RachelTobac Profile Banner
Rachel Tobac Profile
Rachel Tobac

@RachelTobac

Followers
105K
Following
66K
Media
2K
Statuses
25K

Friendly Hacker & CEO @SocialProofSec security awareness/social engineering prevention Training, Videos, Talks | 3X @DEFCON🄈| Chair @WISPorg | Ex @CISAgov TAC

San Francisco and Pittsburgh
Joined March 2015
Don't wanna be here? Send us removal request.
@RachelTobac
Rachel Tobac
3 years
*ANNOUNCEMENT*.Presenting: the trailer for our new šŸŽ¶MUSICALšŸŽ¶ & spoken Security Awareness Videos! After the infosec sea shanty, dozens of teams DM’d me saying "The song worked! MFA usage up, reporting way up, pls make more songs!" So we got to work & you all it's finally here!šŸ¤–
119
309
1K
@RachelTobac
Rachel Tobac
7 hours
So curious to see how YouTube enforces the ā€œreal voiceā€ element of this rule. In the age of AI voice clones, it’s increasingly difficult for humans AND technical tools to verify that a human voice is authentic, their *own* voice, and not a voice clone.
@FearedBuck
FearBuck
12 hours
YouTube will only pay creators who use their real voice and produce original content starting July 15, making reused videos, copied content, low-effort uploads, and fully AI-generated videos will be ineligible for monetization
Tweet media one
9
6
53
@RachelTobac
Rachel Tobac
9 hours
RT @a_greenberg: McDonald's uses an AI bot called "Olivia" for hiring. A pair of hackers found they could access every conversation job app….
0
290
0
@RachelTobac
Rachel Tobac
18 hours
RT @PaulSector2814: I had no idea that it was possible to do this now with such a tiny sample.
0
9
0
@RachelTobac
Rachel Tobac
1 day
We now have a case study that all AI tools will be compared to for the foreseeable future across the industry. Every major algorithm update will result in a question from Leadership and Legal: .Will this proposed algorithm change result in the tool acting like a Grok neo-nazi?.
@yashar
Yashar Ali 🐘
1 day
ā€œEvery damn timeā€ in response to a Jewish surname is a very common social media response from Neo-Nazis. Except now it’s AI.
Tweet media one
4
19
95
@RachelTobac
Rachel Tobac
1 day
RT @TipsyBacchus: I think everyone needs to watch this and understand that as the tech gets better, it’s gonna get worse and worse. so you….
0
6
0
@RachelTobac
Rachel Tobac
1 day
RT @_CoDiddy: Shit.
0
1
0
@RachelTobac
Rachel Tobac
1 day
Everyone wants a quick tool or fix to eliminate the threat of AI voice clones or video deepfakes tricking them, their family, their team, or coworkers. there is already a reliable way to do it right this second and it is: Using another method of communication. It takes a few.
0
3
24
@RachelTobac
Rachel Tobac
1 day
RT @sissythatpatch: THIS IS CRAZYYYYYYYY.
0
6
0
@RachelTobac
Rachel Tobac
1 day
Here is a video demo of how it takes me 10-15 seconds of someone’s voice online to create a believable voice clone like the Marco Rubio voicemail attack to hack in this way AND how to catch AI voice clones in action.
@RachelTobac
Rachel Tobac
1 day
AI voice clones have hit the White House AGAIN, now impersonating the Secretary of State to other Gov officials to try to steal secrets/access. Here is a video of me live demoing how quick and easy it is to clone a voice to hack and how to catch AI voice clone attacks in action!
0
4
23
@RachelTobac
Rachel Tobac
1 day
AI voice clones have hit the White House AGAIN, now impersonating the Secretary of State to other Gov officials to try to steal secrets/access. Here is a video of me live demoing how quick and easy it is to clone a voice to hack and how to catch AI voice clone attacks in action!
@Phil_Lewis_
philip lewis
2 days
Someone used AI to pose as Secretary of State Marco Rubio to contact three foreign ministers, a governor and a member of Congress .
10
98
286
@RachelTobac
Rachel Tobac
2 days
Gone are the days of trusting caller ID. We can no longer rely on ā€œknowing someone’s voiceā€ or ā€œknowing someone’s face on video callā€, I can clone those in minutes in a live audio call or video call. Verify identity using another method of communication before providing.
5
16
77
@RachelTobac
Rachel Tobac
2 days
It takes me 2 minutes total to set up a AI voice clone social engineering attack. I need about 10-15 seconds of a person’s voice to clone it well, spoof a phone call (change caller ID to display another number), and initiate a voice clone attack via call. Governments need to know.
@Phil_Lewis_
philip lewis
2 days
Someone used AI to pose as Secretary of State Marco Rubio to contact three foreign ministers, a governor and a member of Congress .
10
133
470
@RachelTobac
Rachel Tobac
2 days
2 months ago I talked thru my Bribery Emulation Pentests -- why clients have increased asks for them, what they learn, actions they take to prevent. Linking that thread below as here we have another Cred Bribery Attack this time w/ 140 MILLION in losses.
Tweet media one
@RachelTobac
Rachel Tobac
2 months
I've now done multiple social engineering pentests where discussing "lucrative business opportunities" for Support roles was in scope via phone, chat, & email if they are willing to provide user info, credentials etc. Most orgs failed, let's talk about what to do about it:.
1
16
54
@RachelTobac
Rachel Tobac
2 days
RT @DarknetDiaries: Ep 144: Rachel. @racheltobac is a social engineer. In this episode we hear how she got started doing this and a few sto….
0
185
0
@RachelTobac
Rachel Tobac
2 days
RT @grok: @Harmonic_Hearts @_oumuamua @AskPerplexity Sure, amigos! Tagging some DEFCON experts to spice up those DMs: @defcon (official), @….
0
1
0
@RachelTobac
Rachel Tobac
4 days
One thing about me is I’m always going to get 10,000 steps. In a hotel room? I’ll just pace 6 steps at a time until I hit it if I don’t feel like leaving lol.
3
3
56
@RachelTobac
Rachel Tobac
6 days
RT @butterfly7rose: @RachelTobac Nice shoutout xx šŸ¤“šŸ„³šŸ¤˜šŸ˜Ž.
0
1
0
@RachelTobac
Rachel Tobac
8 days
RT @FBI: ALERT—The FBI has recently observed the cybercriminal group Scattered Spider expanding its targeting to include the airline sector….
0
2K
0
@RachelTobac
Rachel Tobac
12 days
RT @DarkWebInformer: Good thread! šŸ‘‡.
0
1
0
@RachelTobac
Rachel Tobac
12 days
@samsabin923 Prepare your Service Desk and IT to verify that people are who they say they are with another method of communication before adding other devices, phone numbers etc to the account!.
@snlyngaas
Sean Lyngaas
12 days
In a new statement tonight, the FBI confirms that Scattered Spider (the rampant cyber criminal group) has been targeting the airline sector:
Tweet media one
0
1
6