You’ve Been Ph0wned: How Attackers Compromise Organisations Via Telephone Social Engineering
Modern vishing attacks exploit the tension between fast, helpful support and rigorous identity verification, enabling a single convincing phone call to bypass even strong technical controls.
Drawing on real-world red team engagements and a live AI voice-cloning demonstration, this session examines the full attack lifecycle - from reconnaissance and pretext development to human manipulation and account compromise. Attendees will gain practical guidance for planning safe, ethical and effective vishing simulations, including actionable lessons and common pitfalls encountered in the field.
While just about everyone has trained users not to click suspicious emails, attackers have quietly moved to the channel nobody prepared for: the phone. From retail giants and luxury brands to automotive manufacturers and casino operators - all have suffered massive financial damages from attacks that started with something as simple as a phone call.
Drawing from real world red teaming engagements, Luiz will walk through the modern vishing playbook: how attackers research targets, craft believable pretexts, pressure helpdesks into breaking their own security policies, and bypass multi factor authentication that was supposed to end credential theft.
The talk includes a live AI voice cloning demonstration, honest discussion of the ethical challenges in realistic social engineering testing, and practical defences that go beyond "just be suspicious of phone calls".
Luiz leads the Offensive Security practice at Bridewell and has 2 decades of experience as a penetration tester, red team manager and leader.
He is a Chartered Cyber Security Professional (ChCSP), holds an MSc in Information Security from Royal Holloway along with various industry certifications.
Luiz has a particular interest in user-driven attacks, and leveraging social engineering to bypass technical controls.