
Episode #102
Deepfakes, Voice Clones and Forged IDs: Fighting AI-Powered Fraud, with Rachel Tobac
In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath ( https://www.verapath.com ), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. About Our Guest This episode's guest is Rachel Tobac, CEO of SocialProof Security and one of the best-known ethical hackers in the world. Rachel got her start hacking a real company live over the phone from a glass booth at DEF CON, and today enterprises, banks, government agencies and the military hire her to break in before criminals do. She and Alec dig into how AI is powering a new wave of fraud, from cloned voices and spoofed caller IDs to beating a large bank's deepfake detection with an iPad. They also cover the practical side: how bankers and advisors can safely use AI day to day, the governance mistakes that leak salaries and secrets, and why AI will create more cybersecurity jobs, not fewer. Top 5 Themes AI meeting prep for wealth advisors. An advisor asks the firm's approved AI assistant for a client summary before a quarterly review: portfolio changes, recent notes, open action items and life events to raise. An hour of prep becomes minutes, the assistant sees only that advisor's clients, and the advisor checks the summary before the meeting. AI reviews the loan file; a human makes the call. A community bank credit officer runs an application through an AI tool that flags missing documents, mismatched numbers and policy gaps. The officer goes back to the borrower for what's missing instead of taking shortcuts, and a person still makes the credit decision. Fraudsters call the help desk, and they sound just like you. Attackers skip email and phone the help desk or an executive's assistant, often with a cloned voice and a spoofed number. Date of birth, address and passcodes are easy to find, so verify identity through a separate channel, such as a callback or a push notification. AI governance and guardrails. Employees use AI tools the company never approved, and poorly governed AI can surface salaries or evidence of office romances. Limit what AI can see, red-team it before employees do, and add guardrails like "don't create fake IDs." AI will create more cybersecurity jobs, not fewer. AI is good at finding bugs when its access is limited. Rachel expects a flood of new vulnerabilities that people will need to review and fix. Resources Here are a few of the companies, organizations and resources mentioned during the episode: SocialProof Security : Rachel Tobac's social engineering testing and security awareness company. socialproofsecurity.com Verapath : Secure, private AI for banks and wealth managers. verapath.com DEF CON : The hacker conference where Rachel competed in the Social Engineering Capture the Flag. defcon.org CNN: "We asked a hacker to try and steal a CNN tech reporter's data" : Rachel's DEF CON hack of Donie O'Sullivan. cnn.com CISA advisory on Scattered Spider : The help-desk social engineering playbook Rachel describes. cisa.gov Influence by Robert Cialdini : The book behind the principles of persuasion scammers exploit. influenceatwork.com Microsoft 365 Copilot : The AI assistant in Alec's data governance story. microsoft.com Wells Fargo sales practices settlement : The fake-accounts scandal Alec references. justice.gov Copyright (c) 2026 Artificial Intelligence Risk, Inc. All Rights Reserved

