Hackfest - Level UP

Scammers Keep Winning: Why Humans and AI Fall for the Same Hustles
Langue: English

Ancient cons still work. Technology just made them faster, cheaper, and easier to scale. What hasn’t changed is the logic that makes them work.

Treating deception as a “spot the artifact” game has failed. Bad grammar, foreign accents, suspicious links, strange senders, and even valid SSL certificates are all just surface cues that tell us nothing about whether the request itself can be trusted. Attackers can use machines to polish the presentation or leverage compromised trusted accounts to appear genuine.

The deeper problem is that both human judgment and machine guardrails can be fooled by the same thing: a convincing request built on deceptive logic.

Using real-world attack recordings and examples ranging from traditional social engineering to recent attacks against AI agents, we’ll examine how the same underlying attack logic can bypass both human judgment and machine guardrails. We'll look beyond the individual psychological tricks to the simple, repeatable logic exploits that make them work.

Attendees will leave with a practical way to recognize and dissect these attacks based not on how they look or how they arrive, but on what they are trying to make the target believe and do.


Intro: We teach the packaging, not the lie

Most security awareness focuses on how a message arrives or how it’s dressed, treating the full range of surface cues, from bad grammar and foreign accents to SSL checks and link inspection, as indicators of whether a message is genuine.

While these heuristics can and do catch low-effort scams, they can also backfire. Some people treat every message as a spot-the-artifact game and waste time on false positives. Others resent the effort, get overwhelmed, and start ignoring the constant warnings. And when a genuine message gets flagged or rejected and disrupts business, it undermines the whole effort for anyone who notices.

Meanwhile, an attacker who cleans up the surface, for example by using AI to fix the spelling and graphics or by sending from a compromised legitimate account, sails through and earns more trust, while the honest coworker in a hurry gets the third degree.

Furthermore, every successful attack creates more training that users must sit through. With each additional round, their focus shifts from “What can I learn?” to “What tricks can I use to get through this as quickly as possible?”

The problem is that this approach teaches people to inspect the packaging rather than the proposition. A convincing approach can have perfect spelling, come from a legitimate account, use official-looking graphics, or even sound exactly like someone you know, while still asking you to do something you shouldn’t. The more useful question is not “Does this look or sound legitimate?” but “What is this person asking me to believe and do, and why?”

The Same-Hand Tell

In poker, a “tell” is an unintentional behavior that reveals something about a player. It gives you a reason to question what they’re representing. It doesn’t reveal their cards or prove a bluff. It simply says: stop and look harder.

In deception, there are tells too. One of the most useful comes from a simple fact: an attacker needs something from you and is typically pressed for time because their window closes as your awareness grows. As a result, they often offer both an urgent problem and an easy solution, from the same hand.

The tell is simple:

When a problem and its solution come from the same hand, verify both independently.

While the tell alone doesn’t make a message deceptive, legitimate interactions do this all the time. It is a structural signal that a message could be deceptive, and therefore deserves independent verification, especially when the party is unknown or untrusted.

Because this is a structural tell rather than a surface cue, it can be checked by machines as well as people. A system can flag any message in which the source that presents the problem is also the one proposing the solution.

A “hand” may include multiple people, accounts, or channels. If the sources are connected, treat them as the same hand.

The GRIFT Cycle

The Same-Hand Tell is one recurring marker, but it’s part of a larger pattern. Across very different forms of deception, the same basic mechanics appear again and again.

The GRIFT Cycle — Game (research and plan), Rile (manufacture urgency), Invite (offer a golden bridge out), Fleece (extract value), and Twist (exit or escalate) — gives us a common structure for pulling those mechanics apart.

It makes attacks easier to dissect, discuss, and teach without getting lost in technical details. Different stories suddenly have the same backbone, whether we’re looking at an old confidence game, a new social engineering attack, or even a con from a movie. And when the next attack comes along, we can run it through the same framework again, reinforcing the pattern rather than adding another warning.

Putting it to work

The framework becomes most useful when we stop talking about it and start applying it. We’ll use examples, recordings, and real-world interactions, stopping along the way to map what’s happening onto the GRIFT Cycle and identify the mechanics as they unfold.

We’ll move from crude scams to sophisticated schemes, including EchoLeak, where Microsoft 365 Copilot followed “authoritative” instructions supplied by the attacker rather than independently verifying them, all without human interaction. Across these examples, we’ll see how the details and technology change while the underlying mechanics remain remarkably consistent.

Takeaway

This isn’t a call to be more suspicious of everyone. It’s a call to read how requests are built instead of how they’re packaged. Use the GRIFT Cycle instead of chasing a hundred different scams. Watch for the Same-Hand Tell and catch the con before the decision window closes.

The structure gives it away. Attendees leave with a repeatable framework for dissecting social engineering, whether they build systems, defend them, or train people.

L'image de profil de l'intervenant
Alex Kasper

Alex is an American technology executive and former hacker. In the 1980s and 90s in Los Angeles, he ran with a group of young hackers and phone phreaks that included Kevin Mitnick, with whom he created and taught the Certified Social Engineering Prevention Specialist (CSEPS), the world's first social engineering prevention certification. He now researches AI deception and is writing a book on the subject. Alex married a Canadian, recently immigrated to Montreal, and is now learning French.