Louis Zezeran
14. juuli 2026
From Counterfeit Bills to Quantum Threats: A Secret Service Veteran’s Journey Through the History of Cybercrime
Imagine sitting on a hotel balcony in Dubai at three in the morning, drinks on the table, deep in conversation with a cybercriminal who believes you’re one of them. Then he stops you mid-sentence: “You told me you didn’t have any family.” Your cover story has just cracked — and you have less than a second to respond.
That moment, and what happened next, is just one of the stories retired U.S. Secret Service Special Agent Richard K. LaTulip shares in this episode of the NEVERHACK Estonia Cybercast. Hosted by NEVERHACK’s Ronnie Jaanhold, the conversation spans nearly three decades of cybercrime history — told by someone who didn’t just watch it unfold, but chased it across continents, infiltrated it from the inside, and wrote a book about it: “Operation Karter Chaos: How One Agent Penetrated the Underground Economy”.
Richard, now Field CISO at Recorded Future and a confirmed Nordic-Baltic keynote speaker for 2027, has a long-standing connection to Estonia. He was one of the very first Secret Service agents ever stationed in Tallinn — and this episode explains exactly why that posting existed in the first place.
From Printer Drivers to Computer Forensics
Richard joined the United States Secret Service in 1998, at a time when there was no “cyber track” at all — as he jokes, the agency was “running into the 21st century uninhibited by technology.” His entry into computer forensics is a story every IT professional will appreciate: he walked into his frustrated boss’s office, installed a printer driver, was instantly declared “highly technical,” and was promptly shipped off to computer forensic school. Sometimes careers really do hinge on a printer.
From there, he had a front-row seat to the entire evolution of financially motivated cybercrime. His core argument frames the whole episode: most cybercrime — at least the kind that isn’t nation-state activity — is simply financial crime facilitated by a computer. The Secret Service, founded in 1865 to fight rampant counterfeiting (at the time, between one-third and two-thirds of all U.S. currency in circulation was fake), was a natural fit to follow the money into the digital age.
The Evolution: Printers, Skimmers, IRC, and the Birth of Criminal Forums
Richard walks listeners through each era of the underground economy:
The earliest “cybercriminals” were down-on-their-luck opportunists spending all night aligning an all-in-one printer to produce fake $20 bills — or, for the more sophisticated, washing genuine $1 bills and reprinting them as $100s. Then came skimming: waiters with pocket devices capturing magnetic stripe data, re-encoding cards, and suddenly turning petty fraud into losses of hundreds of thousands of dollars.
The real inflection point, Richard explains, was a marketing problem. Criminals on IRC channels could only reach a few hundred people. But when carding forums emerged in the mid-2000s, the underground economy suddenly had scale: advertising, tutorials, escrow-style trust mechanisms, and testimonials vouching for sellers. One insider detail Richard reveals: many of those glowing testimonials were written by the sellers themselves under multiple identities, or by their friends. Buyers who would never have wired money via Western Union to a stranger in Kharkiv, Ukraine suddenly trusted an anonymous handle — and the money started flowing. Cybercrime went global overnight, because on the internet, your business partners can be anywhere.
Why the Secret Service Came to Tallinn
One of the most fascinating threads of the episode is the story of how Estonia became a strategic outpost in the fight against cybercrime. After tracing the Secret Service’s dual mission — investigations since 1865, presidential protection since the McKinley assassination in 1901 — Richard explains that around 2002–2003, as cybercrime became “the talk of the town,” the agency decided to place investigators strategically around the globe, mirroring what it had long done for protection.
The research pointed to the Baltics and the concentration of Russian-speaking, financially motivated cybercriminals in the region. The Secret Service weighed Latvia, Lithuania, and Finland — but the synergies pointed to Estonia. Richard became one of the first agents assigned to the U.S. Embassy in Tallinn, with a population of 1.4 million and just two Americans representing the entire agency.
He also clears up a common misconception he encountered constantly in his casework: criminals who insisted, “I never hacked a U.S. bank — why is America arresting me?” The answer: if you use U.S. infrastructure — even something as simple as a Gmail account — to facilitate your crime, you fall within U.S. jurisdiction. In an interconnected world, it is almost impossible not to have a touchpoint somewhere.
Why Boots on the Ground Matter: Stopping a Million-Dollar Fraud
Richard shares a Baltic case that perfectly illustrates why local relationships beat remote phone calls. While stationed in Tallinn, he received a call about a business email compromise: over a million dollars transferred in two transactions to a bank in the Baltics. Because he personally knew the local law enforcement and banking contacts — people he’d shared dinners and drinks with — he could pick up the phone and get the gears moving immediately, stopping the fraud with minimal loss.
Compare that, he says, to a stranger cold-calling from Washington claiming to be the Secret Service: “The person would probably hang up the phone.” Trust, built face to face, is operational infrastructure. That same case connected to the infamous SWIFT system compromise, in which a billion dollars was wired toward a bank in the Philippines — most of it recovered, but not all.
Undercover in the Underground: Operation Karter Chaos
The heart of the episode is Richard’s undercover work — the subject of his book, whose title nods to the villainous KAOS organization from the TV series *Get Smart* (that’s Karter with a K; spell it wrong and you won’t find the book). The operation’s premise was radical for its time: take the digital-only world of carding forums and drag it into the physical world. Meet the criminals face to face. Build rapport. Then dismantle the network.
That’s how Richard, operating under the alias “Surfrider,” ended up drinking with cybercriminals in Dubai, Thailand, and beyond — and how he survived the balcony moment when he was caught contradicting his own cover story. His split-second answer — “That’s because I lied to you… I lie to people all the time online” — resonated perfectly, because everyone in that world lies online. The conversation moved on as if nothing had happened.
But he’s candid about the risks: operating in Southeast Asia or the Middle East with no law enforcement powers, relying on local partners he’d met the day before, in a world where weekly cash handoffs at a San Francisco Starbucks ran $150,000–$250,000 — likely half a million dollars a week in total proceeds. People protecting that kind of money can get violent.
When Hackers Meet the Mafia
One of the episode’s most chilling stories is a warning to any young, talented hacker flaunting sudden wealth. A successful hacker in Estonia — living in one of Tallinn’s most expensive apartments, driving a Maserati — attracted the attention of organized crime. A hood over the head, a van ride into the forest, a gun to the back of the head, and two options: never leave the forest alive, or hack for us. He became their hacker. And because he was a criminal himself, he had nowhere to turn for protection. As Richard puts it: you put a billboard on yourself, and when the computer world and the violent world meet, “you’re in for a new education.”
Protecting the Next Billion Users — and Seeing the Icebergs
Asked how ordinary people can avoid becoming victims, Richard highlights a global blind spot: emerging markets. Scams that died out in the West twenty years ago are being recycled in Africa, South and Central America, and Southeast Asia, where millions are coming online for the first time. Education, he argues, must be part of every responsible company’s market-entry strategy — work he now supports at Recorded Future, including collaboration with Mastercard.
His case for threat intelligence comes wrapped in two memorable analogies. The Titanic: its crew knew icebergs existed, but lacked timely, accurate, actionable intelligence about what lay beneath the surface — a three-degree course change could have meant arriving wounded but alive in New York instead of sinking. And the boardroom dartboard: ask blindfolded executives in a dark room to hit a target, and nobody’s confident; turn on the lights and remove the blindfolds, and suddenly outcomes become predictable. That’s what intelligence does for a business.
What Comes Next
Looking ahead, Richard reframes the “next 20 years” question: given that his $5,000 computer from 1995 was obsolete within two years, we should be watching the next two to five. Television took decades to reach 85% adoption; ChatGPT took two months. Quantum computing, he predicts, will become accessible beyond Fortune 500 companies within roughly two to four years — and just as nobody predicted what would actually drive the early internet’s growth, the most disruptive use cases for quantum will be ones we haven’t imagined yet.
Listen Now
This episode is equal parts history lesson, spy thriller, and practical security briefing – essential listening for anyone in cybersecurity, fraud prevention, or leadership. Listen to the full conversation now, grab Richard’s book “Operation Karter Chaos” (remember: K, not CH), and message Ronnie to enter the draw for a signed copy.
Listen to the full episode now, and if it resonates, subscribe to the NEVERHACK Cybercast on your favourite podcast platform and share it on social media. Got a topic you’d like us to cover? Email us at [email protected].