Ask&Do
A framework for reading a request through five parts: World, Ask, You, Do and Value. The current demonstrations explore requests to both people and AI agents. Their scores are illustrative, not a validated measure of attack risk.
About James · Updated September 2026
Social engineering researcher and keynote speaker. Creator of Ask&Do, BattlePhish and Before You Allow. At QuilrAI, James contributes across design, human behaviour and AI.
His work explores how a believable request turns trust into action, and how to help people and AI agents recognise the risk before they act.
James became known as the email prankster after impersonating familiar people in emails to bank executives, public figures and White House officials. The story began with a colleague, then his bank; the White House exchanges came later. The messages worked by borrowing relationships and expectations the recipients already trusted.
He went on to work in email threat research, brief the US Secret Service and work with the UK’s National Cyber Security Centre. His talks use the actual emails and his experience of sending them to explain why social engineering works.
Public background: James Linton on Wikipedia. First-person accounts: Hacking a Hacker and Inbox Hypnotism.
At QuilrAI, James contributes wherever his experience in design, human behaviour and AI can help. Alongside that work, he develops the independent projects below and gives talks about social engineering.
A framework for reading a request through five parts: World, Ask, You, Do and Value. The current demonstrations explore requests to both people and AI agents. Their scores are illustrative, not a validated measure of attack risk.
A team format for learning how phishing works by taking turns attacking and defending. It uses an organisation’s existing phishing simulation tools.
A solo learning game based on the same thinking. Players assess fictional requests and see an explanation after each decision.
A free, experimental browser extension that explains the consequences of permissions before someone authorises an app. An independent Ask&Do tool, built in James’s own name.
An essay about how believable lures borrow familiar relationships, processes and expectations.
An original graphic-novel world in progress, exploring truth, power and a trusted verification system. The project explains James’s authorship and collaboration with AI tools.
The 2021–2022 archive records the development of these ideas: inbox autopilot, design as a cue for trust, and the original Ask&Do explanation. The posts retain their original publication dates and include links to available archive evidence.
James’s earlier email-awareness series introduced Ask&Do through everyday scenarios, including the value of account access and the manipulation of payment processes. The original video embeds are not hosted on this rebuilt site. For current learning resources, explore BattlePhish, Inbox Arena and the writing archive.
Talks combine first-person stories, actual emails and practical explanations for executives, technical teams and general audiences. Read about the talk or download the speaker one-sheet.