Exposing the Digital Legal Trolling Machine: How Automated Privacy Scams Work—And How To Shield Your Enterprise

In today’s digital ecosystem, threat actors are no longer the only risk to online operations. A parallel threat is actively expanding: automated digital legal trolling.

automated digital legal trolling

Recently, we were contacted in regards to a small mom and pop organization that became the target of a high-volume demand letter accusing their web property of non-compliance with privacy regulations (specifically regarding the deployment of third-party media embeds like YouTube, and underlying tracking scripts).

While these notices appear threatening, analyzing their mechanics reveals an automated, predatory harvesting model designed to trigger immediate financial settlements. We are sharing an operational response guide to expose how these campaigns work and demonstrate how to actively neutralize the risk.

1. Deconstructing the Scam: How Automated Trolls Target Web Infrastructure

These demand letters rely on automated harvesting tools rather than human legal review:

  • Generating Automated Legal Notices: Upon flagging a domain, automated scripts are instantly filling form templates with page URLs and legal boilerplates to simulate individual manual audits.
  • Leveraging Fear of Statutory Fines: The notices are intentionally threatening immediate legal action, calculating that business owners will choose a quick settlement over consulting legal counsel or auditing their technical stack.
  • Ignoring Active Compliance Engines: Scanners are frequently ignoring active client-side script blockers, local caching layers, or privacy frameworks, claiming a compliance violation where none exists or where minimal risk is present.

2. Active Technical Mitigation: How To Eliminate Risks and Remove Vulnerable Plugins

To neutralize any exposure and achieve strict compliance across your web properties, businesses must execute a systematic overhaul of your privacy architecture and consent management engines. This is a time intensive process that looks complicated, but with the right tools at your fingertips, it’s entirely manageable, even by relative novice do it yourself small business and is absolutely worth your attention to shield you from this real risk.

Running this article through your own LLM of choice will serve as a step-by-step blueprint. Mind you, this is not legal advice, this is not 100% fool proof, this is a guide that is designed to point you in the right direction, and if you truly truly want to 100% mitigate your risk, contact your legal council.

Here is exact timeline of actions that must be taken:

Step 1: Deleting High-Risk and Redundant Plugins

  • Auditing Administrative Tools: Actively reviewing all installed WordPress plugins and deactivating unneeded administrative utilities—specifically tools like File Manager Advanced—that are frequently flagged during automated security scans and serve as primary triggers for automated legal letters.
  • Uninstalling Inactive Assets: Completely removing unneeded plugins from the server rather than leaving them deactivated, ensuring their underlying code assets and scripts cannot be indexed or exploited by crawlers.

Step 2: Eliminating Raw Embeds and Sanitizing Links

  • Isolating Unconsented Script Triggers: Locating all legacy media embeds across primary landing pages (/about-us, homepages) to stop unconsented tracking calls prior to user authorization.
  • Converting to Privacy-Enhanced Endpoints: Re-writing raw YouTube embed URLs across the database to use privacy-enhanced endpoints (youtube-nocookie.com), explicitly blocking DoubleClick tracking telemetry prior to user interaction.

Step 3: Deploying Dynamic Script Blocking via Complianz

  • Cataloging Active Cookies: Running site-wide scans to index active cookies, fonts, and scripts across WooCommerce, form plugins, and page builders.
  • Enforcing Dynamic Script Interception: Utilizing a dedicated consent management engine like Complianz to dynamically wrap third-party elements—including Google Analytics, YouTube, Google Fonts, and reCAPTCHA—blocking execution until explicit visitor consent is recorded.
  • Synchronizing Policy Databases: Syncing all detected scripts with open databases (like Cookiedatabase.org) to automatically populate verified cookie descriptions on public policy documents.
  • Publishing Compliance Documentation: Generating required regulatory pages, including standard Opt-out preferences documents, and integrating them directly into footer navigation menus.
  • Activating Global Consent Banners: Enabling live user consent banners across all web properties, ensuring strict compliance enforcement on every incoming visit.

3. Coverage Analysis: How Dynamic Blocking Handles Deep Subpages

A critical question when managing site-wide privacy is whether every single subpage requires manual inspection:

  • Dynamic Theme-Level Interception: Operating the script-blocking engine at the theme/header level ensures that even on deep subpages that haven’t been manually audited, the system is dynamically intercepting and holding scripts before they can execute in the browser.
  • Managing Scanner Index Limits: While free scanning tools typically index up to 50 pages for initial cookie inventory generation, the underlying script blocker is continuously protecting 100% of incoming traffic across all subpages.
  • Ensuring Total Fallback Protection: Combining dynamic script blocking with site-wide database sanitization ensures complete coverage across deep subpages and custom post types.

4. Ongoing Action Plan: Maintaining a 100% Risk-Free Environment

To maintain a hardened, risk-free posture against automated legal bots moving forward, organizations should commit to the following ongoing protocol:

Technical Verification Actions

  • Purging Server and Plugin Caches: Regularly clearing host-level caching (such as WP Engine) and plugin caches (like WP Rocket or W3 Total Cache) to ensure legacy pre-rendered pages are never served to visitors or crawlers.
  • Executing Incognito Verification: Periodically testing inner subpages in Incognito mode to confirm media players remain locked behind consent placeholders until explicit user approval.

Database and Asset Hardening

  • Executing Database Search-and-Replace: Running database search-and-replace routines using utilities like Better Search Replace:
  • This guarantees that even if a client-side script blocker fails, the underlying iframe natively defaults to privacy mode.

Content Publishing & Plugin Hygiene

  • Enforcing Privacy-Enhanced Media Standards: Establishing strict publishing guidelines requiring all newly embedded video or audio assets to utilize youtube-nocookie.com or privacy-enhanced embed codes.
  • Conducting Monthly Plugin Audits: Reviewing installed plugins monthly to deactivate and delete non-essential administrative utilities before they can create new attack vectors.
  • Updating Cookie Inventories: Re-running compliance scans following any plugin or analytics modification to maintain accurate, audit-ready compliance logs.

Seeking the Right Technical Experts: What Your Defense Team Needs

Should you receive a demand letter, when escalating a privacy dispute or preparing a forensic defense, standard web design knowledge is insufficient—you must engage specialized software engineers who can analyze both sides of the application stack. Properly auditing your exposure requires a front-end software engineer to evaluate client-side code, cookies, and browser-level tracking behaviors, alongside a back-end software engineer to analyze the server-side code and data handling logic where the website is hosted.

Because many server environment nuances dictate liability, a crucial preliminary step is establishing hosting architecture: if the site operates on a third-party managed host, server-side data processing may fall under the hosting provider’s infrastructure rather than the site itself. Conversely, if back-end analysis proves the server does not store, transmit, or process the intercepted data, the flagged cookie is functionally a “dead end”—created on the front end, but utilizing no back-end data stream.

While a qualified full-stack engineer can occasionally handle both domains and serve as an expert witness, organizations should carefully vet qualifications and engage separate front-end and back-end forensic specialists if there is any doubt regarding full-stack expertise.

Conclusion: Taking Control of Your Digital Posture

Navigating the modern web means recognizing that automated legal harvesting tools are here to stay. These predatory bots will continue crawling millions of domains daily, fishing for unconsented scripts, legacy embeds, and administrative oversights. While receiving a high-demand notice is unsettling, these letters should never be ignored. Ignoring them can turn a minor technical oversight into an escalated dispute, whereas taking immediate, documented action effectively neutralizes their leverage. By executing a systematic technical cleanup—deleting high-risk plugins, converting legacy embeds to privacy-enhanced endpoints, and deploying site-wide script blocking—you transform your web properties from low-hanging targets into hardened, compliant assets.

Disclaimer: The information provided in this article is for educational and technical risk-mitigation purposes only and does not constitute formal legal advice. Privacy regulations and enforcement standards vary by jurisdiction. If your organization receives a formal legal notice or demand letter, you should consult with a qualified legal professional to evaluate your specific circumstances.

Robert Siciliano, CSP, CSI, CITRMS—recently named one of the 50 Best Cybersecurity Keynote Speakers—is a #1 Amazon best-selling author, CEO of Safr.Me, Head Trainer at ProtectNowLLC.com, and the Architect of The Strategic Human Firewall™. Grounded in his 30+ years of real-world expertise, this content was developed using advanced predictive research tools, with every framework, strategy, and security protocol authored and verified directly by Robert.

Why Most Security Awareness Training Fails (Hint: It’s Not the Software)

Most security awareness training doesn’t fail because the software is buggy. It fails because it targets checkbox compliance instead of actual human behavior.

If your employees are playing compliance videos on mute in a background tab just to clear a dashboard and generate a completion certificate, your organization remains wide open. While massive automated platforms excel at background infrastructure and logging metrics, they consistently leave the critical Human Blindspot™ unaddressed.

To help corporate security leaders, HR executives, and business owners separate passive compliance from active defense, we just published a definitive 2026 market evaluation. We analyzed 8 of the leading corporate platforms against the critical dimensions that separate simple tracking from a true Strategic Human Firewall™.

Here is the quick-reference cheat sheet based on specific organizational needs:

Quick Recommendations by Use Case

  • 🏆 Best for Human-Led Employee Training & Behavior Change: Protect Now LLC
  • 🤖 Best for Adaptive Phishing Simulation Software: Hoxhunt
  • 📚 Best for Massive Self-Paced Content Libraries: KnowBe4
  • 📧 Best for Email-Security Ecosystem Alignment: Proofpoint

The Real Tradeoff: Live Engagement vs. Software-First Platforms

Choosing a platform isn’t about finding the one with the most bells and whistles—it’s about aligning with your true operational priority:

  • The Software-First Model: Platforms like Hoxhunt and KnowBe4 are fantastic if you want continuous background automation, gamified email tracking inside the user’s workflow, or complex metric dashboards for a massive enterprise.
  • The Human-Led Model: If your metrics show that automated phishing clicks aren’t actually reducing real-world social engineering errors, you need live human engagement. Behavioral change requires conversational interaction, real-time Q&A, and pattern-interrupt instructions that break through everyday cognitive fatigue.

Read the Full 2026 Evaluation

We broke down all eight vendors—including deep dives into Infosec IQ, NINJIO, SoSafe, and MetaCompliance—covering cost considerations, small business fit, and compliance mapping for SOC 2, HIPAA, and PCI-DSS.

👉 Read the complete 5,600-word Security Awareness Training Buyer’s Guide here and see exactly where your current vendor stacks up.

What is your organization’s biggest hurdle with security training? Is it getting employees to care, or managing the administrative overhead? Let’s discuss in the comments.

Robert Siciliano CSP, CSI, CITRMS is the Architect of of The Strategic Human Firewall™ a methodology to mitigate the Human Blindspot™. He’s dedicated over 30+ years as a #1 Best Selling Amazon author of 5 books, and the architect of the CSI Protection certification; a Cyber Social Identity and Personal Protection security awareness training program. He is a frequent speaker and media commentator, and CEO of Safr.Me and Head Trainer at ProtectNowLLC.com.

Stop the Slop: A Consumer’s Guide to Surviving the Flood of AI Slop and Synthetic Deep Fakes

What is a Deepfake

The term “deepfake” is a blend of “deep learning” a form of Artificial Intelligence and “fake.” A deepfake is synthetic media (video, image, or audio) that has been digitally manipulated or entirely generated using sophisticated AI technology to convincingly show a person appearing to say or do something they never actually said or did.

YOU WILL Get Suckered By An AI-enabled DeepFake

What is AI Slop

The term “AI slop” refers to digital content—such as text, images, videos, or audio—that has been created using generative artificial intelligence, and is characterized by a lack of effort, quality, or deeper meaning, often produced in an overwhelming volume.

It has a pejorative connotation, similar to the way “spam” is used to describe unwanted, low-value content.

AI slop is viewed as an “environmental pollution” problem for the internet, where the costs of mass production are nearly zero, but the cost to the information ecosystem is immense.

AI slop contributes significantly to the general erosion of trust in the internet by blurring the line between human-created authenticity, machine-generated noise and fraud.

Lies! It’s ALL Damn Lies!

AI slop and deepfakes are fundamentally similar because both are forms of synthetic media created by the same powerful generative AI models (text-to-image/video). They both contribute to a widespread erosion of trust online by blurring the line between human-made content and digital fabrication. While a deepfake is a targeted, high-quality forgery designed to maliciously deceive (e.g., faking a political speech), AI slop is low-quality content mass-produced out of indifference for accuracy or effort, often just for clicks.

Nevertheless, both types of content flood the digital ecosystem, making it increasingly difficult for users to distinguish authentic, verified information from machine-generated noise.

Key Characteristics of AI Slop

  • Low Quality/Minimal Effort: The content is often generated quickly, with little to no human review for accuracy, coherence, or originality.
  • High Volume/Repetitive: It’s mass-produced to flood platforms, often prioritizing quantity and speed over substance.
  • Driven by Profit: It is frequently created for “content farming,” designed to manipulate search engine optimization (SEO) or social media algorithms to generate ad revenue or engagement.

Examples of AI Slop

  • Images: Surreal or bizarre images (like the viral “Shrimp Jesus”), low-quality or inconsistent stock photos, or social media posts featuring images with subtle flaws (like extra fingers or garbled text).
  • Text: SEO-optimized articles that are vague, repetitive, or inaccurate; mass-produced low-effort blog posts; or entirely AI-written books.
  • Social Media: Fake social media profiles, or sensational, low-effort videos and posts designed purely for clickbait and engagement.

The general concern is that the rapid proliferation of AI slop is polluting the internet, making it harder to find high-quality, authentic human-created content and blurring the lines between real and fabricated information.

The contribution to mistrust is not primarily about malicious deepfakes (though that is a related trust problem); it’s about the sheer volume and mediocrity of content that makes the web unreliable.

AI Slop Drives Mistrust

Blurring Reality and Fabricating “Truth”

  • The Problem of “Careless Speech”: AI models are built to generate text that sounds plausible and authoritative, not necessarily text that is truthful. AI slop is often created with indifference to accuracy, meaning it presents subtle inaccuracies or outright falsehoods with complete confidence.
  • Viral Misinformation: Because AI can produce content so cheaply and quickly, it allows for the mass creation and distribution of misleading content (like fake images during a natural disaster or absurd celebrity claims) that can easily go viral before being fact-checked.
  • Normalizing Fake Content: When users are constantly exposed to AI-generated images, videos, and articles that are “just good enough,” they become desensitized. The constant exposure makes the audience question the origin of all digital content, leading to a state where nothing can be fully trusted until proven otherwise.

Undermining Authority and Credibility

  • Degrading Search Results: AI slop sites, designed only to manipulate SEO, push genuinely high-quality, researched, and expert human content down the rankings. When you search for vital information and the top results are vague, repetitive, or inaccurate, you lose faith in the search engine’s ability to act as a reliable guide to the web.
  • The “We Don’t Care” Signal: When a brand, news site, or business publishes content that is clearly generic, full of buzzwords, or poorly edited because it was quickly spun up by AI, it sends a message of complacency and low effort. This DILLIGAF attitude damages brand trust and suggests the company doesn’t care enough to communicate with intention.
  • Fake Reviews and Social Proof: AI slop is used to generate fake reviews and create inauthentic social media engagement (bots commenting “great photography” on a thousand AI images). This corrupts the systems of social proof—like ratings, likes, and comments—that people rely on to judge quality, making it impossible to trust whether a product or a trend is genuinely popular.

The “Enshittification” of the Internet

“Enshittification” is a term coined by writer and activist Cory Doctorow. The widespread adoption of AI slop is accelerating what some critics call the enshittification of digital platforms—the degradation of services as platforms prioritize profit (through mass-produced, algorithm-friendly content) over user value.

  • As the internet fills with more and more machine-generated “junk,” human creators struggle to be seen, and the entire digital environment becomes less useful and more frustrating.
  • This cycle reinforces the idea that the internet is increasingly becoming an unpleasant, unreliable space designed to farm engagement rather than to connect, inform, or entertain in a meaningful way.

The core of the mistrust is the inability to answer two simple questions with confidence: “Did a real person make this?” and “Is this true?”

Protect Yourself: Digital Literacy Matters

Protecting yourself from AI slop and deepfakes requires a dual approach: critical consumption (protection) and responsible behavior (not spreading). The core defense is applying strong media literacy skills to everything you see online.

Critical Consumption (Protection)

Protecting yourself from the proliferation of AI slop and deepfakes requires developing strong habits of critical consumption. The core practice is to refuse to blindly trust what you see and to develop systematic ways of verifying authenticity. This involves checking the source—prioritizing content from established, fact-checked news outlets over anonymous or clickbait accounts that have a financial motive to spread low-effort content.

You must inspect the media itself by slowing down and looking closely for tell-tale AI errors, such as distorted hands, missing jewelry, or unnatural movements in videos.

Source Verification:

  • Check the source, not just the content. Prioritize content from established, reputable news and expert sources.
  • Trace the origin. Use reverse image/video search tools (like Google or TinEye) to find the original source and context of the media.

Inspecting Media and Spotting the “Tells”:

Slow down and inspect closely. Look for visual artifacts that AI generators frequently get wrong.

Look for anomalies

  • Photos: like distorted hands, extra or missing fingers, melted or smudged background details, unnatural shadows, or inconsistent jewelry.
  • Videos: For videos, watch for robotic, jerky, or unnatural body movements, and any lip-syncing issues.

Fact-Checking and Skepticism:

  • Assume it could be fake. If a piece of content elicits a strong emotional reaction (shock, anger, or awe), immediately pause and assume it is manipulation bait.
  • Verify claims independently. Cross-check the story with multiple, credible, independent news organizations before accepting or sharing it.

How to Not Spread AI Slop (Responsible Behavior)

Your personal sharing habits are the most powerful tool against the spread of synthetic content:

  1. Stop the Emotional Share: If a piece of content—image, video, or headline—elicits an immediate, intense emotional response (outrage, shock, fear, or awe), PAUSE. Content creators use emotional triggers to bypass your critical thinking and get you to share instantly.
  2. Question the Motive: Before clicking ‘Share,’ ask: “Who benefits if I share this?” If the answer is an anonymous clickbait site, an algorithmic content farm, or a source pushing a strong, unverified agenda, do not share.
  3. Refuse to Amplify Slop and Deepfakes: Do not engage with or comment on clearly low-quality, AI-generated content (like repetitive, nonsensical articles or bizarre images). Algorithms reward all engagement, so even a comment saying “This is fake” helps the slop gain visibility.
  4. Add Context When Necessary: If you absolutely must share a piece of content that looks potentially fake (e.g., to discuss a trend), clearly label it yourself (e.g., “Warning: This appears to be AI-generated/unconfirmed”).

By adopting these habits, you move from being a passive consumer to an active filter and a digitally literate consumer engaged in protecting yourself and others from misinformation and lies. These are the most effective way to protect the integrity of the digital ecosystem.

Robert Siciliano CSP, CSI, CITRMS is a security expert and private investigator with 30+ years experience, #1 Best Selling Amazon author of 5 books, and the architect of the CSI Protection certification; a Cyber Social Identity and Personal Protection security awareness training program. He is a frequent speaker and media commentator, and CEO of Safr.Me and Head Trainer at ProtectNowLLC.com.

Here’s Why You Need Identity, Privacy, and Device Protection

Our philosophy has always been “all security is personal”. So, whether you are a front line administrator, a CISO, or a CEO, the security of your organization begins with you and your person. If you don’t have your own personal security in order, how do you expect your business data to be secured? It starts with you.

People are often anxious about the security of their personal information and online accounts. Cybercriminals are finding new ways to invade your privacy which is why you need comprehensive protection to keep you safe online.

Here are some protection and privacy best practices that you can use to keep your identity and sensitive information away from prying eyes and restore your faith in technology.

Device Protection

Device protection refers to the measures you take to protect your hardware or physical devices from intruders and potentially harmful software, such as malware, adware, and viruses.

Protect Your Hardware

This may sound simplistic, but knowing where your smartphones, computers, iPads, and gaming consoles are and never allowing people you don’t know to use them are the first steps in protecting them.

Ensure that you protect your devices with a password to ensure that your photos, banking apps, and text messages stored on them are inaccessible if you lose your phone at a concert or leave your tablet in a restaurant. You’d be amazed at how many people don’t have a password in their mobile phone.

Back Up

It’s also a good idea to back up your files regularly so that your images, videos, and documents are lost if your laptop / phone  crashes or is stolen. Use a combination of Google, Apple, online backup services and local external hard drives, and sync software.

Protection Against Malicious Software by Updating

To keep your device safe, you’ll also have to protect it from malicious threats. There are many ways for malware and viruses to get onto your devices, including phishing scams, suspicious websites, questionable downloads, and clicking on advertisements.

When browsing sites that seem unreliable, use caution, and apply common sense when clicking on links.

Updating operating systems, browser, and various software programs, is necessary to keep your data and devices secure. These updates are for functionality purposes, but more often are critical for security updates, when and where at vulnerabilities are discovered by researchers.

Privacy Protection

Protecting your privacy involves preventing advertisers, fraudsters, and other unscrupulous organizations from obtaining access to the information you’d prefer to keep private.

It only takes a few careful modifications to your regular browsing, emailing, and social media activities to increase your internet privacy. Just be thoughtful about where you’re going, what you’re doing, and what personal or sensitive information you may be providing.

Limit What You Share on Social Media

Consider your usage of social media. Do you upload pictures containing information that could be used to identify you? Examples of information that you shouldn’t share online include your:

  • Full name
  • Birthday
  • Physical address
  • Current location

If your profile is freely accessible and anyone can view it, you might want to think about limiting what you post online. Sadly, although your loved ones may like reading your status posts, cybercriminals enjoy them even more.

Fraudsters can learn enough about you in just a few minutes of spying to pass themselves off as you or to target you. Restrict the information you post on social media and restrict the number of people you follow and befriend to those you actually know.

In the end, be thoughtful about what you post, and how a scammer might use it against you, your family, or your business.

Use a VPN

Connecting to a virtual private network (VPN) is another great way to protect your online privacy. By encrypting your connection and keeping your location hidden, a VPN enables you to browse the internet anonymously.

Protecting your privacy with a VPN is essential when using public Wi-Fi at a library, restaurant, or coffee shop.

This is because cyber criminals typically wait around unprotected Wi-Fi networks to spy on users making online purchases or paying bills to gain access to their login information.

Invest in Antivirus Software

Spyware can also threaten your online privacy. Adware, for example, can be used to spy on your online activity to help third parties learn more about your interests and preferences and target you with online ads.

One of the best ways to block spyware is by installing a reliable antivirus application to help you identify and remove malicious software. A reliable antivirus software application to help detect, identify, and remove malware and viruses that could pose a threat to your online security. A paid subscription has multiple layers of protection versus a free antivirus.

Identity Protection

Another type of fraudulent activity to look out for is identity theft. Each time identity theft occurs, dealing with the repercussions can be challenging and may even have an impact on your finances, credit rating, and future ability to obtain loans, credit cards, or mortgages.

Protecting your personal information with care is one approach to keeping your identity safe online. Never provide anyone your Social Security Number via email unless it is absolutely necessary, and you have verified the sender’s identity.

Investing in identity security services that monitors the dark web and notifies you of any suspicious activity that might point to identity theft is a good idea.

Consider getting a credit freeze which locks on your credit report and prevent unauthorized counseling, opened in your name.

Here are some examples of identity theft:

1.    Forging an Identity

The most frequent form of identity theft is when a thief takes a victim’s Social Security number and uses it to create a new false identity.

2.    Creating New Accounts Using Someone Else’s Credentials

When a scammer successfully obtains financial data and personally identifiable information from a user, they can open new accounts such as utility accounts, credit cards, and more using the victim’s good credit rating.

3.    Taking Over Someone Else’s Account

Account takeover occurs when a fraudster takes the victim’s account login information and adds themselves as authorized parties, giving them access to the victim’s banking facilities.

Fortunately, this type of fraudulent activity is steadily decreasing due to the widespread use of EMV chip readers.

4.    Medical Identity Theft

Medical identity theft occurs when fraudsters pose as patients to access certain prescribed drugs and have their medical care covered by the victim.

5.    Corporate Identity Theft

Corporate identity fraud occurs when a criminal tries to issue new lines of credit in the name of a company, sends clients fake bills, and then takes the payments themselves. This type of identity theft is most common in small businesses.

A cybercriminal may still manage to obtain your personally identifiable information even when you follow all the rules.

When a security breach occurs at an establishment with your personal information, you’ll need to find another way to keep your information and banking accounts safe.

Protect Yourself

Considering how many ways there are to target users online, it should come as no surprise that many are uneasy about their safety when surfing the net. Fortunately, you can safeguard your devices, protect your identity, and keep your browsing history away from prying eyes by installing reliable antivirus software.

Keep up with the latest developments, and if a corporation that stores your information is the target of a cyberattack, take swift action to protect your identity and safeguard your account.

Monitoring Tracking or Spying on a Cell Phone

Do you think of yourself as a spy and wonder how you can monitor another person’s cell phone? Well, we aren’t going to tell you that here, but we will give you some information about cell phone monitoring:

phone scamTracking Cell Phones: The Legal Stuff 

In most cases, it is not legal to monitor another person’s cell phone. However, and this is NOT legal advice, if the account is in your name, or if you have some type of written permission from the person owning the phone, you can track it.

Why Would a Person Monitor a Cell Phone?

There are certainly situations where it is perfectly legal, and maybe even useful, for someone to monitor a cell phone. One of these reasons is to monitor your family. This is generally the case if you have a teenager, for instance, who has some freedom.

Another reason why you might want to consider monitoring a cell phone is if you have a person in your family who is elderly, and they use a cell phone. For instance, if your loved one has the onset of dementia, it can be a very good idea to track their phone.

It is possible, too, that a company could be tracking a phone. It is very legal, for instance, for a company to track cell phones that they own. The main reason this happens is not only to monitor employee communication, but to also locate a device if it is stolen or lost.

Sometimes Spying on a Phone is Malicious in Nature.

In a Good Morning America spot I did years back, victims speak out about how their mobile phone being bugged made them paranoid. The perpetrators acted like the puppeteers and the victims their puppets.  Check it out.

The Main Ways Cell Phones are Tracked

There are four main ways that people use to track a cell phone:

  • Via a Carrier – Most major phone carriers have a feature that allows an account owner to track a phone that is on their account. There is usually a fee for this service, and it is definitely legal. This is a good way to track a family member.
  • Via a Computer or Smartphone – You can also track a phone via an app like Find My or Find My Friends. Just remember that the phone must be connected to GPS in order for this to work.
  • Via a Third-Party App – There are also apps that allow you to trace a phone, but to make it legal, you must have access to the phone you want to track, and even own it and/or have written permission from the person who owns it. In general, both the devices used in this tracking must have the app installed for these to work. Some of these apps might have free limited features, but others only are available if you pay a fee for the service.
  • Via a Link – This is likely very illegal, and it can even get you put into jail. Hackers often put these links in emails, texts, or social media posts. To do this, the device has to be infected with spyware and malware, which is installed when the link is clicked. Hackers buy this software from the dark web.

Remember, it is not legal to track a cell phone unless you have permission from the device owner. However, every state has laws pertaining to this, so you may want to look into the laws in your state if you are considering doing any of this. That way, you know what the consequences might be.

Written by Robert Siciliano, CEO of Credit Parent, Head of Training & Security Awareness Expert at Protect Now, #1 Best Selling Amazon author, Media Personality & Architect of CSI Protection Certification.

Keeping Your SMB Bring-Your-Own-Devices Secure

If you have a small or medium sized business, it is likely that you have staff who are bringing their tablets, phones, iPads, and laptops to work every day. However, all of this puts your business to risk as they can also bring malware into your network.

On top of this, any of these devices can be lost, misplaced, or stolen. Since its extremely likely that your staff are using these devices for their work, think about all of the information that could be on there about your company…and it happens because Joe in accounting left his cell phone on the counter at a local coffee shop, and a hacker picked it up.

Also, think about this: depending on how successful your company is, there also might be a list of clients found on the devices, or at least a few. Now, someone has access to your clients, and what is stopping them from contacting your competitors and sharing your sensitive company information…for a price, of course.

Hacking also often involves the act of phishing where an employee will open up an email and then click on a link or open an attachment. When this happens, malware is unleashed, and the device and network is at risk.

Here are some tips to keep devices secure that you can share with your staff:

  • Only use apps that have been purchased from a reliable source like iTunes or Google Play.
  • Do not reuse passwords and use a different password for each login that you have.
  • Keep all apps and operating systems updated. Any update that comes in should be downloaded and installed immediately. Don’t choose to update later, as this is a great opportunity for hackers to get into a vulnerable app.
  • Start using anti-virus software. These apps can be found in iTunes or in the Google Play store.
  • Be cautious when installing anything with a “free download.” Sometimes viruses and malware can be found there, and they can get out onto your network before you know it.
  • Choose the feature where device passwords are protected and wiped clean after a certain number of log-in attempts.
  • Make sure that all staff understands that free Wi-Fi spots are not secure. So, they should be using a VPN anytime they are trying to connect to a free Wi-Fi network.
  • Phishing scams are becoming more common than ever before, so make sure that your staff knows how to recognize scams like this.
  • Don’t trust email addresses that you don’t know and don’t trust any email that claims it is coming from the CEO or Board of Directors unless it’s an email that you can verify.
  • Do not use any device that is jailbroken. This opens it up to too many viruses.

Understanding MDM

Mobile device management software, or MDM, should be used. This software helps to protect devices, and it is a safety net for any type of business or personal device. For instance, if a mobile device is lost and the person who finds it tries to enter the passcode a certain number of times, the device will lock out the person doing it. You can also set it so that the entire device is erased if there are too many login attempts. MDM also offers firewall protection, encryption, and antivirus capabilities. Additionally, it can monitor the system to add another level of security. There should be a policy in place that every employee must use this software on their device, or they can’t use it.

Utilize Additional Experts

“Do it yourself” information security for small business in theory might seem to save a few bucks. But in the long run it might cost your small business a lot more. Engaging experts such as Managed Security Service Providers, or for smaller businesses, also known as a Virtual CISO’s (chief information security officer), can run the most comprehensive vulnerability scanning software among other ethical hacking tools, will make sure bad guy hackers can’t get in and make a mess of all you have worked for.

Written by Robert Siciliano, CEO of Credit Parent, Head of Training & Security Awareness Expert at Protect Now, #1 Best Selling Amazon author, Media Personality & Architect of CSI Protection Certification.

Teen Tragic Love: Lesson for Parents?

This story is kinda dark. Recently the ID Channel ran an episode called “Forbidden: Dying for Love — Together Forever, Forever Together.”

The 19-year-old was Tony Holt. Let’s call his 15-year-old girlfriend Kristen.

Kristen, 14, Falls Hard for Tony, 18

She met him when he was working at a grocery store. But he also happened to be a senior at her new high school. Prior to meeting him, Kristen knew her mother wouldn’t allow dating till she was 16.

Kristen’s mother eventually learned of the secret relationship and forbad it. The girl and Tony kept seeing each other on the sly. Mama learned of this and again, forbad it. Kristen then pretended the relationship was over and even talked of how she now hated Tony. Her mother was thrilled.

Meanwhile the teens kept sneaking around.

Forbidden love can be funner! Anyway, Mama found out again, stormed into the grocery store and angrily announced to Tony that if he ever went near her daughter again, she’d have him arrested for statutory rape. Which, is in fact statutory rape in many states.

The threat had him really scared about going to prison. He appeared at Mama’s house soon after and apologized for upsetting her and said that he and Kristen were going to cool it and just be friends.

But they continued seeing each other, and Mama discovered photos in Kristen’s bedroom of the two making out. More furious than ever, she forbad any contact. (Kristen’s father was out of the picture.)

Not long after, she got a call at work to come to the house. The police were there. Tony and Kristen were both dead from a gunshot wound to their heads.

A suicide note left by Kristen explained that the only way they could be together was to die and go to heaven where they could live happily ever after. Kristen had also left a suicide message on the answering machine, apologizing for the suicide pact. I’ll bet you didn’t see that one coming. Neither did I.

Questions to Wonder About

  • Why didn’t the teens decide to just avoid sex for three years, after which they could then marry and have up to 70 years of glory together? Abstinence is hardly an extreme move when you pit it against a murder-suicide.
  • What if Kristen’s mother permitted the relationship and even had Tony over every week for dinner? But what if, at the same time, she expressed her disapproval over their sexual relations?
  • What if she had said, “If you get pregnant, you’ll be grounded – by your baby. I won’t report statutory rape, but I also won’t help you out with the baby, either.”

That last warning may sound harsh, but it’s a crapshoot type of warning: It just might work.

Lessons Learned

  • You can’t stop two love-struck teens from seeing each other, so you may as well be civil to the unapproved young man.
  • While it’s important to stand your ground as a parent, there also comes a time when a sweet spot needs to be figured out. After all, not only might there be a suicide pact, but there are quite a few documentaries in which the forbidden young man murdered his girlfriend’s disapproving parents.
  • It’s never too early to teach your children the virtues of delayed gratification.

Robert Siciliano personal security and identity theft expert and speaker is the author of Identity Theft Privacy: Security Protection and Fraud Prevention: Your Guide to Protecting Yourself from Identity Theft and Computer Fraud. See him knock’em dead in this Security Awareness Training video.

10 Tips to Not Ending Up A Dead Real Estate Agent

Yes that title is awful and yes you should be offended. Real estate agents often find themselves in dangerous situations. And for 20 years, I’ve been screaming this, doing something about it, and it keeps happening. And the real estate agents and industries response?

Thots and prayers. Thots and prayers. Thots and prayers. Thots and prayers.

How’s that workin’ for ya?

Sometimes you have to visit unsafe neighborhoods, you might have to come face to face with a vicious dog, or even have an unsavory character walk right into an open house.

In 2016, approximately 3% of all real estate agents reported that they were physically attacked when on the clock. Though this might seem like a small number, you have to consider that only about 2% of the entire population of the country are physically attacked each year. This means, of course, that if you are a real estate agent, your odds of assault are higher than the average person.

Remember, no one is immune to this. Here’s a brief first person account posted to Facebook about a real estate agents experience…and it could even be you:

Another reason why I like running my real estate business by referral: Went to meet a female seller today who contacted me on-line. She told me she would meet me at her property as it is an occupied rental. She was there and so were about four guys. Small, cramped house. She told me the tenant would take me around as he knew the house better than her…. immediately I knew something was off.

He takes me around the first floor then he’s showing me upstairs and another guy who wasn’t one of the four downstairs appears out of nowhere and stands behind me. I’m now seriously freaking out as instinct told me something was about to happen. I made my excuses quick and went back downstairs. I put aside my manners and took out my phone and while chatting briefly with the seller, I text my location to my team. Then I left.

My 5ft 100lb self would have been no match for them.

I realized mid-way through that 10 minute tour that no-one knew where I was, I had no idea who these people were and if this woman actually was who she said she was.

Point of the story: realtors please be extra vigilant when being in homes of strangers. I know it sounds obvious yet it’s not as we are simply doing ‘our job’ and we can’t do that if we don’t visit other people’s homes. This ended well yet it could have been a very different story for me today. Stay safe and trust your instinct.”

The seller was a female, and the seller said that she would meet the agent at the property, as it was a rental and currently occupied. When the agent arrived, she saw the seller along with four men in a small, cramped house. The seller, herself, would not give the agent a tour of this home; instead, she said one of the tenants would take her.

REG FLAG.

Almost instantly, the agent knew something was weird about this. One of the men took the agent to the second floor, and before she knew it, there was another man directly behind her…and this man was NOT one of the men she had seen downstairs.

This was a very scary situation, and though this story did not end in disaster, plenty of these situations, do. Be smart, stay vigilant, and trust your instincts when something seems off.

Here are 10 tips that you can use to keep yourself from ending up a dead real estate agent:

  1. Research – Before you meet with a potential buyer, make sure to do a little research. This might be as simple as doing a Google search on them, or you can create a questionnaire to get information from them.
  2. Get an ID – Ask for the ID of any potential buyer/seller before showing the home. You should be able to get a photo of their ID and keep it on your phone and text it to a colleague just in case. If they refuse, this is a red flag.
  3. Show During Daylight Hours – Only show a home during daylight hours.
  4. Bring a Buddy – Do you have an assistant, friend, or family member who wants to keep you safe? Bring them along. When showing a home, try to bring a buddy. Make sure the buyer/seller knows that this other person is coming.
  5. Know What You are Going Into – Do your best to get a lay of the land when going into a home for the first time. Ask if there is anyone else in the home, too.
  6. Stay Near Exits – Make sure when you are showing a home, or being shown and home, that you always have an eye on the exit. Also, don’t go into any area, such as a basement, where someone couldn’t hear you if you had to yell for help. Unless you bring a buddy, and allow the buyer to take a look on their own, if necessary.
  7. Don’t Let Your Guard Down – Any person who walks into a home is a potential “bad guy/gal.” Don’t let your guard down, even if they seem like they are an upstanding citizen.
  8. Advertise Smartly – When advertising, make sure to do so smartly. Make sure that people know that viewing the home is by appointment only and that you will be checking their ID before showing the home.
  9. Dress Appropriately – Don’t wear any expensive jewelry when showing a home, and make sure to dress in a professional manner. Wearing clothing that is revealing, for instance, can send the wrong message.
  10. Trust Your Gut – Finally, trust your gut. If something seems wrong, it probably is.

Robert Siciliano personal security and identity theft expert and speaker is the author of Identity Theft Privacy: Security Protection and Fraud Prevention: Your Guide to Protecting Yourself from Identity Theft and Computer Fraud. See him knock’em dead in this Security Awareness Training video.

The Natural Predatory Nature of Humans

A study published in Nature shows us that both evolution and genetics have made a big impact on the behavior of humans…including in the case of murder. However, as we have become more civilized, these instincts have been muted.

Scientists have looked at the rate of homicide in more than 1,000 species, and they noticed something interesting: The rates of these lethal acts are similar, which means that evolution of each species can give us a good idea of how violent each species really is.

This study states that humans are part of a violent group of similar mammals. These mammals all evolved at the same time, together. Plus, all of these mammals have murderous and violent pasts. So, what does this mean for us? It means that we are violent today because our ancestors were violent.

When you look at all mammals, about three in 1,000 are murderers. However, when you specifically look at humans, the average over time is about 20 in 1,000. Furthermore, when you examine certain time periods, such as the medieval period, this rate rose to about 120 murderers in 1,000. These numbers have fortunately fallen, however, and today, it stands at about 13 murderers per 1,000 people.

So, we are killing each other much less frequently today than we used to 1,000 years ago. However, we are still not as peaceful as other mammals. For instance, killer whales, which we believe to be quite violent, have a murder rate of almost zero against their own species.

We are much more violent than whales, but when we compare our murder rates to those of cougars, baboons, or lemurs, we are less violent. All of these animals have a murder rate of about 100 per 1,000.

Since this research looked at violence by comparing species that are closely related, it is not surprising that these species are similarly violent. It is also interesting that the more closely related a species is, the more similar their instances of violence.

It’s quite difficult to actually calculate the rates of violence among our ancestors, but we are able to get a good idea thanks to archaeological evidence. It was found that by looking at these sites, that violence rates were lower among people who had some type of government or culture. This also suggests that murder rates among a species can be reversed. In fact, this evidence shows that it can decrease or increase based on ecological, cultural, or social factors. This evidence is similar to what was found in a study done at Harvard, which specifically looked at violent crimes including rape and murder.

When looking at these facts, we find that humans are territorial and social, but also naturally violent. As we have developed over time and found more civilized activities, our rates of violence have gotten lower. What’s even more interesting is that most mammals aren’t murderers towards their own species…but some, such as lions, wolves, and primates, which includes humans, engage in violent actions.

Robert Siciliano personal security and identity theft expert and speaker is the author of 99 Things You Wish You Knew Before Your Identity Was Stolen. See him knock’em dead in this identity theft prevention video.

Study Shows Millennials Choose Convenience Over Security

To those of us consider Tom Cruise the movie star of our day or even Grunge as the music we grew up with, looking at millennials, and the way they view life, is fascinating. These “kids” or young adults, many are brilliant. They really do define “disruption”.

However, that doesn’t mean that this tech savvy generation is always right. In fact, a new study shows just the opposite when it comes to internet safety. Though, they can also teach us a few things and are definitely up to speed on the value of “authentication” (which leads to accountability).

Anyway…South by Southwest, or SXSW, is a festival and conference that is held each year in Austin, TX. This year, a survey was done with some good AND scary results. The company that did the survey, SureID, found that 83% of millennials that were asked believed that convenience is more important than safety. That’s not good. But this is not the only interesting finding, however. On a positive note, the study also found the following:

  • About 96% want to have the ability to verify their identity online, which would ensure it was safe from hackers.
  • About 60% put more value on time than they do their money or safety.
  • 79% are less likely to buy something from a person who can’t prove their identity.
  • 70% feel more comfortable interacting with a person online if they can verify that other person’s identity.
  • 91% say they believe that companies “definitely” or “maybe” do background checks on those who work for them. These include on-demand food delivery and ridesharing. However, most companies do not do this.

What does this information tell us? It says that we are very close to seeing a shift in the way millennials are viewing their identities, as well as how they view the people and businesses they interact with.

Millennials have a need to want to better verify another person’s identity. To support this, just look at dating apps. Approximately 88% of people using them find the idea of verifying the identity of the people they might see offsite as appealing. It’s similar with ride sharing, where about 75% of millennials want to know, without a doubt, who is driving them around.

We live in a world today that is more connected than ever before. These days, as much as 30% of the population is working as freelancers, or in another type of independent work. In many cases, this work is evolving from small gigs to large and efficient marketplaces. Thus, the need for extra security and transparency is extremely important. Sometimes, technology helps us act too comfortably with people we don’t really know, and the study shows that having people prove whom they are will help to create higher levels of trust.

Robert Siciliano personal security and identity theft expert and speaker is the author of 99 Things You Wish You Knew Before Your Identity Was Stolen. See him knock’em dead in this identity theft prevention video.