable to join the team, but they have a very special guest, host of the BowTieSecurityGuy After Dark podcast, Rob Whetstine. He is one of the featured speakers this week at Zero Trust World, and he shared experiences from his career at companies like Disney and highlights from his ZTW presentation on Phishing.
Maria's story involves a Maine Supreme Court hearing on a case involving a financial advisory firm that was mislead by a client. Dave highlights a malvertising campaign by a threat actor researchers call D-Shortiez. In our Catch of the Day, comes from the Scambait Subreddit where Mavis offers up large sums of money for a $50 Visa Debit card. We thank Rob for joining us as our special guest.
Resources and links to stories:
Maine Law Court hears oral arguments in $1.3M elder scam case.
Disrupting 59M Malicious Impressions: Inside D-Shortiez Testing Infrastructure and Campaign Management.
Rob Whetstine's BowTieSecurityGuy After Dark podcast.
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Pretexting (noun) [Word Notes]
2026/03/10
Please enjoy this encore of Word Notes.
A social engineering technique in which a threat actor poses as a trusted person or entity in order to trick the victim into disclosing information or performing an action that benefits the attacker.
CyberWire Glossary link: https://thecyberwire.com/glossary/pretexting
Audio reference link: “Batch Pin Hurt Charlize Theron Skin | the Italian Job (2003) Movie Scene.” YouTube, YouTube, 22 Nov. 2016.
Identity theft gets a raise.
2026/03/05
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. For our follow up this week we get an update Merriam-Webster dictionary for Joe, and listener Michael Amezquita suggested that customizable ChatGPT personality settings may explain why Joe and Dave received different responses on Hacking Humans. Dave shares reporting on a Binary Defense case where attackers used social engineering and a help desk reset to hijack a physician’s identity and reroute payroll deposits through a trusted internal system without triggering security alerts. Maria highlights a surge in AI-powered publishing scams targeting authors, where fraudsters use flattery and impersonate legitimate organizations to charge bogus marketing and promotion fees. Joe covers multi-state raids tied to a massive gold bar scam that stole tens of millions from seniors, with stolen gold allegedly melted down through cooperating jewelry stores. In our Catch of the Day, a Reddit scambaiter shared a bizarre ongoing conversation with someone claiming to be “Keanu Reeves from Brokeback Mountain” who reached out to non‑fans in Norway.
Resources and links to stories:
Payroll pirates are conning help desks to steal workers' identities and redirect paychecks
What is it like to attend a predatory conference?
Hungry for Affirmation, Vulnerable to Scams: As a Writer, I Know the Feeling
Third North Texas jewelry store raided over alleged connections to $74 million gold scam targeting seniors
Federal and state authorities raid jewelry stores in multi-state $50 million gold bar scam
Jewelry store raids in Irving, Frisco linked to $55 million gold scam targeting seniors, officials say
Keanu Reeves from Brokeback Mountain reaches out to non-fans in Norway! - Part 1
Have a Catch of the Day you'd like to share? Email it to us at [email protected].
Web Application Firewall (noun) [Word Notes]
2026/03/03
Please enjoy this encore of Word Notes.
A layer seven firewall designed to block threats at the application layer of the open system interconnection model, the OSI model.
CyberWire Glossary link: https://thecyberwire.com/glossary/web-application-firewall
Audio reference link: “VCF East 9.1 - Ches' Computer Security Adventures - Bill Cheswick.” YouTube, 29 Dec. 2015, https://youtu.be/trR1cuBtcPs.
Podcast reviews
Read Hacking Humans podcast reviews
Takoateli 2026/04/10
This is one not to miss.
This podcast is an interesting mix of personalities and security related humor.
SmokeStack9 2026/02/18
Love this pod!
You all had me dying with the Valentine’s Day episode. This show is a very entertaining way to present modern phishing practices (and chicken raising ...
DataJanitor 2025/08/12
One of my go to Podcasts
Such an enlightening and entertaining show. Excellent information delivered that is always applicable. I look forward to it and listen as soon as it c...
0xbeepBoop 2025/02/25
My favorite podcast
I love the hosts, their rapport, sense of humor, and knowledge.
Even my non-techie significant other enjoys listening to this podcast with me.
Tha...
-CCDeYapp 2025/01/12
I can’t recommend this podcast enough!
I have passed this podcast on to everyone in my circle, and they all have come away wiser!
Thank you for sharing your wisdom!
Slygator456 2025/02/19
Excellent podcast, but………
This is a great podcast. I would highly recommend this for someone beginning their cybersecurity learning or those that want to keep up to date. The o...
Fishering1212 2024/09/29
Worth the time to listen
I am glad I was introduced to your show. I have found it very entertaining and useful in my daily life.
Pepe from Kekistan 2024/12/17
Overtly political.
Too political, I feel like I’m listening to Rachel Maddow.
alnueimy 2024/07/28
Best cybersecurity podcast ever!
Thank you so much for all that you do guys this podcast is very informative and very helpful.
rcamp0222 2024/07/19
Can’t listen anymore
Can’t take the annoying laughter along with irrelevant conversation. Unfollowing.
Podcast sponsorship advertising
Start advertising on Hacking Humans relevant audience podcasts
You may also like to advertise on these Podcasts

5141019
Blue Monday: An Ipswich Town Podcast
Blue Monday

4.8228100
Joyce Meyer's Talk It Out Podcast - Video
Joyce Meyer

57684
The Obi One Podcast
John Obi Mikel and Chris McHardy

4.926598
Ask the A&Ps
AOPA

4.8145300
Jojo’s World
Liam S. Smith & Nick Ballantyne

4.618500
Sports on a Sunday Morning
Audacy

4.836490
Computer Talk with TAB
Audacy

4.7181897
Toronto Mike'd: The Official Toronto Mike Podcast
TMDS

4.9406429
Davey Mac Sports Program
"East Side" Dave McDonald

4.8131516
Winnipeg Sports Talk
Winnipeg Sports Talk

