Session

The Phish Is the Payload: Reconstructing the AI Fraud Stack Behind the Message

Security teams often begin investigating where the victim first noticed the attack: the text, email, cloned voice, fake support call, or payment request.

That is usually the final delivery mechanism, not the operation.

Before contact, attackers may already have assembled breached credentials, brokered identity data, household relationships, public records, behavioral signals, recent life events, and likely sources of authority. Generative AI, voice cloning, spoofing infrastructure, and automated messaging then convert that intelligence into a personalized campaign designed to survive suspicion and move the victim across channels.

This session tears down a realistic AI-enabled fraud operation from target discovery to monetization. We will reconstruct the attacker’s data sources, enrichment workflow, identity fabrication, pretext generation, trust transitions, channel orchestration, and payment path. At each stage, we will map required inputs, tooling, dependencies, observable artifacts, and opportunities for disruption.

Attendees will leave with a reusable Human Exploit Chain model for investigating what happened before the visible lure, separating truly new AI capabilities from familiar tactics operating at greater speed and scale, and designing controls that interrupt the campaign before the victim reaches the point of no return.


Session Format

1-hour technical talk

Topics

AI Security
Social Engineering
Threat Intelligence
OSINT
Fraud and Cybercrime
Threat Modeling
Blue Team
Privacy

What will attendees walk away with?

• A method for reconstructing fraud operations beyond the email, text, or phone call that triggered the investigation
• A seven-stage model for mapping attacker data, tooling, decisions, dependencies, trust transitions, and observable artifacts
• Defensive intervention points across identity systems, communications platforms, financial controls, enterprise telemetry, and consumer protection

Level

Intermediate

Can we record your talk?

Yes. The session may be recorded and published.

First-Time Speaker?

No.

Can you present in person in Huntsville March 20?

Yes.

Workshop Logistics

Not applicable. This is a one-hour conference talk.

Catherine (Cat) Karow

Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.

Jacksonville, Florida, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top