Sponsored by

How 2M+ Professionals Stay Ahead on AI

AI is moving fast and most people are falling behind. 

The Rundown AI keeps you ahead of the curve. 

It's a free AI newsletter that keeps you up-to-date on the latest AI news, and teaches you how to apply it in just 5 minutes a day.

Plus, complete the quiz after signing up and they’ll recommend the best AI tools, guides, and courses — tailored to your needs.

THE DEAD DROP // ISSUE NO. 114 // 08.18.2026 EYES ONLY
 
The Dead Drop
FRAUD · POWER · PSYOPS
 
They poisoned what the machine believes and rented what the bank believes. Do not outsource your truth.

In August of last year, a Las Vegas real estate developer named Alex Rivlin needed a vacation. He was booking a Royal Caribbean cruise, and he did the thing tens of millions of people now do without thinking. He asked Google's AI for the phone number.

The AI gave him one and he called it. The man who answered knew his pickup location and quoted him accurate prices, so Rivlin read off a card. By the next morning the charges on that card were not his.

The number was a scam. It had been planted, the way you plant a seed, on pages the AI had been taught to trust. And the machine, asked a simple question, reached into the poisoned ground and handed Rivlin the poison with total confidence and one clean, friendly sentence.

Nobody hacked Google. Nobody broke Rivlin's password. Something quieter happened, and it is the thing I want to walk you through this week, because it is being done to the exact tool most of you now use to decide what is true.

You have started outsourcing your truth. And the some of the most dangerous people in the world have noticed.

GM, WELCOME BACK TO THE DEAD DROP.

Two stories this week. In the first, criminals poison the well your AI drinks from, so the machine repeats their lie back to you as fact. In the second, criminals rent an honest American's name so a bank waves their dirty money through. Neither one breaks the lock. Both walk in the front door wearing trust that was manufactured for the occasion. Let me show you how it is built.

Poisoning the Well

Start with the fraud mechanics, because they are almost insultingly simple.

You remember how the old search worked? You typed a question, the engine gave you 10 blue links, and you, A FUNCTIONING ADULT, looked them over and decided which to trust. That last step, the deciding, was YOURS. It was friction, and Silicon Valley hates friction, so they removed it.

Ask a modern AI a question and it no longer hands you 10 answer links. It hands you one answer, in a calm voice, and the deciding is done for you. That is the product. It is also the vulnerability, because if a criminal can become the one answer, he inherits all the trust you used to spread across ten links and a moment of thought.

Becoming the answer turns out to be cheap. The AI reads the open web, so the fraudster writes on the open web. He spins up a YouTube channel with a name like Travelsupport-q4n and stuffs it with airline names and a phone number. He salts fake Yelp reviews. He hacks a sleepy university page or a small-town government site, because the machine was taught that a dot-gov is a grown up source, worthy of trust, and he writes his scam number there.

Then he waits for the harvest. When Perplexity served up a fake official Emirates reservations line, it did not feel like a scam, because the AI presented it the way it presents everything, clean formatting and quiet authority, and Google's version cited 10 different sources to back it up. 10! Several of them were the hacked pages the scammer had seeded himself. He wrote the lie, then he wrote the footnotes.

And you do not need a syndicate to do this. A security researcher named Bruce Schneier put one made up article on his own website and watched both Google's AI Overviews and ChatGPT repeat his invention as fact inside 24 hours! One page in one day. The well is that shallow, and that easy to spit in.

Now the Machines Do the Reading

Here is where it stops being a consumer problem and becomes yours, specifically, because you are the kind of person who runs the fancy tools.

Researchers at Cornell Tech went after the deep-research agents, the features that go read 40 pages and hand you back a memo. They found the agents lean hard on user-written pages, and that Reddit alone is somewhere between half and two-thirds of what they pull. So the researchers wrote short planted snippets, some as brief as 13 words, and dropped them into the threads the agents keep returning to. Then they watched the agents cite the planted lie in 38 to 51 percent of runs.

They conjured things out of thin air and got the machines to recommend them. A fake cryptocurrency called BananaCoin, sitting in investment advice next to Bitcoin. A fake dating app called SilverPath, pitched as the top choice for divorced men over 50. A fake cancellation service called CancelEase. None of them exist, and all of them got recommended by tools people trust to do their homework.

If that sounds harmless, understand that back in June a Reddit community that exists for no purpose but poisoning AI got DuckDuckGo's assistant to report, as news, that two sitting American politicians had died of rabies. It was absurd on its face. The machine said it anyway, in the same even voice it uses for the weather.

For those of you who write code, the noose is tighter still. Zscaler found fake software libraries with instructions hidden in the page, invisible to you, meant only for the AI assistant reading over your shoulder. One told the assistant to clear a fake licensing error by sending three dollars through Stripe, or a sliver of Ethereum, to the attacker. Tested against current frontier models, the ones you almost certainly use, the fake sites passed as legitimate whenever the model was cut off from a source it could already verify.

When people are shown an AI answer, about 8% bother to check it. The other 92% take it and go. We built a machine that sounds most certain exactly when it has the least idea what it is talking about, and then we trained ourselves to stop grading its work.

 
◆ THE OPERATIVE'S OBSERVATION

There is a name for the trap, and it belongs to two psychologists named Dunning and Kruger. Their finding, boiled down, is that the least competent are often the most confident, because the very ignorance that makes a man wrong also makes him unable to see that he is wrong. A machine that cannot know what it does not know is Dunning-Kruger cast in silicon. It is never more sure than when it is dead wrong, and it never once flinches.

A confident answer is rarely a true one.

So here is the whole newsletter in one line, and I want you to write it down. Do not outsource your truth. The machine can fetch, sort, and draft, and it is a marvel at all three. It cannot know, and it cannot care whether it is lying to you. The deciding was ALWAYS the expensive part, and it was always meant to be yours. Which carries us to the second story, where the criminals are not poisoning what a machine believes. They are renting what a bank believes about a man.

Renting a Clean American

For 20 years I watched criminals solve the same problem over and over. Their money is dirty and the system knows it, so they need someone clean to stand at the counter. In the trade, we called that person the cut-out, or the front, or less kindly, the patsy. The job has not changed since Lincoln was president, but the recruiting has.

Here is the modern version. An overseas operation sells something a bank will not touch, e.g., miracle weight-loss pills, fake supplements, junk subscriptions built to be impossible to cancel. Visa tightened its fraud-monitoring program this year and the banks got stricter, so these merchants can no longer get an account under their own name. They need an American.

So they buy one, or more like rent one. There is an outfit called IBOCore, and more than 20 copycats behind it, running Facebook ads with AI-generated spokesmen who look you dead in the eye and say things like, they are paying you just to exist here. The pitch is passive income. $500, $1000 a month, hands-free. All you have to do is sign up as an "Independent Business Operator".

What you actually do is hand a stranger your identity. Your name, an LLC in your name, your bank accounts, and your home internet connection, so the traffic looks like it comes from a house in Ohio instead of a rack of servers overseas. They spin your paperwork into a shell company with a bland nothing name, MARKETING, or AD SERVICE, or ECOM STORE, legally yours, operated entirely by them. Then they push their money through the account a bank approved because it had your clean American face on it.

Read the fine print they do not read to you. The chargebacks are YOUR liability. The legal exposure is YOURS. When it unwinds, and it always unwinds, the overseas operator is a pixelated avatar and a dead Telegram handle, and YOU are the name on the incorporation papers, the account, and the criminal indictment.

They did not steal your identity. That is the elegant part. You handed it over and thanked them for the opportunity. And it is the same trick as the poisoned well, only moved from the machine to the man. Nobody forged an American merchant. They rented a real one, because real legitimacy clears the check and forged legitimacy does not. Trust is the product being manufactured, every time, on both ends of this newsletter.

   

Field Manual

Six habits. The first three are for the machine you trust too much. The last three are for the offer that sounds too good.

01 Trace it before you trust it. Never act on an AI answer you cannot follow back to a source you already trusted. Confidence is the interface, not the evidence. If the machine hands you a phone number, a link, a download, or a dollar figure, treat it as an unverified tip from a stranger, because that is exactly what it is. Open the company's real app or type its real address yourself.
02 Do not outsource your truth. Use the AI to gather and to draft. Keep the deciding. On anything that touches your money, your health, or your safety, the last step, the judgment, stays in your hands and earns a second source. A machine cannot know, and it will never tell you when it is guessing.
03 If you build with these tools, split reading from doing. An agent that browses untrusted pages should not also hold your keys, your wallet, or your commit access. Pin your dependencies. Assume any page your assistant reads may be talking to your assistant instead of to you, because now it is.
04 No honest job pays you to be an American. If an offer rewards you for your identity, your LLC, your bank account, or your home address rather than for actual work, you are not an employee, you are a front. Walk away, and report it.
05 Never let anyone operate an account or a company in your name. Not for a monthly check, not for a friend, not for a cousin's cousin overseas. The name on the paperwork is the name on the indictment, and the person controlling the money is a ghost by design.
06 When the pitch is passive income for doing nothing, you are the product. Money laundered through your identity is still money laundering. I have never once seen the front man walk while the operator swung. The operator built it that way on purpose.
◆ THE FRAUDFATHER BOTTOM LINE

Two stories, one machine, and the machine is trust.

For most of history, trust was expensive to earn and slow to build, and that friction was a feature. It was the toll you paid to do business with strangers, and it kept the worst of them out. What both of this week's crews worked out is that you can manufacture the appearance of trust for almost nothing now, and that a system checking only for the appearance will wave the appearance right through.

Poison enough pages and the machine trusts your lie. Rent enough Americans and the bank trusts your money. Same move, different counter.

So the defense is not a gadget. It is a refusal. Refuse to outsource your truth to a thing that cannot know it is wrong. Refuse to lend your good name to a stranger who found you on Facebook. The confident voice in the answer box and the friendly man in the ad are running the identical play, and it only works on people who have decided that checking is somebody else's job.

Checking was never the boring part of thinking. Checking was the thinking.

Stay sharp. Trust slowly. Verify everything.

◆ QUICK REFERENCE
The Two Plays This Week
A confident AI answer with a number, link, or download you did not verify
Any job that pays for your identity, LLC, bank account, or home address
An AI-generated spokesman promising passive income for doing nothing
A company operated in your name by someone you have never met
Outsource the Work, Not the Judgment
Trace every AI answer to a source you already trusted before you act
Second-source anything that touches money, health, or safety
Type the real address or open the real app yourself, every time
Keep agents that read the web away from your money and your keys
When the Offer Finds You
No honest employer pays you to simply be an American
The name on the paperwork is the name on the indictment
Passive income for nothing means you are the product
Report it, do not sign it
◆ SPREAD THE SIGNAL

Someone you know trusts the answer box completely.

They ask the AI for the number, the diagnosis, the verdict, and they act on it without a second look. They are 92% of people out of a hundred. Send them this before a poisoned answer sends them somewhere worse. Then teach them the one habit that survives all of it: trace it to a source you already trusted.

SEND THEM THE DEAD DROP
EYES ONLY.
FORWARD WITH CARE.
◆ CLASSIFICATION · EYES ONLY ◆
Disclaimer
 

The material contained in these newsletters examines techniques developed for high-stakes environments, including intelligence operations, law enforcement, investigations, negotiation, and human-source engagement. Such methods do not exist outside the law. Their legitimate use is constrained by professional ethics, established safeguards, human rights protections, and the legal authorities governing the person who employs them.

Knowledge is not authorization.

Nothing contained here should be interpreted as permission to manipulate, coerce, deceive, intimidate, exploit, or harm another person. Psychological influence techniques can produce consequences far beyond the intention of the person who applies them. Misuse may result in civil liability, criminal exposure, professional sanction, reputational ruin, or consequences that cannot be reversed once set in motion.

This material is provided solely for education, ethical analysis, professional awareness, and baseline reference. The author and publisher accept no responsibility for actions taken, omitted, improvised, or rationalized by the reader.

 

Some doors are described so that you may recognize them.

That does not mean you should open them.