Former FBI Agent, Eric O’Neill on Spies, Lies, and the Cyber Wars We’re Already Losing

29 Oct 2025 · 58 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The James Altucher Show: Episode Summary

Episode Title Former FBI Agent, Eric O’Neill on Spies, Lies, and the Cyber Wars We’re Already Losing

Episode Description In this episode, James Altucher interviews Eric O’Neill, a former FBI counterintelligence operative. O’Neill is best known for capturing Robert Hanssen, a double agent who compromised U.S. intelligence for over two decades. The conversation delves into the chilling realities of modern cyber warfare, how hackers exploit human psychology, and practical advice for safeguarding one's data in the digital age.

Key Themes and Concepts

  1. The Capture of Robert Hanssen
  2. Background: Hanssen was the FBI’s top analyst on the Soviet Union while secretly spying for the KGB.
  3. Operation: O’Neill recounts the intricate and risky undercover operation to catch Hanssen, drawing on his skills in elicitation and social engineering.
  4. Consequences: Hanssen's actions caused significant damage to U.S. intelligence, leading to the loss of all assets in the Soviet Union during the 1984-85 period.
  1. The Shift from Espionage to Cybercrime
  2. Modern Espionage: O’Neill explains how espionage has transitioned online, with cybercriminals using sophisticated tactics to exploit vulnerabilities.
  3. Human Manipulation: Emphasizes that modern cybercrime often relies more on manipulating human behavior than on technological hacking.
  1. The Dark Web vs. Deep Web
  2. Definitions:
  3. Deep Web: Refers to the vast majority of the internet not indexed by search engines, including secure data like medical records and banking information.
  4. Dark Web: Part of the deep web where illegal activities occur, including marketplaces for drugs, weapons, and human trafficking.
  5. Psychological Impact: O’Neill shares alarming statistics about crime on the dark web, highlighting how human trafficking and body part sales occur.
  1. Cybersecurity Threats and Solutions
  2. Ransomware: O’Neill discusses the rise of ransomware attacks on businesses, including high-profile cases like MGM Resorts.
  3. AI in Cybercrime: The integration of AI technologies in facilitating cyber attacks, such as using deep fake technology to manipulate victims.
  4. Protective Measures:
  5. Importance of adopting two-factor authentication.
  6. Setting up code words with family members to verify identity in distress calls.
  7. Regularly updating software and being vigilant about phishing attacks.

Key Takeaways

  • Psychological Manipulation is a primary driver behind successful cyber crimes.
  • Awareness and Education are crucial in protecting against cyber threats. Knowledge about potential scams can significantly reduce vulnerability.
  • Real-life Applications: O’Neill provides practical steps individuals can take to secure their data and identity, emphasizing that everyone is a potential target.
  • The Ongoing Danger: The episode concludes with a stark reminder of the evolving nature of cyber threats and the necessity for continuous vigilance.

Timestamped Highlights

  • [00:00] Introduction to the episode and its themes.
  • [02:15] Who is Eric O’Neill? Overview of capturing Robert Hanssen.
  • [13:10] Transition from traditional espionage to cybercrime.
  • [17:30] Clarification of the dark web vs. deep web.
  • [22:00] Focus on why hackers target individuals rather than systems.
  • [32:15] Discusses AI's role in modern scams.
  • [37:55] Recognizing phishing attacks and digital traps.
  • [54:05] The future of cyber warfare and personal protection.

Additional Resources

  • Books by Eric O'Neill:
  • [Spies, Lies, and Cybercrime: Cybersecurity Tactics to Outsmart Hackers and Disarm Scammers](https://www.amazon.com/Spies-Lies-Cybercrime-Cybersecurity-Outsmart/dp/0063398176/)
  • [Gray Day: My Undercover Mission to Expose America’s First Cyber Spy](https://www.amazon.com/dp/B07FZP16V8)
  • Film: [Breach (2007)](https://www.amazon.com/Breach-Chris-Cooper/dp/B009CFY802/)
  • FBI Official Case Summary: [Robert Hanssen Espionage Case](https://www.fbi.gov/history/famous-cases/robert-hanssen)
  • Eric O’Neill Official Website: [ericoneill.net](https://ericoneill.net/)

This episode not only highlights critical cybersecurity issues but also offers a thrilling narrative about espionage, making it a compelling listen for anyone interested in the intersection of technology and national security.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00What can 160 years of experience teach you about the future? When it comes to protecting what matters, Pacific Life provides life insurance, retirement income, and employee benefits for people and businesses building a more confident tomorrow. Strategies rooted in strength and backed by experience. Ask a financial professional how Pacific Life can help you today. Pacific Life Insurance Company, Omaha, Nebraska, and in New York. Pacific Life and Annuity, Phoenix, Arizona. Today on the James Altucher Show. They asked me to go undercover to catch Hansen in the most unique case the FBI had ever run in a job that I was never trained to do.

0:41It was a folder, and in it was a cassette tape, a trash bag, and a bunch of letters. And you try to catch the most notorious spy on Earth with that. During the Cold War, he gave up our entire nuclear warfare plan and our continuity of government plan. So the Soviets would have known where to hit us with nukes, where we were going to fire, and where our nuclear arsenal was, and where we'd send the president, vice president of Congress, and everybody in politics. That matters. Between the years 84 and 85, we call it the year of the spy in intelligence circles, we lost every single asset in the Soviet Union.

1:16All of them. We had no spies. We were completely blind during the Cold War. In the espionage game, we were losing the Cold War, which a lot of people don't know. This isn't your average business podcast, and he's not your average host. This is the James Altucher Show.

1:43Oh my gosh, I am scared. I learned in this episode all about what's really on the dark web. Also, kind of the scary stuff was on what's called the deep web. So Eric O 'Neill, he was the FBI guy who brought down Robert Hansen, who was the biggest double agent in US history, was an FBI guy, the FBI guy in charge of researching the Soviet Union. And he was actually working for the Soviet Union at the same time for 22 years. Eric O 'Neill is the guy who brought him down. There was a movie made about it called Breach in 2007. Anyway, he wrote the book, Spies, Lies, and Cybercrime, Cybersecurity Tactics to Outsmart Hackers and Disarmed Scammers.

2:29And it is scary what is out there right now. And I'll let Eric tell the stories.

2:41Well, Eric, thank you for joining us. Thank you for having me. It's an honor. Your book, Spies, Lies, and Cybercrime. I've read a lot of books on cybersecurity. I've been involved in the internet, obviously, like everyone else for decades. This was the most comprehensive and scariest book I have ever read about what is happening in the world right now. Plus, connecting the dots, I didn't know at first you were the guy who took down Robert Hansen, the most infamous FBI, you know, anti-US spy ever. Like he was working for the KGB for 22 of the 25 years. He was working for the FBI and you brought him down.

3:22Yeah. So Hansen spied against the United States for 22 of his 25 year career. He spied so long. He began with the KGB, survived the collapse of the Soviet Union and the reformation into the Russian Federation. And that was unique because that's when we were catching all the Cold War spies, and then reactivated himself and started spying for the SVR. And at one point, the GRU, so he spied for everybody over there in Russia, and they never knew his identity. That's how good he was. When the Soviet Union collapsed and they just handed over the names of everybody who was spying for the Soviet Union, how come we didn't catch them then?

3:55So what happened was a lot of these former KGB intelligence officers did what they were trained to do. And they were out of a job. They were kicked out of their job and they were mad. They were disgruntled employees, so they stole information from file cabinets and handed it over. It just so happened, Hansen was fortunate because the guy who stole his file decided to just throw it up in his attic for a rainy day. And he didn't give it up until years later when he was ready to retire to somewhere warm. So he let it be known to a joint CIA-FBI task force that he had a file of information that might point to the most legendary spy the FBI had ever hunted.

4:32A spy only known by the code name Gray Suit said, I might have some information you want. It was this slim file of information. It was a folder. And in it was a cassette tape, a trash bag, and a bunch of letters. And you try to catch the most notorious spy on earth with that. But it looked good to the FBI. They bought it for over$14 million, gave this guy witness protection. He moved with his family somewhere warm in the US, I can't say. Because, you know, Putin would feed him a plutonium muffin the next morning if he knew where he was. And then the FBI was able to piece together with just that slim bit of information that Robert Hansen was the spy that they'd been hunting all these years.

5:11And in that little room of agents and CIA officers, hearts completely fell. Because Hansen wasn't just the most damaging spy and our first cyber spy. He was also this Russian analyst that was asked to catch himself. They brought him on board as the top Russian analyst and said, we've been hunting the spy for all these years. Do you know who it could be? Could you make us a list? And he sent the FBI on years of wild goose chases. And they didn't do that as a tactic, like let's ask the spy himself to catch himself. Like that wasn't sort of a tactic to see if, like they just didn't have no idea it was him.

5:46They had no idea it was him. He was the top analyst on the Soviet Union. That was his job, was counterintelligence to catch spies. So realistically, how much damage did he do in his 22 years in our efforts to spy on the Soviet Union and Russia? The worst damage. His damage is in the billions, and it took the FBI years to correct. In fact, they're still fixing a lot of the problems he caused. He gutted the FBI from inside, but he also was able to get on tax forces with other agencies, steal their information. And just some idea of the threat. During the Cold War, he gave up our entire nuclear warfare plan and our continuity of government plan.

6:26So the Soviets would have known where to hit us with nukes, where we were going to fire, and where our nuclear arsenal was, and where we'd send the president, vice president of Congress, and everybody in politics. That matters if there was a catastrophic war. They could have taken out everybody. And did he give up any names of any spies that were in the Soviet Union? Like, were any lives lost of spies? Oh, he did. between the years 84 and 85, we call it the year of the spy in intelligence circles. We lost every single asset in the Soviet Union, all of them. We had no spies. We were completely blind during the Cold War.

7:02In the espionage game, we were losing the Cold War, which a lot of people don't know. And Hansen shares those losses, deaths, and some were pressed into hard labor with another spy in the CIA called Aldrich Ames. And because they were giving up some similar information to the spy masters over in Moscow. That was golden intelligence. It was corroborated from two separate sources. Wow. And then, so when they first started suspecting him, they kind of packaged you to be his quote-unquote assistant. Like you were sort of hired or however they placed people, they told Robert Hansen, oh, here's your new assistant.

7:39They didn't know you were going to basically be the spy investigating him. Well, no, this is the craziest story. So they had a big problem with Hans. They learned about him in December of 2000. He's going to retire April 2001 with a mandatory retirement of 25-year veterans, gold wash, pension, all that. And they had to keep him in the FBI because they only had circumstantial evidence. There's evidence that was given by a source. And, you know, he could get a great attorney who says that source is compromised. That's the SBR, Russian intelligence, trying to besmirch my reputation, all that. So they had to give him essentially his dream job.

8:17And they said, we're going to put you in charge of a new section we've developed at FBI headquarters. And we're giving you a promotion to executive service. And we're going to give you staff. And you're going to build cybersecurity for the FBI. Because you're the only guy who knows how to do it. And he was flattered. Everybody knew he was a narcissist. And what he should have done is just retired. But he took the job and probably thinking, I can spy more now. And now I have access to everything. I have access to the data center and make one last, you know, big push and get one last payout, which, of course, is what the FBI wanted him to do so we could catch him red-handed.

8:53And then the FBI looks around the FBI to find a trained undercover operative who knew how to go do this kind of investigation face-to-face, having a conversation, what we call elicitation. You know, we're having a conversation, James, and you think we're just having a friendly conversation, but really my job is to pull information out of you without you knowing. Am I the investigator right now? I'm not a spy for anybody. You would be the spy, right? And I'm the investigator. You're the investigator doing the same thing. You're doing an elicitation campaign. The only thing, we both know what we're going after.

9:24But here, they couldn't find a trained elicitation undercover op that could do the job and turn on a computer. It was just the FBI was computerizing at that point. They had no idea. So, you know, the FBI is very good at investigations and finding the best person to fit the need. they went deeper into where I was in this super secret undercover team of operatives called ghosts. And our job, my job was to follow targets, to investigate targets, usually from the shadows, counterintelligence and counterterrorism. And those are the disciplines I learned at the FBI Academy and through my career in the FBI.

10:01But I had never talked to a target except once by accident when he wandered up to me just out of nowhere and asked how to find a bus. You know, and you had to learn not to show surprise on your face ever. And so they asked me to go undercover to catch Hansen in the most unique case the FBI had ever run in a job that I was never trained to do. I've always had this philosophy that you have these points in your life where something big comes and you either leap at it, knowing it's going to be really hard, but the payoff could be great. There's something amazing down the road. You take the easy road and you say, no.

10:38And I took the leap. even though I knew it was going to hurt my family and all that. Let me ask you a question. What is failure in this? Like, did you guys already know he was a spy and now you just needed to prove it? Or you weren't quite sure? We suspected he was the spy. Failure would have been, and this is not really a failure, but failure would have been he wasn't the spy and you just spent a year or two doing, wasting your time. Yeah, so failure could have been he gets away with it, which would have been absolutely terrible for the FBI because the most important goal of the investigation was, one, determine he's the spy.

11:12Two, if we do that, catch him red-handed so we can put the pressure on him to get him to tell us what he did. And we could fix the FBI because he broke it. He broke it in countless ways. It has taken decades for the FBI even to repair what Hanson did. So we really had to catch him red-handed to put the pressure on him to tell us what he did. My first job was find out if he is the spy. You know, the other thing that could have happened in the case, knowing what we know about Hanson now, is I'd take a bullet to the head. and that was the other way I could fail. So failure really wasn't an option for me.

11:44Either I never worked for the FBI again because I've just embarrassed myself or this guy shoots me on his way out the door because he knows he has nothing to lose. He's facing the death penalty three or four ways anyway, legally, what's one more murder? So I had to win. And I've been in situations like that before, working undercover, where it's, you can't lose the target, but don't get made, which is almost impossible. And I just had to go in and succeed. And I did. And the amazing thing about the story is I learned how to catch Hanson from Hanson because he was a bragger, because he was a narcissist, and he really just wanted someone to temper and instruct and teach.

12:29And I truly felt that he desperately wanted to tell everybody about his genius. So while he never directly said, I'm the spy, we would get very close. Like what was very close? So he was very close and he would say things about espionage and about how the FBI is broken in a way that there are all these techniques you can use to find out whether you're being surveilled or find out whether there's an investigation open on you. And here's how you can check to find spies. And if you drop them, you can make a lot of money. He's always very instructively getting close to it. And in his final drop to the Russians, and I did catch him, and I found the information that had the FBI sitting there in camouflage, watching at this bridge when he dropped his final drop of information to the Russians.

13:16He dropped my name and information, suggesting that I would be a great person to recruit. Wow, that's how much you fooled him. That's how much I fooled him. So one of the things you did, though, was you stole his Palm Pilot, and then you were able to take all the information off of it, and then put it back on his person without him knowing. How did you steal his Palm Pilot? So what we did is we social engineered Hanson. We hacked him. Learned everything that I could about him in a psychological profile. And I realized that he disliked everyone in the chain of command above him, especially these two individuals, right?

13:50A section chief and an assistant director. And in fact, at one point during this bizarre investigation, and I think maybe this was a test, a loyalty test, He had me go in and cover of night into this assistant director's conference room and steal all the art off his walls. Oh my God. And so I did. Why would he want to do that? Just to see if I would do it. To see if I would, you know, because he was recruiting me, you know, to see how far down the rabbit hole I would go to be a bad guy. And I said, okay, I'll do it. Why not? You know, what's the worst that could happen? We're in a secure skiff.

14:23No one's ever going to come in anyway. So I stole it all and I hung the art around the walls in our office, you know with a little tongue in cheek i put the scene of a fox hunt over my desk the scene of two men in a boat in peril the high seas over his desk right and maybe he should have been looking you know between the lines a little bit i used that assistant director and the section chief he didn't like to come in unannounced slap twenty dollars on his desk and challenge him to go down to the shooting range and shoot. And he was so apoplectic that this assistant director was staring at his art over his desk that it threw him completely off his game.

15:04And for the first time, he forgot to reach down into his bag and grab his Palm Pilot. And I knew something had to be on that Palm Pilot because he loved the thing. He talked about it all the time and he was never separated from it. And then the operation was a go. He leaves to go down and shoot. I've seen the CCTV footage and they did a great job of portraying it in the movie Breach, which is a movie about me and this story. Ryan Phillippe plays me. Chris Cooper plays Hanson. He goes down there and fires off a clip, pulls back his target. There's a really nice grouping in the center and then abruptly holsters his firearm and leaves.

15:39Doesn't say a word to anybody. Probably because he touched his back pocket and realized I don't have my Palm Pilot. How much do I trust Eric? I had minutes. I had gone down three flights of steps, a little unlike the movie. in real life. I run down three flights of steps, completely stressed out, hand it to a tech team, and I'm bouncing up and down on my toes, waiting for them to finish copying the thing. And I'd also grabbed a floppy disk and a data card. You know, all that stuff is data. Grab it all from his bag. And I get there maybe like a two minutes, one and a half minutes before he does.

16:10Kneel down in front of his bag and realize that there are four identical pockets and I have three devices. and in my rush to grab this stuff and run, I'd forgotten. I couldn't for the life of me remember what pocket I'd pulled it all out of. And he's coming through the door. So I just dropped all three, ran to my desk, put the best poker face I've ever had. And just in my mind, I was desperately trying to think of some excuse because there was no way I got this stuff right. And he goes into his office. He slams his door after glaring at me. I hear this telltale zip and I know I'm doomed. And at that point, I just sat there thinking, there's no way I come out of this okay.

16:49I should be running down the hall, but I also realized that this was my mission to win or lose. This was my job, the big job that I had to catch the spy. And it was my duty to sit there and take it one way or the other and do anything I could to bring him back into it. And I think the excuse that I was going to say was I tripped over your bag and everything fell out and I put it back in and that was just not going to work. What if you just said ignorance? Oh, I've just been sitting at my desk the whole time. I don't know what you're talking about. Well, he was one of the most meticulous people in the world.

17:21And this was his baby. It's Palm Pilot. He would have immediately known that it was in the wrong pocket and that everything was jumbled and that something was wrong. And then he would have just cut and run and been gone. We wouldn't have caught him. Maybe he'd be, you know, living with Edward Snowden in Moscow, hanging out in an apartment, eating caviar, drinking vodka, but he could have gotten away. So I had to talk him into the case no matter what. And it just providence, I got it all right because he comes out, glares at me, asks if I was in his office. And I said, yeah, I was in there with like the best face ever, just like this.

17:56Yeah, I was in there. What's your problem? And I put a memo in your inbox. Didn't you see it? And which I had, because you always have to plan for these things. And he just did this Jedi mind trick that CIA guys like to do, where they just stare at you and then stare at you to get you to break and go, hey, you're right, I did, I was in there, I grabbed your bomb. And I didn't, even though I was sweating all down my back. And less than a week later, we caught him on that bridge in Foxtone Park. He had made his final drop to the Russians. Wow. So it turns out I got it right. So, and then you went from there deep into what is probably the most dangerous part of our digital society right now, cybercrime.

18:33And I want to get right to it. What? Yeah. I don't think people realize, I don't think I realized even, how big and dark the dark web is. And before I ask you to define things, what's like the worst things you've seen or encountered on the dark web, which is this underbelly of the internet that nobody really ever goes to, except it turns out millions of people go to it that I have no idea. Well, the dark web is part of the internet. And one thing that I wanted to do in the book was show my readers, or at least show them, how depraved it is, but also have them understand that it can't just be shut off.

19:14It can't be destroyed. It can't be turned up because it is a part of the internet. And there's a marketplace for anything on there. And just to answer your question, here's two. The body part's bizarre and the sheer amount of sex trafficking that happens on the dark web. Not only in actual Well, people, you can go onto the dark web and bid on a person, usually a young girl. Young boys are on there too. And they will deliver them to the hotel room of your choice. And they'll even send you a PDF guide to build your basement dungeon. It's that disturbing. So what does that mean, the soundproof dungeon?

19:53Is that because you're going to keep them prisoner? Yes. And forever? Because you're going to keep them prisoner. Or until you kill them or whatever? I guess until you kill them, yeah. It's the largest human trafficking marketplace in the world. And how many people you think are sold this way per year? I don't have the statistics right in front of me, but I use the UN statistics in my book to show that it is a huge amount. And most of it happens through the dark web because it's the only way to really do this with anonymity. Now, you might buy a person on the dark web and they never actually arrive because there are a lot of criminals and fraudsters there too.

20:33You know, there is no honor among thieves. But if you are in the marketplaces that are more legitimate and are harder to get to and harder to find, then this happens. Slave labor is a huge reason for dark web human trafficking. And so right now, how many Russian girls or boys or any nationality are in dungeons, do you think, you would expect? I'm sure there are thousands all over or more. You know, and it's not just dungeons, of course. That would be a weird personal, you know, depravity. A lot of these are sex trafficked and sold to brothels, right? All over the earth. You can't escape the brothel.

21:14Like, what happens if you just run away? Well, you know, if you can even get away, then they'll find you. But, you know, most people who are sex trafficked have no documentation. that's all taken from them. They have no money. They have no one to call, right? These are sort of the forlorn or the lost, the stolen, and they're purposely given no hope. It's an absolutely terrible and abysmal thing that unfortunately happens in our society. And millions of people go through this every year. And so from what I understand from the book, I would almost categorize very broadly, there's two types of cybercrime that you're focused on.

21:51And you kind of make the distinction, which I never thought of before, between the deep web and the dark web. So the deep web is like all your information's out there. People steal it. Sometimes there's ransomware like, hey, we stole all your information. You wouldn't want this getting out. We're going to charge you a million dollars for you to get your information back or we're going to post the information. We're going to shut down your networks, all that kind of stuff. And there's exchanges for this data. There's these ransomware as a service, almost companies you can call them. And then there's the dark web where you're actually going and buying like a body part or a sex slave or a gun or a drug or whatever.

22:27Yeah, James, let's drill down on that a little bit with the full primer. The internet really has three parts. The surface web, let's think of the surface web as the open to the sunlight area of the internet, right? The mouth of the cave. You're walking into the cave. You see stalactites and stalagmites. You're a tourist, you're feeling good. Anything you can reach out on a browser and receive. Anything that you're getting through Google. the entire history of humanity, all of the social media, all of our web pages. This is where marketing thrives, right? This is the open area of the internet. Then you crawl deeper down into the cavern where you're putting on your suit and your carbide lamp and you're crawling on your belly.

23:08And it's hard to get deeper, deeper, miles and miles below the earth in this cave system, which is the analogy I use in the book because it's cooler than an iceberg. And this deep web, isn't a bad part of the internet. It is the secure layer of the internet. In fact, this is the area of the internet, 90 % of the internet, which is astronomically large. The internet is so large, we can't actually wrap our minds around the number of zeros. The deep web is where cybersecurity is fighting cybercrime for our data. It's where your bank records are, your medical records, everything you want to protect with a password.

23:48And if you're smart, something more than a password, because those don't work. We could get into that. It's everything that matters, right? And part of the deep web is the dark web. It lives on it like a cancer, like a pustule growing on it, which is why you can't cut it out. You can't excise it because that guy's that backup service too. And this is where all the marketplaces exist using special technology in order to access that are fighting for your data and selling it. And here's where you find all these dark web ransomware as a service attackers, e-toolkits for people who want to get into cybercrime, all of the different marketplaces.

Read the full transcript

24:29You can hire an attacker during COVID. There were all these stories of enterprising students, for example, during the pandemic when we were all working from home, right? Who would find their way down to dark web marketplaces where they would hire a cyber attacker, you know, sometimes called a hacker, to shut their school down with what's called a DDoS attack. They flood the network and the servers with so much information, it all crashes. And then they get out of school for the day, right? You know, kind of the modern equivalent of pulling the fire alarm to get out of a test. Well, you know, kids were doing this.

25:01So there's so much you can buy in cyber crime on the dark web. All of our identities are for sale. All our username and passwords are for sale. There's something like six billion of them. When you say all our usernames and passwords, like your Google email password, is that somewhere on the dark web right now? That's certainly on the dark web. Yes, actually, Google has many times noted that your password's been lost. And you should turn on two-factor authentication to protect yourself from the fact that it's the only thing that's going to keep a dark web cyber criminal from buying your username and password for pennies off the dark web been trying it.

25:37Now, that doesn't mean that you personally or any of your listeners would be targeted unless, you know, you work for the federal government or a high-profile company, which is probably true for some of your listeners. There is that micro-targeting, but there are also broad-scale targeting using AI to just try usernames and passwords until they get into accounts. And then you can be a victim of identity theft, fraud. They can use your accounts to launch attacks against all your friends and neighbors and contacts, it can scale to be more damaging from there. So you never want to just rely on your password.

26:11It's always password plus something else. Yeah, I'm going to, I've never used two-factor authentication just because I'm lazy, but I think maybe I should start using it. But if I was like, let's say one of these students who is going onto the dark web to find a hacker who can attack their school, I would be worried about two things. One is I don't even know how to find something on the dark web. Like how does someone go to the dark web. There's no website. Welcome to the dark web. There isn't. And the other thing is I would be worried if I think I'm actually talking to someone on the dark web, it seems like a good chance I'd be talking to a police officer because you're right.

26:48And you're right. So yes, it's difficult to get into the dark web marketplaces. And that's by design. The criminals don't want tourists and they don't want law enforcement, right? So the way that you learn about dark web marketplaces, I don't want people to go do this because, and I'll outline the dangers in a moment, it is usually through these underground message boards where people trade the onion sites. That's what it's called. It's called onion routing. So it's dot onion are the websites. And they're just this very long string of letters and numbers. They make no rhyme or reason. There's not like our normal web pages where you can actually define it.

27:28There's not like google.onion. No, it's not. You have that. There is no. Well, I'll get into that in a minute. But you have to know the site. And then you use a special browser called a Tor browser, which literally stands for the Onion Network, the Onion Router, right? Browser. And anyone can download that and use it. And that will get you onto the dark web. Why you don't want to do it is most of the sites that you're going to find as a tourist are going to just hit your devices with this gnarly malware. And your computer's going to crash. It's going to hate you. It's going to spit fire. It's some of the worst malware because they want to infect you.

28:09And they'll steal your identity and all your data. So you want to be very careful. Also, you can hire an assassin on the dark web. And if you're going too deep and they think that you're somebody that shouldn't be there, a person might show up. So you really don't want to play around with the dark web. I do spend an entire chapter in the book, you might remember, I go down deep into the dark web with a friend to go chase down pictures for a client that were stolen from her phone. She had taken naked pictures of herself for her fiance or boyfriend at the time. And she was underage and really didn't want them on the internet.

28:45We were going to try to find the marketplaces they were on, but it was also a great instructive opportunity to record it and turn it into a chapter for my readers to see how difficult it is to get down there, even for a seasoned veteran who was paid by the DOD to become a bad guy and sell drugs so he could catch a big dark web drug trafficker. So tell that story. So this is Halima in the book, right? Yes. How did she know naked pictures were on the internet? What did you do? what happened. Take a quick break. If you like this episode, I'd really, really appreciate it. It means so much to me. Please share it with your friends and subscribe to the podcast.

29:26Email me at alcatra at gmail.com and tell me why you subscribed. Thanks.

29:38in today's world you have to be super careful with your data whether it's your passwords your bank info your private emails or messages there is non-stop attempts to get your data and some of it's like legit corporations stealing your data and some of it's from hacking and some of it's from viruses you have on your computer. By the way, everybody probably has some sort of virus on their computer. But here's the thing. You wouldn't take out your wallet in a shady part of town and start flashing your money around, right? Because you're worried that it would get stolen. Well, that's what you do every time you use public Wi-Fi.

30:14Public Wi-Fi is the shady part of town. And every time you use public Wi-Fi, you're exposing your data unless you use ExpressVPN. Every time you connect to an unencrypted network, like let's say you use the public Wi-Fi in the airport, your online data is not secure. Any hacker on the same network, it's not easy, but they can do it. They can gain access to and steal your personal data. Again, passwords, bank logins, credit card details, on and on. It doesn't take much technical knowledge to hack someone. Your data is valuable. Express VPN stops hackers from stealing your data by creating a secure encrypted tunnel between your device and the internet.

30:55It's rated number one by top tech reviewers like CNET and The Verge. So for me, it's personally important to use Express VPN. I don't know how my data is gonna be used. I don't want people to even know where I'm at. I don't want people obviously to know my passwords. I probably use the same password for everything. So use that info how you must. But look, secure your online data today by visiting expressvpn.com slash altature. And the altature is all in caps, A-L-T-U-C-H-E-R. That's expressvpn, E-X-P-R-E-S-S-V-P-N, expressvpn.com slash altature to find out how you can get up to four extra months.

31:35Expressvpn.com slash altature.

31:44Being an entrepreneur is a 24-7 job. And when you're hiring, you need a partner that works as hard as you do. That hiring partner is LinkedIn Jobs. When you clock out, LinkedIn clocks in. LinkedIn makes it easy to post your job for free, share with your network, get qualified candidates that you can manage all in one place. For one thing there, you can post a job. LinkedIn's new feature can help you write job descriptions and then quickly get your job in front of the right people. You get qualified candidates. At the end of the day, the most important thing to your business is the quality of the candidates.

32:16And with LinkedIn, of course, you can feel confident that you're getting the best. Based on LinkedIn data, 72 % of small and medium businesses say using LinkedIn helps them find high-quality candidates. Find out why more than 2.5 million small businesses use LinkedIn for hiring today. Find your next great hire on LinkedIn. Post your job for free at linkedin.com slash altature. That's linkedin.com slash altature to post your job for free. Terms and conditions apply. So she was contacted by a criminal, a cyber criminal, through a DM on her Instagram account, or Instagram account, yes, telling her that he had her pictures and he was going to sell them unless she paid him a lot of money.

33:03and her father, she finally told her father, they came to us and we told her, look, you know, this gang is in Belarus. We believe in Belarus. You know, there's no law enforcement that we can use to take them down, but we will go find them and find the pictures and see how real this is. The pictures were showing up like sexy teen photos with her name on Google, on the primary search engines. And she was afraid her friends would see this. And she had just taken pictures and used Snapchat to send them to her boyfriend. And a lot of kids do this, and it's a terrible idea. And they do it because they believe that Snapchat, you take the picture and it disappears, right?

33:44That's not true. Unless you turn off a setting, it saves everything to your camera roll as you take the picture. In fact, law enforcement can get all those pictures from Snapchat anyway, so nothing actually disappears off the internet. So kids, don't snap anything you wouldn't want your grandma to see on Snapchat. Anyway, the attacker was able to use Instagram to get into her iCloud account, which is where her camera roll was saved to the cloud, download all her pictures, found the really racy ones, and then was selling them on an underage dark web marketplace for teens. and we actually took a snapshot of the website, you know, where she was on there, blacked out all the names.

34:29You just pick your teen and where they're from and you can go in and look through their photos and then download whatever you want to pay. But what we were able to show her is that we went all the way down in the dark. We found the marketplace. We investigated and realized that what the criminal was doing was creating this marketplace, not to sell the pictures, but to steal identities and data from people who would go on and buy it, right? With their pure interest who wanted to go buy pictures of young teens. And the second you clicked on any of the links, your computer just was hit by this malware that stole all your information.

35:06Anybody who goes to try to buy these or even look at them is going to be hit by a major cyber attack. And we reached out to all of the major search engines and identified all the links and said, this is an underage person, and they all removed them. So we were able to give her the peace of mind, even though in that case, you know, Belarus doesn't care. Russia doesn't care. China doesn't care. If the criminals are there, they just look the other way, unless it's a huge national event and a lot of pressure from administrations. And so that's interesting. So a couple of things there. One is you're saying the site was set up, not the crime.

35:46Okay, they were committing a crime by selling these underage pics, but what they were really trying to do is they knew enough sickos would be buying these pics that they're the perfect ones to steal all their information because they're not going to complain. Exactly. So is it the case that I could just click on a random link and that could take over my computer? Certainly. If you're in places where you, you know, you can think of the places. The internet is filled with pornography. And a lot of it's free. And the reason that it is is because, you know, they're posting it there because they want you to click through.

36:26And many of these sites will start trying to data mine you for information or look for weaknesses that can be exploited through a web browser exploit. Like what's a weakness that can be exploited? Well, we have all sorts of vulnerabilities. So one thing I talk about in the book is the need to patch our systems, right? And for an individual, for example, when you get that alert from your phone, saying from either Google, Android, or your iPhone, or whatever company you use for your phone, that says, hey, there is a critical update. That usually means that the brilliant engineers have found a flaw that a cyber criminal or a spy can exploit, and they want you to update quickly before, you know, the bad guy finds a way into your phone.

37:08It's the same with any web browser or computer or operating system. And they can use different sniffers or scanners in order to look at your, when you log onto their website, now they have a connection to you. They can start scanning you to find a flaw that they can exploit. And then what they do is they just grab the toolkit that they can use because you didn't patch something and now they're in. That's why websites can be so dangerous. And one of the biggest tips for anyone is be careful where you go. The internet's not a safe place. Go to legitimate websites. Don't play around with your data by going to things that are too good to be true or things that you believe aren't going to be dangerous because you want a great deal or you want to go look at a picture of a teen girl.

37:57Now, the Body Parts website, this is a website. Ah, the Body Parts Bazaar. Yeah, this is a website that now they sell body parts, I guess, like if you need a liver, they'll sell you a liver and they took the liver from someone they killed or whatever. Yeah, they can get parts from all over. They get them from cadavers. Obviously, if it's transplanted, it sort of has to come from someone who either has just died moments ago or might still be alive. You do hear stories of people waking up in bathtubs because they decided to go join the wrong people for a party. that actually happens, those body parts can find their way to the dark web and then can be sold on these marketplaces.

38:38And they'll even charge you for shady doctors who will transplant it for you. For example, a heart went for something like$150 ,000 with the doctor to transplant it, eyes for$2 ,000. And as I was looking, some of the weirdest things were like hands and feet. Does that work? 500 bucks. No, you can't transplant it. There are weirdos who just want to buy a human hand. Oh my God. And they're cheap. You know, so in the, you know, they, I guess they, I've never obviously tried this. FedEx it to you in dry ice. I mean, how else are you going to get a hand? Now, why did you come across this? Were you investigating something relating to this?

39:15This is, yeah. I wasn't investigating something related to this. I was diving into the dark web just to find some of the most bizarre sites to be instructive for my book, just to really show what this place is and how crazy it is for what you can buy. What's weird is in your book, you describe these companies like Lockbit, which is, it's almost like a real company. They identify themselves. You know where they are. It seems like it's like a formal institution like Google is or McDonald's is. And you mentioned this one NGO where their information was hacked. The Lockbit was going to release the information unless the NGO gave them$5 million.

39:58What kind of information could be, A, so important? And B, if everybody knows, oh, it's Lockbit, why can't you just go find Lockbit and do something to them? I don't know. Well, let's unpack all that. So first of all, the NGO story is my through story for the book. I wanted the stories to read like true crime, thrilling thrillers, right? Each story. But I also wanted, I didn't want it to just be like a collection of short stories that teaches something. I wanted to have that one core story that carries you through the book. And just as I was writing the book, you know, a client had this horrible cyber attack and I was right in the middle of it.

40:37And I was recording and remembering everything. And that became my through story that carries you from the beginning all the way to the end. And this was an NGO, a non-governmental organization that did government contracting, primarily with USAID and humanitarian work all over the world. including in Ukraine, and was attacked by a Lockbit, which is actually Lockbit 2.0, right? The upgraded version of the cybercrime syndicate, which is a Russian cybercrime syndicate who attacked the NGO because they were doing humanitarian work in Ukraine. You know, Lockbit believed it was their patriotic duty to harm anyone helping the Ukrainians.

41:16And I know this because the bad guy called me on my personal cell, and he had my personal cell because he was so deep into their data that he was able to just look at lists and found like Eric O 'Neill and everybody, all the bad guys know my name. And he called me directly and said, what are you, why are you playing around? You know, just get them to pay. You know, they have insurance and I don't want to give away the story, but we were able to save that company. And it was just, it was really clever how we figured it out. And what kind of information did they want to sell? Like, why was it worth that much money?

41:46Right. Yes. Your original question. The, these cybercrime syndicates know how to exert pressure. Pressure is the golden rule for cyber criminals. Pressure means that you don't think. Pressure means that you pay. And what they were claiming is that they had a wealth of customer data, but also the data of people that the company was helping. And that could destroy the reputation of the company if they found out that they're helping all these people that were essentially resettling refugees in Ukraine, and suddenly all their data was released. Could you imagine? And now the Russians know the identity of these people and they could cause physical harm in the middle of a war.

42:27So the company was terrified. And the number one goal for the investigation was to determine what the attackers had stolen, because they said they had everything. So we had to prove that they didn't have anything. And at the same time, keep them on the line and keep them negotiating before they released whatever they had. Another situation that you write about is, and I remember this from a few years ago, several casinos in Las Vegas were just like shut down because they were a subject of ransomware. Like some organization stole all their data or, or, or no, actually just seized control of their computer systems, like shutting down the elevators.

43:04And they were just going to keep things shut down unless they paid. And I believe they paid, right? So, so what was that all about? So this was MGM, the MGM. So I didn't realize this and I go to Vegas a lot, not really because I like to gamble, but because I speak and they've got these immense conference centers and I've spoken at the MGM Grand many times. I didn't realize MGM owns like half the hotels in Vegas. And with a 10-minute phone call, a cyber attack group called Al5 and their buddies in this affiliate group called Scattered Spider, which are really good at what we call social engineering, were able to call the IT help desk for the MGM grant and get the username, password, and two-factor authentication reset for a systems engineer.

43:52The IT people that are able to create passwords, create whole accounts, like do all the mayhem within a network, within a computer system if the bad guys get a hold of their account. And then become that person and then spread throughout not just the MGM Grand, but all these other hotels and bring it all down with a ransomware attack. And what makes it a cool story for an author isn't just that they were brought down by a ransomware attack. It's the unfortunate chaos that happened. I mean, to the point where people couldn't check into the hotels. People who were checked into the hotels, their room key wouldn't work.

44:28And then randomly, some people's room key opened every room in the hotel. I mean, this is Vegas. Imagine the chaos for that. You couldn't make a reservation to eat or for a show. The gambling tables were down. None of the slot machines worked. So now you're in Vegas, and I don't know what else other people do in Vegas, but those are like the top three things to do. Eat, gamble, and go see a show, right? You couldn't do any of that. They're sending people out of their hotels. And here's the kicker, because you always look for one little hook, right? They were putting cases of bottled water in the elevators because sometimes the elevators would work and sometimes they wouldn't.

45:02And they didn't want people getting stuck between two floors and they couldn't get them out without water. So it was bananas. And I don't believe they paid, but they had to do the immense amount of work to get out from under it and remediate the attack, which took them weeks. And I mean, they lost more than$100 million just in downtime and a magnitude worse in reputation and sending people to other hotels. So it was a disaster for them. And that same cyber attack group was then pummeled by the FBI, Al-5. The FBI went into the dark web, found all their servers, found all of their websites, took it all down, stole cryptocurrency, stole decryption keys from them.

45:46like really went in and punished them because you know, the FBI loves Vegas too. And the leader of AL5, this dude like AL5.sup or whatever his name was, he swore he would be back because these guys are all hysterical and back with a vengeance. And they did, they came back, they rebranded, they came back and they launched this attack, which was our biggest critical infrastructure attack here in the US against change healthcare, which you might remember, it was November, 2023 when MGM was attacked. and then by December, the FBI attacked ALF-5 and then by February of 2024, Change Health was attacked and nobody could go to a pharmacy and fill a prescription.

46:27And that was ALF-5 because bad guys have backups too and they just restored all their service from backup and were right back in business. And that's why you can't shut down the dark web. Law enforcement can't do it. They can just do little things here and there We need to protect ourselves. Why isn't every company every day just down because of all of this? Like, it seems like there's so much better at it. And just in general, offense is easier to do than defense because defense, you don't know what you're defending against. So why isn't just every company down all the time? Companies are constantly down.

47:07They don't always tell you when they're down. You might have just noticed that we never know whether it's a cyber attack or a glitch. CrowdStrike was a big cybersecurity company that went down, and then you couldn't fly on planes. And there was chaos everywhere, but that was a glitch. Amazon Web Services just went down, and that was also a glitch, not a cyber attack. Just as many companies go down through a cyber attack, they don't always say it unless they have to. Media doesn't report on it as much as they should. And I think some of that is that the media doesn't understand this, so they should all read my book.

47:41And there are so many cyber criminals, and there are a lot of them, but there are a lot more companies. So it's a little bit of a roulette whether that ball lands on you or not. Also, cybersecurity is getting good. I mean, if a company invests in robust cybersecurity that's offensive, that hunts threats, doesn't just play defense, they have a good chance of catching the breach before it does a huge amount of damage and limiting that exposure and saving themselves. You know, with my company, that's what we do with a lot of cybersecurity advising is helping companies get to that point. And the more companies that do that, the more we dry up the dark web.

48:16It's sort of like putting a sign on your lawn that say, we have dogs. Whether or not you have dogs or not doesn't even matter. Like, oh, they have dogs. I'm going to focus on the houses that don't have the signs. We have dogs. So once a company does a little bit, probably the cyber attackers say, okay, it's not worth it. There's 6 ,000 other companies we can look at. Yeah, that's a good place. In security, we call that displacement. I like to give Connecticut examples for cyber, right? Because we understand physical. I did this case for a client. It was a housing community in Washington, D.C., in a bad part of Washington, D.C., and they were just tired of crime.

48:52I mean, to the point where some of the crime was actually in the community. People were selling drugs from their first-story windows, people who would come in off the street, and they would have to figure that out. So we went in and we looked, the first thing we did was looked at all the other communities like this, housing communities surrounding them. And then we went to our client and said, I know you don't have any money, so we're going to make you a little bit better than your neighbors. And we did. Built a wall, put some cameras up, good lighting, made it really hard for criminals to go and do anything.

49:24And you know what they did? They were displaced. They just went to the neighbors. Now, does that solve the crime problem? Well, no, but for your client or for that company, you can translate that to cybercrime. It does save you. So yeah, it's the companies that don't do a little bit of work. And it can be painful and it can be expensive, but it is far less expensive than getting hit by a cyber attack and losing everything. Now, somebody was once telling me that probably every company in the Fortune 500 has already been attacked. And there are like sleeper cells, these bots, these bot armies that are probably sitting on every desk and just waiting to be activated to do some harm somewhere.

50:03Do you think that's true? I don't think that in particular is true. Now, them all being attacked, certainly. Companies get attacked thousands of times a day. If you were to look at the investigative chain and say an attack is an attempt, right? That could be an attack. Then they're constantly bombarded from attacks, especially in the Fortune 500. That's big game hunters are going after them. They can be very clever and really understand the company and launch a much more successful attack. But these constant bombardment attacks happen all the time. It's kind of like having an umbrella against the rain.

50:39Now, whether they've been successfully attacked and the criminals have left something behind is a little less likely. It does happen. But when a company is attacked successfully, they go through an immense amount of pain to clean everything up. and usually you're going back to a backup that is before the attack. You're bringing in people like me to find every place the bad guy went and completely scrub them out of it. And then you're bleaching everything to make sure the bad guy's not there and that they can't get right back in, at least using the same attack vector. Companies that get attacked end up being stronger than they were before if they survive.

51:16Now, you know, speaking of getting bombarded thousands of times a day, like I get emails, I'm sure everyone gets emails, all day long, things like, oh, someone's trying to use your Google account. Click here if that's not you. Obviously, that's a phishing attack. And I always kind of look at the real data being sent you. You can kind of, what is it called? You can look at the actual HTML of the email. Yes, right. You can look at the web address of the attack or who is sending you the email address of the person sending it to you. And if you just click on it, you can usually tell. Now, sometimes they get really clever, but the real trick here is don't click through the link.

52:00If you get an email from Gmail that says there's an attempt to compromise, right? And we've blocked it, but you should change your password. That's the most tricky one. And if you see that, then don't click. Go to www.google.com and then log into your Gmail account and see if there's an alert there. That's where they'll put the actual alert. And if there's an alert there, change it. Or if you don't feel good, go directly to gmail.com, change your password there, but don't change it through a link. When you get the email, especially as we move into the holidays, right, that says, we tried to deliver your package, but it was held up.

52:40It's sitting at the warehouse. We need more information to deliver it for you. Click here and fill out our form, right? Don't do that. call ups go to ups.com go to fedex.com and look directly for that alert don't trust that email so so so i know that and again i get at least dozens of these a day like between my spam and my regular inbox a lot of them pass through to the regular inbox but right how many people have already clicked on that and they've already been compromised maybe their information hasn't been used yet maybe whatever's on their computer hasn't activated yet but how many people in general in the United States do you think are already compromised?

53:20In just our conversation here, millions. In just the 50 minutes we've been talking, James. Wow. It is pervasive and it is broad spectrum. And the only way to stop it is knowledge. The only way to stop it is knowledge. The reason I wrote this book, so people read it, you're never going to get caught by, it's going to be really hard to catch you from one of these now because you've read the book. You know that the punch is coming. You can see it coming. Well, not only was it such an informative book, but it really read like a spy thriller. I really congratulate you on how you wrote it. You should write a crime thriller next, a crime novel.

54:00I'm serious. You must have considered it. I've got a plan. All right. I have a plan. I think my next book will be fiction, spy fiction. But one of the reasons I wanted people to read it, read it. But two, there are so many cybersecurity books out there that in a chapter will put you right to sleep. And I wanted something that people would pick up and read because they love the book. They like reading it. Not only you get to read a good story, but it's like when you read a great story or you go see a great movie and you come out of it thinking you're super powered because you also learned something.

54:31I think those are the best authors. And if you don't tell a good story, then people, one, won't finish the book and two, won't remember it. And I just used the practice that I learned as a keynote speaker, which I've been doing for more than two decades, very successfully, storytelling. Even though I talk about cybersecurity, people always rate me as the best keynote of the day. And it's because I tell really cool stories and people feel cooler after hearing me. And that's what I want people to feel after they read. But also, learn everything they need to know to protect themselves from the scourge.

55:02And it's going to get worse. AI has made it all worse. AI hijinks now are making the cyber criminals job so easy. Oh yeah. The whole deep fake thing where someone's daughter calls, it's like, oh, I'm captured by bad men. And the mother's freaking out. This is in your book. And it was just a deep fake of the daughter's voice. It's crazy how that happens. It is. And you know, there's a new one. There's a scourge across the West now of this deep cake where here's how it goes. it's your, let's just use your daughter, right? Your daughter calls and says, dad, I'm in trouble. I screwed up. She's crying.

55:39I hit somebody with my car. It's a whole mess. I think the woman's pregnant. I just need some help. I'm in jail. And then the phone gets handed over and you hear this other voice and it's the public defender. Yes, your daughter's in jail and in this county and this place, I'm her court appointed attorney. She's going to be stuck here for weeks, I don't know, maybe a month while we set up trial and she gives a rain and da-da-da. I need you to pay bail so I can get her out today. And oh, by the way, this is the only call she gets. After this, I can't talk to you illegally, right? That's not true, but they know that you're scared and they're putting urgency and pressure on you.

56:18Urgency and pressure. That's what the cybercriminal has to do. That's your trick. If you feel that urgency and pressure, that horrible terror, you have to take a step back and think. And it's costing people thousands of dollars every minute for these scams. They are using AI of somebody that you know to clone their voice. They're getting it right from our social media. And normally they try to do it when that loved one is on vacation or away, right? So they're not going to be easy to contact and say, is this really you? Oh my God. So the solution I give in the book is have a code word with your family and your friends, right?

56:52That's a great idea. I'm going to do that with my daughters. Yeah. If you don't hear the code word, then you know, it's probably not true. Or, you know, on the call, I know it sounds crazy, but you get that terrified call from your daughter, a terrifying call, and you say, oh, honey, okay, I'm going to help you, but what's the code word? And if you don't say the code word, then, you know, it's probably a scam. Eric O 'Neill, you've done so much, you know, both for your country through the FBI. I mean, Robert Hansen's the highest profile double agent in history. And also just all the work you've done, not only in stopping these or helping in these cybercrime situations, but then writing this book and explaining it in such an easy to understand way through these stories, really riveting stories.

57:38It's a scary world out there. They should make a movie out of this book, Spies, Lies, and Cybercrime, Cybersecurity Tactics to Outsmart Hackers and Disarm Scammers by Eric O 'Neill. former FBI spy hunter. Eric, thank you so much. This is just such a fascinating topic and there's no end to it. So I hope your work gets better and better. Yeah, James, thank you. This has been a great podcast. I mean, this is definitely a keeper. You asked great questions. We got down into deep into some of the stories. And I guess for your listeners, I might offer read the book or if you really like my voice, listen to the audible version, which I recorded, which was a lot of fun.

58:18It was a lot of work, but it was a lot of fun. And I also have a companion newsletter to the book where every week I go through a new cyber attack so the book can continue to live and breathe in your hands and you can learn from it. Thanks again, Eric. Thank you. Thank you, James.

58:45This October, fear is free. on Pluto TV with horror movie collections from Paranormal Activity, The Ring. You will die in seven days. Scream. And from dusk till dawn. This is my kind of place. And don't miss the man-made nightmares in Mary Shelley's Frankenstein or the world-ending chaos in 28 Days Later. There's something in the blood. All the scares, all for free. Pluto TV. Stream now, pay never.

From the publisher

A Note from James

Oh my gosh—I was scared after this one. In this episode, I learned about what’s really on the dark web… and the even scarier stuff on what’s called the deep web.

Eric O’Neill—who, by the way, is the former FBI agent who brought down Robert Hanssen, the biggest double agent in U.S. history—joined me for this conversation. Hanssen was the FBI’s top analyst on the Soviet Union, and at the same time, he was secretly working for the Soviet Union—for twenty-two years. Eric was the one who caught him. There was even a movie made about it—Breach (2007).

Now Eric has written a book called Spies, Lies, and Cybercrime: Cybersecurity Tactics to Outsmart Hackers and Disarm Scammers. And honestly, it’s terrifying what’s out there right now—the dark web, the black markets, the cyberattacks, the scams that most of us have no idea are happening in the background of our digital lives.

I’ll let Eric tell the stories.


Episode Description

In this episode, James talks with Eric O’Neill—former FBI counterintelligence operative and the man who captured the most notorious spy in U.S. history—about the unseen cyber battlefield shaping our world today. O’Neill explains how hackers, state actors, and scammers exploit human psychology far more than technology, and why every one of us is a potential target.

From the lessons of his undercover work tracking Robert Hanssen to the rise of ransomware and AI-assisted phishing, O’Neill offers both a chilling reality check and a practical guide for staying safe in the digital age. He and James break down how modern espionage has moved online—and what ordinary people can do to protect themselves before it’s too late.


What You’ll Learn

  • How Eric O’Neill captured Robert Hanssen, the most damaging spy in FBI history
  • Why modern cybercrime depends more on human manipulation than hacking code
  • What really happens on the dark web and how it fuels global criminal networks
  • How AI is changing the speed and sophistication of digital attacks
  • Simple but critical steps you can take right now to protect your data and identity


Timestamped Chapters

  • [00:00] Introduction — James sets the stage for a chilling conversation
  • [02:15] Who is Eric O’Neill? The story behind capturing Robert Hanssen
  • [07:45] The day Hanssen was caught — inside the FBI sting
  • [13:10] From spycraft to cybercrime — how espionage went digital
  • [17:30] The real difference between the dark web and the deep web
  • [22:00] Why hackers target people, not systems
  • [27:40] Social engineering and the psychology of manipulation
  • [32:15] AI and the next generation of scams
  • [37:55] How to recognize phishing and digital traps
  • [44:20] Why cybersecurity starts with self-awareness
  • [49:10] Lessons from the field — how espionage teaches us to think critically
  • [54:05] The future of cyber warfare and personal protection
  • [59:00] Final thoughts — the cost of complacency


Additional Resources

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

More from The James Altucher Show

All 301 episodes
Former FBI Agent, Eric O’Neill on Spies, Lies, and the Cyber Wars We’re Already LosingThe James Altucher Show · 58 min
Listen in VO