Phish-Back: How to turn the problem into a solution.
Gautier Bugeon (CEO · a software company specializing in deception technology)
BSides Las Vegas 2025 · Day 1
Overview
Gutier Bjon, CEO of Moken, presents “Phish-Back” (spelled “Fishbach” by the host in the transcript): a strategy to recover visibility into stolen credentials by placing high-fidelity fake login portals on the internet, deliberately discoverable during attacker enumeration, so that credential tests against a plausible corporate surface generate actionable alerts. The talk contrasts this with traditional security awareness training, phishing simulations, and dark web monitoring, arguing that most stolen credentials never appear in marketplaces and that MFA—while important—did not prevent a major incident in the speaker’s past when a new subsidiary rolled out without MFA enabled.

Key moments
- 2:00 Problem framing: stolen credentials as dominant access path; skepticism toward dark web monitoring as exhaustive coverage.
- 4:00 Origin story: four users phished at a 12k-person org; MFA everywhere except a new subsidiary opened a critical login path within ~24 hours.
- 6:00 Phish-Back definition: fake external portals crafted like phishing pages to catch enumeration-phase credential tests—not classic intel honeypots.
- 8:00 Scanner fingerprinting basics: Shodan hashing of HTTP, HTML, DOM—and why naive cloning duplicates impossible ETags.
- 12:00 Citrix login replication scale argument: endpoints × languages × user agents × HTTP methods → 162k+ variations.
- 14:00 Lure strategy: credible hostnames like test.corp.com that pentesters admit they will try first.
- 16:00 Noise funnel: password policy + naming regexes claim ~95% false positive reduction; directory validation as final gate.
- 18:00 Results: 2.3B attempts across ~50 portals / ~20 companies → 257 valid creds with no dark web presence; 0.1% rate stresses automation need.
Phish-Back: How to turn the problem into a solution.
Speakers: Gutier Bjon (as introduced; host also references “Gaia Bjon”), CEO, Moken (cyber security software company)
Conference: BSides Las Vegas
YouTube: https://www.youtube.com/watch?v=zbh-Kopflec
Overview
Gutier Bjon, CEO of Moken, presents “Phish-Back” (spelled “Fishbach” by the host in the transcript): a strategy to recover visibility into stolen credentials by placing high-fidelity fake login portals on the internet, deliberately discoverable during attacker enumeration, so that credential tests against a plausible corporate surface generate actionable alerts. The talk contrasts this with traditional security awareness training, phishing simulations, and dark web monitoring, arguing that most stolen credentials never appear in marketplaces and that MFA—while important—did not prevent a major incident in the speaker’s past when a new subsidiary rolled out without MFA enabled.
Background
▶ Watch: Problem framing: stolen credentials as dominant access path; skepticism towar... (2:00)
The speaker frames passwords as high-value assets because they are easy to steal and remain a dominant initial access vector. He critiques training as often failing to engage users, simulations as rarely producing “great results” in practice (anecdotal, from his experience), and dark web monitoring as over-marketed: some credentials appear in marketplaces, more move in private groups, but the largest share is never shared—only used.
The origin story (as told) is a true incident roughly two years before the talk: attackers phished a small set of users at a 12,000-person organization; four users returned valid credentials; the attacker followed a pentest-like playbook, hitting internet-exposed services. MFA was enforced broadly, but a South American subsidiary went live with MFA forgotten; attackers found it within about 24 hours, logged in, and triggered what the speaker describes as the largest crisis of his professional life.
After remediation, the speaker reasoned: had a fake VPN gateway existed among real ones during enumeration, the attackers might have tipped their hand weeks earlier, enabling password resets before the critical login path existed.
The talk’s rhetorical pivot is important: the speaker anticipates the audience muttering honeypot and agrees on the surface similarity, then argues the intent and fidelity bar differ. Classic external honeypots often optimize for collecting noise and trends. Phish-Back optimizes for a rarer event—correct credentials typed into a non-production hostname that should never appear in legitimate workflows—while still surviving the same scrutiny tools that attackers use to prioritize targets.
Key Findings
▶ Watch: Phish-Back definition: fake external portals crafted like phishing pages to c... (6:00)
- Conceptual distinction from classic honeypots: Internet-facing honeypots are traditionally used for threat intelligence and broad noise collection. Phish-Back targets credential recovery using phishing-grade fidelity rather than generic tarpits.
- Two dominant challenges:
- Perfect illusion: Inside a network, attackers move quickly; on the internet, they may take weeks or months probing authenticity, so the decoy must survive deep scrutiny (fingerprinting, localization, odd HTTP behaviors, TCP stack details for cautious actors).
- Signal in noise: A public login surface receives massive automated traffic; operators must reduce billions of events to dozens of meaningful alerts.
- Fingerprinting against scanners: Tools such as Shodan fingerprint via hashes of HTTP responses, rendered pages, and raw HTML. The speaker gives examples where simple copy-paste fails: FortiNet login pages change hashes due to ETag randomness; Outlook Web Access behaves differently across hash types (DOM hash stable while others vary). The methodology must be per-product.
- Scale of faithful replication (Citrix example): For a Citrix login page, the speaker claims 194 base endpoints, 12 languages, 7 user agents, 10 HTTP methods, yielding >162,000 variations—used to illustrate engineering depth beyond a static HTML clone.
- Lure design via plausible hostnames: Examples include
test.corp.comand themes like home office / remote that stand out during DNS/service enumeration yet blend into real external postures.
- Filtering heuristics: Apply password policy constraints (e.g., reject attempts shorter than corporate minimum length), regex patterns for firstname.lastname conventions, and dark web leak checks to eliminate most noise. The speaker states these two classes alone remove ~95% false positives (as presented).
- Automation for verification: The final step described is integrating with Active Directory / Okta / similar to verify whether submitted credentials are valid before forced reset actions.
- Empirical results (speaker-reported): Deployed across ~20 large international companies over ~18 months, ~50 portals, processing 2.3 billion login attempts, yielding 257 validated credentials without dark web exposure—about 0.1% of attempts. The speaker emphasizes automation quality: without it, the approach is “useless.”
Technical Deep Dive
▶ Watch: Citrix login replication scale argument: endpoints × languages × user agents ... (12:00)
Fingerprint evasion is treated as an adversarial ML-adjacent problem without ML: you must match not only visuals but headers, timing, endpoint graphs, and sometimes protocol behaviors. The speaker recommends reconnaissance patterns familiar to pentesters: documentation, CVE mapping for hidden endpoints, proxy-based analysis, directory brute force (mentions ffuf), and manual clicking.
Operational security considerations (implied, not fully explored): running lookalike portals can create brand/legal risk, abuse reporting, and data handling questions if real users mistake decoys for production. The talk focuses on attacker deception rather than enterprise policy edge cases; specifics are unknown from the transcript.
Detection pipeline is a funnel: raw logs → policy/regex filters → leak correlation → directory validation → alert. The defining property of a “critical” alert in this model: a valid credential used against a fake portal nobody legitimate should use.
Attacker-model nuance (as described): On internal networks, attackers are depicted as rushed—any weird server might still be “good enough” to try. On the public internet, the same credential-testing behavior is slower and more careful because wrong guesses are costly and anonymity is imperfect. That asymmetry is why the speaker stresses months of possible scrutiny and why language, mobile layouts, and HTTP method coverage become first-class requirements rather than polish.
Operational cautions the talk mostly does not solve: If a decoy domain is too plausible, you risk user confusion and credential capture of employees who believe they are logging into a legitimate test system. If automation resets passwords aggressively, you can create availability incidents or lockouts. The transcript does not provide an enterprise runbook for these failure modes; any real deployment would need explicit scope, branding, legal review, and support processes beyond what is on stage.
Demo / Proof of Concept
▶ Watch: Lure strategy: credible hostnames like test.corp.com that pentesters admit th... (14:00)
No live demo is described in the transcript; the talk relies on architecture explanation, Shodan fingerprinting discussion, and deployment statistics from the speaker’s program.
Defensive Implications
▶ Watch: Results: 2.3B attempts across ~50 portals / ~20 companies → 257 valid creds w... (18:00)
- Treat credential theft as an ongoing condition; monitoring only marketplaces misses most real-world misuse patterns described by the speaker.
- If you deploy decoys, invest in engineering parity with production identity surfaces—half-faithful pages may only catch noisy actors.
- Pair decoys with strong IAM hygiene (the MFA gap story is a reminder that one unprotected ingress negates broad controls).
- Build automation before scale: billions of attempts will overwhelm human triage.
- Consider legal, privacy, and support workflows if credentials are validated against live directories—ensure resets do not harm legitimate edge cases (not detailed in talk).
Why the MFA story matters to the architecture: The speaker’s breach was not “MFA failed everywhere”; it failed at the new edge of the business. That matches a common real-world pattern: partial coverage plus rapid IT change creates a narrow window that skilled attackers exploit quickly (24 hours in the narrative). Phish-Back is presented as an early warning mechanism during reconnaissance, not a replacement for MFA rollout discipline.
Key Takeaways
- Phish-Back reframes honeypots as credential tripwires placed where post-phish attackers actually work: external enumeration and password spraying.
- Scanner-grade fidelity matters as much as human UI polish; hash stability behaviors differ per vendor stack.
- Noise reduction is the core engineering challenge; without it, internet-facing login traps drown in bots.
- Speaker-reported field data suggests non-market credential use is material across large enterprises—treat as hypothesis worth validating in your own telemetry.
- The talk’s strongest cautionary tale is operational: MFA everywhere is a process problem, not a checkbox—new sites and exceptions are classic failure modes.
Interpreting the speaker’s statistics carefully: The 2.3 billion attempts number is useful mainly as an order-of-magnitude stress test: internet login surfaces are dominated by automated traffic, so any detection strategy that requires human review per event will fail. The 257 “valid credential” outcomes are presented as surprising relative to expectations (one or two in the speaker’s prior guess), but the talk does not define “valid” beyond passing directory verification, does not specify false negative/positive rates, and does not break down how many events led to confirmed incidents versus proactive hygiene. For a reader building a business case, treat the figures as deployment experience from a vendor CEO rather than independently audited research—still useful directionally, but not a substitute for your own measurement in your identity telemetry.
Where this complements (rather than replaces) existing controls: The speaker is not arguing against MFA, conditional access, or device trust; he is arguing that credential secrecy remains valuable and that marketplace monitoring is an incomplete window into misuse. A balanced enterprise program might still use passwordless where feasible, enforce phishing-resistant MFA for administrators, and run canary tokens—Phish-Back is one more sensor aimed at a specific attacker behavior: testing stolen creds against external auth surfaces.
About the Speaker(s)
Gutier Bjon (name as spoken; alternate spelling appears in host intro) identifies as CEO of Moken and previously as head of cybersecurity operations for large international companies and a pentester for 10 years. Further credentials beyond the transcript are unknown.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Clever operational concept with real engineering teeth (fingerprinting and noise control), but the talk is light on adversarial counterplay and governance edge cases. The field stats are interesting if you trust the speaker’s deployment, but they are not independently verifiable from the stage content alone.
Heather Calloway (CISO) — SOLID
This is defensive entrepreneurship: a control that sits between threat intel and IAM operations. The business and legal exposure of lookalike authentication surfaces is real; the talk under-addresses that, but the MFA gap story is a textbook governance failure mode.