Carlos Alvarado Quesada
48th President of Costa Rica (2018-2022) | Professor of Practice, The Fletcher School, Tufts | TIME 100 Next | National Geographic Planetary Leadership Award
World-Renowned Security Researcher & Ethical Hacker | Inventor of Evercookie & the Samy XSS Worm | Co-Founder of Openpath | Cybersecurity, Privacy & Hardware Expert
Samy Kamkar is one of the world's most recognized security researchers, a self-taught hacker whose creations exposed critical flaws in global systems, from the most viral XSS worm in history to tools that clone car key fobs. Now a chief security officer and enterprise founder, he gives technical and executive audiences alike a rare inside view of how real attacks are built and how to design systems resilient enough to withstand them.
Want to book Samy Kamkar as a speaker for your event? Please provide the info below and we’ll get in touch within 24h:
Speaker Samy Kamkar is one of the most influential cybersecurity researchers in the world, a self-taught hacker, entrepreneur, and privacy advocate whose work has exposed fundamental weaknesses in systems most people assume are secure. From connected vehicles and key fobs to corporate networks and critical infrastructure, Kamkar’s research has repeatedly shown that the attack surface of modern life is far larger than organizations realize, and that understanding how adversaries think is the most powerful defense available.
Cybersecurity speaker Samy Kamkar first gained global attention in 2005 when he released the Samy worm, the fastest-spreading virus in internet history, which infected more than one million MySpace accounts in under 24 hours by exploiting a cross-site scripting flaw. He was 19. What made the event remarkable was not only its scale but what it revealed: major platforms were defending against threats that no longer reflected how real attacks were built. The episode led to his cooperation with federal authorities and ultimately redirected his talent toward building safer systems for organizations worldwide.
In the years that followed, Kamkar engineered a series of landmark demonstrations that became required study in security circles. He created Evercookie, a mechanism showing how websites could track users even after cookies were deleted, spurring international debate about digital privacy. He built SkyJack, a drone capable of autonomously hijacking other drones in flight, and developed tools showing how car key fobs could be cloned in seconds and how everyday devices leak far more data than their owners suspect.
Kamkar co-founded Openpath Security, a frictionless enterprise access-control company acquired by Motorola Solutions and now part of Avigilon Alta, where he has helped shape secure access technology as a chief security officer and advisor. He has counseled companies across technology, financial services, and defense, working at the intersection of offensive research, hardware hacking, and privacy policy. That combination makes him one of the few voices who can speak credibly to both engineering teams and the C-suite about what real threats look like before they become breaches.
As a speaker, Samy Kamkar brings something few security professionals can offer: the perspective of someone who has built the attacks, not just defended against them. His sessions demystify how sophisticated intrusions actually work, from social engineering and credential theft to hardware exploits and supply-chain risk, and translate that knowledge into a practical security culture for organizations at any level of maturity. Senior audiences leave with a sharper understanding of their risk surface and a clearer framework for investing in resilience.
Most organizations invest in cybersecurity without understanding how adversaries actually operate. In this session, Kamkar walks audiences through the real mechanics of high-profile attacks — from the Samy XSS worm to drone hijacking to vehicle key fob cloning — using his own work as a lens to expose the creative, methodical thinking behind sophisticated intrusions. Attendees gain a visceral understanding of their actual risk surface and leave better equipped to ask the right questions of their security teams.
The perimeter of a modern organization extends far beyond its network. In this technical-yet-accessible keynote, Kamkar demonstrates how everyday physical objects — access cards, key fobs, garage door openers, connected vehicles — can be compromised using inexpensive hardware and publicly available tools. He explores what this means for enterprise physical security strategy and why the convergence of digital and physical threats demands a new category of organizational thinking.
Drawing on his work exposing tracking mechanisms like Evercookie, Kamkar explores the privacy implications of modern data collection practices — and makes the case that privacy is not a compliance burden but a strategic asset. This session helps executive audiences understand the gap between what their systems actually collect and what users and regulators expect, and outlines a framework for building products and policies that earn trust rather than erode it.
Security culture is not built by policy documents and annual training — it is built by organizations that understand why attacks succeed and empower every employee to be part of the defense. Kamkar translates his research experience into a practical framework for embedding security thinking across teams, reducing the human attack surface, and positioning cybersecurity investment as a driver of business resilience rather than a cost center.
| Basic Data Protection Information | |
|---|---|
| Data controller | AURUM SPEAKERS BUREAU S.L. |
| Address | Parc Audiovisual de Catalunya 1, Oficina S11, 08225 Terrassa, Spain |
| Purposes | We will use your data to respond to your requests and deliver our services to you. |
| Marketing | We will only send you marketing correspondence if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Lawful basis | We will only process your data if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Recipients | Generally, only our members of staff who have been duly authorised may access the data that you have provided. |
| Your Rights | You have the right to know what information we hold about you, to rectify it and to erase it, as explained in the additional information available on our website. |
| Additional Information | For more information, please see “PRIVACY POLICY” on our website. |