(TL16) (INCYBER) Social engineering, quand le pirate préfère hacker votre cerveau que votre clavier

(TL16) (INCYBER) Social engineering, quand le pirate préfère hacker votre cerveau que votre clavier

🎙 Damien Bancal 👥 7K 📅 April 15, 2026 ⏱ 32 min 👁 45 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

social engineeringcybersecurityhuman factorOSINTphishing

Summary

In this talk, Damien Bancal, a cybersecurity expert with 40 years of experience, presents a live demonstration of social engineering attacks, emphasizing that hackers often target the human mind rather than technical systems. He begins by recounting historical examples, such as the first documented Ponzi scheme in 1832 and the famous con artist Frank Abagnale, to illustrate the long-standing nature of social manipulation. Bancal then showcases real-world attack scenarios, including retrieving a hotel guest’s ID by impersonating a family member, using OSINT to gather personal information from social media, and exploiting children’s photos to target their parents’ companies. He highlights the importance of understanding human behavior, such as observing which hand people raise to determine their dominant side, which can be used in physical social engineering. The talk also covers the use of fake advertisements in legitimate magazines to collect data, and the infiltration of cybercriminal groups to understand their methods. Bancal stresses that even seemingly innocuous information, like a class photo, can be leveraged to attack individuals and organizations. He concludes by urging the audience to educate themselves and their teams about social engineering, as it is a critical defense against cyber threats, and shares personal anecdotes of threats he has received from cybercriminals.

205 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into social engineering from a practitioner’s perspective, with concrete examples and live demonstrations that make the concepts tangible. The argumentation is persuasive, relying on the speaker’s extensive experience and real-world cases, such as the attack on a French minister and the use of fake ads in Capital magazine. However, the presentation is largely anecdotal and lacks rigorous scientific backing or statistical data, which weakens the overall argumentative strength. The speaker effectively conveys the importance of the human factor in cybersecurity, but the lack of verifiable sources and the reliance on personal stories may limit its credibility for a more technical audience.

115 words

Title / Content Match

The title accurately reflects the content, which focuses on social engineering attacks targeting human psychology rather than technical hacking.

Quality & Reliability

7/10

The speaker is a seasoned cybersecurity expert with 40 years of experience, providing concrete examples and simulations. However, the talk is largely anecdotal and lacks formal citations or verifiable data, relying on personal experience and general claims.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

This talk offers a unique perspective on social engineering by focusing on live demonstrations and real-world examples, rather than theoretical concepts. The speaker’s experience as a practitioner and his participation in social engineering competitions provide practical insights that are not commonly found in academic literature. The emphasis on the human factor and the importance of educating employees is a valuable contribution to the cybersecurity discourse.

Pour aller plus loin :

  • Social engineering (security) — Provides a comprehensive overview of social engineering techniques and defenses.
  • OSINT (Open-source intelligence) — Explains the methods used to gather information from public sources, as demonstrated in the talk.
  • Kevin Mitnick — A famous social engineer mentioned in the talk, whose exploits illustrate the power of human manipulation.

122 words

Radar Profile

The radar profile shows a balanced distribution across all dimensions, with slightly higher scores in information quantity and quality, reflecting the speaker's expertise and the richness of examples. The technical level is moderate, suitable for a general audience, while the reliability is moderate due to the anecdotal nature of the content.

Reliability 6/10