Knowledge Hub

Knowledge Hub

Field notes, breakdowns and lessons on OSINT, KYC, due diligence and fraud risk - written by our analysts.

Due Diligence & Background Checks

Amendment No. 10 to the Criminal Information and Rehabilitation of Offenders Law: what changed, and what it really means for employers and background checks
Due Diligence & Background Checks

Amendment No. 10 to the Criminal Information and Rehabilitation of Offenders Law: what changed, and what it really means for employers and background checks

In February 2026, Amendment No. 10 to the Criminal Information and Rehabilitation of Offenders Law, 5779-2019, was approved. At first glance it looks like a relatively technical amendment, but in practice it has significant implications for the bodies entitled to receive criminal information, for job candidates, and for the way organizations manage recruitment risks.

Read full postShow less

At the same time, the amendment sharpens an important distinction that many people are unaware of: there is a separation between criminal information held in the criminal register and protected by law, and factual, public information found in open sources (OSINT), which is not part of the criminal register at all. It is precisely this distinction that makes OSINT-based background checks a more important tool today than ever before.

What did Amendment No. 10 change? The amendment adds a new mechanism of a “notice regarding the existence of a criminal record entry,” through the new Section 16A of the law. In certain cases, instead of disclosing the full content of the criminal record, the authorized body will receive a notice stating that a criminal record entry exists, in accordance with the arrangements set out in the law. In addition, this notice was defined as part of the term “criminal information.” The purpose of the amendment is to continue strengthening the principle of rehabilitation of offenders, while balancing the public interest against a person's right to rehabilitate.

What does it mean for employers? For most employers, the basic legal situation has not changed. Even today: an ordinary employer may not require a candidate to present a criminal record; it is prohibited to require a candidate to obtain information from the police on the employer's behalf; and only bodies expressly authorized by law may receive information from the criminal register, and only to the extent set by law. In other words, even after the amendment, most employers cannot base their decision-making process on the criminal register.

But this is where the common mistake begins. Quite a few people believe that if you cannot obtain a criminal record, you are not allowed to know anything about a candidate's past. This is not the correct interpretation. The law regulates access to the criminal register and to criminal information managed by the state. It does not prohibit locating factual information that has already been lawfully published in open sources. This is a very important legal distinction.

What is the difference between a criminal record and open information? A criminal record is information managed in the criminal register of the Israel Police, and access to it is regulated by law. By contrast, information such as judgments published in legal databases, official court publications, Israel Police spokesperson announcements, State Attorney's Office announcements, publications by regulatory authorities, credible news articles, tender and disqualification notices, liquidation, receivership or legal-proceedings documents, public business information, and publications of sanctions or international blacklists does not constitute “criminal information” as defined by law merely because it describes a criminal event or a conviction. This is public information that was lawfully published, and therefore it is not part of the criminal register itself. Of course, the use of such information must also be carried out in accordance with privacy protection laws, the prohibition of defamation, and the principles of relevance, proportionality and good faith.

This is where OSINT-based background checks come into the picture. A quality background check does not try to circumvent the law and does not try to obtain confidential information. On the contrary. It operates solely through public and lawful information sources. When professional OSINT is performed, it is sometimes possible to locate substantive information that is not accessible through the criminal register, for example: convictions published in judgments, involvement in fraud affairs that received publicity, indictments published lawfully, insolvency proceedings, significant civil proceedings, problematic business relationships, conflicts of interest, ties to high-risk companies or parties, indications of fraud or impersonation, and public behavioral patterns with occupational significance. Sometimes it is precisely this kind of information that gives the employer a broader picture than the mere existence of a criminal record.

Does this replace a criminal record? No. These are two entirely different tools. The criminal record is official state information. OSINT is not a criminal register and does not claim to be one. Its purpose is to identify indications of risk from public information that can be verified, cross-referenced and professionally assessed. Therefore, in many organizations, especially in sensitive positions, OSINT checks do not replace the checks prescribed by law, but rather complement them.

The practical meaning for employers: Amendment No. 10 continues the legislator's trend of strengthening the protection of people's privacy and the principle of rehabilitation. However, it does not eliminate employers' duty of care toward their employees, their customers and the organization. Therefore, the more restricted access to official criminal information becomes, the greater the importance of conducting quality background checks based on open, lawful, relevant and verified information.

The challenge for the employer today is not to obtain more information. The challenge is to know how to distinguish between information that may not be received and public information that is permitted, and even worth considering, as part of an informed decision-making process. It is also important to remember that any use of information originating in OSINT must be carried out in accordance with all relevant legislation, including the Privacy Protection Law, the prohibition of defamation, labor laws, and the principles of equality and proportionality. The mere fact that information has been published publicly does not automatically make it relevant or legitimate for every recruitment decision.

Read the article
He had already been convicted before. That didn't stop people from handing him millions of shekels again
Due Diligence & Background Checks

He had already been convicted before. That didn't stop people from handing him millions of shekels again

This morning I read the article about Ido Samuel, who was previously convicted of fraud offenses, served a prison sentence, and after his release went back to managing money for private clients. Some of them lost significant sums.

Read full postShow less

This story is not just a story about investments, crypto or the capital market.

It is a story about a failure of due diligence.

Many people think a background check is only meant for hiring employees. In practice, it is no less important when choosing a business partner, an investment manager, a supplier, an advisor, or anyone who is supposed to be given access to money, information or assets.

In this case, some of the information was completely available in open sources: a criminal conviction for fraud offenses; a lengthy prison term; historical media coverage; legal proceedings and rulings; and business and public information that can be located through professional searching.

The problem is that finding the information is not enough. You have to know how to connect the dots.

An OSINT-based background check is not just about collecting data. The real value lies in the analysis and in understanding what the information means for the purpose of making a decision.

When you assess a person who is meant to manage your money or make financial decisions, the question is not only "Did he have a prior conviction?", but rather: Did he disclose it fully? Are there additional warning signs? Are there gaps between the public image and reality? And are there patterns that recur over the years?

Ultimately, most major frauds don't begin with technological sophistication. They begin with trust.

And before extending trust, it is worth conducting a professional background check based on open information sources, in order to make an informed decision grounded in facts rather than in personal impression or charisma.

Read the article
The biggest mistake in background checks? Attributing information to the wrong person.
Due Diligence & Background Checks

The biggest mistake in background checks? Attributing information to the wrong person.

Many people think the main challenge in background checks is finding information.

Read full postShow less

In my view, that's actually the easy part.

The real challenge begins the moment after we've found the information: are we certain it belongs to the person we're actually checking?

In a world where millions of people share similar names, use nicknames, maintain multiple digital profiles and sometimes leave only partial traces, it's very easy to fall into the trap of a "quick identification."

I often come across cases where investigators, recruiters or managers see a problematic profile online, an old article or a negative mention, and rush to draw conclusions.

But a professional background check is not an exercise in gathering information. It's an exercise in verifying identities.

Before drawing conclusions, you have to verify: is it the same person? Does the geographic location match? Does the timeline line up? Are there additional identifiers that connect the data points? And are there independent sources that confirm the link?

The greatest danger isn't missing negative information. The greatest danger is attributing negative information to the wrong person.

A mistake like that can lead to flawed hiring decisions, damage to the reputation of an innocent person, and even legal exposure.

That's why one of the most important principles in open-source intelligence (OSINT) work is: first you verify. Only then do you conclude.

That's the difference between gathering information and pursuing the truth.

Doubt Is Your Lifeline
Due Diligence & Background Checks

Doubt Is Your Lifeline

Today I came across a post about the "Venezuelan Poodle Moth" — a "poodle moth" that looks like a furry, cute creature out of an animated film.

Read full postShow less

At first it seemed completely credible. Photos, explanations, Google results, mentions on various sites including Wikipedia.

But the deeper I dug, the more I discovered that most of the story isn't grounded in anything at all. Some of the photos were wool sculptures by a Japanese artist. Others were images of entirely different species. And in practice, the only thing that truly exists is a single photograph of an unidentified moth taken in Venezuela (the image at the top left). There isn't even an official scientific recognition of such a species.

What's interesting here isn't the moth. It's the way information turns into "truth."

Today, search engines no longer rely solely on original sources. They are also fed by content created by AI, by automated summaries, by copying between sites, and by information that recycles itself again and again.

And what this means is that even if you try to do a "reverse trace" and check what the real source is, it becomes very difficult. Because at a certain point, the original source disappears, the information is copied hundreds of times, AI systems summarize erroneous information, and unverified content starts to look more credible than reality itself.

And this is precisely one of the great challenges in the world of background checks.

It isn't enough to know how to search for information. You need to know how to doubt information.

You need to understand: Who is the source? Is there any verification? Is this primary information or a copy? Is there a vested interest? And is everyone simply quoting one another?

In an era where AI can generate enormous quantities of convincing content, the ability to think critically becomes a critical professional asset.

This is exactly why professional background checks cannot rely solely on a quick Google search or on AI tools.

In the end, you still need people who know how to connect contexts, identify manipulation, understand what's missing from the picture — and above all, know when not to believe immediately something that looks credible.

When you're asked to "find the culprit" - but your capability isn't built for it
Due Diligence & Background Checks

When you're asked to "find the culprit" - but your capability isn't built for it

Recently I was approached with a very sensitive case involving the spread of fake content online.

Read full postShow less

The request was clear: locate the source of distribution, stop it quickly, and remove the content.

On the surface, this sounds like a classic open-source intelligence task. But that's exactly where the problem begins.

I want to share with you, with professional honesty, where OSINT is strong and where it simply isn't enough.

Where OSINT delivers real value: you can map how content spreads, identify groups, channels and distribution hubs, track recurring users across different platforms, and understand who is "pushing" the story forward. This provides a very important intelligence picture.

But here comes the critical limitation: you cannot identify with certainty who the person behind the account is, prove who created the content, access closed information (IP, devices, logs), or guarantee complete removal from the internet.

And when it comes to sensitive incidents, especially involving minors or privacy violations, the smallest mistake in identification can turn into a serious legal problem.

The real risk: the problem is not only technological - it is managerial. When you make promises like "we'll find who did it" and "we'll take everything off the web" without understanding the limits, that's a recipe for disappointment at best, and for damage at worst.

So what is the right thing to do in such cases? The right approach is always multidisciplinary: OSINT for mapping and understanding, DFIR for collecting evidence from devices and systems, legal support for approaching the platforms, damage control and prevention of repeated distribution, and continuous monitoring. Anyone who handles this alone, from a single angle, misses the picture.

The bottom line: open-source intelligence is a very powerful tool - but it is not magic.

Knowing what can be done is important. But knowing what cannot be done - that is what separates professional work from risk.

The problem is not a lack of information. The problem is noise
Due Diligence & Background Checks

The problem is not a lack of information. The problem is noise

Google's new capability to analyze information from the dark web using AI, and what struck me most is not the technology itself but the approach: no longer "more information", but smart filtering that understands context.

Read full postShow less

And this is exactly where many organizations fall short.

We live in an era of endless open information: forums, groups, leaks, small hints. But without real business context, without an understanding of what is relevant to a specific organization, it all turns into noise.

And this is not only in the cyber world.

It is exactly the same principle in the world of open-source intelligence.

I see it all the time: organizations think they need "more checks", "more sources", "more data". But the truth is the opposite. The real value comes from the ability to connect the dots.

For example: someone posts on a dark forum offering access to a system. They do not mention a company name. There are no clear keywords. Classic systems will not detect it. But if you understand the context, the type of system, the size of the company, the geographic location, the type of activity, suddenly it is no longer "general information". It is a very specific threat.

And now think about this in the context of insider threats.

Many times the threat does not start from within the organization. It starts outside, on the dark web, in forums, in groups. But it connects to people on the inside: an employee with access, a vendor with permissions, a candidate trying to get in.

Without a connection between external intelligence and an internal understanding of the organization, you miss the story.

And this is the truly important point: AI alone does not solve the problem. Relying on OSINT alone does not solve the problem.

Only a combination of real business context, human analysis that understands behavior, and technology that can operate at scale creates a real advantage.

Whoever keeps collecting information without understanding what is relevant to them will drown in the noise. Whoever knows how to connect the dots in time will identify the threat before it becomes an incident.

Amendment 13 to the Privacy Protection Law and international privacy regulations: Do they jeopardize the future of OSINT-based background checks?
Due Diligence & Background Checks

Amendment 13 to the Privacy Protection Law and international privacy regulations: Do they jeopardize the future of OSINT-based background checks?

In recent years, we have witnessed a significant tightening of privacy protection requirements around the world. Regulations such as GDPR in Europe, CCPA in California, PIPEDA in Canada, and additional legislation in many countries have created a new standard for managing personal information. In Israel, Amendment 13 to the Privacy Protection Law represents another significant step in this direction.

Read full postShow less

For organizations that conduct background checks based on open-source intelligence (OSINT), the question sometimes arises as to whether these regulations will make such checks impossible or undermine their effectiveness.

The professional answer is no.

Regulation changes the way in which the check is performed, but it does not eliminate the need for it, and it does not prevent the conduct of high-quality checks when they are carried out in a professional, lawful, and proportionate manner.

What is Amendment 13 to the Privacy Protection Law? Amendment 13 is intended to strengthen the enforcement capabilities of the Privacy Protection Authority and to align Israeli law with modern international standards. Among other things, the amendment grants the Privacy Protection Authority broader enforcement powers, significantly increases the level of financial sanctions, requires organizations to manage personal information more responsibly, increases the accountability of database owners and data processors, and strengthens the rights of data subjects. In practice, the implication for organizations is that violating privacy provisions may become a significant business, legal, and reputational risk.

How do privacy regulations affect background checks? The most common mistake is to think that privacy legislation prohibits the collection of information. In fact, most regulations around the world do not impose a blanket prohibition on collecting personal information. They require that collection be carried out on the basis of clear principles: a legitimate purpose, proportionality, transparency, data minimization, data security, and limited retention over time. In other words, the question is not "is it permitted to collect information?" but rather "what information is collected, why is it collected, and how is it used?".

The use of OSINT is not exempt from privacy laws. There is another mistaken perception according to which information published online is "free to use". The fact that information is found online does not negate the fact that it is personal information. For example: a LinkedIn profile, social media posts, news articles, business records, and forum content. All of these may be considered personal information and subject to privacy laws. Therefore, an organization conducting background checks cannot rely on the claim that the information was merely "public".

How can high-quality background checks be conducted in compliance with regulation?

Defining a clear purpose: A background check should be directly related to the risk that the organization seeks to mitigate. For example: detecting conflicts of interest, identifying past fraud, detecting behaviors that may harm the organization, examining reputational risks, and identifying problematic business relationships. Collecting information unrelated to this purpose may be considered a deviation from the principle of proportionality.

Collecting only relevant information: A professional check is not measured by the quantity of information collected but by the quality of the information. In many cases, an excess of information actually makes decision-making more difficult. The correct approach is to focus on information of genuine business value and to link it to the required risk assessment.

Using human analysts: One of the central problems in automated checks is the massive collection of information without context. A professional analyst knows how to distinguish between fact and opinion, cross-reference sources, identify errors in identification, understand cultural and linguistic contexts, and exercise judgment. Precisely in a world of stringent regulation, the value of the human element grows.

Transparency and consent when required: In recruitment processes or certain engagements, it is recommended to obtain explicit consent to conduct a background check. Even when the law does not fully require this, clear consent strengthens the legitimacy of the process and reduces legal risks.

Deletion of information and limited retention: One of the fundamental principles in most privacy regulations is limiting the duration of retention. After completing the check and making the business decision, one should examine whether there is justification for continuing to retain the information, whether the reports can be deleted, and whether only partial retention of the data is necessary. This approach reduces data security risks and lowers regulatory exposure.

The advantage of OSINT precisely in the age of privacy: Paradoxically, privacy regulations actually strengthen the standing of high-quality OSINT checks. In the past, many organizations relied on collecting information from numerous databases, some of which were legally problematic. Today, the emphasis is shifting to information gathered from open, lawful, documented, and verifiable sources. When the check is conducted professionally, it is possible to reach significant insights even without access to private or confidential information. In many cases, it is precisely the open information that provides the most important indications regarding behavior, business relationships, reputational risks, or conflicts of interest.

The key is Governance, not prohibition: The central message of Amendment 13 and of privacy regulations around the world is not "do not conduct background checks". The message is: conduct them responsibly. Organizations that build orderly work processes, adhere to proportionality, operate control mechanisms, and use professional analysts will be able to continue conducting highly effective background checks even under stringent regulation.

In fact, in a world where insider threats, fraud, AI-based impersonation, and conflicts of interest are becoming more complex, the need for professional background checks is only growing.

The new challenge is not to find information. The challenge is to know how to collect the right information, use it lawfully, and derive from it insights of genuine value for decision-making.

Insider Threats & Organizational Risk

The brilliant startup that can't work because it has no security clearance
Insider Threats & Organizational Risk

The brilliant startup that can't work because it has no security clearance

In recent years I've been hearing more and more defense organizations talk about their desire to work with small, innovative and agile companies. Everyone wants innovation. Everyone wants creative solutions. But in reality, quite a few companies never even make it to the starting line.

Read full postShow less

An interesting article published recently in the UK exposed one of the biggest challenges in the defense world: the security clearance process itself.

On the one hand, there's no debate about the importance of background checks, security clearances and protecting sensitive information. These are essential mechanisms designed to safeguard national interests, sensitive technologies and critical supply chains.

On the other hand, when the process of obtaining a clearance drags on for many months and sometimes more than a year, an absurd situation arises: the company can't get a contract because it has no clearance, but it also can't get a clearance because it has no contract.

This dilemma isn't unique to the UK. Anywhere that complex screening processes and trustworthiness vetting exist, the challenge is finding the balance between security and agility.

As someone who has worked for many years in the field of background checks and trustworthiness vetting, I believe the goal is not to lower the requirements. On the contrary.

The goal is to create smarter, faster and risk-management-based processes.

Not every supplier represents the same risk. Not every employee needs the same level of vetting. And not every process has to drag on for many months.

When risks are managed properly, you can both maintain security and enable innovation and growth.

The real challenge isn't to perform more checks. The challenge is to perform the right checks, at the right time, and in a way that lets the organization move forward instead of getting stuck.

Read the article
Would you let someone who stayed silent in the face of murder treat you?
Insider Threats & Organizational Risk

Would you let someone who stayed silent in the face of murder treat you?

I read the article about Lihi Darnell (Gluzman), the state's witness in the Asaf Steierman murder case, who is now undergoing training in clinical psychology. Beyond the legal and public debate, this case raises in my eyes a far broader professional question:

Read full postShow less

How deeply do organizations vet the people in whose hands they place power, influence and trust?

In this case it's a therapeutic profession. In other settings it's a CFO, a security officer, a procurement manager, an IT person with broad permissions, or an employee exposed to sensitive information.

One of the central lessons from the world of insider threats is that not every risk is measured by a criminal record or a conviction. Sometimes it's precisely behavioral patterns, decision-making under pressure, moral judgment and reactions to extreme events that should set off warning lights.

Many organizations focus on the question "Does this employee have a criminal record?", but often the more important question is: "Is there material information about their past conduct that would make us think twice before granting them a sensitive role?"

In this specific case, it isn't a legal question but a question of risk management.

When a person is set to hold a position of trust, to influence other people or to gain access to sensitive resources, it's worth examining several layers: a history of decision-making in extreme situations; involvement in events of public or moral significance; gaps between their current image and material past events; an up-to-date rather than one-off risk assessment; and oversight and control mechanisms over time.

It's also important to remember that insider threats don't arise solely from malicious intent. Sometimes they stem from poor judgment, from withholding information, from a lack of accountability, or from value conflicts that weren't identified in time.

Ultimately, every organization has to decide where the line lies between personal rehabilitation and professional responsibility. It's a complex decision, but it must be made out of informed risk management and not out of the assumption that if there's no legal impediment, there's no risk either.

Read the article
He looked like the perfect employee, until he started to dismantle the organization.
Insider Threats & Organizational Risk

He looked like the perfect employee, until he started to dismantle the organization.

One of the most disturbing books we have read recently in the field of organizational behavior is "Snakes in Suits: When Psychopaths Go to Work" by Paul Babiak and Robert Hare.

Read full postShow less

The book deals with the kind of people that most organizations don't really know how to identify in time. Not violent criminals. Not extreme characters from movies. Rather charismatic, impressive, sharp people, with an extraordinary ability to make others believe in them.

It is precisely because of this that they are dangerous.

The authors describe how an organizational psychopath manages to fit into an organization, advance quickly, accumulate power and influence, and along the way leave behind enormous damage: the breaking up of teams, the creation of conflicts, political manipulations, intimidation of employees, harm to trust, the creation of a toxic culture, and at times also fraud and abuse of authority.

What is particularly interesting is that the book explains that the problem is not only with the person himself. At times the organization also contributes to it without realizing it.

Organizations that sanctify charisma, fast results, aggressiveness, achievement at any cost, and internal politics, may mistakenly identify psychopathic behavior as "leadership".

One of the important things in the book is the description of the three stages in which an organizational psychopath operates.

In the first stage he studies the system: who is strong, who is weak, who is influential, who is threatened, who has access to power and information.

In the second stage the manipulation begins: flattery, the creation of false trust, adapting his personality to each individual, sophisticated lies, and quiet harm to rivals.

In the third stage comes the abandonment: when the person is no longer useful, he is thrown aside. Sometimes also with deliberate harm to his reputation.

The most important part for me is the understanding that it is not always possible to identify such people through charisma or first impression. On the contrary.

In many cases they are calm under pressure, know how to speak convincingly, project self-confidence, know how to "read people", and imitate empathy excellently.

And therefore in the world of Insider Threats, employee recruitment, and reliability assessment, one must not rely only on intuition or a "gut feeling".

One must examine: behavioral consistency, gaps between words and actions, patterns of manipulation, attitude toward people without power, history of conflicts, and repeated use of victims, accusations, and politics.

This book is an excellent reminder that the most dangerous threats in an organization don't always come from outside.

Sometimes they are sitting in the boardroom.

The most dangerous manager in the organization? It isn't always the one who steals information
Insider Threats & Organizational Risk

The most dangerous manager in the organization? It isn't always the one who steals information

I meet quite a few managers who look at the 'insider threat' only through the prism of information theft, industrial espionage or financial fraud. But there is another kind of insider threat, far quieter, that usually does not appear in security reports.

Read full postShow less

The abuser.

That manager who belittles employees, humiliates them in front of others, instills fear, erodes them psychologically, creates anxiety and dismantles self-confidence over time.

Studies have already shown that workplace abuse does not stay on the emotional level alone. It harms cognitive ability, decision-making, memory, concentration and professional functioning. An employee under ongoing psychological terror begins to make more mistakes, to withdraw, to lose motivation and sometimes even to develop anger toward the organization itself.

And this is exactly where the connection to the world of insider threats begins.

Because sometimes the 'predator' himself is the insider threat. And sometimes he creates a new insider threat: the employee he has harmed.

An employee who experiences ongoing humiliation can turn into a bitter, indifferent, vengeful or uncommitted person. In certain cases this manifests as quiet quitting, leakage of information, harm to processes, or simply a functional collapse that damages the organization from within.

This is exactly why I think it is not enough to check only the integrity, past or reliability of candidates. You also need to know how to identify predatory patterns.

Yes, there are ways to identify them. You can detect early signs already at the recruitment stage: extreme patterns of control, manipulativeness, lack of empathy, destructive interpersonal relations over time, recurring burnout patterns in the teams they have managed, and a work environment that produces fear instead of trust.

And if that person is already inside the organization, you must monitor such behaviors exactly as you monitor other security anomalies. Because their damage does not always appear immediately, but when it explodes, the organizational cost is enormous.

I think that in the near future organizations will understand that workplace abuse is not only an issue of HR or employee well-being. It is an issue of organizational security.

Phishing doesn't only steal passwords. Sometimes it steals sensitive technology.
Insider Threats & Organizational Risk

Phishing doesn't only steal passwords. Sometimes it steals sensitive technology.

The story published by NASA's Office of Inspector General should worry every organization that holds sensitive knowledge, code, software, engineering designs or valuable business information.

Read full postShow less

According to the publication, a Chinese citizen named Song Wu posed for years as American engineers, researchers and professors, and approached NASA employees, academic researchers, military personnel and private companies. His goal was not to obtain a password to an account. He asked for something far simpler and far more dangerous: copies of software, source code and sensitive engineering tools that could be used for aeronautical design and the development of weapons systems.

And that is exactly the point.

In many organizations, when people hear the word 'phishing', they immediately think of an email with a suspicious link, a fake website or a request to enter a password.

But in more sophisticated cases, phishing does not look like a cyberattack. It looks like a legitimate professional request from a familiar person. 'Please send me the code'. 'I need the latest version of the software'. 'Send me the file, I'm working on it with the team'.

The victim doesn't feel they are falling for an attack. They feel they are helping a colleague.

And that is precisely the danger.

The professional mistake I see again and again is that organizations treat this threat only as a technological problem. But in this case, the central weakness was not only in the system. It was in human trust, in the work culture, and in the absence of a clear mechanism that requires stopping and checking before sensitive information goes out.

As I see it, there are several important lessons here.

Not every request that comes from a 'familiar' person really comes from them.

Not every sharing of information between colleagues is an innocent act, especially when it involves code, software, plans, data, models or infrastructure.

Employees need to know how to recognize not only suspicious links, but also unusual requests: repeated requests for the same software, no explanation of why the information is needed, a sudden change in the payment or transfer method, the use of unconventional channels, or pressure to hand over material without an orderly process.

And most importantly: in a serious organization, an employee should not decide alone whether sensitive material may be transferred to another party, even if that party appears familiar, senior or professional.

You need a procedure. You need identity verification. You need a permissions check. You need an understanding of the limits of regulation, export, confidentiality and intellectual property. And you need a culture in which stopping to check is not seen as bureaucracy, but as part of professional responsibility.

The NASA story is a sharp reminder that an insider threat does not always begin with a malicious employee. Sometimes it begins with a good, professional employee who wants to help, but doesn't realize they are being manipulated.

And that may be one of the most dangerous threats of all: a human Trojan horse that doesn't know it is one.

Read the article

Behavioral Profiling & Vetting

The body betrays long before the words break
Behavioral Profiling & Vetting

The body betrays long before the words break

One of the most fascinating topics in the world of human behavior is the Embodiment Effect.

Read full postShow less

The core idea is simple but very profound: our body does not merely "express" emotions and thoughts, it also influences them, and sometimes even reveals them before the brain manages to control the message.

For years, body language was viewed as an "add-on" to communication. Today it is already clear that it is part of the thinking system itself. Sitting posture, hand placement, breathing rate, head movements, distance from the camera, use of space, micro-expressions, vocal changes, and even the manner of typing are all part of a behavioral information system.

In business profiling this is critical.

When we conduct a reliability assessment or try to identify the potential for an internal threat within an organization, we are not looking only for a "lie." It is far more complex. We are looking for incongruence.

The Embodiment Effect makes it possible to understand when physical behavior is not synchronized with the narrative a person is trying to produce. For example: a candidate who speaks confidently but whose body is in continuous defensiveness; an employee who declares commitment to the organization but reacts physically with stress when issues of authority, control, or loyalty arise; a manager who presents stability but shows abnormal signs of arousal around financial questions or internal conflicts; a remote candidate who produces "too perfect" eye contact, with an artificial response pace and communication patterns that suggest the use of external aids or real-time AI.

And here the new challenge enters: remote assessment.

In the era of hybrid work and Zoom interviews, some people think it is possible to "hide" behavior through a screen. In practice, the opposite sometimes happens.

The camera reduces background noise and forces us to focus on micro-behaviors: response delays, tone changes, eye darting, over-adjustments, unnatural listening, disconnects between voice and expression, motor freezing, and excessive use of calculated gestures.

Precisely in a remote environment, when you know what to look for, you can identify very significant indications of reliability, stress, concealment, manipulation, or internal conflict.

But it is important to state the professional truth: there is no "magic sign" that proves a lie. This is one of the biggest mistakes in the field.

Professional profiling is not built on myths of "touching the nose = lying." It is built on creating a behavioral baseline, identifying anomalies, cross-referencing information sources, analyzing context, understanding motivations, and reading dynamics rather than just isolated signs.

The Embodiment Effect is especially important in identifying internal threats within organizations, because people can control their words far more than their bodies. And in situations of stress, conflicting loyalties, a sense of threat, or concealment, the body almost always "leaks" information.

The future of the world of business profiling will not be based solely on technology nor solely on human intuition. It will be a combination of deep behavioral understanding, digital analysis, the use of OSINT, anomaly detection, and the human ability to read people even through a screen.

Because in the end, even in the era of AI, a person still leaves a behavioral signature.

Not every toxic employee shouts. Some just smile right in the interview.
Behavioral Profiling & Vetting

Not every toxic employee shouts. Some just smile right in the interview.

One of the most troubling topics in the world of personality assessment is 'the Dark Triad'.

Read full postShow less

These are three personality traits that may initially look like self-confidence, charisma, or assertiveness, but within an organization they can turn into a real internal threat: narcissism, which involves a need for admiration, a sense of superiority, and difficulty accepting criticism; manipulativeness (Machiavellianism), which means using people as tools to achieve goals, without much guilt along the way; and functional psychopathy, which involves extreme coolness, a lack of empathy, and the ability to carry out harmful actions without conscience.

The interesting part is that people with such traits don't always fail job interviews. On the contrary.

More than once they are very impressive. They know how to talk. They know how to sell themselves. They know how to identify other people's weaknesses. And they know exactly which persona the organization wants to see in front of them.

That's why I think one of the biggest challenges today in the world of insider threats is not only identifying a 'problematic past', but understanding patterns of personality and behavior that may turn into an organizational risk in the future.

This can manifest as leaking information, deliberately harming the organization, manipulating employees, creating a toxic culture, or simply making dangerous decisions without any empathy for the consequences.

It's clear that not every person with Dark Triad traits is a criminal or an insider threat. But when you combine access to sensitive information, pressure, ego, lack of oversight, and manipulative ability, you get a combination that managers must be aware of.

And this is exactly where the value of in-depth assessment, proper questioning, intelligence from open information sources, and identifying red flags before harm occurs comes into play.

Because in the end, the most dangerous threat in an organization is usually not the one who looks dangerous. It's the one who knows how to look perfect.

Culture shapes the person standing in front of us
Behavioral Profiling & Vetting

Culture shapes the person standing in front of us

When we assess a person, it is very easy to project our own value system onto them. What looks to us like suspicious, inconsistent, or even problematic behavior can, in another context, be perfectly normal.

Read full postShow less

For example, there are cultures in which avoiding eye contact is a sign of respect. For others, it immediately raises questions. There are places where direct communication is seen as positive, while elsewhere it is perceived as rude.

And this is where biases come into play.

When we are not aware of them, we are not really analyzing the person. We are analyzing the gap between them and us.

In business profiling, this is especially critical. Decisions are made about people: candidates, partners, suppliers. An error in interpretation can lead to missing out on an excellent person, or worse, to failing to identify a real risk.

So what do we learn from this?

First of all, professional humility. Understanding that not everything that seems right to us truly is.

Second, context. Always asking: where does this person come from? Does the behavior fit with the culture they come from?

And finally, the right combination of analytical tools and human understanding. Without this, there is no real objectivity.

Anyone who works with people must understand cultures. Otherwise, they are simply guessing.

Is Enshittification a bad thing? Not always.
Behavioral Profiling & Vetting

Is Enshittification a bad thing? Not always.

Enshittification = the extreme degradation of something into a worse version of itself.

Read full postShow less

I remember a time when LinkedIn was a very "clean" place. Professional, calculated, a little sterile. Everyone wrote the same things, everyone sounded the same, and there was almost nothing there that truly revealed who the person behind the profile really was.

And then the enshittification began.

More personal posts. More politics. More extreme opinions. More provocations that gain exposure because the algorithm loves noise.

For anyone looking for a purely professional platform, this looks like deterioration. And to a large extent, it really is.

But from my perspective, something interesting happened here.

It is precisely this "out of place" content that begins to tell the real story.

When I check someone as part of a background check from open sources, I'm not just looking at what they do. I'm looking at how they think. How they react. What sets them off. Where their boundaries are.

And these things almost never showed up on the old LinkedIn.

Today they are there. In abundance.

A political post written without filters, an aggressive response to a professional discussion, a choice to join a provocative trend, these are no longer "noise" to me. They are signals.

What was once a barren wasteland in terms of understanding personality has become a gold mine of behavioral indicators.

So yes, LinkedIn has changed. And maybe not for the better for those looking only for professionalism.

But for those who understand how to read between the lines, it's a platform that tells far more truth than it did before.

AI, Deepfakes & Synthetic Fraud

When the face on the screen is real. The person behind it isn't.
AI, Deepfakes & Synthetic Fraud

When the face on the screen is real. The person behind it isn't.

This past week, a particularly troubling case came to light in Israel that shows how the world of fraud is being transformed by artificial intelligence.

Read full postShow less

According to the suspicions, a 20-year-old managed to create “synthetic identities” of Israeli citizens using photos and personal details obtained from breached databases. With AI tools he animated the photos, produced videos that looked entirely authentic, and used them to open bank accounts, order credit cards and carry out financial transactions in the names of people who had no idea it was happening.

According to the investigation, many dozens of victims have already been identified, and it is suspected that hundreds of citizens were harmed by this activity.

What troubles me most about this case is not only the scale of the fraud, but the proof that the identification methods we have relied on for years are no longer sufficient on their own.

A photo of an ID card, a selfie, a short video, remote verification — until recently all of these were considered strong layers of protection. Today, in the right hands and with advanced AI tools, they can be faked to a level that makes it very hard for the human eye to detect the deception.

This challenge no longer belongs only to banks. It is relevant to any organization that hires employees remotely, approves suppliers, opens customer accounts, grants access permissions or runs digital identification processes.

The question is no longer whether an identity can be faked, but whether your control system is able to detect the forgery in real time.

In recent years I have seen more and more cases in which the line between a real person and a figure created by AI is becoming blurred. Organizations must adapt their verification mechanisms to the new reality, and not rely solely on methods built for a world that existed before artificial intelligence.

Alongside the threat, there are now advanced solutions that make it possible to spot signs of AI forgeries, detect anomalies in the identification process and verify identities in real time.

We have advanced technological solutions to address these challenges in real time. Feel free to reach out to me for details.

Read the article
How do we know if what we're seeing is really happening or really happened?
AI, Deepfakes & Synthetic Fraud

How do we know if what we're seeing is really happening or really happened?

This is no longer a philosophical question. It's a business question, a security question and a management question.

Read full postShow less

The article in Science by Prof. Hany Farid, one of the world's leading experts on detecting digital manipulation, lays out a reality we all have to internalize: a deepfake no longer looks like a technological toy. It looks real, sounds real, spreads fast, and shapes the way people make decisions.

And the big problem isn't just that the fakes are getting better. The bigger problem is that trust is being eroded.

When a manager receives a video. When the HR department runs an online interview. When a company gets approached by an investor, a candidate, a vendor or a business partner. When an incriminating video starts circulating online. When a familiar voice asks for urgent action.

The first question can no longer be: "Does this look real?" Because today, plenty of fake things look completely real.

The right question is: "How do we check this professionally before we act?"

What I especially liked in the article is Farid's investigative approach. He doesn't settle for an automated tool that says "90% fake" or "70% real." He examines physics, motion, shadows, reflections, angles, lip-sync to voice, consistency between frames, and the broader context.

And that's exactly the point. With deepfakes there is no single magic solution. You need a combination of technology, investigative experience, an understanding of human behavior, an understanding of the digital arena, and the ability to ask the right questions.

In the business world this is especially critical. Because deepfakes don't threaten only politicians or celebrities. They threaten hiring processes, background checks, trust between organizations, fraud protection, digital identity, and the ability to understand who is really standing in front of us.

An online job interview can be faked. A professional profile can be well built yet not genuine. A manager's voice can be cloned. A video can be edited. An image can be generated from scratch. A document can look authentic while being part of a broad deception scheme.

That's why organizations can't stay at the stage of "it looks real to me." They need a verification capability. Not out of panic. Not out of excessive suspicion. But out of responsibility.

Anyone who recruits employees for sensitive roles, vets business partners, verifies identities, handles fraud incidents or deals with suspicious content online must add to their desk the ability to deal with deepfakes too. Especially when everything happens online.

If you're dealing with a suspected deepfake, a fake identity, a suspicious interview, problematic digital content or an incident where it's unclear what's real and what's not, you're welcome to reach out to us.

We have innovative, groundbreaking solutions for dealing with deepfakes, including in online environments, combining advanced technology with professional human analysis.

Read the article
AI, Deepfakes & Synthetic Fraud

If a face can be faked at the click of a button, how do we know who is really sitting across from us?

One of the greatest challenges in the world of modern recruitment is the fact that we no longer truly know whether the person appearing on screen is who they claim to be.

Read full postShow less

AI tools are now available to anyone and make it possible to alter appearance, voice and even an entire identity in real time. What was once the domain of intelligence agencies or film studios has become an accessible tool that can be run from a home computer.

The implication for organizations is clear: a video interview is no longer a sufficient means of verifying identity.

In recent years, the world has seen quite a few cases of candidates impersonating other people, using fabricated identities or concealing material information during the recruitment process. As Deep Fake technologies become more convincing, the risk grows accordingly.

This is precisely why background checks based on open-source intelligence (OSINT) are becoming an increasingly significant part of recruitment processes, especially for sensitive roles.

When you examine a candidate's digital footprint over time, cross-reference different sources of information and verify the consistency between the presented identity and the real digital presence, you can identify gaps and warning signs that would never surface during an online interview.

The technology that makes it possible to hide the truth is advancing rapidly.

The challenge for organizations is to ensure that the tools for revealing the truth advance at the same pace.