Session

The Phish Is the Payload: Reconstructing the AI Fraud Stack Behind the Message

Security investigations often begin with the artifact the victim noticed: a phishing email, fraudulent text, cloned voice, fake support call, or payment request.

That artifact is usually not the attack. It is the payload produced by a larger operational stack.

Before contacting a victim, attackers can combine breached records, brokered identity data, public sources, social graphs, household relationships, property data, behavioral signals, and recent life events. Generative AI, voice cloning, spoofing infrastructure, automated messaging, and channel switching can then convert that intelligence into a campaign designed to establish trust, survive suspicion, and move the victim toward payment or account compromise.

This session reconstructs a realistic AI-enabled fraud operation from target discovery through monetization. We will map the attacker’s data sources, enrichment workflow, identity construction, pretext generation, persuasion logic, delivery infrastructure, trust transitions, and payment path.

A controlled demonstration will show how fragmented personal data can be transformed into an adaptive impersonation campaign, then trace the technical and behavioral artifacts defenders can observe at each stage.

Attendees will leave with a repeatable Human Exploit Chain model for investigating beyond the visible lure, distinguishing capabilities genuinely introduced by AI from older tactics made faster and cheaper, and identifying defensive choke points before the victim reaches the point of no return.


Session format

Conference session

Level

300: Advanced

Session duration

45 minutes

Technical content
OSINT and commercial-data acquisition
Entity resolution and identity enrichment
Relationship and household graph construction
Target selection and vulnerability signals
Synthetic identity and pretext generation
Voice-cloning workflow and limitations
Caller-ID spoofing and communications infrastructure
Cross-channel campaign orchestration
Payment coercion and monetization paths
Detection artifacts and intervention opportunities
Threat modeling for human-targeted operations
Demonstration

A safe, controlled reconstruction using a synthetic target profile:

Assemble fragmented identity data
Build a relationship graph
Generate and adapt a fraud pretext
Produce a synthetic identity artifact
Move the campaign across channels
Map telemetry and interruption points

No live victim data, criminal services, or operational abuse infrastructure will be used.

Attendee takeaways
Reconstruct AI-enabled fraud beyond the email, text, or call that triggered the investigation
Map attacker inputs, tooling, dependencies, trust transitions, and observable artifacts
Identify opportunities to disrupt targeting, impersonation, delivery, and monetization before loss occurs
Why it is new

The contribution is not another overview of AI scams. The session models fraud as a connected technical and behavioral system, showing how lawful data, compromised data, communications tooling, generative systems, and payment infrastructure combine into one operational chain.

Speaker notes

This session is vendor-neutral and contains no ZoraSafe product demonstration. It draws from documented fraud patterns, threat research, consumer cases, social-engineering analysis, and direct experience building human-centered fraud defenses.

Catherine (Cat) Karow

Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.

Jacksonville, Florida, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top