MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Tactics of Deception: Protecting Trust and Purpose

Trained people, strong controls, still getting fooled? This session breaks down how modern social engineering exploits trust and urgency, and what actually works to stop it.

Social engineering attacks no longer rely on poorly written phishing emails or obvious scams. Today’s adversaries exploit trust, authority, and urgency, often using AI-driven voice cloning, deepfakes, and highly tailored impersonation, to manipulate well-trained professionals into making high-impact decisions in minutes.

In this session, Bishop Fox's Alethe Denis, Red Team Sr. Security Consultant and DEF CON Social Engineering Black Badge winner, examines how modern deception tactics are being used to target extended vendor ecosystems. Drawing on real-world incidents, from vishing attacks that bypass bank controls to deepfake-enabled executive impersonation, this talk explores why traditional security controls often fail when the human element is under pressure.

Session Summary

This workshop explores tactics of deception and the human attack surface, focusing on how attackers exploit trust, urgency, and psychological pressure rather than technical vulnerabilities. Through real-world examples, including near-loss financial scams and deepfake-enabled fraud, the session demonstrates how social engineering manipulates human behavior to bypass traditional security controls. It highlights why existing defenses often fail under pressure and emphasizes the need for process-driven safeguards, cultural awareness, and human-centered security design to reduce manipulation-driven risk.

Key Takeaways

  1. Humans are not the weakest link, they are targeted because of inherent trust and social behavior.
  2. Social engineering attacks rely on psychological principles like urgency, authority, and scarcity.
  3. Attackers create cognitive overload and isolation to bypass verification and force compliance.
  4. Traditional security controls often fail due to time pressure, familiarity bias, and process drift.
  5. Deepfakes and AI increase realism, but manipulation tactics remain fundamentally human-driven.
  6. Effective defense requires process controls (e.g., callbacks, dual approvals) and intentional friction.
  7. A strong security culture empowers people to pause, verify, and escalate without fear or friction.

Microsoft Teams image 23

About the speaker, Alethe Denis

Senior Security Consultant

Alethe Denis is a Senior Security Consultant at Bishop Fox. She is best known for social engineering, open-source intelligence (OSINT), and performing security assessments and trainings for both the private and public sectors with emphasis on critical infrastructure organizations. Alethe was awarded a DEF CON Black Badge at DEF CON 27 for Winning the 10th annual Social Engineering Capture the Flag (SECTF) contest. Using both OSINT and Social Engineering skills, she compromised her target Fortune 500 company using just a telephone. She, along with her teammates, received a bronze, silver, most valuable OSINT, and black badge award from a series of TraceLabs capture-the-flag contests, including first place in

She’s a frequent conference speaker and podcast guest, including speaking at DerbyCon, BsidesSF and ConINT, as well as an appearance on the TraceLabs, Layer 8 Conference, and Darknet Diaries podcasts.

Alethe is always focused on giving back to the information and cybersecurity community, including her work conducting free Security Awareness Trainings and hosting workshops for people who want to get into the cybersecurity industry.