Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover
Show notes
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.
Join hosts John Dilgen and Alexandra Moore as they break down:
✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console
✅ Why threat actors are now impersonating HR to make their calls more convincing
✅ How legitimate B2B platforms are being weaponized to personalize attacks before a single call is made
✅ The specific controls that can stop these campaigns before they reach your users
🔑 Two questions your organization should be asking right now:
- If a caller already knew your employee's job title, manager's name, and direct number — would your team recognize it as a social engineering attempt, or fall for it?
- Is your organization still relying on push-based MFA as its primary account takeover defense?
👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest
👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree