186. Tech Espionage and Sexpionage is now Normalized
Your secrets are only as secure as your weakest employee. Billion dollar techs are much easier to steal than to reproduce. Advances in tech (Including AI) vastly increase the vector vulnerabilities.
People who have common knowledge (that AI stole from 10,000 people before you), no one cares about that. AI will replace you if it hasn’t already. But the moment you get hired on a new project and you learn something valuable to others, now you become a privileged mark. If you aren’t used to being a mark, then you are an easy mark. There is no easier mark than someone that gets a privilege and then translates that into a belief of merit.
I think I used this example some 14 years ago when I was defining Pay to Win. I can have a track race with an 8 year old and two Olympic runners. I ask the athletes to let the kid win. To everyone watching, they understand the situation. But the kid really wants to believe they won based on merit. It makes them feel great.
When you are 8 years old, this might be harmless. But now that you have key scientists working on projects being offered as much as $1.5 BILLION dollars to work on tech that could be worth trillions of dollars, this can put those people into a state of ego where they really believe they beat the Olympians.
This is a picture of the guy that was supposedly offered $1.5B from Meta. Do you think the women are lining up for this guy based on his photo? He was rich at birth so he’s probably a bit used to being chased by sugar babies. Now if he’s paid that much, that would mean what’s in his head is worth well over $10B.
Ask yourself, for $10B what would you be willing to do to poor young Andrew here to get what he knows? Or prevent him from whistleblowing? This is what I want to impart in this paper, and I have (unfortunately) first hand knowledge of all three types of espionage that I will talk about here:
Commercial Espionage
Whistle Blowers
Human Sexpionage
Commercial Espionage
This is a very broad category of stuff that used to be racy spy thriller stuff but today it’s all around us so we don’t even care much anymore. But if you have secrets to protect, you really should get agent level education on the subject because the agents going after you would appreciate you not knowing what they are going to do to you.
Hacking is pervasive, and has been around a while. It gets ever more effective as the tools for this become more advanced. But even if you are not connected to the internet, you could get hacked just by someone slipping a thumb nail into your laptop for a few minutes and then removing it. They don’t even have to log into your computer, they could put something on your system that allows remote access.
Similarly if you are traveling and you stop at an airport that is controlled by a country that is curious about you, they can stop you and scan all of your electronic devices. This was done to me in Manchester UK of all places, and they stole a hard copy of my Supremacy Goods microeconomic model and sent it to their intelligence services. This was prior to my publishing it, which forced me to publish it early.
I was detained for at least 12 hours, interrogated for hours, food was withheld unless I agreed to eat an animal (I’m strictly vegan), and I was denied a phone call to the USA consulate. I was told that I was being held in “no man’s land” and that international laws did not protect me. They could hold me indefinitely and no one would even know where I was. I had already gone 2 days without food on some awful flights (no vegan options) and was hypoglycaemic. I was light headed and asked for help filling out the customs card, that’s why I was detained. That and I was traveling to the UK with a Middle Eastern name during the Olympics which were held there that year.
Once they saw I had all sorts of complex sounding scientific papers on me, they decided they had hit the jackpot. I’ve been to Russia, Belarus, and China. They never treated me like that but the UK has a special relationship with Middle Easterners. The UK studio that paid to fly me out ended up going out of business due to this UK government adventure.
Espionage can be between governments, companies, employees, or any combination of those. Anyone with sensitive information of value to someone creates an incentive for espionage operations. Anything you travel with is relatively easy to compromise as you may be in hotel rooms (easy to access) or making many transitions (easy to pick pocket or such). If you are traveling solo, you have to be extra vigilant and ideally travel with devices that contain no sensitive information. If you travel with a partner, the partner needs to know not to have arguments or otherwise create distractions that would increase vulnerability for both of you.
Just in the last year I had a former employer (who knows how valuable my tech is) try to buy my tech off of a more recent employer. I had anticipated this and was hired with the understanding this would not be allowed. My employer didn’t believe me that they were after my tech, but I activated my lawyers to make a transfer more complicated. Sure enough when the papers came over, they specifically requested all of my design docs. This is the curse of having my tech being undervalued by those that don’t understand it. Previous employers could potentially try to buy it off of all my future employers. This requires me to have a “no transfer” clause in my contracts.
The same employers also brought on a person as a director that I had immediately identified as “high risk”. I was there when he invited himself onto the team, which is a classic way to insert an agent. This person’s resume, if it was even real, contained multiple positions that would have required intelligence clearance at the highest levels of government, from a competitor government. So, the best case scenario was that he was a catfish and his background was fake. Worst case scenario would have been for it to be authentic.
He was hired over my objections and proceeded to do what you would expect: he wanted copies of every design and infrastructure document from every department in the company. Stuff totally unrelated to his role. Somehow this didn’t raise any red flags either. I had to helplessly watch as my designs were pillaged. When the agent became aware I was onto him, he proceeded to gaslight me with the founders which was also successful and compromised my function in the company.
It took months before the founders finally figured out what was happening and kicked the agent from the company. For weeks he was still trying to download docs from us, and I personally had to go to our vendors and alert them to the person being a security threat as the founders didn’t bother to do this.
This was the great thing about working with Russian teams: they have a security mindset. But this team, developing cutting edge technology (it was fundamental to their startup pitch), had zero experience with security. The founders even had their most critical accounts (like the ones with money in them) hacked multiple times even as I was talking to our CTO about raising security in the company. It was like running naked through Time Square yelling “fund my startup!”
Whistle Blowers
Sometimes your own company can engage in espionage against you. Many company laptops come with employee monitoring software. This is spyware designed to keep tabs on you as much as possible. And a lot is possible. But what if your company becomes concerned that you know too much? Perhaps they are under threat from a class action lawsuit due to mistreatment of workers. Or a unionization movement. Or…
Maybe they’ve broken the law. The public safety might have even been threatened. If there is a risk that a knowledgeable employee could go to the press or even be subpoenaed as a witness, now there is an immediate need to neutralize that employee. Whistle blower laws are supposed to protect these employees but some countries have notoriously weak protections. In Australia for instance, the government actually prosecutes the whistle blowers! This is why you see so many web3 companies headquartered in Australia.
If you are a common employee, this is not really ever going to affect you. But if you have information that could cost a company $100M or even billions of dollars, then you better take out that life insurance policy in a hurry. Boeing whistle blowers have notoriously short lifespans. This young but talented OpenAI whistle blower from UC Berkeley ended up suffering from “my head is missing” right after ordering Door Dash.
I’ve been a whistle blower a number of times, including a (USA) federal whistle blower. The more money is on the line, or the more years your testimony might cause someone to be in prison, the more careful you have to be. Generally you will be intimidated first. If that doesn’t work then you will be investigated to see if there is any compromising information around that can be used to pressure you into silence. When that fails the situation will escalate to extortion and/or false allegations. If it gets to that stage and the whistle blower does not capitulate, then they should seriously assume that “an unfortunate accident” is part of their short term future. The “unfortunate accident” business seems to have grown in recent years from a boutique industry to something much more organised. When the police refuse to investigate some of the most high profile “accidents” in the history of Earth, like with Suchir Balaji, then you know that person saw in way over their head. Suchir likely had no idea what was coming as he blissfully ordered his Door Dash.
Human Sexpionage
Exploiting the romantic weaknesses of a person for the purpose of getting secrets or neutralizing them is something that’s been going on for millennia. People get stupid, and thus more vulnerable, when their hormones are pumping. It’s been known that the Soviet Union had extensive training programs for agents to learn how to compromise targets using romantic and sexual advances. Female agents were called “Swallows” (seriously! I didn’t make that up!) and male agents were “Ravens”.
More recently USA intelligence agents have been warning of a veritable army of Chinese “Swallows” being sent after American tech workers. If a mark is valuable enough it can be worth it to install an agent in a close relationship with that mark. This could even go as far as marrying them and having children with them. Typical marks would be military, political, or high tech personnel. Accusations against Kash Patel’s “half his age” girlfriend and her defamation suit are this week’s high profile example. But with the pervasiveness of “sugar dating” in Washington, it’s dangerous to assume it’s state sponsored unless you’ve got hard proof. That said, sexpionage is MUCH more common than you would imagine because it is hard to prove, victims want to cover it up, and because it is so effective.
Sexpionage generally takes two forms, based on who the target is:
Valuable Mark: The mark knows stuff. Valuable stuff. And you want it.
Hazardous Mark: The mark knows too much and could make your life overly complicated.
Let’s go back to that picture above with Andrew where there is a young woman in the background. If this is a Valuable Mark scenario and I want what is in his head then I’m going to want to find out what/who he likes. Then I can either drop a matching agent into his work environment or have a Swallow (I’m going to have to keep using that word) hang out at his favorite Starbucks until he comes in so she can bump into him. Starbucks lets you hang out for hours so that’s easy. Another option could be to contact any associates of Andrew (like the woman in the picture) and see if they want to 100X their income.
Ideally this is as low profile as possible. Make it look natural and authentic. If the mark becomes suspicious he could break the relationship or even start feeding our agent misinformation. (But like the 8 year old in my first example, “smart” people have a way of believing their intelligence makes them sexy.) If the agent is exposed, then counter intelligence might be able to backtrack handlers and round up multiple agents.
If Andrew already has a partner we can’t compromise, then we may be able to get him to cheat on his partner. Someone like Andrew is going to be under near constant surveillance (whether he knows it or not) so that would be difficult. But for most employees this is pretty easy, especially if the mark is male. The mark might be especially agreeable to doing questionable things in order to keep the affair hidden. They also may provide information that could be used to compromise other easier marks within the organisation.
This scenario changes a lot if Andrew is a Hazardous Mark. This would involve his existence being a direct threat to his own company. Typically this is because he could leak inconvenient information to the press or authorities. If the authorities are already under our control then the press would be the greater threat initially. If people go to the press and don’t know how, their info can be “catch and killed” and now they are in serious trouble because they are exposed and a high level threat.
In my personal scenario I observed and documented numerous cases of wrong doing, all various flavors of illegal. I reported these to the founders who decided I was becoming inconvenient. A young female co-worker arranged to have lunch with me during a lunch break, and also arranged for the chaperone which I requested in writing for my protection to not be available. Then the woman asked me personal questions about my sex life that were accusatory in nature. The accusation (that I date young women) was untrue and I let them know the only person I was dating was 60 years old. I also pointed out that I’m here to get food, this isn’t a date.
I’m a very hard target for sexpionage. The next day I notified her in writing that I would not have any more social contact with this person. I have all these documents saved for my protection. So in this case the agent was sent to collect compromising information about me that could then be used to coerce my silence. Pretty normal stuff. When that failed, they waited 6 months and accused me of being accused of improper behavior. I never received any negative remarks from the agent so it could have all been made up.
When “extraction” fails in a Hazardous Mark case, things escalate to the “extortion” phase. He said/she said attacks are very difficult to avoid as you saw from the Herd-Depp trial. Most men don’t have the resources to defend against even the weakest accusations. In my case, I assumed a black ops against me was coming so I had tons of documentation. But if the other side has enough money, and there are no official whistle blower protections, neutralizing a witness at this level is pretty easy.
If that still doesn’t work, then you can Boeing or OpenAI them. My former employer is almost certain to be “investigated” and my testimony could cost them $100M or more. I’m sure a problem like that can be solved for $1M or less. So I’ve become increasingly transparent about my pacifism and anti drug lifestyle so that if my head disappears or if I’m found with a needle in my arm, it will obviously be foul play.
I ended up changing my entire lifestyle to “accident” proof it. I don’t even drive anymore, I walk everywhere.
I seem to get about one Chinese honey trapper a year, here is a sample dialogue (in the last year) with how upset they get when I reject their advances:
I assume the shaming language is to elicit an emotional response, which in my case is pretty difficult. This person did a lot of research on me before contacting me, and I assume they are under a lot of pressure to get a result so I can understand the really intense reaction when they get rejected.
The World We Live In
The world is increasingly becoming polarized. Tech is advancing faster than we can adapt. New vectors of attack are being invented daily, if not hourly. I recently posted on LinkedIn an AI agent trying to con me out of $200 for “job searching”. If an AI can do that to one million people a day, that would be quite a business model.
Not all targets of espionage are tech secrets. As the world moves into entrenched war preparations, whether that’s for cold or hot wars, the focus is on tech and supply chains. Ultimately, degrading your opponent’s supply chains is what forces them to capitulate. The tech race is there for that purpose. Even as a basic employee, you are part of a supply chain. If you are vulnerable to being compromised, you could end up compromising the entire supply chain.
You could be a minimum wage QA worker but you could be used to compromise passwords of other higher ranked employees without even knowing it. If even the most powerful country in the world lacks a security mindset at the highest levels, then you can imagine how easy it would be to compromise a tech firm. Or maybe even a water filtration plant, or a low level worker in an electrical grid infrastructure.
It’s not paranoia if they really are out to get you. Paranoia was a great game, you really missed out if you never got a chance to play it. Makes me feel old realizing that game is over 40 years old now. But they should bring it back and make every tech worker play it. 40 years ago that was just entertainment. Today it might be essential work related skill sets. Heck, you could even play it at work and use real events in the office which already look suspicious as the elements of that week’s role playing session. Who knows what you might figure out… Make Kash Patel play it, it could be of national security importance!
Sigh, it’s difficult to watch. Don’t be that person. If something seems too good to be true, it probably is.




interesting take