What is Phishing?
Phishing is a deceptive technique used by malicious actors to trick individuals into revealing sensitive information such as passwords, credit card numbers, or personal data by posing as a trustworthy entity via email, websites, or messages. It exploits cognitive biases like authority and urgency to bypass rational decision-making and prompt quick, often risky, actions. In the digital landscape, phishing also undermines user trust and can significantly impact website credibility and SEO performance.
The Basic Idea
We’ve all been there. You’re checking your email when suddenly: jackpot! You’ve won a brand new iPhone 19 (does that even exist yet?) from a contest. You don’t remember entering, but your hopes are up because surely you must have entered something at one point, given how often you sign up for things online…
Or maybe you’ve had the privilege of being contacted by a Nigerian prince who needed your help moving millions of dollars out of the country. You’d never even been to Nigeria, and you’re not sure why he’d chosen you, but you were honored nonetheless. All he needed was your bank account, your Social Security number, and your eternal trust.
Or maybe it was one of the texts that we all seem to get on a weekly basis nowadays: your "bank" urgently needs you to confirm suspicious activity, or a “friend” sends you a weird link with no explanation. Whether they’re conveying reward, royalty, urgency, or just weird vibes, these messages all have one thing in common: they’re fake. And they’re not just annoying; they’re phishing attempts, one of the most common and costly forms of cybercrime today.
NO EASY CHOICES • EPISODE 2
Speed, Safety, and the Future of Fraud Prevention with Nicky Goulimis

Nicky Goulimis
Founder & CEO, TunicPay
I think we need to just arm consumers better and better - but that's just becoming less and less tenable as a path as these attacks get more and more complex. I'm more of a believer in systems-level solutions than pure individual solutions.
Phishing is a type of cyberattack where criminals impersonate trusted individuals or institutions to trick people into revealing personal information like login credentials, financial data, or even access to sensitive systems. These attacks typically come via email, text messages, or phone calls, and they often rely on psychological tactics like fear, urgency, or curiosity, as well as cognitive biases like the authority bias to get the victim to click a malicious link or download an infected attachment. Once the attacker has the desired information, they can access private accounts, steal identities, or carry out larger-scale breaches. In 2023 alone, phishing was responsible for billions of dollars in losses globally and remains the most reported cybercrimes.12
So why does phishing matter? Beyond the obvious financial toll, it’s often the gateway to more complex attacks. Hackers use phishing to breach corporate networks, compromise personal data, and spread malware. It’s a critical weak point in cybersecurity because it targets the one factor no firewall can completely control: human behavior. In short, phishing is dangerous not because systems are vulnerable, but because people are.
You might be wondering: isn’t phishing just another name for spoofing? Not quite. While the concepts are connected, they’re distinct. Spoofing refers to the “disguise” used by hackers—it's how the attacker fakes an identity, such as making an email look like it came from your boss or a trusted website. Phishing, on the other hand, is the con itself. It’s the attempt to trick you into taking the bait. Think of spoofing as putting on a convincing costume, while phishing is the actual scam that the costume is used to pull off. In many cyber attacks, spoofing is the method, and phishing is the mission.
“Passwords are like underwear: you don’t let people see it, you should change it very often, and you shouldn’t share it with strangers.”
— Chris Pirillo, American entrepreneur and technology personality
Key Terms
Spoofing: A deceptive tactic where a scammer disguises their identity, such as faking emails, phone numbers, or websites, to trick individuals into revealing sensitive information or taking harmful actions. Common in phishing attacks and cyber fraud, spoofing undermines trust in digital communications.1
Spear Phishing: A highly targeted form of phishing where attackers tailor their messages to a specific individual or organization, often using personal information to make the message more convincing.1
Social Engineering: A broad set of manipulative tactics that exploit traits of human psychology (like feelings of trust or urgency) to trick individuals into revealing sensitive information.1
Business Email Compromise (BEC): A phishing scam where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring money or sensitive information, typically via email.1
Malware: Any software intentionally designed to cause damage, steal data, or gain unauthorized access to systems. The name comes from “malicious software,” and it includes viruses, worms, spyware, trojans, and other harmful programs often delivered through spoofed or deceptive means.2
Ransomware: A type of malware that encrypts a victim’s files or locks them out of their system, demanding payment (often in cryptocurrency) to restore access. It frequently enters through spoofed emails or malicious websites and is used in both individual and large-scale attacks.2
History
The term “phishing” as we use it today dates back to the mid-1990s and originated as a form of social engineering aimed at exploiting human psychology to gain access to sensitive information.1 The word itself was coined by infamous hacker Koceilah Rekouche, also known by the pseudonym Da Chronic, and is a play on the word “fishing,” with “ph” referencing hacker culture that often used “ph” instead of “f” in names (like “phat” and "phreaking").3 This is also a nod to early phone hackers like John Draper, who manipulated telecommunications systems in the 1970s.3 The earliest known phishing attacks occurred on AOL.com in the mid-1990s, where hackers created tools to automate the process of impersonating AOL employees and tricking users into revealing their login credentials.3 One of the earliest documented phishing tools, called “AOHell,” was released in 1995 by Rekouche, who has since spoken about his role in the inception of phishing.3
As the internet expanded beyond AOL, phishing attacks migrated to email and websites, taking advantage of the growing popularity of online banking and e-commerce in the late 1990s and early 2000s. Criminals would send spoofed emails pretending to be from trusted institutions like banks or PayPal and then directing users to fake websites that captured their credentials.1,3 These attacks capitalized on the absence of widespread cybersecurity education and the novelty of online transactions. Perhaps the first major phishing attacks targeting financial institutions happened in 2003, when many companies suffered severe financial losses due to their vulnerabilities. This prompted the birth of organizations like the Anti-Phishing Working Group (APWG), designed to bring together industry and law enforcement to respond to the growing threat of phishing.2
As awareness and defenses increased, phishing attacks became more sophisticated. "Spear phishing," or highly targeted phishing, emerged in the mid-2000s, aimed at individuals or small groups within specific organizations.1 These attacks often used personal information to craft believable messages, leading to higher success rates. A notable example was the 2013 spear phishing attack on the retail chain Target, which compromised 40 million credit card numbers.4 But it’s not just commercial giants at risk: nation-state actors have also used phishing for cyber espionage. During the 2016 U.S. presidential election, for example, Russian hackers used spear phishing emails to gain access to the Democratic National Committee's emails while simultaneously spreading fake news about the legitimacy of American democracy. Attacks like these have highlighted phishing's potential geopolitical implications, which may continue to escalate as phishing technology improves.5
By the 2020s, phishing attacks had evolved to use artificial intelligence (AI) and machine learning to customize attacks at scale. Attackers now also use social media, text messages, voice calls, and fake websites to launch multi-platform phishing campaigns. Business Email Compromise (BEC) scams, where attackers impersonate executives to trick employees into sending money or data, have become one of the most financially damaging forms of phishing, with the FBI reporting losses in the billions annually.6 The COVID-19 pandemic, unfortunately, provided even more pretext for phishing, capitalizing on the chaos and uncertainty of the moment, with attackers impersonating health authorities, employers, and government agencies to exploit public fear and uncertainty.12
Despite increased awareness and widespread use of security technologies, phishing remains one of the most prevalent and effective forms of cyberattacks. Organizations and governments continue to invest in user training, threat detection, and authentication protocols like multi-factor authentication to combat it. Key figures in the ongoing fight include cybersecurity researchers like Markus Jakobsson, who has published extensively on phishing mitigation strategies, and groups like the APWG, which tracks phishing trends globally.2 As AI becomes more advanced and generative adversarial networks improve the quality of AI-generated sound and video, experts warn of “deepfake phishing,” in which synthetic audio or video may be used to impersonate trusted figures more convincingly than ever before. The history of phishing is ultimately one of adaptation, where defenders and attackers continually escalate in a high-stakes digital arms race.
behavior change 101
Start your behavior change journey at the right place
People
Mary Aiken
A renowned cyberpsychologist whose work explores the intersection of human behavior and technology, including the psychological manipulation involved in phishing. Her research has highlighted how cybercriminals exploit emotional triggers like fear, urgency, and trust, which are core tactics in successful phishing schemes. Aiken’s insights help explain why people fall for digital scams despite growing awareness and technological safeguards.7
John Draper
Also known as “Captain Crunch,” Draper was a legendary figure in early hacking culture and a pioneer of phone phreaking, a precursor to modern digital exploits like phishing. Although he wasn’t directly involved in phishing, his manipulation of telecommunications systems in the 1970s laid the groundwork for the kinds of social engineering and system exploitation tactics that phishing later adopted. His work marks an important historical moment in the evolution of hacking and online fraud.3
Koceilah Rekouche
Computer expert credited with coining the term “phishing” in the mid-1990s in the documentation of his “AOHell” application that targeted AOL users. He helped develop early phishing tactics that involved sending fake messages to trick people into revealing passwords and personal information. Rekouche’s role is pivotal in the history of phishing, marking the shift from amateur mischief to organized digital deception.3
Markus Jakobsson
A leading expert in phishing and online fraud, and co-author of the influential book Phishing and Countermeasures. His research helped establish the link between email spoofing and social engineering, offering scientific methods to detect and prevent such attacks. Jakobsson's contributions have shaped both academic research and practical anti-spoofing tools used today.2
Joseph Blount
The CEO and retired President of Colonial Pipeline. It was during Blount’s time as president that the infamous May 2021 spoofing and ransomware attack on the company occurred, where hackers exploited a legacy VPN account lacking multi-factor authentication to infiltrate Colonial Pipeline's network, leading to a shutdown of critical fuel infrastructure and a $4.4 million ransom payment.14
Impacts
Phishing isn’t just a technical problem; it’s a psychological and economic one. Its success hinges on the exploitation of human cognitive biases, resulting in both personal devastation and large-scale financial and reputational damage for individuals, businesses, and governments alike.
Exploitation of Cognitive Biases
You may be asking yourself: how do so many people fall for these scams? Isn’t it obvious that the messages are fake? Well, hindsight is 20/20. Phishing attempts are often successful because scammers leverage the power of several cognitive biases. For example, attackers often pose as trusted figures like celebrities, the police, IT departments, the individual’s boss, or a CEO. This exploits the authority bias, which describes our tendency to be more influenced by the opinions and judgments of authority figures, often without critically evaluating the content of what they’re saying. The requests from someone important are often paired with an “act now or lose access!” message or even suggest an immediate emergency.
This activates feelings of scarcity or worry for ourselves and others, creating panic and causing people to bypass rational thought. Imagine if you got an email from someone who appeared to be your best friend, claiming they were being held at gunpoint and needed you to send over a ransom right away. You’d likely rush to do everything you could to help them. The high stress of the situation could make it easier to miss subtle details, like their email address being spelled wrong, which would normally tip you off. We’re also programmed towards an action bias, wherein we often feel compelled to act, even when we lack evidence to suggest that our action will be helpful.
Belief perseverance describes our tendency to continue to hold onto established beliefs even when faced with clear, contradictory evidence. Once we’ve been “hooked” by a phishing attempt, it’s hard to move on; this bias suggests that we tend to prioritize our initial conclusions and resist changing our minds, even when it might be in our best interest to do so. The consistency bias also follows from our tendency to stay engaged with something once we’ve started. Many salespeople use this tactic, knowing that people are more likely to follow through on something once they’ve engaged.
Major Personal Financial Loss
At the individual level, phishing can result in devastating financial consequences, often unfolding within mere hours of clicking a malicious link. When victims unknowingly hand over their login credentials or other personal information, attackers can then use this to drain people’s bank accounts, rack up tons of credit card debt, access their personal files, or even open new credit cards or bank accounts. The Federal Trade Commission (FTC) consistently ranks identity theft and impostor scams (which often begin with phishing emails or texts) among the top forms of consumer fraud in the United States.9 Recovery from identity theft is usually slow and painful, with victims spending months disputing charges, freezing credit, trying to restore compromised accounts, and arguing with their banks.
Stolen credentials obtained via phishing are usually sold on the dark web or reused to infiltrate systems. People often store some of their most personal information on their devices, and if that info gets into the wrong hands, the effects can be disastrous. Depending on the person, phishing can lead to leaks of personal, corporate, or even state secrets. Criminals may target people whom they know might be holding valuable financial or political intel on their devices, or they might go after individuals with a lot of funds to spend on a ransom. With the right photos or data, or even by simply locking someone out of their accounts, a criminal may find an opening for blackmail, just so that the person can get their data back.
When my partner had his phone stolen in Peru, the thief got into his phone and used it to access his email, bank account, investment apps, Venmo, and credit card. This began a nonstop nightmare of us calling his bank, phone company, and every associated application to try to freeze any outside access to his accounts and stop all purchases from going through. Every time we called one of the customer service centers (which always involved a very long hold on the phone), we were promised that all charges would be frozen. But then, ten minutes later, we’d see a new credit card charge come through from the thief trying to purchase something. Because this villain had access to the card application, every time an email came through that said “we are now pausing your card,” they would go into the app and undo it.
The same was true every time we tried to change the password to one of his accounts; the thief would see the “password change request” email come through and delete the security code before we could get to it, eventually locking my partner out of even his email. After many months of arguing with the different banks and applications holding his funds captive, the end result was less horrible than we feared; besides losing a brand new phone, he’d lost everything in a small stock trading app and his Venmo account balance. Not good, but in the scheme of identity fraud, he got off pretty easily.
Large-Scale Theft, Reputational Damage, and Economic Consequences
On a larger scale, phishing poses significant threats to organizations, from small businesses to multinational corporations. Attacks often begin with a single compromised email or an account that enables hackers to penetrate deeper into internal systems. Business Email Compromise (BEC), a subtype of phishing where attackers impersonate executives or vendors to trick employees into transferring funds, is one of the most financially damaging types of cybercrime. According to the FBI’s Internet Crime Complaint Center, losses from BEC scams reached a staggering $43 billion globally between 2016 and 2022, with a sharp increase during the pandemic years due to remote work vulnerabilities.6 Phishing is also the primary delivery method for ransomware attacks, which can wreck businesses in much the same way as they can destroy the lives of individuals. A ransomware attack can halt all operations (especially if employees are locked out of their business accounts) and force organizations into multi-million-dollar payments, further compounding losses.
These types of large-scale attacks often make the news, and for most brands, a single phishing-related breach can lead to user loss, media scrutiny, and declining share value. If you remember the Change Healthcare cyberware attack, you’ll know that this was not only costly for the company, but thousands of people’s personal and highly sensitive health data were leaked.9 As a result, users are not only scared of being attacked themselves, but also hesitant to trust the institutions that are supposed to be responsible for keeping our information safe. Whether it’s banks, retailers, or the government, general trust and security erode with each new phishing scheme.
Beyond individual and organizational losses, phishing contributes to broader economic instability and cybersecurity costs. Financial institutions must absorb fraud-related expenses, increase spending on fraud detection, and pay for insurance premiums, all of which may be passed on to consumers. Government entities have also faced large-scale phishing attacks targeting unemployment systems, stimulus programs, and even election infrastructure, draining public funds and undermining public trust. Moreover, phishing incidents often incur indirect costs such as legal fees, regulatory fines, customer churn, and the need for extensive post-breach remediation. As phishing tactics become more sophisticated—leveraging AI-generated emails, deepfake audio and video, real-time realistic responses to customers, and compromised cloud systems—the financial risks continue to escalate, demanding more robust countermeasures that focus not just on the technology, but also on how we regulate large-scale attacks.1,3
Controversies
Once again, phishing is more than a personal cybersecurity issue; it’s a systemic challenge shaped by digital inequality, collective social behavior, and platform design. Understanding who is most vulnerable, how phishing spreads, and what protective steps we can take is essential to building a safer digital environment for everyone.
Digital Inequality
Digital inequality, defined as the unequal access to and ability to use information and communication technologies, plays a significant role in determining who is most vulnerable to phishing attacks. Populations such as older adults, people with low digital literacy, and those from socioeconomically disadvantaged backgrounds are disproportionately affected. If you’ve ever spoken to a grandparent about the emails or calls they get, which seem like an obvious scam to you but are confusing for them, you may be concerned that older individuals are particularly susceptible to phishing, and research confirms this. Due to cognitive decline, unfamiliarity with digital environments, and a greater tendency to trust authority figures in messages, older adults are more likely to fall victim to these schemes.10
Similarly, people with limited education or minimal internet experience may not recognize phishing cues like URL mismatches or suspicious attachments. As a result, these groups are more likely to click on malicious links or provide sensitive information without hesitation, making them prime targets for cybercriminals. The interconnectedness of wealth, level of education, and factors like ethnicity means that those who are already some of the most disenfranchised are taken advantage of at an even higher rate than other populations.11
Like many socioeconomic issues, those who start with wealth are largely protected from the worst-case scenarios, or at least have an easier time getting back on their feet. The disparity in digital skills directly translates into a gap in cybersecurity preparedness, a phenomenon that the COVID-19 pandemic starkly exposed.12 While wealthier, more digitally literate users adopted multifactor authentication, password managers, and phishing awareness training, lower-income and marginalized users often lacked the knowledge, resources, or institutional support to do the same.11
Many phishing campaigns have been tailored to exploit these gaps. For instance, fake government aid emails, job scams, and phishing SMS messages during the pandemic were designed to appeal specifically to financially distressed or low-literacy populations.12 Once a victim’s information has been stolen, those with the resources to hire investigators or pay for expensive cybersecurity software can more quickly return to their daily life (and have a higher chance of recovering some of what they’ve lost) than those without the connections or means.11
Addressing this inequity requires us to rethink how cybersecurity awareness and protections are distributed. Public health-style campaigns like those we saw during COVID-19, simplified security tools (so that even grandparents can understand), and community-based digital literacy programs are key to reaching underprotected populations. We can also leverage the power of behavioral science by designing default protections (like browser phishing filters and AI-based threat detection) that minimize user burden, particularly for those unable to recognize threats on their own.12 Scholars like Mary Aiken have argued for a more inclusive “cyber-psychology” approach that considers social and psychological vulnerabilities alongside technical ones.7 As phishing attacks continue to evolve, any serious response must include structural efforts to close the digital divide and ensure that cybersecurity is not a privilege, but a baseline right for all.
Collective Behavior and Social Contagion
The early days of phishing usually involved suspicious emails or deceptive websites. While these common spoofing tactics still exist, phishing increasingly operates through social channels where peer-to-peer communication accelerates its spread. Social media sites like Facebook, WhatsApp, Instagram, and TikTok have become fertile ground for phishing attacks that piggyback on trusted relationships. When people receive a direct message or a link from their friend or family member, they’re obviously far more likely to trust the message. Again, thanks to the impact of urgency, when the message is framed as highly emotional, people often engage with the message with less skepticism than usual. Some studies have found that phishing campaigns on social media often exploit pre-existing trust within networks, spreading in patterns that mirror epidemiological contagion.3,7 Thus, phishing isn’t just about technical viruses—it’s also a behavioral issue that thrives on our human social habits.
Phishing’s viral success on social platforms is also explained by psychological principles like social proof, which is our tendency to assume that behaviors or information are correct if others around us endorse them. When users see that a link has been liked, shared, or commented on by others (especially if those others are people in our social circle), they infer legitimacy, even when the content is malicious.
If this reminds you of the way rumors tend to spread at school or work, you’ve caught on to a key pattern. The dynamics of rumor propagation, where repetition and familiarity increase perceived truthfulness, are very similar to the way phishing schemes and fake news can spread.5 Attackers often craft phishing messages to mimic the hottest trends or memes, which makes it even more challenging to identify what’s real and what’s not. Even the most tech-savvy among us may fall victim if a message taps into our pre-existing beliefs (confirmation bias) or strong emotions like political outrage or our fear of missing out.
Now that we’ve acknowledged that phishing schemes are often perpetuated via social contagion, there are some very important questions that arise about platform design and responsibility. The same algorithms that prioritize engagement and virality can simultaneously amplify malicious content. Some researchers argue that platforms should adopt behavioral countermeasures, such as adding warnings before sharing suspicious links or increasing visibility controls on forwarded content. The instant messaging platform WhatsApp actually implemented such measures after misinformation-fueled violence in India. The platform limited the number of times a message can be forwarded (which has also been shown to help slow phishing).13 Once again, phishing thrives not just because of individual technical error, but because it leverages collective social dynamics.
How to Protect Yourself from Phishing Attempts
What can you do right now to keep yourself (and your family and business) safe from phishing attacks? The first and most essential step is to use a robust spam filter. Most major email platforms today, like Gmail and Outlook, have built-in filters that catch a significant portion of phishing attempts before they ever reach your inbox (thanks, email!). However, the systems aren’t perfect. If a phishing email does sneak through, you might not catch it right away, especially because it was sneaky enough to get through your email spam filter. Look carefully at the sender’s email address. Phishers often use spoofing tactics to impersonate trusted institutions, but use email addresses that don’t match the organization. They might have a contact name like “Apple Support,” but you’ll see that it’s actually coming from a string of random characters at gmail.com. That’s a scam, don’t respond to it.
Phishing texts often work the same way. A message might claim to be from the IRS or Amazon, but the sender's number is just a generic phone number or an unfamiliar short code. I usually get WhatsApp messages that claim I have a package being held up at Customs, but why would the international border be texting me from “420Ja”? These messages will usually contain links urging you to “act now” or “verify your account.” Avoid clicking links or downloading attachments from any message (email or text) that you didn’t expect, even if it sounds urgent. If there is an attachment, it’s wise to check the file extension before opening it. Phishing documents often hide malware in what appear to be PDFs or Word files but are actually disguised executables (like .exe or .scr). When in doubt, trust your instincts: if something feels off, it probably is.
Another important rule of thumb is to avoid responding directly to the phishing message, even if you’re just trying to question its authenticity. Just responding to ask “who is this?” can be enough to alert scammers that there’s a real person attached to your phone number. Instead, go directly to the supposed source. If your “bank” emails you asking to verify a transaction, don’t click the link in the email. Open a new browser tab or use your bank’s official mobile app to check your account independently. You can also call the customer service number on the back of your debit card or on the bank’s official website. Most legitimate companies will never ask for sensitive information like passwords, PINs, or Social Security numbers over email or text.
Finally, installing anti-malware and antivirus software is a simple and powerful safeguard. These tools can often detect and block malicious attachments or redirect attempts, acting as a second line of defense if you accidentally click a bad link. Even free antivirus programs can scan incoming files or flag suspicious downloads before they execute harmful code. Particularly if you manage a team or organization, cybersecurity training is essential for everyone on your team. Not just once, but on an ongoing basis, because phishing tactics evolve quickly, and staying informed is vital to staying protected.
Case Studies
The 2021 Colonial Pipeline Attack
In May 2021, millions of Americans got a harsh wake-up call about just how devastating a cyberattack can be. Colonial Pipeline, one of the largest fuel suppliers in the United States, was hit by a crippling ransomware attack that forced it to shut down operations after hackers compromised its business network and billing system.14 Although ransomware did the bulk of the damage, the attackers wouldn’t have been able to get as far as they did without first stealing an employee’s password, most likely through a phishing email. It’s hard to imagine that one simple breach, perhaps an email from a sender spoofing a secure source asking for confidential password information, could be responsible for so much damage. While the oil company was essentially locked out of its own infrastructure, the group responsible for the attack demanded an exorbitant ransom to regain access.14
Colonial Pipeline’s CEO, Joseph Blount, ultimately decided that the best move for the country as a whole was to pay the ransom. Thus, although defining an exact cost for the breach is nearly impossible, we do know that the company ultimately paid $4.4 million for a decryption key to regain access to its data. But the pipeline itself supplies nearly half of the East Coast’s fuel, and because it stayed offline for about a week, the delivery of an estimated 20 billion gallons of oil was delayed. That much oil is worth over $4 billion, and the shutdown inevitably triggered a sharp spike in gas prices and left over 10,000 gas stations dry, even after operations resumed.14 Perhaps the impact this breach had on the U.S. economy will be enough to “fuel” efforts to improve security against future malicious spoofing and phishing-driven breaches.
The Google and Facebook Phishing Scam
Between 2013 and 2015, Google and Facebook fell victim to one of the most successful phishing attacks in history, losing a combined total of over $100 million to a single scammer.15 The attacker was a Lithuanian man named Evaldas Rimasauskas who had posed as a representative of a company called Quanta Computer. This spoofing attempt was well-planned because although he did not actually work there, Quanta Computer was a legitimate Taiwanese hardware supplier that both tech giants regularly did business with. Rimasauskas created fake email addresses and invoices that looked very similar to those of Quanta, then sent them to the finance departments at both companies. Because the emails appeared authentic and referenced real business relationships, they passed internal checks at the companies, ultimately leading to the transfer of large sums of money into bank accounts which were secretly controlled by Rimasauskas.15
What made this phishing scam particularly effective was its spear-phishing approach. The targeted and personalized deception of the specific Google and Facebook employees who handled invoices and payments led them to fall right into his trap. Rimasauskas further legitimized the scheme by forging supporting documents, including contracts and corporate stamps, and even setting up a fake company with a nearly identical name. He then laundered the stolen funds through multiple bank accounts across Eastern Europe. The scam was eventually uncovered by investigators, and Rimasauskas was arrested in 2017 and later pleaded guilty to wire fraud and money laundering.15
Related TDL Content
How to Protect An Aging Mind From Financial Fraud
Because older generations are so often the targets of financial fraud, and because older minds are often more susceptible to phishing schemes, it’s extra important for aging minds to protect themselves from fraud. This article outlines why older populations are more susceptible to financial fraud, as well as research on how to alter our decision-making environments to protect ourselves from such attacks.
The Human Error Behind Fake News with David Rand
Phishing attempts are often about deceit, and the rise of the internet has led to an abundance of new scams and misinformation. In this podcast episode, David Rand, professor of Management Science and Brain and Cognitive Sciences at MIT, discusses his research on misinformation, aiming to understand why people believe fake news, why it is spread in the first place, and what people can do about it.
Sources
- Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 3. https://doi.org/10.3389/fcomp.2021.563060
- Jakobsson, M., & Myers, S. (2006). Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. MIT Press.
- Rader, Marc & Rahman, Shawon. (2015). Exploring Historical and Emerging Phishing Techniques and Mitigating the Associated Security Risks. International Journal of Network Security & Its Applications. 5. 10.5121/ijnsa.2013.5402.
- Reuters. (2017, May 24). Target settles 2013 hacked customer data breach for $18.5 million. NBC News. https://www.nbcnews.com/business/business-news/target-settles-2013-hacked-customer-data-breach-18-5-million-n764031
- Office of the Director of National Intelligence. (2017). Assessing Russian activities and intentions in recent US elections: The analytic process and cyber incident attribution (ICA 2017-01D). https://www.dni.gov/files/documents/ICA_2017_01.pdf
- Federal Bureau of Investigation. (2022, May 4). Business Email Compromise: The $43 billion scam (I-050422-PSA). https://www.ic3.gov/PSA/2022/psa220504
- Aiken, M. (2016). The cyber effect: A pioneering cyber-psychologist explains how human behavior changes online. Spiegel & Grau.
- Federal Trade Commission (FTC). (2023). Consumer Sentinel Network data book 2022. https://www.ftc.gov/system/files/ftc_gov/pdf/CSN-Data-Book-2022.pdf
- Alder, S. (2025, April 16). UnitedHealth adopts aggressive approach to recover ransomware attack loans. HIPAA Journal. https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/
- James, B. D., Boyle, P. A., & Bennett, D. A. (2014). Correlates of susceptibility to scams in older adults without dementia. Journal of elder abuse & neglect, 26(2), 107–122. https://doi.org/10.1080/08946566.2013.821809
- Ogunola, A., Sonubi, T. O., & Toromade, R. O. (2024, November). The intersection of digital safety and financial literacy: Mitigating financial risks in the digital economy. International Journal of Science and Research Archive, 13(2), 673–691. https://doi.org/10.30574/ijsra.2024.13.2.2183
- Interpol. (2020). INTERPOL report shows alarming rate of cyberattacks during COVID-19. https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19
- Newton, C. (2020, April 7). WhatsApp puts new limits on message forwarding to fight spread of misinformation. The Verge. https://www.theverge.com/2020/4/7/21211371/whatsapp-message-forwarding-limits-misinformation-coronavirus-india
- Eaton, C., & Volz, D. (2021, May 19). Colonial Pipeline CEO tells why he paid hackers a $4.4 million ransom. The Wall Street Journal. https://www.wsj.com/tech/cybersecurity/colonial-pipeline-ceo-tells-why-he-paid-hackers-a-4-4-million-ransom-11621435636
- Department of Justice. (2019, March 20). Lithuanian Man Pleads Guilty To Wire Fraud For Theft Of Over $100 Million In Fraudulent Business Email Compromise Scheme. U.S. Attorney’s Office, Southern District of New York. https://www.justice.gov/usao-sdny/pr/lithuanian-man-pleads-guilty-wire-fraud-theft-over-100-million-fraudulent-business



















