Session
The Human Exploit Chain: How AI Turns Personal Data Into Precision Fraud
Fraud is usually analyzed at the moment of contact: the phishing email, cloned voice, fraudulent text, or urgent call. By then, the attack is already underway.
Modern social engineering begins earlier, with breached data, brokered profiles, identity resolution, relationship mapping, behavioral signals, and vulnerability discovery. Attackers combine this intelligence with generative AI, voice cloning, spoofed identities, and automated messaging to create personalized, adaptive campaigns.
This session introduces the Human Exploit Chain, a framework for mapping AI-enabled fraud from data collection and target selection through identity simulation, persuasion, multi-channel coordination, payment coercion, and repeated victimization.
Attendees will learn to analyze these campaigns as connected systems, separate new AI capabilities from accelerated old tactics, and identify practical defensive intervention points.
Session Type: Technical Conference Session / Cybercrime Research / Emerging Threats
Preferred Track: Cybercrime, AI and Cybersecurity, Threat Intelligence, Fraud, Human Factors
Technical Level: Intermediate
Preferred Duration: 45 minutes, with optional Q&A
Target Audience:
Security researchers, threat intelligence teams, fraud investigators, financial security teams, red teams, blue teams, identity specialists, privacy researchers, AI practitioners, platform security teams, and security leaders.
Technical Topics Covered:
• Data acquisition through breaches, public records, data brokers, social platforms, and compromised accounts
• Identity resolution, entity enrichment, relationship mapping, and target prioritization
• Behavioral and vulnerability profiling
• Generative AI-assisted pretexting and adaptive scripting
• Voice cloning, synthetic media, spoofing, and identity simulation
• Cross-channel attack orchestration
• Trust transitions and persuasion mechanics
• Payment coercion, mule networks, account takeover, and victim-list reuse
• Defensive telemetry and intervention opportunities
• Threat modeling for human-targeted attack systems
Original Contribution:
This session introduces the Human Exploit Chain, a security framework that models modern fraud as a connected operational system. Rather than treating phishing, impersonation, voice cloning, data brokerage, social engineering, and payment fraud as separate categories, the framework maps how they combine across seven stages:
Data acquisition
Target enrichment
Vulnerability and timing analysis
Identity construction
Persuasion execution
Channel and payment orchestration
Monetization, reuse, and repeated targeting
Each stage is evaluated through four defensive questions:
• What data does the attacker require?
• What decisions or capabilities can be automated?
• What trust transition must occur?
• Where can the operation be detected, disrupted, or delayed?
The session draws from documented fraud campaigns, cybersecurity and threat-intelligence reporting, consumer scam cases, data-broker practices, social engineering research, and lessons from building consumer fraud-prevention technology.
The presentation is vendor-neutral and will not promote specific commercial products.
First Public Delivery: New for 2026
Media Availability: Yes
Photography: Yes
Catherine (Cat) Karow
Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.
Jacksonville, Florida, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top