Beware! Pickpockets, Hackers, and Loose Women

By Mike Zusman

The lamest cybersecurity cliche is the one about surviving bear attacks.

Cybersecurity experts (who often have never actually hacked anything themselves) will say that you don’t have to outrun the bear, you just need to outrun your friend.

Meaning that if you get your cybersecurity basics right—install the latest software updates, use strong passwords with two-factor authentication, and don’t click on sketchy links—hackers will move on to your fatter, slower friend (the easier targets who don’t have the basics down.)

Try telling this to the bear-spray-equipped couple who, along with their dog, were mauled to death by a grizzly in Alberta in 2023. They got the basics right, as told by their government experts, but it wasn’t enough.

They all died.

Back in 2014, when my brother-in-law and I stumbled into the sleazy casino at the now defunct Hotel Veneto in Panama City, Panama, we weren’t worried about bears.

The casino was teeming with an army of South American working girls and Russian mafia types who all came to attention when we showed up.

“Hola, papi! Dance with me?”

“No, gracias, hermosa,” I replied, fending off her mauling, while pushing the limits of my eighth-grade Spanish. Her jacked Russian pimp rolled his eyes at my shit accent.

We only needed to survive one night in the Veneto. The next day we’d catch a local flight before heading offshore to the Hannibal Bank to hunt black marlin and giant Pacific sails.

Staying relatively sober and keeping hookers at arm’s length—a strategy as old as the profession itself—would keep us physically safe while my brother played blackjack.

However, personal cybersecurity in the Veneto was a different story. This would require more than just common sense.

At the time, I was a justifiably paranoid cybersecurity CEO. Our company provided penetration testing services to the telecommunications industry. Companies hired us to hack cell phones, apps, and the backend network infrastructure that let you text racy memes and off-color jokes with your friends.

Having unusually deep knowledge regarding the weak points of cellular networks, I took security seriously, especially when traveling abroad in sketchy environments. 

For this trip to Panama, I carried only a burner iPhone. Essentially brand new, it was configured with alternate iCloud, email, cloud file storage, and Virtual Private Network (VPN) profiles. All protected with strong passwords and two-factor authentication.

The burner functioned like my normal iPhone. But, if there was any suspicion the phone was hacked during travel, all accounts could be disabled, and the phone literally set on fire. I could throw it in the trash, and pick up my normal phone back home as if nothing happened.

I didn’t bring a laptop or smartwatch on this trip. If I had, the laptop would’ve been a similarly configured burner ready for loss, theft, and invasive border searches. As for smartwatches? They create unnecessary risk, but perhaps more importantly, they’re just not cool. Instead, I wore an old Tag Heuer Aqua Racer, a relic from my early 20s when a start-up I worked for got acquired.  

Even with a burner phone, spending time in sketchy, crowded places like the Veneto requires additional operational tactics. You can bet the air is thick with malicious signal traffic across cellular, WiFi, Bluetooth, and Near Field Communication (NFC) spectrums. And while you might not be a direct target, you can easily become collateral damage, or a target of opportunity.

Simply turning your phone off doesn’t guarantee safety from wireless attacks. Instead, keep the phone in airplane mode, but also double check that WiFi, Bluetooth, and NFC features are manually disabled. Finally, carry it in a Faraday bag that blocks all wireless signals.

A Faraday bag could save your ass if a high-tech prostitute slides up next to you at the craps table packing an NFC relay device in her purse. These sorts of tools can silently attack your phone, contactless payment cards, and even your car keys.

For Internet access, avoid hotel WiFi. I try to use a trusted VPN over cellular, but ideally from a less sketchy location. Where there are crowds, there could be StingRays or hacked femtocells spying on cell phone communication.

Consumer-grade femtocells improve cellular service when you’re not close to a cell tower. With the right know-how, you can turn a femtocell into a poor-man’s StingRay.

A StingRay is a commercially-produced spying tool used by law enforcement, intel agencies, and crooks to intercept data from your cell phone signal and, sometimes, your actual calls and texts, too.

We made it out of the Veneto with our cybersecurity, wallets, and moral integrity unscathed. And we ended up having a helluva time fishing, drinking, and enjoying a disconnected life at sea for a week.

Eleven years after our trip, however, it’s harder than ever to stay digitally safe.

Despite $13B in total federal funding for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) since 2018, and a current market value of over $60B for the U.S. cybersecurity industry, very few organizations can deliver secure and effective IT products and services.

As a result, hackers and foreign adversaries are enjoying their digital turkey shoot more than ever.

In January 2025, a handful of cybersecurity news stories quickly filtered through the news cycle.

One story covered Chinese hackers enjoying unfettered access to major U.S. cellular networks AT&T and Verizon for over a year. Hackers were able to access text messaging and call data for everyone from your grandma to prominent politicians.

Another covered U.S. Treasury Department computers and networks being hacked by China—including Treasury Secretary Janet Yellen’s very own work computer.

A third didn’t get much fanfare at all. A January 2025 Wired article detailed an investigation that indicated a StingRay (or similar device) was likely deployed to spy on cell phones at the 2024 Democratic National Convention in Chicago.

Today, digital grizzlies are everywhere, and we’re all more likely to be attacked than not. Keep your bear spray–you can’t ignore the basics–but you also need to have a large caliber handgun strapped to your chest.

SIM swap and number mirroring attacks (where bad guys hijack your phone number to access bank, email, and other critical accounts) is a very real and current threat to everyone. Talk to your carrier about the best safeguards on their network. For additional protection, consider purchasing a secondary eSIM, with a separate, anonymous phone number to use exclusively for two-factor authentication on critical accounts. If your primary is compromised, attackers still won’t have access to your most critical accounts.

Signal Messenger is a free text and voice messaging platform offering end-to-end encryption, making it a solid option for evading surveillance over the air and Internet. But don’t get complacent. Signal isn’t immune to direct attacks or malware on your device.

Want to know if malware has turned your phone into a 24/7 surveillance device? iVerify Basic is an inexpensive app that can detect if your phone has malware on it. Malware usually gets installed when you do something dumb like click on a link or visit a shady website. But, if you have powerful, well-funded adversaries—like nation states, activist groups, evil billionaires, etc—you need to be extra diligent. Malware can be installed silently on your phone through a text message you never see, or a phone call that doesn’t even ring. iVerify Basic can’t prevent these attacks—but it can help you find out after the fact. 

Elon’s Starlink Mini lets you pack your own Internet connection anywhere in the world. Convenient? Maybe. But it also means trusting Elon with your data and accepting whatever technical risks the Starlink Mini hardware might introduce.

Former Blackwater CEO Erik Prince now runs a company called Unplugged, selling a privacy-focused phone designed to keep your data out of Big Tech’s reach. While I have faith in Unplugged’s potential to limit data exposure, the phone’s support for old-school 2G & 3G cellular networks (as listed on their website) likely leaves it vulnerable to StingRay-style attacks just like regular Androids and iPhones.

So before you go dropping serious money on “secure” phones and other high-tech solutions, take a lesson from Hezbollah: know exactly what you’re getting.

When Hezbollah leadership ditched standard cell phones to evade Mossad surveillance, they were already 27 steps behind. Their bright idea? Switching to two-way pagers and walkie-talkies. The problem? Mossad had already infiltrated their supply chain, rigging the new devices with PTEN explosives and encrypted backdoor triggers.

In September of 2024, Mossad remotely triggered these devices injuring thousands, and killing 42, including civilians.

The takeaway? No tech is inherently secure. Security comes from understanding threats, minimizing exposure, and thinking like attackers.

Remember, sometimes the basics won’t cut it, and you should always be ready to shoot a charging grizzly in the face.

Talk to other members like yourself about this article in Society, our exclusive community for Field Ethos Journal subscribers.
Click here




From the FE Films Archive


See More Films from Field Ethos

You May Also Like