This Newsletter is Sponsored by
Weekly Intelligence for a Digital World
INTELLIGENCE BRIEF // DECLASSIFIED
Briefing No. 100!
August 18, 2026Dear Readers,
On September 19, 2024, I hit “publish” on the first edition of Spies, Lies & Cybercrime. It went to 69 people. Nearly two years later, more than 4,500 of you are reading this one.
One hundred issues.
I had to stop for a moment when I realized it had been almost two years. Somehow, Tuesdays accumulated. Stories became investigations. Investigations became lessons. And a little newsletter about spies, lies, hackers, cybercriminals and the strange new world technology is creating became a community of people who wanted to understand these threats rather than simply fear them. My fellow spy hunters.
When I wrote that first issue, I was also deep into editing my latest book. At the time, the manuscript had a different name: Invisible Threat. My editor thought the title was too generic. He was right. When the team at William Morrow and I started brainstorming alternatives, I pointed them toward the newsletter I had just begun writing: Spies, Lies & Cybercrime. They loved it.
On October 7, 2025, Spies, Lies, and Cybercrime was published by HarperCollins/William Morrow. Issue 55 celebrated publication day. The newsletter had given its name to the book, and the book gave the newsletter an even larger mission.
But the story really began long before either existed.
Sometimes I think about a much younger version of myself sitting in a lonely office on the ninth floor of FBI Headquarters. Room 9930. I was an undercover operative who had spent his career learning how to disappear. No public profile. No social media. I skipped the entire MySpace era, which in retrospect may have been my finest counterintelligence decision.
My job was to help catch Robert Hanssen, an FBI agent who had spent more than two decades spying for Moscow. At the time, the investigation felt enormous. Hanssen had compromised some of America’s most closely guarded secrets. People had died. Operations had been destroyed. Our national security had been badly damaged. And somehow this young undercover operative was supposed to get close enough to him to help prove it.
There were days when I was stressed, exhausted and lost inside the magnitude of it. I wish I could go back to Room 9930 and tell that younger version of myself something: One day, all of this will matter in ways you cannot possibly imagine.
One day, you will write two bestselling books about counterintelligence and security. You will travel the world talking about spies and cybercrime. And somehow, impossibly, you will publish a newsletter read by thousands of people who have decided to become spy hunters themselves.
He wouldn’t have believed a word of it. Frankly, I’m not sure I do either.
But here we are. And you made that possible.
So for Issue 100, I don’t want to simply look backward and celebrate where we’ve been. I want to do what intelligence officers are supposed to do after a long operation. I want to debrief it. What did we learn? What did we get wrong? What changed? What stayed the same? And, most importantly, what is coming next?
After one hundred briefings, I think I finally know the answer.
100 BRIEFINGS. ONE WARNING
What two years of spies, scams, cyberattacks and artificial intelligence taught me about the oldest vulnerability on earth.

Over the past two years, we have investigated spies, ransomware gangs, romance scammers, deepfakes, fake job applicants, artificial intelligence, hackers attacking critical infrastructure, insider threats, sextortionists, hostile governments, robots, surveillance systems and more ways to steal a password than any reasonable civilization should have invented.
At first glance, these seem like completely different threats. They aren’t.
The strangest thing I learned from writing one hundred issues is that I didn’t discover one hundred different problems. I kept finding the same problem wearing different clothes.
Somebody believes something that isn’t true. Then they act on it. And the door opens.
That was true when I hunted Robert Hanssen. It is true when a victim sends money to someone they believe loves them. It is true when a company hires an employee who isn’t who he claims to be. It is true when an executive hears the familiar voice of a CEO generated by artificial intelligence. It is true when an employee clicks a link because an email appears to come from Microsoft, their bank, their boss or the FBI.
Technology has transformed espionage and cybercrime beyond recognition. The first move hasn’t changed much at all.
The lie comes first.
After one hundred issues, here are the five lessons I think matter most.
CASE FILE 01: TRUST REMAINS THE ORIGINAL VULNERABILITY
Robert Hanssen didn’t need to hack his way into the FBI. We gave him access. He had a badge. A security clearance. A career. Colleagues. Authority. He looked exactly like what he was supposed to look like: an FBI agent entrusted with America’s secrets.
Behind that identity was something else entirely.
For more than two decades, Hanssen exploited one of the most dangerous assumptions any organization can make: that someone who has already been trusted no longer needs to be questioned.
Technology has changed enormously since Hanssen began spying. Human nature hasn’t. Organizations spend fortunes building walls around their information. Firewalls. Endpoint security. Identity management. Encryption. Zero-trust architecture. All necessary. But the most dangerous person may already be inside the wall.
That lesson has appeared again and again throughout these one hundred issues. The insider may be a spy, a disgruntled employee, a compromised contractor or simply someone whose credentials have been stolen. The common denominator is access.
Hanssen taught me something I have never forgotten: Trust is valuable precisely because it can be exploited.
That doesn’t mean we should become paranoid. It means trust should never become permanent.
CASE FILE 02: CYBERCRIME BECAME PERSONAL
For years, cybersecurity was marketed as an IT problem. Install antivirus software. Update the firewall. Change your password.
Meanwhile, cybercriminals figured out something much more important: Why attack the computer when you can attack the person using it?
The scams we have investigated in this newsletter increasingly target emotion before technology: fear, love, greed, loneliness, urgency and authority. A romance scammer doesn’t begin by asking for money. The scammer builds a relationship. An investment fraudster doesn’t begin with theft. The fraudster creates confidence. A phishing attack doesn’t begin with malware. It begins with a reason to click.
That is why stories such as The Vacation Trap have resonated so strongly with readers. The danger isn’t hiding in some distant server farm. It is sitting beside us at the airport, arriving in our inbox, appearing in a text message or sliding into our social feeds.
The battlefield moved into everyday life. And that means cybersecurity can no longer belong only to cybersecurity professionals. Everyone needs a little counterintelligence training now.
CASE FILE 03: IDENTITY BECAME HACKABLE
This may be the development that worries me most.
We once authenticated people by looking at them. Then we trusted their voice. Then video. Then identification documents, résumés, references and professional profiles.
Artificial intelligence is steadily eroding every one of those assumptions.
We have already seen North Korean operatives use stolen identities and remote-work infrastructure to obtain jobs inside Western companies. We have seen alleged Chinese intelligence operations create convincing consulting businesses designed to recruit people with access to sensitive information. We have seen AI-generated photographs, synthetic voices and increasingly convincing deepfakes.
Consider what that means. The résumé can be fake. The photograph can be fake. The references can be fake. The voice can be fake. The person on the video call can be fake. And all of them can agree with one another.
That changes the fundamental problem of security. For most of human history, seeing was believing. We are entering an era in which seeing may simply mean somebody rendered the image correctly.
Identity is becoming something that must be proven rather than perceived. That is an enormous change.
CASE FILE 04: CYBER ESCAPED THE COMPUTER
For a long time, the consequences of cybercrime were mostly invisible. A database disappeared. A credit card number was stolen. A computer stopped working.
That era is ending.
The systems running modern civilization are connected to networks: water treatment, electricity, hospitals, transportation, telecommunications, manufacturing, emergency services and logistics. Which means the consequences of a cyberattack can increasingly become physical.
A hacked water system is not a computer problem. A disabled hospital is not an IT problem. A compromised power grid is not a data problem. They are public-safety problems.
Last week’s investigation into hackers targeting water infrastructure illustrated where this is heading. The digital world and physical world are merging, and our adversaries understand the implications perfectly well.
A cyberattack no longer needs to steal anything to cause enormous damage. Sometimes the objective is simply to make something stop working. That distinction will become increasingly important during the next hundred issues.
CASE FILE 05: AI DIDN’T INVENT DECEPTION. IT INDUSTRIALIZED IT.
Artificial intelligence receives more hype than almost any technology I have watched during my career. Some of it is deserved. Some of it is marketing. And some of it sounds suspiciously like someone watched The Terminator after three espressos.
But beneath the noise is a profound change. AI dramatically lowers the cost of deception.
A criminal once needed time to research a victim. AI can help do it in seconds. A spy once needed to build a convincing persona. AI can help generate one. A scammer once needed language skills. AI can translate, rewrite and personalize. An attacker once needed to choose targets carefully. Automation makes it possible to attack thousands or millions.
AI did not invent manipulation. It gave manipulation a factory.
That is why I believe the most consequential effect of artificial intelligence on cybercrime may not be some autonomous super-hacker breaking into the Pentagon. It may be something far simpler.
AI makes lying cheap. And cheap things scale.
THE ONE WARNING
Put those five lessons together and a pattern emerges: Hanssen. Romance scammers. Fake employees. Phishing attacks. Deepfakes. Hostile intelligence services. Ransomware crews.
They use different technology. They pursue different objectives. They operate at wildly different levels of sophistication. But their attack chains often begin in remarkably similar ways.
First, manufacture belief. Convince the target that the email is legitimate, the caller is real, the employee exists, the investment is safe, the lover is sincere or the FBI agent is loyal.
Then, gain trust. Trust lowers defenses. It creates familiarity. It turns extraordinary requests into reasonable ones.
Then, acquire access. A password. A wire transfer. A security clearance. A remote connection. A confidential document. A click.
Finally, create leverage. Money can be stolen. Secrets can be extracted. Systems can be disrupted. People can be blackmailed. Infrastructure can be damaged.
Manufacture belief. Gain trust. Acquire access. Create leverage.
That is the attack chain I keep seeing.
Which means the greatest cybersecurity tool ever invented may also be one of the least sophisticated: independent verification.
The adversary wants you to move quickly through the moment when belief becomes action. Our job is to resist the urge to react to the adversary. Instead, act like a spy hunter.
Know Someone Who’d Enjoy This?
If someone forwarded you this newsletter, join more than 4,500 readers every Tuesday for practical lessons from the worlds of espionage, cybercrime, artificial intelligence, and the human stories behind them.
THE NEXT 100

If the first hundred issues taught me anything, it is that predictions about technology should be made carefully. Anyone who claims to know exactly what the next decade will look like is probably selling something.
But counterintelligence is partly the business of identifying trajectories. And there are five I intend to watch closely as we head toward Issue 200.
Synthetic identity will become ordinary
Fake identities are going to become dramatically more convincing. Soon we will encounter situations in which the photograph, voice, résumé, references, documents and video call all support the same identity. And the identity may still be false.
Organizations that continue authenticating people through appearance and familiarity are going to get burned.
Today’s AI mostly gives us answers. Tomorrow’s AI will increasingly take actions. Agents will schedule meetings, access systems, purchase products, move information, write software and make decisions on our behalf.
That changes the security question. We will stop asking only, “What can this AI know?” We will increasingly ask, “What is this AI allowed to do?”
Permission may become one of the defining cybersecurity battles of the AI era.
Cyberattacks will increasingly produce physical consequences
Our infrastructure is becoming more connected, not less. That creates enormous efficiencies. It also creates enormous dependencies.
Water, electricity, transportation, healthcare, manufacturing, communications and logistics will remain attractive targets because disruption creates leverage far beyond the compromised computer.
The boundary between cybersecurity and physical security is disappearing. Our defenses need to catch up.
Espionage and cybercrime will continue to converge
The old categories are getting messy. Nation-states use contractors. Criminals sell access. Ransomware crews exploit vulnerabilities intelligence services also want. Cybercriminals steal information that governments value. Governments use techniques pioneered by criminals.
The next generation of threats may not fit neatly into boxes marked “spy,” “hacker” or “criminal.” The ecosystem is blending. We will need to follow behavior and evidence rather than labels.
TO MY FELLOW SPY HUNTERS
One hundred issues ago, there were 69 of you. Today there are more than 4,500.
Some of you have been here almost two years. Others arrived last Tuesday. Together, you have read my stories about spies, hackers, criminals, artificial intelligence, surveillance, scams and the strange intersection between human nature and technology.
You’ve sent me your own stories. You’ve challenged my conclusions. You’ve forwarded these briefings to friends, colleagues, employees and family members. You’ve stopped me at speaking events and told me about an issue that made you change a password, question a text message, talk to your children about online safety or look at an email differently.
Those moments matter to me more than the subscriber count.
Because that was always the mission.
Counterintelligence isn’t about living suspiciously. It is about seeing clearly. It is understanding how someone can manipulate trust, recognizing the moment when something doesn’t quite fit and having the confidence to stop before taking the next step.
That is what I learned hunting spies. It is what I’ve tried to share for one hundred issues.
And now I want to hear from you.
Which story from the first 100 changed something you actually do?
Reply and tell me. I want to know which investigations stuck with you, which lessons became habits and what you want us to investigate during the next hundred.
There will be new spies. There will be new lies. There will certainly be plenty of cybercrime. And if the last two years taught me anything, there will be threats we haven’t even imagined yet.
Good. We’ll investigate those too.
As long as you’re riding shotgun with me, I’ll keep writing.
What worries you most about the next 100 issues?
Sponsor Corner
This issue is sponsored by Nexasure.
Cybersecurity shouldn’t require a translator. Nexasure helps CEOs, boards and executive teams cut through the noise, understand their real cyber risk, and build security strategies that protect the business without slowing it down. No fearmongering. No shelfware. Just experienced cybersecurity leadership focused on what matters.
Think your cyber strategy could be stronger? See how Nexasure can help →
Stay safe out there and keep thinking like a spy hunter.
Praemonitus Praemunitus!
Forewarned is Forearmed!
~Eric








