CypherCon 2026
Spiders, Deepfakes, and Access Credentials
Tom Cross
Abstract:
For several years, various criminal groups such as Scattered Spider have been gaining access to corporate networks by exploiting weaknesses in account recovery procedures. One of the most well known attacks targeted MGM and Caesar’s Casinos in the summer of 2023. To target MGM, the criminals reportedly identified employee profiles on Linkedin, and learned enough about one employee in particular to call up MGM’s IT Helpdesk and successfully convince them to reset that person’s login credentials.
These attacks prompted many organizations to take a closer look at how they handle credential reset. The increasing popularity of remote work means that it is no longer reasonable in many cases to tell employees to just “drop by the office” if they loose access to the network. SIM swapping, deepfakes, and breach data provide lots of ways to overcome various controls that organizations try to establish.
This talk will provide a breakdown of different classes of attack on credential reset workflows and show how attackers can subvert different countermeasures. We’ll then discuss how organizations can leverage what they know about their own employees to build robust defenses against these kinds of attacks.

Tom Cross
Spiders
Tom Cross is the Head of Threat Research at GetReal Security, where he tracks threat actors and attack activity involving deepfake social engineering and impersonation. He is also a Principal at Kopidion, a cybersecurity training and strategy consultancy. His career in cybersecurity has spanned three decades, and numerous roles, including CoFounder and CTO of Drawbridge Networks, Director of Security Research at Lancope, and Manager of the IBM Internet Security Systems X-Force Advanced Research team. He has spoken at numerous security conferences, including Black Hat Briefings, Defcon, CyCon, HOPE, Source Boston, FIRST, and Security B-Sides. He has a B.S. in Computer Engineering from the Georgia Institute of Technology.