The story
How an office prankster with no security background ended up in the inboxes of CEOs, bankers and the White House - and the moment it stopped feeling like a game.
Before that I’d done the same to Mark Carney, then Governor of the Bank of England and now Prime Minister of Canada. And to the CEOs of Goldman Sachs, Citibank and Barclays. And to Harvey Weinstein and Kevin Spacey. The White House came last - Tom Bossert, the Homeland Security Adviser, sent me his personal email address. The talk is me working through it honestly: how it happened, how it actually felt, and the uncomfortable, very human reasons it kept working.
01 / THE TALK
It started with a work colleague. I spotted a gap in how they’d read an email, tried it, and it worked. When I fell out with my bank I used the same trick on its CEO. After that I kept making it a bit harder for myself each time, a little more elaborate, to see where it stopped working. It never did. None of it came from studying scammers - I didn’t know pretending to be a CEO was a thing. It came from wanting to trick someone and realising I could just set up an email address. The talk is that journey, honest about the thrill, the panic, and the very human psychology that made it all work. Fair warning: it’s a little rustic. That’s rather the point.
How an office prankster with no security background ended up in the inboxes of CEOs, bankers and the White House - and the moment it stopped feeling like a game.
The thrill, the panic, the paranoia that followed - and what ADHD and autism had to do with why any of it worked at all.
The actual emails I sent - Goldman Sachs, Citibank, Barclays, the White House - pulled apart on screen, and what AI changes from here.
02 / THE FRAMEWORKS
The talks come from somewhere: frameworks built to explain how manipulation actually works - and to teach people to see it before the click.
Every request has five parts, whether it lands in an inbox or in front of an AI agent. Name them and you can see where the risk is before anyone acts. Run a request through the gate and watch.
Phishing awareness as a team competition. Everyone attacks, everyone defends, then everyone learns why the message worked. The battle is the hook, the learning is the point.
A five-minute solo drill. Attack, defend and read the ask behind six inbox encounters - score, streak and a rank to share. No account, no money, just your judgement.
Why believable lures feel true. Four situations people actually fall for, what each one borrows and what it quietly takes - and the equation behind inherited trust. The thinking the other three are built on.
03 / THE STORY
From pranking the powerful to working with the people who protect them.
By the time I got to the White House it was routine. A lookalike email address, a message to a senior official, a reply within minutes. I wasn’t exploiting software. I was exploiting culture.
That realisation took me from the headlines to briefing the US Secret Service and working with the UK’s NCSC. These days it’s building tools at QuilrAI to catch the kind of thing I used to send.
It got picked up a fair bit. Two of the times it got explained back to me on telly.
04 / WRITING
Before there were frameworks there were notes - me trying to explain to myself why any of this worked. Rough in places, and I’ve left them that way.
I tried to introduce myself to the winners of a social engineering competition by phishing them. It worked. Neither of them has spoken to me since.
The name I gave the trance you fall into blasting through your inbox - and why it is exactly the state a scammer needs you to be in.
We read emails with our eyes before we read them with our heads. What a message looks like is doing more of the persuading than what it says.
05 / SIDE PROJECT
A story I’m writing on the side. A city where a machine verifies everyone’s truth in seconds, so the courts went away. Then a detective notices one man’s answers come back a fraction slower than the machine should allow.
Truth has a backdoor. It found one.
Enter the record →06 / BOOK
Part storytelling, part live demonstration, tailored to executives, technical teams or all-staff sessions.
45 minutes plus 15 minutes of Q&A. Adaptable between 30 and 60 minutes.
Delivered in person or virtually.
A screen (HDMI or USB-C), audio from my laptop through the room speakers, and a lapel or handheld mic. Slides run 16:9, I bring my own clicker.
No security knowledge assumed in the room.