Podcast
Root Causes 238: Tim's Big Phishing Adventure


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
August 15, 2022
In a personally unprecedented occurrence, Tim's identity as a Sectigo executive is being used in a "waterholing" phishing scam intended to raid job seekers' bank accounts. We describe what is going on, how we found out, and the challenges in combatting such an attack.
Podcast Transcript
Lightly edited for flow and brevity.
I just think it is terribly unfortunate, and the main reason for bringing it up on this podcast is, my goodness, if you're being asked for your banking information, I think first of all you should question it straight up. There’s so many other ways to make payment for things that are legitimate, but as well, for anybody who might be coming across Tim’s name with this intent for phishing, I think it's very good, Tim, for you to have been explaining here what’s going. What a terrible thing to happen.
That’s probably not something that exists today in massive scale, but I think it will be something with distributed identities and as that kind of world develops, that, in conjunction with, as you say, DMARC just for standard e-mail communications, I think those are things to be aware of in the future. And if you’re a real sharp person who is looking for a job and you want to really know if it’s Tim Callan, I mean just going out to LinkedIn and saying, Tim - that’s probably your best bet because you know Tim’s a good guy, and he will set you straight, but on the other hand, if you really were in need of verifying somebody, there are ways of doing it, and it’s something for us to talk about down road.
Again, you understand all this intellectually, but now, all of sudden you start saying, okay, I know what it feels like to be somebody in the branding team at FedEx or PayPal or Bank of America watching their brand being used in phishing attacks and being upset and being angry and feeling violated and not being able to solve it. Obviously, those brands are much bigger and more important than my little name but, it is weird and it makes you feel, it makes you feel bad. It’s a bad thing. Even though I’ve met some nice people out of this and some nice people who are smart and savvy, and that’s good, but it would be better it this just wasn’t happening at all.

