Talks


Keynote Speakers:
Friday, 1:00 pm
Christina Lekati – “The Social Engineering Threat Landscape: Campaigns, Actors, and Emerging Trends”

Saturday, 1:00 pm
Micah Hoffman – “Become a Creator — Building the Community That Builds OSINT”

Friday: 10:30 am
Drones in Intelligence
William Ruzich
A former U.S. military intelligence specialist, Will has built a private sector career focused on financial fraud, human trafficking, and government advisory work. As a certified drone operator, he will present on the effective and lawful use of drones in investigations, highlighting practical applications and operational considerations.

Friday: 10:30 am
My OSINT F*ckups – What I’ve learned
Lisette Abercrombie
An OSINT mistake is easily made…just one click of a button and you’ve accedently liked your targets profile picture. That moment when you feel that all of you intestants sink to your feet, is a moment Lisette knows quite well. She’s made some pretty horrible mistakes, and learned some lessons the hard way. She wants to share what she’s learned with you. So you don’t have to make that same mistake ;-)!

Friday: 11:00 am
The Scammer Industrial Complex: Measuring the Impact of Enforcement Raids
Adam McNeil
Pig-butchering scams have evolved into one of the most profitable social-engineering operations in the world, powered by large criminal compounds operating across Southeast Asia. In recent months, governments have conducted high-profile raids against these operations, arresting workers, dismantling compounds, and seizing infrastructure. But do these enforcement actions actually disrupt the scam ecosystem?

This talk examines that question through the lens of real messaging data. Using large-scale analysis of reported scam messages, we track pig-butchering activity across multiple enforcement events targeting major scam compounds. The results show clear and measurable disruptions following raids, and the adaptation and recovery as operations reorganize, relocate, and resume activity.

By analyzing messaging patterns before and after enforcement actions, we can observe how the broader scam ecosystem behaves under pressure. Some raids produce sharp declines in scam messaging, while others appear to have little lasting effect. In other cases, the disruption is temporary as the underlying criminal supply chain remains intact.

The findings reveal an uncomfortable reality: pig-butchering scams now operate as an industrial complex capable of absorbing enforcement shocks. Understanding how these operations respond to disruption is critical for investigators, threat researchers, and policymakers seeking to reduce the impact of global scam operations.

Friday: 11:00 am
Its in the method Man by Redman
Brett Redman
In an era of unprecedented access to data, open-source intelligence has never been more visible, more automated, or more misunderstood. Tools are faster, datasets are larger, and confidence often arrives long before understanding. Yet many OSINT failures still stem from the same place: the human layer.

This talk uses the cultural lens of hip-hop, and in particular the idea of “method” embodied by Method Man and Redman, to explore why discipline, structure, and judgement matter more than volume, speed, or tooling. Drawing on real investigative practice, the presentation examines how OSINT investigations succeed or fail long before the first search is run, and how cognitive bias, narrative lock-in, and over-collection continue to undermine otherwise capable teams.

Framed squarely at Layer 8, the session focuses on the analyst as both the greatest asset and the greatest risk within OSINT. It unpacks the importance of hypothesis-led investigation, verification over velocity, negative intelligence, and knowing when to stop. Cultural references are used deliberately to anchor complex ideas and keep the audience engaged, without diluting the seriousness of the subject.

Designed for practitioners, decision-makers, and leaders alike, this talk is not about tools or technology. It is about protecting method, respecting tradecraft, and understanding that in OSINT, confidence must always be earned.

Attendees will leave with a clearer understanding of how to reduce noise, improve judgement, and build OSINT practices that stand up under pressure, scrutiny, and consequence.

Friday, 2:00 pm
The Hijacked Brain: Neuroscience and Why Social Engineering Works
Sarah Sabotka
Social engineering attacks don’t just exploit systems, they exploit your biology. This talk examines a curated set of real-world email phishing threats designed to provoke fear, urgency, anxiety, and excitement in their targets, using them as a lens to explore a phenomenon that security awareness training rarely addresses: amygdala hijacking.

When a threat actor crafts a message warning you that your account has been compromised, that legal action is imminent, or that a loved one is in danger, they’re manipulating your judgment by triggering a measurable physiological stress response. The amygdala, the brain’s threat detection center, can effectively override rational thought before you’ve consciously processed what is in front of your eyes. It doesn’t distinguish between a predator in the wild and a well-crafted phishing email, or what’s real and what’s fake. By the time your prefrontal cortex catches up, you may have already taken the bait.

This session walks attendees through compelling examples of fear-based phishing and social engineering emails, analyzing the specific psychological levers each one pulls and why they are so effective at short-circuiting clear thinking. From there, we’ll explore the neuroscience behind why these tactics work so reliably and why even trained security professionals aren’t immune. Attendees will leave with a deeper understanding of how physiological responses can be weaponized by adversaries, and with practical frameworks for recognizing the moment their threat response has been activated and restoring rational thought before misguided instinct makes the decision for them.

Friday, 2:00 pm
Don’t Try This at Home: Lessons Learned in Social Engineering Jobs
Jesse Roberts
This session goes through various covert entry and physical social engineering jobs that Jesse has performed through his career. He will include stories, lessons learned and advice on what worked and what didn’t. If you’ve wanted to perform in-person social engineering, Jesse will have useful tips and advice for you.

Friday, 3:00 pm
How to Avoid Scams and Being Influenced by People
Jennifer Shannon
From phishing emails and phone scams to in-person manipulation, scams and social engineering attacks succeed not because their targets are careless or unintelligent, but because they are human.  Attackers deliberately exploit fundamental psychological principles including trust, authority, urgency, fear, and our natural discomfort with conflict to craft convincing scenarios that bypass rational thinking and trigger instinctive responses.  This talk explores the psychology behind why these tactics work so effectively.  We’ll breaking down how scammers and manipulators build believable pretexts, leverage cognitive biases, and use emotional pressure to influence decision-making, often convincing otherwise security-conscious individuals to act against their own best interests. Through real-world examples drawn from both personal and professional environments, we’ll examine how these attacks unfold from first contact to a successful compromise, and more importantly, where the opportunities to recognize and stop them exist.  Whether you are new to cybersecurity or an experienced professional, this session aims to strengthen your awareness of how human behavior can be targeted and provide practical strategies to recognize and resist these forms of manipulation, helping you better protect yourself and those around you.

Friday, 3:00 pm
What They’re Really Saying: Decoding Linguistic Patterns in OSINT and Social Engineering
David Ford
Every time someone writes a message, posts online, or sends an email, they leave behind linguistic fingerprints: patterns of word choice, sentence structure, slang, regional colloquialisms, and punctuation that reveal far more than the author intended, even in an era of AI-generated content.

This talk explores the practical applications of linguistic analysis across the OSINT and social engineering landscape. Attendees will learn how stylometric techniques can link anonymous accounts and unmask authorship across platforms, how cross-platform linguistic fingerprinting can track a person of interest even when they change usernames and details, and how coded language like evolving slang, emoji shorthand, and cultural euphemisms can disguise criminal activity, conceal intent, or communicate threats in plain sight.

Social engineers exploit these same principles every day, crafting phishing messages that mirror a target’s communication style, adopting regional dialect to build false trust, and using pretexting scripts designed to avoid suspicion. Understanding how language works in both directions makes investigators sharper and targets harder to exploit.

Drawing on real-world investigative experience in missing persons, social engineering, and open-source intelligence, this presentation offers a practical framework for integrating linguistic awareness into your OSINT workflow. No linguistics degree or special tools required. Whether you’re tracking a person of interest, analyzing threatening communications, or defending against social engineering attacks, this talk will sharpen your eye for patterns you’re already seeing but not yet using.

Saturday, 10:30 am
Human Zero Trust Architecture
Harutyan Galstyan
Through practical examples, the presentation demonstrates how attackers collect information through open-source intelligence (OSINT), personal interactions, and publicly available data, allowing them to profile potential victims and exploit psychological and organizational weaknesses.

A key focus of the discussion is the progression of these attacks. Fraud schemes often begin with simple physical interactions, paper-based communications, or small-scale deception, but can gradually develop into coordinated operations involving multiple participants and long-term manipulation. In some cases, individuals who initially become short-term victims may later unknowingly contribute to larger operational structures that enable continued exploitation.

The presentation also explores how these tactics extend beyond individuals to affect major service providers and institutions, including financial organizations, accounting firms, law firms, nonprofit organizations, and small businesses. Independent workers—such as taxi or rideshare drivers—can also become vulnerable entry points within these broader networks.

By examining these patterns, the session emphasizes the importance of integrating human-centered security strategies within Zero Trust frameworks, demonstrating that effective cybersecurity must address not only technical systems but also the behavioral and social factors that attackers increasingly exploit.

Saturday, 10:30 am
Search Engine Optimization: Only for Marketing or a Tool for OSINT Exploitation?
Tim Farmer and Chris St. Germain
Finding resources can be difficult and understanding how to get to them without raising a red flag is a bigger concern. During this presentation, Tim will outline how best to use SEO databases and website structure to find information that can be “hidden” from search engines.

Saturday, 11:00 am
Vishing at Scale: Humans vs. Voice Agents
Carter Zupancich
I’ve run 8,500+ human-to-human vishing calls. Now I’m doing the same thing with fully automated voice agents, at scale, against F500 and government employee/helpdesk workflows (sanitized artifacts, real outcomes).

This talk is the before/after: humans vs. voice agents in real operations. Not necessarily an academic apples-to-apples study, because frankly, that’s not how internal red teams work. Instead, I’ll break down what actually changes when “voice becomes software”: persistence (callbacks/retries), parallelization (no labor bottleneck), consistency, and the ability to chain SMS/email/other messaging while on the call to push targets through password resets, MFA reset flows, and other sensitive information disclosure.

We’ll define: where agents outperform humans today, and where humans still win (interruptions/barge-in, emotional pivoting when challenged, deeper influence/elicitation techniques, and company-specific nuance/edge cases).

I’ll also share what’s moved the needle in measured outcomes (compromise, reporting, shutdown) and what hasn’t, so you can tune your own voice exercises and harden the workflows that make this possible at scale.

Saturday, 11:00 am
Breaking Social Engineering Without Accusations: The Deception Disruption Framework (DDF)
Ian Sun
Social engineering remains the dominant initial access vector in today’s breaches, yet most defenses rely on post-hoc detection or awareness training against known attacks. These approaches fail as attackers evolve and operate patiently, politely, and professionally, lying low to avoid showing red flags. Meanwhile, across many workflows, such as help desks and emailing, simply not engaging can be detrimental.

This talk introduces the Deception Disruption Framework (DDF): a method for detecting and disrupting deceptive actors by applying cognitive pressure in live interaction when prior disengaging is unfeasible. DDF is built around three simple techniques: Lived Experience (LE), Context Change (CC), and Moral Reflection (MR). Rather than accusing or interrogating, DDF integrates seamlessly into normal conversation and forces deceptive actors to sustain concrete personal narratives, tolerate social expansion, and reflect ethically on their actions; things that, due to cognitive load and dissonance, they struggle with.

In early 2026, DDF was tested live against an active job scam conducted entirely over text. Using only polite and conversational questions, the interaction produced repeated behavioral failures even without visible vocal or expression leakage. The scammer struggled to provide experiential detail, resisted social expansion, deflected ethical reflection, and ultimately pivoted to authority appeals, causing a major contrast between the attacker’s behavior and the expected legitimate behavior that gives license for disengaging before further damage can be done.

This presentation marks the first public debut of DDF. Attendees will learn how DDF differs from scambaiting, why it generalizes across different kinds of social engineering attacks, and how it can be used by everyday people in hiring, help desks, onboarding, and more. The goal is not confrontation, but disruption: extracting signals of deception that warrant disengaging or reporting, while legitimate actors have less to worry

Saturday, 2:30 pm
How Digital OSINT Enables Physical Access: Blended Social Engineering Across Online and Real-World Environments
Chris Klossner
OSINT and social engineering are often discussed as digital disciplines, confined to screens, platforms, and online personas. In practice, the most meaningful impacts of both occur when digital intelligence translates into real-world access.

This presentation explores how publicly available information, routine online behavior, and seemingly low-risk digital exposure can enable physical approach, influence, and access when combined with social engineering techniques. Rather than focusing on tools or collection methods, the talk examines how attackers think across domains and how digital signals become real-world opportunities.

Using real-world scenarios drawn from security and protective intelligence work, the session walks through the progression from online research to physical interaction. Attendees will see how fragmented pieces of information, when aggregated, can reveal patterns about movement, habits, authority, and trust that are exploitable outside of digital spaces.

The talk also highlights common blind spots in how organizations assess OSINT risk. Many focus on data exposure without considering how that exposure affects physical security, staff behavior, or access control assumptions. By separating digital and physical threat models, organizations often miss the point where the two converge.

This session is designed for practitioners who want to better understand how OSINT and social engineering operate together in the real world, and how digital visibility can unintentionally create physical risk. The goal is not to alarm, but to provide a clearer mental model for identifying and reducing cross-domain exposure.

Saturday, 2:30 pm
Hooks and Hooks: How AI Is Revolutionizing Both Phishing Attacks and Our Defenses
Levone Campbell
In this thought-provoking session, we explore the rapidly evolving landscape where artificial intelligence and phishing attacks intersect, creating both unprecedented threats and innovative defensive capabilities.
As AI technologies become more sophisticated and accessible, cybercriminals are leveraging these tools to craft increasingly convincing phishing campaigns that can evade traditional detection methods. Simultaneously, security professionals are adopting AI-powered solutions to identify and neutralize these advanced threats before they reach potential victims.

Saturday, 3:30 pm
Closing Ceremonies and Networking Event


Speaker Biographies

William Ruzich
William Ruzich built his career at the front lines of national security. He began in the United States Army as a signals intelligence (SIGINT) operator, serving through multiple combat deployments before transitioning into other U.S. government intelligence services, where he spent years conducting sensitive operations in demanding environments.

Backed by that operational foundation and academic training at Purdue University and Arizona State University, William brings more than twelve years of experience across the intelligence spectrum — from human intelligence (HUMINT) and signals intelligence (SIGINT) to open-source intelligence (OSINT). Over his career he has supported a global client base, including high-net-worth individuals and government officials navigating high-threat environments.

William founded the Aracari Project to bring that same caliber of intelligence to the clients who rarely have access to it: smaller and emerging governments, politically exposed figures, and businesses operating in complex conditions. As the firm matured, he integrated drone and unmanned-systems operations into its model — extending its reach from the ground to the air.

Today the Aracari Project is more than an intelligence firm. Under William’s leadership it has grown into a diversified organization that solves complex, high-stakes problems for a diverse set of clients worldwide.

Lisette Abercrombie
Lisette, also known as Technisette, has been active in the OSINT field for over 15 years. Over that time she’s gained tons of experiences which she actively shares with her colleagues in Dutch Law Enforcement, but also with her students at My OSINT Training. Just the keep everyone OSINTcurious ;-)! . She specializes in social media and person investigations. And she’s bringing stickers and stroopwafels, just for Layer8!

Brett Redman
Brett Redman is an open-source intelligence (OSINT) subject matter expert and executive with extensive experience in financial crime, sanctions, serious and organised crime, and complex attribution challenges. His work focuses on applying rigorous intelligence tradecraft to open-source data to produce actionable insight in high-risk and time-sensitive investigative environments.

He is currently Chief Operating Officer at OSINT Industries, where he is responsible for operational delivery, product strategy, and global engagement across law enforcement, government, and private-sector partners. In this role, Brett works closely with investigators and analysts worldwide to ensure that OSINT capabilities are practical, ethical, and aligned with real-world investigative needs rather than theoretical use cases.

Brett is a regular international speaker, trainer, and advisor, having presented at conferences and workshops across Europe on topics including sanctions evasion, economic crime, attribution, and the responsible use of OSINT and automation. His approach emphasises disciplined methodology, data provenance, and human-led analysis, with technology used to support analysts rather than replace judgement.

He is particularly passionate about reducing investigative noise, improving signal clarity, and helping practitioners connect disparate data points to understand behaviour, networks, and risk. Brett’s work is grounded in the belief that effective OSINT is not about tools alone, but about people, tradecraft, and context. His sessions are known for being practical, engaging, and directly relevant to professionals operating in complex and high-risk environments.

Adam McNeil
Adam McNeil is a Senior Threat Research Engineer at Proofpoint with over 20 years of cybersecurity experience in malware analysis, spam and threat intelligence, and mobile abuse. He works extensively with 7726 mobile reporting data, has previously presented at M3AAWG on conversational scams, and focuses on analyzing scam trends and campaign behavior at scale.

Sarah Sabotka
Sarah Sabotka is a Staff Threat Researcher on Proofpoint’s Threat Research team, where she focuses on Business Email Compromise (BEC) and fraud threats, is a co-host of Proofpoint’s Discarded podcast, and host of Intercepted Threat Research interactive videocast series. Prior to joining Proofpoint, Sarah developed and led the Global Cyber Threat Intelligence team at Experian; before that she was a Senior Threat Analyst at Goldman Sachs. Sarah earned a Master’s in Cybersecurity from Utica University, where she specialized in both Threat Intelligence and Digital Forensics, and a Bachelor’s in English from the University of Connecticut at Storrs. Her interest in threat intelligence began during her tenure as a Cruelty Caseworker for an International Animal Welfare organization, where she specialized in OSINT collection and digital evidence preservation to investigate Internet-based crimes against animals; she was also responsible for interpreting and communicating domestic and international animal protection laws to support prosecution of perpetrators, and collaboration with law enforcement from multiple jurisdictions. Sarah is passionate about educating clients and the public on current cyber threats, especially evolving social engineering techniques. She is driven to empower individuals and organizations with the knowledge and tools they need to protect their valuable information and systems. She resides in New England where she runs a small 501(c)3 animal sanctuary, home to several rescue dogs, ducks, a guinea pig and rabbit, and chickens.

David Ford
“David is an OSINT practitioner and investigative professional with over 25 years of experience in marketing, technology, and digital intelligence. He serves as the Director of Intelligence at the Lydia Lerma Foundation, a nonprofit focused on missing persons investigations and locating wanted individuals, where he uses open-source intelligence techniques to support active cases. He is also the founder of Midnight Intelligence, where he conducts OSINT investigations and provides strategic intelligence services.

His work spans OSINT, social media intelligence, social engineering, and linguistic analysis. He has hands-on experience tracking persons of interest across platforms, analyzing communications for signs of deception or coercion, and piecing together connections across complex cases.

David also develops and delivers OSINT training for corporate teams, law enforcement, and other organizations, with an emphasis on practical techniques that can be put to use immediately. His background in missing persons and investigative work has shaped a grounded, practitioner-first approach to both his investigations and his teaching. His approach focuses on building understanding and critical thinking, not just showing techniques, so people can keep learning and adapting as the field evolves.”