Fraudology Podcast with Karisse Hendrick
Fraudology Podcast with Karisse Hendrick

The One-Shot Phishing Attack

20 August 2026 35:08 Karisse Hendrick

Listen to episode

About this episode

Welcome back to Fraudology.

I have to tell you I’m genuinely excited about this one. Today’s guest was highly recommended by Matt Vega, someone whose opinion I trust completely in this industry. By the time we finally hit record, we’d already been talking for 45 minutes off air. That’s a pretty good sign this episode is going to deliver.

Cy Khormaee spent years at Google, building out what eventually became the company’s user protection platform and the technology that now runs quietly in the background protecting billions of devices worldwide from phishing and malware. He took that experience and eventually founded Aegis.AI, and he just got back from Black Hat, which means he is walking into this conversation with a front-row view of exactly where adversarial AI is heading next.

What I wasn’t fully prepared for was how far he was willing to take the demonstration. Cy didn’t just tell me adversarial AI is a growing thread, he showed me, live. Using nothing more than ChatGPT and information freely available online. It’s the kind of moment that changes how you think about a threat you thought you already understood.

We cover a lot of ground in this one. And if you work in fraud, trust and safety, or security in any capacity, this is one you’ll want to sit with.

What you’ll hear in this episode:

  • Cy's path from Google's user protection platform, home of reCAPTCHA and Safe Browsing, to founding Aegis.AI, and how credential stuffing defense evolved into a hundred-million-dollar business.
  • A live ChatGPT phishing demo where Cy used open source intelligence to research himself and generate a convincing, contextualized phishing email and matching fake conference website in minutes.
  • Why AI phishing attacks have moved from theoretical to fully operational, with real-world state actor phishing tactics now automatable at near-zero cost.
  • The staggering AI phishing email bypass rate statistics: over 50% of emails now slip past existing security email filter bypass controls.
  • Why AI red team fraud thinking, treating AI as a gardener to nurture rather than a carpenter to micromanage, changes how fraud and security teams should actually deploy these tools.
  • How the real Robinhood phishing attack shows why login fraud detection signals and upstream fraud detection AI matter more than ever.
  • Why fraud and cybersecurity convergence isn't optional anymore, and how fraud data sharing across teams closes gaps that adversaries are actively exploiting.
  • How automated sandboxing fraud detection can catch attacks before a user ever clicks, and why carding attack prevention and account takeover detection increasingly rely on the same signals as cybersecurity teams.

You should listen to this episode if you:

  • Work in fraud, trust and safety, or security and want to understand how adversarial AI is changing social engineering and phishing attacks.
  • Are responsible for account takeover detection, credential stuffing detection, or synthetic identity risk at a bank, fintech, or merchant.
  • Assumed business email compromise had been mostly solved and need a reality check.
  • Are evaluating AI fraud investigation automation tools and want a clearer sense of what can realistically be automated today.
  • Are trying to build the case internally for fraud and cybersecurity convergence and fraud data sharing across teams.

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 Fraudology Podcast with Karisse Hendrick. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.