Why scambaiting videos leave security professionals with more questions than answers.
Scambaiters like Kitboga, Jim Browning and Pierogi educate millions, waste scammers’ time, and undoubtedly prevent people from becoming victims. As a security professional, I genuinely appreciate what they do.
But every time I watch one of these videos, I find myself asking the same question: What happened in the missing five minutes? How does a legitimate remote support session suddenly become full control over the scammer’s computer? Is it a vulnerability? Poor operational security? Social engineering? Or simply the part of the story that gets left on the cutting room floor?
This isn’t a criticism of scambaiters. It’s an exploration of the unanswered security questions that every IT professional should be asking, and why understanding how something happened can be just as important as enjoying the outcome.
Listen now on Apple Music, Spotify, Deezer, Youtube or where-ever you get your panic attacks.

The Colorful Styles of Scambaiters
One of the most compelling aspects of scambaiting is the variety in styles. Each scambaiter has a unique approach that sets them apart:
- Kitboga: Known for comedic brilliance, Kitboga specializes in social engineering, leading scammers on wild goose chases without the need to “hack back.” His videos are a blend of humor and education, making us laugh while enlightening us on the methods criminals use.
- Jim Browning: With a strong IT background, Jim Browning takes an investigative approach. He goes beyond wasting time; he dives into unsecured camera systems and poorly configured infrastructures, shining a light on operational security flaws.
- Pierogi: Another fantastic entertainer, Pierogi connects to scammersโ PCs and reverses the tables. He delves into their files and webcams, creating entertaining and insightful content. However, his methods highlight some pressing questions on how these connections work.
The IT Dilemma: Unanswered Questions
When watching these videos, a technical conundrum arisesโhow are they really doing it? We’re left wondering about the mechanics. Often, the critical technical maneuvers are edited out, leaving us with an incomplete picture.
The Magic Reversal Explained
- Commercial Software: Scammers utilize legitimate remote software like Anydesk and TeamViewer. These are not tools inherently designed for malfeasance but are used by thousands of companies worldwide for legitimate purposes.
- Theories of Exploitation:
- Vulnerabilities: Could there be unidentified flaws within this software? If so, have vendors been made aware and have these been patched?
- Operational Lapses: Misconfigurations or weak settings might pave the way for exploitation.
- Social Engineering: Sometimes, scammers might inadvertently install software themselves, allowing baits to take advantage.
Compromised Systems: The Larger Picture
What if remote software isn’t the weak link? Often, scammers operate with poorly secured systems:
- Pirated and Obsolete Software: Many scammers use pirated Windows and Office versions, lacking timely updates and basic defenses like antivirus software.
- Pre-Compromised Systems: Such conditions make their systems vulnerable to further exploits by scambaiters, suggesting that many machines are compromised even before any action is taken.
“A compromised Windows machine is very easy to compromise further,” and this becomes the critical point of concern for IT professionals.
The Editing Reality of Scambaiting
The videos we love watching have been edited to remove the technical back-and-forth. While this makes for more engaging content, it masks the true challenge and complexity of these operations.
- The Illusion of Success: We often only see the successful attempts, leading to a skewed perception of how foolproof these methods are.
- Reality Check: Ten failed attempts might precede one successful operation, reminding us of the intensive trial-and-error process involved.
Seeking Security Answers: A Call to Action
It’s not just about the thrill of watching scammers get their due. For those of us in IT and cybersecurity, the practices observed in scambaiting videos raise valid concerns.
- Vendor Accountability: Are software vendors aware of these potential exploits? Have they been informed to patch vulnerabilities, if any?
- Learning from Incidents: Every IT exploit should be a learning opportunity. What’s the lesson here, and how can it reinforce security practices for legitimate remote software users worldwide?
The Broader Impact
This isn’t just about the scammers but also about protecting everyone who relies on remote software:
- Businesses and Individuals Alike: MSPs, hospitals, banks, and home offices must be prepared to mitigate risks by understanding potential vulnerabilities associated with remote access software.
Closing Thoughts: The Dual Lens of Entertainment and Security
I cheer when scammers are trapped, but as a security professional, these moments are more than entertainment. The fast-paced editing leaves many questions unanswered, particularly those surrounding security implications.
Scambaiting videos may be a spectacle, but they also remind us of the complexities behind the scenes. The gap between seeing and understanding persists, and finding that bridge is crucial.

Leave a Reply