All episodes
EP 030The Defenders Log

Inside the Fight to Disrupt Cybercrime at Scale

Michael Roberts

Inside the Fight to Disrupt Cybercrime at Scale

Exposing the Digital Abyss

In a recent episode of The Defender’s Log, host David Redekop spoke with veteran cybercrime investigator Michael Roberts, founder of Rexxfield, to reveal the reality of modern online fraud.

Cybercriminals now operate with incredible speed and scale through “Scam-as-a-Service” models. Specialists build fake social media profiles, laundering pipelines, and phishing sites, selling them to syndicates. Meanwhile, traditional law enforcement remains bogged down by jurisdictional red tape, slow cross-border processes, and massive backlogs—often ignoring losses below $1 million.

To bridge this gap, Roberts co-founded Stingbase and Stingforce. These AI-powered platforms aggregate threat intelligence across private investigators, banks, and ISPs to automate threat hunting, build airtight cases, and disrupt syndicates at the speed of the internet.

Key Takeaways & Protection Tips:

  • Beware the “Wrong Number”: Unsolicited texts or WhatsApp messages starting with friendly mix-ups are almost always social engineering pretexts for investment scams like “pig butchering.”
  • Protect Vulnerable Groups: Seniors and kids are prime targets; parents should warn children never to communicate with strangers on gaming or social platforms.
  • Demand Platform Accountability: Big Tech routinely ignores fraud signals. Pushing for updated terms of service and fiduciary duties will force platforms to disrupt known criminal infrastructure.

TL;DR

  • The Evolution: Cybercrime operates at scale via “Scam-as-a-Service” models, using specialized providers for infrastructure, fake profiles, and money laundering.
  • The Systemic Barrier: Bureaucracy, slow cross-border processes, and high loss thresholds keep law enforcement from acting quickly.
  • The New Tool: Michael Roberts co-founded Stingbase and Stingforce to pool private intelligence, automate investigations with AI, and speed up scam disruption.
  • Platform Inaction: Major platforms like Meta/WhatsApp fail to act on clear fraud reports due to corporate incentives and lack of legal duty to disrupt crime.
  • Protection Advice:
    • Treat all unsolicited “wrong number” texts as scam pretexts.
    • Keep kids off public social platforms and warn family about online grooming.
    • Join open threat-hunting networks to help disrupt organized syndicates.

Links

View it on YouTube: https://www.youtube.com/watch?v=4vx78kLh79k

Listen to the episode on your favourite podcast platform:

Apple

https://podcasts.apple.com/us/podcast/inside-the-fight-to-disrupt-cybercrime-at-scale/id1829031081?i=1000789547507

Spotify

https://open.spotify.com/episode/4hZGLkYW5NGAaQeTkdzRkV

Amazon Music

https://music.amazon.ca/podcasts/d7aa9a19-d092-42a6-9fe9-9e8d81f68d30/episodes/6acadeb5-7ea8-4a69-81db-d12d17eaadd7/the-defender%E2%80%99s-log-podcast-inside-the-fight-to-disrupt-cybercrime-at-scale

ADAMnetworks

https://adamnet.works


The Defender’s Log full transcript - Episode 030

Announcer:

Deep in the digital shadows, where threats hide behind any random byte, a fearless crew of cybersecurity warriors guards the line between chaos and order. Their epic battles? Rarely spoken of until today. Welcome to the Defender’s Log, where we crack open the secrets of top security chiefs, CISOs, and architects who faced the abyss and won.

Here’s your host, David Redekop.

David Redekop:

Welcome back to “The Defender’s Log,” and today’s guest is someone I’ve had the privilege of knowing for well over a decade. Michael Roberts is a veteran private cybercrime investigator, a victims advocate, and the founder of Rexxfield, and that was the time at which I got to know him in Australia.

And over the years, Michael has been on the front lines tackling everything from complex financial fraud and crypto tracing to online harassment and organized cyber schemes, and I have some personal experiences that we might even get into today. And what makes Michael’s journey so compelling is how he constantly translates hands-on investigative pain points into scalable solutions.

And most recently, he co-founded Stingbase and Stingforce, platforms built to bridge the gap between private threat intelligence and financial institutions intelligence and law enforcement to accelerate cybercrime response and disruption. Michael, welcome to the show.

Michael Roberts:

Thanks, David. Good to see you again.

David Redekop:

Likewise, even if it is only virtual. We see each other once in a while, but it’s nice to connect in this way as well.

The Evolution of Cyber Crime and “Scam as a Service”

David Redekop:

Michael, we’ve known each other for a long time, but looking back at when you were running Rexxfield in the early days, what is the single biggest shift you’ve seen in how cyber criminals operate since then?

Michael Roberts:

They operate at the speed of the internet and at scale and incredible cooperation. So there has been the emergence of many infrastructure, scam infrastructure as a service, scam laundering as a service, scam sock puppets as a service. There’s people in places like India and places like that who their full-time job is just setting up fake profiles for Facebook, for WhatsApp, things like that, and then selling them to scammers.

So they don’t necessarily benefit from the scam apart from that sale. So all these specialty criminals who put the infrastructure in place. And some of them don’t even commit the actual crime. But in the, for example, the RICO laws, for organized crime in the US, it’s comes under the sort of legal theory of an unspoken meeting of the minds.

They are liable, just like in a murder case, the getaway driver is guilty, as guilty as the trigger man. But they compartmentalize, and it’s very difficult because there’s so much of it happening, it’s very difficult to track it all down with because law enforcement have cross-border judicial processes that slow things down.

There’s a lot of institutional apathy with law enforcement to chase these things down, and there’s a lot of good law enforcement agents who are just overwhelmed with caseload backlog and thresholds. In some jurisdictions in the United States, for example, in the bigger jurisdictions, if your loss is less than a million dollars, they won’t touch it.

David Redekop:

Wow. So your frustration that I see over and over again is around the bureaucratic delays, which seems to be understood based on what you’ve just described. But is there any movement in terms of the bureaucracies being accelerated in certain cases? Does it have to be an amount larger than a million dollars for all that to be set aside for there to be a straight focus for more rapid resolution?

Michael Roberts:

Well, there is a RAT team, R-A-T, I’ve forgotten the acronym, rapid something, that the IC3 group in the United States, for example, runs. And if the scam is less than three days old, over a million dollars, and actionable, that does get rapid attention. The million-dollar threshold is policy, it’s not law, of course.

They can investigate a $10 loss if they wanted to. Today, I noticed an announcement that the UK and the US are working on a collaboration for disrupting and investigating crypto-related cybercrime. And there are other things happening. For example, in what’s called the Budapest Convention, 24/7 Convention, there’s almost 100 countries, I think, now signatories to that, which allows rapid preservation of evidence. So just for example, if an Australian victim and it’s a Nigerian threat actor, the Australian law enforcement through the representative in Australia, Australian Federal Police, can contact the equivalent in Nigeria. They can get evidence frozen or preserved from a telco or an ISP or a bank or something, so it doesn’t perish with time, which is a big problem.

And then they can wait for the judicial process, which is still glacially slow most of the time, to actually get the evidence transferred. Criminals don’t have the judicial processes. They operate very agile and as organized crime cross-border, so that’s why we can’t keep up.

The Birth of Stingforce and Justice at Scale

David Redekop:

I appreciate anybody and everybody who’s in the defender space because it requires a tremendous amount of coordination in many different disciplines too, I might add, not just one, in order to actually catch a criminal, but just as importantly, help a victim have some sense of closure or recovery when they’re in that space.

But let’s just roll back the timeline just a little bit, Michael. You have a fascinating life story that certainly is very interesting to me. What aspects of your life story actually is what got you to a place that you finally realized, “Okay, this Stingforce, stingbase approach is what the world needs to do justice at scale”?

Michael Roberts:

Well, it’s pretty much a lot of what I’ve already covered. It’s just the frustration when we can see with our own eyes on our own screen crime happening real time. We can identify all the disruption opportunities to actually disrupt the syndicates. For example, over a year ago, our team, our threat hunting team, found some open Excel spreadsheets or Google spreadsheets that were open, not password protected, for a Chinese organized crime syndicate that had thousands of UK WhatsApp numbers.

And we could actually see by analyzing these files, we downloaded them all, they’re still live, they’re still operating. We can see day by day the numbers that they are using to contact prospective victims for investment scams. It’s called a phish fry, by the way. So pig butchering is one name. Pig butchering is the general, because usually the Chinese threat actors and other countries do it too.

They fatten up the pig for the slaughter. Horrible name, but the pig in this case that they’re referring to as a pejorative is the victim. So the phish fry, I think, I’ve never seen that before. So I reported that to Action Fraud in the UK. I reported it directly to UK inspector at inspector level and commissioned officers in the UK and said, “We have all these numbers.

They’re UK numbers. They’ve been registered through WhatsApp. They’re being actively used to scam people. The Google sites are still live. The scammers, we can see the users changing the cells. I log in anonymously and I can see what they’re doing, and then once a number gets reported to WhatsApp and eventually blocked by WhatsApp, which is rare.

So I’m using this as actually as a case study on how ineffective Meta is at disrupting crime, and they’re making money from it. And, yeah, it’s just appalling. The Brits have done nothing. US investigators aren’t interested because it’s not focusing on US victims. They’re actually using these UK numbers to contact high-net-worth individuals in the Middle East.

So we can see all the numbers that they’re calling and texting with, and we realized a pattern and I thought, “Oh, that’s clever on those criminals’ part.” They’re focusing on numbers ending with triple digits or four digits or six digits, all identical, and you know that they are wealthy Arabs who are paying to buy these special numbers.

As you might know, in Dubai, the number one is, I think, a $20 million number plate or more. It’s all about ego and things like that in those jurisdictions, and it seems that their phone numbers are also something that they pay for. And this Chinese syndicate has caught onto that and trying to scam wealthy Arabs.

There’s other people as well in the UK, but we noticed this cluster of behavior in there.

David Redekop:

That’s crazy to me because that’s not even something that you can preemptively determine, right? In the world of internet domain names, we’re at the point now where so memory of the algorithms are now known to organizations like us, where we can preemptively determine a piece of malware’s next domain name that it’s going to register even before it’s registered, so a DGA, dynamically generated algorithm, domain registration.

But with phone numbers, that’s not even something that you can preemptively predict, right? Otherwise there would be an interesting opportunity to preempt and to further disrupt. Sorry, I’m just solutioning and talk-processing all, at the same time, correlating it back to what we do, Michael, but, yeah…

Michael Roberts:

We actually can. We know because we have the list of numbers that they haven’t used yet. We’ve literally got thousands of UK numbers that have already been registered to WhatsApp, and we know the ones that they haven’t launched yet. So WhatsApp could actually do something about this, but are choosing not to. Yes. I’ve contacted WhatsApp and I’ve contacted WhatsApp’s investigators and Meta, as far as I am concerned, Meta is a sociopathic corporate person.

So if corporations are corporate persons, you can apply the DSM-5 for mental health issues to a corporate person, and they check all the boxes for malignant narcissism or even antisocial personality disorder. Because corporations by corporate law, they have to put the interest of the shareholder first, right?

They don’t have to necessarily do public interest good. And so if the shareholder is number one even by corporate law, that is by definition narcissism. And that’s what I like about in a lot of US jurisdictions now, you can actually have a new for-profit company filing, which is a PBC, a public benefit corporation.

There’s no reporting necessary to the government, just to the shareholders, but they know going into it that there will be a public benefit mandate, which means it’s not narcissistic by definition.

David Redekop:

Well, I hope we make it there, and I hope that happens while we preserve what so far seems to be a solution based on integrity of Signal, and that’s why I prefer Signal over WhatsApp because I don’t want to support a platform that is narcissistic. That’s for sure.

Michael Roberts:

WhatsApp, by the way, is an incredible source of evidence because when scammers use WhatsApp, and they delete, if somebody blocks them or if they block somebody, that never disappears from the logs. I’ve helped a lot of law enforcement agencies, particularly smaller ones, where I’ve ghostwritten the subpoenas for them for WhatsApp, and then they don’t know what to do with it.

So they ask me to analyze it for them. And the WhatsApp records have, symmetric contacts, which is, means the scammer has them on their contact list and vice versa, asymmetric, whether the victim has, and things like that, and as well as blocked by and blocked. we can see all the numbers the scammer blocked.

We can see all the numbers, all the people who blocked the scammer. It’s incredible. you can draw a lot of inference from that type of intel. WhatsApp only keeps the last IP address generally, which is a problem. They, I think they should have a, a, an exhaustive log of IP addresses and timestamps. but I think that’s, it’s not a, it’s not a storage issue. I think, that it’s by design.

Collaborating Across Silos for Real Disruption

David Redekop:

This is a, a very challenging space to navigate, and so what I’m understanding what, that you’re doing with Stingforce and Stingbase is positioning it at the intersection of, private investigation, internet service providers, banks, crypto exchanges, and law enforcement.

And how do you build trust between groups that traditionally operate very much in silos?

Michael Roberts:

Very slowly. There are plenty of mission-driven law enforcement agents around the world that we work very well with. They receive our tips, they receive our finished cases, they act on them. People have been arrested in Nigeria, for example.

In the last few months, we’ve frozen over 240 bank accounts in Nigeria for 10 cases that I hand, nine or 10 cases that I handed over recently. All of them are US victims. Tens of millions of dollars in losses, and so that’s getting disrupted. In fact, one of the threat actors in Nigeria who’s actually living in the UK contacted the agency and said, “I want to do a deal.

I want to do a plea bargain,“ because he was notified by the bank that his accounts, 120 accounts for one guy who provides money laundering as a service. But then he disappeared. Even his own lawyer, who he contacted the cooperating agency through, he doesn’t know what’s happened. So we think he was just feeling the situation out.

But, yeah, that judicial process for all those cases are running at the moment in Nigeria. We have similar relationships in Ghana. I was able to identify a sextortionist a couple of years ago in Ghana. He’s been in jail since Christmas Eve 2024 or 2023. So he’s a Nigerian in Ghana, and the prosecutors there are looking at 25 years without parole for aggregated circumstances, because he would videotape himself, video himself uploading the intimate videos that he got from his victim to pornography sites to torment her into giving more money.

And so that escalated it to aggravated circumstances, and Ghana’s taking it very serious. 25 years now by statute you can get for sextortion.

Protecting the Vulnerable and Threat Hunting Strategies

David Redekop:

So let’s use this moment to flip a little bit into a story where I had you involved with a personal friend of mine whose daughter was groomed, and the groomer was someone that we or they wanted to identify, who it was, and it was someone that was interested in pictures of his daughter, obviously.

And, tell me how you went about, without revealing any details, broadly speaking about quickly identifying who the perpetrator was, because that’s all that, in this particular case, needed for it to stop, for the individual to know that he was now known. Talk a little bit through that process that would help any potential parent or any potential young person in preventing to be victimized.

Michael Roberts:

Sure. That was a long time ago, so a little bit blurry in my memory. But generally, those types of cases where there’s vulnerable persons, kids in particular, if it’s on WhatsApp, for example, or TikTok, things like that, those, again, sociopathic organizations hold the keys to all the evidence needed to unmask that person, and it would not be unduly burdensome for them to unmask that person if they would cooperate, whether it be with law enforcement or private.

They will not cooperate with us. No, we need judicial process, and we’ve already discussed the reasons why that’s not gonna happen, because law enforcement’s overwhelmed. So we need to get past those firewalls legally, and the way we do that is we engage the individual with what we call a tripwire.

Some people might call it a canary token or something like that. And so we’ll send a pretext-based message to, to the individual through the platform that they’re communicating with the, the victim or the target on, and in the hope of catching an originating IP address and fingerprinting their device.

So there’s nothing malicious about it. It’s just normal internet protocols and the information that’s exchanged for the internet to work. So we capture that, we isolate it, but we do it in a way that it’s a, let’s call it an orphaned link. So it’s just a link, like a phishing link that they click.

We have a good story wrapped around it to social engineer them into following it, like a bank, a fake bank website that we’ve set up. We’ve got thousands of these domains for different purposes. And then we follow the breadcrumbs back. Then there’s open-source intelligence, there’s dark web intelligence tools that we use, and we also have access to closed-source intelligence.

So closed, CSINT or closed-source intelligence is information that is provided to us by financial institutions, crypto exchanges, social media platform staff unofficially who are mission-driven. They understand the problem, and we can’t abuse that process. If we did, we’d be cut off. There has to be a public interest for the disclosure, and it’s almost never admissible in court, not because it’s gained illegally, but because the people who provide it will not testify.

So it’s on condition that it’s unattributable, it’s not attributable, it’s not admissible. They’re just breadcrumbs that can give us a new starting point to get closer to the threat actor. And, so yeah, we rely on a lot of that. And often criminals will slip up. They might go to a pornography website or something like that, click a phishing link or a malware link, and then they might have a complete dump, stealer log dump of their device, for example.

We’ve caught a lot of criminals like a French pedophile that I uncovered almost two years ago. I have him dead to rights that was communicating with four minor girls in the United States that were influencers, which I tell you, parents, don’t let your kids be influencers because they will be targeted.

And, I identified him. His first name’s Marc, M-A-R-C, and I know where he lives. I proved that he was using the ProtonMail email account to communicate with this girl to send very disgusting messages. I have his full activity log from this stealer file, including the pedophile pages that he visited, the file names that he uploaded to the pedophile sites.

We can’t see the files, but we can see by the naming in French what they are, in some cases who they are. And nothing has happened. We’ve got him dead to rights and nothing has happened. He’s on the loose. He doesn’t know we’ve caught him yet.

David Redekop:

And it’s moments like this that you start to wonder, how do you just take this into your own hands, to take him off the streets? Of course, we don’t cross that line, but you think about it.

Michael Roberts:

And I’m now in the process of reaching out to French activists. But the problem is there’s this guy himself pretended to be an anti-child abuse, and that some of his communications with the parents of the girl were under the sock puppet account that I protect children.

But he lives these different lives with different personalities. I’ve got an exhaustive list of his 32, I think, email addresses that he uses. So it gets quite frustrating. And I’m describing this to you now as if I’m like reading a shopping list, but you start to get a bit numb to it after a while, the frustration, the disgust, and, yeah, but hopefully Stingbase will make a difference in the Stingforce community.

So Stingbase is a SaaS platform that we’re building that will allow aggregation and telemetry to be shared at the speed that criminals work with and if law enforcement don’t take the case or are not fast enough or MLAT’s getting in the way, we’re hoping that the platforms, the social media platforms, the banks, the crypto exchanges, the telcos will add new policies.

So part of the project will be giving suggested wording for policy amendments, use of terms of service that they can share, again, where there is a clear public interest information that will help, at worst, disrupt the criminal organizations or the criminals themselves, and at best, maybe even speed up the investigation timeline and allow us to hand a complete case over to law enforcement that is so appealing to them because a lot of prosecutors won’t touch something if they’re not guaranteed a conviction.

Even if they could disrupt the crime and save the kids or save the pensioners who are getting ripped off, they want their resume to have 99% conviction rate, and that’s not justice. That’s not mission-driven. That’s greed and it’s self-promotion. So they’re denying justice for their own resume. And so if we can hand it to them as a complete case where they just do a parallel reconstruction of our work, and when I say our, I mean people all over the world that are joining Stingforce that want to be part of this from the different organizations I’ve already described, and then we consolidate that work, hand it over.

It’s an AI native platform that can do a full month investigation in a day, in some cases, and actually find things that human won’t, humans won’t find.

Outpacing the Adversary and Reforming Platforms

David Redekop:

Well, we do know that modern democracies are really built upon a assumption that there’s a certain low number of criminal intent mindsets. So that freedom itself can scale, right?

But it seems like if criminals are aware how far they can get away with things, even when they leave plenty of digital breadcrumbs everywhere, that to me almost gives more criminals to keep on doing what they’re doing because of how slow the wheels of justice traditionally move.

Michael Roberts:

Yeah, crime pays. Crime pays today, yeah. We literally trademarked the phrase “justice at scale.” Those three words, we’ve trademarked it all over the world, and those three words sum up what we hope to do. If we can get enough people to catch the vision and come on board with it.

David Redekop:

If we talk further about this it could get quite depressing to look at the reality, but you and I are both optimists in terms of looking forward where we can change the future. Let’s switch back to the criminal cybercrimes just for a little bit in the area of the massive spikes that we see in organized financial scams, the crypto drainers, the pig butchering operations that you and I have discussed at length.

So from an intelligence and disruption standpoint, why are traditional legal mechanisms still failing? I know you’ve addressed some of this already. And how does an active counter-engagement help?

Michael Roberts:

Well, the counter-engagement, where we use social engineering to trick them into thinking we’re a fat cat victim and they’re ready to send them money, it just helps us to map out the infrastructure. So we can find the servers that they’re using and there’s a money trail from the server provider. We can find the registrars for the domain names. We can find the WhatsApp evidence and things like that.

But they need to play nicely with us, which almost nobody does with private for all the aforementioned reasons. So we could disrupt at a much greater scale with that cooperation. We don’t get it, so we just do our best piece by piece, pivot point by pivot point to find the infrastructure, and then, we send out notices of concern to the providers, to the vendors in the hope that they’ll pull them down.

And sometimes some domain registrars, for example, within hours they say, “Yep, we looked at it, we suspended these domains.” All they do is suspend it. What they need to do is put a holding page that says, “This has been suspended because it’s scamming people. If you’ve been scammed, call the police.”

But they don’t do that. So the people that have already been scammed try to log onto their account on the fake investment platform, they don’t get the notification. So these are some of the policies that we need the terms of service to be rewritten across the board. If WhatsApp does suspend a number, A, they don’t tell us.

We get no feedback, so we’re not encouraged to keep on going. Most of them don’t get suspended. I’ve got one case where I have the scammer on my WhatsApp account, and I’ve been communicating with her for more than two years, and she’s stole more than 500,000 US dollars from a woman named Ashley. And I’ve just got the name Ashley Scammer, right?

And, I’ve reported it multiple times. I did an experiment where I sent the number to multiple people and asked them to connect with that person and say, “Hey, I was given your number by somebody else. How do I make money on crypto?” Just to get the chat going and then report it. So I know that this particular number’s been reported more than 53 times, and it’s still operating.

She still pings me, asks if I’m ready to invest yet, things like that. And I’ve tracked her down. She’s a Chinese national or a Chinese native speaker living in Kuala Lumpur using SpaceX modems. And I’ve given Starlink the IP address details for that, and that, as far as I know, that same modem is still being used. Starlink was a total nothingburger in their response.

David Redekop:

Judicial process only. And that’s what we find, broadly speaking, in the cloud hosting providers as well, right? Because these scammers, they rely on being able to set up and utilize publicly available infrastructure. And so if they separate it across jurisdictions, then it makes it that much more difficult for service providers to just throw hands up.

Because if it’s not part of their mission to protect people, if it’s not part of their mandate to actually do a public good, then to your earlier point, then why would they? You and I are also working or were on another case together that was a pig butchering scam that does not show any obvious outward signs of being one for quite some time until you do a deep investigation.

It’s an actual New York address. It’s registered as an exchange, but then it turns out that it actually does an exchange of fake coins that don’t even exist. But to the subscribers of the exchange platform, it looks like they can do leverage contract trades. But really, their leverage contracts trades they’re doing are completely fake, and it’s the operators that determine the supply and demand price so that there can be a buildup of a win and then a sudden rug pull.

But, the complexity of these scams is mind-boggling because you have to literally be a subject matter expert in order to even detect some of these scams. So is there any end to the scam ability?

Michael Roberts:

Yeah, I hope so. But it’s gonna need, like I said, user terms of service changes and some sort of mandate for prosecutors that we hope as part of Stingbase, that there will be for internal use for users, that they’ll know which prosecutors you don’t want to take the case.

We want to start rating them. Who does plea bargains, who doesn’t take cases, things like that. And, just on the case you just talked about, even though it’s not that specific case, through a dark web StealerLog breach, I just identified a Pakistani national living in Lahore who provides the full infrastructure for those fake scam websites, including the backend API that look like you’re making profits.

And so he is not only providing the website templates, he’s providing all the beacons and all the API connectivity from what I can see, at least 50 active sites right now. I am working with DHS HSI right now on this one. They want this case because it’s an easy disruption and convictions because we’ve identified an individual in the US that is using the infrastructure.

And Pakistan has a good cooperation for this. And there’s tens if not hundreds of millions lost because of this guy. He’s a brilliant coder, and I can even see what his day job is. So I found his Fiverr account and all sorts of things. So hopefully that one will be a big one.

But again, we need to get the domains seized and the holding pages because the victims will always go back, say, “How come I can’t log in?” And with Nigeria, the Nigerian federal authorities have worked with us and given us permission to do, it’s called a controlled operation. So if there is a commissioned officer that’s usually inspector or higher in common law-based countries, Canada being one, a controlled operation is where a law enforcement agent is given permission to hack, essentially to break the law to effect to advance a criminal investigation.

So we’ve been effectively, in the past, deputized in some cases, for lack of a better word, because the agencies we were working with didn’t have the hacking skills, and we’ve been able to get in and take control of a lot of infrastructure, burn it down, capture the files, find other victims by getting in there.

And we just need to scale these skills, and this is part of all the skills that we’re training our Stingbase system. The skills that we’re teaching, it will allow people that don’t necessarily have this level of threat-hunting capabilities to be able to do threat hunting effectively because we’re automating it through the AI systems that we’re building.

We’re building it in such a way that nothing falls through the cracks. So you’ll hear that a lot if you’re on the dev team, nothing falls through the cracks. The to-do list, the witnesses, the subpoenas, everything that have to be done, those buckets are all created because when you’re on the hunt, when a threat hunter is doing triage, a lot of intel is found very quickly. What do you do with that?

And it’s easy to slip through the cracks or forget something. So we’re building it so it’s watertight. And it builds, like you said, a one or two-year operation can be done in a week with our system. So yeah, we’re excited about what it can do.

Fixing the Broken Regulatory Framework

David Redekop:

Yeah. I’m excited about your AI-first approach because criminals, by many measures, are actually far advanced in their AI usage compared to the defenders because they’re using it for automated social engineering, for rapid money laundering.

And the defenders need to be even more equipped to use it faster, and find a way for their AI use to work against them and not for them. Yeah. Michael, if you could instantly pass one global standard or regulatory change for digital platforms, you talked about that there’s gonna be a need for a terms of service change.

But if you could pass a regulatory change for digital platforms, banks, ISPs regarding threat intelligence sharing, what would that be?

Michael Roberts:

An obligation to disrupt crime when they receive credible signals of fraud and crime that’s not necessarily judicially provided, such as from my team.

WhatsApp, for example, every time somebody reports a number like I’ve done, we don’t know how many times it’s been reported, only WhatsApp does. We need to take that outside their firewalls, and that’s something that we’re doing. We’re doing a without-excuse-type proof of service system where those crime signals and takedown requests can be done outside their firewall.

So if a grandma loses her life savings from this WhatsApp number, specific WhatsApp number, three months after it was reported multiple times by others for crime, then maybe WhatsApp will start becoming liable under RICO laws for unmade, unwritten, an unspoken meeting of the minds and benefiting from the user base of WhatsApp who are then, if they know it’s criminal activity, then they should be held accountable like a getaway driver and a trigger man.

David Redekop:

Like in Canada, we have a FINTRAC, right? Which is Financial Transactions and Reports Analysis Center of Canada. That is Canada’s financial intelligence unit effectively. You’re suggesting that kind of an approach where it’s a separate organization, but it overrides the country’s or the company’s individual terms of service authorship.

So if you wanna be a service provider in the area of social media and you’re classified as that, then you must be in compliance with this basic requirement. Is that what I’m hearing you say?

Michael Roberts:

Yeah. If somebody knows what they should do and don’t do. It’s a sin. And these guys don’t do it.

And, yeah, there needs to be this fiduciary obligation with legal consequences for the platforms if they do not act on a credible fraud or crime signal.

Getting Involved and Final Advice

David Redekop:

And so for threat intelligence teams and even private sector defenders that are listening, who want to be more proactive in disrupting threats rather than just reacting to them, because that’s our entire space, where should they start?

Michael Roberts:

Stingforce is an unincorporated entity, and it’s a collection of people who want to use the Stingbase platform when it’s released. So they can go to LinkedIn and look for Stingforce. They’ll see there’s a LinkedIn group which they can join there. Not a lot of activity over there.

It’s just a bucket for people that express interest. So they can also go to stingforce.com and sign up for the newsletter, and again, not much happening just yet, but they’ll be notified as things start to move forward. Become a citizen disruptor or a professional disruptor of crime by joining the Stingforce collaboration.

David Redekop:

I hope you get a lot of momentum in that because sadly, a lot of the times, people are moved to action only after have someone close to them experience a major problem, right? I’ve had enough interface with people that have been victimized or almost victimized and saved by the skin of their teeth that this is a very important topic to me, very personal.

And so that’s why I wanted to check in with you, Michael. And before we end the recording today, what is one piece of wisdom that you would like to leave with our listeners? Or what’s one piece of advice or information that you’d like the whole world to know about your space?

Michael Roberts:

Okay. Half the world uses WhatsApp. When you get a wrong-number message on WhatsApp, “Hi, Mary. Are you coming on the weekend?” Who’s Mary? That’s a scammer, and that’s a pretext, and they wanna start a relationship with you and ultimately scam you. And they’re getting the old people in particular. So they’re pensioners and they’re retirees.

Warn your family, warn your friends, whoever hears this, tell everybody, if you get a wrong number on WhatsApp or on iMessage or anywhere else, it’s very likely a scammer, and very possibly a slave, by the way, in a scam compound in Cambodia or Myanmar or somewhere like that. And also for kids looking for CSAM material, the kids will get contacted on the different games that we’re pretending to be kids, but they’re not.

They’re predators. And the kids should never respond.

David Redekop:

Oh, kids should be offline. But parents, you make a deal with your kids, you get to see everything, and tell them not to talk to strangers.

Michael Roberts:

That’d be a great product name, David: Don’t Talk to Strangers.

David Redekop:

Don’t Talk to Strangers, that’s right. And now we’ve added Don’t Listen to Strangers as well. And that actually leads me to a request. It would probably not be in the best interest of Meta, but in the same way that Apple’s iPhone has had a feature, since the beta launch, I’ve turned it on, where anybody who attempts to call me that isn’t in my phone book, the phone never even rings.

I would love for that to be a WhatsApp feature, where I can’t even be texted on WhatsApp unless the source is already in my address book.

Michael Roberts:

You know what’d be really cool? Meta has in its possession, it’s the custodian of every fraud report for every WhatsApp number. So if that WhatsApp number contacts you, it says, “You’ve got a new request from such and such, and by the way, it’s had seven reports of scams,” wouldn’t that be nice?

David Redekop:

Wow. It would force the attacker to cycle through more numbers.

Michael Roberts:

Will have to work much, they’ll still be criminals will be criminals, and they will just have to work much harder to succeed. At the moment, WhatsApp and Meta have lowered the barrier to entry to online crimes. They make it very easy for hundreds of thousands of criminals.

David Redekop:

And to your point at the beginning of this call, that it boils down to their mandates, right? They have a fiduciary responsibility to increase shareholder value, and it’s not one of their mandates to do the right thing.

Michael Roberts:

Yeah. If you have to spend money on crime fighters and you’re immune for it under Section 230(c) of the Communications Decency Act, or your policy saying, “We only act on judicial processes,” why spend salaries on talented threat hunters when you don’t have to?

It’s not just Meta, I should say. It’s everybody, but yeah.

David Redekop:

Yeah. But on that depressing note, we’re gonna have to end it today because you and I both have work to do. Very good. Thanks for the call. Thanks, Michael.

Announcer:

The Defender’s Log requires more than a conversation. It takes action, research, and collective wisdom. If today’s episode resonated with you, we’d love to hear your insights. Join the conversation and help us shape the future together. We’ll be back with more stories, strategies, and real-world solutions that are making a difference for everyone.

In the meantime, be sure to subscribe, rate, write a review, and share it with someone you think would benefit from it, too. Thanks for listening, and we’ll see you on the next episode.