Sign in

Rachel Tobac

@racheltobac.bsky.social
13K followers 763 following 293 posts

Hacker & CEO @SocialProofSec security awareness/social engineering training, videos, talks | 3X @DEFCON🥈 | Ex Chair @WISPorg | Ex @CISAgov Technical Advisory Council under Director Jen Easterly

PostsRepliesMedia
Reposted by Rachel Tobac
Ian Coldwater 🧊🚫 @lookitup.baby · 26/09/2026
Wait, you didn’t know that? Yeah, I’m smol I think @whit.zip and @racheltobac.bsky.social are the only people I’ve met in infosec who are shorter than me
172
Reposted by Rachel Tobac
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 30/07/2026
Finally some good innovation from LinkedIn.
26516
Rachel Tobac @racheltobac.bsky.social · 30/07/2026
The new “⚠️Seems like AI slop” button on LinkedIn is sending me into orbit lmao
1419735
Reposted by Rachel Tobac
typing loudly ⌨️ @typingloudly.zip · 29/07/2026
my LI feed is basically just @lauriewired.bsky.social and @racheltobac.bsky.social because I thumbs down all the slop
221
Reposted by Rachel Tobac
Marko Bevc @marko.social · 22/07/2026
That's not a lot of reflection to go on 🤯
121
Reposted by Rachel Tobac
Zemich @zemich.bsky.social · 21/07/2026
This is scary; Start the cleanup 😆
021
Rachel Tobac @racheltobac.bsky.social · 21/07/2026
Was curious if I could use AI (Graylark) to find coordinates of this house using just a *reflection in a keypad* of the surroundings. Well...it worked. YIKES. Daniel Heinen does not make this AI tool available to the public for this reason. youtube.com/shorts/Xzbvi...
youtube.com
Can AI geolocate using just reflections?!
YouTube video by SocialProof Security
1189
Rachel Tobac @racheltobac.bsky.social · 25/06/2026
This year WISP is sending 41 Scholars to @defcon.bsky.social / @blackhatevents.bsky.social to find their community, new skill, or next job! I just donated $1K to cover 1 scholar’s WISP support team, swag, events, community room, etc. Who’s matching me! wisporg.app.neoncrm.com/forms/wisphsc26
0164
Rachel Tobac @racheltobac.bsky.social · 11/06/2026
Doing an AMA style panel for our ContinuumCon opening keynote tomorrow! We need your questions to answer, drop them below! What do you want us to talk about? List anything you want to know more about below! Cc: @johnhammond.bsky.social @rekdt.com @jun34u.bsky.social continuumcon.com/schedule/
continuumcon.com
Schedule
ContinuumCon is the cybersecurity conference that never ends. It's a hands-on workshop and interactive lab environment that meets you where you are. Sessions range from foundational concepts to cuttin...
252
Reposted by Rachel Tobac
Zoz @mrzozelow.xyz · 02/06/2026
In the age of tech companies consistently doing shitty things, this is genuinely cool and a smart solution to stopping Scammers with RCS (meaning it's encrypted and private too)!
182
Reposted by Rachel Tobac
Victoria McIntosh @vmcntosh.bsky.social · 02/06/2026
Now we’re talking 🎉
172
Rachel Tobac @racheltobac.bsky.social · 02/06/2026
WHOA Google let me know they saw my tweet last year & built a tool to defend against the exact call spoofing + AI voice clone attack! As of *today*, fake call detection on Android alerts when someone is impersonating your contact. Thread and demo below:
35517
Rachel Tobac @racheltobac.bsky.social · 27/05/2026
I used deepfakes & injection attacks to hack an identity verification tool used for remote workforce, helpdesk, & onboarding…until they updated the tool to catch me. Thank you @incode.bsky.social for having me hack you 110+ times to find the latest vulns and fix them🤖🤘 Full vid: youtu.be/pAegYkwWIgE
2191
Reposted by Rachel Tobac
Stephanie Hughes @hughesstephanie.bsky.social · 14/05/2026
"If there's one thing I could tell people to do, it would be to use a password manager. Do not reuse old passwords." @racheltobac.bsky.social, on how to protect yourselves from hacks
1195
Rachel Tobac @racheltobac.bsky.social · 12/05/2026
Whoa, Instructure (who owns Canvas) says they came to an agreement with the cyber criminals (typically this means a ransom was paid) in exchange for the stolen data being deleted instead of leaked and criminals ceasing all extortion requests from customers. Huge development.
23717
Rachel Tobac @racheltobac.bsky.social · 08/05/2026
Canvas is hacked and stressing out 230+ million students, teachers and staff during finals. What does this mean and how do we stay safe? What are the next steps for the 8,800 affected schools during finals. Answered below in my video:
43214
Reposted by Rachel Tobac
Brian Honan @brianhonan.bsky.social · 29/04/2026
My dad told me if I'm the smartest person in a room, then I'm in the wrong room. For the @rapid7.com Global #Cybersecurity Summit I'll be in the right room as I'll be joined by @rajsamani.bsky.social @racheltobac.bsky.social & @grahamcluley.com for the Keynote Panel. Join us rapid7.brighttalk.com
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
0103
Rachel Tobac @racheltobac.bsky.social · 23/04/2026
Have you received a party invite that turned out to be fake (a scam!) in the last 6 months?! I just broke down how this scam works for the @nytimes.com, dive into the 2 distinct paths this scam follows, how to catch it, and how to reduce its impact if you do click: www.nytimes.com/2026/04/23/s...
nytimes.com
There’s a New Phishing Scam: Fake Invitations
1103
Rachel Tobac @racheltobac.bsky.social · 15/04/2026
Want my thoughts on Anthropic's Mythos risk vs hype, how I use AI to bypass identity verification systems now, & more? Tune in for my Rapid7's 2026 Global Cybersecurity Summit keynote panel 5/12 with Graham Cluley, Raj Samani, Brian Honan! Join me here: rapid7.brighttalk.com
171
Reposted by Rachel Tobac
Graham Cluley @grahamcluley.com · 14/04/2026
I'm speaking at Rapid7's 2026 Global Cybersecurity Summit, May 12-13. Come hear me chat about how modern attacks actually start, and the reality of running a SOC in 2026 - alongside @racheltobac.bsky.social, @rajsamani.bsky.social, and @brianhonan.bsky.social rapid7.brighttalk.com?utm_source=r...
rapid7.brighttalk.com
Rapid7 2026 Global Cybersecurity Summit | Virtual Event
Join Rapid7’s 2026 Global Cybersecurity Summit, a two-day virtual event on preemptive security operations, cyber resilience, MDR, and AI-driven defense.
073
Reposted by Rachel Tobac
Joseph Lorenzo Hall, PhD @josephhall.org · 14/03/2026
Going to this UN thing in Vienna with my team and the only name I recognize on the program is @RachelTobac (which is a good sign! So much to learn about scams!)
2102
Reposted by Rachel Tobac
dervishe the grey @dervishe.eurosky.social · 14/03/2026
This is still a good reminder from @racheltobac.bsky.social
youtube.com
Rachel Tobac - Security, hackers and password
YouTube video by Atlassian Community
151
Reposted by Rachel Tobac
Ilthea 🏳️‍🌈 🧞‍♀️ @ilthea.hackandarrow.com · 27/02/2026
I watch my company’s security awareness training just because the speaker is @racheltobac.bsky.social
3111
Reposted by Rachel Tobac
Ian Coldwater 🧊🚫 @lookitup.baby · 26/01/2026
Signal will never message you like this. If you get a message like this, SOMEONE IS TRYING TO HACK YOUR SIGNAL. DO NOT GIVE THEM THAT CODE.
Message from "Signal Support"

Dear User, this is Signal Security
Support ChatBot.

Our system has detected a recent login attempt to your account from an unrecognized device or location. As a security measure, we have blocked this attempt and sent a verification code via
SMS to your registered phone number.

If this was NOT you: To secure your account and block this unauthorized access, please reply to this message with the verification code
you just received.

If this WAS you:
You can safely ignore this message. The login attempt will be automatically approved shortly. 

Thank you for helping us keep your
account secure.
1519731279
Reposted by Rachel Tobac
Andrew Couts @couts.bsky.social · 28/01/2026
WARNING, fellow journalists: As @nicoschmidt.io explains, attackers are trying to hijack reporters' Signal accounts by tricking people into handing over their 2FA codes. www.linkedin.com/posts/nicosc...
In the last days, there has been an unprecedented attack targeting investigative journalists trying to seize their Signal accounts. This has gone largely unreported.

I have been repeatedly targeted by phishing, and I learned that also colleagues from other outlets were targeted, with the attackers unfortunately managing to compromise at least one colleague’s account. What’s worrying: this doesn’t seem like an isolated case. A broader wave is apparently hitting journalists (and some civil society actors) via Signal.

How it works: Attackers message you on Signal pretending to be “Signal Support,” warning about “suspicious activity,” and urging you to “re-verify” your account. Once you accept the chat, you receive a real Signal SMS verification code, because the attacker is actively trying to register your number on a new device. If you share that code, you’re handing them the keys. 

Signal’s extra protection is the Signal PIN. If an attacker also tricks you into giving up your PIN (or you don’t have strong protections enabled), they can see your contacts and networks, potentially join chats going forward, and lock you out by changing settings. 

Quick protections worth doing today:
- Signal will never contact you via a two-way in-app support chat. Treat those messages as hostile. 
- Never share SMS codes, Signal PIN, or anything called “registration lock.” 
- Turn on Registration Lock (Settings → Account → Registration Lock). 
- If you see a “safety number changed” alert: verify the person via a different channel (call/video), not just Signal text. 
- Report + block suspicious requests, and review linked devices. 

If you work with sensitive sources: this isn’t just about losing an account, it’s about exposing networks. Please share this with colleagues who rely on Signal day-to-day.
11878663
Rachel Tobac @racheltobac.bsky.social · 27/01/2026
If you’re an activist, journalist, exec, or have a high threat model for any other reason, I do recommend using all tools to protect against spyware including Apple’s lockdown mode and WhatsApp’s new Strict Account Settings. Thanks WhatsApp for the partnership to get the word out to folks.
4258
Rachel Tobac @racheltobac.bsky.social · 14/01/2026
The repairable, customizable, build-it-yourself, physical webcam & mic kill switch, Linux compatible, port swappable @frame.work laptop has hit the SocialProof office 🤖🤘
5703
Reposted by Rachel Tobac
andy jabbour @andyjabbour.bsky.social · 10/10/2025
Great work from @racheltobac.bsky.social, with @cnn.com: How the latest deepfake scam can cheat companies out of millions. Good one to share with your company, and with friends & loved ones. edition.cnn.com/2025/10/07/b... cc @craignewmark.bsky.social @pausetake9.bsky.social @gate15.bsky.social
edition.cnn.com
How the latest deepfake scam can cheat companies out of millions | CNN Business
From CEOs to colleagues, deepfake technology can trick people into sending money, sharing passwords, or revealing sensitive information - all in seconds. CNN’s Clare Duffy met with ethical hacker and ...
21210
Reposted by Rachel Tobac
jalal on eurosky @satori.cafe · 13/10/2025
An totally entertaining, and informative interview with @racheltobac.bsky.social and Scammer Payback about hacking and handling your online privacy in the new epoch of AI. youtu.be/xEdZwLRJttQ?...
youtu.be
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
2339
Reposted by Rachel Tobac
Across the Pondcast @acrosspondpod.bsky.social · 24/10/2025
Episode 22: Social Engineering, Gas Mark 4, and AGAs with Rachel Tobac! @tib3rius.bsky.social & @swiftsecur.bsky.social are joined by @racheltobac.bsky.social to talk social engineering war stories...and more! Links below!
143
Reposted by Rachel Tobac
WIRED @wired.com · 22/10/2025
“The consumer’s son has been interacting with an AI chatbot called ChatGPT, which is advising him not to take his prescribed medication and telling him that his parents are dangerous,” reads the FTC’s summary of one of the calls.
wired.com
People Who Say They’re Experiencing AI Psychosis Beg the FTC for Help
The Federal Trade Commission received 200 complaints mentioning ChatGPT between November 2022 and August 2025. Several attributed delusions, paranoia, and spiritual crises to the chatbot.
23516
Reposted by Rachel Tobac
Mike Sager @mikesager.net · 16/10/2025
Hey @racheltobac.bsky.social you're probably going to need to hire a lot more people for all the new clients you're about to get.
181
Rachel Tobac @racheltobac.bsky.social · 09/10/2025
*My Latest CNN Zoom Call Deepfake Demo* An eng org sent $25M to scammers who deepfaked the CFO in a live video call. Are your colleagues, fam & friends ready to catch this AI attack? I demo'd a live Zoom deepfake to CNN's Clare Duffy to help you spot the signs: edition.cnn.com/2025/10/07/b...
edition.cnn.com
How the latest deepfake scam can cheat companies out of millions | CNN Business
From CEOs to colleagues, deepfake technology can trick people into sending money, sharing passwords, or revealing sensitive information - all in seconds. CNN’s Clare Duffy met with ethical hacker and ...
12212
Reposted by Rachel Tobac
The New York Times @nytimes.com · 02/10/2025
Two of our tech reporters tested out Sora, a smartphone app made by OpenAI that lets people create videos entirely from A.I. “It is, in effect, a social network in disguise; a clone of TikTok down to its user interface, algorithmic video suggestions and ability to follow and interact with friends.”
nytimes.com
OpenAI’s New Video App Is Jaw-Dropping (for Better and Worse)
224711
Reposted by Rachel Tobac
Alan Stamm @alanstamm.bsky.social · 03/10/2025
"It makes it really easy to create a believable deepfake in a way that we haven’t quite seen yet." -- @racheltobac.bsky.social, CEO of SocialProof Security, a cybersecurity start-up in San Francisco
162
Reposted by Rachel Tobac
Traci @butterfly7rose.bsky.social · 29/09/2025
@racheltobac.bsky.social new threat model for businesses? 😬😵‍💫
3102
Reposted by Rachel Tobac
707Kat @707kat.bsky.social · 17/09/2025
This should be mandatory watch by everybody who has a phone and or email. @racheltobac.bsky.social shows how vulnerable we all are to getting hacked through social engineering and with gAI tools it's only gotten easier.
youtube.com
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
2459
Reposted by Rachel Tobac
Riccardo Mori @morrick.bsky.social · 10/09/2025
I only watched this today, but I enjoyed it immensely. So many security lessons in a very entertaining package. 😊
1122
Reposted by Rachel Tobac
Amber Mac @ambermac.bsky.social · 06/09/2025
🪞Does ChatGPT think you're perfect? You're not alone. 🎧 On this week's episode of The AmberMac Show podcast, @racheltobac.bsky.social and I chat about the sycophantic nature of this popular tool. Listen to the full episode here: bio.site/ambermac
1101
Reposted by Rachel Tobac
Amber Mac @ambermac.bsky.social · 06/09/2025
💻 When I need to learn more about AI safety & security, I ask @racheltobac.bsky.social. You may have seen her on 60 Minutes. I met Rachel when I interviewed former FBI Director James Comey at an event (we all had dinner the eve before, that's a whole other story!). www.youtube.com/watch?v=cule...
youtube.com
AI Safety & Security with Ethical Hacker Rachel Tobac [The AmberMac Show Ep029]
YouTube video by Amber Mac
0154
Reposted by Rachel Tobac
Amber Mac @ambermac.bsky.social · 03/09/2025
🥺 Are chatbots dangerous for our kids? 🎙️ We are dedicating this week's new episode of The AmberMac Show podcast, out today, to this topic 👇 bio.site/ambermac @racheltobac.bsky.social on some of these risks @jeffmacarthur.bsky.social on the dangers of chatbots becoming a "mentor" in the home
0162
Reposted by Rachel Tobac
Marko Bevc @marko.social · 02/09/2025
Great interview with @racheltobac.bsky.social shining a light in a lot of important topics, like what are likely attack vectors, impact of #AI on #security, #ethics, affecting social interactions and #privacy . "Be politely paranoid." 👏 www.youtube.com/watch?v=xEdZ...
youtube.com
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
3126
Reposted by Rachel Tobac
Lisi Hocke @lisihocke.bsky.social · 30/08/2025
If you want to learn more on how easy these things are these days especially given AI tooling, I recommend following @racheltobac.bsky.social and her fabulous work on social engineering. Learned a bunch from her and her demonstrations. Latest video I loved: youtu.be/xEdZwLRJttQ
youtu.be
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
2183
Reposted by Rachel Tobac
Marc @not-mark.bsky.social · 28/08/2025
This was a VERY eye opening and informative interview that is worth watching!
172
Reposted by Rachel Tobac
Zemich @zemich.bsky.social · 21/08/2025
Definitely worth a look. Scary world we live in at the moment 😱 When do people wake up - What can we do 🤔?
281
Rachel Tobac @racheltobac.bsky.social · 21/08/2025
*New live hack demo - stealing security question answers w/ AI voice clones* At @defcon.bsky.social I went on ScammerPayback podcast and hacked the host by calling his friends & stealing answers to his bank's password reset questions using a voice clone w/in 10 secs. www.youtube.com/watch?v=xEdZ...
youtube.com
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
64415
Rachel Tobac @racheltobac.bsky.social · 19/08/2025
Live from New York it’s hackers at Nasdaq! Great to go live with @davegerryjr.bsky.social @bugcrowd.com in Times Square today to talk ethical hacking, security and AI!
4212
Rachel Tobac @racheltobac.bsky.social · 18/08/2025
Today at #GRCConf I show up to tech check for my keynote at 7 am and Jackie Burns (the longest running Elphaba from Wicked) is there and that’s the moment I realized the opener before my keynote was Elphaba singing Defying Gravity. I’ll never be the same lol
2241
Rachel Tobac @racheltobac.bsky.social · 13/08/2025
Join me and 1Kosmos on 8/20 for a live hacking demo and fireside chat! I'll show how I use AI to bypass traditional defenses in Hiring, Support, Service Desk & more. You’ll see attacks used in the wild & actionable steps to catch them! Register to join: us02web.zoom.us/webinar/regi...
0101