Hackfest - Level UP

How to Make $25K in 60 Seconds in 2026: ShinyHunters, BEC & the Industrialization of Cybercrime
Langue: Français

A compromised mailbox.
One fake invoice.
One Teams message.
One trusted supplier.

60 seconds later:
$25,000 is gone.

Welcome to cybercrime in 2026.

This talk dives into the industrialization of Business Email Compromise (BEC) and modern financially motivated threat actors like ShinyHunters, showing how attackers evolved from “hackers” into highly efficient cyber businesses.

The scary part?
Most attacks no longer rely on advanced malware or zero-days.

They rely on:
- trust
- weak processes
- social engineering
- MFA fatigue
- Shadow AI
- overprivileged accounts
- and humans moving too fast

We’ll break down real-world attack chains used today against organizations of all sizes:
from mailbox compromise to vendor impersonation, internal fraud, data theft and payment diversion.

We’ll also explore how modern threat actors weaponize:
- leaked credentials
- infostealers
- cloud identities
- AI-generated phishing
- session hijacking
- and trusted collaboration tools like Teams, Slack and SharePoint

And while everyone is chasing “next-gen AI security”…
many organizations still use weak passwords, lack MFA coverage, have no tested recovery process, and trust email far more than they should.

This is no longer cybercrime.
It’s operationalized digital fraud at scale.

Participants will leave with:
- A better understanding of modern BEC tradecraft
- Why attackers target finance and operations teams first
- How ShinyHunters-style operations scale so efficiently
- The role AI and Shadow AI now play in fraud
- Practical ways to reduce exposure immediately

The future of cybercrime is fast, scalable and frighteningly human.


Story-driven conference mixing:
- real-world incidents
- threat intelligence
- attacker methodology
- financial fraud evolution
- AI-enabled phishing and impersonation
- operational security failures

The presentation is designed to be highly engaging and accessible while remaining technically credible.

Audience:
Intermediate to advanced security professionals, IT leaders, SOC analysts, executives and incident responders.

Strong focus on:
- BEC evolution
- ShinyHunters ecosystem
- identity compromise
- operational trust abuse
- AI-assisted fraud

L'image de profil de l'intervenant
Julien Turcot

With 20+ years in cybersecurity, Julien Turcot empowers businesses to thrive amid digital threats. As GoSecure's SVP of Sales, he crafts innovative strategies, nurtures relationships, and ensures exceptional service. Julien's leadership, strategic vision, and community engagement make him a cybersecurity luminary.