https://krebsonsecurity.com/2022/09/fake-ciso-profiles-on-linkedin-target-fortune-500s/ Advertisement [13] Advertisement [10] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Fake CISO Profiles on LinkedIn Target Fortune 500s September 29, 2022 5 Comments Someone has recently created a large number of fake LinkedIn profiles for Chief Information Security Officer (CISO) roles at some of the world's largest corporations. It's not clear who's behind this network of fake CISOs or what their intentions may be. But the fabricated LinkedIn identities are confusing search engine results for CISO roles at major companies, and they are being indexed as gospel by various downstream data-scraping sources. If one searches LinkedIn for the CISO of the energy giant Chevron, one might find the profile for a Victor Sites, who says he's from Westerville, Ohio and is a graduate of Texas A&M University. [victorsites] The LinkedIn profile for Victor Sites, who is most certainly NOT the CISO of Chevron. Of course, Sites is not the real CISO of Chevron. That role is currently occupied by Christopher Lukas of Danville, Calif. If you were confused at this point, you might ask Google who it thinks is the current Chief Information Security Officer of Chevron. When KrebsOnSecurity did that earlier this morning, the fake CISO profile was the very first search result returned (followed by the LinkedIn profile for the real Chevron CISO). [fakecisosearch] Helpfully, LinkedIn seems to be able to detect something in common about all these fake CISO profiles, because it suggested I view a number of them in the "People Also Viewed" column seen in the image above. There are two fake CISO profiles suggested there, including one for a Maryann Robles, who claims to be the CISO of another energy giant -- ExxonMobil. [maryannrobles] Maryann's profile says she's from Tupelo, Miss., and includes a quaint description of how she became a self-described "old-school geek." "Since playing Tradewars on my Tandy 1000 with a 300 baud modem in the early '90s, I've had a lifelong passion for technology, which I've carried with me as Deputy CISO of the world's largest health plan," her profile reads. However, this description appears to have been lifted from the profile for the real CISO at the Centers for Medicare & Medicaid Services in Baltimore, Md. Interestingly, Maryann's LinkedIn profile was accepted as truth by Cybercrime Magazine's CISO 500 listing, which claims to maintain a list of the current CISOs at America's largest companies: [ciso500] The fake CISO for ExxOnMobil was indexed in Cybercrime Magazine's CISO 500. Rich Mason, the former CISO at Fortune 500 firm Honeywell, began warning his colleagues on LinkedIn about the phony profiles earlier this week. "It's interesting the downstream sources that repeat LinkedIn bogus content as truth," Mason said. "This is dangerous, Apollo.io, Signalhire, and Cybersecurity Ventures." Google wasn't fooled by the phony LinkedIn profile for Jennie Biller, who claims to be CISO at biotechnology giant Biogen (the real Biogen CISO is Russell Koste). But Biller's profile is worth mentioning because it shows how some of these phony profiles appear to be quite hastily assembled. Case in point: Biller's name and profile photo suggest she is female, however the "About" description of her accomplishments uses male pronouns. Also, it might help that Jennie only has 18 connections on LinkedIn. [jenniebiller] Again, we don't know much about who or what is behind these profiles, but in August the security firm Mandiant (recently acquired by Google) told Bloomberg that hackers working for the North Korean government have been copying resumes and profiles from leading job listing platforms LinkedIn and Indeed, as part of an elaborate scheme to land jobs at cryptocurrency firms. None of the profiles listed here responded to requests for comment (or to become a connection). In a statement provided to KrebsOnSecurity, LinkedIn said its teams were actively working to take these fake accounts down. "We do have strong human and automated systems in place, and we're continually improving, as fake account activity becomes more sophisticated," the statement reads. "In our transparency report we share how our teams plus automated systems are stopping the vast majority of fraudulent activity we detect in our community - around 96% of fake accounts and around 99.1% of spam and scam." LinkedIn could take one simple step that would make it far easier for people to make informed decisions about whether to trust a given profile: Add a "created on" date for every profile. Twitter does this, and it's enormously helpful for filtering out a great deal of noise and unwanted communications. The former CISO Mason said LinkedIn also could experiment with offering something akin to Twitter's verified mark to users who chose to validate that they can respond to email at the domain associated with their stated current employer. "If I saw that a LinkedIn profile had been domain-validated, then my confidence in that profile would go way up," Mason said, noting that many of the fake profiles had hundreds of followers, including dozens of real CISOs. Maryann's profile grew by a hundred connections in just the past few days, he said. "If we have CISOs that are falling for this, what hopes do the masses have?" Mason said. Mason said LinkedIn also needs a more streamlined process for allowing employers to remove phony employee accounts. He recently tried to get a phony profile removed from LinkedIn for someone who falsely claimed to have worked for his company. "I shot a note to LinkedIn and said please remove this, and they said, well, we have to contact that person and arbitrate this," he said. "They gave the guy two weeks and he didn't respond, so they took it down. But that doesn't scale, and there needs to be a mechanism where an employer can contact LinkedIn and have these fake profiles taken down in less than two weeks." This entry was posted on Thursday 29th of September 2022 04:52 PM A Little Sunshine Ne'er-Do-Well News The Coming Storm Web Fraud 2.0 fake CISOs LinkedIn Rich Mason Post navigation - Accused Russian RSOCKS Botmaster Arrested, Requests Extradition to U.S. 5 thoughts on "Fake CISO Profiles on LinkedIn Target Fortune 500s" 1. rip September 29, 2022 LinkedIn became a cesspool even before Microsoft took it over. I left a small bit of token information up for one of my last jobs and removed anything about me personally. I doubt that the information has actually been removed since companies like google, microsoft, amazon, apple, etc. are trying to get the goods on everyone they can. Reply - 2. Stephen Heider September 29, 2022 Hi Brian! Great writeup - kind of incredible to be honest. Am curious - what did your 9 connections that appear to be linked to Maryanne say about their relationship? Reply - 3. Jon Marcus September 29, 2022 Jennie's profile uses mixed (confused?) pronouns, not just male: "...Jennie has worked *her* way up..." but then "...where *he* was in charge of..." Reply - 4. Will P September 29, 2022 Perhaps the goal is to use the fake LI profiles as a source for credibility when attempting to socially engineer ones who would fall somewhere under the CISO's chain of command. Reply - 5. Ollie Jones September 29, 2022 ArsTechnica.com has just posted an article about an attack on big companies via supply chain compromise in open-source apps. The article says a North Korean state actor is behind the attack. Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [3] Advertisement Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Fake CISO Profiles on LinkedIn Target Fortune 500s * Accused Russian RSOCKS Botmaster Arrested, Requests Extradition to U.S. * SIM Swapper Abducted, Beaten, Held for $200k Ransom * Botched Crypto Mugging Lands Three U.K. Men in Jail * Say Hello to Crazy Thin 'Deep Insert' ATM Skimmers Spam Nation Spam Nation A New York Times Bestseller! Thinking of a Cybersecurity Career? Thinking of a Cybersecurity Career? Read this. All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Russia's War on Ukraine * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Why Paper Receipts are Money at the Drive-Thru (530) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security