Interested in being a guest? Email us at
[email protected]Personalized phishing is no longer “spray and pray.” It’s targeted, multi-channel, and increasingly powered by exposed employee data that’s sitting in plain sight. We sit down with Paul Mander, Chief Commercial Officer at Optery for Business, to unpack what’s driving the next wave of AI-driven social engineering and why so many security teams are rethinking where the real attack surface begins.
Paul walks us through eye-opening survey findings from more than 400 cybersecurity leaders: social engineering attempts are rising sharply, most attacks are moderately or highly personalized, and a large share of those successful attempts lead to credential compromise. We also dig into why there’s no single channel to defend anymore. Email still matters, but attackers are mixing phone calls, SMS, social media, and impersonation to make their stories feel “verified” from multiple angles.
The biggest shift is where attackers get their homework done. Data brokers and people search sites compile dossiers that include phone numbers, home addresses, relatives, employment history, and even org chart details that help threat actors pick high-leverage targets. We talk about why IT, HR, and finance often take more heat than executives, and what practical teams can do today: strengthen MFA and training, then get proactive by finding and removing exposed PII through opt-out and deletion workflows at scale.
If you’re a CISO, IT leader, or security practitioner trying to reduce phishing risk, social engineering risk, and account takeover risk, this is the playbook for treating privacy exposure as a core cybersecurity control. Subscribe, share this with your team, and leave a review with the one data source you think attackers rely on most.
Support the show
More at https://linktr.ee/EvanKirstel