2026 Session
Escambia Ballroom
4:35 pm - 5 pm, Tuesday, October 13
What AI Needs to Attack Your People Is Already Public
About

Attacking one of your people takes a list of facts about them, nearly all of it public. AI can now assemble this in minutes. The same list serves a vishing call, a credential reset that should never have been approved, a deepfake, or a spear phish.

Start with what is out there. The National Public Data breach lost Social Security numbers and address histories, the proof many recovery processes accept. AT&T lost call records showing who an employee talks to and who their mobile carrier is. Coinbase lost government ID images, what an identity vendor checks a selfie against. Infostealer logs carry reused passwords and session cookies. Roles and voices sit in LinkedIn, public filings, and earnings calls. Any one of these has limited organizational security risk. Assembled into one profile, they are able to be effectively weaponized by an attacker using AI.

In early August, Bloomberg reported a coordinated voice-phishing campaign against Citadel, Point72, Two Sigma and Millennium Management, where attackers used AI cloned voices of trusted employees to get credentials and access. No software was exploited. The profile was the weapon.

What changed in the world is that building that profile stopped being work. It used to take attackers days, and that slowness was the defense. Anthropic's November 2025 GTG-1002 report described a Chinese state-sponsored group using Claude Code against roughly 30 organizations, with the AI doing its own reconnaissance and 80 to 90 percent of the tactical work.  It worked on its own for one to four hours at a stretch while its human operator spent two to ten minutes reviewing and approving. What took days now takes minutes, and it runs against the whole workforce in parallel. Advancing AI has changed the landscape and how security teams need to operate.

Seniority is not what makes someone a target. What matters is whether your systems or processes act on their say-so, and whether their verification questions can be answered from a breach dump. The help desk agent who resets credentials. The admin with standing access. Whoever releases payments.

The key insight is that every one of those attacks relies on a recipe of exposed identity data ingredients. Attacks are only able to succeed if the underlying ingredients for a given recipe can be weaponized. Countermeasures applied against the right ingredients break the attack chain and disrupt the attacker’s campaign. Six categories of countermeasures offset AI exposed identity risk:

  1. Enforcement initiates a technical control as the countermeasure. Sessions revoked, a reset forced, conditional access narrowed, triggered by identity exposure.
  2. Gating gives your systems and alerts context on what is exposed. If a date of birth and address sit in a dump, the help desk solution should not treat them as evidence of identity.
  3. Removal takes the record down where one actually can.
  4. Suppression goes after visibility rather than existence, pushing a record out of reach when it can’t be removed.
  5. Coaching reduces the risk from the employee whose own post just supplied a travel pattern or a vendor used.
  6. Advisory changes an organizational process, like confirming a voice-approved payment on another channel.

None of this can run on a schedule to be effective. New exposure appears constantly, and each addition can complete a recipe that was incomplete yesterday. This causes your people's risk posture to change without anyone telling you, and today there is no alert and no way to offset it. AI fueled reconnaissance and attacks are automated and continuous, so countermeasures have to be too, which means defense needs the machinery offense is already using.

Many security teams are adding this control to their security program. External identity security measures how exploitable your workforce is to AI and drives that number down without anyone filing a ticket. It belongs alongside identity and human risk, and is the missing half of both.

As part of this session, we will work one attack end to end, listing every fact the attacker needs, where it lives, and which countermeasure keeps the attack from completing. I will also show a matrix scoring all six countermeasures against cyber attacks, impersonation, deepfakes, harassment and physical targeting, because those differences decide what you should prioritize first.

Attendees leave with a blueprint for standing up an external identity practice inside an existing security program, and a maturity path for growing it.

I will close with what we built at VanishID to run all six external identity mitigations continuously and advance that maturity.

Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Interested in speaking at the event?

InfoSec World
Stay
Informed
Join our mailing list for the latest news on InfoSec World 2026.