Video summary

Podcast with a REAL HACKER 🖥️ Part 3 | AI Scams, Phone Hacking & Cybersecurity Careers in 2026

Main summary

Key takeaways

Technology

Tech & Cybersecurity Summary (Podcast Part 3)

1) Data privacy: phone number ≠ “just an identifier”

  • The speaker shows that sharing only a phone number can be enough to retrieve extensive personal details (e.g., birthday/Aadhaar digits, father’s name, and location/address-like data) through OSINT (open-source intelligence) and public data aggregation.
  • Key concept: Phone number (and email) acts as a “connector.” Once matched across leaked profiles, attackers can link multiple datasets into a fuller identity.

2) Public-data OSINT + leaked-data correlation (two-stage view)

The discussion frames personal information as coming from two buckets:

  • ~30% “given publicly” People voluntarily post/tag details on social media, including family information, birthdays, locations, resumes/job history, and more.

  • ~70% “not intentionally given” Data collected via KYC/insurance/financial services, telecom/health apps, loan flows, etc., which can later leak from organizations.

Once breaches happen, scammers can buy/sell data and use it for impersonation.

3) Data leaks and enforcement (policy + incident response)

  • Breaches are treated as inevitable, but responsibility should lie with service providers.
  • An Incident Response Model is mentioned, with multi-phase coverage such as:
    • preparation
    • identification/contamination
    • eradication/fix, etc.
  • Regulatory/policy points mentioned (in DPDP context):
    • Breach notification within 72 hours
    • potential large fines (the speaker cites numbers like ~₹250 crore) if reporting/security controls aren’t followed.
  • Example cited: a health insurer leak where leaked data was later validated as real through samples sourced from elsewhere.

4) Dark web vs normal web (and Tor as the access layer)

  • The dark web is described as:
    • a segment of the internet accessible via specialized routing/browser tooling such as Tor
  • It’s compared to the normal web as more “air-gapped” in behavior, though technically it’s just a different access network/anonymity layer.
  • Attackers are said to use it to trade stolen data and target victims by region.

5) Biometric security: not the data itself, but the implementation

The speaker’s core argument: biometrics must be used correctly.

  • Mentioned principle (NIST-style): biometrics should not be the only factor.
  • Authentication should be multi-factor (e.g., something you are + something you have/know).
  • Example: AEPS-style systems (Aadhaar-enabled payment concepts), where attackers may attempt to reconstruct/abuse fingerprint workflows.
  • Practical mitigations suggested:
    • Lock/unlock biometric permissions (e.g., “Aadhaar lock” concept)
    • ensure OTP/second factor is involved rather than relying on biometrics alone

6) AI scams: voice/video impersonation at scale

Capabilities claimed:

  • With only a few seconds of voice, AI can generate a realistic voice; more data improves accuracy.
  • With photos from multiple angles, AI avatars can mimic a person’s appearance.

Example scam scenario:

  • An avatar/voice requests money using UPI wallet/transfer-style prompts.

Escape/detection advice:

  • “Three-finger test” in video calls: move fingers close to the face and look for clone distortions/artifacts (the speaker claims AI struggles with live multi-finger real-time generation).
  • Change the channel: hang up and call back using a known trusted method, not the incoming voice/video stream.

7) Phone number cloning & “trusted caller” social engineering

  • The speaker describes personalized scams where attackers use a cloned caller identity so victims’ contacts trust the call.
  • Suggested mitigations:
    • Call back on a different channel
    • use a shared family verification code for emergencies

8) “Cyber slavery” / forced labor scams

  • Covers fake job offers that move victims internationally and trap them.
  • Countries mentioned include Cambodia and Indonesia (also mentions Malaysia/Thailand routes).
  • Claimed workflow:
    • victims are held/coerced and made to run scam scripts using stolen documents and phones.

9) Faraday bags for privacy isolation

  • A Faraday bag demo is described:
    • it blocks electromagnetic signals so a phone inside cannot transmit/receive
  • Emphasis: privacy protection and isolation (not misuse).

10) Wi-Fi-based sensing as “camera replacement” (ESP32 / CSI-style idea)

  • A guest demonstrates small Wi-Fi/ESP32 devices used to detect/estimate movement inside a home without a conventional camera.
  • Device idea:
    • analyze Wi-Fi signal changes/amplitude shifts due to reflections and obstacles.
  • Framed as potential future intrusion detection using Wi-Fi presence rather than visible cameras.

11) AI in security: faster testing and workflow automation

  • AI is presented as helpful for defenders by automating repetitive scanning/assessment.
  • Mentions connecting “AI” with a security scanning tool (talks about MCP and a pipeline idea) to run checks like OWASP Top 10 across mobile/web/API targets.
  • Overall claim: AI can help security teams work more efficiently, not replace security professionals.

12) Ethical vs offensive: Red Team vs Blue Team

  • Red Team: attack-focused (“win once”)
  • Blue Team: defense/ongoing prevention (“must keep winning repeatedly”)

Hiring/job advice:

  • Degrees/certifications can help on resumes, but practical skill gets the job.

13) Biggest scams & cybersecurity habits

  • “Most dangerous scams” discussed include investment/fraud at large scale (positioned as bigger than “digital arrest” scams).
  • A key repeated habit:
    • Verify by changing the communication channel (hang up + independently call back)

14) Sex-tortion / deepfake blackmail advice

  • AI-generated nude imagery/blackmail is described as sextortion (also noted it can target boys).
  • Recommended actions:
    • Don’t pay
    • tell trusted people (family/friends)
    • use official cybercrime reporting channels (mentions 1930 cybercrime helpline)
    • don’t panic; follow reporting processes

15) Roadmap for entering cybersecurity

  • Start with basics:
    • networking fundamentals
    • computer basics
    • programming basics
    • how IP works and basics of OSI layers
  • Hands-on learning platforms/labs mentioned:
    • Hack The Box
    • PortSwigger/Burp Suite-style learning (mentioned as “Verbsuite”)
  • Then move toward AI security topics (LLM + OSINT/Top10 concepts) and continuous learning.
  • Certification advice:
    • choose practically oriented certifications
    • certificates alone won’t replace hands-on skills

Main speakers/sources (as referenced in the subtitles)

  • Rishabh Pandey — podcast guest; cybersecurity student/Red Team Security Analyst; runs “Cyber Rish” awareness content
  • Ajay — host/interviewer; returns for this “part three” segment

Original video