The Human Element of Cyber Security Makes Security Work

May Chen-Contino talks about the human elemenet of cyber security.

These days, the biggest security problems and breaches don’t start with the code or the technology. They start with people. Criminals exploit the human element of cyber security to get access and do their damage. But when the stakes are high, that same human element is crucial to protect people from those who want to exploit them.


See When Cybercrime Gets Personal with May Chen-Contino for a complete transcript of the Easy Prey podcast episode.

May Chen-Contino is the CEO of Unit 221B, a threat disruption company that focuses on delivering actionable threat intelligence to businesses, law enforcement, and government agencies. They have a roster of cyber security pros with decades of experience, and they work on a huge variety of crimes, including ransomware, child exploitation, and more. May had always had a strong sense of justice and fairness, and when a friend told her about a group of “white hat” hackers who were doing real work hunting bad guys, she was intrigued. When she met the team, she immediately felt like she found a home she never realized she needed. So much of her life had been oriented around seeking truth and justice, helping this phenomenal team of cyber pros scale and help more people was what she wanted to do.

Everyone Has Been a Victim

May doesn’t want anyone to be embarrassed or ashamed of being a victim of a scam or incident. If some nefarious criminal decides to target you, that’s your fault. Everyone’s been a victim of some kind of scam, whether or not it’s cyber security-related. Even cyber security pros have been victims of sophisticated scams. The human element is especially strong in these attacks. Social engineering and manipulation are huge parts of all kinds of crimes, both on- and offline.

100% of people have fallen victim to a scam of some sort, whether or not it’s specifically cybersecurity.

May Chen-Contino

May herself ran into a scam. Before she got into the cyber security industry, she tried to sell a pair of old luxury shoes on eBay. eBay is a great company, but all online marketplaces have risks. To try to mitigate that, eBay holds the buyer’s money in escrow until the seller confirms shipping the item. May sold the shoes, took them to FedEx to ship, and as she was going to put the shipping confirmation into eBay, she gets an email that PayPal can’t release the funds. She immediately realized she’d been scammed.

Then the fake buyer reached out, trying to get her to move to a payment app and steal more money. They claimed there was something wrong with their PayPal but they really wanted to pay for the shoes. May doesn’t recommend this approach, but she was angry and wanted this scammer to experience some kind of justice. So she decided to engage.

Talking to the Scammer

May was angry that the scammer would get the shoes regardless. But when she complained to a friend who worked in ecommerce shipping, he mentioned that FedEx may be able to reverse the shipment. So she immediately called FedEx, and they were able to find the shipment and have it returned to her. She already felt better knowing that the scammer wasn’t getting anything out of this scam.

The scammer wanted her to send some money on a payment app to “connect their accounts,” and then they would send back the money she sent plus the payment for the shoes. May’s first job out of school was as a graphic designer. She took a screenshot of the payment app platform and photoshopped a pretty large sent payment. Then she sent the scammer that photoshopped image and claimed she sent the money. The scammer, obviously, didn’t see it, and started escalating, putting more urgency in the messages and even accusing May of being a scammer herself.

This went on for a while. The night before the shoes were set to be returned, May suggested the scammer send her some money to connect the accounts, and she’d keep the shoe payment and send the rest back once they verified they had the shoes. They agreed, but the next day still hadn’t sent any money. May ended the interaction by sending the scammer a photo of the shoes, back in her possession.

It’s important to choose where you engage. This situation definitely could have gone differently, and it’s generally not smart to chase someone who’s threatening you. But people like May with a high sense of justice might choose to do it anyway. If you do that, do it wisely – shore up your defenses, know what you’re doing, and decide accordingly.

Unit 221B Takes On Criminals

Unit 221B specializes in criminal investigations, not specifically cyber crime investigations. That’s because crime and cyber crime have involved and are not always fully distinct. Their goal is to get people arrested and criminally charged at the federal level, whether that’s because they’re stealing or scamming a lot of money, hurting kids, or causing other kinds of harm. If a big company loses millions to ransomware, for example, they could fire the security team or lay off people. There are a lot of ways big, anonymous attacks can impact real people.

The team at Unit 221B does threat intelligence, investigation and digital forensics, pen testing, red teaming, and incident response. They often handle sophisticated, high-level incidents. In a lot of ways, they’re like a digital military unit or SWAT team. When someone in the industry has a problem, they call Unit 221B. They come in, take countermeasures, do forensics, and figure out who the criminal is. They are very much a group of people fighting to protect the innocent.

Unfortunately, a lot of victims get left behind. If an average person gets caught in a scam, there often aren’t a lot of options for recourse. So Unit 221B is also scaling to help more people with their threat intelligence platform. Cyber criminals aren’t staying “in their lane” and sticking to just one thing. Unit 221B is putting the data together to track them across all kinds of crimes and hopefully catch them.

There are a lot of current trends and a lot of concerns May has for the direction cyber crime is going. But there are two main ones that stand out. And both of them have to do with how cyber criminals are evolving.

Ransomware is a good example. A lot of the ransomware organizations are professionals. They generally have a code of conduct where they’re just after the money. If you pay them, they’ll stick by their promises to give back your data and not do things you don’t want with it. They often even have negotiators. In a lot of ways, they’re like the mob in old mob movies – they take pride in their work and keep their word so their criminal organization succeeds.

The human element of cyber security is how we stay protected from organized cyber criminals.

The other impact is the newer cyber criminals, especially the younger ones. There are criminal organizations mostly composed of young men from English-speaking countries ages 14 to 16. These young criminals don’t have an older organization enforcing a code of ethics. And they’re looking for like-minded people and want to show off to their friends. Their goal is not just about money, but also about power and ego. So they have fewer (or no) lines they won’t cross.

Both of these criminal organizations exploit the human element of cyber security. Social engineering of third parties and those in the supply chain is especially common as a way to get access .

A lot of large organizations have really good security because they’ve spent many years focusing on and improving it. Their systems are locked down, their tech tools are in place, they have the correct protocols set up. At that point, the human element becomes the cyber security weak point. All the security in the world won’t defend against a help desk person who resets a password for an impostor, or an employee who is social engineered to let a criminal in.

Many organizations have really great security because they focused on it for many years … it’s really the humans that start to impact the weak point.

May Chen-Contino

Even when it comes to investigations and prosecutions, humans are the weak point. If you’re caught in a scam and wipe your device as part of recovery, you’ve just erased all the evidence. Sometimes companies try to respond to ransomware by wiping everything and restoring from backup. But when you decide to do that, you no longer have a way to figure out who was in your systems, what they took, or how they got in. Is it a persistent threat? Is it an insider? You have no way to know – and no way to know if they can get back in. And when you report it to law enforcement, you don’t have any evidence to help them build a case.

Unit 221B recommends delaying a wipe, even if it’s eventually necessary, for as long as possible. Get your defenses in place as much as you can, get an incident response team involved, and lock down as much evidence as you can first. It will also help you determine who the criminal is and therefore who and what is still at risk.

Know Your Adversary

One area where the human element of cyber security comes into play is in the decision-making process when an incident happens. When a company gets hit with ransomware, they have to decide. Do they pay and hope the criminal group keeps their word? Or do they not pay and try to recover from having all their systems and data encrypted?

Identifying the criminal is crucial to these decisions. If it’s one of the older, established groups with a long history of keeping their word if you pay, that’s a different situation than if it’s one of those younger criminals whose goal is chaos and almost never live up to their end of the deal they offer. Knowing your adversary is key to incident response. But regardless of how much data you have on the situation, it’s still a hard decision to make.

One thing Unit 221B advises people to look at immediately is the PR and legal impacts of the situation. They have a cyber security lawyer on their team, and he can work with organizations to figure out the legal impact. There are regulations about notifying people and filing things. And companies have to decide how they want to react from a PR standpoint. Do they work with law enforcement to try to catch and prosecute the criminals? Sweep it under the rug and hope for minimal damage? Be open with the public about what happened and what they did to fix it? May loves to see companies being open and sharing knowledge, but every course of action has potential consequences.

Payment and Prosecution

May’s professional advice for any ransomware situation is to never pay. Don’t give them money, don’t engage with them, it’s just not worth it. Part of that is May’s strong sense of justice preferring an attitude of not negotiating with terrorists. And the experts at Unit 221B have even cracked some older ransomware programs. But even if you call in Unit 221B for help, you know your business better than they do. It’s ultimately up to what makes sense for your business. May has seen companies pay millions, but when they looked at the whole situation losing millions of dollars was the least amount of harm.

Our professional advice for any ransomware … don’t pay it. Don’t engage. It’s just never worth it.

May Chen-Contino

There is a lot of misinformation about federal law enforcement’s help. They’re notoriously understaffed and underbudgeted, and have to take cases that end up being slam dunks for the prosecution. (This is why evidence is important!) Unit 221B works with a lot of federal law enforcement agents, and contrary to the popular myth, they do care. They just don’t have the resources to prosecute anything below a certain level. If your situation meets the level for federal involvement, May highly recommends working with them.

Just because federal law enforcement only works big cases doesn’t mean you shouldn’t report it. Report it to your local police department, because sometimes they can help. But resources like the FBI’s IC3 reporting center are important, too. Even if you don’t think they’ll help you specifically, reporting lets law enforcement know about the scope of the problem. If nobody reports it, the government is going to assume it’s not a problem and so won’t provide any resources to fight it.

The Future of Threats

There are many factors on where attacks and cyber security are going in the future. One of those is ransomware. It’s not a new topic, but their methods and programs are getting more and more advanced. AI is also a big factor for the future. Both sides have it, so it’s a race to see who will use it better and faster.

A large element in the work May does with Unit 221B is the human element of cyber security. That includes things like social engineering succeeding because they’ve used OSINT to get information on the target in advance. You can have the best defenses in the world, but the human element will be your weak point, and attackers are exploiting that more and more.

In a social engineering attack, you can have the best defenses in the world … that to me is the week point that we’re seeing now, quite frankly, scaling faster and faster.

May Chen-Contino

But that human element can also be a benefit. One of Unit 221B’s initiatives is an invite-only tech platform to connect top performers in investigations, law enforcement, government, private sector, and anywhere else doing this kind of work. This information sharing is what actually moves forward investigations, catches these criminals, puts protections in place, and saves victims. Pure tech can’t do that – the human element is why it works.

The human aspect is what gets the actual protection in place and saves these victims. No technology can do that alone.

May Chen-Contino

Learn more about Unit 221B at unit221b.com, or connect with them on social platforms like LinkedIn. They share materials on how to keep yourself protected, and also handle high-stakes investigations and threat intelligence work if you’re dealing with something and need another expert opinion.