episode.ascii — live render
● episode

Paperweights

TL;DRA Canadian man's wife had her iPhone stolen at a mall. After locking and blacklisting it, the phone surfaced in Vietnam, then prompted phishing texts impersonating Apple to steal her iCloud credentials so thieves could unlock and resell it.

The story of the wild amount of work it takes to turn a stolen phone back into money.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: So this family goes shopping at the mall.

Speaker 2: My wife and I and kid were shopping.

Speaker 1: That's the dad, John. And it's getting a little bit late in the day and their son is starting to get tired.

Speaker 2: Because it was kinda getting close to nap time. I had to get supper started and whatnot. And she kept shopping with my mom who was who was visiting.

Speaker 1: And while he's at home, he gets this call.

Speaker 2: About twenty minutes later, she called me up from my mom's cell phone and said, hey, can you track my iPhone in the you know, I I seemed to lost it. I think my kid, you know, we we kinda thought, oh, maybe our our son took it out of her purse and dropped it on the floor or something like that.

Speaker 1: So he logs into her iCloud to see where it is, and her phone isn't reporting its location anymore. It's gone offline. It's been turned off in the last couple minutes, which makes him think,

Speaker 2: like, this isn't just a, random, okay, lost my cell phone. It's somebody stole it.

Speaker 1: Here's a question. In a world where you can lock, encrypt, and blacklist a lost or stolen phone, where a lost phone, if properly reported, is

Speaker 2: basically an expensive paperweight.

Speaker 1: What is the point of stealing a phone? Who would buy it? Do you just sell it for parts, or is there something that I and John were missing? John, which isn't his real name, works at a really well known technology company. And when his wife's phone went missing at the mall, he started going down this rabbit hole of trying to answer that question. What does a phone thief even do with a wiped, registered as stolen, blacklisted phone? Until one night, his wife's new phone gets a text message. Something came crawling back out of the rabbit hole. This is where stolen phones go, here on hacked. Have you ever lost a phone?

Speaker 3: No. I don't think I have. But Mhmm. But I know many people that have, obviously.

Speaker 1: Yeah. Sure. I've never lost one. I found a phone once, and I I returned it to the person.

Speaker 3: Same. But Same.

Speaker 1: Yeah. As we all should.

Speaker 4: We're we're

Speaker 1: both good.

Speaker 4: You and

Speaker 2: I Yeah.

Speaker 4: Good. I

Speaker 1: know. Yeah. High five. Pat on our back.

Speaker 3: Yeah. Yeah.

Speaker 1: Yeah. But I have always wondered. So, like, for about ten years now in the West, I guess, there's been really good infrastructure for blacklisting stolen or lost phones. And it probably it kinda when you look at the timeline, it sort of roughly lines up with the transition from phones being phones to phones being personal computers that contain Sure. Art. But exactly. But it didn't used to be that way. There's we had to build this infrastructure. The first step to locking down stolen phones was developing, like, a a blacklist of stolen devices. Europe got one in 2004. Canada followed about nine years later with the CWTA in 2013. The US got one a little bit after that. And over time, a bunch of them have all sort of started talking to each other, like sharing this list of stolen phones, a list of IMEI numbers. Do you know what an IMEI number is, Scott?

Speaker 3: I sure do. It's essentially the unique ID code for your phone,

Speaker 1: on the wireless network. Bingo. International Mobile Equipment Identity. It's like a 15 digit fingerprint for when your phone connects to the carrier. Yeah. When you report a phone stolen, what they do is they add that IMEI number to a blacklist that's shared between all these different networks. So if anybody tries to use the phone anywhere in all of North America, that blacklist is gonna prevent it from being activated on any wireless carrier until you remove it from the list, which only you, the owner, can do. You can technically change an IMEI, but it's difficult if, say, on, like, an iPhone, you mark it as lost through iCloud, which remotely locks and encrypts the device, disables Apple Pay. It's very, very hard. The phone is, if I'm, you know, following all this correctly, to borrow John's phrase, it basically becomes a paperweight. So John's wife's phone goes missing at the mall. She calls up her husband, and John starts kinda poking around a little bit. He posts on a local community Facebook page, where they live, just saying, hey.

Speaker 2: You know, if anybody finds a blue iPhone 12 in, you know, in the mall, probably around this time, let me know. You know, it belongs to my spouse. And then a few minutes later, I started getting replies saying, oh, my phone's missing too. So I had about four or five people report, you know, just on that Facebook post saying that they're they had a phone stolen from them at the mall or, you know, neighboring stores, that afternoon. And that's kinda that's kinda when I thought, okay, man, what's what's going on? Like, this isn't just a a random, okay. I lost my cell phone. It's somebody stole

Speaker 1: it. So John goes through those steps that we've listed before. Right? Turning the phone, he thinks, into a paperweight.

Speaker 3: You're bricking it.

Speaker 1: Bricking it. He goes to the carrier portal. He marks it as stolen. So the phone's IMEI number gets added to the blacklist and won't connect to any carrier in North America unless she removes it. Then to protect the data and make the device useless outside of North America, he hops on to iCloud and reports it as lost there, which locks the phone itself down, disables Apple Pay.

Speaker 3: You can wipe it. You can wipe it. Yeah. And do all kinds of things.

Speaker 1: Now you don't even you can't even just get into it with the phone's password. You need the full iCloud credentials if you wanna essentially unlock this phone at this point. And even then, it still wouldn't connect to a carrier unless he tells the carrier, hey. I found my phone.

Speaker 2: So, you know, it can't connect. There's no data usage, no phone usage, and it's just kinda marked as lost or stolen. That way, you're not on the hook for incurring any charges that happen after that.

Speaker 1: John does exactly what I, as a layperson, kind of understand you're supposed to do when you lose a phone. He he, you know, locks it down, and he goes to bed. And, sure, it's kind of a sour note to end an otherwise nice day at the mall on, but, like, you know, you lose a phone sometimes. What can you do?

Speaker 3: Costly costly errors, but but something that's probably more common than we wish it was.

Speaker 2: Until Later that night, about 10:00, I got a ping on my cell phone that said, oh, iPhone's been located. And it had shown up online, three hours away in in, at a strip mall in Toronto. I thought, okay. That's really weird. So I reached out to a couple of the people that I had been chatting with on Facebook about them having, you know, their partner or girlfriend or whatnot had their phone stolen. And said, hey, so our phone showed up, you know, in at this address. You? And they the two people that I spoke to confirmed it, that their phone was there as well.

Speaker 1: So the phone goes missing, and then briefly appears online, three hours away in a strip mall before going dark again, and it wasn't alone. And this all kind of starts to tell a little bit of a story. Someone has spent the day stealing phones across this part of Ontario, and they get in their car or whatever with all these phones, and they go somewhere, and they take them to the same place. And there, in the middle of the night, they're just sort of quickly turning these phones on to see if they're locked or wiped or if they work or if they don't. They turn on John's wife's phone, and they see it's got the password, see it's locked, and they quickly turn it back off. So John, now confident that this is a theft, does you mentioned this earlier, He doesn't just lock the phone. He now says, okay. Next time this thing turns on, wipe off the hard drive. Delete everything on this thing. These are phone thieves. Brick it. Truly, the last step he could take.

Speaker 3: Yeah. Shut shut it off. Kill it forever.

Speaker 1: Kill it. Just butcher the thing.

Speaker 3: Save the protect the data. Exactly.

Speaker 2: So the next time it comes online, it'll check-in and and erase itself.

Speaker 1: And it's still locked down behind those iCloud credentials. He's not only bricked the phone, he's filed a police report, told it to erase itself the next time it comes online. The only way this phone is of any use is if somehow his wife gets it back and can log back into her her iCloud account on it. She would have to redownload everything and turn it back into a phone. A couple of weeks pass until this device shows its face again. And in those intervening weeks, it has gone on a journey. It's two weeks later, again in the middle of the night, and they get an email. A legitimate email from Apple saying, hey, you know how you told us that the next time this phone comes online to immediately wipe the hard drive? Well, we're just letting you know it came online, and we wiped it. And John says, where did it come online?

Speaker 2: Was reporting as being located in Vietnam.

Speaker 1: So they put this phone on a plane, in a shipping container, in a package, and they'd gotten it to Vietnam where someone had tried turning it on, at which point Apple says, there's that little bastard, and wipes the drive. And sends John a message letting him know what had happened. The blacklisted, wiped, and importantly locked phone is now in Vietnam. The only way it becomes a phone again, anything other than a paperweight, is if John's wife were to log in with her iCloud credentials. And John gets this suspicion that he knows what's gonna happen next. For sure.

Speaker 2: I kind of jokingly said to my wife that, okay, you're gonna start to see some phishing emails.

Speaker 1: In the weeks since his wife had gotten a new phone with the same number as before, and the next morning

Speaker 2: she gets a text message that basically said something along the lines of, your iPhone has been found. Please click here and log in to see its location.

Speaker 1: And she says, is this what you meant? John says, yes. That is exactly what I meant. Don't click on that whatsoever.

Speaker 2: The the verbatim, the text is what it says. It would be, dear customer, your iPhone twelve sixty four GB blue was found. View the location at and then there's a URL, and then, you know, it's signed by find my iPhone.

Speaker 1: And these texts just start coming one after another after another. And John could have ignored them. He could have said, it's kinda creepy that they've got our old phone, and they're trying to trick us into giving them the iCloud login. But as long as you don't, as long as I don't, as long as no one gives those credentials, we're fine. I think I probably would have just called it a day there. But curiosity gets the best of him, and he starts saying, I'm gonna collect these messages. I'm gonna start creating a little database, and I'm gonna start putting them in and keeping track of all these URLs, these phishing attempts. I'm gonna try and just figure out what it is these people are doing.

Speaker 2: What we did was I just started collecting them. I started collating the these bad links as a way just to see, okay, what are they doing?

Speaker 1: He starts building this database, trying to figure out how this thing works. I think in one of our early episodes, we talked about the phishing classic of, like, you get an email from someone with an important file, but it's not actually their email. It's It's a version that's ever so slightly misspelled. Right?

Speaker 3: Like, that's the classic of this. The easiest easiest deception.

Speaker 1: At first, I assumed it was gonna be more complicated than that, so I started researching what had happened to miss like, where did we go after the misspelling? There were some really cool evolutions of that attack vector. One I thought was really cool was called the homograph technique. Have you heard of this? No. So it was in vogue for a couple years before browsers sort of nipped it in the bud. So say for, like, example, Cyrillic characters. Cyrillic characters will have codes that you can use. And if you were to type in one of these codes, copy it in probably, the software will automatically convert it to the Cyrillic character. If the domain you're trying to spoof has a character that has a Cyrillic equivalent, you can just make a domain with that long code in place of the letter, and the browser will automatically convert it to display as the Cyrillic character, which then shows it as a normal letter to the user. Sure.

Speaker 3: And it looks exactly the same.

Speaker 1: Looks exactly the same. Eventually, browsers figured this out and said stop dis auto displaying these, character codes as the character itself because this is like we're baking spoofing functionality into our browsers.

Speaker 3: We are facilitating this attack.

Speaker 1: The messages that John is getting are even simpler. They're the classic one, the misspelling. She's getting these texts that say you lost your iPhone. Log in here to see where it is. And the link, instead of apple.com, it's actually, what, how would you spoof apple.com? Apple.com.

Speaker 3: Oh, with a misspelling? Yeah. That make the p's q's maybe?

Speaker 1: That's pretty good. That's pretty good.

Speaker 3: Like, one of them, it's like your brain will auto fill it in probably if, like, the second one. Yeah. But even that, I don't know.

Speaker 1: And q is pretty good. Yeah. They went with app e, and I think they had to tag something else on

Speaker 4: the end

Speaker 1: of it, atpuppercasei.com. Exactly. You type it in, it looks pretty good. I think Apple does own I'm actually gonna check this. They must.

Speaker 3: Yeah. For protection's sake, do they own appy.com?

Speaker 1: Yeah. The the app apple.com owns appy.com. So they'd they'd strung something else in there in order to make it their own. But generally speaking, they were hiding behind the appie.com.

Speaker 3: Appie.com takes you to something that I don't even I probably shouldn't be here.

Speaker 1: For don't forget the e.

Speaker 3: I did. I went to a ppie.com.

Speaker 4: Oh, god. And I

Speaker 3: got Really?

Speaker 4: Yeah. Yeah.

Speaker 3: Yeah. And it looked like something that it looked like a a website that you don't wanna open on your computer.

Speaker 1: Weird. I'm getting to apple.com.

Speaker 3: Oh, maybe your browser is smart enough that it's redirecting you.

Speaker 1: Oh, I'm on I'm in Safari.

Speaker 3: Yeah. Yeah. Yeah. Maybe Apple has baked that functionality in. I was just using Microsoft Edge. That's

Speaker 1: fascinating. Yeah.

Speaker 3: Yeah. Yeah. So maybe they they have a protection built into their stuff to to stop people. And that could actually honestly be because of this attack. Because it's probably the same source code. Yeah. Yeah. Appy.com on my Safari browser takes me right to Apple too. Yeah. On Microsoft Edge, it definitely does not.

Speaker 1: So real time discovery here.

Speaker 3: Real time.

Speaker 1: Safari has, anti spoofing measures for Apple's own proprietary domains.

Speaker 4: Yeah.

Speaker 3: Probably to stop links opened on their mobile devices running Safari from opening and going to, you know, bad places.

Speaker 1: Whatever the spoof domain is that they're using, if you go to it, it redirects to just apple.com. So it looks like it's legitimate. But

Speaker 2: But these, you know, scammers actually were sending you a URL with, a malicious identifier. There was a header in the in the email link so that my suspicion is they could identify what phone that, credential belonged to. Right? So they'd send you a a reference and there'd be a key field, and that reference would say, hey. This is this is this blue iPhone that was stolen. Because if you actually fired up a browser and navigated to the link and clicked on the link that was sent in the message, it would bring you to a page that wanted you to to log in and actually, you know, enter your credentials.

Speaker 1: It takes you to a page where it says, hey, welcome to iCloud. Go ahead and log in here.

Speaker 3: Yeah. Yeah. Why don't you put your security credentials into this box? We'll we'll we'll take those from you. Thank you very much.

Speaker 1: It sounds like you wanna log in to iCloud. Why don't would you come to the right place?

Speaker 3: We can help you.

Speaker 1: A very old school phishing scam aimed just at you trying to steal your iCloud credentials so they can unlock your phone.

Speaker 2: And that's kinda when my, you know, my my spidey sense started tingling. I'm like, okay, what's going on here? And I've, you know, fired up a a private browser and, you know, VPN client. The I actually used a virtual machine to do this so that I wasn't downloading anything malicious on my on my home computer and just started seeing what these domains actually were. And I started just started compiling. Okay. You know what? This domain redirects to this domain and it's using this registrar and, you know, just compiling as much information as I could about it.

Speaker 3: I like that. I like that. I like that you made you made a sandbox just in case. Just in case.

Speaker 1: 100%. A little hazmat suit for wandering in some yeah. And he starts thinking about it. And the volume of phones stolen on just that day, all of which are getting these texts, implies that the people that are doing this have even more devices, and are trying to run and manage a pretty high volume of these different phishing texts, trying to gather all the data mapped to specific phones. Like, it's a lot of information flow to be managing. You would probably want to automate this in some way. You'd need some software to manage this operation if you were to do it at any kind of scale. So John, hidden behind his VPN and his virtual machine in his little sandbox hazmat suit, he makes his way to some iffy forums where he starts finding folks selling tools that do just this. What he starts to figure out are the tools being used by this hacker to deploy these phishing texts at scale.

Speaker 2: Interestingly enough, found out that you know, I started started doing some some digging into the dark web and found out that, there's actually these malware toolkits or, you know, phishing toolkits built for this sort of thing. And they're all built around this PHP exploit called Find My iPhone, which leverages the Find My iPhone API to hammer it and try and release the activation lock. So, I found this GitHub project that was, a proof of concept somebody had done clearly for, you know, quote unquote, not malicious purposes, wink wink, nudge nudge. And what it what it allowed the users of that, you know, particular tidbit of code to do would be to pass in the Apple ID and password that they were they were given. And then it would try and log in and it would, I I think it would remove the activation lock if it was able to log in. But at the very least, it was validating that those credentials were legit.

Speaker 1: A fully automated process. You punch in the number of the stolen device, which even though the device is locked, you have because you have the device's SIM card. And it's off to the races. Deploying these phishing texts to try and get these, you know, all important iCloud credentials, which if you were to fall for it and give them over, it would use to automatically log in, do a legitimate reset of the device, thus making it resellable without you having to touch anything. And if we think about the two security steps it takes to brick a stolen phone, the iCloud stuff is reversible if you have the iCloud credentials. It has to be because what if you found the lost phone? You have to be able to get it running again. Mhmm. Your credentials are the last line of defense. If they get those, they're you as far as that device is concerned. The other line of defense is getting the device IMEI blacklisted. But, again, that's only North America wide, and they're in Southeast Asia. So if you could get the device running again with iCloud credentials, it would now be a phone again as long as you don't try and connect to a North American carrier. Through this process, the paperweight has been turned back into a phone. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations, but boy does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify dot com slash hacked.

Speaker 5: No one goes to Hank's for spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 4: You have one new message. Translating. Disney and Pixar's Hoppers is now available on Disney plus.

Speaker 1: You could say that again.

Speaker 4: Critics are calling it Pixar's funniest movie ever and a wildly entertaining ride. Blizzard potato, it's certified fresh and verified hot.

Speaker 3: Now, we party.

Speaker 6: This is incredible.

Speaker 4: Wow. I am clearing the rest of the day. Disney and Pixar's Hoppers, now

Speaker 1: available on

Speaker 4: rest of the day. Disney and Pixar's Hoppers now available on Disney plus. Rated PG.

Speaker 1: So John starts playing close

Speaker 7: You thought this was your run club era. Turns out, it was more of a thinking about run club era. The good news? Someone's marathon training is about to start. Sell your workout gear on Depop. Just snap a few photos, and we'll take care of the rest. They get their race day fit, and you get a payout for trying. Someone on Depop wants what you've got. Start selling now. Depop, where taste recognizes taste.

Speaker 1: Attention to the domains that the hackers are using.

Speaker 2: I started collating as much, detail as I could around the domains that were used for the phish, evidence of evidence of this, figured out. They were actually all pointing to the same domain in the back in the background that was hosted. So I was was protected by a CloudFlare proxy, so I couldn't really find anything about it.

Speaker 1: And even if he can't tell who controls the domains, he knows that this activity definitely qualifies as abuse under the terms of any registrar. Of course. And he's been assembling all of this evidence for his own purposes and takes all of it, all the screenshots, all the domains, all the stuff he's found, and he turns around and he goes to the registrar and says, I'm reporting some abuse.

Speaker 2: So I just compiled all that information and then on mass fired a bunch of emails off to the abuse, you know, abuse accounts at all the different, the registrars and hosting providers. At the end of the day, I didn't really care so much about the stolen phone. It was that, holy crap, what are these guys doing? It was more than just a single it's more than just a single phone. Like, there's, you know, they've got some mechanism to do this.

Speaker 3: Well, you're probably also just, like, looking for a little bit of, I don't know, value out of all the time invested in kinda tracking it down. So that makes sense. Go after them. I kind of assume those abuse at emails are just, like, voids that you throw things into, but I'm intrigued to hear if that's the truth.

Speaker 1: It works. Oh.

Speaker 2: Really? Probably within the next day or two, they were just taken offline. I didn't even get I didn't even get a response back from the registrars or anything. Just gone. Gone. You know, I I fired up my, virtual machine one night just to log in and see, hey. Are they still are they still doing this? And they're gone. And then the phishing mess the phishing messages stopped.

Speaker 3: Within a day or two.

Speaker 1: Within a day or two.

Speaker 3: That's shocking.

Speaker 1: They're gone. He's taken the sites down. And the question that you naturally then ask is, like, hey. URLs are really, really cheap. And John knows he probably didn't destroy this operation, but he certainly slowed it down.

Speaker 2: And I don't know if, if it was how how they maybe they just stopped fishing me. I don't know. But, they they stopped fishing us. That's for sure.

Speaker 1: So John had reverse engineered the architecture of this hack. Right? He'd used that to at least create a little bit of a speed bump for this thing, a little bit of friction for these folks. He'd gotten sites pulled, and, hopefully, those registrars might learn to recognize this in some way. At least make it harder for people to do the same thing again. But if you're following the story kinda closely, there's still the IRL physical part of this that hasn't totally been worked out. What is the connection between these pickpockets in Eastern Canada and phone hackers in Vietnam? Where do those phones go? How does a pickpocket get a phone to a hacker a world away? That's the only part of this where there isn't really a digital trail of breadcrumbs for someone like John to follow. Yeah. And then a thought popped into my head as we were discussing this, This moment earlier in the story that we lack a little bit of clarity on. After the phone is stolen, but before it shows up in Vietnam.

Speaker 2: About 10:00, I got a ping on my cell phone that said, oh, iPhone's been located. And it had shown up online, three hours away in in, at a strip mall in Toronto. I thought, okay. That's really weird.

Speaker 1: The strip mall, which was its last stop in North America before it shipped off to Vietnam. And so I asked John, like, what business in particular in this strip mall did it show up at?

Speaker 2: It was a Vietnamese restaurant in Toronto.

Speaker 1: And so I asked John, did you ever go to the restaurant?

Speaker 2: No. No. No. The the thought crossed my mind, but but no, I did not.

Speaker 3: You kind of assume that maybe they went for dinner after a busy day of stealing phones, and maybe they have connections in Vietnam. Maybe they're Vietnamese themselves, and maybe they like Vietnamese food. You know? And Interesting. Maybe they're maybe it's completely unrelated.

Speaker 1: Maybe it's a total coincidence that they went for a bowl of pho after a day of stealing phones, and those phones, wherever they took them, just happened to end up in Vietnam. Right? Or or there is an international hacking ring being run out of a Vietnamese restaurant in Ontario.

Speaker 3: In a strip mall in Ontario. Or that. Could be.

Speaker 1: We'll never know.

Speaker 3: We'll never know.

Speaker 2: I mean, I thought Initially, I thought this was going to be, hey, you know, phone got stolen. It's been wiped. And somebody's going to sell it on, you know, Facebook or Kijiji or Craigslist or something. And then make a quick buck disappear, and the person that buys it is left holding the phone that can't be activated because of the activation lock. Okay. Big deal. You know? And and when I talked to my friend who's the police officer, they said the same thing. Like, okay. Well, you know, whoever buys it is gonna be upset because they can't activate it and and big deal. But no. In this case, it was so much bigger than than that. It did not stop there.

Speaker 3: The, yeah. Like, I the the economics of it just it's the the weirdest thing where it's like like, you gotta assume that they're quantity over quality here. Right? Like, you're you're you're buying bricked phones by the hundreds hoping to unbrick a few of them. Like, I can't imagine, like, the the churn rate is high. Like, I imagine that, you know, you send out a bunch of, you know, phishing scams and maybe you get 10%. So if you get buy 10 brick phones, maybe you get one out of it. But I guess I guess if you're paying $50 a phone for 10, that's $500 and you can resell that phone for, like, 800, you know, that's still a pretty good profit margin, but, it's just sad. I wish the world could take and dedicate all this, like, lost utility to to good things.

Speaker 1: For sure. An iPhone 12 for context, an unlocked iPhone used an unlocked used iPhone 12 retails on eBay for in and around in the 5 to 600 range Canadian.

Speaker 3: Right.

Speaker 1: So if we assume this really, this whole thing just turns on what is your success rate with the phishing scam because that's the, like, number you're dividing this out by. If it's half of them and you buy these phones for $50 and you can sell essentially you're selling one for 500, but only half of them are working, so you're making, like, 250 on average per stolen phone. Pretty good rate of

Speaker 3: return. Yeah.

Speaker 1: Is it every other phone works? Is it one in 10? Is it one in 20? The economics of this depend entirely on how effective your phishing attack is.

Speaker 3: And but, like, not even that. Like, how effective your pickpocketing is. Like, imagine if you need two people, like, what's your hourly pay? Like, Jordan and Scott go to the mall and steal phones for a day. Say we get say we get 20 phones. Yeah. Like, we have a wildly successful day. I feel like if you can

Speaker 1: get 20

Speaker 3: phones in a day, each of those phones sells for $20. It's $400. Mhmm.

Speaker 4: You know,

Speaker 3: they say that that was a full eight hour workday. You know? That's $25 an hour each. Like, that's not crazy money. Like like, I feel like there's better legal, more productive, you know, contributing to society in a positive way way to make $25 an hour. Maybe that's some entitlement that I have, but it just feels like

Speaker 1: It might also be that and, again, just speculating wildly. It could also be that this is sort of like a there's stages to it. Right? It's like the best thing we can do is try and truly unlock this phone because now it has become worth about $600 Canadian. Sick. That's our best case scenario. If we can't do that for parts alone, because every store that, you know, replaces screens has to get them from somewhere. Every store that replaces batteries, all of that stuff, the camera module, yeah, it reduces the devalue of the device when it's not a single working unit. But, say, for parts, it goes from 600. Even if it on parts alone, is worth half, that phone is still worth $300, roughly speaking. So it's not all or nothing. It's just this last ditch attempt at extracting the most value out of this phone as humanly possible.

Speaker 3: The other thing too would be when you're sitting in that Vietnamese restaurant power cycling these phones

Speaker 1: Yep.

Speaker 4: Yep.

Speaker 3: What's the percentage of phones that aren't bricked that haven't been locked? And, like, this is gonna sound bad, but, like, I know people that still don't have passcodes on their phone.

Speaker 1: Sure.

Speaker 3: And it's like, if there's not a passcode on your phone, you could pretty much reset it pretty simply. Like, I think you still need to log in to iCloud, if I'm not mistaken, assuming it's connected to iCloud. So yeah. I wonder what their hit rate of, like, just free winners are. You know? They They don't really

Speaker 4: do much.

Speaker 1: Yeah. Right the second you take it out of the pocket, it's worth the full retail value.

Speaker 4: Yeah.

Speaker 3: Yeah. Or whatever it's selling for used.

Speaker 1: And then you go down to stage two for the ones that are locked down, and they get run through this phishing scam, and then it trickles down to selling it off for parts.

Speaker 3: Yeah. Literally tearing it apart and selling the batteries and screens. Exactly. When you get digital criminals, you know, they're orchestrated, like, essentially organized crime. But, you know, they're going after massive things and hacking and stealing and ransomware where you're, you know, one good strike and you're making, you know, millions of dollars versus, like, steal phones. And I'm not stealing phones to, like, get access to someone's Bitcoin wallet and steal their Bitcoin or, like, get their, like, you know, get past their two factor authentication. It's like, no. I'm stealing phones because phones are worth money.

Speaker 2: I always thought, like you, right? Oh, there's the the phones have activation lock on them, and they're pretty they're pretty much useless if they're stolen. But clearly, they're not.

Speaker 1: Thanks for listening everybody. Thank you in particular to John for sharing his story with us, for reaching out, for being very generous with his time. I hope the plumbing debacle is going well. If you happen to have solved an interesting cybercrime hacking type story and you want to get in touch, if you have a story you think we should know about, especially if it's something you experienced or have some connection to, feel free to get in touch. You can find our contact information at patreon.com/hackedpodcast. Single best way to support the show is baking up. My main man, Eric Bacon, thank you for being a Patreon supporter. Stuart Bowles, your support means a lot. Drum roll. Holy hell. Thank you so much to Alisa Gonzalez Smith. Hacked Patreon patron of the month. Thank you so much. That's this one. That's this episode. Another one in the can. Thanks for listening. We'll catch you in

Speaker 4: the next

Speaker 6: one. This episode is brought to you by Nespresso. Being the best version of yourself is an everyday journey, and it begins in the morning by taking a moment to ground yourself. With the new Nespresso Vertuo Up coffee machine, morning routines become rituals, just one gentle press. And coffee brews, unfolding into whatever you need today, Bold or delicate, iced or hot, familiar or new. Press to explore. Every coffee, a new world. New virtual up. Shop now at nespresso.com.

Speaker 8: Every week, the Snap Judgment Podcast drops you inside someone's biggest decision. The kind of decision you can only make once. With everything on the line, what do you believe? What do you want? And what would you risk to get it? Find out. Tap to listen now to Snap Judgment from KQED on Spotify.

Speaker 9: This podcast is brought to you by Carvana. Selling your car should feel like one less thing on your list, not one more. With Carvana, it is. Just go to carvana.com, enter your license plate or VIN, and get a real offer down to the penny. No back and forth. No surprises. Just an experience you can trust. Like your offer? Accept it. Schedule a pickup and we'll come to you with a check-in hand. Your car, your timeline, your terms. Visit carvana dot com to sell your car today. Carvana. Delivery fees and terms may apply.