Hacked - The Bibliophile
Episode Date: May 1, 2023The story of a manuscript hacker who scammed the publishing industry for years with increasingly elaborate social engineering schemes and an unclear motive. Learn more about your ad choices. Visit po...dcastchoices.com/adchoices
Transcript
Discussion (0)
So back in 2017, a posthumous sequel to the Girl with the Dragon Tattoo book series is set to be published.
It's going to be this big literary event.
And the book's Swedish publisher, Nordstetz, is all hands on deck for the book's launch.
Okay.
Because a book like that isn't one book.
It's 27 books.
There in Sweden, there's the English language version, Spanish, Japanese, international launches, translations, media appearances.
People are calling, texting, emailing.
The big day is coming up for this book.
The book's Italian edition editor, Francesco Verroto, sends the folks at Nordstetz,
as well as the author's manager, an email, asking them to re-send her the link to the manuscript.
Piracy is a really big problem with pre-publication books, so what do you do to keep a lockdown?
Norsetz, the Swedish publisher, was using an encrypted, password-protected email service called hushmail
to send the manuscript via email,
with the password to the manuscript
delivered separately via phone
for an added layer of security.
Yeah, very smart. I like it.
Emails are flying, everyone's calling everybody.
The author's agent Magdalena Headland
sees that email from the Italian publisher friend
asking for the manuscript,
and she fires her off the hushmail link to the book.
Verota then sends an email to both of them,
hey, could I also get the password?
The publisher sees this,
knows they're supposed to deliver that password
it over the phone, so they text her. Some to the effect of, hey, you asked for this code.
And the Swedish publisher immediately gets a call back saying, no, I did not.
Whoever was emailing these people on this big day, when everyone is running around trying
to get this very locked down copy of this book out the door, was not who they said they were.
Classic, is what I'd say. It's a classic. We're going to talk about the mechanics of this fishing
scam, the domains they registered, the social engineering, all of it. And we're going to talk about
And we're going to talk about the scale, because at the same time as they were messaging
Nostetz about this book, that same fake email was emailing other publishers about other
books, and emailing yet other publishers about different books using different fake aliases.
This was not one incident.
It was a fishing spree, and it didn't just last that day.
It had been going on for years and would go on for years further.
What I want to dwell on is why.
Why a person would undertake a project of this scope for as long as they did?
Broadly speaking, you could do it to pirate books, though spoiler to the end, there's no evidence that any of these titles were ever pirated.
You could do it to steal the book and then blackmail the publisher, though there's no evidence that any of these publishers were blackmailed.
You could do it because you're someone in Hollywood desperate to find the next piece of big IP.
Everyone's going to fight over.
We talk about that theory for a while, along with any of the other increasingly obscure practical reasons why you would do this.
The why is what makes this one weird.
Maybe they just really wanted to read the books.
Yeah, that's what I'm thinking here.
You just got a huge literary fan out there that just wants early action.
I remember I can't remember but some movie dramatized that idea of getting a copy of
the new Harry Potter I think it was like the devil wears Prada or something it was some
really obscure movie I guess that's probably not that obscure but obscure to me obscure motion
picture devil wears Prada yeah obscure obscure to me I'm not sure why I watched it
I remember being kind of a cute movie actually if I recall but um I think that's actually
pretty pretty cute film and weirdly Harry Potter comes up later in this story
I really hope it's just, you know, some nerdy hacker who's just figured out that the best thing for him or them to do is hack their way into getting the story before anybody else.
I really hope that that's the, this has like a cute, like teenage book nerd vibe to it.
It, I think you're going to, I think you're going to like where this goes.
years later, the pandemic hits.
And a bunch of journalists with ties to this publishing industry are stuck inside with nothing to do.
And a bunch of them get on to this story and they start digging.
To this story that if it happened in almost any other industry, we'd probably know like a tenth of what we know about this.
We know a lot about this one.
So we're going to talk about it now because a month ago, finally, the court case for this whole weird.
story came to an end.
Concerning this person who seemingly, as you said, either really loves books, a bibliophile,
or really, I guess, hates book publishers, which we don't really have a word for.
So for now, we'll just call this one the bibliophile.
Here on Hacked.
Is bibliophile a real word?
Bibliophile is a real word.
It's a person who loves books.
Like, just likes reading books.
I guess that makes complete Latin sense.
I just never heard that word before.
Yeah, you don't hear it trotted out very often.
But it is, it was the first thing that popped into my head when I bumped up to the,
maybe this person just loves books a lot.
I'm like, it's a bibliophile hacker.
Like they, it's a person who loves books so much, they hack them before they come out.
Wow.
I'm intrigued and excited to hear the story.
It's like, it's like, you know, we've talked about so many things.
where it's like people doing bad and taking over this and state sponsored hacking.
And now it's just like, it's like, no, no, God gave me this great power and I'm going to use it
for personal gain because I want to read more books that I can't get a hold of.
Well, it's it, we won't get ahead of ourselves because there's, there's a little bit more to it than
that. I think it's a, there's some complicated motivations going on here. But we'll, we'll, we'll dig into
that. But not before. But not before. But not before. We thank just the best Patreon on the
internet. Okay. Well, I think we have to have a brief chat about this before we jump into the
thanking list. So we got a notification from one of our patrons that we apparently missed. Yes.
Anna Di Lorenzo. And Adi Lorenzo. Thank you so much for your support. Yes. That for sure.
But what it led to is that we were looking at email notifications from Patreon to see who would become a new subscriber since a specific date.
Yes.
And it turns out that we're not getting email notifications for everybody that joins, which seems surprising.
But it's the truth.
So we might have missed a plethora of people.
So yeah.
So I think we should go back to what do you think?
Like April 1st, maybe?
I'm down to go back to April 1st.
April Fool's.
Patreon played a prank on us.
Okay, let's go to April 1st.
Let's go back to then.
Yes.
So I recognize some of these names, but they're worth saying again because we love you all.
Sean Miller, Crow 404, godly goon.
Jade, Dissoray, whom I do not remember saying before.
I don't think we got Jade.
I think that one's new.
Jesse Anger, I think we got Jesse.
Mark Christensen.
Marco.
Madeline Acosta, the Duchess.
And I think, I recognize a few of those.
Some of those are new.
So I think if we have missed you,
jump on Patreon and fire us a message.
You will get a personal apology.
And we will make sure to look out for you next time.
And thank Anna Di Lorenzo for bringing this to our attention.
For blowing the whistle on this Patreon scandal.
Oh, my God.
When you thought you could trust a platform,
you don't mean notifications,
wasteful notifications that I just don't care about.
I have to mute every day.
And the one notification I want.
It really matters.
Totally.
We'll inform you about some of the people that have been kind enough to support your podcast,
but not all of them.
And it will be unclear which is which.
Okay.
Well, let's jump back into bibliophiles.
The bibliophile.
Again, a word that I don't think I've ever heard, but I...
It's a pretty good word.
I definitely re-googled it to make sure I was using it right and I'm presently re-googling it to make sure that I'm using it right. I'm using it right. Cool. A person who collects her has great love of books. I'm good. I had faith in you. I knew you had it. I knew you had it. I was like, there's something you're good with, Jordan. It's words. I was like, I'm pretty, I'm 99% sure. Um, so book piracy.
Book piracy.
I want to take a little detour and talk about book piracy.
Back in the early 2000s, when people were starting to get really concerned about internet piracy for good reason, this idea emerged that the easier it was for people to legitimately get your content, the less piracy was going to be a problem.
I think that is both true and false.
Yes.
I was curious how books compared to other media.
It's basically reading tea leaves, trying to figure out the cost of piracy because a pirated movie,
does not equal, say, one lost movie ticket or movie rental.
Sure.
There is a lot of content that is only consumed because it is free.
Yeah.
Yeah.
Exactly.
The economics of piracy.
It's super interesting.
I'd like to do more of these about sort of just the history of piracy on the internet.
But books are an interesting kind of side case study.
We should do that.
I have some interesting thoughts on what open access to,
software and stuff, certain things, has led to in society.
So I think that that's a good episode concept.
We should mark that one down.
We should do that one.
I want to do a lime wire and Caza and Morpheus era peer-to-peer sharing network retrospective.
I feel like there's a lot to dig into there.
But so you have to take a lot of these numbers with a grain of salt because they're often the result of research done in a lot of cases to justify really just harsher legal handlings of piracy.
Let's use movies for a comparison.
A lot of people steal movies.
According to the GIPC and NERA economic consulting, quote, in 2020, there was an estimated
137 billion visits to film and TV piracy sites globally, which cost the U.S. economy,
this is the important number, at least 29 billion in lost revenue each year.
Wow.
That is out of the, quote, combined global theatrical and home entertainment revenue representing
99 billion in 2021, according to the MPA.
So if we're doing some probably bad napkin math, that says we're looking at about 30 billion lost out of a $100 billion American film industry.
30 to 100, do with that ratio what you will.
Alternatively, according to a 2019 Forbes analysis, book piracy estimated to cost U.S. publishers $300 million each year.
It's not insignificant, but it's about 1% of what you see in film.
That's a really good narrative on society right there.
Right.
It's like the book people are book people and everyone is a movie person.
Totally.
Just based on the scale of, you can rank the scale of a market by how much piracy exists in it.
But I think there's more to it than that because so the question that asks is, is the publishing industry 1% the size of the film industry, right?
And the answer, it would seem is no.
The most recent numbers I found is that it is about one quarter to one third the size of the film industry, about 30 billion.
And yet it is about 1% of the piracy.
That's still massive.
It's way bigger than I would have thought.
But then I was talking with my partner about this.
She was like, you know there's bookstores in every mall, right?
And every airport.
And I was like, right, there's like whole stores that just sell books.
Right, right.
Books popular.
This makes total sense.
Amazon came from just selling books.
Totally.
I majored in English.
I paid money to be taught how to read books I could already read.
Books are popular.
So why?
You also really have to respect the fact that, you know, in today's kind of climate,
we're watching the decline of, I guess it's just based on that.
I'm now just having a conversation with myself, but, you know, magazines have been
significantly impacted, you know, digitized.
But I guess it comes down to the amount of consumption.
required. Like, it would be hard to sit down. I guess Kindle is the digital equivalent of a magazine,
but of a digital magazine or the digitization of a magazine. Yeah, I, you know, I guess books still
have that standing power, you know, when I go on vacation, I make sure I pack a physical book.
Totally. And magazines managed in a lot of cases to make that jump. I'm not even sure if it's
better than books. Books did pretty good, but we think of a lot of legacy magazines that are just
very, very, very popular websites now.
It certainly impacted how they were able to monetize their journalism, but they were able
to make that jump in a lot of cases.
Yeah, if not expand the reach.
You know, now we're now we're consuming, consuming like the production, like we've made
magazines, you and I.
That's a real thing.
It costs a lot of money to make a magazine, like the physical production of it.
Tens of thousands of a thing.
Yeah, it's not cheap.
You could spend that money.
Or hundreds of thousands?
Totally. Like you could spend that money, as we have learned, kind of expanding your print product into a whole media thing. It's like there was no reason for you for a magazine to get into video because you can't print those on paper. But now you can have documentary departments and podcasts all kind of under that banner if you think of it as a sure. Yeah, cooking like digital first product.
Cooking YouTube channels that have spawned out of major lifestyle magazines. It's a. The digital revolution is. It's a digital revolution.
has been good for content.
Well, it was once a dry page and a photo of a dish
is now a 28-minute YouTube video about how to make it.
With just as many ad breaks as it had in print.
Exactly.
Going back to this discrepancy, right?
One quarter of the size, but about 1% of the piracy.
There's an unattributed piece in TechCrunch
that speculates that it's all about what the kids are into.
Quote, perhaps it was because the kids care less about stealing books
than they do about cracking the DRM on movies,
which is why bookshops remain unscathed during the London riots
while DVD stores down the street were looted.
Or maybe it's because the book industry
learned from what happened to their audio and visual cousins.
Either way, devices like Kindle, Nook, and iPad,
and publishers' willingness to embrace them
allowed a legitimate and lucrative electronic publishing industry
to grow up before the pirate sees the initiative.
Books got on to digital distribution early,
They're less popular amongst the age demographics that pirate content hardest.
If you buy that hole, the easier it is to get your content, the less piracy is going to be a problem argument.
This is a relevant data point.
So then there's this subset of piracy, right?
Kind of its own thing, which is leaking.
Like before a launch, the book leaks.
Books being leaked before their launch is a uniquely storied history.
You name a popular franchise.
Odds are, one of them snuck online before the book actually hit shelves.
Harry Potter, Twilight, 50 Shades of Gray.
Let's rush to the present.
Number one most recent bestseller, Prince Harry's memoir, all leaked before launch.
Books you wouldn't think anyone would care to leak.
Leak before launch.
Books leak.
Do you think when a book leaks impacts sales?
Because here's the other thing is like book people
Yeah
Like to own the book
Yep
Mm-hmm
They sure do
So it's like
If I'm such a fan
Of 50 Shades of Gray
That I seek out
If
Big if there
Big if there
That I seek out
Sure
An illegally distributed
Early Release copy
Yeah
I'm gonna better
that I still go out and buy the physical copy.
I would bet that you're in a lot of cases right.
I'm sure there's a subset of people that go,
I already have this book on my Kindle.
I got a hold of it pre-release.
I'm never going to buy it.
I think that's probably true.
I think for the really rider die fans,
the book, you are able to get a hold of the book
a couple days before launch.
You start reading it,
and then you pick up the book,
hopefully on launch day when, you know,
you can get a physical copy of it.
or go to a signing.
Exactly.
And if it's just,
if it's a thing you want to have on the shelf,
you might,
you're probably going to pick up a copy.
If you were only ever going to buy a digital copy,
once you've got the pirated version,
it then takes on,
there's like an ethical choice
to support the author and the publishing industry
and retire your pirated copy
and go buy a real copy.
But that's a very different.
One is you want the physical thing on the shelf.
The other is you want to,
support the person who created it.
There's two different motivations there.
Mm-hmm.
Mm-hmm.
I don't know.
Maybe it's just, like, movie piracy is just like, I'm bored.
I want to consume something.
I need something to distract me from the fact that I'm stuck in existential crisis.
Exactly.
A book is like...
I need something to point my senses at so I don't have to think about whatever I was
thinking about.
Exactly.
Exactly.
And it's, I feel like, I feel like if I'm, if I'm, if I'm,
If I'm stealing books, I'm stealing books.
Like, you know, this is my hope for this story is that I hope that we're, you know,
some hackers stealing them because you just can't, or they can't wait to get the content.
Sure.
It's kind of like a cute love affair, but in a very illegal way.
Yeah.
That's, that's part of it.
Part of it.
Okay.
Okay.
This brings us back to that face.
version of the real Italian publisher of the book from the intro, Francesca Veroto.
That's spoofed email.
The real Veroto works at an Italian publisher called Marcillio Editor.
Their IT department starts digging into these spoofed emails.
Turns out same day, the fake Veroto went after the girl with Drake and Tattoo.
They also went after a bunch of other books.
The spoofed version of the email was actually the correct, like,
domain but dot com instead of IT. So they got a better version of the URL.
The fraudulent domain was registered through GoDaddy to an Amsterdam address created the
day before the scam attempt and had a Dutch phone number registered.
They call up the phone number and it is the Dutch hotline for IBM.
Best guess is this person imitating Verrodo had actually started back probably like a year or two
earlier.
Fall of 2016, first phishing email starts circulating amongst a sloth.
group of people managing the flow of pre-launch manuscripts between countries, this very insular
part of the publishing industry. Foreign rights manager in Greece, an editor in Spain, an agent
promoting international writers in China, which is where we start to kind of make the case that this
person might be an insider. During the attempted Girl with a Dragon Tattoo heist, only a handful of
people worldwide were aware that that book was being distributed to foreign publishers, and that the
specific people at that Swedish publisher were in charge of giving out the hushmail and password links to it.
The hacker knew that.
They also knew if we go through all of these emails, a lot of the lingo.
Scott, say you get an email from someone in publishing and they use the acronym MS.
What would you guess that stood for?
I'm going to assume manuscript.
Nice.
Ding, ding, ding, ding, ding.
Thank you.
Yeah, that's good.
That's good.
One down.
Thank you.
W.E.L. Rights.
World exclusive licensing.
Pretty good.
That's pretty good.
World English language rights.
You got world right.
Ah, okay.
Not bad.
I wouldn't have known that.
The hacker did.
So, this case, maybe they're on the inside.
But what kind of insider?
There's a job in publishing called a literary
scout. So folks in film and other mediums are constantly looking for IP. Books often get turned
into movies. There's money to be made, getting early access to books to be able to advise the
people buying your clients. What's a book you might want to take a look at before it even comes
out? Interesting. Yeah. It's not a common job. There's probably only like a few dozen people
worldwide who do this, but it's a really specific job that would fit the MO.
that's kind of emerging here.
So you're like an internal critic?
Kind of.
You're almost like a book spy.
Like you're trying to get a hold of books before that.
You don't work at a publisher.
You're just trying to get early copies of books to show to people that license books.
Hey, give this a read.
It's going to be coming, it's going to go public in a few days.
And you can have made up your mind if you want it.
You can get in early, right?
Okay.
Okay.
You're working behind the scenes to help make these deals.
You're cultivating those relationships with publishers so that
they can give you, they call those early things slips, which are manuscripts acquired secretly
from well-informed sources inside publishing.
You get a slip, you give your client a competitive edge.
So maybe this is someone trying to generate slips.
Also, it's not a very common job.
So if you're looking at scouts as the possible hacker, you're looking at a nice small suspect
pool.
Sure.
In this weird, obscure job, you rarely see people working together trading,
manuscripts because you're kind of getting too friendly with your competition.
But in 2018, a scout named Natasha excitedly messages her one of her clients.
I've got a potential manuscript trade for this hot upcoming new book.
Another scout named Jane Southern had reached out to her offering to exchange Ian McEwen's
hot upcoming new novel for a significant release that Natasha had.
Natasha is pumped.
She makes this trade, gets an early copy of the Ian McEwan book.
goes to show it to her like clients.
But then she bumps into Southern while she's at like a trade conference,
Book Fair in Frankfurt.
This is the person she's doing the trade with.
And she goes up to them and thanks them,
hey, thanks for making that trade with me.
And Southern says,
I have no clue what you're talking about.
And just like the intro,
Natasha realizes that the person she'd been talking with and trading books was the thief.
The hacker had gotten a copy of Ian McEwan's book.
from another fishing scam and then turned around and used it as lure, kind of bait in this trade
for yet another book they didn't have a copy of.
To get more.
To get more.
So they're re-upping.
They're re-upping.
They're re-investing.
They're like stealing a book and then using it to steal another book.
Wow.
So the focus is starting to hone in on this Hollywood IP scouting system.
And it accelerates.
By 2018 or so, word of this person is starting to make its way really through the
publishing world. People know about this. And by this point, there are people who have basically
been in months-long catfishing relationships with the book hacker thinking they're talking to
someone else until, like Francesco and Southern, someone bumps into someone in person
realizes they weren't talking to who they thought they were talking to. Or they don't. Because,
spoiler, there's probably people who up until very recently, like last year,
We're still talking with this person thinking they were someone else.
I guess this just demonstrates how effective social engineering and fishing can be.
So much.
When you go quality over quantity.
Totally.
Like when you have 10 or 15 prospective targets, like look at how effective you can be,
like years of manipulation versus, you know, 400,000.
bulk emails that nobody reads.
Totally.
And get auto deleted by spam filters and corporate security systems.
Mm-hmm.
Like, that's just, that's amazing.
Like, that's a, that's like a movie.
This needs to be a movie.
This needs to be a book.
These people are book people.
Turn this into a book.
Oh, I'm sure someone's going to write a book about this.
I think I know who's going to write a book about this, but we'll get to that.
So right before the pandemic, people start to go more public with this.
One of those scouts tells a big British trade publication called The Bookseller about the situation.
Publishers Weekly does an interview with someone about the book hacker.
A New York Scout reaches out to the state attorney general's office who is advised to consider talking to the FBI,
given that this is a weird, complicated jurisdictional nightmare.
But paranoia is starting to kind of start to simmer in the publishing industry.
You've got people signing NDAs for really obscure novels no one has ever heard of.
of.
And it's not just the publishers being impacted.
Writers were starting to get emails from this person pretending to be their publisher
or agent asking for copies of the books while they were being written.
This person is just on a tear.
And they have the attention of the entire publishing industry.
You figure if they were internal, if this was an inside job, they would know that people
were getting close.
So it's like, why would you speed?
up. I guess this is like the, like the, what do you call it when you like, you take the last gas
before you die. It's like that like last jolt. Maybe they're just trying to maximize
output. Maybe right before they go like, you know, ghost. Yeah. But anyway. That would suggest
though that people were anywhere close to finding the person. And they were trying. So people start
laying traps. And I like this one. So you got this, this hot up.
coming book coming out soon and someone's people, you're getting emails from people asking for it.
Most of them legit, but you know some aren't. So some people started swapping out the real text of
books partway through the book for other copy from other old books. Like it would just be Jane Austen
copy halfway through the book and it would switch over. And the idea is that you could use those
custom doctored versions to try and suss out who the hacker is. Because if that doctored version ever
made it up to some IP person or some other publisher or get used in one of these trading scams,
you could work your way back to who had that original doctor copy. Pretty clever. Kind of a
honeypot. The hacker never falls for it. And this just keeps going. Over time, people start to
question the It's a Scout theory that's been dominating this very intense but insular discussion.
In 2019, the sequel to Handmaid's Tale, book called The Testaments, became the Thieves' chosen obsession.
They're just hammering people trying to get it.
If you come back to the why, if it's about rights, that book, The Testaments,
it's foreign publishing and film and TV options.
All of that stuff was long since sold by the time the hacker started going after it.
Sure.
It's not really valuable to a scout.
It's no good to them.
All the thing they would be selling has been sold.
So you go down the list.
Is piracy?
Well, none of the other books were ever pirated.
That book was never pirated.
Ironically, the only public leak of the Testaments prior to its launch was when Amazon accidentally shipped just shy of a thousand copies off before the launch date.
Classic.
It's a classic, right?
Scouting doesn't really track.
Piracy doesn't track.
And just going down the list of old reliable culprits, if it was like a nation state actor, A, weird target.
And B, they knew way too much about a very small corner of the public.
establishing industry.
Turns out there's just, you know,
Kim Jong-un is like a massive book.
50 shades a great thing.
Yeah, he's a massive bibliophile.
Biblophile.
Just turns the entire North Korea like information,
infosex sector into like getting him books that he can't get.
I need Prince Harry's memoir before anybody else.
I need the dramas.
Exactly.
That's,
it needs enough the drums.
One handful of cybersecurity performance.
professionals brought in, discovered that the thief had kind of started upping their security measures in 2019.
Over time, it looks like they registered over 300 fake domains, but they'd added, like,
slightly better digital security certificates right around 2019.
Those certificates, they were able to suss out, reveals that a single entity controlled
all of these different domains.
Other investigators, because there was multiple groups of investigators working on this independently,
inquired about potential credit card information and the thief's expenses.
However, GoDaddy confirmed that it had reclaimed several of these domains likely due to payment fraud
as it appeared that the thief was using stolen credit cards to do all of this.
Some more insiders turned to the FBI for assistance, sharing the thief's emails with the bureau.
But the case remains kind of low on the priority list, it seemed, because this person wasn't really doing financial harm.
They weren't leaking the books, weren't pirating them.
They weren't blackmailing the publishers.
It was just very, very weird waste of time, really.
But I guess remember, at least two parties have now contacted the FBI about this,
because that becomes relevant later.
During COVID, the hacker got a little mean.
At the end of that first pandemic in August,
a woman named Linda Altrovberg, who is part of the Swedish publisher from the intro,
gets a message.
It was a thief impersonating a Spanish.
editor asking for a book that Berg knew the editor would never want.
She knew, okay, I'm talking to hacker.
And she sends a message back, keep on dreaming.
Which is a pretty polite way to respond to someone trying to hack you.
Previously, the thief had kind of like retreated when being confronted.
But this time, they replied in Swedish,
Hopas at do d'Udorf of coronavirus at, which in English means hope you die of coronavirus.
Wow.
They start tricking low-level publishing people.
to work for like bad pay that they never actually paid them,
like translating books for 150 bucks and then ghosting them without payment,
just like weird kind of petty stuff that's really out of character with their MO up until now,
which has really just been about trying to get these books.
Could it be that there's multiple people?
It doesn't seem like that's what's going on.
Seems like this person, whoever they were,
was just having a hard time with coronavirus and was acting like kind of a jerk.
Just got in their head the feels, the mental health aspect of being locked away.
I think that's part of it.
So, vulture, New Yorker, all the coverage that I read, interestingly, had this very cryptic reference to a suspect.
This unnamed person who everyone was secretly convinced was behind this, like, again, for years.
So wait, there was like a unanimous, unanimous theory that it was a specific.
person? Not quite unanimous, but over time, it sounds like a name started to percolate.
Interesting. First, only a couple people thought it, but then as more and more people became aware
of this, and everyone goes, well, who do we think it is? This name starts to, you know, rise up.
To quote that vulture article, he was from another country and his English wasn't great. His manner
in person and writing could be brusque. His client list was small. His scouting business sometimes
struggled. One former client told us that after parting ways with the scout, he would like kind of
sent her so many texts as she had to block his number. He wasn't on the literary social scene,
which made people presume he was kind of resentful. Then again, one scout admitted to Vulture.
Do we all just think it's him because he's weird? After the break, I want to talk about the person
who was arrested in January for this very strange years-long hacking spree. The funniest thing
about this story that gets, in my opinion, a little less funny from here out is a tweet.
And it concerns that suspect.
The person everyone was certain was behind this,
just for years, an open secret that everyone was convinced it was this person.
Last January, the FBI arrests a man at JFK Airport,
and that same day, literary agent Kent Wolf posts a tweet,
quote,
Which of Us is in charge for ordering the gift basket
for the poor soul everyone was fingering as the manuscript scammer?
Because the FBI had arrested 29-year-old Felipe Bernardini,
who pretty much no one
throughout this whole story
had ever heard of.
His story, his arrest,
and the result of his court case
after the break.
Think about the last time you heard
a breach story on this show.
It always starts the same way.
Someone, somewhere, saw something too late,
an alert buried, a signal missed,
an SOC that just couldn't keep up.
Arctic Wolf set out to solve that problem
by rebuilding security operations from the ground up
for a world where attackers are already using AI.
They created the Aurora Super Intelligence Platform,
a fully agentic system powered by the swarm of experts.
Instead of single-purpose bots or lucky guess LLMs,
this swarm is full of deterministic agents
that handle whole entire workflows.
Humans stay in the loop and on the loop
to validate the critical decisions
and keep everything trustworthy.
And all of this is just off running
on their secure operations graph.
A constantly updating intelligence engine
fueled by more than nine trillion telemetry events,
every week and over a decade of real-world incident response.
The system reasons on real signals and real context not synthetic training data.
And the result is the new Aurora Agent SOC.
It's the first SOC that is agent-led-by-design.
You get agents that coordinate, agents that investigate, agents that respond at machine speed,
and hundreds more that automate the repetitive work that normally buries human analysts.
Arctic Wolf didn't try and bolt AI onto an old model.
They rebuilt the model entirely.
What makes even more effective is how it works with Arctic Wolf's concierge experience.
The team brings customer-specific context directly into the platform so every AI-driven decision reflects your environment instead of generic assumptions.
The automation frees your concierge security team to focus on higher value strategy and proactive risk reductions while the agents handle the grind.
If you want to see what trustworthy, production-ready AI and security operations actually looks like, go to arcticwolf.com slash hacked.
Ever feel like cyber threats are evolving faster than anyone can keep up?
Last year, 2025 was nothing short of a record-breaking year for major breaches,
from sophisticated ransomware operators to AI-enabled attacks that turn defenses on their head.
Organizations around the world saw headlines they never expected
and cybersecurity teams were tested like never before.
But here's the thing.
These incidents aren't just news headlines.
They're learning opportunities.
And that's why Arctic Wolf is hosting a live webinar on February 5th,
diving into the most impactful breaches of 2025.
Their field CTO and security leaders are going to unpack not just what happened,
but why these attacks succeeded.
And most importantly, what businesses can do to fortify their defenses for it's too late.
You're going to walk away with real insights into how threat actors are evolving,
how defenders are responding, and what strategies can help you stay ahead of the next big breach.
It's not fearmongering.
It's practical, actionable intelligence from experts in the trenches.
Register now at arcticwolf.com slash hacked.
Okay. Okay.
Who's Felipe?
Okay.
On January 5th, 29-year-old Felipe Bernardini, working in the Foreign Rights Department at Simon & Schuster's UK division is arrested by FBI agents at JFK Airport.
So before we get to Y, who was this dude?
Let's do who and how.
Do who and how.
Yeah.
I don't know who this guy is.
Let's do a little.
How they caught him.
Do we have that detail?
We don't actually have how they caught him.
That's one part of this we do not know.
I would guess the full weight of the FBI looking into it is the short answer.
But how they actually found him, I don't know.
Interesting.
So back in 2008, Bernardini is a teenager residing in a small town, an hour north of Rome.
And teenage Bernardini writes a book.
And he gets it published by an independent Milan-based publishing house.
uses a pseudonym Philippo B for the publication.
And the book is called bully.
And it was about a teenager named Diego who got bullied at school.
He's smart.
He does one in his class.
He loves books and hanging out on the internet.
Diego in these diary entries that the book takes the form of writes about his
struggles, stating that people called him gay and that school bullies wanted to beat him up.
And in the book, there's this scene where Diego has this rare win.
he gets the new Harry Potter book before anybody else,
impressing all of his schoolmates.
But aside from that moment,
Felipe's protagonist, Diego, has a pretty rough go-throat the book.
He reflects on how to escape being bullied,
and he entertains whether the answer is to become kind of the bad guy himself.
He thinks about committing a robbery and says he thinks he'd be really, really good at it.
In an English lit class, we would call that foreshadowing.
Bernardini pursued a publishing career.
from a young age. He studies English and Mandarin as an undergraduate in Milan in the early 2010s.
He works as a proof reader for the publisher that released bully. And he posts on Instagram
about getting kind of early access advanced copies of books from authors like Jonathan Franzen and
Nick Hornby, hashtag uncorrected proof, hashtag advanced reader's copy kind of thing.
2015, he moves to the UK to get his master's degree in publishing. He's clear he wants to work in this
field. And according to a resume he sent out, the focus of his dissertation was on the children's
literature classic Pinocchio, a story about a lying puppet. In English lit, we would call that
foreshadowing. I'm glad your English degree is coming in, coming in hot here. He was bound to come up
eventually. After the university, Bernardini begins pursuing a career in publishing. In his resume,
he cites that he has language skills as a translator and proficiency in php and html in 2016
bernardini interns at andrew nernberg associates a london-based literary agency he doesn't get a full-time
job at the end of an internship and shortly after his departure the company's website was hacked
with pages defaced personal information exposed on the site along with insulting comments left behind
Nuremberg never identified the individual responsible for that hack.
FBI alleges that Bernardini starts attempting to steal manuscripts
during his Nernberg internship at age 24.
He has a tough time finding a job after he leaves.
He applies to a bunch of places, doesn't have any luck.
2016, he starts pitching himself as a translator.
A couple places give him a chance, but he doesn't stick around long
because his translations weren't quite up to snuff at that point.
If you remember that 2018 attempted hack,
of the Margaret Atwood book, The Testaments, sequel to The Handmaid's Tale.
It's right around now that Bernardini interviews for an assistant position at the very same agency,
where he would be responsible for managing several prominent authors.
One agent at that place, Curtis Brown, remarked that if Bernardini was the hacker,
he sure did apply and come in for a job for an interview at the exact same time he was allegedly hacking them.
He is nothing, if not confident.
That's going to be an interesting vibe in the interview room.
Yeah.
You're sitting there knowing that you're like essentially breaking into this place.
Pretty much.
I wonder if that's confidence boosting.
I'm just thinking that.
Like you got a little swagger in your step when you go into that interview.
Yeah, you got like the, you know the smirky emoji with just the corner of your like lips going up?
I feel like that's the attitude you go in with if you're like actively breaking into a company that you're also consequently interviewing for a,
job at. Yes. If this was a movie, and I'm sure it will be, that would be a pretty great scene in it.
So there's the stretch of time, just years, applying and pitching himself, applying and pitching
himself, trying to climb this corporate ladder that just would not have him. In this industry,
books that he's clearly loved for a very, very, very long time. That application and rejection
cycle starts to tell a bit of a story.
About a person who's frustrated.
He finally starts to have some luck in 2018 when an Italian publisher starts having him
translate some bestsellers out of China.
He's got a toehold in the industry.
And eventually, he secures a full-time job in the Foreign Rights Department at Simon
and Schuster, UK.
Things are starting to go well.
Gets a promotion.
A book he translates ends up on like a fancy 10 books to read last summer list.
in the industry cares about.
After years of struggling, he's starting to break into publishing.
And yet it would seem, even as his fortune is kind of turning around a little bit,
he keeps up this weird, alleged side hustle right, like right up until the day of his arrest.
Well, let's just hang there for a sec.
We say side hustle.
Is he making money?
You make a really good point.
We can't even really call it a side hustle.
He never made any money.
or advanced his career doing it.
We now know he's an aspiring publishing professional.
It doesn't seem to have helped him at all.
So looping all the way back to the beginning of this episode.
Yes.
Theory says, evidence points to the fact that this person was literally stealing these books solely for the game of it, as well as to probably just read them.
Yes.
Yes.
Wow.
It really does look that way.
The charges against Bernardini accused him of committing wire fraud and identity theft.
The indictment claims that beside the counterfeit domain names he used, he'd actually started creating fake
fishing web pages, a quote, minimum of two harmful pages that closely mimicked the main page of a database
used by a scouting agency in New York, like he said in his resume, HTML and PHP.
And it's alleged that Bernardini persuaded multiple clients of that agency to go to this
link where they would have entered their passwords into the fraudulent site, possibly if not
probably, granting him then entry to the real site using their account credentials.
That was at the start of last year when he was arrested.
He's been in jail since then.
This past month, the trial wraps up that Felipe pleads guilty.
I managed to research this almost chronologically.
Like I knew he'd been caught while I was reading about it, but not that he'd pled guilty.
So the whole time, I'm kind of trying to decide in my head, like, what do I think should happen to this person.
Yeah.
I was literally just having that moral discussion in my head as well.
Right.
It's like, like aside from a bunch of wasted time.
Yeah.
It sounds like the harm was pretty low.
I would tend to agree.
And it's, you know, in today's current, you know, crime is becoming definitely a talking point in the political sphere.
of media. So it's intriguing. I'm intrigued to know what the penalty for this is.
So Bernardini pleads guilty to wire fraud. The result. The judge, Colleen McMahon,
sentences Felipe Bernardini to time served. No additional imprisonment. He has agreed to
compensate Penguin Random House with $88,000 to cover the legal and expert fees incurred due to his
actions. And he's also received a three-year supervised release sentence and will probably be
deported from the U.S. back to either the UK or Italy where he spent his childhood.
The bookseller, that publication from earlier, got a hold of a bunch of the court documents
in which Bernardini writes, in his own words, why at least he says he did this. And we finally
get an answer in his own words as to why. Oh my God, do tell.
Regarding the books, he, quote, wanted to keep them closely to my chest and be one of the fewest to cherish them before anybody else, before they ended up in bookshops.
He says he had a, quote, burning desire to feel like he was a publishing professional and that he had no intention of leaking the books he sold.
He felt a, quote, special and unique connection with the author, almost like I was the editor of that book.
And then I think the big important quote here, he explains how it all starts.
One day, I created a spoof email address for someone I knew of in the publishing industry,
and I sent an email to someone else that I knew of asking for a pre-publication manuscript.
I wrote in the style and using the language that my former colleagues had used,
and when that request was successful.
From that moment on, this behavior became an obsession,
a compulsive behavior.
There's a lot of practical reasons to write something like that in the context of what seems
like a slam dunk court case against you.
But a love for books, a year's long desire to be part of that world all yielding this
compulsion when you figure out what you can do, I kind of buy it.
It's such an interesting, a lot of hackers, if you go back in time enough, they did a
they did it for the game.
Sure.
Nobody ever had malintent.
It was a puzzle.
You know, we're puzzle gamers.
I've made this reference before and it's, people wanted to, yeah, people wanted to crack
things, crack the code.
Yeah.
This guy used identity theft and fishing and impersonation to crack a code and polishing.
Totally.
And got him, got him a reward that it's very strange, you know, like, and the thing that
shocks me about his punishment is that it's it's way more lenient than I expected.
Like you've got to assume that the judge took sympathies.
I think they did.
Because like we've on this show, we've talked about people that like view the source code
of a web page and get five years in prison.
Yes, 100%.
And that's something that's not even illegal and is common functionality and is actually just
the way that the internet communicates or source codes.
Sure.
So that's, that's, that's, I'm more shocked that in a digital theft world and in a way, in the world that we're punishing.
Yes.
You got to assume that their truth in that matter was a significant part of getting them a leniency on their sentence.
Yeah.
They, I bet if they pled not guilty.
Yeah, it might have been different.
It was proven.
Yeah.
It might have been a way stronger thing because that just seems shockingly low to me, given how severe others get punished.
They pled guilty.
They never made a buck doing it.
So what did they do?
They impersonated people.
Like, don't do that.
That is a crime.
That's bad.
But a year in jail, $88,000 and you're deported.
88K.
Is that it's like, okay.
We're in the ballpark there.
I certainly don't think it should be more than that.
But they didn't pirate the books.
Didn't blackmail the companies.
Didn't leak them.
They got books for free.
I do that all the time.
I go to the library.
Exactly.
You know?
They just got them a few months earlier.
Yeah.
It's like the impersonation part, you shouldn't do that.
That's not a good thing to do.
You do material harm.
We're not justifying it here in any way.
Not at all.
And punishment, let's talk about that.
But I'm glad that this wasn't, we're going to make an example out of you.
I don't think that's what this needed.
I think this was a person that kind of stumbled into a bit of a compulsion and it just
lasted for a really, really long time.
It's such a personal story, too.
Such an interesting, like, you've got to imagine there's a whole,
like especially given the words that they wrote in their plea.
There's a whole empowerment angle there.
You know, like I felt powerful.
I was seeking, seeking professional esteem and things like that
and wasn't getting it.
And this gave me a bit of a personal power, you know,
made me feel probably better than he did on an average Tuesday.
And it's just, it's, it's, it's,
Yeah, it's a very interesting.
It's a very interesting story.
I really hope that it gets turned into the book.
Maybe.
Who wrote The Big Short, Michael Lewis?
I think so.
Well, so here's what's interesting about that.
His lawyer described him as being,
and it's kind of part of arguing that he's been punished more than enough for this,
which I think I agree with.
But they described him as being, quote,
effectively banned from the publishing industry
as sort of part of how he's been punished in a very intense way,
given that we know about him.
course.
The irony here is that while Felipe Bernardini publishing professional is, as his lawyer said,
probably effectively banned from the industry,
Felipe B, the author, would probably have a very good career ahead of him if he was to write
a book about this.
You know what?
I would read that book.
Your theory here, if Felipe V, if you're listening, I think.
feel like this is you've you've created your own story.
Well, that was,
that was the name he used to publish his first book,
bully.
And I,
it just seems like maybe an opportunity there.
It feels very,
like it's got a wulfle wall street angle to it.
Yeah.
Like,
it's like,
you know,
a bad person who's been punished,
then comes out and writes a book about all the bad things they did.
And then it gets turned to do a,
that huge movie.
And then you get wildly successful.
from that. I feel like this could have an angle like that. I'm, I don't think what they did
was right by any means. I think that they, they were punished. I don't think the punish was
nearly as severe as I would have expected, but also, you know, my bigger questions would be,
A, can they control the compulsion? Because let's be honest, yes, it's probably going to be tough.
And, and be, are they themselves going to license the story, or are they going to do it themselves
because that's interesting.
Imagine being somebody sitting in who sued them for the 88K penguin?
It was he had to, yes, he had to pay back Penguin for legal costs and then costs they accrued trying to figure out who this hacker was.
It probably ended up paying for some of those cybersecurity professionals.
Totally.
Imagine being the literary scout or one of the literary scouts that was conned by him and then later receiving his manuscript about how he conned you.
You little shit.
And having people and having like big companies like penguin who were conned by this person,
then bidding for rights on the story about how they were conned.
Right.
I like that in itself is another book.
It feels like people,
it feels like when he starts pitching this book,
there's going to be a lot of people that slam the door in his face.
But the real flex would be to recognize if we take our ego out of this,
this is a really, really good story.
Well, let's just, and here's the thing too,
is that I just think that those are monies,
sorry,
those are industries dominated by money and revenue,
shareholder return.
They can't,
it would be,
it would be against their fiduciary responsibility
to turn their eye on something.
To not publish this book about how someone did crimes at them.
Exactly.
I can just see the cutscene at the end.
Like, isn't that the wolf of Wall Street?
There's a cut scene where the real,
that's literally how the Wolf of Wall Street ends.
Can't you see that happening?
here.
Everyone's reading the book and the person who hacked all the authors wrote about the time
they hacked all the authors.
Yeah.
Completely.
It will inevitably be a movie.
Too many people, even if it's not Felipe O.B. writing about it.
Like I said at the beginning, this all kind of popped off during the pandemic when a bunch
of journalists were stuck inside.
It is so thoroughly reported on.
There's so many great.
long form, really long form articles that a person could license if they wanted to make a movie.
Now this episode of this podcast, get in touch.
Well, look, my mind jumped to Michael Lewis.
This just felt very, you know, big short.
Like, I've read all Michael Lewis's books that's great at the stuff.
The books that he's written, the screenplays that they get transferred into also great.
I feel like this has just got a natural, you know, large cast, lots of locations.
You know, it just has a big short vibe to it.
know, multiple storylines running in the same direction.
Yeah, I don't know.
But I think that if this isn't going to be you, Felipe, or, you know, maybe call Michael
Lewis.
I'd love to read the Michael Lewis take on this and watch the screenplay adapted off of his book.
Anyway, those are my end thoughts.
What about you, Jay?
I'm just going to end with a quote from an author named Felipe's first book, bully.
I don't even know that I agree with this quote.
but it sure is relevant to the story.
Quote, there is a relationship between tormentors and victims,
something close to a real friendship or even love.
A person cannot live without the other,
just as the tormentor cannot live without his victim.
