Episode

The One-Shot Phishing Attack

Podcast
Fraudology Podcast with Karisse Hendrick
Published
Aug 20, 2026
Duration seconds
2108
Processing state
not_requested
Canonical source
https://fraudology-podcast.captivate.fm/episode/the-one-shot-phishing-attack
Audio
https://episodes.captivate.fm/episode/be9b4aa2-8a19-4304-8c1b-985b09deb884.mp3
JSON
/v1/public/podcasts/fraudology-podcast-with-karisse-hendrick-1368872/episodes/the-one-shot-phishing-attack
Markdown
/podcast/fraudology-podcast-with-karisse-hendrick-1368872/the-one-shot-phishing-attack.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/fraudology-podcast-with-karisse-hendrick-1368872/episodes/the-one-shot-phishing-attack/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872/the-one-shot-phishing-attack.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Welcome back to Fraudology. I have to tell you I’m genuinely excited about this one. Today’s guest was highly recommended by Matt Vega, someone whose opinion I trust completely in this industry. By the time we finally hit record, we’d already been talking for 45 minutes off air. That’s a pretty good sign this episode is going to deliver. Cy Khormaee spent years at Google, building out what eventually became the company’s user protection platform and the technology that now runs quietly in the background protecting billions of devices worldwide from phishing and malware. He took that experience and eventually founded Aegis.AI, and he just got back from Black Hat, which means he is walking into this conversation with a front-row view of exactly where adversarial AI is heading next. What I wasn’t fully prepared for was how far he was willing to take the demonstration. Cy didn’t just tell me adversarial AI is a growing thread, he showed me, live. Using nothing more than ChatGPT and information freely available online. It’s the kind of moment that changes how you think about a threat you thought you already understood. We cover a lot of ground in this one. And if you work in fraud, trust and safety, or security in any capacity, this is one you’ll want to sit with. What you’ll hear in this episode: Cy's path from Google's user protection platform, home of reCAPTCHA and Safe Browsing, to founding Aegis.AI, and how credential stuffing defense evolved into a hundred-million-dollar business. A live ChatGPT phishing demo where Cy used open source intelligence to research himself and generate a convincing, contextualized phishing email and matching fake conference website in minutes. Why AI phishing attacks have moved from theoretical to fully operational, with real-world state ac…