BSides Canberra 2026

Just spoof the government?
2026-09-26 , Off-Main Track

During an authorised social engineering engagement for a state government department, email security flaws were identified which led to successful target interaction with “malicious” infrastructure.

With the engagement a success, the question was raised; where else can these email security flaws be found across the gov.au domain, and can we 'just spoof the government?'

Ben™ is an Offensive Security Consultant with a diverse background in Information Technology and Education. Since transitioning from teaching and vocational education governance, he has conducted various offensive security engagements, including penetration testing and adversary simulation. Ben™ has experience conducting testing across external applications and services, internal and cloud-based corporate networks, as well as specialist experience in various forms of social engineering.

He operates under the assumption that snacks improve all outcomes, brings a methodical approach to chaos and a chaotic approach to method, and quietly wonders why people insist on paying him for something he’d likely do for free.