We will hack you,before attackers do.

AwareXone detects and stops social engineering, scams and human-targeted attacks.
We find them by running them first.

Right now, somewhere, an attacker isreading your org chart to find who approves payments
Built by the team that secured:
NASAGoogleMetaAmazonSonyAllstateChatGPTToyotaWordPressNetflixXTrip.comNASAGoogleMetaAmazonSonyAllstateChatGPTToyotaWordPressNetflixXTrip.com
Our work has been featured in
The Daily StarThe Peninsula QatarUniversity of CyberjayaBoston Institute of AnalyticsGulf TrickThe Desi BuzzWiser.myOpenTools.aiThe Daily WarriorsSirf PakistanNomusicaVOH.com.vnMyTech MyanmarBabab.netMy Electric SparksBD PreneursBangi NewsThe ChronifyThe Daily CampusLondon Bangla TimesEducation TimesBangladesh Branding LLCSomoy TVBangla VisionJugantorDaily InqilabJago News 24Doinik BanglaNews Bangla 24The Daily StarThe Peninsula QatarUniversity of CyberjayaBoston Institute of AnalyticsGulf TrickThe Desi BuzzWiser.myOpenTools.aiThe Daily WarriorsSirf PakistanNomusicaVOH.com.vnMyTech MyanmarBabab.netMy Electric SparksBD PreneursBangi NewsThe ChronifyThe Daily CampusLondon Bangla TimesEducation TimesBangladesh Branding LLCSomoy TVBangla VisionJugantorDaily InqilabJago News 24Doinik BanglaNews Bangla 24
Open source

We build in the open, so defence moves faster than fraud

A fixed share of our engineering time goes into security tooling anyone can clone today. No licence, no paid tier, no upgrade path. Attackers have shared their tools for twenty years. Defenders are only now catching up.

awarexone/Agentic-Bug-Hunter

It drives the reconnaissance, triage and reporting loop a bug bounty hunter would otherwise run by hand. This is the same tooling we point at client scopes, published with nothing held back for a paid tier.

40k+installs4,416stars796forksPython
public-skills-builder

Generates agent skill files for eighteen vulnerability classes from public disclosures.

223Python
web3-bug-bounty-hunting-ai-skills

Eighteen smart contract security skill files for agent-assisted review.

129Markdown

Fraud does not check whether you have a security budget before it starts. Publishing the tooling is how the clinics, schools and small businesses we will never invoice get to defend themselves too.

4,768 stars across three public repositories.

The open source program
The problem

Social engineering already worked.
AI made it industrial.

Attackers stopped bothering with your firewall a long time ago. They call someone instead, and the tools that make it convincing now cost almost nothing.

01
0%of breaches involve a human elementVerizon DBIR 2025
02
0 secof audio is enough to clone a voiceMicrosoft VALL-E, 2023
03
$0Mlost in one year to crime with an AI nexusFBI IC3 Annual Report 2025
04
$0Mtaken in a single deepfake video callArup, Hong Kong, 2024
Diagram: how scammers use AI. Research, language and voice feed a single model that produces images, video, scale and fabricated identities.
One model now covers every stage an attacker used to need a team for.
Voice

A familiar voice is no longer identity

Three seconds from a webinar or a voicemail greeting produces a real-time clone. Your staff have spent their careers treating a recognised voice as proof.

Video

Seeing someone is no longer proof

Live face replacement survives a compressed webcam stream and an eight-minute meeting, which is exactly how approvals happen.

Language

Bad grammar is no longer the tell

Models write flawless, context-aware messages in any language and any register, personalised per recipient, at unlimited volume.

Reconnaissance

Research costs nothing now

Mapping an org chart, matching it against breach data and writing a tailored pretext per employee took an analyst a week. It is now an overnight script.

A Zoom call with one real participant and three marked as fake. $25 million stolen with one deepfake video call, Hong Kong, 2024. Source CNN and SCMP.
Hong Kong, 2024. A finance employee joined a video call where every other participant was synthetic, and made fifteen transfers.
A video call where the two participants presenting as government officials are pixelated to show they are deepfakes. The victim transferred $4.9 million. Source Singapore Police, May 2026.
Singapore, 2026. Same method, two years later, against someone who had every reason to be careful.

Which leaves one control that still scales: a workforce that verifies through a second channel, and is never punished for doing so.

What we do

One team for the whole human attack path

From the reconnaissance an attacker starts with, to the person they eventually call, to the systems behind them. Engaged individually or as a single program.

Fig. 01Social engineering

Every path ends at a person.

  • Recon
  • Contact
  • Access
The Human Firewall Program

Assess. Simulate. Train. Measure. Repeat.

Fig. 02The program loop

A loop, not the annual module.

  • Exposure
  • Memory
  • Proof
01Simulate

Run the attack before somebody else does

Pretexts built from live reconnaissance of your own organisation, delivered across every channel an attacker would use.

  • Spear phishing, vishing, smishing, quishing, chat and deepfake video
  • Weighted by role, privilege and payment authority
  • Measured on reporting speed and escalation, not just click rate
02Train

Train the mind, not the checklist

Surface cues are dead, so we teach the psychological lever instead. The lure will always be new; the feeling it creates never is.

  • The seven levers every social engineer uses, and how each feels from inside
  • Ninety-second coaching the moment somebody fails, not months later
  • Verification made procedural, so declining is never a confrontation
The psychological buttons: authority, familiarity, urgency, reciprocity and commitment, fear, scarcity, and social proof.
The levers taught in every session, and how each one feels from inside.
03Measure

Report human risk like any other risk

A number your board can act on, built from behaviour rather than attendance, weighted by the privilege each person holds.

  • Scored by department, role and access level
  • Repeat susceptibility surfaced for coaching, never for discipline
  • Evidence mapped to ISO 27001, SOC 2, NIST CSF and GDPR expectations

Delivered as a rolling program or as a one-off assessment if you need a baseline first.

Scope a program
From the field

What we show on stage

Figures from our talks, workshops and engagement debriefs. Every loss number here comes from a named source: UNODC, the FTC, the FBI, Singapore Police.

Scroll for all 16
01/16
Social engineering: psychology with a goal. A hand emerging from a phone screen works a person like a marionette.
01Manipulation is a discipline, not a trick. Every pretext is built around a psychological objective.
Map of East and Southeast Asia. Up to $114 billion lost to scams in 2025, around three times the 2023 figure. Source UNODC.
02Regional losses roughly tripled in two years. This is the market we operate in.
Scams in the world: $16 billion lost to fraud in the US in 2025, imposter scams the most common category at $12.5 billion in 2024. Source FTC.
03Reported United States losses alone. Imposter scams are the single largest category.
A phone showing an AI investment bot advert sitting inside a bear trap. 22,000+ complaints involving AI-related information, losses exceeding $893 million. Source FBI Internet Crime Complaint Center, 2025.
04The FBI now tracks an AI descriptor on its complaints. In its first full year it accounted for $893 million.
Fake voice plus fake video equals deepfake.
05Two cheap components, and a verification habit your staff have relied on for their whole careers stops working.
A gloved hand gripping the globe. What changes when AI goes multilingual?
06Language was the last geographic barrier to fraud at scale. It is gone.
Two professionally dressed figures. Why smart people get scammed.
07Susceptibility is not a measure of intelligence. It is context, pressure and perceived authority.
The question 'who are you?' struck through, replaced by 'what evidence are we using to decide that you are you?'
08The question every verification procedure has to answer, and that most never actually ask.
Two figures exchanging a fifty ringgit note. Would you give RM50 to a stranger?
09The opening question in our workshops. Nobody says yes. Most of the room has already done it.
A finger pressing the control key on a keyboard, with an intruder hidden beneath it. The moment of control.
10Every attack has one instant where a person can still stop it. Widening that instant is the product.
A hooded attacker in red facing a suited defender in green, both channelling energy. Their advantage and ours.
11The same models are available to both sides. Only one side is currently using them systematically.
AI on our side: prioritise suspicious transactions, correlate identities and indicators, threat intelligence, flag unusual patterns, search data, simulate attacks, better human verification.
12Where we point agents. Reconnaissance, correlation, simulation and triage - with an analyst deciding what matters.
Concentric defence layers: identity, context, friction, intelligence, recovery.
13Five layers. A successful pretext has to defeat all of them; most organisations are running two.
The future of verification: identity verification, cryptographic provenance, behavioural analytics, threat intelligence, human review, known contacts, device and session signals, transaction intelligence.
14What replaces “I recognised their voice” as proof of identity.
What organisations should change tomorrow: high-risk financial requests cannot be verified through the same channel that delivered them, create explicit stop-and-verify triggers, train people on psychology rather than only red flags.
15Three changes that cost nothing and close the most common path in.
Closing slide reading 'Questions?' with the speaker credit MD Shariar Shanaz Shuvon, Founder and CEO, AwareXone, Annual Asia Anti-Fraud Leaders Summit 2026.
16Closing the Annual Asia Anti-Fraud Leaders’ Summit, Kuala Lumpur, 2026.

We publish the research rather than gate it. If a figure here is useful to your board, take it.

Read the write-ups
How we work

You are handing us permission to manipulate your staff

That deserves more than a statement of work. Four constraints, in writing, on every engagement.

Fig. 03Rules of engagement

The boundary is drawn before we start.

  • Scope
  • Authorisation
  • Stop authority
01

Authorised, scoped, documented

Signed rules of engagement naming targets, channels, timing and limits, plus a named contact who can stop an engagement instantly.

02

No blame, no names

Individual results go to the individual. Leadership sees aggregates. Programs that shame people stop receiving reports.

03

Evidence over theatre

Findings reproduced by hand and rated on real impact. If a control already works, we say so.

04

Independent by design

We resell nothing and take no vendor commission. Often the recommendation is a procedure rather than a purchase.

Evidence mapped to
ISO 27001SOC 2NIST CSFGDPRPCI DSSDORANIS2HIPAA
Pricing

Three ways to start,
and no price list

What it costs depends on headcount, channels, depth and cadence, so the number comes out of a thirty-minute call rather than a table. No pitch deck, and no proposal unless there is something worth doing.

  • A real conversation, not a sales script
  • You talk to the person who would run the work
  • No proposal unless there is something worth doing
Questions

Before you ask

Yes, and only under signed authorisation with an agreed target list, consent controls, an emergency stop contact and a full audit trail. Scenarios are designed to teach rather than humiliate, and every simulated call is debriefed. If your leadership is not comfortable authorising it, we will say so and scope around it.
No. Individual results go to the individual, along with the coaching. Leadership sees aggregates, trends and department-level risk. Programs that name and shame reliably produce the same outcome - people stop reporting - and concealment is what turns a two-minute incident into a two-week one.
No. Small organisations are targeted heavily precisely because they have no security function. Engagements start at a single workshop or a one-off exposure assessment, and we deliberately keep an entry tier that a twenty-person company can afford. If you have genuinely no budget and serve a community, ask about our free monthly sessions.
Start with a free thirty-minute call. We talk through where you stand, what a program would look like, and whether it is worth doing - no pitch deck, no assumed findings before we have even spoken. Pricing depends entirely on headcount, scope and channels, and we will only propose work if that conversation turns up something worth doing.How pricing works