The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Risk and Reason
Risk and Reason artwork

Imprint's Director of Risk, Jason: Basement Hackers To Global Rings

Risk and Reason · 2025-12-16 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

68 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality12 / 20
Guest Caliber17 / 20
Specificity & Evidence13 / 20
Conversational Craft12 / 20

Jason Brown brings nearly three decades of federal law enforcement experience to Imprint's risk operations, having worked across the Secret Service's Electronic Crimes Task Force, cyberintelligence units, and most recently as agent in charge of the Knoxville field office. The conversation traces the professionalization of cybercrime from early 2000s carding forums - like the marketplace run by Albert Gonzalez that Operation Firewall dismantled - to today's specialized criminal marketplaces offering discrete services: malware writers, money mules, fake document producers, and ghost-tapping operators. Brown emphasizes that while AI accelerates fraud detection and improves efficiency, it cannot replace human judgment in understanding criminal motivation, which he argues is the fundamental driver of all fraud. He illustrates this through concrete examples: mule networks shipping encoded phones for point-of-sale fraud, remittance patterns revealing suspicious account usage (Minnesota surprisingly ranking second for bank transfers to Mexico), and the distinction between cyber-enabled financial fraud targeting payment networks versus nation-state intrusions. For fintech and lending operators building risk stacks, Brown's framework centers on deriving intent - determining whether actors seek platform access to steal data, exploit stolen credentials, or launder money - rather than simply detecting anomalies.

Key takeaways

  • →Criminal marketplaces operate with specialization where bad actors purchase specific skills (malware writers, mule runners, document forgers) rather than operating horizontally, making traditional horizontal fraud detection insufficient.
  • →AI should augment rather than replace human analysts because fraud is fundamentally motivated by human greed and laziness, requiring experienced judgment to evaluate both evidence accuracy and criminal intent.
  • →Understanding mule networks and money movement patterns - including anomalies like Minnesota's unexpectedly high remittance volumes - reveals organized crime's financial infrastructure beyond individual transaction fraud.
  • →The Secret Service's 25-year focus on cyber-enabled financial fraud (any fraud involving cryptocurrency, stolen payment credentials, or digital exploitation) differs from intelligence-focused law enforcement and provides unique insights applicable to private sector risk operations.
  • →Synthetic fraud powered by AI-generated identities requires human analysis of motivation because the fraud occurs not at application but when someone exploits the artificial identity for financial gain.

In this episode

  1. 1Jason Brown's Path from Political Science to U.S. Secret Service
  2. 2Early Career in New York Electronic Crimes Task Force and Digital Forensics
  3. 3From Cybersecurity Policy to Protection Detail and Leadership Roles
  4. 4Professionalization of Cybercrime: From Basement Hackers to Organized Criminal Marketplaces
  5. 5Operation Firewall and Carting Forum Take-downs
  6. 6AI as Force Multiplier: Balancing Automation with Human Judgment in Risk Operations
  7. 7Synthetic Fraud, Intent, and the Human Element in Fraud Detection
  8. 8Criminal Specialization in Fraud: Mule Accounts, Ghost Tapping, and Payment Network Exploitation

Mentioned

ImprintU.S. Secret ServiceJason BrownBobby WeaverAlbert GonzalezSteve WardPaul PattonUniversity of KentuckyNew York Electronic Crimes Task ForceDepartment of Homeland SecurityGoogle WalletApple Wallet

Guests

Jason Brown

Topics in this episode

U.S. Secret ServiceOperation FirewallImprintElectronic Crimes Task Force (ECTF)Albert GonzalezCarding forumsCyber-enabled financial fraudSynthetic fraudAI in fraud detectionMule networks

Questions this episode answers

What is a carding forum and how did Operation Firewall dismantle it?

Carding forums like the one Albert Gonzalez ran are password-protected marketplaces where stolen credit card data (track data, full identity information, PINs) is trafficked by reputation-based criminals. Operation Firewall had the Secret Service take over the forum itself for months to identify and apprehend perpetrators globally.

How has fraud specialization changed since the early 2000s?

Criminal marketplaces now offer discrete services - malware writers, data collectors, account openers, mule runners, and fake document producers - allowing fraudsters to purchase exactly the skill they need rather than operating solo, making fraud more efficient and harder to detect.

Why can't AI fully replace humans in fraud detection?

Fraud is fundamentally human-motivated by greed, laziness, and determination; understanding why a criminal is acting (stealing data, exploiting stolen credentials, money laundering) requires experienced human judgment that AI cannot replicate, and hallucinations in LLMs create regulatory risk in compliance-sensitive environments.

What is ghost tapping and how does it differ from traditional mule cash-out schemes?

Ghost tapping encodes multiple stolen credit card numbers into virtual wallets (Google Wallet, Apple Pay) on phones that are mailed to criminal operatives, who conduct point-of-sale fraud directly via phone, replacing older methods of mailing white plastic cards to ATM networks.

Why is Minnesota's rank as number two in remittances to Mexico suspicious?

Texas logically leads due to the border; Minnesota's unexpected second-place ranking suggests mule accounts and money laundering networks may be using Minnesota banking infrastructure to send proceeds, indicating organized crime moving money through less-obvious channels.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers solid practitioner insights on fraud evolution, criminal marketplaces, and AI integration in risk operations. Jason provides concrete examples (Operation Firewall, carting forums, mule accounts, ghost tapping) and articulates non-obvious frameworks (fraud as fundamentally human-motivated, specialization in criminal marketplaces). However, substantial portions are biographical filler and repetitive exploration of familiar concepts (AI as force multiplier, human-in-the-loop) that a seasoned operator would already know.

fraud is so human-based. No matter what the fraud looks like, there's always going to be a human element to it. It's the motivation behind the criminal act.
specialization, uh, especially if you look back at the marketplaces we discussed earlier. If you go in there, you could shop around for exact skill set you need.

Originality

12 / 20

The episode recycles standard frameworks (AI as force multiplier, human oversight necessity, blockchain traceability) that dominate fintech risk discourse. The novel elements - fraud as fundamentally human motivation, criminal specialization via marketplaces, application timing in synthetic fraud - are valuable but not contrarian. Most of the discussion follows predictable risk industry talking points without first-principles challenge or counterintuitive positioning.

I don't think AI is a substitute for personnel whatsoever. Uh I don't believe it's going to eliminate the people working in risk and fraud. I think it is a force multiplier.
Blockchain is highly traceable. It's you can you can utilize some really good tools to figure out who's doing what.

Guest Caliber

17 / 20

Jason brings exceptional operational credentials: 25 years at U.S. Secret Service including founding member of cyberintelligence section, oversight of Operation Firewall, work on national cybersecurity policy, and current role leading risk operations at a fintech. He has directly worked the problems he discusses (not theorized about them) and now operates in the practitioner space. This is senior practitioner caliber with proven execution experience.

was one of the original agents in the cyberintelligence section down there. Uh, that was a unit that we formed back in the early 2000s, really, to address the large-scale trafficking of access device fraud data
was on President Obama's detail for four years while I was there, specialized in counter-surveillance

Specificity & Evidence

13 / 20

Jason provides named examples (Operation Firewall, Albert Gonzalez, Bobby Weaver, Texas remittances to Mexico, Minnesota anomaly) and concrete fraud techniques (white plastic encoding, ghost tapping with Google Wallet/Apple, ATM cash-outs). However, specificity lacks depth - examples are mentioned but rarely unpacked with metrics, timelines, or quantified impact. No specific dollar figures, loss data, or measurable outcomes are provided for any case discussed.

Operation Firewall. The agent was Steve Ward, and it was uh after the apprehension of an individual named Albert Gonzalez, who was running one of the largest English-based uh carting forums
ghost tapping where they will preload several credit card numbers into virtual wallets via Google Wallet or or Apple or things of that nature and encode those on phones and actually ship the phones out

Conversational Craft

12 / 20

The host asks competent questions and attempts follow-ups on key topics (AI in risk, mule accounts, blockchain), but rarely pushes back or challenges Jason's claims. Questions are often layered and long-winded, diluting focus. The host accepts Jason's framings without probing deeper - e.g., no push on blockchain traceability education gap, no specifics requested on stable coin regulation timeline, no challenge to the blanket statement that government won't identify exploitations. The conversation feels collaborative but lacks the friction that produces insight.

I think it it poised us in a unique position with being in the Secret Service to begin with
That's a that's a tough question because I would often say that a lot of those exploitations that are out there to exploit the payment rails that we don't know they're out there, I don't think it's going to be the government that identifies them

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

fraud32service17secret16back15credit13human12card11network10government10sure9criminal9seeing9corporate9seen8risk8access8

Episode notes

In this episode of Risk and Reason, Eli Wachs sits down with Jason Brown, Director of Risk Operations at Imprint and former U.S. Secret Service agent, to explore the evolution of cybercrime and financial fraud. Drawing on nearly 25 years in federal law enforcement, Jason discusses the professionalization of fraud networks, why fraud is fundamentally human, and how AI can act as a force multiplier without replacing human judgment. The conversation also covers synthetic fraud, payment rails, stablecoins, and what the future of risk management looks like in an increasingly digital economy.

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

We're no longer dealing with a hacker in their mom's basement. We're dealing with multi-state organizations. Having AI make decisions quicker, but making sure there's still people in the loop. How have you seen that progression and evolution?

The professionalization of hacking, network intrusion, the marketplaces that we see out there, fraud is so human-based. No matter what the fraud looks like, there's always going to be a human element to it. It's the motivation behind the criminal act. I don't think AI is a substitute for personnel whatsoever.

I don't believe it's going to eliminate the people working in risk and fraud. The human has to be involved in there, and experience really drives that in evaluating what the accuracy of those fraud investigations would look like. Hello, everybody. Welcome back to the Risk and Reason podcast.

I'm joined by a very special guest today, Jason Brown. He's the director of risk operations at Imprint. He has a pretty fascinating background working, I want to say close to 25 years in the U.S.

Secret Service, working across cybersecurity, cybercrime, digital forensics, and has taken that experience now into the world of consumer credit, a really interesting B2B use case, and how transactions in the age of synthetic fraud and AI fraud have evolved. So, Jason, thank you so much for joining us. Thanks, Eagle. Thank you for your having me here today.

I I guess to start off, I gave uh introduction, which probably does a disservice to all that you've done. Could you walk us through, you know, what drew you to, I guess, this broader realm of, I'd say protecting people uh for from a young age and and uh just please give us that story. You know, I went to college at the University of Kentucky in Lexington, Kentucky. I studied political science there.

Uh I thought I was going to run political campaigns for a living. And in my senior year, I did an internship in the then Lieutenant Governor's office, Paul Patton, who was eventually uh elected governor and worked for the first four years of his administration as one of the staff members. That short period of time, although it was a great learning experience and I had a great time in the office, uh figured out I didn't want to remain in politics. I decided I wanted to go into law enforcement.

And uh I applied for the Kentucky State Police and the U.S. Secret Service both at the same time. The Secret Service called first, and that's where I ended up.

Uh, started off my career up in the New York field office, was assigned after only two weeks up there into the New York Electronic Crimes Task Force, where I spent for the entire seven years that I was up there in New York, uh, under the tutelage of Bobby Weaver, the one we called the the uh the grandfather of the ECTF network. Uh what was cool about the ECTFs, Bobby really tried to teach us to act and think about the way corporations look at at crimes and violations and security instances.

So, you know, yeah, we were out there, we were wanting to apprehend the individual, but you know, we were more worried about in shareholder value, learning about the corporations, making sure that we did what we could do to help them protect their networks moving forward. Through that, uh, I was able to go into the electronic crime special agent program, like you said, uh doing digital forensics for a couple of years. Uh, when my time in New York was up, I still had a commitment for XAP before I could go into my protection time.

So I transferred down to headquarters, was one of the original agents in the cyberintelligence section down there. Uh, that was a unit that we formed back in the early 2000s, really, to address the large-scale trafficking of access device fraud data over the internet, uh, credit card information for lack of a better term, and to address some of the major network intrusions that we were seeing out there. So, you know, this was pre-PCI DSS. So we were having a lot of uh track data being stored on corporate computers that were being uh exploited and stolen and then trafficked out on the internet.

Did that for several years. Um, after uh a couple of years, I was assigned over to the White House in the last year of the Bush administration with the Homeland Security Council, and did that for the last year of Bush and the first six months of Obama working on the comprehensive national cybersecurity initiative, doing defensive cyber policy. Uh after that, transferred back to headquarters, was one of the agents to help help stand up the critical protection, the C C SPI, excuse me, Critical Systems Protection Initiative.

And that's essentially the cyber advance that we do for all of our all of our protectees up until this day. Uh from there, uh transferred back over into protection. I was on President Obama's detail for four years while I was there, specialized in counter-surveillance. Uh, was promoted off Obama's detail to go back, and I was actually for six months over our exat program, the digital forensic program for the service.

And after a short period there, went back and became the supervisor of the cyberintelligence section. So, full circle as one of the first agents in the section, and then was able to go back and be a supervisor there for about a year. Uh, came down to a point where uh in my personal life, I had a couple of boys that were getting older. My wife and I both being from Kentucky, we wanted to get back to the South to raise them.

Uh, the Knoxville resident office came open. Was fortunate enough to be transferred down here as the agent in charge in Knoxville, where I spent the last eight years of my career. And down here I was responsible for the 23 counties, northeast Tennessee, with everything that we had going on down here from both criminal investigations, protective intelligence to protection, and uh wrapped up my career down here in July 24. Took about six months off to get my head straight, to uh recover a little bit, take it, take a little downtime uh recharge, and uh wanted to go into private industry.

Uh, was looking at fintech, was looking at at cyber threat intelligence uh companies out there, and uh found imprint, and or should I say they found me, and uh was fortunate enough to uh interview with them and they brought me on board, as you said, with the as the director of risk operations uh where I serve now. And in that capacity, I'm over everything that we do operationally in the risk sides. It's an amazing story. Uh I didn't know you studied political science.

I love that. Uh when you when you when you when you got in ECTF, I believe it came from the Patriot Act. And actually, the ECTF predated the Patriot Act. And then after 9-11, uh the Patriot Act codified the ECTF, and it was a subsection of the Patriot Act where we had to expand the ECTF network all over the Secret Service and all of our major field offices.

Interesting. When you when you talk about, I guess, codifying it, uh I'm guessing that you know we say people saying risk today, to to jump ahead before we jump back, that we're no longer dealing with a hacker in their mom's basement. We're dealing with multi-state organizations. When you're dealing with cyber terrorism, cybercrime at a government level, you're coming at it, I imagine, with with that mindset.

Could you talk, though, about how you you've seen in these different approaches the professionalization of these battlefronts? You know, we say, you know, it's not Bonnie and Clyde anymore going to a bank. Uh bad actors have moved online. And, you know, these are still multinational criminal organizations, and there are different ways that they're they're going at it now.

But to the degree of what you can share, how have you seen that progression and evolution? Absolutely. I mean, it's been the, as you said, the professionalization of hacking, network intrusion, the marketplaces that we see out there. Back in the early uh 2000s, there was a case out of our Newark office called Operation Firewall.

The agent was Steve Ward, and it was uh after the apprehension of an individual named Albert Gonzalez, who was running one of the largest English-based uh carting forums out there. Um I worked on that. So that's the carting forum is. Yeah, absolutely.

It's uh it's a website where you gain membership into it, and they regularly traffic stolen credit card information. Uh that credit card information could come from a gas pump skiver. It may come from a major network intrusion, it may come from a piece of malware, but we're talking about everything that you would need to either effect a credit card transaction or do a full identity takeover, whether you're just buying the track data from the credit card or you're buying what we call fulls, which include your name, your social security number, everything you can to take over a person's identity.

And those marketplaces are out there plentiful. We've seen a lot of that migrate to the dark web, to the unaddressable space where you would access via Tor these days. But back in the early 2000s, it was uh open, well, not necessarily open, but regular uh web portals of web pages that were password protected, and you gained a reputation as a reliable criminal because there is honor amongst thieves, and that's how you got into those portals. And I cut you off, and then for the professionalizations, you're you're talking about this operation that you did, and you caught someone who ran the largest card for him or one of the larger ones at the time.

Yeah, uh, I didn't personally run the investigation. I was in New York at a time, but I assisted with it whenever they eventually did a roundup, and we had some arrest over in New York, but it was an individual that was arrested for um for other violations, and they figured out that he was the main administrator of this um carting portal. And so in that undercover operation, there's been a lot of stories out there written about it. The Secret Service essentially took over that courting portal for a span of months and was able to apprehend multiple um perpetrators of that stolen credit card information that were located all over the world.

Now, when you you think about an operation like this, uh that obviously many things have to go into the successfully. You you need cooperation against multiple teams, uh you you need uh this diligence over many months. People talk about fraud is this cat and mouse game of you know, fraudsters are trying to do things and risk teams are trying to respond. What did what did being in the government and the secret service feeling teach you about how to manage teams that that have maybe diverse skill sets and getting those different teams to work together towards this type of goal?

Aaron Powell I think it it it poised us in a unique position with being in the Secret Service to begin with. The Secret Service is a very small federal law enforcement agency when you look at comparatively to the FBI and some of the other ones out there. Just when you look at the protection mission that the Secret Service has, whenever we go into a city to to set up a security plan for the president or the vice president when they travel in there, it's not the Secret Service doing that security plan.

It's the Secret Service, it's the local police, it's it's the state police, it's other our other federal partners. Everybody has their piece of the pie and their piece of the puzzle to make that that plan happen. The same thing goes with the complex uh criminal investigation. Uh my specialty at the time in the early 2000s was computer forensics.

We had other individuals that specialized investigating in network intrusion investigations. You had other individuals that were that were uh network administrators that had a background in IT. You need to to, nobody's gonna be an expert in anyone's situation. So you really have to be a force multiplier, and you cannot only just rely on that within federal law enforcement.

When you get into large-scale operations such as that one and any of them subsequently, you have to partner with corporate America because corporate America is always gonna be a couple of steps ahead of the government. That's just the way it is. And if you're not engaging and working with your corporate corporate partners, then you're not gonna be as effective as you could otherwise. I I I there there's so much here.

I I think when you talk about um the idea of kind of speed of corporate maybe versus government, definitely a hot topic when we think most people today is artificial intelligence and how you can use AI to drive uh kind of effectiveness, to drive precision. At the same side, uh, there can be hallucinations as we know. And AI isn't always about telling you where it has hallucinated. We're dealing with an area here where if you get something wrong, if you're wrong and this person actually is on a sanctions list and now the bank is able to uh is now running afoul of the Patriot Act, they could get in a lot of trouble.

How do you think about that balance of you know having AI make decisions quicker, but making sure there's still people in the loop, uh, whether they're do you think that a human should always be approving from a QA perspective? What do you think that balance should look like? This is something we're going through right now in imprint, and I'm sure a lot of corporations are. How do you most effectively bring AI in?

I don't think AI is a substitute for personnel whatsoever. Uh I don't believe it's going to eliminate the people working in risk and fraud. I think it is a force multiplier. It makes us more efficient, it makes us better at what we're doing and make where we can do it quicker.

But there are some things that we can automate. If you train that LLM well enough, can it do, can it follow your standard operating procedure? Can it analyze the evidence, the data itself, and make an educated decision in a way that both you or like with us with imprint, we have to look to our sponsoring banks as well, making sure they're comfortable with those decisions. We don't have that in the workflow as of yet, but you know, that's always something that we want to explore is how do we properly deploy AI?

How do we ensure that there aren't hallucinations? And I think, Eli, you're right on right on the the target there, that I do think that the human is always going to be involved with that, not only to make sure that it is coming through and it's doing everything accurately, but on top of that, something that I shared with you earlier before we we did the talk is I think fraud is so human-based. No matter what the fraud looks like, there's always going to be a human element to it.

It's the motivation behind the criminal act. It's the motivation behind why they are are doing what and where in the steps of the intrusion or the the steps of the violation. Are they utilizing AI and other pieces of technology because they're lazy? Or are they doing it because they don't have the knowledge, you know, the old script kitties that we always used to see with malware production?

Or is it just making them more efficient on there? Um that's hard for a computer always to figure out, and I think the human has to be evolved in there, and experience really drives that in evaluating um what the the accuracy of those fraud investigations would look like. Yeah, you shared with me in advance a line that I love, which is fraud is fundamentally human. And I think this is really interesting when you think about AI, and I I like, and you did as well, to bucket synthetic fraud in here, in that what when you think about what synthetic fraud is, it's creating identities, nurturing them into a bureau that shouldn't exist.

AI makes it easier to create combinations of this, and Gen AI makes it easier to create more fake identities. So AI and synthetic are increasing the amount of overall identities we have to sift through. When you say fraud is fundamentally human, I'm guessing that you're kind of staying to the fact that at some point a human must do something to take advantage of these identities. You know, the fraud technically isn't necessarily happening at the moment of application, is what you're doing with it.

What do you how do you think about that? How do you think about kind of deriving the intent? Or or do you even kind of uh do you think it even steps starts to step sooner? I think more than anything is I'm looking for the motivation of what's happening.

Why is the person doing what they're doing on the platform? Are they trying to gain access to the platform to steal information? Are they trying to gain access to the platform to exploit uh stolen information they already have? Do they have a bunch of of stolen account numbers that they're looking to engage in money laundering to wash money in one way or another through a transaction?

I think the human is always part of that because uh fundamentally people are greedy and people are lazy. And to what extent that's what dictates where they fall in the fraud line is how greedy are they, how lazy are they, and how determined are they to try to exploit your your network and exploit your platform. And do you do you think, um, what when you're kind of talking about I I like the thing in that we say we work in many different verticals. And I say on the one hand, fraud is fraud, in that the tool you use to catch synthetic fraud for a real estate company is probably the same tool you're using to catch it for a credit company.

However, I say fraud is not fraud in that the real estate company is worried about eviction rates going up and the credit lending companies worried about uh chargebacks and disputes. So these are worried about fundamentally different motivations. When you talk about this and figure out the motivation, do you think that changes from your perspective? One, I guess.

Do you think fraudsters operate in multiple uh kind of vectors? Like are fraudsters a diversified horizontal suite, if you will, where they're kind of trying to use the same tools to get access? Uh or do you think that kind of you've seen maybe a develop of specializations where there are different kind of fraudsters or rinks that have developed specialties at romance scams or develop specialties at defrauding certain types of companies? I think overall we see a great uh specialization, uh, especially if you look back at the marketplaces we discussed earlier.

If you go in there, you could shop around for exact skill set you need. Did you need somebody that was a malware writer? Did you need somebody that was able to deploy the malware and collect the information from you? Did you need to go in and purchase large-scale access devices so you can go out and exploit them?

Did you need somebody to produce fake identification documents for you? All those specialties are out there and available. And the individuals in the criminal uh, the overall marketplace, they serve different functions. Uh, if you're really good at running a set of mules, mules would be people that if you have a bunch of credit card numbers with associated pins, debit cards, and you encode them to white plastic.

And in previous years, you used to mail those pieces of white plastic out with the ATM numbers, and you would have people go out and actually go to the ATMs and do cash outs. Uh, we still see that from time to time. We've seen uh lately a lot more of ghost tapping where they will preload several credit card numbers into virtual wallets via Google Wallet or or Apple or things of that nature and encode those on phones and actually ship the phones out so the phones can do can do the transactions at the point of sale uh right from the phone.

There's a lot of specialization in there, and it's just what is your motivation and what do you need? What piece of that do you need to complete your fraud? You brought up Mule accounts. There's this interesting study, I think, that I could be slightly off on it.

Uh Texas is the state with the number one remittances via bank to Mexico, which makes sense. Uh, it's on the border. And I believe uh one year Minnesota was two, which people thought was very suspicious, in that this seems like these are perhaps accounts being leveraged to send money uh with less of a connection. And I want to throw this to you for two reasons.

One is I think mule accounts are on the rise because fraudsters realize that they may not be able to open accounts anymore, so can they get people to do their dirty business? But two, to me, this goes back to I think an important area that uh when we talk about fighting fraud, we're fighting, you know, like that example is highlighting how cartels bring in money to them. And do uh kind of crime and and and traffic substances. And I think maybe I'm curious, do you uh like kind of bring a sense of like and I mean this in the most sincere way, kind of real pride of what you're working on in the Secret Service?

Those organizations aren't discriminating if they're targeting government or private companies, but they're using the proceeds all the same. And I feel that maybe we we don't spend as much time talking about what does it mean to catch a bad actor? Who are those bad actors and what what would they actually be doing? So I know that was a lot, but I'm curious from mule accounts to to cartels.

Well, I think we're unique when we're talking about the Secret Service. Um when we were formed, we were part of the Treasury Department originally. And then after the Patriot Act, we became part of the Department of Homeland Security. Um we have always been a white-collar financial fraud investigation agency.

And that's why we are always interested in protecting the payment, uh, the payment networks of the of the U.S. corporate system. So that's why we are always involved with access device fraud from the beginning.

Um and what differentiates us from other law enforcement uh entities is just that is we're looking for in fraud. Uh we changed the vernacular that we used for for access device fraud and other crimes that the Secret Service um investigated several years ago to say that we we were investigating cyber-enabled fraud. So that would be any type of fraud where uh some type of some type of cyber is involved with it. Are you using crypto to use to move the money?

Are you trafficking in the credit card numbers? Are you exploiting those credit card numbers over the internet? Are you re-incording white plastic and doing it at ATMs? Are you going in and doing point of sales?

We look at it more in the financial fraud side of it. Now, you brought up cartels and things of that nature. There's also what we could look at when we're talking about especially network intrusions. Are we talking about nation-state and things of that nature?

The Secret Service overall, we don't have any Title 50 authorities, so we are not an intelligence agency as the way FBI is uh when they're dual hats. So when it came to nation-state type of investigations, we would not actively engage in those. But with the Secret Service, we were always looking for that financially motivated criminal looking to exploit the uh financial services networks. It it's it's really interesting.

Um when you when you think about kind of looking to exploit financial networks, would will you be going preemptively to a payment rail or some type of method and saying we think this is an exploitation that you should be worried about? And part two of that is how do you feel about now with whether it's stable coins, agentic commerce, or like there are newer methods that are being introduced and regulations definitely lagging behind, protocols are lagging behind. I still haven't really seen much with agentic commerce.

Um but how how do you uh and I'm not sure when we will, but that's not for me to raise money on, so I'll let them figure it out. But when you think about these new uh these new methods, how do you how do you think about kind of like what should the role be of government or agencies to make sure that these are actually built in a way that the protocols aren't able to be exploited? That's a that's a tough question because I would often say that a lot of those exploitations that are out there to exploit the payment rails that we don't know they're out there, I don't think it's going to be the government that identifies them.

I don't necessarily think it's always gonna be the criminal element that identifies them. I think it's gonna be corporate America as we're going through and we're looking to implement these new methods. I am absolutely fascinated by stable coins right now. Um I'll I'll talk those upside, uh one side up and the other.

I think that is the next step of what we're seeing in payment systems, especially for cross-border payments. And AI is going to be involved, especially what you said with the genetic commerce. And we just saw, you know, the disagreement that we've got going on right now with ChatGPT and with Amazon. Are those are those agenic merchants going to be able to operate on Amazon, or is Amazon rightfully classifying them as a bad actor because it does have the same indications of somebody looking to exploit their their platform?

A lot of these problems, I you can't look to government for that. And that's why it's particularly interesting for me for being out of government now and being in private industry and is and being in a startup. You know, imprint's been around for a little over five years now, so we're still a small pre-public company. And it's fun because we are moving at the speed of light.

As soon as we can figure something out, we're we're moving along. The same thing with you guys, Eli, with Footprint. You guys are doing the exact same thing. I think a lot of what we're going to see for the agent of change that is going to come from small, young, nimble companies like ours that are addressing the issues in the space as they're seeing them in real time because we're not hamstrung by the old brick and mortar uh financial services processes that some of our larger corporate partners are involved with.

Think about, I guess, the future of the space. What gives you hope? Like what have you kind of discovered that has really given without you know letting people know what they can't do to get past you anymore, but what broadly do you think kind of is giving you hope that kind of there are more and more tools for people like you in the seat uh of fighting these threats? I think by enabling some of the more uh innovative ways of making payments out there, it's going to make it more secure.

I think blockchain is a great thing. Blockchain is highly traceable. It's it you can you can utilize some really good tools to figure out who's doing what. Once it hits the blockchain, it's then it's in there.

You just have to learn how to how to how to utilize it. Stable coins fall right into that. I think by utilizing crypto, you know, back in the past, when we were talking about it in the early 2000s, we were talking about web money and e-gold and some of these old um online currencies that work just because we agreed they work. Now that we're seeing crypto with blockchain, based off the blockchain, Bitcoin, uh, Ethereum, Solana, uh, everything we're seeing with stable coins, USD, USDC versus USDT, you know, with the Genius Act being passed this year.

Um seeing that coming back into shore, where we were seeing a lot of things with stable coins going offshore in the past couple of years, because maybe we weren't as as forgiving for those new technologies with the U.S., but we're seeing more of it going on now. I guess just a long-winded way of saying there's so much that is changing and has changed quickly in the last couple of weeks to months in the crypto space that I believe that what was largely seen as foreign just months ago that nobody understands when we say stablecoin, it's just some fad that we're actually seeing it be endorsed by U.

S. government entities, by major corporations like JP Morgan Chase. And then you have the preeminence of a lot of what were going on with the with the fintechs, with Coinbase and others, Fireblocks, all those type of companies that are just really making these technologies mainstream. Could you maybe touch on the traceability aspect?

Why is that so tough traditionally? Mainly because it's an education gap. People need to learn how to utilize the tools. The blockchain is there.

I'm not the best, I'm not the most well trained on it. I have experience in it, but we always utilize people that have more experience that we're doing that to assist us in law enforcement to do those, uh, to utilize those tools on the blockchain to look at them. But the capability is there, the technology is there. You just have to learn how to utilize it properly.

And like I said, I'm not the best one to speak to that right now. A final fun question for me. Uh, you may or may not be able to answer it. Did you ever get to ride in the beast?

I never rode in the beast because I was never in the transportation section. I was in the follow-up vehicle, the very large uh suburban that followed it quite often. But uh no, never on the beast. Was on Air Force One, was never on Marine One.

But uh yeah, we uh we there were some unique experiences there. I'm sure. Jason, thank you so much for coming on. Really appreciate you coming and sharing sharing these stories and all you've learned and appreciate all the work you do.

Uh I really appreciate the opportunity and uh look forward to running into you again sometime soon. Likewise, sir.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 125: Stop Avoiding the Question That Will Change Your Life w/ Jason BrownNo Limit Leadership · features Jason Brown54 / 100
  • Secret Service Agent Reveals Undercover Cyber OpsThe Audit · on U.S. Secret Service76 / 100
  • Managing the Mission at Homeland Security: A Conversation with Troy Edgar, Deputy Secretary, U.S. Department of Homeland Security.The Business of Government Hour · on U.S. Secret Service66 / 100

More from Risk and Reason

All episodes →
  • What Banks and Fintechs Get Wrong About Each Other w/ Ethan from FS Vector79 / 100
  • Why the Right Eviction Rate Isn't Zero w/ Brendan from Findigs92 / 100
  • From eBay Skunkworks to Agentic Payments w/ Shayanth from Highnote86 / 100
  • Zero Fraud Means Zero Revenue w/ Zach from Comun79 / 100
  • Dub's COO, Brett: Why “Move Fast” Breaks Fintechs86 / 100
All Risk and Reason episodes →