The Best Con Artists Don't Just Fool You
A good con artist does not just take your money. He gets you to defend him for taking it.
That is the real metric, and nobody talks about it enough. You can measure a Ponzi by its balance sheet, a phishing campaign by its click rate, a supply-chain compromise by its blast radius. But the strength of any con — whether it is stealing $65 billion or stealing your belief in a founder who never built what they promised — lives in one question: how long does the mark keep believing after reality shows up?
Weak cons collapse the moment facts arrive. You see it in every phishing email that gets reported before anyone clicks. Strong ones keep believers long after the verdict, sometimes for life.
Elizabeth Holmes walked out of Theranos with a conviction and a prison sentence, yet people who had staked their reputations on her still blamed the press, the regulators, or skeptics who would not wait. Bernie Madoff confessed to the largest Ponzi in history and the belief died on the spot — because a Ponzi is binary, money is there or it is not. But notice who his marks were: banks, charities, sophisticated financiers who prided themselves on due diligence. Not amateurs.
The interesting question is what prolongs that survival, and why it should worry anyone who has ever signed off on a vendor without really looking.
Source
The Profile of a Susceptible Mark
Start at the weak end. When Madoff confessed, belief died on the spot — but not before he had built a client roster that read like a who's-who of financial sophistication. Banks. Charities. Partners at hedge funds. People whose entire career was built on asking hard questions about where money actually lives.
Fraud researcher Tamar Frankel found a pattern in who falls for these schemes: not stupidity, but a specific kind of distrust. Many marks share one combination — they distrust established institutions and readily believe an alternative source that flatters what they already want to be true. It is less about intelligence than about which authorities a person has chosen to trust.
Here is where it gets uncomfortable for anyone in security. The people most confident in their critical thinking are often the easiest to take. Social psychologist Roland Imhoff calls this the "need for uniqueness" — the hunger to hold knowledge that sets a person apart. The pitch writes itself: you are too smart for the official story. Only you and I see what is really going on. It is flattery dressed as revelation.
Think about the last time you dismissed a vendor's security posture because they lacked some shiny certification, then signed off on something else that made you feel like an insider. That is the shape of this trap. The con does not ask you to lower your standards; it asks you to redirect them toward the right target.
The Theranos board included former cabinet secretaries and decorated generals. Daniel Kahneman spent a career showing that the biases behind all of this are built into every human mind. The mark is not a separate kind of person.
Source
The Rhetorical Toolkit
The skilled grifter is not improvising. Robert Cialdini's research on influence catalogs the moves with surgical precision, and they translate directly into how social engineering attacks succeed in enterprise environments.
Borrow authority. Wrap yourself in credentials and a cause. In security terms, this is the difference between a phishing email that says "your password expires" and one that impersonates your CISO's voice with the right internal branding. The mechanism is identical: borrow the halo of an institution you already trust.
Manufacture consensus. When enough respectable people vouch for you, doubt feels like heresy. Lance Armstrong built a halo from a cancer-survival story, a foundation, and a sea of yellow wristbands. For years, that halo made the doping charges sound like an attack on a hero. He denied everything and sued those telling the truth. Even after his 2013 confession, many fans stayed loyal.
In cloud security, this shows up as the "everyone is doing it" pattern: a compliance framework gains adoption not because it works, but because enough marquee names signed on. Once the critical mass hits, questioning the approach starts to feel like questioning the industry itself.
Defend at any cost. Cognitive linguist George Lakoff has shown how framing triggers a moral reflex before reason engages. Each of these moves buys the con more time before belief has to meet reality.
The pattern maps cleanly onto incident response. When a breach hits, the first instinct is often to contain the narrative — blame the vendor, point to a zero-day, invoke an act-of-God scenario. The same psychological machinery that keeps con believers loyal also drives how organizations respond to their own failures. The grifter's toolkit is not unique to fraud. It is the default operating system for human credibility management.
Source
Why Belief Hardens
The longer you have believed, the longer the belief endures. Part of this is the sunk-cost fallacy: refusing to abandon a bad investment because so much has already been invested. The other part is identity.
When Sam Bankman-Fried was convicted of stealing billions from FTX customers, his defenders sent letters praising his altruism, as if the persona answered the charge. When Trevor Milton was convicted of faking a Nikola truck video — rolling a dead prototype downhill to make it look like it was driving — many retail investors kept defending him even as he insisted he had done nothing wrong. Adam Neumann torched tens of billions at WeWork and was then handed the largest check his marquee backer had ever written for his next idea.
Political psychologist Lilliana Mason describes how, once an identity fuses with a belief, facts stop being shared reality and become tribal property. Giving up the belief starts to feel like giving up part of yourself. That is what keeps it alive.
In security, this shows up when teams double down on a tool they have spent months configuring, even after evidence mounts that it is not solving the problem. The sunk cost is real — time, money, reputation all at stake — but the deeper lock-in is identity. Admitting the tool failed means admitting you made a bad call, and for someone whose career is built on technical judgment, that admission carries a cost no dashboard can quantify.
The con does not end when the theft is exposed. It ends when the mark stops needing to believe.
Source
The Manufactured Rescue
The strongest version turns belief into dependency.
Wilfred Bion's psychoanalytic theory describes a pattern that echoes through every high-control organization: anxious people form dependency groups around a troubled leader, certain he will save them from a threat he largely created. The self-help world runs on it.
Keith Raniere sold NXIVM as personal growth and executive coaching. After his conviction for racketeering, sex trafficking, and a 120-year sentence, some members still stood outside the courthouse defending him. Here, belief resists all evidence because the evidence now feels like an attack on the rescuer. This is the con that endures longest, because leaving means indicting your own past.
In enterprise security, this pattern shows up when a vendor becomes so embedded in your incident response workflow that switching costs become existential. The vendor did not just sell you a tool; they sold you a narrative where they are the hero and everyone else is part of the problem. After a breach, the instinct is not to ask whether the tool worked — it is to defend the vendor's version of events, because admitting failure means admitting you built your entire response architecture around a lie.
The manufactured rescue is the con that endures longest, because leaving means indicting your own past.
Source
Why It Is So Hard to Walk Back
Some ground is more fertile than others.
Arlie Hochschild's research shows how stories of lost status prepare people to accept anyone who names a culprit. Jonathan Haidt's moral foundations theory explains why the same con is tuned differently for different audiences — some moved by loyalty and authority, others by care and fairness. The grifter does not use one script; they read the room and adjust.
Once someone is in, confrontation backfires. Brendan Nyhan has found that attacking a cherished belief tends to reinforce it, while affirming the person's values first and then introducing the fact works better. This is not just academic — it is the difference between a successful incident response and one that leaves your team defensive and your attackers still inside.
Robert Putnam's work on social capital suggests why the isolated are most exposed: they have fewer real ties and more of their reality arrives by algorithm. In security terms, this is the team that has no peer review, no second pair of eyes on architecture decisions, no one to call when something feels off. The con thrives in silence.
The practical implication is uncomfortable: the people most likely to spot a con are often the ones least equipped to act on it. They see the pattern, they name it internally, and then they stay quiet because calling it out would mean admitting their organization made a series of bad decisions. The cost of truth becomes higher than the cost of the lie.
Source
The Mark Is Us
Daniel Kahneman spent a career showing that the biases behind all of this are built into every human mind.
The Theranos board included former cabinet secretaries and decorated generals. The mark is not a separate kind of person.
Here is the question. Each of us has kept faith in something past the point where the facts turned: a stock, a boss, a company, or a person we needed to be right about. The strength of a con is measured by how long belief survives contact with reality.
So, ask it plainly: where is one of your beliefs still running on faith after the evidence stopped supporting it? The person most certain they could never be conned is usually the one who has already stopped checking.
In security, that question lands differently. It is not about whether you would fall for a phishing email — it is about whether you would admit when the tool you championed failed, the vendor you defended under pressure was wrong, or the architecture you designed had a flaw you ignored because naming it would mean rewriting months of work. The con does not need you to be stupid. It needs you to be human.
And humans, it turns out, are excellent at defending the people who take from them — as long as letting go would mean indicting their own past.