Darket Diaries
Darket Diaries

144: Rachel

Rachel Tobac is a social engineer. In this episode we hear how she got started doing this and a few stories of how she hacked people and places using her voice and charm. Learn more about Rachel by following her on Twitter https://twitter.com/RachelTobac or by visiting https://www.socialproofsecurit

Featured Speakers

Jack Rhysider HostRachel Tobac Guest

Topics Discussed

Episode Summary

Executive Summary: The episode follows social engineer Rachel Tobac as she explains how trust, public data, and weak identity verification can be exploited through phone calls, LinkedIn, hiring processes, and now AI voice cloning. Through real-world pen tests, she shows how companies leak sensitive information and how better protocols, training, and verification can mitigate these risks.

Main Topics: The stock prediction scam as a lesson in probabilistic deception (Priority: 5/5): A classic scam illustrates how a seemingly flawless stock tipster can appear credible by selectively telling different victims opposite predictions, then only continuing with the subset who saw success. Rachel Tobac’s path into social engineering (Priority: 5/5): Rachel describes a nonlinear journey from childhood spy fantasies and psychology/neuroscience into DEF CON, where she discovered social engineering and launched a career in ethical hacking. Social engineering contest and the power of rapport (Priority: 5/5): At DEF CON, Rachel entered the social engineering contest, using pretexting and conversational skill to extract information live on stage, which became the launchpad for her company. Bank account takeover via phone spoofing, OSINT, and document manipulation (Priority: 5/5): Rachel demonstrates how a bank support workflow can be bypassed using spoofed caller ID, public data, and fabricated identity documents to take over accounts in a controlled test. Leakage of merger and acquisition information through everyday conversation (Priority: 4/5): A tech company hires Rachel to find out why M&A news keeps leaking; she discovers that employees reveal clues through casual, non-explicit comments in interviews and elsewhere. AI voice cloning and deepfake-enabled fraud (Priority: 5/5): Rachel and Jack discuss a 60 Minutes demo where voice cloning and spoofed caller ID were used to trick a colleague, highlighting how AI undermines audio trust. Defensive practices and the future of trust verification (Priority: 5/5): The episode closes with recommendations like callbacks, one-time codes, manager verification, stronger policies, and eventually cryptographic identity checks for remote communication.

Key Arguments: Selective calling can make a random scam look mathematically impossible when it is actually just filtering for successful outcomes. Social engineering works because people naturally trust polite, plausible, and emotionally resonant requests. LinkedIn and data brokerage sites dramatically lower the cost of reconnaissance for attackers by exposing roles, email patterns, and personal details. Phone number spoofing remains a practical vulnerability because caller ID is treated as a trusted identifier even though it was not designed as one. Strong identity verification should not rely on easily discovered knowledge-based questions; multi-factor, callbacks, and service codes are better. Hiring processes and public employee chatter can leak sensitive strategic information even without malicious insiders. AI voice cloning and deepfake video will make voice and visual identity less reliable, pushing security toward cryptographic proof and pre-established trust channels.

Data Points: DEF CON social engineering contest participants: 14 contestants - Rachel describes the live contest at DEF CON where contestants attempt phone-based social engineering against a target company. Contest selection pool: Hundreds of applicants - Only 14 are chosen from a large applicant pool to compete in the social engineering contest. Rachel’s contest results: Second place three years in a row - She competed in the DEF CON social engineering contest across three consecutive years and placed second each time. Bank pen test timeline: 2 days - Rachel says her team took over each bank account they were asked to hack within two days. Bank account takeover turnaround: By 9 a.m. after 8 a.m. email - She emailed the bank at 8 a.m. and had full admin access by 9 a.m. after submitting forged verification documents. M&A interview leakage rate: 3 of 6 interviewers - During the product manager interview-based penetration test, she extracted M&A-related information from half of the interviewers. Interview prep time: 3 full weeks - Rachel says she studied for three weeks to convincingly interview for the product manager role. Voice-cloning source audio: About 5 minutes - She used roughly five minutes of Sharon’s audio from YouTube to train the voice clone for the 60 Minutes demo. Sponsored discount: 20% off - DeleteMe sponsor offer for listeners using the promo code DD20. One bank support workaround: 3 identity documents - The bank requested a driver's license, Social Security card, and utility bill as an edge-case verification method.

Pivotal Quotes: "There is an unpatched vulnerability, in my opinion. You can still spoof it." — Rachel Tobac: Rachel argues that phone number spoofing remains a security weakness because caller ID can be manipulated. "You just have to see yourself in the position." — Rachel Tobac: She explains how representation and exposure helped her realize hacking could be a real career path for women. "I mean, yeah, I can do that, but it's complicated." — Rachel Tobac: She describes the consent and planning challenges of staging a live AI voice-cloning social engineering demo for 60 Minutes.

Implications: The episode shows that human trust is now a primary attack surface. Organizations need stronger verification, better employee guidance on public disclosures, and plans for AI-era deception where voices and videos can no longer be assumed authentic.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries