racheltobac 

17K Followers
1.5K Following
469 Posts
Hacker, CEO of SocialProof Security: security awareness/social engineering training, vids, talks, tests, 3X @Defcon🥈, Chair of the WISP board, Tech Advisory Council for @Cisagov
Twitterhttps://twitter.com/RachelTobac
Instagramhttps://www.instagram.com/racheltobac/
Websitehttps://www.socialproofsecurity.com/
Pronounsshe/her
If you’re an activist, journalist, exec, or have a high threat model for any other reason, I do recommend using all tools to protect against spyware including Apple’s lockdown mode and WhatsApp’s new Strict Account Settings. Thanks WhatsApp for the partnership to get the word out to folks.
@0x00string @frameworkcomputer whoa yuck, first I’m hearing of this nonsense
The repairable, customizable, build-it-yourself, physical webcam & mic kill switch, Linux compatible, port swappable @frameworkcomputer laptop has hit the SocialProof office 🤖🤘
@jd "Be politely paranoid" as @racheltobac says. Share a passphrase in advance with family.

Episode 22: Social Engineering, Gas Mark 4, and AGAs with Rachel Tobac!

Tib3rius & Andy Swift are joined by @racheltobac to talk social engineering war stories...and more!

Spotify: https://open.spotify.com/show/3PeV2Fhf87zLtQ8LjuMrsb
Apple Podcasts: https://podcasts.apple.com/us/podcast/across-the-pondcast/id1789463186
Amazon Music: https://music.amazon.com/podcasts/cfa2092b-c00b-4804-b9b1-6de7c105b820/across-the-pondcast
YouTube: https://www.youtube.com/channel/UC5L2Q76DgZhP2V8S6qx8knA

Across the Pondcast

Podcast · Across the Pondcast · Cybersecurity rants and war stories from both sides of the Atlantic.

Spotify

*New CNN Live Zoom Call Deepfake Video*
An engineering org sent $25 Million to scammers who deepfaked the finance team in a live video call. Are your colleagues, family & friends ready to catch this AI attack?
I demo'd a live Zoom deepfake to CNN's Clare Duffy to help you spot the signs.

These live video call or audio call deepfakes are increasing in the business world. Most often, an exec is deepfaked to the team that supports them asking for money, passwords, MFA codes, etc:
- $25M sent to scammers in Arup video call deepfake attack https://cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
- Fraudsters Cloned Company Director's Voice In $35 M Heist: https://forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/
- Wiz CEO says company was targeted with deepfake attack that used his voice: https://techcrunch.com/2024/10/28/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice/

We're also seeing a large increase in attackers using AI to voice clone an exec and target their team to steal money, data, or access, like in this example I did for 60 Minutes: https://x.com/RachelTobac/status/1976308961684189576

Many recommend using a verbal "passphrase" with colleagues, family and friends to verify that person you're talking to is who they say they are.
A verbal passphrase could work in some scenarios, especially the ones that aren't super dire or extreme. But, in the scenarios tricking families, where a child is deepfaked to a grandparent/parent/sibling etc and is in extreme distress, screaming, and crying -- remembering passphrases will be hard to do in the moment.
That is because we know from neuroscience that the amygdala in the brain takes over during times of crisis, making it challenging to remember anything at all except the present moment.
If you've ever been through a true crisis at home then you may know that it's hard to even remember your own ADDRESS to report to 911 during an actual emergency. The brain goes blank.
What I recommend instead is: if your family, friends, or colleagues get a terrified phone call from "you" asking for money (for example), stay on the line and use another method of communication to verify authenticity of the request while offering words of support.
Even a quick text, chat, or DM (even while the call is ongoing!) can verify that the call is a scam (and your loved one is actually safe) before sending money.

Share this example with family, friends & your team to ensure everyone is on the same page about Being Politely Paranoid and using another method of communication to verify people are who they say they are:
CNN: https://edition.cnn.com/2025/10/07/business/video/deepfake-scam-ai-zoom-call-digvid

Right now, AI voice clone scam calls are increasing for orgs.
I give it 1 year before criminals increase use of live video call deepfakes in their scams. Get your team and folks prepared now.

@paulgatling thank you!!!

*New live hack demo: hacking bank security questions with AI voice clone calls*
At @defcon I went on the @scammerpayback Payback podcast and hacked the host by calling his friends & stealing answers to his bank's password reset identity questions using a voice clone within 10 seconds!

The Scammer Payback podcast was one of my favorite interviews of all time because I got to:
- do hard OSINT on Daniel, present my findings live and shock the glasses off him multiple times
- live hack his bank account in front of him by calling his friends and using AI voice clones to take over his account
- talk about how hacking has changed in the past year
- discuss how AI psychosis happens from a neuroscience perspective
- tell a never before heard story about how I almost took the worst job in history
- and what we can do to protect people from scammers in 2025 in our personal and professional life

This is also probably the funniest interview I've done in years.
I haven't gotten to laugh this hard on camera in a while.

Watch the full Scammer Payback interview on YouTube here: https://www.youtube.com/watch?v=xEdZwLRJttQ

Join me and @1kosmosblockid on 8/20 for a live hacking demo and fireside chat! I'll show how I use AI to bypass traditional defenses in Hiring, Support, Service Desk & more.
You’ll see attacks used in the wild & actionable steps to catch them!
Register to join:
https://us02web.zoom.us/webinar/register/WN_cpnNjAWYQ4OeHbxwbxJxXA#/registration
Welcome! You are invited to join a webinar: Fireside Chat and Live Hacking Demo: How I Would Hack you Live with AI . After registering, you will receive a confirmation email about joining the webinar.

What happens when one of the world’s top ethical hackers takes on the defenses of a modern enterprise? In this live, eye-opening session, renowned social engineer Rachel Tobac exposes how AI-assisted impersonation attacks are bypassing traditional technical defenses and exploiting human trust at scale. From HR onboarding to IT service desk calls, identity is being compromised before it’s even authenticated. You'll witness real-time tactics used in modern impersonation and social engineering campaigns — the same methods behind high-profile breaches at companies like Marks & Spencer, Qantas, and WestJet, and recent attacks linked to North Korean operatives targeting the Fortune 500. We'll then get actionable and focus on how you can stop these attackers in their tracks. Don’t miss this virtual showdown between today’s most advanced attacks and most resilient defenses. You’ll walk away with an understanding of how to spot the latest AI-powered attacks at both the human and technical level.

Zoom