Skip to Primary Navigation

Transcript: Jeremy Sheridan podcast

Jeremy Sheridan
GRIP Montage: FTI Consulting

Alexander and Jeremy discuss how organizations should approach the risks and security implications of cryptocurrency, blockchain transactions and AI-enabled fraud

The following is a transcript of the podcast episode Jeremy Sheridan on AI, blockchain and financial crime investigations between Deputy Content Manager Alexander Barzacanos, and Jeremy Sheridan, Managing Director at FTI Consulting.

[INTRO]

Alexander Barzacanos: Financial fraud is not new, but artificial intelligence, digital payment systems and cryptocurrencies are changing the speed, scale and sophistication of the methods available to bad actors.

At the same time, digital assets present something of a paradox. They can be used to move funds quickly across borders, but blockchain transactions can also create an unusually durable record for investigators trying to trace stolen assets and identify the people behind them. AI is also making it easier for fraudsters to tailor more convincing schemes and carry them out at greater scale.

To discuss how financial crime is evolving, I’m joined by Jeremy Sheridan, a managing director at FTI Consulting and the former assistant director of the US Secret Service’s Office of Investigations.

Jeremy, welcome to the podcast. Thanks for joining us.

Jeremy Sheridan: Thank you very much for having me.

Alexander Barzacanos: You spent many years at the Secret Service, where you were instrumental in creating its first dedicated digital asset investigative unit. Can you tell us about your time at the agency and how financial crime has changed, particularly as cryptocurrencies have become more popular?

Jeremy Sheridan: I spent almost 25 years with the Secret Service. We’re certainly well known for the dark glasses, earpieces and bad haircuts, but I also spent much of my time in the investigative realm.

I retired as the assistant director of the Office of Investigations, where I led the agency’s investigative mission to protect the nation’s financial and payment infrastructure and enforce laws involving payment systems and financial fraud.

Because of my age, I began in an investigative environment that was less digital in nature. We were primarily focused on identity fraud, credit card fraud, money laundering and similar investigations.

As my career progressed over those 25 years, however, the adversary modernized and evolved toward a more digital approach, primarily through the use of cryptocurrency, digital assets and virtual assets as both the means and the method for executing financial crimes.

As an agency, we had to lean into that investigative capability, both in terms of personnel and resources. We needed to understand the technology, investigate its use effectively and bring consequences to those employing it for criminal purposes.

Alexander Barzacanos: Who are those adversaries typically?

Jeremy Sheridan: It runs the gamut. The thing about digital assets or cryptocurrency is that they represent a unit of value, and anything involving value will attract criminals.

At one end of the spectrum, you have large-scale state actors such as North Korea, which focus on crypto assets because of their value and the way they can facilitate criminal activity. At the other end, you have individual actors who may target smaller entities but still recognize how digital assets and cryptocurrencies can be used to execute a crime.

There isn’t one type of entity, population or profile associated with criminals who use cryptocurrency. It would be like asking, “Who are the criminals who use money?” It is something of value, and that attracts criminal activity.

Alexander Barzacanos: Around when did this become something that the Secret Service had to begin focusing on?

Jeremy Sheridan: I think our earliest cases were probably around 2012 or 2013, not long after the value of crypto assets really started to explode.

When cryptocurrency first entered the financial environment, it had very little value and therefore was not particularly attractive to criminal entities. Once its value began to rise significantly, criminals became interested in using it.

That happened at roughly the same time that the credit card payment system was being modernized through chip-embedded technology, which made it harder to commit financial crimes using credit cards and electronic payment systems.

As with anything involving crime, once you focus enforcement on a particular area, you squeeze the balloon and the criminal activity moves elsewhere. Cryptocurrency happened to be exploding in value at the same time that credit card fraud was becoming more difficult. Criminals began recognizing the advantages of cryptocurrency as a way to execute crimes.

But I want to be clear here. We began this conversation by discussing criminal activity involving digital assets, but I think cryptocurrency and digital assets have often been mischaracterized through a false narrative that they are solely tools for criminal purposes, or that the only reason they were designed was to commit crimes.

That may have been the cloud around the technology in its early years. Many people viewed it that way because they didn’t understand it and because criminals were using it. But then, as now, criminal activity involving digital assets is dwarfed by the criminal activity conducted through traditional financial methods and fiat currencies.

Criminal activity represents less than half of one percent of overall digital asset transaction volume. I don’t want to frame cryptocurrency as solely a criminal tool.

Alexander Barzacanos: That’s a great point and definitely worth mentioning.

There is a common perception that crypto transactions are fully anonymous and that stolen funds are effectively gone once they have been transferred. How accurate is that perception? What can investigators learn from blockchain transactions that they might not see in traditional payment systems?

Jeremy Sheridan: It has been said that cryptocurrency transactions provide a source of evidence without peer. That isn’t my quote; it came from a judge in a case, although I don’t remember the exact case.

The judge’s point was that the immutability and recording of crypto transactions on a blockchain ledger provide a phenomenal and unchangeable source of evidence concerning financial transactions.

From a law enforcement perspective, cryptocurrency crimes can therefore be much easier to investigate in some respects. Investigators can identify transaction flows, assign attribution and understand the origin, intermediary points and final destination along a financial chain.

As you said, people initially believed, incorrectly, that cryptocurrency transactions were fully anonymous. I think very few people believe that now. They understand that the transactions are pseudonymous.

The “pseudo” part is that the identifiers appearing on-chain are cryptocurrency wallet addresses rather than the individual customer identifiers we ordinarily understand, such as a name or address. But the transactions still provide documented evidence of the flow of funds.

It requires specialized tools, specialized knowledge and a particular investigative skill set to translate that transaction history into understandable and presentable information.

It is even more difficult to go beyond a list of wallet addresses and transaction steps and connect them to an actual person or entity. That becomes particularly complicated when someone takes overt action to make attribution harder through anonymizing techniques, privacy tokens, chain hopping, mixers or other methods of obfuscation.

Once those elements are introduced, the investigation becomes more complicated.

Alexander Barzacanos: Out of curiosity, you mentioned chain hopping and mixing. What are those strategies?

Jeremy Sheridan: Any time you can break the visible transaction chain between the point of origin, an intermediate stop and the final destination, you make the investigator’s job more difficult.

That can be done in several ways, including switching blockchains through a bridge. People often talk about “the blockchain” when, in fact, there are thousands, if not tens of thousands, of individual blockchains in existence.

Depending on the chain, an asset held on one blockchain may not be capable of being transacted on another. Some blockchains certainly have a degree of reciprocity and allow assets to be transacted across multiple chains.

Moving an asset from one chain to another through a protocol or mechanism known as a bridge can disrupt the clear, start-to-finish transaction chain.

Similarly, certain wallets or tokens employ methods that obscure the destination of a transaction from its origin. That also makes the investigative process more difficult.

Alexander Barzacanos: The other emerging technology I wanted to address is, of course, AI. Could you tell us about the current state of AI-enabled fraud and where you think companies are most vulnerable?

Jeremy Sheridan: The current state of AI-enabled fraud largely involves facilitating misrepresentation and manipulation targeting companies and individuals.

It allows scammers and fraudulent actors to create documents at scale that are tailored to appear as though they came from a particular individual or entity. Those documents can appear legitimate and fool an unsuspecting victim into sending funds, completing a transaction or providing information to the bad actor.

This is often coupled with some form of deepfake technology or methodology. AI can be used to misrepresent the author or originator of information and tailor it to individual locations, languages and cultures. That allows fraudsters to target people around the world without raising the suspicions of whoever receives the information.

They can do this at scale while tailoring the approach to individual companies, locations and targets.

They can also build a strong rapport with the target. In my opinion, that is one of the core elements behind the success of criminal activity involving AI and misrepresentation. When you can get the target or victim to believe you and feel a connection with you, you are much more likely to persuade that person to send funds.

Alexander Barzacanos: Circling back to your blockchain expertise, you’ve written about the potential role of blockchain in verifying the origin and integrity of data in situations where there may be concerns about AI. How developed are those tools today, and where might they be most useful?

Jeremy Sheridan: They have a long way to go. The technology and the capability exist, but they haven’t been applied fully or at sufficient scale to leverage all the advantages of blockchain technology.

In my opinion, the veracity of data and the believability of information are going to become major considerations as AI becomes a greater part of everyday life.

It is going to become difficult to believe information, even when it appears to come from a verified source. That will erode trust in institutions and in systems that depend on information being shared within trusted environments.

Blockchain technology creates an opportunity to verify source information through digital signatures and blockchain-based cryptographic techniques. These techniques can authenticate data and demonstrate that it has not been altered between its origin and its destination, or between transmission and receipt.

A cryptographic hash value can be assigned to the data. When the information is received, that hash can be checked to verify that the data is authentic and came from its stated origin.

You can also use blockchain-delivered smart contracts programmed to check the integrity and authenticity of data used by AI before that data is allowed into a particular application.

Overall, cryptographic verification could help preserve trust in information by confirming that it came from a verified source, has not been altered and can be trusted.

Alexander Barzacanos: You said that some of this technology is still a long way off. What do you recommend firms and individuals do now to protect themselves against AI fraud?

Jeremy Sheridan: I don’t know that I would say the technology itself is far away. It is far away from being widely applied. Both technologies exist, but merging the two is technically complex.

I think adoption will accelerate as more AI-enabled fraud occurs.

As with our discussion of cryptocurrency, I also don’t want to present AI solely as a tool for adversaries. For as many vulnerabilities as it creates, I think it creates an equal number of advantages.

For example, many cryptocurrency models use AI analytical tools to ingest data concerning every element of a transaction or customer. That can support transaction verification, customer identification and the approval or authorization of transactions by customers.

I don’t want to present AI as solely negative. But to answer your question, as we move toward applying blockchain technology and data-verification techniques to AI systems, I don’t think we will ever be able to separate out the human element.

Entities that receive or process financial information, or operate transaction systems that leverage AI, need to apply manual review to potential risks, abnormalities or anomalies identified by AI.

They need to train, equip and prepare personnel to conduct technical forensic work and verify authenticity. Until blockchain-based cryptographic signature capabilities are widely in place, they also need to conduct metadata analysis around transactions.

Firms should continue using pattern analysis and cross-document verification to check AI-generated or AI-simulated documents against comparable or known verified documents.

They also need independent corroboration. They should not rely on a single point of failure, whether that is an automated system or a human-reviewed system. There needs to be a marriage between the two so that information is compared and checked for authenticity, approval and authorization.

Alexander Barzacanos: Finally, I wanted to ask a general question. Looking ahead, what risks do companies or policymakers still underestimate when they think about digital assets, AI and financial crime more broadly?

Jeremy Sheridan: I would put the risks that need to be understood into two categories.

The first is regulatory and policy risk. As it relates to digital assets and cryptocurrency, we still do not have a unified legislative and regulatory approach at the federal level in the United States covering cryptocurrency and digital asset transactions, payments and payment systems.

There is certainly legislation concerning stablecoins, and other legislative approaches are in progress. But my concern is that the issue is becoming politicized along party lines, which will impede progress.

I also think much of the legislation proposed to date has focused on restriction rather than enablement.

My hope is that we can move forward, achieve security and still leverage the benefits, capabilities and technological innovation offered by blockchain, cryptocurrency and digital assets in both decentralized and centralized financial environments.

Those are very ambitious goals, and they certainly aren’t easy to achieve. I don’t mean to be overly critical, but I think this is a bipartisan issue that would benefit everyone. I hope our legislators can come together and finalize an approach.

The second category concerns data veracity and verification, which we have already discussed to some extent.

AI and cryptocurrency are both developing extremely quickly. When technology moves this fast, criminal organizations are often early adopters, and they have effectively unlimited budgets. They will move very quickly into these areas in search of criminal gain.

Unfortunately, the protections tend to lag behind and operate in response mode rather than staying ahead of the criminals. That is true across law enforcement, legislatures and regulatory agencies.

Individuals often suffer the consequences. You can see that in the novelty of these technologies.

Many people pursued cryptocurrencies because of the hype and the prospect of rapid increases in value and profit. But they entered the market without fully understanding how the technology worked, its vulnerabilities or the threats targeting its users.

We see a great deal of victimization because people don’t understand the technology. They get involved, make mistakes, fall for scams or transact in ways that result in losses.

That is my concern for both entities and individuals. As AI, cryptocurrency and tokenized payments continue to develop rapidly, without understanding and comfort catching up at the same pace, they will create further opportunities for loss.

Alexander Barzacanos: I think that’s an excellent analysis of the situation and a great note to end on.

Jeremy, thanks again for coming on.

Jeremy Sheridan: Thank you.

Listen to the audio.

Get full access, free for a month

This is a free article. Try Premium free for 28 days to get every article on GRIP and more – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience