John Sileo lost his entire net worth and software business after his partner stole his identity, a devastating betrayal that inspired the Hollywood movie Identity Thief. While Stacy Sherman sat in an audience of 1,000, he accessed her phone in under three minutes, showing how quickly human psychology can be manipulated to bypass security defenses.
When protection fails, or identity verification feels painful, people experience immediate anxiety, fear, and frustration. How clients feel during these vulnerable moments defines their total impression of your brand. Preserving personal details is not a back-office technical task; it is the highest-stakes emotional experience in the entire customer journey.
What You Will Learn
-
The $25 Million Deepfake: How criminals are cloning executives’ faces and voices on live video calls to trick employees into wiring millions of dollars.
-
The $5 Billion Human Error: The single forgotten button that caused the massive UnitedHealthcare breach, and why your biggest threat isn’t technology—it’s your people.
-
The Airplane Hacker: Why opening your laptop in an aisle seat allows the row behind you to zoom in and steal your passwords and corporate spreadsheets.
-
The “BS Reflex”: The one critical instinct only 1 in 1,000 companies teach their customer service teams that stops hackers dead in their tracks.
-
The AI Data Trap: Why everything you type into AI platforms is being indexed, and the default privacy settings you must change today.
Podcast Episode Chapters
0:35 The Identity Theft Story That Inspired a Movie
1:12 Framed by a Best Friend: The Insider Betrayal
3:13 Default AI Settings and Data Exposure Risks
4:41 AI Deepfake Impersonation Scams and Live Video Deepfakes
6:29 Doing CX Right®: Why Safety and Customer Feelings Are Connected
9:29 Corporate Breaches: Human Decisions vs System Failures
13:27 Security Protocols: Protecting Clients Without Creating Frustration
17:04 Customer Anxiety: Managing Risk to Prevent Flight
19:30 Stage Demonstration: Accessing My Phone in 180 Seconds
23:00 Instant Image Manipulation and Fake Media
25:26 The Verification Reflex for Customer Service Teams
26:57 Visual Privacy and Travel Security Risks
31:08 The File Metadata That Proved Innocence
34:55 Practical Daily Defense and Values-Based Leadership
Press Play To WATCH On Youtube
Read Full Episode Transcript
Full Transcript: AI Deepfake Warning: Stacy Sherman’s Phone Hacked In Front Of 1K People
[00:00:00] Stacy Sherman: Hello, John. Welcome to the Doing CX Right show
[00:00:06] John Sileo: It’s so good to be here. Thanks for having me on
[00:00:09] Stacy Sherman: Oh, this is a special episode like no other, and people are gonna soon find out. If they don’t already know you, this show will change their life. I guarantee it. But before I say more, can you share a little bit about why have you dedicated your professional life, your life, not even just professional, to educating people about cybersecurity?
Can you share your fascinating backstory?
[00:00:41] John Sileo: Yeah, I’ll give you, I’ll give you the short version. Um, I’ve, I’m a two-time victim of cybercrime. So the first time was kind of a garden variety. Uh, a woman stole my Social Security number out of some unshredded trash that I had thrown out, um, used it to buy a home in Florida, declared bankruptcy [00:01:00] on, uh, the home, my life, my savings, uh, drained our life savings.
We kind of had nothing at that point, and, uh, it was all done by a female, which is, um, you know, a little bit odd, and that’s why it became the, the basis of the movie Identity Thief with Jason Bateman and Melissa McCarthy, um, which about the first third of the story is very much like what happened to us.
It happened in Denver. She moved to Florida. They went cross-country together. It was, it was a, you know, a comical version of it. Um, and unfortunately, while that was going on, I had a second case of cybercrime, uh, that was a- an inside job, um, where our business partner used my identity to embezzle from all of our clients, and that was much more serious.
I had a two-year criminal trial that I faced, lost the business, lost, uh, every ounce of net worth that we had. Um, spent a ton of time away from, from my wife and daughters, which was actually probably the hardest part of [00:02:00] all, was, was watching my girls grow from, you know, small to medium in that time. And, uh, at that point, you know, I, I literally, I’d lost everything: the business that I had started, the software company, our, our, our, uh, savings.
And my wife said to me, “You know, you gotta do something with this.” And, uh, so I did. I wrote a book, and the book led to s- you know, speaking tour eventually, and that’s what I’ve been doing for the last, uh, long bit of time is, is keynoting conferences and trying to inspire people to care about this topic before they go through what I went through.
[00:02:34] Stacy Sherman: Mm. The first incident that you had, did that prepare you for the second in any way?
[00:02:42] John Sileo: You know, it would’ve if they hadn’t have been simultaneous. So what happened is the inside job that happened to be, um, uh, uh, performed by my business partner and best friend, which makes it even worse, um, he took advantage of my first [00:03:00] case, and I was so distracted by the identity theft case that then when he was committing these insider cyber crimes, uh, I just wasn’t paying attention like I should’ve been.
So had I known beforehand, um, k- kind of the lesson that I learned, and I’ve mentioned it, you know, when we’ve worked together and, on speeches, um, is all I- all, uh, security is personal first. Like it starts at home, how we protect our smartphones and online accounts, our kids, our parents, and so forth, and that’s really where all security begins, and that’s the lesson that I would have learned had I had time before, uh, crime number two started taking place.
[00:03:41] Stacy Sherman: So in this AI world, and everybody’s giving their information to AI platforms and chatGPTs and Claude and, what’s your perspective? I mean, everybody’s, everybody’s doing it. Our data is showing, as you say
[00:03:57] John Sileo: Y- perspective, wow. [00:04:00] Um, it’s all moving so fast. I’m not sure there’s any great, uh, uh, really educated opinions on it. We don’t know what they’re collecting and how they’re using it. We know that they are collecting and that they are using it. Um, of course, you and I and everybody else probably on this podcast has to use it to some degree, right?
To stay competitive. Um, but it’s kind of goes back to, to security lessons from everything else when we started with email and internet, which is you’ve got to change your defaults. You’ve got to set it up to begin with so that you are not as, uh, at, at much risk as everybody else is. And as you lower your footprint and your profile using that I- AI, it becomes safer.
Now, of course, there’s also, you know, phishing scams that are now created by AI, so there’s no grammar or spelling errors. There’s, uh, deep fake videos, and there’s just so much more now for businesses and in- [00:05:00] individuals to, to consider from the, the advent of AI and cyber. Um, it’s a little bit mind-numbing
[00:05:08] Stacy Sherman: It is mind-numbing. And as a podcaster and as speakers, I also think about how easy it is to clone my voice and, and be me even though it’s not me. That is so frightening
[00:05:22] John Sileo: It’s, it’s frightening and it’s expensive. Um, what we’re seeing a lot of are w- you know, what we call business communication compromise. That’s the technical term. It used to be business email compromise. Essentially, it’s when somebody is impersonating someone in power and they’re doing it now, uh, on live Zooms, on podcasts, uh, with Slack, with text, with email, um, and using deep fake videos to pose as a person in a position of power.
You know, and, and if you’re at an organization and your boss is on the video saying, “I need you to write this check,” like, uh, an engineering company did for [00:06:00] $25 million, “I need you to write, uh, to send this money,” it was a wire transfer. It’s very hard for a, a subordinate employee to think, “No, I’m not gonna do that.”
They just– they click in and think I, “I’ve got to do what’s on the, on the video.” So AI has really changed the shape of it utilizing deep fakes and disinformation.
[00:06:20] Stacy Sherman: Hmm. So for my listeners, those that may not have been at the National Speakers Association where John and I first met, um, my phone was hacked in front of nearly 1,000 people, and it was so impactful. I wanna talk about that, but I’m gonna save it till later because there’s so many topics to discuss, it could take up the whole show.
So I’m giving everybody a little teaser, because this story I will never forget for the rest of my life, and the lessons. So I’m gonna pause on [00:07:00] that for a moment and talk about, first of all, John, this is the Doing Customer Experience Right show, and doing customer experience has a lot to do with feeling safe, secure, risk mitigation.
So when I say customer experience in the industry that you’re in, what does that mean to you?
[00:07:22] John Sileo: You know, to me it means it kind of boils down to trust. Um, there’s such a common misconception because cybersecurity and security in general can be inconvenient, right? We, we all have those extra codes we have to put in and changing our passwords. But I want to tell you, customer experience and cust- and cybersecurity are not opposites.
Um, if they are done right, if cyber is done right, and that means it’s thoughtful in advance, it’s prepared before the hack, like we’ll talk about the iPhone hack. If it’s prepared before that happens, cybersecurity creates a [00:08:00] deep trust and loyalty with customers, and they, they’ve started to begin to expect this because, um, you know, in the end, there’s nothing worse than having your identity or your money or your private information stolen, and that is a bad customer experience
[00:08:17] Stacy Sherman: Mm. So true. So I love your saying your data is showing. It’s funny, and yet the reality of cybersecurity is devastating. Can you talk a little bit about when you say your data’s showing, what does that mean? What is the gap, and how seriously leaders need to protect that?
[00:08:41] John Sileo: Yeah, I think just starting at a personal level, you know, with, um, the introduction of social media, with, uh, you know, smart devices, smartphones, Internet of Things, connected TVs and refrigerators, um, people just weren’t used to, to thinking first, you know, “I got to [00:09:00] build security in by design from the start.”
Um, and companies made it frictionless to just skip those steps. So your data is showing means everything you put out there on social media is available to anyone. Um, and we can talk about that in, in, you know, the hack that happened at, at the conference. Um, everything that you put into AI is being indexed and shared.
You are part of the model unless you make the changes so that you’re not. And then that ripples into the, the business aspect of it, of, uh, you know, is your, is your website revealing, uh, a pathway into your company? We call it island hopping. You know, have you protected it so that they can’t move from your website into your, your business, um, you know, your CRM system or, uh, the data that really runs your company?
And, um, most companies don’t [00:10:00] actually take a look until they get hit. It’s the same lesson as mine. I’m not holier than thou. They don’t think about it in the depth and degree that they need to until they have been hit. And consequently, their data is exposed all over the place by employees using shadow IT, by, you know, using Dropbox or, um, chatGPT on a, uh, a personal basis, but on a work computer, for example.
Those type of things are constantly being missed by companies, and they’re, they’re actually very solvable
[00:10:33] Stacy Sherman: All right, so let’s talk about Solvable. Um, and you don’t have to mention client names, but can you share a little bit about some of the use cases and, like, the problem and the action that they’ve taken that others can learn from?
[00:10:49] John Sileo: You know, Stacy, in almost every use case, and you will have seen it, you know, at the, at the NSA speech, it’s a human [00:11:00] decision, a bad human decision. It’s not very often the technology itself that fails, and that’s a, I think a common misconception about cybersecurity is this is all a technological problem.
It’s actually a technology matched with, in general, a bad human decision. So for example, when, um, uh, UnitedHealthcare, right? Which we all heard about their breach, uh, a year or two ago. It was, uh, uh, Choice was the, the particular branch that was, that was hacked. Um, they d- hadn’t– They had purchased and never turned on two-factor authentication, something that I guarantee you have got on, your listeners have got on.
You know, they’ve got two-factor, two-step logins on their banks and their investments. Well, UnitedHealthcare had purchased it. They could deploy it, and they didn’t. And that one mistake, that one human choice not to do that is what allowed hackers to get in. And $5 billion later, [00:12:00] they are, uh, still dealing with the aftermath of Choice Healthcare having been breached and that, that working through the system.
The same is true of MGM Grand Studios. It was a human being who, over the phone, thought they were talking to an employee and gave away a password to an administrator account that allowed access. And $100 million later in that first week, they started to think, “Wow, we have to train our people to detect these type of breaches before they happen.”
And that’s probably the most, uh, for businesses, that’s the most overlooked aspect, is you can’t just have the good technology. You have to have the people who know how to, to apply it and, and utilize it to best effect.
[00:12:43] Stacy Sherman: So is this a training call out for leaders? Is this a, like what, what is the go do tomorrow?
[00:12:54] John Sileo: It’s a cultural call-out, which is, um, if you’re not taking care of your [00:13:00] people and yes, training them on protecting their own identity, they’re never going to, uh, build a culture of security beyond them as an individual in the organization. So yes, I would say that, um, you know, the, the average missing piece of the puzzle and, and, you know, I talk about it in terms of how a blockbuster movie comes together.
You’ve got heroes in a risky setting that are attacked, um, and defeated, and then that’s when they start to bring on a team, think about a plan, and achieve victory. Well, there are gaps in every one of those frames of, of the story, and probably the biggest one of all is the very first one, which is the heroes.
If you’re not training your people on the other five quadrants, there’s absolutely no way you’re gonna stop the, uh, the new forms of attacks that are out there.
[00:13:53] Stacy Sherman: Hmm. It reminds me, you said how every employee, everyone has to [00:14:00] own and be accountable for security and safety, especially of customer data, never mind their own. And in the customer experience world, so many people say, “Eh, not my job.” They point to somebody else, and I’m out there yelling from the rooftops that, “No, you have that role regardless of job title.”
So it’s really similar
[00:14:28] John Sileo: Yeah, that, that, um, that ownership as you call it, that buy-in, um, is, is so critical and sometimes we don’t, we don’t enact it until we feel it. I know on a customer experience level, you know, I was on the, the phone for several hours the other day trying to, to right a healthcare thing that was so frustrating and it made me think, “Okay, you know, I get the sense of when, when somebody’s implementing a cybersecurity control like, you know, two-step [00:15:00] logins or pass keys and we don’t understand it, how frustrating it can be for people.”
But I think one of the key things here is that businesses really need to, to understand what’s at stake, what data is most important, what they actually need to protect, what they don’t wanna spend the time on, and then the friction that they cause from security needs to match the risk that they’re facing.
And what a lot of businesses do is they just boil the ocean, right? They wanna secure every last thing, and it’s just, it’s too costly. It takes too much, too many resources, too much time. So you gotta make sure that that friction matches the risk so that, A, the customer experience is good. They have as little friction as possible, and when they have it, they know that it’s protecting them.
And inside of the organization, the IT team isn’t, isn’t tasked with solving every last security thing because it just can’t happen
[00:15:56] Stacy Sherman: Hmm. I kid you not, [00:16:00] yesterday I tried to buy something on Amazon and my credit card did not go through, but I never got a alert from the, um, credit card company that there was a hack or anything. So I tried again and it didn’t go through. And so I called the credit card company and they said that I– they couldn’t help me until Monday.
I can only activate a card on the weekend. And I’m thinking, “How is that possible? How can, how can I have no human to talk to to fix this problem that I can’t use my card?” Or, or the anxiety I feel around why can’t I use my card? So it’s, it’s customer service. Like when you’re feeling that anxiousness and fear, it, it is so essential.
Much more than, “I got a product I wanna, you know, exchange for a different size.”
[00:16:56] John Sileo: Yeah. Yeah, that’s th- um, that [00:17:00] feeling of, of lack of control, of powerlessness, it’s petrifying when you’re the one who on Friday night at, you know, 10:00 discovers this and can’t do something until Monday morning. It, it’s crazy. I can’t imagine that. Most large credit card companies, you should be able to go on the app and freeze it, find out what’s going on, release it if…
so that you can make the Amazon purchase. Um, but that, that anxiety is, um, you know, and mind you, cybersecurity, we have a lot to learn from customer experience as well, right? Of, of, um, not just being all about security. We also have to be about experience because people aren’t gonna do it if it’s too inconvenient, if, um, if there’s too many hurdles to protecting themselves.
So there’s, there really is a, a, an interplay here that we have to pay attention to.
[00:17:52] Stacy Sherman: Yeah. I’m glad you said that because the user experience of these different platforms, if it’s not easy, if [00:18:00] it’s not frictionless, like that’s gonna play into how much people are taking the extra step. It sounds logical, no duh, that you would do that, but obviously they’re not. Um, and I think that just like in the customer experience world where we design an experience how a customer learn, buy, get, use, pay, and get help, in that journey mapping, I believe, and I’m getting educated talking to you, is that we need a security m-moment.
Like does this spot require in the journey to be an AI, a human, a, a, a double check two, you know, two factor or not? Like that has to be very intentional
[00:18:49] John Sileo: Absolutely, and I love that you included the word human because there, at some point, there has to be, uh, an understanding of the emotion behind it, not just the, the [00:19:00] large language words that are, you know, put together. And, and that’s one thing in cyber that companies have to be really careful of is when the two-step login is not working and you can’t get into the darn account, you should be able to call somebody and have a phone number that’s published that you can get to.
That customer experience is often terrible in the cybersecurity world, and we really have to, to pay attention to that because having h- having the solution to that problem like yours, um, you could lose a customer over that, right? You could lose thousands of customers over that
[00:19:36] Stacy Sherman: So in September, coming soon, I have a report, a commissioned research, that talks about the importance of emotions in customer experience and driving loyalty. So many companies are so transactional and logical, and I’ve been saying, actually, emotion is the experience. [00:20:00] And so when you just talked about the anxiety and the fear, many companies are saying, “Well, we don’t really need to pay attention to emotions.
That’s fluffy.” And I’m saying, “No, no, no. Actually, now my data shows that if you make one mistake, it takes six positive consecutive experiences to make up for that one.” Six. And there are a ton of other statistics in this report, and it’s gonna be… It’s free, so I’m gonna put it in the show notes for people to download.
But the fact is that for companies, they have to realize that the anxiety and the fear factor with cybersecurity and breaches, it l- as you said, it can lose a customer. In fact, not only will it lose a customer, people are gonna tell others, “Do not buy from them.” That ripple effect.
[00:20:57] John Sileo: Absolutely, and it’s, it’s [00:21:00] devastating once it’s unleashed, and we have seen it. I mean, the same is true in, in cyber. You have a breach, and that unleashes all kinds of negativity and customer flight and so forth, and the same is true with, with, uh, customer experience. When you have that bad customer experience, what do I do?
I’m lucky if I just go off and tell 10 people about it. For those people who use a lot of social media, they’re telling thousands of people about it
[00:21:25] Stacy Sherman: Well, also with social media and what I’m learning a lot from my study is that AI is using the sentiments across the web, the negative and positive, and using it to recommend or not recommend brands. So if anyone’s out there saying, “I feel such risk interacting with X brand,” or, “This happened to me, and I had– they weren’t helpful in solving the breach or solving the security and the billing [00:22:00] issues I had,” they– the AI is going to actually punish you for that
[00:22:06] John Sileo: Interesting. I, I can believe it because it is, it’s pulling together knowledge that does come from emotion and translating it into numbers and, and words and facts, and those make it all over the web
[00:22:21] Stacy Sherman: Hmm. All right, so I’m gonna share the story, the big story, and we’ll talk about what can people do. What can people do as customers of brands, and what could leaders who are listening to the show do? So Oh, how to wrap this up really quickly ’cause it is a big story. So when I was at the National Speakers Association, I was among almost 1,000 people, very in tuned to John’s presentation.
And it was about cybersecurity and backstory, [00:23:00] as you just heard. And so he came up to me, uh, after looking at the crowd to decide w- whose phone is he gonna hack? He’s gonna prove a lesson of the importance of, of security and even your phone. Now, John and I had never met. He asked some questions when he came to me, chose me.
And by the way, I did not realize I was on these big screens in the room, almost like, like candid camera on me. I didn’t even realize. So everybody in the room knows now it’s me.
[00:23:34] John Sileo: Your face was priceless.
[00:23:36] Stacy Sherman: I’ve heard that. I can’t wait to watch it. So, so you asked me a bunch of questions about things that are very common on the web.
Anybody could have found this. So I answered out loud, not even thinking twice about all the people that are in the room that are hearing my answer anyway. Like, I, I just was, like, [00:24:00] going with it ’cause I was so confused, and I was like, “There’s no way you’re gonna hack my phone.” Like, I have a r- I have a really good password on my phone, and, nah, he’s, he’s not gonna do it that quickly and, and such.
Well, anyway, so to my surprise, you did. You hacked my phone. And the questions that you had asked me, none of them actually happened to be associated with the specific code on my phone to access anything. Well, I and the audience, the room was flabbergasted. Like, “Oh my God, how did that just happen?” I mean, it was j- it was so much commotion during and then even after the event.
So you had kindly invited me to the stage so that we could talk a little bit more, and you showed the audience how much more you were able to dig into my life in a safe way. [00:25:00] But it, it changed me forever. So can you share a little bit from your angle? Because I was having an out-of-body experience. Though I did see you pulled up pictures that were just so funny and scary at the same time.
Can you share a little bit from your angle, uh, ’cause you were really in the moment, as I was on a cloud
[00:25:26] John Sileo: Absolutely. And, and I, you know– So what I was doing was socially engineering you, right? I had you caught off guard. I was going quickly. I was asking questions, some that mattered, some that didn’t. I had you on a cloud. I brought you up onto the stage. You’ve got a thousand people staring at you, many of them who know and revere you.
And, you know, in that moment, your thought processes are mine, right? I’ve socially engi– I’ve manipulated you into doing what I need you to do to get into that phone. And then as you saw, once you’re in the phone, [00:26:00] you know, then I, I did do a down swipe and type in the word bank, and I know where you bank. By the way, I made that up so that nobody would actually know where you bank.
But, um, you know, you’ve got so much access. That phone is becoming the authentication device. It’s the, the keys into everything. And then, yes, there were pictures that were on that phone of you with friends and colleagues, not with me, ’cause we had never met. And, uh, those were quickly manipulated by AI in the timeframe from when I first got to your phone to the point when I brought you up, and that was about a three-minute period that, uh, AI was able to go in, alter those photos, uh, embed them in my presentation, and have them ready, uh, so that, that I could show them.
It was, you know, you and me playing pickleball together, you and me, uh, at a, at another s- uh, speaking event that I certainly wasn’t at, and then finally, both of us at the premiere of, [00:27:00] of The Devil Wears Prada 2, you dressed in, in Prada and me dressed in a tuxedo. And these were all, you know, made-up photos, partially true based on, on your photos.
And that was an example both of the power of the smartphone, the power of somebody who knows how to talk you out of the keys to the kingdom, and the power of AI to produce very rapidly, very, um, authentic-looking photos, videos, and audio that really can change your perception on, on w- what reality is
[00:27:35] Stacy Sherman: The other part of this story, I still can’t believe it happened, was that when you hugged me and thanked me and sent me nicely off the stage, I left without my phone. And the audience is, like, taking care of me. They’re, like, whispering like, “Stacy, Stacy, your phone, your phone.” [00:28:00] And I went back on the stage, and I’m like, “Oh my God, I, I can’t believe I just left without my phone.”
I remember saying to you, “What the F?”
[00:28:11] John Sileo: Yes, you did.
[00:28:13] Stacy Sherman: And I just couldn’t believe the whole experience, but it really made me realize in that moment how I have to take this more seriously. I get to share more, with more people like today who you are and what you’re teaching, because everyone needs to know. And by the way, after I got off the stage and the event was over, at least 200 people minimum had come up to me and said they called their family, they’ve changed their passwords, they told their family to change their passwords, they created these, um, code words if anybody [00:29:00] calls.
Like look what, how, what an impact you changed lives
[00:29:05] John Sileo: We changed it. I mean, you were so good up there it couldn’t help but work. And, you know, and the underlying point that we’re not talking about here is, um, when you train your people, you educate your executives, your boards, your managers and employees, when you educate your vendors and your clients to have a reflex that says, “Hang on, I’m not giving any information until I know it’s legitimate.”
You know, we called it the hogwash or the BS reflex during the presentation, during the keynote. But that s- single little tool right there is the most powerful of all cybersecurity tools, and about one in 1,000 companies have ever trained on this fraud reflex that says, “I’m not giving you what you need until I verify that it’s, it’s necessary.”
That right there, that is the, the biggest takeaway for any organization is you have got to train on that internal gut Spidey [00:30:00] instinct that says, “Hang on, I need to verify this
[00:30:03] Stacy Sherman: Well, I did something for the first time when I left the event and I went on the airplane, and you know on a plane you’re sitting close to people. I never did this before until I met you, that I s- I had my laptop open and on my home screen is, like, my name, my full name, and then obviously enter my password, and I literally shut my computer, like, kind of facing me and typed where nobody to my right or left could see me.
I was so super sensitive, and I think that’s the way to be, like, when you’re that close to strangers
[00:30:42] John Sileo: Yeah, an airplane is really interesting. The number of, um, compromising photos that I can take from the next, especially the next row, you know, looking one row up. And I mean, I can… On my iPhone, I can zoom multiple times. I’ve seen, um, company [00:31:00] financial spreadsheets that no organization would ever want out.
I’ve seen passwords to phones, um, for somebody who uses physical. You happen to use facial recognition, but some people still are typing it in. Um, I’ve seen, uh, uh, private, you know, photos that people should probably not be looking at. And there are, you know, there are little screen protectors on there. But I will tell you that probably the safest thing of all, it’s so, so simple, it’s not perfect: the window seat.
You know, if the window’s over here, and you’re like this, and the people can’t see through the seats, you’re considerably mo- safer than you are on the aisle seat. The aisle is where I always get the photos, sometimes the middle. But just little thoughts like that of, okay, if I’m gonna have this computer open to something that’s got banking information or financial information, business intellectual property, um, I’m either gonna keep it down, keep it small, or, or cordon myself off a bit
[00:31:58] Stacy Sherman: I have to ask, I [00:32:00] imagine people after the event, right after we left the room, had to have come to you and said, “How did you do that?” What do you say to that question?
[00:32:13] John Sileo: I say thousands of hours of research That’s it. That’s, that’s all I can share because I don’t want anybody else going out and, and doing this. I don’t want true hackers to know what, you know, what led to that. So, um, I don’t share it. It’s, you know, it’s just a bundle of work that I’ve put in and my team has put in on figuring out how we do this
[00:32:40] Stacy Sherman: Hmm. Fair. And I, all I did is tell everybody it really happened, and y- just focus on what you can do about it. That’s,
[00:32:53] John Sileo: change that password to alphanumeric. Utilize facial recognition so that you can put a long and strong [00:33:00] password. There’s a great example of, you know, good security, which is a 20-digit password, you know, that, that is your one password into the phone. Um, and it’s effortless because you go like this to get into your phone.
You go, you, you show it your face to bank, to get into your password management software, to open your photos, whatever. That’s, that’s a good combination of security and experience
[00:33:25] Stacy Sherman: What about at airports? I started to think about the facial recognition when we go through. I never thought about that, but I did have a sense of fear. Um, like we can’t control everything, but, uh, like what do you do in those situations? You know too much. Like, do you say, “Sorry, you can’t have my face,” or are you going through and just taking extra precaution, like you yourself?
[00:33:57] John Sileo: That is a perfect example of how difficult [00:34:00] this topic is because, um, yeah, at the, at the airport, um, facial recognition speeds things up, right? And yes, you can refuse to have that. There are theme parks in which you can’t go in if you don’t give your thumbprint. Like, they will just not let you in, and, and I guess they get to do that.
Um, at the airport, you can opt out of, of utilizing your face. What I will say is your face is all over the place. Your face is attached to already to, um, an identity that is hopefully your identity. Um, and so what I do is I minimize the places that I allow facial recognition. Um, airports are one. Now, if all your face is doing is it’s representing a multi-thousand character password, right?
So it’s associated with a password. That was breached at the old Clear, um, before ClearMe, at the old Clear. [00:35:00] All of those were breached. Um, the good part is you can generally change the backend passcode that comes off of the algorithm that is made from your face, so it’s not the last time you can ever utilize your face.
But it’s also pretty easy to, to replicate, um, digitally. So in person, not so much. It’s very hard to make a, a mask that you could walk through TSA with. But online, it’s much easier for me to a-appear as you with– if I have enough video and, and photos of you. So that’s, that’s kind of the cutting edge right now of, of these deepfakes is, you know, what is…
what happens when my face is what’s used to bank and it’s, it’s, uh, AI allows us to recreate that face perfectly? Um, there aren’t answers to that yet. It’s still what, what, uh, we and, and the companies we work with are, are working on.
[00:35:52] Stacy Sherman: Hmm. Going back for a moment to your, the crime that you faced, [00:36:00] um, and, and the victim of, how did they end up finding what happened?
[00:36:07] John Sileo: Um, in the first case, the one that was made into the movie, into “Identity Thief,” um, we never actually found Rosemary Serrano, who was the woman who utilized my identity, that what Melissa McCarthy’s character was based on. Um, and that’s because most identity thieves are several layers deep. So they were using her identity to steal my identity to steal another identity, and it’s very hard to track back.
So the, the, uh, law enforcement at that time said, “We’re never gonna catch this person.” Nothing happened. I was responsible for everything. Um, the second one is kind of a complex story, but in essence, um, uh, we were… A-after these clients came after me because they knew that money had been stolen out of their systems, data out of their systems, um, there was [00:37:00] a, a meeting between myself, my business partner, who was also my best friend, and a couple other people in the company.
And, um, the business partner, Doug, said, um, “I’ve got a spreadsheet showing that all of these transfers of money, banking transfers, were legitimate,” and he sent it to me. And so I’m on the computer and on this conference call with all the important people, um, not the district attorney at that point. It was before that.
And, um, having been in the technical world, I could look at metadata. I could see when that file had been created, which he had said was years before. He had been logging all of these transfers. Well, it showed that it had been created the night before, so that was the point at which I knew he was, you know, not, not a victim of this crime.
He was the perpetrator of the crime. Um, that led us to give that evidence, along with a voicemail from his wife admitting that he had done it, um, to the district attorney, and I went from being [00:38:00] the lead suspect to being the, the lead witness in what was a two-year criminal trial
[00:38:06] Stacy Sherman: I have goosebumps. Like, I can’t even wrap my brain around this, this just, just,
[00:38:14] John Sileo: It was an awful five years
[00:38:17] Stacy Sherman: Well, y- you have, um, you are the perfect example of out of bad comes good, and you’re changing lives. And so that’s what the speaking business is. And, um, and I’m gonna have in the show notes for people to find more about your story on your website and your book and everything about you.
Um, as we come to the end, rapid-fire questions here. What is the one most important key takeaway you want listeners to go do right now?
[00:38:54] John Sileo: Uh, from a business or a personal perspective?
[00:38:57] Stacy Sherman: Both
[00:38:59] John Sileo: Both. [00:39:00] From business perspective, I think it is, um, to take a look at how you’re, how you’re dealing with the human element of cybercrime. I guarantee you technologically, security-wise, um, there’s much more attention being paid to that. But what about the employee who gives away the answer that lets the criminal in, you know, in through the back door that you didn’t even know existed?
Um, so that human element of training is absolutely critical and the most overlooked thing by far. On the personal side, um, I would say, you know, what we might do is I’ve got those 10 tips, um, on my, my, uh, blog that are video tips of what people should do. One, two, three, four, five. They’re three-minute videos.
You can enact them quickly. It talks about switching, for example, from passwords to pass keys, which are far safer. It talks about data backups in [00:40:00] case you’re a victim of ransomware, those type of things. And I’d, I’d be happy for this, this group, and I don’t share this broadly, but, um, we can put a link in your show notes to those, uh, those videos, a page of those videos so that your listeners can go and enact those on a personal basis.
[00:40:17] Stacy Sherman: That’s awesome. Yes. Yes, yes. Thank you for that. And leadership advice, the best you’ve ever received or given
[00:40:28] John Sileo: Boy, the best I’ve ever received leadership advice. Um, I think it’s just, it’s all about the people. Like you take care of the people, uh, internally, externally, vendors, and part of that, of course, is trust and security, and part of that is customer experience, and part of that is employee experience. But m- focus, focus on the people.
Profits, they are a part of business, absolutely. But man, when you put the people first, to me at, that, that’s always a winning, winning formula[00:41:00]
[00:41:01] Stacy Sherman: And do not forget that as people, we are humans with emotions.
[00:41:06] John Sileo: Mm-hmm.
[00:41:07] Stacy Sherman: Do not ignore fear, anxiety, delight, joy. You cannot ignore that, otherwise you will not sustain into the future
[00:41:19] John Sileo: No, I agree totally
[00:41:22] Stacy Sherman: And my final favorite question I’ve asked over 200 people. John, if you could go back in time and talk to your younger 20-year-old self based on what you know now that you didn’t know then, what would you tell the younger you?
[00:41:38] John Sileo: Oh boy. What age am I going back to?
[00:41:41] Stacy Sherman: Twenty
[00:41:43] John Sileo: 20. I’d say take yourself less seriously
[00:41:48] Stacy Sherman: Tell me more
[00:41:51] John Sileo: You know, there’s, there’s so much, um, there’s so much pressure to perform and define success according to societal [00:42:00] terms that, you know, that it’s about money and status and ego and, um, really you kinda get through all of the crap that I’ve been through and you realize now it’s about the three or four really close friends I’ve got.
It’s about my wife and daughters, my parents, the, the family that’s around me. Um, and if I had known that, you know, all the hard work that we put in to achieve amazing things in careers and money and wealth and so forth, uh, matter way less, uh, over time. N- not that they’re not important, they’re just, uh, if I, if I were to tell myself, “Listen, you’re gonna be fine.”
It’s same thing, same message for the leaders, you know? Focus on the people. That’s what it all comes down to, and I’d love to tell my highly educated self way back then, “Listen, it’s, it’s… You know, the important stuff is, is the people that you’re with, uh, the life that you lead, not [00:43:00] the money that you make, not the, the job or the status, um, that you achieve.”
[00:43:05] Stacy Sherman: And I imagine having lost so much of the tangible stuff, did that actually make that lesson and thought even more prominent?
[00:43:19] John Sileo: Absolutely. So after this case was over and I’d started to write the book, um, you know, and my wife was, was… said, “You know, you need to, to go do something about this. You need to, to not just let this fester.” I decided I didn’t wanna just become a speaker who goes out 150 times a year. I didn’t want to, um, consult as I had done in the past and have to travel and not see my girls grow up even more.
I mean, I had… It was so clarifying in terms of my values because I had lost so much. It became just painfully clear that what I wanted was more time [00:44:00] at home as a dad, uh, uh, a career that allowed me the freedom and the flexibility and the autonomy. So when I went into speaking and when I made decisions, it was all based around how can I travel and only speak to, you know, 30 or 40 clients a year, do the most work in the least amount of time, and have that time for the rest of, of my life.
And, uh, it was really the, the pain of losing so much that, that led to that, that perspective.
[00:44:29] Stacy Sherman: That’s what I figured. Well, thank you. It is such a gift. Your presence is a present for being here, and I know people are gonna love listening to this and engaging with the content that you’ve offered, so it will all be in the show notes, and thank you again
[00:44:49] John Sileo: My pleasure. So nice to be here. Thank you
[00:44:54] Stacy Sherman: Hello, John. Welcome to the Doing CX Right show[00:45:00]
Oh, this is a special episode like no other, and people are gonna soon find out. If they don’t already know you, this show will change their life. I guarantee it. But before I say more, can you share a little bit about why have you dedicated your professional life, your life, not even just professional, to educating people about cybersecurity?
Can you share your fascinating backstory?[00:46:00] [00:47:00]
Mm. The first incident that you had, did that prepare you for the second in any way?[00:48:00]
So in this AI world, and everybody’s giving their information to AI platforms and chatGPTs and Claude and, what’s your perspective? I mean, everybody’s, everybody’s doing it. Our data is showing, as you say[00:49:00]
Mm-hmm.[00:50:00]
It is mind-numbing. And as a podcaster and as speakers, I also think about how easy it is to clone my voice and, and be me even though it’s not me. That is so frightening[00:51:00]
Hmm. So for my listeners, those that may not have been at the National Speakers Association where John and I first met, um, my phone was hacked in front of nearly 1,000 people, and it was so impactful. I wanna talk about that, but I’m gonna save it till later because there’s so many topics to discuss, it could take up the whole show.
So I’m giving everybody a little teaser, because this story I will never forget for the rest of my life, and the lessons. So I’m gonna pause on that for a moment and talk about, first of all, John, this is the Doing Customer [00:52:00] Experience Right show, and doing customer experience has a lot to do with feeling safe, secure, risk mitigation.
So when I say customer experience in the industry that you’re in, what does that mean to you?
Mm-hmm.[00:53:00]
Mm. So true. So I love your saying your data is showing. It’s funny, and yet the reality of cybersecurity is devastating. Can you talk a little bit about when you say your data’s showing, what does that mean? What is the gap, and how seriously leaders need to protect that?[00:54:00] [00:55:00]
All right, so let’s talk about Solvable. Um, and you don’t have to mention client names, but can you share a little bit about some of the use cases and, like, the problem and the action that they’ve taken that others can learn from?[00:56:00] [00:57:00]
So is this a training call out for leaders? Is this a, like what, what is the go do tomorrow?[00:58:00]
Hmm. It reminds me, you said how every employee, everyone has to own and be accountable for security and safety, especially of customer [00:59:00] data, never mind their own. And in the customer experience world, so many people say, “Eh, not my job.” They point to somebody else, and I’m out there yelling from the rooftops that, “No, you have that role regardless of job title.”
So it’s really similar[01:00:00]
Hmm. I kid you not, yesterday I tried to buy something on Amazon and my credit card did not go [01:01:00] through, but I never got a alert from the, um, credit card company that there was a hack or anything. So I tried again and it didn’t go through. And so I called the credit card company and they said that I– they couldn’t help me until Monday.
I can only activate a card on the weekend. And I’m thinking, “How is that possible? How can, how can I have no human to talk to to fix this problem that I can’t use my card?” Or, or the anxiety I feel around why can’t I use my card? So it’s, it’s customer service. Like when you’re feeling that anxiousness and fear, it, it is so essential.
Much more than, “I got a product I wanna, you know, exchange for a different size.”[01:02:00]
Yeah. I’m glad you said that because the user experience of these different platforms, if it’s not easy, if it’s not frictionless, like that’s gonna play into how much people are taking the [01:03:00] extra step. It sounds logical, no duh, that you would do that, but obviously they’re not. Um, and I think that just like in the customer experience world where we design an experience how a customer learn, buy, get, use, pay, and get help, in that journey mapping, I believe, and I’m getting educated talking to you, is that we need a security m-moment.
Like does this spot require in the journey to be an AI, a human, a, a, a double check two, you know, two factor or not? Like that has to be very intentional[01:04:00]
So in September, coming soon, I have a report, a commissioned research, that talks about the importance of emotions in customer experience and driving loyalty. So many companies are so transactional and logical, and I’ve been saying, actually, emotion is the experience. And so when you just talked about the anxiety and the fear, many [01:05:00] companies are saying, “Well, we don’t really need to pay attention to emotions.
That’s fluffy.” And I’m saying, “No, no, no. Actually, now my data shows that if you make one mistake, it takes six positive consecutive experiences to make up for that one.” Six. And there are a ton of other statistics in this report, and it’s gonna be… It’s free, so I’m gonna put it in the show notes for people to download.
But the fact is that for companies, they have to realize that the anxiety and the fear factor with cybersecurity and breaches, it l- as you said, it can lose a customer. In fact, not only will it lose a customer, people are gonna tell others, “Do not buy from them.” That ripple effect.[01:06:00]
Well, also with social media and what I’m learning a lot from my study is that AI is using the sentiments across the web, the negative and positive, and using it to recommend or not recommend brands. So if anyone’s out there saying, “I feel such risk interacting with X brand,” or, “This happened to me, and I had– they weren’t helpful in solving the breach or solving the security and the billing issues I had,” they– the AI is going to actually punish you for that[01:07:00]
Hmm. All right, so I’m gonna share the story, the big story, and we’ll talk about what can people do. What can people do as customers of brands, and what could leaders who are listening to the show do? So Oh, how to wrap this up really quickly ’cause it is a big story. So when I was at the National Speakers Association, I was among almost 1,000 people, very in tuned to John’s presentation.
And it was about cybersecurity and backstory, as you just heard. And so he came up to me, uh, after looking at the [01:08:00] crowd to decide w- whose phone is he gonna hack? He’s gonna prove a lesson of the importance of, of security and even your phone. Now, John and I had never met. He asked some questions when he came to me, chose me.
And by the way, I did not realize I was on these big screens in the room, almost like, like candid camera on me. I didn’t even realize. So everybody in the room knows now it’s me. S- I’ve heard that. I can’t wait to watch it. So, so you asked me a bunch of questions about things that are very common on the web.
Anybody could have found this. So I answered out loud, not even thinking twice about all the people that are in the room that are hearing my answer anyway. Like, I, I just was, like, going with it ’cause I was so confused, and I was like, “There’s no way you’re gonna hack my phone.” Like, I have a r- [01:09:00] I have a really good password on my phone, and, nah, he’s, he’s not gonna do it that quickly and, and such.
Well, anyway, so to my surprise, you did. You hacked my phone. And the questions that you had asked me, none of them actually happened to be associated with the specific code on my phone to access anything. Well, I and the audience, the room was flabbergasted. Like, “Oh my God, how did that just happen?” I mean, it was j- it was so much commotion during and then even after the event.
So you had kindly invited me to the stage so that we could talk a little bit more, and you showed the audience how much more you were able to dig into my life in a safe way. But it, it changed me forever. So can you [01:10:00] share a little bit from your angle? Because I was having an out-of-body experience. Though I did see you pulled up pictures that were just so funny and scary at the same time.
Can you share a little bit from your angle, uh, ’cause you were really in the moment, as I was on a cloud[01:11:00] [01:12:00]
The other part of this story, I still can’t believe it happened, was that when you hugged me and thanked me and sent me nicely off the stage, I left without my phone. And the audience is, like, taking care of me. They’re, like, whispering like, “Stacy, Stacy, your phone, your phone.” And I went back on the stage, and I’m like, “Oh my God, I, I can’t [01:13:00] believe I just left without my phone.”
I remember saying to you, “What the F?”
And I just couldn’t believe the whole experience, but it really made me realize in that moment how I have to take this more seriously. I get to share more, with more people like today who you are and what you’re teaching, because everyone needs to know. And by the way, after I got off the stage and the event was over, at least 200 people minimum had come up to me and said they called their family, they’ve changed their passwords, they told their family to change their passwords, they created these, um, code words if anybody calls.
Like look what, how, what an impact you changed lives[01:14:00]
Well, I did something [01:15:00] for the first time when I left the event and I went on the airplane, and you know on a plane you’re sitting close to people. I never did this before until I met you, that I s- I had my laptop open and on my home screen is, like, my name, my full name, and then obviously enter my password, and I literally shut my computer, like, kind of facing me and typed where nobody to my right or left could see me.
I was so super sensitive, and I think that’s the way to be, like, when you’re that close to strangers[01:16:00]
I have to ask, I imagine people after the event, right after we left the room, [01:17:00] had to have come to you and said, “How did you do that?” What do you say to that question?
Hmm. Fair. And I, all I did is tell everybody it really happened, and y- just focus on what you can do about it. That’s, that’s the message[01:18:00]
What about at airports? I started to think about the facial recognition when we go through. I never thought about that, but I did have a sense of fear. Um, like we can’t control everything, but, uh, like what do you do in those situations? You know too much. Like, do you say, “Sorry, you can’t have my face,” or are you going through and just taking extra precaution, like you yourself?[01:19:00] [01:20:00]
Hmm. Going back for a moment to your, the crime that you faced, um, and, and the victim of, how did they end up finding what happened?[01:21:00] [01:22:00] [01:23:00]
I have goosebumps. Like, I can’t even wrap my brain around this, this just, just, um… Well, y- you have, um, you are the perfect example of out of bad comes good, and you’re changing lives. And so that’s what the speaking business is. And, um, and I’m gonna have in the show notes for people to find more about your story on your website and your book and everything about you.
Um, as we come to the end, rapid-fire questions here. What is the one most important key takeaway you want listeners to go do right now?
Both[01:24:00]
Mm-hmm.[01:25:00]
That’s awesome. Yes. Yes, yes. Thank you for that. And leadership advice, the best you’ve ever received or given
And do not forget that as people, we are humans with [01:26:00] emotions. Do not ignore fear, anxiety, delight, joy. You cannot ignore that, otherwise you will not sustain into the future
And my final favorite question I’ve asked over 200 people. John, if you could go back in time and talk to your younger 20-year-old self based on what you know now that you didn’t know then, what would you tell the younger you?
Twenty
Tell me more[01:27:00] [01:28:00]
And I imagine having lost so much of the tangible stuff, did that actually make that lesson and thought even more prominent?[01:29:00]
That’s what I figured. Well, thank you. It is such a gift. Your presence is a present for being here, and I know people are gonna love listening to this and engaging with the content that you’ve offered, so it will all be in the show notes, and thank you again
Questions & Answers: What Leaders Need to Know about AI Deepfakes and Protecting Customer Data
Q: How does a company decide where to add security steps without hurting the customer experience?
A: A company identifies which systems and data carry the highest risk, then applies verification steps such as two-factor authentication only where that risk justifies the extra step for the customer. Adding the same level of friction to every interaction increases cost and slows down low-risk activity while leaving the highest-risk systems without added protection.
Q: What does a company do when a security control locks a customer out of their own account?
A: A company gives the customer a published phone number connected to a live person who can resolve the issue immediately, rather than requiring the customer to wait until the next business day. A customer who cannot reach anyone when a security tool fails often stops using that company for future transactions and shares that experience with others.
Q: How does a company reduce the risk of an employee being tricked into transferring money or data?
A: A company trains every employee, including executives, to pause and verify a request before acting on it, especially when the request is urgent or comes from someone claiming authority. This verification habit, referred to in the episode as a fraud reflex, is described as one of the most effective and least commonly trained tools available to a business.
Q: Why does a single security breach affect customer loyalty more than most companies expect?
A: A single mistake requires several positive experiences afterward to restore the customer relationship to where it stood before the mistake occurred. Customers who experience a breach or a poor security-related support interaction often share that experience with others, and that word of mouth reduces the likelihood that new customers will choose the brand.
Q: How is artificial intelligence changing the risk of fraud for businesses and individuals?
A: Artificial intelligence allows attackers to produce realistic voice, video, and image content in a very short period of time, which increases the likelihood that an employee or individual will believe they are interacting with a real person in a position of authority. Businesses need to train employees to verify identity through a second channel before acting on instructions delivered by video, audio, or text, no matter how convincing the request appears.
About John Sileo:
He lost his multi-million-dollar startup, his wealth, and two years of his life to cybercrime. It began when a hacker electronically embezzled from the company’s clients using John’s identity. John was initially held legally and financially responsible for the felonies committed. The losses not only destroyed his company and decimated his finances, but also consumed two years of young fatherhood as he fought to stay out of jail.
But John’s story has a happy ending and has become a worldwide catalyst for change. Since being found innocent of all crimes (and the real hacker put in jail), John has made it his life’s work to share hard-earned wisdom as a cybersecurity expert, award-winning author, 60 Minutes guest, and keynote speaker. His happy clients range from the Pentagon to Amazon, small associations to enterprise organizations. His mission is to keep others from becoming the next disastrous data breach headline. John specializes in the human elements of cybersecurity and uses disarming humor, audience interaction, and cutting-edge research to keep his training relevant and entertaining.
John is President & CEO of The Sileo Group, a Colorado-based technology think tank, and serves on several boards. He graduated with honors from Harvard University and was recently inducted into the National Speakers Hall of Fame. John finds his greatest joy in spending time with the loves of his life: his wife, two daughters, and mini golden doodle. And yes, life’s bumps have shaped him into a slightly over-protective but well-intentioned helicopter dad.
Connect with John on LinkedIn and website.
Get more of John’s actionable cybersecurity tips at https://sileo.com/tips, including his take on the AI deepfake scams and breaches discussed in this episode.
About Stacy Sherman:
An award-winning international Certified Speaking Professional (CSP) who has delivered hundreds of standing-ovation keynotes and workshops and co-authored best-selling books on Experience Management for sustainable success. She developed a proprietary framework that enables leaders and teams to enhance revenue and brand reputation. Her proven methodology is based on her MBA degree and 25 years of leadership in sales, marketing, employee, and customer experience across diverse industries, including Verizon, AT&T, Schindler Elevator Corporation, Wilton Brands, Martha Stewart Crafts, and LiveOps, generating $2.4 billion in savings and hundreds of millions in revenue. Stacy Sherman has earned widespread recognition for her award-winning “Doing CX Right” podcast, ranked in the top 2% globally with over 200 episodes, and for her courses on LinkedIn Learning, which have garnered hundreds of 5-star reviews. A multi-year Global CX Guru awardee and 2026 ICMI Hall of Fame inductee, Stacy’s insights have been featured in Forbes, Psychology Today, Yahoo News, and other leading publications.




