Video summary
Podcast with a REAL HACKER 🖥️ Part 3 | AI Scams, Phone Hacking & Cybersecurity Careers in 2026
Main summary
Key takeaways
Tech & Cybersecurity Summary (Podcast Part 3)
1) Data privacy: phone number ≠“just an identifier”
- The speaker shows that sharing only a phone number can be enough to retrieve extensive personal details (e.g., birthday/Aadhaar digits, father’s name, and location/address-like data) through OSINT (open-source intelligence) and public data aggregation.
- Key concept: Phone number (and email) acts as a “connector.” Once matched across leaked profiles, attackers can link multiple datasets into a fuller identity.
2) Public-data OSINT + leaked-data correlation (two-stage view)
The discussion frames personal information as coming from two buckets:
-
~30% “given publicly” People voluntarily post/tag details on social media, including family information, birthdays, locations, resumes/job history, and more.
-
~70% “not intentionally given” Data collected via KYC/insurance/financial services, telecom/health apps, loan flows, etc., which can later leak from organizations.
Once breaches happen, scammers can buy/sell data and use it for impersonation.
3) Data leaks and enforcement (policy + incident response)
- Breaches are treated as inevitable, but responsibility should lie with service providers.
- An Incident Response Model is mentioned, with multi-phase coverage such as:
- preparation
- identification/contamination
- eradication/fix, etc.
- Regulatory/policy points mentioned (in DPDP context):
- Breach notification within 72 hours
- potential large fines (the speaker cites numbers like ~₹250 crore) if reporting/security controls aren’t followed.
- Example cited: a health insurer leak where leaked data was later validated as real through samples sourced from elsewhere.
4) Dark web vs normal web (and Tor as the access layer)
- The dark web is described as:
- a segment of the internet accessible via specialized routing/browser tooling such as Tor
- It’s compared to the normal web as more “air-gapped” in behavior, though technically it’s just a different access network/anonymity layer.
- Attackers are said to use it to trade stolen data and target victims by region.
5) Biometric security: not the data itself, but the implementation
The speaker’s core argument: biometrics must be used correctly.
- Mentioned principle (NIST-style): biometrics should not be the only factor.
- Authentication should be multi-factor (e.g., something you are + something you have/know).
- Example: AEPS-style systems (Aadhaar-enabled payment concepts), where attackers may attempt to reconstruct/abuse fingerprint workflows.
- Practical mitigations suggested:
- Lock/unlock biometric permissions (e.g., “Aadhaar lock” concept)
- ensure OTP/second factor is involved rather than relying on biometrics alone
6) AI scams: voice/video impersonation at scale
Capabilities claimed:
- With only a few seconds of voice, AI can generate a realistic voice; more data improves accuracy.
- With photos from multiple angles, AI avatars can mimic a person’s appearance.
Example scam scenario:
- An avatar/voice requests money using UPI wallet/transfer-style prompts.
Escape/detection advice:
- “Three-finger test” in video calls: move fingers close to the face and look for clone distortions/artifacts (the speaker claims AI struggles with live multi-finger real-time generation).
- Change the channel: hang up and call back using a known trusted method, not the incoming voice/video stream.
7) Phone number cloning & “trusted caller” social engineering
- The speaker describes personalized scams where attackers use a cloned caller identity so victims’ contacts trust the call.
- Suggested mitigations:
- Call back on a different channel
- use a shared family verification code for emergencies
8) “Cyber slavery” / forced labor scams
- Covers fake job offers that move victims internationally and trap them.
- Countries mentioned include Cambodia and Indonesia (also mentions Malaysia/Thailand routes).
- Claimed workflow:
- victims are held/coerced and made to run scam scripts using stolen documents and phones.
9) Faraday bags for privacy isolation
- A Faraday bag demo is described:
- it blocks electromagnetic signals so a phone inside cannot transmit/receive
- Emphasis: privacy protection and isolation (not misuse).
10) Wi-Fi-based sensing as “camera replacement” (ESP32 / CSI-style idea)
- A guest demonstrates small Wi-Fi/ESP32 devices used to detect/estimate movement inside a home without a conventional camera.
- Device idea:
- analyze Wi-Fi signal changes/amplitude shifts due to reflections and obstacles.
- Framed as potential future intrusion detection using Wi-Fi presence rather than visible cameras.
11) AI in security: faster testing and workflow automation
- AI is presented as helpful for defenders by automating repetitive scanning/assessment.
- Mentions connecting “AI” with a security scanning tool (talks about MCP and a pipeline idea) to run checks like OWASP Top 10 across mobile/web/API targets.
- Overall claim: AI can help security teams work more efficiently, not replace security professionals.
12) Ethical vs offensive: Red Team vs Blue Team
- Red Team: attack-focused (“win once”)
- Blue Team: defense/ongoing prevention (“must keep winning repeatedly”)
Hiring/job advice:
- Degrees/certifications can help on resumes, but practical skill gets the job.
13) Biggest scams & cybersecurity habits
- “Most dangerous scams” discussed include investment/fraud at large scale (positioned as bigger than “digital arrest” scams).
- A key repeated habit:
- Verify by changing the communication channel (hang up + independently call back)
14) Sex-tortion / deepfake blackmail advice
- AI-generated nude imagery/blackmail is described as sextortion (also noted it can target boys).
- Recommended actions:
- Don’t pay
- tell trusted people (family/friends)
- use official cybercrime reporting channels (mentions 1930 cybercrime helpline)
- don’t panic; follow reporting processes
15) Roadmap for entering cybersecurity
- Start with basics:
- networking fundamentals
- computer basics
- programming basics
- how IP works and basics of OSI layers
- Hands-on learning platforms/labs mentioned:
- Hack The Box
- PortSwigger/Burp Suite-style learning (mentioned as “Verbsuite”)
- Then move toward AI security topics (LLM + OSINT/Top10 concepts) and continuous learning.
- Certification advice:
- choose practically oriented certifications
- certificates alone won’t replace hands-on skills
Main speakers/sources (as referenced in the subtitles)
- Rishabh Pandey — podcast guest; cybersecurity student/Red Team Security Analyst; runs “Cyber Rish” awareness content
- Ajay — host/interviewer; returns for this “part three” segment