Surveillance, scams and machines: Best infosec long reads 8/29/26
Hunting a global crypto scam network, When license plate surveillance gets it wrong, The hidden threat of Meta’s smart glasses, Inside the NSA’s secret Cold War supercomputer, Democracy versus the machine

Happy Saturday to all!
Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.
8/29/26: This week’s long reads explore the technologies that enable deception, surveillance, and control—from the infrastructure behind a global cryptocurrency scam network and the human consequences of ubiquitous license-plate readers and camera-equipped smart glasses, to the secret history of the NSA’s Cold War code-breaking supercomputer. They also revisit the early warnings that mass data collection, automated prediction and computer-driven decision-making could transform politics and undermine democracy.
The Scam Hunt
NRK's Martin Gundersen and Dan Kåre Engebretsen, along with Premium Times' Chinagorom Ugwu, report on their investigation into a global cryptocurrency fraud network and follow a Norwegian ethical hacker as he penetrates hundreds of fake investment sites, traces millions in stolen funds, and uncovers the Nigerian web-hosting operation that helped make the scams possible.
Daniel Christensen rarely says no to hunting down a fraudster. His favorite hobby is hacking into computer systems. When Daniel helped comedian Johan Golden figure out who was using his face to run scams, he picked up the trail of Hagen's TikTok imposters.
The scammers thought they had tricked another person into investing money on the website they had set up.
They did not know that Christensen was the wolf, and not the sheep.
– I could see immediately that the website was not legitimate.
It did not take Christensen long to get behind the scenes of the website.
The information there made the website's purpose unmistakably clear:
To defraud people out of as much money as possible. Those behind it would go in and increase the "returns" on the invested money with a few keystrokes.
As he investigated the websites, more and more of them kept appearing.
All with the same flaw.
All with lists full of unwitting investors.
One woman on the list was a nurse from the United States. Christensen could see that she had recently deposited money into the website.
– She was about to send more, so I called her, he says.
He warned the woman, but it took several conversations before he managed to convince her that the investment website was fake.
She was stopped from transferring 320 USD. By then the woman had already lost around 2,000 USD, according to her own account.
Christensen realized he could not call everyone.
He had a new idea.
What if he changed the payment address on the websites?
The money would then go to him and not to the unknown scammers who had created the website.
The plan: to transfer the money back to those who had been deceived.
It worked. But only for a short while.
The scammers quickly shut down the clever attempt.
Now all the websites showed nothing where the payment addresses had previously been.
Who could be behind it? Christensen took a fresh look at the investor lists. One entry caught his attention. The person called themselves "Eagleworker" and had an investor profile on many of the sites.
Last fall, Christensen shared everything he had found with NRK.
He had found 100 websites. NRK found 200 more.
The websites shared certain features that made it possible to establish that they had the same origin.
60 websites had the same code flaw, through which you could easily see the backend system.
NRK's analysis shows that over 5,000 investors had entered their full name, phone number, and email address on the fraudulent websites.
55 entries were associated with a Norwegian phone number. Some had uploaded their passport to verify their identity.