📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

STOP Doing THIS on Your Phone Right Now!

Rossen Reports41:35

Transcription

Welcome to Rosin Reports. I am Jeff Rosson. Packed show for you today. A lot of important things to talk about because there are some threats coming at you with some brand new scams that we've just learned about, um, that we are going to expose and you are going to see some of them play out on camera.

This is a new spyware scam that we're going to start with. And what's so dangerous about spyware, you probably heard it before, malware, spyware. This isn't one of those scams that just takes your money. Worse yet, they don't take your money immediately. They want to get into your phone to watch every keystroke, everything you do. So, it's not you falling for one scam, they get a thousand bucks or even if they get a lot of money, this is them getting money over a period of time because every time you type in a password, every time you go on your AMX app, they are there along with you watching everything and they have new ways of getting in.

There's also ransomware attacks going on right now, too, where they actually hijack your phone. We're going to get into all of that. They even are trying to get your signature. There's a lot to get to and there's the brand new tactics that they're using. There's also I'm going to show you I do a real-life experiment with this and my personal information is stolen live on camera. Do you see what I do for you? So, you're going to see all that and how not to and how to avoid that so it doesn't happen to you.

We also have a brand new Apple scam targeting you if you have Apple devices. It's called the high alert scam. I'm going to get into all that.

There are also stores now, we just got word that there are stores, and I'm going to name the stores for you, that now have placed or they have license plate reader cameras, special cameras that read your license plate in the parking lot. So, now we've talked all about the surveillance of stores tracking you when you're walking around, and that's bad enough. Now, they're tracking your car. They know what you pulled up in. They know when. They know what you what you walked in with. They know what you walked out with. They know everything. And they can track your vehicle with these license plate readers. And the big question, do police have access to this information? We're going to get into that.

Plus, we found a map. This is sick. And we're going to give you the website to go to a map where you can see where all of these license plate special cameras are all over the country. You can just type in your zip code, your city, your town name. Boom. It'll zoom it right in and you can go find the parking lots that these cameras are in. So, you're just for that, you're going to want to stick around because they're in a lot of neighborhoods and there's a major data breach to tell you about with one of the biggest home security companies in the country. You probably have their alarm in your house right now. When there's a data breach, it's dangerous. When a home security company gets a data breach, it's downright scary because you're relying on them for home security. And now your personal information, including perhaps alarm codes being leaked out on the dark web right now. Uh, we're going to name those names, too, and tell you exactly what to do.

Uh, in the meantime, join the chat. Join the chat right now. Let us know where you're watching from. Let us know what you're up to. We love hearing from you guys. Oh, very personable. Thank you, Karen. I appreciate that. You and you and my mom think so. No one else, but thank you. Uh, Connecticut's in the house. What's up, Paul? So, keep the comments coming. We love it. Also, hit like on the video with a little heart or a little thumbs up. Really, really appreciate it. It does world world of wonder for the algorithm. Sends it out to more people. So, I really Oh my god, look at these comments. They're so nice.

Also, since you love me so much and I'm so personable, become a Rossom Reports member. We've just launched this where you can hit the join button on your phone. If you're watching this on a on a computer or your phone, hit the join button and become a Rossom Reports member. You get access to all these stickers. We have um early access to videos, membersonly live streams. If you're watching this on your TV or anywhere else, you can scan the QR code right now. Just point your camera right at that QR code. Sign up to be a Rossom Reports member. We get together, you can ask me questions in a more kind of comfy environment where it's comfy and cozy for just the subs, just the members, and early access to videos, lots of other perks, and you get access to all these cool emojis. Wow. So, scan the QR code or hit join on your phone right now.

All right, let's get right to it. This is important. The genius new spyware scam that is exploding right now. Spyware has been around for a while, but now the thieves and the criminals are using AI. There are new tactics to get into your phone. And they don't just want your money. They don't want a one-time shot. They want to get inside your device, inside your computer, logging your keystrokes, watching everything so they can slowly slowly just drain you dry, bleed you out financially. Then we're also going to talk about ransomware where they hijack everything. Um, I want to show you the very latest scam with spyware. And wait till the end because there is a twist here.

>> Looks like it's the real deal. They are new phishing emails that can fool you and your computer's security systems. Checkpoint Research says in a recent 30-day period, it uncovered 200,000 of these new elaborate phishing emails, mostly in the US.

>> What they're doing is manipulating the URL to make something that is bad look good. So, when you click on it, you're none the wiser that this is actually a bad website. And your security systems are also likely none the wiser. So, it takes you to a site that for all intents and purposes looks good, but in fact is not.

>> If you click the link, hackers can install malware onto your device and even hold it hostage, or they can try to get you to give up personal login information. These new phishing links can look like landing pages to your email accounts, an important document to review, or a request for your signature.

>> Boom. That part at the end, the request for your signature. That's a huge new twist where now, but think about how popular DocuSign is. Once they have your signature, they can walk into places and practice your signature. They know your account numbers now because they're spying inside your device. And now they know exactly how you sign as well. They can do it online or in person. And there's a second part of this spyware scam that is incredibly dangerous. It's called quishing. I don't know who names this stuff, guys. I I I quishing. Q U I S H I N G. Anyway, it it sounds more lovely than it is. It's a QR code scam. And the worst part of this one is it's not just in private. This one targets you in public places, restaurants, parking garages. We all use QR codes all the time. Not the ones that I'm showing you guys. The ones I show you were vetted and there awesome reports approved. I'm talking when you're out in the wild and you got to pay at the meter, when you got to scan a restaurant menu. The thieves have figured out easy ways to replicate where it looks real once you click into it, but boom, they're there in your device. I did a real-world experiment to show you how this works. And I worked with a a world-renowned cybersecurity expert who's going to join us in a minute to help you with some tips on how to protect yourself. He stole my personal information, my real personal information, no joke, live on camera. The stuff I do for you. Watch this.

This hacker is about to wreak havoc in this restaurant. He just did it. Did you see it? Watch from another angle. He slides a menu onto the table that looks just like the others. It has a QR code that you think leads to the menu, but instead it brings you to a fake website that looks just like the restaurant's, but it's run by him. So, you know, since COVID, right, they don't like giving out paper menus. A lot of restaurants, a lot of the tables have the the QR codes on them to get to the menu. So, I'm going to open up my camera. I'm going to scan that. It brings me to this website right here. Anony's Fish Grotto. That is their logo. It looks legit. Get 10% off your next meal. And to unlock that, I need to sign up for an account before I get to the menu. So, I'm going to I want a deal. I'm going to sign up for an account. Jeff. Beep. I'm going to type in my password like this. Hit continue. Now, here's the menu. And the menu looks great. Looks totally normal. And then I just order. That's how easy it is on this end. And I have no idea that something just happened to me.

>> While I'm ordering food, the hacker is outside collecting all my information in real time. Luckily, in this case, the hacker is security expert Jim Stickley, and he's working with us.

>> So, I switched out the QR code, and that was obviously really simple. And now I can see he already scanned it with his phone. There's his email, jeff.roson. Oh, and there's his password. Look, it's actually pretty simple just having that information. Most people use the same password for all of their accounts. So now I can go online and start typing that same email address and password to every type of system. So I can look at his Facebook or I can look at Amazon or I can look at any of those major retailers out there trying those same credentials. And just like that, I'm in all of his accounts.

>> But it's not just restaurants. It can get even more dangerous. The FBI warning it's happening in places that make you type in your credit card information, like parking lots. Watch what Jim does here, putting his QR code on the sign over the real one. More and more parking lots across the country are doing this where instead of having an attendant or an actual machine where you put your credit card in, this is easy for them, right? You just uh hit the QR code so you can enter. There it goes. You can enter your credit card information. So, it's asking for my license plate. Looks very much like a legit site. License plate there. I'm typing that in. First and last name, Jeff Rosson. My credit card number. I'm typing that in, but I'm not going to say it out loud, guys. Sorry. Make payment. And done. Jim. Jim's just off camera here. Jim, come here. You have that information?

>> Yeah. Yeah.

>> Already?

>> Already? Yeah. I mean, right now I'm looking at your name. There's your credit card number.

>> Read it to me then.

>> Three. What's the expiration date? What's the what's the security code?

>> And that's the most important part because for me now I can go online and start shopping because as you know you need a credit card, you need expiration and you need those last three or four digits and that's what lets me go and buy anything I want with your credit card.

>> And so by the time I get home, you've already

>> Oh, absolutely. You're out here doing whatever you're doing. By the time you get back to your car, I've already had my fun.

>> So what is the what do we do here? What what's the tip?

>> Well, I mean like for this one, for example, this is really simple. When you walk up to any of these boards like this, just go like this. See if these things peel off. If they peel off, that that's not a good sign. Don't use this.

>> That simple.

>> Yeah, real simple. Uh, if you're at a restaurant, when you scan the code, if it pops up and says it wants your personal information, name, email address, it wants you to create an account, any of that stuff at all, stop, call the hostess over and say, "Hey, what is this asking for this information?"

>> And they may say, "We don't."

>> Exactly. And then that's when you know there's a problem.

>> Or ask for a paper menu like I do.

>> Yes. Old school paper menu. He got my information and these scammers are getting your information in real time. And they're not sitting in front of you. They're in another country. They are very hard to catch. They are in China. They are in Russia. They are overseas. India, some huge, you know, you know, center where they're all sitting around stealing information and it's a cottage industry just from a QR code from a restaurant you're at locally and they hire somebody locally to swap the stuff out and it looks real. So follow Jim's advice.

There's also a giant spike right now in ransomware ransomware scams. So, this is even more diabolical because yes, losing your money is terrible, but what about losing your money and them locking up your device, your files, your photos, your videos, your account information, everything in every one of your devices, your documents, unless you pay them a ransom. And by the way, it's not only happening to people. Believe it or not, it's happening to big cities. And you're like, "Okay, well, that doesn't really impact me." Yes, it does. Because guess who holds all of your personal information? Big cities, hospitals, the electric company, the utility company, water. So, when they're hit, it can ruin your life. And you don't even know about it until it's too late. Watch what happened to this guy when his city got hit with ransomware.

>> Address, a driver's license number, social security number.

>> Oakland native Dick Warmarmac is living through a financial nightmare. on the credit report. There's credit cards that should have been closed. They're now open with balances of like $17,000, um $30,000 and I don't have them right now. Yeah, I have no idea what's going on.

>> Months after the city's network was hacked, he says his credit score dropped more than 200 points. But little did he know that was only the beginning.

>> You think your identity was stolen from the Oakland hack?

>> Yes. Yes. I mean, I'm getting the phone calls, the emails that I get stating, "Oh, you have this account, you have that account." I've been getting letters from Chase and u Bank of America. I don't have a bank account here.

>> After the hack, the IT team consulted cyber security professionals to download the leaked data. This was an attempt to get a better idea of the impacts facing victims due to a limited response from the city. That's when we found Warmarmac's social security number published on the dark web. If you look at my email now, my entire list of emails, it all reads fraud. It looks like my junk mail.

>> Warmarmac is one of dozens of victims the IT team contacted who previously filed a claim with the city alleging injury, but instead ended up with their sensitive financial information leaked. Now he says fraudulent checks are being made in his name.

>> So I don't know what this is.

>> $2,000.

>> Yeah. to strange sewage and water bills being sent to him.

>> The water and sewage wasn't from East Bay Mud. Like, what is that? Is that New England? So, how can I have an open balance

>> and then this

>> there's things that are popping up on my phone. I'm getting notices about refinancing a home and I'm like, I pay rent.

>> Worm believes someone has even purchased a home in his name.

>> Somebody has something in my name somewhere since October. I've been getting things from Best Buy about kitchen installations.

>> And to add to the stress, he says he didn't even know about it until we contacted him.

>> Right? That you don't even know about it. You're getting all this weird stuff. It's not like the city is telling you, hey, we have a ransomware attack. They usually try to keep it private because they may be negotiating with the terrorists, with the scammers, even though they say they don't do that. Do they pay to get their information back or not? Meanwhile, you're suffering.

We have all the tips for you on how to avoid all this. So stick around just for a second because we are going to run through what you can do to kind of lessen your chance of this happening and avoid these problems. But the big question I had when I was watching all this is how easy is this for hackers? Has it gotten so much easier now in 2026 because of AI? Um, and I came across this video from Vice. um one of these ransomware hackers, spyware hacker too. He's done both. Who's coming clean to expose their tactics? He's hiding his identity. But this is worth watching about how easy this is for them to do now with technology. Anybody can do it. This is insane. Watch.

>> The kind of things that are vulnerable to ransomware attacks is literally everything that is connected to anything. In the old days, for a country to cause disruption to a country as big as the United States, you'd need millions and millions of dollars worth of investment to do something. But today, you just need a few thousand dollars in a laptop and a couple of smart hackers to write some code and send something out. So, ransomware is an attack technique that's been around for decades. Modern ransomware is usually a piece of malware that gets on your system, encrypts all of your data, and then holds that hostage, demanding that you contact the gangs that are operating it, paying them in some form of currency before they'll give you the key that decrypts your data and gives it back to you. The challenge is it's not a scenario where you want to say, "Well, why don't we stop people from paying them?" Because ultimately, you have to protect the victims. I've watched hospitals get encrypted and people are left with a choice. Do I pay to decrypt the data or do I risk lives? Over the last year, we have definitely seen a significant acceleration in ransomware. And I think that's because there's been a huge increase in the profitability. Back when it started, ransomware was charging hundreds of dollars, maybe thousands of dollars for uh individual targets. The bigger payouts that we're talking about now are easily into the tens of millions.

>> Insane. By the way, is that beard part of the mask or is that really? Anyway, I think of the weirdest things. Um, a few thousand and a laptop. That's all you need. A few thousand and a laptop. And when you picture a hacker, I know I've always pictured hackers as, you know, these lonely, you know, men, adults sitting in a basement with a dark hoodie like this, you know, kind of sitting there just, you know, right. It's not that anymore. Now it's kids. Can you believe that? It's children as young as 13 years old. How are they being recruited? They're being recruited on popular gaming apps like Roblox. The cybersecurity, not the cyber terrorists are trolling these game sites looking for amazing players, saying, "Wow, they're really good." And then they pretend to be another kid playing the game and slowly recruit them to be a scammer. This is one of the most crazy clips I've seen and I wanted to show it to you. There is a kid who is going to jail right now for being a hacker for scamming people online. He was recruited and he admits if they didn't catch me, if they weren't sending me to jail, I'd still be doing it. This is insane.

>> I need my punishment. I wouldn't say everyone needs prison, but I think I need to go to prison for what I did.

>> Matthew D. Lane. Shortly after graduating high school, this Massachusetts teenager, Matthew Lane, helped launch what's been called the biggest cyber attack in US education history.

>> Potentially concerning news for parents.

>> The PowerSchool data breach out one of the largest student information systems in the world that has potentially exposed the personal information of millions upon millions. The company reportedly paid close to $3 million in ransom to recover the private information of 60 million students that Matthew helped compromise.

>> I definitely knew what I was doing in spectrum of hackers like like here.

>> Matthew, now just 20 years old, sat down with ABC News for an exclusive interview 2 days before reporting to federal prison.

>> I'm going to take my punishment.

>> Are you not scared?

>> Yeah, of course I'm scared.

>> For Matthew and so many others like him, his gateway to cyber crime was a gaming platform that most teenagers know, Roblox.

>> Here, every game is built by the community.

>> It's an online space where gamers can connect with players from all around the world and even create their own games. It wasn't until I was like 13, 14, a friend that I knew, um, he put me on, uh, the Roblox stream program and then I started to get into that and just kind of spiraled from there. Honestly.

>> The bad guys are on all the platforms watching the kids playing and when they see an elite level performer, they go approach that kid masquerading as another kid and they go, "Hey, you want to earn some crypto? Here are the tools. Here are the techniques." It's way more than driving 120 mph on like a back road or a highway. Incomparable to any drug at all. As well.

>> Individuals as young as 14 are being interviewed by the FBI.

>> The cases are startling. From a 17-year-old who hijacked the social media accounts of Barack Obama, Kim Kardashian, Jeff Bezos, and others to the 15-year-old hacker who allegedly cost major Las Vegas casinos more than $100 million. Another team said hacking was his hobby before breaking into thousands of platforms at the massive sports betting platform DraftKings and stealing hundreds of thousands of dollars.

>> When was the last time you hacked someone's account?

>> Less than a week ago.

>> Here he is being questioned by police about his years of hacking.

>> Do your parents know a fraction of this? How do you think they're going to react?

>> Not their best.

>> The average age of someone arrested for serious crime is 34 years old. Average age of someone arrested for cyber crime is 19 years old.

>> There was the 19-year-old New Yorker who from inside his parents' house founded one of the world's leading hacker forums, a global market for stolen data that Matthew Lane frequented. It was called Breach Forums and that's where everyone flocked to.

>> The FBI nabbing its founder in an elaborate raid.

>> Walk out.

>> I have a 14-year-old son who played Roblox all the time. It is frightening. And the ma this Matthew was an innocent kid until he was recruited. It is absolutely terrifying. I want to bring in a world-renowned hacker, but he uses it for good. Uh, one of the best hackers in the world, Jim Stickley, um, who you saw in that report with the QR code who stole my personal information. He's still running up tabs on my credit card. Um, Jim, you see this about kids doing this? I mean,

>> are these gaming platforms absolutely incredibly dangerous and where I mean, what do you think when you see a kid this young who's able to just scam tens of millions of dollars out of people?

>> I mean, I get it. I completely I watch this and I go, man, I I started hacking when I was a kid. It was different back then, but I would have done the same exact thing. Like there's no doubt in my mind. Like, and when he's talking about the rush, like I literally could feel the rush he's talking about when he was talking about like it's better than driving 120 miles an hour. Like, hacking is really fun. And it's it is super cool challenge. And I can see how if you've got the skills as a kid, it'd be so easy because at first you don't look at it as a crime, you look at it as a challenge. And so I can see how any kid if they said, "Hey, like I have this opportunity for you. Go. I think you could get into this." The kid's going to go, "Yeah, I get into that." They're not thinking, "I might go to prison." They're just thinking it's a fun challenge. And then once they start doing it, then of course the stakes get higher and higher and it's like like a drug like where you want more and more. And I I could see how, you know, I watched this kid and I feel for him because I could see how he would fall for this so easily, get so pulled in.

You and I you and I talk all the time about um how much technology has changed since you were a kid and you were becoming a hacker. And I should say Jim is hired by some of the biggest companies in the world who say to him, "Hey, can you come hack us?" They pay him to hack them so they can figure out vulnerabilities. Like when you get those security patches on your bank apps or even from Apple or from Android devices, it's somebody like Jim and in often cases it is Jim who's found the vulnerability for them. So Jim, you use your hacking abilities for good, very easily, could use it for bad. How do we protect ourselves in 2026 from a spyware scam, a phishing scam? Let's start there. A ransomware, how they get these links into and they can take over our devices. What are some things we can do in our real life?

>> I I mean the number one thing is you've got to be paranoid. So, like if you receive a text, an email, you know, whatever correspondence and there's a link or there's an attachment, you know, I I feel like it's been harped to death, but yet people seem to ignore when you say, "Don't click on it. Don't open it." Because they kind of can rationalize these things. And so, they'll go, "Oh, you know, I I got a text. It says it's from the bank or it says it's from Walmart or it says whatever." And they just assume it is. And so they click the link, it takes them to a website that looks just like the site they thought they were going to, only it's not. And now that site says, "Oh, we need you to install some software to do something or we need you to enter your credentials to do something." And now you're you're cooked at that point. So it's being paranoid right out of the gate.

>> Yeah. Because we all sit around and like in in in a vacuum like this, we're like, "Of course I wouldn't do that. Only idiots fall for that." People are falling for this every day. There's a reason there are scammers. It's because there are victims and there are smart victims, right? I mean there are people who are old and are young.

>> And that's that's it. Everybody assumes oh well then it's old people. Old people fall for these. Everybody falls for this. It's all the time. Every age.

>> And it's really easy right for an it comes up as Bank of America in your as an email or something. It's very easy for them to mask that, right? You got to hover your mouse over the the actual email address to look at who it's coming from. That's a huge piece of advice.

>> And that even doesn't work now. Um, so that used to work great. You'd hover your mouse over and you'd see like the link it says it was isn't the link it's actually going to. But now there's these things called um h um uh homoglyphs. And homoglyphs allow you to buy domain names that have the character of like an E, but instead of it being an E, it'll be a different language character that looks like an E, but it's actually a different language. So, I could buy a domain name and have it say like Rosson Reports, but where the E is, the E will actually be a different version of an E. So, when you look at it, it looks just like yours, but when you click on it, it's actually going somewhere else.

>> Wow. So, now you can't even look for the actual name anymore because it does look like Rosson reports, but it's a it's another language and you can't tell.

>> Yeah. And in those cases, when in doubt, my recommendation is this. Take your mouse if you got it or even on your phone, drag over. So you highlight the entire domain. Okay? Then go to Google and in the search box just type is this legitimate and paste in what you just copied and hit the little AI verify. Like you have a little AI box to check now in Google. It will come up and it'll say this looks suspicious. Here's why. And it will see the characters being weird and warn you.

>> Oh, that's a great piece of information. That's a great tip. Thank you, Jim. Um, I want you to stick around because we have a couple of other scams I want to get your take on. There's a brand new Apple scam, guys. And it's called the high alert scam targeting Apple users. They know your account information. And again, everything about hackers, and Jim, you can attest to this, is putting your guard down, right? So, if they have your own account information, our guards immediately go down because who else would have that? It is leaked on the dark dark web from data breaches, which we're going to get to in a second. There's been another big one. But they they claim to have access in this Apple scam to all of your money. And um it just happened to this woman. She actually just fell for this and lost a good deal of money. Watch this.

>> It started with a text message that said, "Apple high alert."

>> It is a message that a countless number of Americans have received.

>> Someone has taken this amount of money out of your account. If you did not do that, call this number. Since she did not make the purchase, Barbara, who was asked that her last name not be used, did respond to the text.

>> So, I called the number and the man said, "Well, we want to protect the rest of your money and you you need to go to the bank."

>> Barbara was told by the person on the phone that hackers now had access to all of her funds. So, she went to the bank, withdrew her money, and wired it as instructed to protect her money. This woman's money went to a fraudulently created bank account that was uh it was made online. She wired $20,000 to it and within two hours the money was wired to a bank account in China.

>> Detective Jonathan Martin with the Manheim Township Police tells me this scam is claiming more victims and more money each day.

>> I'd say multiple times a week we we receive a case where someone has fallen for the someone is taking your money. We need to protect it for you.

>> I said I don't. In Barbara's case, she actually lost $24,000 that she'll never see again.

>> If this would help somebody else, as soon as they say wire money, don't do it.

>> Yeah. Never ever do it. And Jim, the other thing when you get something from Apple, right? Call Apple. Go online to apple.com and call Apple yourself. Right. Yeah. Apple's not sending you a text ever. They're just not. It's it's it's something they will never do in the history. They're not there to do security in general. Yeah. When in doubt, go to their legitimate Don't click a link. Go to a legitimate site, pull a phone number, call it that way. Call one of their little stores in the malls. It's it's you're not getting a text from Apple. I promise.

>> Yeah. So, got it. So, that's that's great. Apple is not texting you at all, let alone trying to watch out for fraud. By the way, another great piece of advice I heard yesterday was before you wire money like that, call a family member. call somebody who loves you and just say, "Hey, by the way, I'm wiring this." And usually a family member is going to be like, "WHAT THE HELL ARE YOU TALKING ABOUT? It's a scam."

>> Because we get in our heads when we think our life when we think our life savings is at at risk, we get nuts.

>> Yeah. The banks also ask the teller, if you go to wire money, every bank in America, the tellers have all been trained on these scams now. So if you literally say, "Hey," and most like I'm surprised this lady didn't get stopped because most time they're so used to this now, they see something like this happening, they'll generally say, "So why are you doing this transfer?" And they'll actually ask questions. So you can tell the teller, "Hey, I've got this thing. I'm trying to protect my money." They'll immediately shut you down as well.

>> Yeah. The problem is we don't go to the teller, right? We do it all online. We're doing it from the privacy of our own home and we're freaked out and we wire the money. There is no teller. And you get that little thing that comes up like whenever I wire money on Zelle or something. It's like are you sure this is not a scam? We all just nope. I know it's not. And we we just it's become so it's like white noise now.

>> You're 100% right. That I mean that is that is the sad situation that we're in now is people don't pay attention.

>> Wait, you're a privacy expert too, Jim? It all ties together. This next story is crazy. Stores are now tracking your car in the parking lot. And we have the names of the stores uh at some locations that are doing this. They've set up special cameras that are license plate readers. So, not only are they now tracking you in the store, not only are they using all that against you to price you and figure out what you're doing and build a profile, then sell that data, now they're tracking what car you drive, when you arrived, when you left, possibly merging it with other cameras, possibly with law enforcement. The store is doing it right now. Home Depot and Lowe's just installed these cameras at multiple locations. Uh, watch this, Jim. We'll talk on the back end. And by the way, we have a way that you can check in your zip code right now where these cameras are. It's an amazing website. I just went on it. You're going to be obsessed. And I'm going to give you the website. But here's what's happening at Home Depot and Lowe's with these cameras.

>> Home Depot and Lowe's are among the stores installing special cameras in their parking lots with automated license plate readers hoping to boost safety. Some critics have raised privacy concerns as law enforcement embraces this technology. They're literally tracking everybody that passes, whether you're in violation of a law or not.

>> The cameras, which capture license plate numbers, date, time, and location, are increasingly being used by police, but civil rights groups worry the technology could be used to target suspected undocumented workers or women seeking reproductive health care. Home Depot and Lowe's insist they do not share information with third parties. Lowe's saying it only discloses your personal information if required by law or legal process. Home Depot saying we do not grant access to our license plate readers to federal law enforcement. But experts say with tens of thousands of cameras now installed across the country. Adding more license plate readers will help law enforcement build what could become a nationwide mass surveillance system. They can literally trace almost exactly where I've been just by connecting all of the different data points based upon that license plate number. I can find out where somebody lives just based upon tracking their data. They can recreate my morning probably better than I can recreate my morning.

>> I mean, it's insane. Just for going shopping at a store Jim, they can track our license plates. This is privacy run amok. It's insane. And these are the same cameras the police use. And their argument is that this is giving me safety because they have my personal what I'm trying to

>> They're saying it's to fight theft. They're saying it's to fight theft. They're saying that that people are robbing them blind and they want to see people. They want to be able to track the cars from theft rings and from people stealing. That's the public claim.

>> But the the problem with that theory is already criminals aren't stupid. So they're going to see they put the cameras up. So they're just going to park their car out on the street and they're just carry the stuff out to the street. The only people that are going to be being monitored are the people that are the legitimate people.

>> Yeah, exactly. And by the way, you want to know where these cameras are? Check this out. Look at this screenshot. And let's put up the website on the bottom. So, the company doing this with the it's called Flock is the name of the company that runs all these like license plate uh special cameras. If you go to this website, maps.flock.org, look at this. And by the way, you see in the top left of the screen, this is where all the cameras are. God, I live in Florida. Look at that. It's like all yellow. It's like full of cameras. Um, I typed in you in the top left, you can see you can type in your city, your town, your zip code, and you can zoom in down to the street level and see what parking lots and where these license plate cameras are. So, I did it a few minutes ago and it's absolutely bonkers how many there are. How cool is that, Jim? That we can now look. We're all getting together and we're figuring this out.

>> Yeah, this is awesome.

>> Hallelujah. I stumped Jim Stickley. You've never seen this before.

>> Yes.

>> No, I have not. This is really cool.

>> Yeah. Go to maps. Yeah, Jim right now. Go to I mean, well, don't kill your connection, but when we're done here, go to maps.flock.org on your phone or something.

>> And again, you can just type in your zip code. You can go right in and it shows you like down to the parking lot in the store where the cameras are. It's absolutely um insane. But I think this is privacy gone crazy. Um, and by the way, remember Lowe's and Home Depot both are like, "Oh, we don't share it with third parties. We don't just share it." But guess what? We both know, let me let me give you a little secret. When they give a statement like that, a PR statement. If they get a subpoena from law enforcement, they hand it right over. I mean, these big companies do not fight subpoenas, and the police get, "Oh, yeah. We want the license plates from uh 9:00 a.m. through 3:00 p.m. Uh, done. Here it is. Yep. That's exact. You're 100% right. There's They can't fight it even if they wanted to, but they're they're not going to want to. Why would they?

>> Yeah.

>> So, they can put out the statements. We don't share it with law enforcement unless we're compelled to by a by a by a court. Um, there's a major data breach, Jim, that we talk about data breaches all the time and how important they are. You wonder why scammers have your information. It's when your information gets leaked on the dark web. How does that happen? When a data breach happens. ADT security was just breached. So, I want to tell you about this because it's absolutely huge. Maybe you have an ADT security system at home. A normal data breach is dangerous. When a home security company is breached by hackers, we rely on them for our security, the security codes, home addresses, and your personal PIN codes for your home alarm system. Uh, that's not something you want leaked online. Here's what we know right now about the ADT breach. Your home security system might have been hacked without anyone touching your house. 5 and a half million people just had their personal info exposed after attackers tricked an ADT employee with a simple phone call. No high-tech break-in, just social engineering. Names, addresses, even partial social security numbers are now out there. And here's the twist. The security systems themselves weren't compromised, just the people behind them. It's a reminder that even the smartest tech can't fix human mistakes. So, how safe is secure? Really?

>> Yeah. Not really. Anyway, Jim, the crazy thing about this I just read what makes this is a um the way that this happened was literally just like a phone call to an employee that ended up like a scammer tricked an ADT employee into handing over all this information like unwilling. Unwilling.

>> 1990s.

>> But one person got scammed.

>> Yeah. One person got scammed, an employee, and all of a sudden millions of us are screwed. What happens to this information when it's leaked onto the web?

>> Yeah. People don't realize that's all it takes now. Like they think about all the security that's put on all these massive companies, but oftentimes one employee there has access to the data that's in there. And so if you can just get that one employee, they're cooked.

>> Yeah. What happens when our information when when I say our information our why should we care about data breaches? I always I I want you to say it. I I'm sick of saying it, but that's where it all comes from. We hear data breaches so often from companies we don't know about. In this case, it's a big one. What's happening on the door? What happens as soon as my information's leaked? Where's it going?

>> So, the minute your information is stolen, criminals give them a choice. They can either pay the ransom and then maybe they won't release it or in most cases they just release it. And it gets released to the dark web. And the dark web is basically it's it's a different version of the internet. Still on the internet, but you access through a different browser. Once criminals are on there, this is all just basically search and you know discover whatever you want. So there's these massive treasure troves of data. And oftentimes they'll even put them all together to where you can download billions of records at one time. I said billions with a B. And so they can download these and then they can use software to then target people however they want. And then with AI, I can now use AI to filter through the billions of records and say like, I only want to target people of a certain age in a certain city that work for a certain company or whatever it happens to be. And so they can then fine-tune it down. So I go like, I want to target Jeff Rosson. I start looking for data on just Jeff Rosson and threw out all this stuff. There'll probably be a lot out there. Or I don't care the specific person's name. As long as I have a name, a social security number, address, sometimes a driver's license number, that's all I need to become you. and I'll take that information and then I just started opening up account after account after account and then you're having to deal with all the mess behind it.

>> And we also if they have one of your passwords they can what like try a million a mill Chase Bank of America, Wells Fargo, AMX, City Bank, Discover and just plug that password in. This is why we say have different passwords because they'll just plug it in across the board and see what hits.

>> Yeah. And it's not even them like go oh well that would take a lot of time. They're they're not doing it themselves. There's programs that do it. So, they just take the database that has all of it in there, stuff it into the program, and then it goes out and tries that login name, which is almost always your email address, and then that password at every major site just plows through. So, they can be sitting there playing video games. An hour later, they check to see how many accounts do they now have access to.

>> All right. So, if you guys are a victim of this, freeze your credit immediately. Go on. TransUnion, E, Equifax, Experian, the three big credit agencies. I keep my credit locked anyway. It's something you should all do. It should just be locked. Unless you're like buying a car, unlock it that one day and then relock it. It takes two seconds online and that way nobody can open accounts, big accounts like buying a car, renting a house, buying a house without that happening. Also, two-factor authentication is huge. And what Jim, change your p change your passwords all the time, right? And have different passwords for every place. Exactly. Anything that's like a high risk, bank accounts, email accounts, um mortgages, those types of things. Have a unique password at each one. I know it's a pain in the neck, but it is so worth it.

>> Jim Stickley, world-renowned hacker. Thanks, man. I really appreciate it. I have a good go to go to that website, the what? Maps.flock.org. Yeah, man. Let's go find out where those cameras are so we can we we don't track your car. Jim, thank you very much and thank you at home for watching and we'll see you next time.