April 2025 News & Tips | AI Kidnapping Hoaxes, $7M Payroll Fails & SignalGate

April 2025 News & Tips | AI Kidnapping Hoaxes, $7M Payroll Fails & SignalGate
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! Get strapped in. From 23andMe to working 73,000 hours in a two-week pay period to SignalGate, April has been a wild ride. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

 

The call from your kidnapped child is likely a hoax

As a parent, it’s terrifying to imagine your child in the hands of a kidnapper. Last week, WSJ chronicled the harrowing ordeal of Linda Roan, a Colorado woman who received a frantic call from someone who sounded just like her daughter. An alleged abductor then got on the line and demanded money in return for her daughter’s release. The nightmare only ended after Roan wired $2,000 and the caller hung up. Roan soon discovered her daughter had been safe at home the entire time.

Takeaway: We are living in the world of AI, and it’s much easier to impersonate another person’s style of email, their voice, or even videos. Assume that an urgent call, a video or an email in front of you is a fake until proven otherwise. Resist fight-or-flight responses. Even extremely seasoned and well-respected cybersecurity professionals sometimes fall for scams. Stay vigilant.

 

Computers don’t understand what is “reasonable” unless we make them

There are a lot of things that humans take for granted. Generally speaking, we understand possible from impossible. If someone tells you they can run at 500 miles per hour, you would know that is impossible. If someone tells you their USA zip code is “31415926535897932384626”, that too is impossible. Zip codes are 5-digit codes, such as 90210. Computers are happy to assume the impossible is possible unless they are programmed not to. For example, an audit of a Maryland school district found that a substitute teacher was paid for 73,000 days of work because a payroll person accidentally typed in the substitute teacher’s ID number into the “hours” field of their payroll system. In actuality, the teacher worked 3 days. Payroll systems should have “guard rails” that prevent someone from being paid for more hours than exist in a given pay period, but this system didn’t have that feature, so the school district paid over $7 million to this substitute teacher. The good news is that they recovered the funds, almost two months later when the error was noticed.

Takeaway: If you are designing a computer system, making it “work” isn’t good enough. The system needs to know to reject impossible entries, such as a person working 73,000 days on one paycheck.

 

23andMe is bankrupt, but they still have your data

Over 15 million people used 23andMe’s genetic testing service. The company declared bankruptcy in March of this year, which puts the genetic information of those 15 million people in a precarious position. If they don’t have money to continue operations, the odds of them having money to protect your data is suspect. Their 2023 data breach of almost 7 million customer profiles demonstrates that they weren’t taking cybersecurity as seriously as they needed to before they went bankrupt, and bankruptcy rarely helps situations like this.

Takeaway: The company claims that you can delete your data if you choose to do so, which I strongly recommend. Here is how.

 

Signal. War plans. Wow…

I’ve said before that cybersecurity and politics are inextricably intertwined, and the month of April was no exception. In what has widely been dubbed “SignalGate” by the press, the secure messaging app Signal was used by a group of USA government executives (among them Defense Secretary Pete Hegseth and Vice President JD Vance) to discuss upcoming military strikes against targets in Yemen. Then they accidentally added Atlantic reporter Jeff Goldberg to the chat group. 

There is so much to unpack here… First, using a system for a purpose that it was never intended for is very risky. Signal is designed for secure messaging, but there are no guard rails on who is allowed to use it, who a person may have in their list of Signal contacts, nor what devices can be added to a user’s Signal account. War plans should be sent using confidential classified channels that have appropriate guard rails in place, exactly the same way that Signal doesn’t. Signal wasn’t designed for military use. The WWII “Enigma” machine was designed for military use, and even that wasn’t Secure Enough (from an Axis powers point of view). A tool like Signal being used to discuss upcoming war plans is unthinkable. To make a horrible situation worse, it’s been reported that the NSA sent out a warning about possible vulnerabilities in the Signal app a month before the Yemen chat took place.

Furthermore, now that it’s been proven that Signal is being used to discuss war plans, Signal finds itself firmly in the crosshairs of Nation-State level cyber actors that will try to find a way to hack it, the same way the Allied powers hacked the Enigma. They don’t have a nation-state level budget to counter that threat.

There has been a lot of spin on this story. Claims have been made that Jeff Goldberg somehow hacked his way into the chat. Claims have been made that the plans on where bombs were about to drop in Yemen somehow wasn’t classified information. I will leave further research on those topics as an exercise for the reader, other than to quote Hanlon’s Razor: “Never attribute to malice that which can be adequately explained by incompetence.”

NOTE: TCE Strategy is a paid user of Signal. We believe in what they are doing and decided to provide financial support.

Takeaway: Square pegs and round holes don’t go together well. If you need a hammer, buy a hammer and use it as designed. If you use a ratchet as a hammer, it won’t end well.

 

When a very high-risk maneuver is the lowest risk thing you can do.

For those that have heard me give a presentation, I often talk about how in a very difficult situation, sometimes the best thing to do is something that would be unthinkable in normal circumstances, such as cutting the Internet connection to your business or taking your e-commerce website offline. In the middle of a ransomware attack or a takeover of your website, these actions are definitely under consideration. This theme isn’t specific to cybersecurity. Here is an amazing story of restaurant owners who purposely flooded their business with tap water, in the hopes of keeping out muddy flood waters that were rising outside of their building. That never would have occurred to me to do, but it makes sense. Kudos to them for thinking outside of the box. 

Takeaway: Make the hard decision. Not making a decision is often riskier than making a tough decision, and these restaurant owners are a great example. The road is full of flattened squirrels that refused to run left or right. Don’t let your cybersecurity posture get run over.


Until next month, stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


May 2-4, Brainerd, MN

May 14-15, Des Moines, IA

May 26-30, Las Vegas, NV

June 3-6, Victoria, BC, Canada

July 3, Brainerd, MN

July 9-21, Dublin, Ireland

July 22-24, Orlando, FL

July 25-30, Phoenix, AZ

August 24-27, Indianapolis, IN

October 21-23, Lansing, MI

October 29-30, Worcester, MA

December 1-5, Key West, FL

December 22-26, Ft. Myers, FL


 

TCE Strategy in the News

Thank you to Gordon Severson, KARE 11 and NBC for the opportunity to partner on a story about the City of Blane, MN having a serious cybersecurity incident.
 

Thank you to Ian Russell, KARE 11 and NBC for the opportunity to be interviewed on texting scams regarding unpaid tolls.

Interesting Articles

It's about time Apple! I'm surprised that this wasn't done earlier. User privacy is a strong differentiator, and not one that should be given up easily just because the UK government wants you to.

 
"There are at least three threads over on Reddit detailing the [iPhone iOS 18.4] issue. Some users report new apps -- usually games like Squid Game or Cooking Mama -- and others are saying that apps that were previously deleted have reappeared."
"The announcement follows a warning from MITRE Vice President Yosry Barsoum that government funding for the CVE and CWE programs was set to expire today, April 16, potentially leading to widespread disruption across the cybersecurity industry."
There is a fix for a vuln that is being actively exploited by ransomware gangs in Microsoft's April Windows monthly patches. Patch early, patch often.
Cybersecurity Tip of the Month
 
Creating Online Accounts Before Someone Else Does For You
 
Many people choose to have a minimal online presence thinking it may help keep them safe from becoming a victim of cybercrime. However, with the increased availability of personal information that can be found online, cybercriminals have gotten better at using social engineering and other methods to commit fraud. This can include using information such as addresses, Social Security numbers, and birthdays to impersonate victims and create accounts online, allowing them to steal financial information or money and avoid detection until well after the damage is done.
 
Banks, water companies, power companies, the IRS and even the post office are all offering to service you through an "online account". It is very important that you set up these accounts as yourself, before a cybercriminal beats you to it and tries to have your mail rerouted to them or your IRS tax refund sent to the wrong account. Turn on multi-factor authentication on these accounts and add a pin number if possible. Freezing your credit can also help prevent fraud. If you have older friends or family members who do not have much experience using the internet, offer to help them set up their own accounts and credit freezes as well.
 
Some places that you should set up online accounts include:

•    phone and internet provider
•    cell phone carrier
•    bank and retirement accounts
•    credit cards
•    IRS
•    USPS 
•    Social Security Administration

See my August 2024 Newsletter for steps to freeze your credit with the three major credit bureaus: 


https://bryceaustin.com/newsletter/august-2024-news-tips-cybersecurity-news-roundup/
 
LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: