News & insights
August 3, 2026

Trust Has Never Been Easier to Fake

Speaker Victoria Baines on a fake recruiter scam that nearly worked, and why the old markers of digital trust and authenticity no longer prove anything.

Victoria Baines
News & insights
August 3, 2026
Illustration representing a fake online job offer and the collapse of digital trust markers
Share
Table of Contents
Found this useful?

Tell us about your event and we'll match you with the right person for your audience.

Trusted by 3k+ event planners

Digital trust has never been easier to fake. Earlier this year an executive search consultant called Sarah Goldberg wrote to me about two senior roles for which she was certain I would be perfect. She had done her homework. References to my years at Europol's European Cybercrime Centre, my trust and safety work at Facebook, and my Gresham Professorship were all correct, flattering, and assembled into a paragraph intended to make me feel recognised.

How does a fake recruiter approach actually work?

It gets the details right and the structure wrong. Sarah Goldberg did not exist. Her firm boasted over a decade of experience on a website that had been registered just fifty-four days earlier. Her colleague's photograph had been artificially generated rather than taken. Buried in the follow-up correspondence was the sentence that gave the whole thing away: an instruction not to apply for either job directly, because the opportunities were confidential.

Both roles were publicly advertised. She was very keen indeed to protect her position as the sole channel between me and them. As recent media coverage has highlighted, I am not the only former government intelligence analyst to have been targeted in this way. Precisely because I am a former government intelligence analyst, I spent a highly enjoyable and very productive afternoon picking the operation apart. It had all the hallmarks of the online badness that regularly features in my talks to audiences, whether that is the spread of disinformation, corporate phishing, or consumer scams.

Why are the old markers of authenticity no longer reliable?

The markers themselves have become cheap to produce. The corporate logos were real. The job listings were real. The face in the photograph belongs to a real woman who it would appear has nothing whatever to do with any of it. An accurate, specific and well researched approach was once evidence of effort. Save for the most sophisticated spear phishing attacks on chief officers, it might reasonably have been held to be evidence of good faith.

Such an approach now costs a few pence and can take a matter of seconds. We are witnessing the collapse of traditional barriers to trust and markers of authenticity, processes on which a great many organisations still rely for their assurance and integrity.

» Explore: Cybersecurity speakers

What does two decades of investigating online trust teach you?

That trust is a judgement made at speed, on incomplete information, with someone always unhappy about the outcome. I have spent twenty years on various sides of this question, in law enforcement, in European policing, inside a platform making those judgements at a scale of billions, and now in research.

I began by investigating online offending for UK law enforcement, where the ultimate aim was to establish who someone really was and to hold them accountable. At the European Cybercrime Centre I analysed cyber threats and designed strategies to tackle criminal abuses of trust. I sat at tables where governments negotiated what we should all be obliged to believe about one another. Then I went to Facebook, where I managed government expectations of trust and safety in diverse, and often diverging, jurisdictions in Europe, the Middle East and Africa. I learned what it is to make judgements at a scale of billions, at high speed, and always with someone furious at the outcome.

Since then I have been an independent consultant and an academic, latterly as Gresham Professor of Information Technology. In my research on trust, my doctorate in classical rhetoric has been indispensable. Rhetoric is the study of how persuasion works, even on people who believe themselves immune to it. It has much to teach us about how and why communications land, whether it is a phishing email, a government press release, or a vendor's security claims.

What does your organisation trust structurally, and who decides?

Very few boards have ever written that question down, which is what makes it the harder half of the problem. The interpersonal aspect of the trust problem is the easy part. Structural trust runs through the certificates, cloud, compute and models an organisation depends on, and through whoever happens to control them.

Consider the padlock in your browser. Most of us treat it as a verdict. It is closer to an opinion. It rests on a small set of root certification authorities, and when I mapped where those authorities actually sit, the concentration in a single jurisdiction was considerable. The same is true of cloud, of compute, and of the AI models now being wired into decisions about recruitment, lending and healthcare. Infrastructure you do not control is infrastructure someone else can switch off. This is a governance question. It is a question of digital sovereignty.

What do digital ethics mean in practice?

Digital ethics are a good deal less abstract than the phrase suggests, and a good deal less concerned with whether robots should have rights. In practice they are the business of knowing who is accountable when an automated decision is wrong, whose interests are served, and which of your dependencies remain unquestioned simply because everyone else has them too.

Why does scaremongering make organisations less safe?

Fear makes people passive, and passivity is precisely what cyber adversaries prefer. In my public outreach, media appearances and corporate briefings, I consistently challenge the scaremongering so often characteristic of cybersecurity, because a frightened organisation stops asking questions.

Senior audiences, in my experience, want to know what is real, what is marketing, and which questions to ask on a Monday morning. They are not impressed by jargon and do not take kindly to attempts to blind them with science. That is, after all, a well-known scam tactic.

So, trust has never been easier to fake. It has also never been more valuable to foster and maintain, or more exciting to explore and dissect. That is fortunate, because doing so with audiences around the world is one of the most enjoyable and interesting aspects of my work.

💡 Interested in booking Victoria Baines for your next event? Get in touch with the PepTalk team and we will scope the right format for your audience. You can also call us on +44 20 3835 2929 (UK) or +1 737 888 5112 (US). Remember, it's always a good time to get a PepTalk!

Navigate the realities of technology, power, and trust with Victoria Baines, a leading voice on cybersecurity, digital ethics, and the geopolitics of emerging tech. Drawing on senior roles at Facebook and Europol, Victoria helps organisations make sense of risk, regulation, and innovation, alongside regular BBC appearances and her public lectures at Gresham College.

Found this useful?

Tell us about your event and we'll match you with the right person for your audience.

Trusted by 5k+ event planners

Tell us about your event. We'll find the right voice.

Get expert recommendations matched to your brief, your audience, and your budget.

15,000+ speakers
Shortlist in 24 hours