Rachel Tobac's Avatar

Rachel Tobac

@racheltobac.bsky.social

Hacker & CEO @SocialProofSec security awareness/social engineering training, videos, talks | 3X @DEFCON๐Ÿฅˆ | Chair @WISPorg | @CISAgov Technical Advisory Council under Director Jen Easterly

12,602 Followers  |  726 Following  |  227 Posts  |  Joined: 23.04.2023  |  1.962

Latest posts by racheltobac.bsky.social on Bluesky

The Latest Messaging Scams - WhatsApp PSA
YouTube video by SocialProof Security The Latest Messaging Scams - WhatsApp PSA

See lots of scam messages via text & apps lately? Youโ€™re not alone!
Scammers are using people's economic anxiety to trick with lures that are too good or too dire to be true! They're also using AI to create attacks.
Here are the latest messaging scams + how to catch them.
youtube.com/shorts/K8x86...

05.08.2025 16:22 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Stream live news 24/7, including NBC News NOW, Sky News, Dateline, Noticias, TODAY All Day, and more. Choose your local market and stream for free today. Stream live news 24/7, including NBC News NOW, Sky News, Dateline, Noticias, TODAY All Day, and more. Choose your local market and stream for free today.

Iโ€™ll be on NBC News Now soon talking thru the Tea App hack and how to protect yourself during a data breach sometime between 7-8 pm ET tonight (probably 7:30 pm ET) if you want to watch ๐Ÿค–๐Ÿค˜
nbcnews.com/watch or www.youtube.com/watch?v=3o_t...

29.07.2025 22:50 โ€” ๐Ÿ‘ 20    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Exactly right

28.07.2025 23:21 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It doesn't matter whether this app was a honeypot or just vibe coded by a bunch of assholes with no security awareness, the impact is exactly the same

28.07.2025 23:20 โ€” ๐Ÿ‘ 25    ๐Ÿ” 4    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
A 2nd Tea App breach?! | Rachel Tobac A 2nd Tea App breach?! Now 1 million leaked messages w/ sensitive cheating stories, details of ending pregnancies, contact details, real names โ€” it could not be more serious. Here are actions to prote...

2nd Tea App breach?! 1 million messages w/ sensitive cheating stories, details of ending pregnancies, contact details, real names โ€” it could not be more serious. Here are actions to protect yourself.
Iโ€™ll be on NBC News Now at 7 pm ET tomorrow discussing this.
www.linkedin.com/posts/rachel...

28.07.2025 23:12 โ€” ๐Ÿ‘ 17    ๐Ÿ” 9    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 2

6. Why the Tea App hack matters -- why selfies and IDs together allow a hacker to perform account takeover with deepfakes and how to catch it

28.07.2025 18:20 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

4. AI voice clones and how they are hitting everyday families in the wild in 2025 to steal money & how to catch it
5. How live AI agents automate and scale hacking with voice clones over the phone and how to catch them

28.07.2025 18:20 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

2. How AI voice clones hack voice biometrics for bank account take over & how to stop it
3. Live AI deepfakes hacking KYC, liveness detection, and identity verification for account takeover for banks, social media accounts, etc & how to stop it

28.07.2025 18:19 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Time to find the right journalist(s) for live hacking demo video pieces. If you're coming to DEF CON and want a scoop, lmk:
1. How AI voice clones are currently being used to target Execs and their orgs in the wild for wire transfer fraud, passwords, and document stealing & how to stop it

28.07.2025 18:19 โ€” ๐Ÿ‘ 16    ๐Ÿ” 7    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
After $380M hack, Clorox sues its โ€œservice deskโ€ vendor for simply giving out passwords Massive 2023 hack was easily preventable, Clorox says.

@racheltobac.bsky.social arstechnica.com/security/202...

24.07.2025 03:12 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Simple as that ๐Ÿฅฒ

24.07.2025 18:41 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

took this into work today and showed folk there... I think we might see some change ... thank you for doing this

09.07.2025 09:14 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Thatโ€™s awesome!!

09.07.2025 11:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thank you!

08.07.2025 23:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I was so sad the day I realized AI could finally tackle the Irish accent. @donie.bsky.social was safe for so long

08.07.2025 23:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I guess I may need to!

08.07.2025 19:31 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Video thumbnail

AI voice clones have hit the White House AGAIN, now impersonating the Secretary of State to other Gov officials to try to steal secrets/access.
Here is a video of me live demoing how quick (2 min) and easy it is to clone a voice to hack and how to catch AI voice clone attacks in action!

08.07.2025 19:19 โ€” ๐Ÿ‘ 42    ๐Ÿ” 16    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 0

This. I know people who are naturally graceful and kind at cons like Wendy Nather or my lovely spouse @deviantollam.bsky.social or @racheltobac.bsky.social or so many other icons I look up to.

But as an introvert it is *hard* to have that energy. Itโ€™s physically draining, though very meaningful.

01.07.2025 18:11 โ€” ๐Ÿ‘ 26    ๐Ÿ” 1    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 0

Aw thank you for this kind sentiment. Itโ€™s deeply meaningful to me and after I sit in a very dark room quietly for hours to feel regulated again ha!

01.07.2025 19:55 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Thanks Andy!

30.06.2025 18:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Hacker Conversations: Rachel Tobac and the Art of Social Engineering Interview with Rachel Tobac, hacker and social engineer who is co-founder and CEO of SocialProof Security.

It's fun to learn from smart people. @racheltobac.bsky.social is smart people. Check out: Hacker Conversations: Rachel Tobac and the Art of Social Engineering. www.securityweek.com/hacker-conve... cc @gate15.bsky.social #cybersecurity

30.06.2025 13:34 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Rachel Tobac hacking in the glass booth in front of 500 people at DEF CON 25.

Rachel Tobac hacking in the glass booth in front of 500 people at DEF CON 25.

I got my start hacking in the booth at @defcon.bsky.social. It changed my life. Now I'm a *Judge* for the NEW Social Engineering Community Village AI-powered hacking competition where teams use AI agents for live phone call attacks on DEF CON Sat! Apply to compete: www.se.community/battle-of-th...

24.06.2025 23:37 โ€” ๐Ÿ‘ 46    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Rachel Tobac -  Security, hackers and password
YouTube video by Atlassian Community Rachel Tobac - Security, hackers and password

Il y a quelques annรฉes, @racheltobac.bsky.social avait adaptรฉ ce magnifique shanty ๐Ÿ˜€ www.youtube.com/watch?v=Ft5b...

21.06.2025 00:02 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

So great to join you and showcase all of my wigs, grey hair spray and glasses for live video deepfakes lol!

11.06.2025 19:34 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Another stellar Wednesday Offensive! Thank you @racheltobac.bsky.social for an engaging conversation and real time examples of the power of Deepfakes!

Next week we have Kevin Ripa discussing "When forensics gets it wrong"

#hacking #infosec #cybersecurity

11.06.2025 19:23 โ€” ๐Ÿ‘ 7    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

It's time to reorient ourselves with the Disgruntled Former Teammate & Insider Threat Prevention Handbook.

insights.sei.cmu.edu/library/the-...

06.06.2025 02:55 โ€” ๐Ÿ‘ 77    ๐Ÿ” 12    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Voice clones are easy.
Be suspicious even if a call appears to be from someone you know.
Alsoโ€ฆDonโ€™t set up voice authentication for banking.

30.05.2025 15:52 โ€” ๐Ÿ‘ 34    ๐Ÿ” 13    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Please train your team to spot and shut down voice clone attacks. This attack is easy for beginner attackers and weโ€™re seeing this attack vector increase week over week (now many of my customers have had their execs voice cloned to staff in the past quarter).

x.com/racheltobac/...

30.05.2025 14:23 โ€” ๐Ÿ‘ 7    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

Additionally, I donโ€™t need to take control of someoneโ€™s phone number to succeed with this type of attack. Often times Iโ€™m just voice cloning and spoofing a phone number to appear on caller ID (but it doesnโ€™t even seem the attacker did that in this case)!

30.05.2025 14:22 โ€” ๐Ÿ‘ 10    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I am now able to now able to create a believable voice clone using just 10 seconds of someoneโ€™s recorded voice. The tools are publicly available, easy to use, and in many cases they are free.
Itโ€™s essential your family, friends, and workplace understands how easy this attack is.

30.05.2025 14:22 โ€” ๐Ÿ‘ 11    ๐Ÿ” 4    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

@racheltobac is following 20 prominent accounts