1. How did you manage to break into a major bank as a teen?

Treptel: “I got my first computer when I was 14, an old Pentium 486, and became obsessed with understanding how systems worked. I taught myself everything I could, inspired by the hacker stories and figures I was reading about at the time.

“By the age of 16, I was breaching one of Australia’s Big Four banks, where I gained access to around 40,000 credit card numbers and other sensitive information.

“It wasn’t about the money or personal gain at the time, I really got a thrill out of figuring out how to get into their systems as opposed to any financial payoff.”

2. How did the police catch up with you?

“The bank eventually detected suspicious activity and alerted authorities. Funnily enough, it was a pizza I ordered using compromised details that led the Australian Federal Police to my door in 1996.

“That experience was a major turning point, and made me realise the consequences of what I was doing and ultimately convinced me to walk away from black-hat hacking for good.”[Treptel‘s age and the less stringent cyber security laws at the time saw him escape with 150 hours’ community service.]

3. What’s your role today?

“My focus now is on helping organisations stay ahead of the cyber threats. I founded CTRL:CYBER, grew it into a business valued at more than A$100 million, and sold it in 2021.

“Since then, I’ve launched Ironclad ID, which focuses on tackling social engineering attacks which is one of the fastest-growing forms of cyber crime.

“I also host the CyberHacker podcast, which has grown to more than 100,000 subscribers, and through MVRCK Digital I work with organisations to strengthen their security posture and recover from cyber incidents.

“Alongside that, I work as a keynote speaker and media commentator, speaking on cyber crime, AI risk, deepfakes, and the growing intersection between technology and politics.”

4. If you were a hacker today, how would you be exploiting AI?

“If I were an attacker today, I’d be using AI to supercharge social engineering. Deepfakes, voice cloning and synthetic content are making impersonation scams far more convincing than ever before.

“AI allows cyber criminals to personalise phishing attacks at scale instead of sending thousands of generic emails; now they can create highly targeted messages tailored to individual victims in seconds.

“It also dramatically speeds up reconnaissance as attackers can gather intelligence on potential targets faster, automate parts of the attack process and operate far more efficiently than they could in the past.”

5. How can organisations defend themselves against AI threats?

“The first step is recognising that traditional cyber awareness training is no longer enough; employees now need to understand how deepfakes, voice cloning and AI-powered social engineering attacks actually work.

“Organisations should implement multi-channel verification for high-risk requests, whether that’s payments, credential resets or access to sensitive information. A simple phone call or secondary approval process can stop a major incident.”

READ MORE

“Cybersecurity also needs to be treated as a leadership and culture issue, not just an IT department responsibility; it’s clear that the organisations that respond best are the ones where security is embedded across the business. Those that have a breach response and recovery plan in place before an incident occurs are already miles ahead of those who don’t.”

“Most importantly, stay proactive. Regularly test your systems, challenge your assumptions and audit your defences. The threat landscape is evolving too quickly to assume yesterday’s protections will be enough tomorrow.”

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.