Osric Chau
Actor, Producer & Founder | Supernatural & DC Arrowverse | Fandom, Representation & the Future of Storytelling
World-Renowned Security Researcher & Hacker | Inventor of Evercookie & Samy XSS Worm | Privacy, Cybersecurity & Hardware Expert
Samy Kamkar is one of the world's most recognized security researchers — a self-taught hacker whose creations exposed critical flaws in global systems, from the most viral XSS worm in history to tools that track vehicles and clone key fobs. His talks give technical and executive audiences alike a rare inside view of how real-world attacks are built and how to design systems resilient enough to withstand them.
Want to book Samy Kamkar as a speaker for your event? Please provide the info below and we’ll get in touch within 24h:
Samy Kamkar is one of the most influential cybersecurity researchers in the world — a self-taught hacker, entrepreneur, and privacy advocate whose work has exposed fundamental vulnerabilities in systems most people assume are secure. From automobiles to key fobs, from corporate networks to government infrastructure, Kamkar’s research has repeatedly demonstrated that the attack surface of modern life is far larger than organizations realize, and that understanding how adversaries think is the most powerful defense available.
Cybersecurity speaker Samy Kamkar first gained global attention in 2005 when he created the Samy worm — the fastest-spreading virus in internet history, which infected over one million MySpace accounts in under 24 hours by exploiting a cross-site scripting vulnerability. What made the event remarkable was not just its scale, but what it revealed: major platforms were protecting users against threats that no longer represented the cutting edge of attack methodology. Kamkar was 19 years old. The incident led to his cooperation with federal authorities and ultimately redirected his talent toward building safer systems for organizations worldwide.
In the years that followed, Kamkar engineered a series of landmark security demonstrations that became required reading in cybersecurity circles. He created Evercookie, a JavaScript API that showed how websites could track users even after cookies were deleted — spurring widespread regulatory and industry debate about digital privacy. He built SkyJack, a drone capable of autonomously hijacking other drones mid-flight. He developed tools demonstrating how key fobs for luxury vehicles could be cloned in seconds, how garage door openers could be compromised with a circuit board the size of a credit card, and how location data could be extracted from smartphones without user consent.
Kamkar is the co-founder of Openpath Security, a frictionless enterprise access control company acquired by Motorola Solutions, and has served as a security advisor to companies across the technology, financial services, and defense sectors. His work sits at the intersection of offensive security research, hardware hacking, and privacy policy — making him one of the few voices who can speak credibly to both technical teams and C-suite audiences about what real-world threats look like before they become breaches.
As a speaker, Samy Kamkar brings to the stage something few cybersecurity professionals can offer: the perspective of someone who has built the attacks, not just defended against them. His sessions demystify how sophisticated intrusions actually work — from social engineering and credential theft to hardware exploits and supply chain risks — and translate that knowledge into actionable security culture for organizations at any level of technical maturity. Senior audiences leave with a fundamentally different understanding of their risk surface and a clearer framework for prioritizing investment in resilience.
Most organizations invest in cybersecurity without understanding how adversaries actually operate. In this session, Kamkar walks audiences through the real mechanics of high-profile attacks — from the Samy XSS worm to drone hijacking to vehicle key fob cloning — using his own work as a lens to expose the creative, methodical thinking behind sophisticated intrusions. Attendees gain a visceral understanding of their actual risk surface and leave better equipped to ask the right questions of their security teams.
The perimeter of a modern organization extends far beyond its network. In this technical-yet-accessible keynote, Kamkar demonstrates how everyday physical objects — access cards, key fobs, garage door openers, connected vehicles — can be compromised using inexpensive hardware and publicly available tools. He explores what this means for enterprise physical security strategy and why the convergence of digital and physical threats demands a new category of organizational thinking.
Drawing on his work exposing tracking mechanisms like Evercookie, Kamkar explores the privacy implications of modern data collection practices — and makes the case that privacy is not a compliance burden but a strategic asset. This session helps executive audiences understand the gap between what their systems actually collect and what users and regulators expect, and outlines a framework for building products and policies that earn trust rather than erode it.
Security culture is not built by policy documents and annual training — it is built by organizations that understand why attacks succeed and empower every employee to be part of the defense. Kamkar translates his research experience into a practical framework for embedding security thinking across teams, reducing the human attack surface, and positioning cybersecurity investment as a driver of business resilience rather than a cost center.
| Basic Data Protection Information | |
|---|---|
| Data controller | AURUM SPEAKERS BUREAU S.L. |
| Address | Parc Audiovisual de Catalunya 1, Oficina S11, 08225 Terrassa, Spain |
| Purposes | We will use your data to respond to your requests and deliver our services to you. |
| Marketing | We will only send you marketing correspondence if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Lawful basis | We will only process your data if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Recipients | Generally, only our members of staff who have been duly authorised may access the data that you have provided. |
| Your Rights | You have the right to know what information we hold about you, to rectify it and to erase it, as explained in the additional information available on our website. |
| Additional Information | For more information, please see “PRIVACY POLICY” on our website. |