Technology keeps changing, but many of the most effective scams still come down to something very human: trust. My guest today is Tony Sales, co-founder of We Fight Fincrime and Underworld TV. Tony has a perspective most people in fraud prevention will never have. Earlier in his life, he was involved in organized financial crime and was once described in the UK press as Britain’s greatest fraudster.
After years in that world, and after serving time in prison, Tony made the decision to use what he knew to help stop the very crimes he had once been part of. Today, Tony works with financial institutions, governments, law enforcement, and major organizations to help them better understand fraud, social engineering, money laundering, and cybercrime. In this conversation, he explains why criminals are often so effective at exploiting human behavior, why security training can miss the real-world ways scams unfold, and why friction is not always a bad thing when it helps protect people from devastating losses.
We also talk about the role of leaked data, call center scams, deepfakes, banking safeguards, and why consumers and organizations both need to think differently about fraud prevention. Tony’s message is direct: criminals adapt quickly, and if we want to defend against them, we need to understand how they think.
“A small incident is not that different from a big incident. It's just the level of stress and visibility that comes with it.” - Bryce Austin Share on XShow Notes:
- [01:25] Tony Sales shares his background as a former UK fraudster and explains how he now works through We Fight Fincrime to help people understand money laundering, online safety, and human vulnerability.
- [03:04] Tony describes being drawn into crime as a child, beginning with small thefts before gradually moving into sponsorship scams, credit card fraud, and cloned debit cards.
- [06:10] After getting caught for identity theft and spending years as a fugitive, Tony explains how prison and seeing the impact on his family became a turning point in his life.
- [08:35] How organized crime operates like a business, with different people handling IDs, fraud schemes, fake watches, mortgage fraud, and professional connections.
- [11:40] Why criminal networks rely on trusted introductions, insulation, and layers of separation to protect the people at the top.
- [14:30] Tony explains how criminals adapt in the moment, use confidence to avoid suspicion, and often rely on talking their way out of situations instead of escalating them.
- [18:20] The difference between how criminals and security professionals think, including why criminals are not limited by the same rules, checklists, or assumptions.
- [21:35] Tony discusses how childhood experiences, ADHD, and a lack of structure contributed to the way he viewed rules and boundaries.
- [24:00] Social engineering is not always dramatic or technical; Tony explains how believable stories, ordinary behavior, and quick adaptation can be more effective than elaborate tactics.
- [26:45] How call center scams combine scripts with salesmanship, emotional pressure, and real-time responses to keep victims engaged.
- [29:33] Tony explains why leaked data remains valuable for criminals and how even a name and phone number can be enough to build a convincing attack.
- [31:43] The conversation turns to personal and organizational protection, including Tony’s belief that people need to “patch” the human operating system.
- [34:20] Why fraud awareness training often fails when it is boring, generic, or disconnected from people’s everyday consumer lives.
- [36:16] An example of a bank adding friction to an international wire transfer, and Tony explains why friction can protect people from major losses.
- [38:30] Tony discusses the tension between fast, frictionless transactions and stronger safeguards that may slow people down but reduce fraud risk.
- [41:03] AI, deepfakes, and impersonation scams raise new challenges, but Tony emphasizes the importance of live verification and using common sense.
- [43:24] What consumers should understand about bank security, shared responsibility, and why no system can remove every risk.
- [46:00] Everyday data requests, such as hotels asking for passport copies, can create long-term privacy and fraud risks if that information is mishandled.
- [47:48] Tony discusses online safety, young people, and why banning access to social media may create new vulnerabilities instead of solving the underlying problem.
- [50:15] Why learning from former criminals, hackers, and people who understand real-world attacks can help organizations defend themselves more effectively.
- [52:30] Tony explains why companies need more security talent, stronger resources, and boards that understand the scale of modern fraud and cybercrime threats.
- [54:32] Tony shares where listeners can find him online and learn more about We Fight Fincrime.
Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.
Links and Resources:
- Podcast Web Page
- Facebook Page
- whatismyipaddress.com
- Easy Prey on Instagram
- Easy Prey on Twitter
- Easy Prey on LinkedIn
- Easy Prey on YouTube
- Easy Prey on Pinterest
- We Fight Fincrime
- Tony Sales – LinkedIn
- Underworld TV
- The Big Con: How I Stole £30 Million And Got Away With It
Transcript:
Tony, thank you so much for coming on the podcast today.
You're welcome, Chris. Thanks for having me.
Can you give myself and the audience a little bit of background about who you are and what you do?
Yeah, sure. My name is Tony Sales. I was previously dubbed as Britain's greatest fraudster here in the UK. It's not something I'm proud of. It's what the media and press give me. But it’s extremely good for getting bums on seats in important rooms to deliver—a lot of what the messaging I do today is about money laundering, about keeping safe online, understanding what that looks like, how human vulnerability is by far the biggest risk that we all face today. And I kind of I've been beating that drum for a long, long time. It's one of the ones that I continue to be and will continue to be day in, day out with We Fight Fincrime.
Take me back to the beginning. How does someone become a fraudster?
I mean, for me, I was kind of criminalized at a young age. My uncle, seven years old, kind of lures me into a pub to go and unbump the door for them so they can just get in and nick whatever. It was like an off-license part of the pub that was separate that they actually got into. They just robbed it. It was boxes of Mars bars and bottles of pop back then, used to get the money back on the balls and all that. I don't know if you remember that, Chris, but here in the UK, we had that and we just kind of nicked all that stuff and cigarettes.
I loved it. I just absolutely loved it. It was one of them. My mum and dad had both left by the time I was two days old. I was living with my grandmother. She didn't have money for trainers and for the expensive clothes that not every kid was wearing, but there was lots of other kids wearing them. I wanted to fit into that racket and see that. And that just drove—I think it's actually abused. You kind of come to a point where you just say, “Fuck it.” Like, “I've had enough. I can't take no more. I'm just going to become this person.”
You kind of come to a point where you just say, “Fuck it.” Like, “I've had enough. I can't take no more. I'm just going to become this person.” -Tony Sales Share on XThat then leads on. For me, it starts with going door-to-door sponsorship forms. One week, we're doing a sponsored jump, sponsored spin, sponsored bounce, sponsored whatever it was that I could steal people's money. It gradually elevated through to credit card fraud, debit card fraud. And by the time I was 16, I figured out how to clone credit and debit cards, just buying the machinery. I worked tech, tech, savvy at all, Chris. I was just like an inquisitive kid just searching for this stuff and not knowing a bloody thing about it.
You have to ask someone else, like, “How does it work?” Like, and getting all of that kind of stuff. But because I was driven like that, you know yourself, if you, it's only you that can drive things. You only know the next stuff that's coming by doing it or finding out what's actually there. I was just always like that. And that leads on to 30 years of my life as an organized criminal, like at the highest level here in the UK, being the left-hand man, not the right-hand man, of a very influential underworld figure here in the UK for a long time.
In prison, in 2010, I've been caught. I've kind of come away from all that organized crime stuff here. It's all just kind of becoming too much. I actually, I end up getting caught in a shopping center doing identity thefts in a place called Sheffield, which is, if you're where I'm based in London, that's obviously up north. We just thought we would never get caught with greedy, stupid, overconfident, and just not really thinking that the police would be that savvy into knowing what was going on.
Because, normally, they're looking for people that are breaking in. There's always evidence of people breaking in. What we was doing, people were opening the door as we walk out and patting us on the back. And saying thanks for the customs. Yeah, like that. That's the perfect crime as you're leaving. We kind of got arrogant to that. Then got caught. That changes everything. At that point, I don't know what to do. My wife's pregnant at the time with my daughter, and I've just literally decided to go on the run, or on the lamb, as you guys call it.
And spent six years of my life as a fugitive here in the UK. And that really changes you, changes your DNA, changes how you think, changes, like, your full process about how you move when I'm out on the street and rolling around, you know, it just has to, you have to adapt to a load of other different stuff in the moment. Now, I've always been very—I’ve always been able to adapt to multiple situations. I guess that's part of the skill of being criminal. But also in my job that I do today, being able to adapt to the systems and processes that we constantly be is what's key to all that stuff.
And all of that is what creates who I'll become. My mum and dad’s, going back to what you originally said, like all of that kind of stuff plays into it. How does Tony become a fraudster and a criminal and get involved in it? Once I've realized that, all that stuff, I'd had kids, in 2010, on the first visit after they come to visit me after I've been on the run for all that time, and my son's crying his eyes out. That was the first realization that I'm pushing the trauma that I've got onto them.
There was no, when you're in the, when you're as highly plugged in as what I was, crime is just like work, a job. It's not—going to prison is not a deterrent. But it's not something that any true criminal is frightened of because once you're in there, I'm going to see people I ain't seen for years. I'm not going to end up doing life sentences. I'm not murdering no one. But I might get a little five. I might get a three. I might get something. But I can still find out what happened. “What was you up to?”
There's always that networking part. When you're involved in that criminal lifestyle, you convince yourself that that's what—it’s OK for that. But without realizing the impact of what then happens to the family, that’s what changed me is realizing that impact for the first time, when you see your own kid crying because of the stuff that you're doing. Any father would—you don't want to hurt your kids.
But without realizing the impact of what then happens to the family, that’s what changed me is realizing that impact for the first time, when you see your own kid crying because of the stuff that you're doing. Any father would—you… Share on XYou hate your kids crying or being distracted. You don't want to hurt your kids. You don't want to hurt your kids crying or being distressed or any of that. And so you put things in to prevent that from happening. At that moment of the world, they were ashamed of me. How do I, you know, how do I switch that round? WeFightFincrime was born.
We'll come back to that. I want to kind of ask about while you were living your, living the high life, so to speak, during the peak, what was your day like?
I'd get up in the morning. Normally, the day starts, I've already got all the IDs. I've got everything, debits, credits, voter IDs, loads of different bits and pieces for the teams that are going out to go and hit places, right? Then my day would be spent up meeting these people, delivering the IDs. They never knew. Lots of them never knew who I was, because I kept it all quite secret.
Now that I was just working for the man, there's always someone above you. Because when you're working with that many people, you can only have a close. I had like three captains that were always close. There was five of us in total. But three of them were what I consider captains. One would be my right-hand man. And of course, everything you get just like in a normal organized crime gang kicks back up.
Whether I'm running watch scams where we're getting fake Rolexes, putting the paperwork with them, and then selling them to other criminal networks, as real watches, yeah, or I'm over here controlling a mortgage fraud that needs mortgage offers fed into it. That's going to need a dodgy lawyer, a dodgy accountant, loads of professional laborers that just come to put that together. I was kind of the art of business, as they say, as being a good middleman.
That's exactly in crime works exactly the same to put the whole thing together. You can't be greedy. You’ve got to understand all of the workings, all of the value that you're going to add to that pot, and all of the value that the people that you're bringing to that pot adds. That's organized crime, right? There's no difference. It runs as a business.
It really was a business for you in a sense that you were middle-level management and you had guys that worked for you that did the dirty work and you just kind of supervised.
Yeah, like every now and again, someone might turn up at the door with blood running down their face because something's happened, or I might get a phone call in the middle of the night to say someone's been shot, or it just has different things going on around it when you're plugged into it in that way. Or someone who robbed us three years ago has just been seen in a pub in Manchester.
“The group up there have got him. Do we want to go and get him?” Like, there's so many different aspects. That's how it all just kind of intertwines. Normally, my role in the organized crime group part was always if you stole drugs, for instance, let's say someone runs off with a kilo of cocaine. Instead of the group killing you, you meet me. Yeah. And I'd say, “Right. Hello. Well, tell me about yourself. Tell me what do you own as your credit file? Right. OK. How much money you got in the bank? If you ever used your bank for certain different bits and pieces?”
“No.” “OK. All right, mate. Listen, come on. You look, you've got any of them APP stuff that you do. I got a meal.” But I'll get it all plugged in and it's knowing who you know and what scams can go where to do whatever, and then I might say, “You, look, you go over there and do a mortgage offer. That's 200 grand. You can get a loan there, a loan there, a loan now. Who else do you know? You've got anyone else? What about your missus?”
Because once they're in debt to the crime group, the crime group is just going to really look to get the money back because that was my kind of MO. That's what I got known to do. If you was meeting me, he's probably in quite big trouble. I've done that on multiple occasions for multiple people that got themselves in those situations.
Where did most of the people that worked for you come from? How did they get introduced into the organization? Is it just, hey, someone that you trust says, “Hey, this is my friend. I trust him. Therefore, you should trust him”?
Yeah, you can't get in. It's a bit like this. I'm sure you're aware of infiltrators, which, Rob Lazar is what an amazing thing to be able to get to infiltrate that high up and it is rare because it's so rare. That's why they make Hollywood films about it because it is the Donnie Brasco goes to these world are extremely rare. They just are, right. I was dealing with this fella once and we just, we went out for a pizza, right? I just didn't feel him. He just feels wrong. I said, “Come with us to the toilets.”
I'm stripping him in the toilets because I want to make sure you ain't got nothing on, wires. Like this is going to go a different way of that. When you're in that level, you have to be doing all that stuff. You can't get to the top tier because they're so far away. And even the crime groups only interact. It's a small amount of people that can actually get, because they're very aware of insulating themselves away from all this stuff.
When you've got that sort of money, you can find out from lawyers and things how you insulate all that, how you keep everything away from you. I think, has always been how criminals work. I think it's because most law enforcement, maybe law enforcement doesn't underestimate criminals as much, yeah. But, you know, they are, there are some really sophisticated, smart criminals that annihilate systems that are put in play. They just get their way around them. It's the cat-and-mouse game that we continue to play and has been continued to be played for many, many years, right?
When you were on the run, I know UK, at least currently, massive, you can't walk down the street without 16 cameras pointing at you. How did you get around and move and do things? Or was that fairly pre-surveillance?
It was pre-surveillance, yeah. But I mean, one of the things that always—I brought this with me as well, because I want you to see this, because it's quite funny, because when CCTV cameras always come up, I didn't leave it on my table. I did, I got it. Nowadays, we're OK for people to walk around with these things on. And we think it's totally OK. How would you get around that?
There's so many different—we allow this. For some reason, we allow this. I don't know why we allow it. I think it's daft. I think people look daft in them. When the sun's out and people are walking around in them, I think it looks really stupid. It just does. But it's a fashion item and I get it. But that's a vulnerability that we're creating that all them millions of pounds in facial recognition bypass because it's got—someone’s put a ski mask on.
It's amazing what high-tech things can be overrun by a dollar of cloth.
People are always people. People only know what you tell them in every single situation. -Tony Sales Share on XThe amount of times I've seen it is just like, people are always, people are always people. People only know what you tell them in every single situation. And so when you're criminally minded your whole life, for me personally, my whole life, I was trained not to get scared in a situation that other people might get scared in. If you get stopped, it's better to talk your way out of it than touch them, hit them, because now that's aggravated burglary, assault, commercial burglary, whatever it may be. Even though we could go that way, we don't want to go that way.
It's far better to just let them let you walk out the door, no matter what the scenario. That I think is what sets the criminals apart, of how far they are willing to push the rules, that's why. When we think of all this pen testing stuff that we do, I see that you've had some great people on your…. I've known FC and Jess for quite a while. Those guys are the top of the tree. They really are, and they've been the top of the tree for quite a while. Saying the same stuff as they've been saying for a long time.
It's really important that people start to understand that. I love seeing them get their recognition. It's amazing that FC is in the States now. All that kind of, I love it. I love seeing that and all that stuff because it's really important for the industry to understand that. Because when people can think differently, they think differently. Like I said to you earlier, because I'm not a hack, I'm not a genius computer person. I'm just not. But I'm going to come with something that you just didn't think about in a different way. And change perception of how people think about things.
And that's the security industry in general, is in that zone at the moment, of where we've relied on tech for so long. Part of my daily chores today, as a criminal, I'd be doing, finding out what the latest stuff's going on, and how it's going, and where it's going, and who's doing what, who's got this and who's got that. There's no difference to what we're doing in our jobs today, because we're all looking at what's going on. We're all looking at who’s, what's coming next, and what are the next threats that we see, and how can we defend against these next threats, right?
Some of the advantage of your skill set is that you think differently than most. I'll make some gross generalizations here. Most people go with the flow. Kind of, “I'm going to follow the rules, and I'm going to assume every, because I'm a functioning member of society, I'm going to assume everybody else is going to follow the rules. If we all follow the rules, then everything is going to be OK.” What was it about your mindset that allowed you to, well, “I'm not going to follow the rules, because then I just….” Ultimately, I think that leads you to seeing things differently than everybody else does.
I suppose the structure of society, you know, rules, I was not in school. I suppose it wasn't listening, I couldn't listen, they used to test me to see if I was deaf because they thought, “Why is he not listening?” I actually did my primary school—we had a deaf department, you know—and I would play down there with all the kids down there. But there was a load of stuff going on at home, right, that I don't want to talk about. But back then, people are not really talking about that stuff.
I've got, obviously, I have ADHD and I've got it back then, it's not just something that comes, it's what I've got. I've got this shed, loads of energy that most kids don't have. When you've got that, and you want to fit in, and you want to, I'm breaking rules, when I go nicking around the shop, when I get dropped into the pub. Rules are not a structure for me, they're things that other people put in place that I always think I can bend. My whole life, I've been brought up to understand that rules bend and rules are created by other people.
Rules are not a structure for me, they're things that other people put in place that I always think I can bend. My whole life, I've been brought up to understand that rules bend and rules are created by other people. -Tony Sales Share on XWe as society, we agree on what we believe we agree on what a rule set is. We believe in what we agree that this rule set is, and that’s—we all agree in a democracy to abide by those rules. Well, criminals don't abide by any rules. In multiple different ways in society, if someone murders someone, they become criminalized. They're not abiding by what the rules are. They’ve murdered someone, and they will be convicted of it.
Same way with stealing, rape, pillage, whatever the labels are that are given to it, they're wrongs that just get, as humans, when you see past that, that other people made those rules that we're now following our life by, you start to bend them. I think rules get outdated sometimes as well. We have to learn to adapt to those rule structures if we really want to make society better. Now we're all talking about ADHD. The whole world's talking about ADHD. When I wrote the book in 2020, there was hardly any.
But now there's lots of people talking about—we’ve all got ADHD and how it's all….If in the right way, I would have been given and governed in a correct way, I probably wouldn't have ended up in crime and realized that the stuff that happened to me, I was probably victimized and criminalized at a young age, that then makes that person then come out because no one's born bad. We can be born different.
But when no one has ever been born bad. The surroundings, the nurture, people say, “Oh, there's been an argument for nature and nurture for many years.” There's always nurture. Nurture has always been there because no one's just been left to grow up on their own. Otherwise, they die. If they don't receive love or any of that stuff, that's what happens. The rule structures are made up. When you've been in a position where all you need is love, or you're looking just for a parent's approval, rules go out the window. Most criminals have that.
Did you actively work on your social engineering as a criminal, or was it just kind of second nature to you? And it wasn't like a skill set that you actually were trying to figure out how to do better?
No, you just kind of—it don't even start like that. It just starts with just trying to make—“Are we going to make some money?” Just, like, on a test nowadays. Going back to what we were saying about tick boxing and what's the difference, what is that rule structure? In today's penetration testing industry, it's set by rule structures, tick boxing. It's very tick box that it has to be followed in this way.
Well, criminals don't follow that same tick box today, because they've either infiltrated over there, or they've managed to compromise someone over here, or they've got an internal member of staff helping them over here. They've already broken out of the rule structure. We're trying to defend it with a whole load of tick boxes. It's just an impossible standpoint that we can't fix. But because our industry is run by decent, hardworking and honest people, it is. That's why we're like that. When it comes to thinking out of the box and thinking differently, if you think of.
Nowadays, people say, “Oh, when we're testing, we try to think differently.” I always ask them, “OK, so what are you doing that makes you think differently?” They've always got a James Bond story, ain't they? I don't know if you've heard that, Chris. “I've got a ladder from a roof to a roof, and I come across like that.” That's all really great and all that kind of stuff. But the reality is I'm just going to get a dog lead. I'm just going to walk through the bloody front gate and send my dogs, just run off me into your land.
“Can you help me find a dog? I'm really willing, so my missus is going to go nuts.” That's how criminals work, like, and that, you know, understanding in the moment, how you can adapt. That's what we're up against with the latest social engineers, whether they'd be trying to steal people's money through banking, like, my mum is in her 60s, late 60s, yeah. She gets quite a lot of calls on her phone. I get a lot. I mean, I play with these people. Because I just want to just see what are they talking about? How are they talking?
What…how quick are they? Where were they actually looking to go through this? Once they've realized they've got an answer for everything. There's always a get around somewhere that they're getting around, no matter what the security process is. That's because they're adapting in that moment. I don't know how we stop that.
There's always a get around somewhere that they're getting around, no matter what the security process is. That's because they're adapting in that moment. I don't know how we stop that. -Tony Sales Share on XI'm kind of curious, because a lot of the, maybe it hasn't really changed, but a lot of these, like, call center crime organizations, they're run with playbooks and standard operating procedures. Does that mean that the guys that are on the front lines are actually good at social engineering, or do they just have a good playbook? Or are they actually just following the tick boxes really well that someone else has written for them?
Well, I think we just have to look at what the, how it works. Let's say that if we started a call center, right? In the call center, we're going to sell bottles of wine. That's what we're going to do. It's expensive wine. The more bottles of wine you sell, Chris, the more money you're going to make. Or the more freedom I'm going to give you of your life. I'm going to free your family in whatever country it may be.
I'm going to—I’m just playing out however the criminal might be. There's a load of different plays for that. But if I give you a script and you just read it, what are you doing? How are you going to sell to someone? Don't work like that, does it? Think about it. Here's the confusion about when we hear call center, call center, call center. We're naturally assuming without actually realizing, “Well, if you just had a script, I'm going to be very wooden in my first time,” but to be a real salesman, there's another, there's always someone in a real call center who's like, who you look at and go, “Wow.”
Like the Wolf of Wall Street shit, right? I've got this pen, you know, and this pen is amazing. It's got the fountain stuff on it. You see the ink? This ink never runs out on this pen. And if you want like that, that's salesmanship. That's what social engineering is. It's being able to sell something, taking small pieces of information. Just utilizing it back on the victim. That's what good social engineers do. I think, yes, there'd probably be lots of people that still become victims because of a script.
That's what social engineering is. It's being able to sell something, taking small pieces of information. Just utilizing it back on the victim. That's what good social engineers do. -Tony Sales Share on XHowever, I think a lot of those people that are delivering those scripts have a lot more to do with it than we probably realize or giving the criminals credit for you. Because it's just simple, isn't it? When you're reading a script, we can all just now relate that and go, “Well, it wouldn't just happen like that.” Until someone points it out, you don't see it.
Are they targeting specific individuals, or is this just all en masse of we just don't care? We're going to go after everybody and everything that moves.
Yeah, I think a lot of, like, they come from tech to pushes from different types of ways of phishing, right? These are always efficient, aren't they? Traditionally, we've got caught up with phishing looking like an email, but, you know, I might phish you on the phone, giving you a call. Just because I'm just phishing for information and that's where this terminology comes from. Phishing is very important. It comes in multiple different ways.
Understanding how criminals might phish us allows us to understand how to defend against that stuff in a much better way. -Tony Sales Share on XUnderstanding how criminals might phish us allows us to understand how to defend against that stuff in a much better way. Look at all the databases, I talk about this regularly, where everyone talks about the hacks and, “Oh, there's this hack that's happened and there's that hack that's happened.” Honestly, I don't know if we're ever going to stop that. I work with a guy called Solomon Gilbert, who I've worked with since he was very young. He's bloody terrifying.
It really is terrifying some of the stuff that you can do. I can't see that getting any less. I can only see it getting more. People say quantum computers. Well, I'm sure there'll be quantum hackers somewhere. But let's definitely realize that that may be a thing. Because if we don't, that's problematic. Like I said, the stuff that some of these guys come up with when they're doing their stuff is amazing.
It's understanding what all that looks like and piecing it all together. And criminals would always explore it en masse. Data is never going to go out of date, is it? Right. Your address might change. Your card number might change. But in the amount of information that's been lost over the years, if you think of Equifax—143 million people's financial information—they may have different accounts. But just think of the wealth of information that's on there.
When they did GDPR here in the UK, I said, “Well, who said that three pieces of information is important? Because I only need your phone number.” -Tony Sales Share on XI don't think there's still enough criminals on the planet to harvest just that information and use it. It's like that's the reality of it. This stuff's coming day by day. There's databases for sale for, like, 50P. They've got loads of people's information on there. All I need is, I only need a phone number. When they did GDPR here in the UK, I said, “Well, who said that three pieces of information is important? Because I only need your phone number.”
What's your name? Now I've got two. Now from them two pieces, I can build an attack. I've heard of different types of attacks of going down the phone and listening to different types of things. All that stuff is possible in today's day and age. So like I said, we have to adapt to the threats as we're going through, change our structuring of our rule set to evolve with the threats that we continue to see.
There's clearly kind of, like, two fronts of moving forward. There's organization of businesses need to change the way that they do stuff. Then there's individuals need to change the way they do things. Those are probably different. What should individuals be doing then? Like, is there such a thing as low-hanging fruit, or are we all at risk kind of regardless?
I think we're all at risk. I think, and even I'm sure you and I, Chris, have always heard, but that never happened to me. Like we did, that's the, we see in boardrooms. That sometimes senior management don't actually want to tell the board what's actually going on or the positions that they may face if things go on because the board are pretty protected. No one wants to speak them out or frighten them into something that might not be true or might not happen.
But when did we decide not to arm them with the correct information needed to defend against this stuff when it truly happens? When it's OK doing a workshop, training a board on a workshop, and how that might play out in a cyber attack. But we all know once they're in, the cyber criminals don't care. They just go, “OK, we own you when you're paying us.” That's the reality of it. Then you see companies getting backed up into a thing of, “When are we going to pay the ransom? Are we going to? What's the fines? Is it legal to pay the ransom?”
Now there's a whole load of other problems. For me, we need to get culture correct in the right way first. But understanding we have to fix, and I call this the human operating system, OK? The human OS, and we have to patch humans. That's what we've got to do. In technical terms, we've got all this great stuff over here for tech, right? But over here for humans, we've got a click-through course. It's training them.
For me, we need to get culture correct in the right way first. But understanding we have to fix, and I call this the human operating system, OK? The human OS, and we have to patch humans. -Tony Sales Share on XLet's go. Ask them. Go and ask them. They'll all say a training is boring. How many times have you heard it? If training is boring, how do we engage it so it's not boring? How do we give people the correct information that empowers them both in their corporate life, Chris, and in their consumer life? Because every single day, we're a corporate and consumer. When we go to buy lunch, we turn into a consumer. When we're getting dinner ordering from Uber, Just Eat, whatever your favorite one, whatever it may be, we're all becoming consumers as part of that day.
Knowing what keeps us secure and safe, what looks dodgy, what doesn't look dodgy, asking questions of stuff in the correct way, and not being so bloody obsessed with friction. Try selling friction to a victim who's lost 100 grand. We have a frictionless system. Well, if you've just got 100 grand, that's not, we don't want you to have, why is there no friction? Why are you not asking me no questions? Do you see what I mean? And like, it's just about understanding it through the ball.
Knowing what keeps us secure and safe, what looks dodgy, what doesn't look dodgy, asking questions of stuff in the correct way, and not being so bloody obsessed with friction. Try selling friction to a victim who's lost 100 grand.… Share on XI can't believe that people give away passwords after all the millions, Chris, that's been spent globally in advertising and awareness campaigns to make people aware never give your password to anyone, yeah? In every single language, you can imagine. It still happens. Because as humans, we just fall down and we just have to be honest with ourselves about that. Culturally, be honest with ourselves about that. And then we can start to fix all of those little bits in term, you know, you don't want everyone to be paranoid, that'd be crazy.
Unfortunately, if we want to keep the web, and we want to keep the amazing, because I love it, it changed my life, it's changed your life, it's changed so many people's lives around the world. It continues to do that. Whether you like it, dislike it, it’s something that we didn't have. And now it's connected all of us in a way like never before. Now as humanity, we should be bloody proud of it. Not just worried about all the bad stuff that happens on it all the time. Let's just get better at using it.
How do you sell, like I said, I think it's easy to sell friction to someone who's lost a lot of money. How do you sell friction to people who haven't lost money? Because there's been so many decades of marketing about, “Hey, we have this frictionless process.” How do we now change? Everything that we've been trying to sell you for the last 20 years is actually wrong. You now actually want friction. I get it. I agree that.
There was a while back that I had wired money to someone I know overseas and I had done all the things that would raise the alarm at a bank. I had opened the bank where I bank, intentionally did not do international transactions. I opened a new bank, opened an account with a bank, moved money in, waited a couple of weeks for the money to season and then transferred like 90% of it out overseas. All the classic signs of something fishy is going on here.
Relatively, you got this, yes, you get there's a process you have to go through online to wire money. Then what actually surprised me is I get a call from the bank, very nice woman, who's like, “OK, why are you sending this money? Who is it that you're sending it to? How do you know it's really the person that you're sending it to?” I was both annoyed and ecstatic at the same time.
Annoyed because I don't want to go through the friction. But also it's super exciting because like, “Oh my gosh. Somebody is doing the right thing in what appears to be an absolute example of a scam.” But how do you sell that to general consumers? Because you've already been selling me for the last 20 years that you're a safe bank. Now you're telling me that I actually wasn't safe and I have to do this instead.
Oh, we're telling them that we don't have the processes in place that maybe they believe we had.
Either way, it doesn't, to me it almost doesn’t—I think it's easy for a new financial institution to come and say, “Hey, we realize there's a problem and everybody else has been doing it wrong. We're going to do it right. We're going to keep your money safe.” OK. But how do—name your top five banks in your country. How do they pivot without hurting their reputation?
I mean, it comes down to…like if we want frictionless, we have to accept the losses, right? And that gets into an acceptable loss phase. Now, I've always said no loss to me is acceptable because none of us would accept someone coming into our house and only stealing 2% of our goods. We're not going to accept that. But in business, we have to accept it because it's part and parcel of what happens. If we want to do transactions at a super rate, that's part of doing business nowadays.
If you want clients, we all want faster transactions. We all want to send our kids money in five minutes, or it's just all what we are, wives, our partners. We all want to do that now. And that's the need that we have to pay for something instantly right now in the moment. But it always comes back to everything else. Then the KYC systems need to be built in the correct way to truly understand KYC. The IDV systems need to be built in the correct way, not just claims of looking for whatever stuff.
That then comes out later because everyone jumps on a bandwagon. Money's to be had. VCs invest fortunes. Yeah. And all of a sudden, there's products on the market that are not actually capable of doing what they say they can do. That's the position that we're going to get in again with AI, because people are not understanding what that truly, no matter what any of experts, and I've heard so many experts, and now everyone's an AI expert.
However, the true people that really know about it, they're scared because of how people think about it. How reliant people are becoming on it, or not being able to spot all this stuff. It's such a big brainfuck for the consumers. It's like a great big, “Whoa! We're all terrified!” It's Daily Mail rubbish, just headline sensationalism for fear-based stuff. The reality is you just need to use your brain a bit and look at what's in front of you. See that, actually, I see people impersonating superstars and all that.
Yes, I think that try and do it live. Just stop talking rubbish. Do it live. Because if you're going to do what, because the selling of something. It's different if you don't know someone and you're talking to me as you don't know me. You're not going to know my voice or what I look like, yeah? I can put a deep fake on and talk in this voice. You're not going to put two and two together. Or I can change my voice like that and then start talking.
But they're all things I have to do. Hell, all of that stuff that people don't even realize until you start calling it out about things. But that's the true reality of it. Instead of people embracing it and understanding how the friction could help them to better understand what's going on, we get fear-based fastness thrust upon us that's not really helping the consumers no matter what. Consumers, no matter what way we look at it.
We just need to be better at figuring that stuff out. That's all it is. Better KYC, better IDV. It really works, like I said. I don't think there's anything that exists in the true moment. Understanding how live, not liveness checks, but live checking, you know, confirming who you and I are together in that moment, making a transaction of each other, yeah? It doesn't always have to be tech.
Let's talk about, like, with financial systems. What are the questions that we should be asking of financial institutions if we're looking, like. I really want my accounts to be safer. I want my banking to be safer. How do I choose which bank? What questions should I be asking? And how do I read through the marketing hype versus the reality?
I suppose that's a really good question. It's definitely something for the future that, as a consumer, what I'd like to see, is me setting my own friction. If I want to send faster payments, like, how much of that do I understand is upon me? I'd like a bank to place that out. Some banks do. Some start-up charger banks, they're kind of being really upfront about the types of things that they do.
A lot of the old-school ones are putting that stuff in as further down bump, as we call it. Stuff to just talk about. But it's about making them understand what the threats are, who's doing that.
All banks are trying to help their consumers understand so they can mitigate against those threats. Like I said, even with millions spent on campaigns, it still happens. Because once fear plays into it, and then the trust of the big bank plays into it, you're being hacked, or your money's being stolen right now.
“It's OK. I work for the bank. I'm here for you. What I can't do is give you your passwords. I don't know any of that. But I've got another account open for you here so you can transfer all the money. I've just sent you a one-time passcode. If you just give me back that code, I'll be able to put it in.” All these things that are there, there's already friction that happens, because the consumer is believing in that moment that they're with the bank. How do we make that friction work for us as the consumer?
And that's what needs to be figured out. I think the banks do a lot. They can always do more, as I'm sure there'll be lots of people that say they can always do more. But let's just be real about it, right? They're a business. It's the only business in the world that we're going to blame if our money goes missing. They're actually—they don't make shed loads of profits. It may seem that way, but they're operating on our money. That's how it works. There's not actually a lot of profits.
They spend shed loads in trying to defend against and they have a whole range of attacks, from I could think of a big tier one here that's probably got 50 people in this cyber unit. That's just one unit. Then what about over there? They've got like a whole load of other units to deal with a whole load of other different types of crimes that are constantly hitting them from cash points being exploded to glass being broken on a part of the building. There's so many different threats that they face.
They focus quite a lot of their attention on fraud and financial crime, really, and cyber attacks because they see it happen into so many consumers over and over again. But ultimately, we can't put that on the banks. We are our own custodians of our own information. The sooner we start to understand that as consumers, the better. Because that's when you can really see—think about me times, we was talking about travel earlier, right? How many times you've gone to a hotel, Chris? And they said, “Can I get a photo of your passport?” Where's it going?
We are our own custodians of our own information. The sooner we start to understand that as consumers, the better. -Tony Sales Share on X“Then you want my phone number, my email address, where I work. Like, wow, all this other stuff you've already paid on my card. You've got my card information.” And I've now brought into it like, “Whoa, that's a whole load of information.” But the problem isn't that, it's when you say to them, “I don't want to give you a copy of my passport.” Why is that? And they're not understanding of that.
What you have to do is law, because in some countries, it will be law for a hotel to take that information. We're back to the crossover stuff of what's what. We just have to get to a good place of, I don't know how we do it, Chris, policing the internet. Sometimes, some days, I think it's a great idea. Other days, I think it's a bad idea. But I think the further we get into it, I think it's definitely something that's going to have to happen at some point. Because we just can't stand all this forever, can we?
I mean, it's an interesting balance, because you want those using the hotels, they need to protect themselves, they need to do what they need to do to operate a business. But then as a consumer, we're like, “Well, but if you get compromised, you've now put me at risk.”
Yeah, what's the hashed version of that? What's that? What's the actual hashed version of that that we could all sign up for? That's a hashed version? Is there each government agency around the world? Let's start thinking of our own people and start thinking how we can interact with others without sharing?
That seems smart to me to be able to do stuff like that, right? That's how we get to better understanding of how we’ve—maybe friction is there that we don't see, but just works better for the customer. But then you'll get people that say, “Well, we don't want the government knowing all that information.” It's like, we've got this always and always.
There is no one perfect solution, because one perfect solution does, because there's different problems. The consumer has a problem, the business has a problem, and the government has a problem, and they overlap in which ways that are mutually exclusive. We can't solve this problem without hurting that side.
I've been having a debate today. Actually, we've gone LinkedIn about banning under 16 from social media here in the UK. It's one of those ones that I get why people would want to ban it. But I also look at that and think, “Oh, maybe in a few years when some of them people have got no experience of social media, what's going to criminals will be queuing up for that data.” They're already looking for data that's fresh, unused, manipulative.
That's a whole stream of people that could come into a flow of criminal attacks that they're not even nowhere near prepared for. We don't have the resources, the knowledge base, to be able to deliver education in our education systems to train the younger generations to stay safe. Why would we want to block something that's so beautiful, that can be. It's adults that use it in bad ways. That's the reality of it.
There are adults that use it in bad ways against the kids, but let's ban the kids. It's just wow. There's a lot of thought. But I mean, there are a lot of people that are thinking in the right way and understanding in the right way. I think we've got better at defending these, slowly but surely we're getting better. Both countries, mine and yours, are getting better at defending attacks that come in relentlessly from foreign states continuously.
Back in the beginning, you think there was no phishing training. No one even knew what that was. Nowadays, at least, that's kind of there. In a way, Wi-Fi is getting much more secure. There will always be some smart ass that breaks it and beats it somewhere. That's great. We want that. We want that sort of thing. Just having an open attitude to that stuff, I think in the future, from some of the things that I'm sure we'll see, some of these hackers that have hacked companies, been to prison, come out, what they've got to teach us, learning from them, I think will be really important.
When I started all those years ago, having to bang drums, saying that data was the new cash, that ransomware would be on its way, all of that kind of stuff, listening to these people, instead of now, 15 years later, we're having the same conversation because if nothing changes, nothing changes.
I appreciate that you have taken your experience and said, “I don't want people to be a victim of what I was doing. I want to do something different. I want to use my experiences to try to prevent that from happening.” I'm very glad that you had that epiphany with your family that has allowed you to say, “OK, I need to do this differently.” And hopefully that it's been very rewarding for you.
Yes. I mean, I love it. I enjoy it. I'm not doing it for anyone else but myself and doing it to just give the information that I clearly know is needed in lots of different ways. Help those victims that continue to come in my inbox, that I, for some reason, victims don't mind talking to me, maybe because they feel embarrassed about a lot of this stuff, and maybe with someone like me, we can flesh it out and make them understand that, look, you're not actually, you're playing against a pro.
We always give it a soccer reference. I always say, “If you're just playing football against Pelly, any nutmeg jar, or Messi, you wouldn't be upset with that.” You'd actually be like, “Wow, did you see what he'd done and that?” We underestimate criminals in that way. They are the Messi’s because they're coming up with these latest scripts, these latest ways of delivering stuff, latest attacks, latest vulnerabilities, you know, and that's a good thing.
We need to go beyond bug bounties, you know? We need to get more jobs for people. Yeah, that's what we need. There was a McKinsey report that our chairman, Dr. Ken Rowe, often talks about the warfare talent of where once corporations were starting to really fly, the talent just wasn't there to be able to take all these FTSE 250 companies and really elevate them into the super, super duper companies that we see today.
We're in very similar times with our space, right? Where's the talent? Where's it coming from? We can't put it on poor old FC and Jess to save every single thing out there. I'm sure they wouldn't want that either. Or the other amount of amazing hackers that do all of their stuff that they continually do. I'm sure they'll say we definitely need more people because that's the reality of it, by convincing the boards to spend more money on those people.
Give those people that are in those bloody places the right resources that they need to be able to deal with the problems. And that is often something that doesn't get seen. That's part of it all as well. Thanks, Chris, for giving me the opportunity.
Give those people that are in those bloody places the right resources that they need to be able to deal with the problems. And that is often something that doesn't get seen. -Tony Sales Share on XYou're welcome. If people want to connect with you or We Fight Fincrime, where can they find you guys online?
We are at wefightfincrime.com. Very simple. Or you can get me on LinkedIn. Just search up Tony Sales. You'll see that the social engineering expert little logo come up. You can just come and follow me there or connect with me there if you want to ask any questions. More than happy to answer in any way that I can.
Awesome. Tony, thank you so much for coming on the podcast today.
No worries, Chris. Thanks for having me, mate. I really appreciate it. Thank you.







