SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
James was relaxing at home when his phone suddenly erupted with notifications. The password for his personal email account had been changed, but he didn’t remember changing anything. Soon after, his social media accounts followed, alerting him that those passwords had been changed, then his bank alerted him to suspicious purchases. Panicking, James tried logging into his email, but his password no longer worked. Someone had locked him out! Over the next several days, James spent hours recovering accounts, disputing charges, and changing passwords. What confused him most was that he had done everything he thought he was supposed to do. He used a strong password and never shared it with anyone!
But his password wasn’t the problem: the problem was relying on just the password alone. What James didn’t realize was that the urgent text message he received last week from what he thought was his email provider was actually from a cybercriminal, who had tricked him out of his password. Once the cybercriminal obtained the password to James’s personal email, they had complete control of his email account. Not only were they able to access all of James’s emails, but they could use his email account to reset the password on many of his other accounts.
James’s sister, Ariel, received the very same text message, and just like her brother, she was tricked into clicking on the malicious link and entering her password. However, unlike James, Ariel used Multi-Factor Authentication (MFA) to protect her email account. This meant that the attacker was missing a second factor needed to log in, separate from the password, and had a frustrating day of unsuccessful logins. Ariel blocked the attacker, secured her email, and had a much better day than James. Soon after, she helped her brother set up MFA so he could ruin an attacker’s day, too.
Multi-Factor Authentication, or MFA, is a free and simple way to add an extra layer of security to your accounts. Instead of relying just on your password, MFA adds a second step (or factor) to prove it’s really you. With MFA, logging in typically requires at least two of the following:
Even if a cybercriminal steals your password, they still cannot access your account without that second factor. This is why enabling MFA is often considered the single most important step you can take to secure your accounts.
The good news is that MFA is simple to use and widely available. Most major services (email, banking, social media, and shopping sites) offer it for free. Even better, often you only have to log in once with MFA for each site. After that, the website learns and remembers your browser, making authentication not only stronger but simpler. Here’s how to get started:
Take Control of Your Security Enabling MFA is one of the most powerful ways to protect yourself online. Don’t wait until after your accounts are compromised like James’s. Be like Ariel, and make sure it’s the attacker who has a bad day.


Betta Lyon Delsordo, a Penetration Tester at AWS, specializes in application, cloud, and AI security.
Learn more