Thomas Le Coz

Thomas Le Coz

About Thomas Le Coz

Social engineering expert, Thomas is the co-founder of Arsen.

After contributing to the development of the first versions of Arsen’s available features, he now oversees sales and marketing operations.

He shares the results of his research through Arsen’s blog articles on all topics related to social engineering attacks (phishing, smishing, vishing), as well as the impact of AI on them.

Read our editorial standards and transparency page for editorial and corrections information.

Thomas Le Coz Latest Posts

How to Defend Against Advanced Smishing Attacks (and Why Basic Training Isn't Enough Anymore)

How to Defend Against Advanced Smishing Attacks (and Why Basic Training Isn't Enough Anymore)

Smishing has moved well beyond a fraudulent text. From MitM OTP hijacking to cross-channel escalation, here's how sophisticated SMS-based attacks work, and what it takes to stop them.

ClickFix Attacks: How Hackers Make Your Employees Run Malware Themselves

ClickFix Attacks: How Hackers Make Your Employees Run Malware Themselves

ClickFix is one of the fastest-growing social engineering attack techniques. It needs no exploit, no malicious attachment, just a fake error message and a willing user. Here is what happened, why...

Microsoft Entra Users: Be Careful, You Might Be the Target of a New Vishing Campaign

Microsoft Entra Users: Be Careful, You Might Be the Target of a New Vishing Campaign

ShinyHunters are exploiting a legitimate Microsoft OAuth feature to compromise Entra accounts. No fake login page, no stolen password. One convincing vishing phone call is all it takes to hand...

Figure Data Breach: Social Engineering Actors Are Preying on Fintechs, but It’s Not a Fatality

Figure Data Breach: Social Engineering Actors Are Preying on Fintechs, but It’s Not a Fatality

Blockchain lending firm Figure confirmed a significant data breach resulting from a social engineering attack on an employee, leading to the leak of customer data and highlighting the persistent...

The Era of "Dark LLMs": How AI is Supercharging Social Engineering

The Era of "Dark LLMs": How AI is Supercharging Social Engineering

The AI revolution of the 2020s has positioned Large Language Models (LLMs) as the new foundation for digital transformation. With unparalleled data processing power and text comprehension, LLMs...

How Sophisticated Vishing Attacks are Currently Bypassing SSO for Wide-Scale SaaS Data Theft

How Sophisticated Vishing Attacks are Currently Bypassing SSO for Wide-Scale SaaS Data Theft

The ShinyHunters group is currently orchestrating vishing attacks and exploiting SSO to bypass multi-factor authentication. These sophisticated campaigns have led to breaches of cloud platforms...

The New Vishing Playbook: Attackers Can now Control the Flow in Real-Time and Break SSO

The New Vishing Playbook: Attackers Can now Control the Flow in Real-Time and Break SSO

Identity attacks are evolving into hybrid vishing operations. New phishing kits allow attackers to manipulate a victim’s browser in real-time, syncing web visuals with phone scripts to perfectly...

How Quishing Can Be Weaponized to Target Top Organizations: The North Korea’s Kimsuky Case

How Quishing Can Be Weaponized to Target Top Organizations: The North Korea’s Kimsuky Case

The FBI warns that North Korean group Kimsuky is using quishing to target organizations. Discover how bad actors exploit QR codes to bypass security controls and how to test your defense against...

The InboxPrime Case: AI-Based Phishing Kits, Or The New Frontier of Credential Theft

The InboxPrime Case: AI-Based Phishing Kits, Or The New Frontier of Credential Theft

AI and LLMs are creating a paradigm shift in cyberattacks. Attackers now use AI-powered kits to automate the entire attack lifecycle with unprecedented speed and precision. CISOs must adapt...

The BlackForce MitM Phishing Kit & MFA Hijacking: When Your Credentials Are No Longer Enough

The BlackForce MitM Phishing Kit & MFA Hijacking: When Your Credentials Are No Longer Enough

Phishing has evolved. Zscaler ThreatLabz recently revealed BlackForce, a toolkit hijacking active sessions and bypassing MFA, using the "Man-in-the-Middle" (MITM ) attack tactic. CISOs must update...

Vishing Training Platforms for Call Center Teams

Vishing Training Platforms for Call Center Teams

Call centers are prime targets for voice phishing due to high-pressure environments and shared access. Discover why specialized vishing training platforms are essential for BPOs to defend against...

Vishing Training for Financial Services Teams

Vishing Training for Financial Services Teams

Protect your financial institution from voice phishing. Learn why vishing targets banking and fintech teams, the limitations of traditional defenses, and how to implement scalable, compliant...