Through our Global Voices interview series , we speak with leaders, experts, and practitioners to learn more about emerging trends, challenges, and opportunities in the cybersecurity landscape. Today, we share an interview with Kitboga , YouTube creator and CEO of Seraph Secure, who has been exposing scam operations and tactics through his work since 2017.
What inspired you to start making videos that expose scams and waste scammers’ time? Why do you think these videos have had the impact they have, as opposed to other tactics?
I’m a software engineer and I’ve always been a problem solver. When I heard about tech support scams about eight years ago, I knew immediately that my grandparents would fall for it if they got a call from someone claiming to be Microsoft. If they said that there were viruses on the computer, that there were hackers on the network. My grandma, who had dementia, my grandpa had Alzheimer’s, and they would have gone along with it. They would have fallen for the scam. And so, I had this spark, this inspiration to do something.
I didn’t know what it was going to be. And the only thing I could think of at the time was to pick up the phone and start calling the scammers. I figured if I spent 5, 10, 30 minutes, an hour on the phone with a scammer, that was an hour that they weren’t talking to someone’s grandpa or grandma and an hour that they were a little bit safer.
And as time has gone on, I do think the videos have had a huge impact. I mean, there’s almost a billion views across just the YouTube channel alone, which is way more than I ever would have imagined. I have gotten countless emails from families that said, “Because I watched your videos,” or “because I saw one of your talks, I knew to hang up the phone.” And that’s such a joy.
You’ve built a huge following by turning scam-baiting into both entertainment and education. What’s the most rewarding or surprising feedback you’ve gotten from someone who avoided a scam because of your work?
I’d say in general, the most rewarding is anytime that I hear of a scam being prevented. That was what I set out to do in the beginning – was just to protect someone, to protect anyone. And now through the work that we’re doing with Seraph Secure, we’re preventing scams every single day. And it’s something that truly energizes me and makes me want to continue fighting this fight. To know that there are people who could have lost their life savings and it was prevented because of our work has been huge.
What types of scams are you seeing the most these days, and how are they evolving?
There are so many scams out there today. I would say if anything, they are more aggressive and going after higher dollar amounts. I think that there are more scams than there were when I started almost a decade ago. There are scammers that target very niche subjects. It’s not just someone who needs their printer fixed anymore. There are people who want to publish a book, and there’s a scam for that. There are small business scammers who are pretending to deal with your legal fees and accounting problems, but they’re just going to steal everything from you.
So, I think there’s a lot more scams. We’re seeing it happen all over the world, targeting just about every country. There’s scammer call centers popping up all over the world. We’re also seeing large criminal organizations do scams. It’s not just a couple guys in their back office call center.
The most common scams that I see right now are primarily investment scams and tech support scams. Someone who claims there’s a problem with your computer and someone who can help you make a lot of money. Those are probably the two biggest ones that I see.
What impact is AI having, and how can you tell if something is AI-generated?
It is getting harder and harder to tell if something is AI generated. In the beginning, you could look at their hands or their ears or their hair, and then with video, you could watch when they moved around and noticed the screen tearing or strange artifacts, but it is getting really good.
In fact, a group of scammers that I’ve been following for a while that pretend to sell people high ticket items like cars and trailers and trucks, they are using AI deepfakes to sell the cars to generate photos of these vehicles, video walkthroughs, even testimonials of customers who claim that they’ve bought vehicles. And it’s really hard to tell that it’s AI.
I think that we’re only going to see more of this. I think the celebrity impersonation scammers are going to win huge here because they can deepfake the celebrity’s voice and face and actually get on a video call with you. So I think we’re entering an era where all of the traditional advice is starting to go out the window. When we told people, “make sure you know who you’re talking to. Call them on the phone. The romance scammer, they’re never going to get on a video call with you,” well, now they can. And now all of the pictures and all of the videos are going to look very real. You said how can you tell? The short answer is I don’t know right now. There are AI-generated watermarking tools. So Gemini, Chat GPT and them are watermarking and you can look that up.
I would say right now your best defense against AI is being skeptical of what you see. I don’t think that it’s rude to be skeptical. I don’t think you need to be nervous about that at all. Right now, be careful trusting what you see online, especially if someone is asking for money or your information.
If people are not sure whether something is genuine or not, what would you recommend they do?
I’ll answer this in a few different ways. If someone is calling you, I would jot down a few notes, maybe take the reference number if they have one, and then hang up. I wouldn’t trust that the person calling you is actually who they say they are or where they’re calling from. Let’s say it’s your credit card company or your bank. I would look at the bank’s phone number on their website or on the back of your debit card or credit card and call that number directly so you know that you are talking to the right person. If it’s an email, I would double check that it actually came from the right domain.
If you’re trying to buy something online, I would check to see how old the website is. Like scammers are making new websites every day, all day long. Sometimes the websites are just three or four days old. So, be careful about that.
I think with AI and deepfake type stuff, if you’re really concerned and for example, if you’re on a video call with someone, you could ask them to like move their hand in front of their face or do a peace sign and do things in real time that might obstruct the face or ask them to put a shoe on their head, something like that. But it’s only going to keep getting worse and worse with deepfakes.
You launched Seraph Secure, which scans for existing remote access tools and blocks new remote access attempts that scammers often use. GCA has incorporated Seraph Secure into the GCA Cybersecurity Toolkits. How does this tool help prevent scams, and who should use it?
We built this specifically to protect people from remote connections of scammers. They are very aggressive about gaining access to your devices. Once they’re on your computer, they have full access like you do. They can see your files, they can see your webcam, everything, your emails, bank account. So, it’s really important to protect yourself against this. I think that this is something that just about anyone can use. I built it with my mom in mind because I’ve seen the devastation that it causes and I would never want my mom to have a scammer on her computer.
It’s a free tool. It will remove any existing remote connections. There could be a scammer that perhaps got access to your computer, a loved one’s computer years ago, and they still can get back. So, it removes these connections for free and it also blocks these remote connections from ever coming back in the future.
Thank you so much. It has been a mission of mine and the team to protect as many people as we can from scams and I hope that this helps make the world a safer place.