Threat Picture
Latest Cybersecurity News

Rachel Tobac: How a Phone Call Becomes a Security Test

A DEF CON contest turned a UX researcher toward social engineering. Her demonstrations reveal how convincing stories defeat safeguards.
By Charles Joseph · Updated
Share
Share
Copy URL

In October 2019 CNN handed a hacker a simple assignment: steal its tech reporter's personal data. Rachel Tobac got it in seconds, with nothing more than a phone and a convincing story.

Tobac is the CEO of SocialProof Security and one of the best-known social engineers in the world, a hacker whose weapon is the human voice. She's fooled reporters on CNN and 60 Minutes, trained staff at Google, NASA and the United Nations, and turned security awareness training into music videos.

She also started out with no security background at all. The road from user research to the DEF CON stage began with a trip her husband talked her into.

Rachel Tobac at a Glance

  • Tobac was working in tech as a UX researcher when her husband took her to DEF CON around 2015, and the social engineering village hooked her.
  • Chosen as one of 14 competitors from roughly 400 applicants, she entered DEF CON's Social Engineering Capture the Flag and took second place three years in a row.
  • In 2017 she co-founded SocialProof Security, which runs social engineering penetration tests, training and live hacking demonstrations.
  • In 2019 she hacked CNN reporter Donie O'Sullivan on camera, and in 2023 she scammed a 60 Minutes staffer to show how easy digital theft is.
  • Her client list includes Google, Meta, NASA, Salesforce, JPMorgan Chase, Cisco, Uber and the United Nations, and her training videos include original songs.
  • She still runs penetration tests at least weekly while giving keynotes around the world, including a 2026 ContinuumCon keynote.
  • In late 2025 she warned that AI tools would hand attackers an edge in 2026, and the following spring she was explaining the Canvas hack that disrupted thousands of schools.
Sponsored

The Life of Rachel Tobac

Tobac's Unlikely Start

Rachel Tobac didn't come up through the usual hacker pipeline. She was working in tech as a UX researcher, studying how people use software, when her husband brought her along to DEF CON in Las Vegas around 2015.

At the social engineering village she watched competitors sit in a booth and talk strangers out of information over the phone. The mix of improv, research and acting captivated her, and she decided she could do it too.

"I think a lot of hackers, me included, see hacking as a fun game," she told SecurityWeek in 2025. "It's a bit like a puzzle."

Inside the Booth

DEF CON's Social Engineering Capture the Flag is a strange sport. Contestants research a target company for weeks, then sit in a soundproof booth in front of an audience and make live calls to its employees, collecting harmless "flags" such as which vendor shreds the paper or who hauls the dumpsters.

Tobac applied and was one of just 14 people chosen from roughly 400 applicants. She placed second in her first year, then second again the next year, and second again the year after that.

Three consecutive podium finishes in a contest built to humble people made her name in the industry before she'd ever sent an invoice.

Sponsored

Building SocialProof Security

In 2017 Tobac co-founded SocialProof Security as an LLC, with herself as CEO. The company does what she'd been doing for sport: social engineering penetration tests by phone, email, chat, text message and social media, plus account takeover attempts, with the company's consent and without the target employees' knowledge.

The other half of the business is prevention: live training, red team programs, keynotes, and two- to three-minute awareness videos, some of them set to music. The company's stated goal is to make people "Politely Paranoid."

Its client list reads like a Fortune 500 index with a few extras: Google, Meta, Uber, Salesforce, JPMorgan Chase, Cisco, Palo Alto Networks, NASA, St. Jude Children's Research Hospital and the United Nations.

Hacking CNN on Camera

Tobac became famous the way social engineers do, by doing it to someone in public. In October 2019 CNN's Donie O'Sullivan, a tech reporter who thought he was being careful on social media, agreed to let her try. She proved him, in CNN's words, "very, very wrong," pulling his personal data in seconds.

The clip has been watched hundreds of thousands of times, and it established the Tobac format: a cheerful hacker, a real target and a lesson that lands harder than any slide deck.

Prime Time

Television kept calling. In May 2023 she scammed a 60 Minutes staffer on camera to show how easy digital theft has become, and NBC Nightly News turned to her during its coverage of a massive hack investigation.

When Elon Musk took over Twitter in late 2022 and gutted its staff, Politico sought her out on the risk of a breach. Her interview with David Bombal in 2023 and a 2025 appearance with the scam-busting channel Scammer Payback each drew hundreds of thousands of viewers, the latter more than two million.

She's become a podcast regular too. Darknet Diaries devoted an episode titled simply "Rachel" to her in March 2024, and at TechCrunch Disrupt 2023 she sat on a panel about learning from cybersecurity "trash fires."

Through it all she kept her hands dirty. In 2025 she was still running penetration tests at least weekly while leading her team and giving keynotes.

Sponsored

Tobac in the Age of AI

The tools changed faster than the humans. SocialProof's demonstrations now include AI deepfakes, and in December 2025 Tobac told Axios that AI tools would give cyber adversaries a boost in 2026.

A month earlier, in a December 2024 Wired piece, she'd urged families to agree on a secret password, a low-tech defense against impostor scams that no deepfake can clone.

That spring, when the hack of the Canvas learning platform disrupted thousands of schools, she was one of the experts explaining to parents and students what had happened. In 2026 she also keynoted ContinuumCon.

Rachel Tobac: Politely Paranoid

Tobac's career is proof that the best defense against social engineering isn't a firewall but a person who's seen the trick before.

She still competes, in a sense, every week, except now the companies on the other end of the line are paying to lose.

Be politely paranoid. She'd be, and she's the one calling.

QUOTE:

"Amateurs hack systems, professionals hack people."