Social Engineering Village

Hackfest SECTF 2026

Gather OSINT on a real Canadian company, then call it live from a soundproof booth in front of a crowd. No one gets victimized, everyone learns.

  • Oct 10 to 25OSINT phase
  • Fri Oct 30Live calls
  • Sat Oct 31Shmooze Off
Training, October 28 and 29 OSINT/Social Engineering Bootcamp Two intensive days with Shane MacDougall, SECTF organizer and two-time DEF CON black badge winner. Advanced level, in English. See the training

Registration

  1. Register for the SECTF on Eventbrite

    $25 CAD fee, refundable: you get it back when you show up and compete.

    Register for the SECTF
  2. Get a Hackfest ticket

    The SECTF takes place during Hackfest: a Hackfest ticket is also required to compete.

    Buy a ticket
  3. Email your targets

    Send an email to [email protected] with:

    • Your name or handle
    • 5 proposed target companies: they must be Canadian, and you cannot have any affiliation with any of them
    • The best email and phone number to reach you
    Email [email protected]
  4. Read the rules

    All the contest rules are below. Know them and follow them.

    See the rules

Registration fee: the $25 CAD is refunded if (and only if) a) you withdraw your application within 21 days of submitting it, or b) you show up and compete. If you do not show, or show but do not compete, the fee is not refunded and goes to the beer/food/debauchery fund for all the other contestants. No fee, no entry.

Rules

Read ALL THE RULES CAREFULLY. It is each contestant's responsibility to know and abide by all the rules. Any violation of any rule may result in instant disqualification, and may place the contestant at risk of criminal or civil prosecution.

These rules are designed to protect you. Know them and abide by them!

Phase 1

OSINT information challenge

October 10 to October 25, 2026, midnight Pacific

  • Each contestant will be sent their target company by email, with its name and URL.
  • A list of the flags to gather, with the score of each, will be provided to each contestant at the start of the competition. Each contestant has until midnight Pacific time, October 25, to gather the flags, then complete and file a report following these rules.
  • Each contestant shall gather as much information as possible using public, open source intelligence (OSINT) sources only. This includes, but is not limited to, social media, websites, message boards, etc. The source of each flag must be cited and accessible to the judges. Any cited source the judges cannot access or reach will not be considered.
  • Contestants are prohibited from calling, emailing or contacting the target company for the purpose of OSINT, with the sole exception of calling a number to confirm that it works.
  • Each contestant shall create a report based on the information gathered during this phase. The report lists all the discovered flags, as well as proposed pretexts that could be used for social engineering calls.
  • The dossier MUST contain a list of the phone numbers to be dialed. No number will be called during phase two unless it is in the dossier, or discovered during the call(s) of the competition.
  • Contestants must submit their report for review to [email protected] on or before midnight Pacific time, October 25, 2026. A late report may disqualify you, so turn in a partial report if necessary.

Phase 2

Live call phase

Friday, October 30, from 9:30

  • Phase two takes place on Friday, October 30 at the Hackfest SECTF village: introduction and rules at 9:00, first call at 9:30.
  • BRING A COPY OF ALL THE VETTED PHONE NUMBERS AND NAMES OF THE PEOPLE YOU WILL CALL INTO THE BOOTH. Once your call starts, you can only dial those numbers, or others you gather during your call(s).
  • Contestant order is drawn randomly, but time slots may also be arranged to improve the odds of reaching the target company's representatives. For example, contestants with East coast targets compete first, and those with West coast targets compete later in the day. Accommodations will be made for speakers with conflicting schedules.
  • During their time slot, each contestant is placed in a soundproof booth and given exactly 25 minutes to call their target company, and tries to capture as many flags as possible. Flags captured during this phase are worth full points.
  • The clock stops while you are on hold or waiting for someone to answer (up to 5 minutes). During this grace period, the clock only runs while you are talking to someone. If someone looks information up during a conversation, the clock keeps running. Pick numbers you know will be staffed to maximize your chances.
  • Before the contest, contestants must provide a list of all the numbers they intend to call, and any numbers they need spoofed. No calls will be made to numbers that are not in your dossier. If you learn of another number during your call, you can use it, but we cannot and will not spoof a number that was not provided in advance.
  • All phone numbers must be in Canada or the USA.
  • Each flag can only be scored once. If you gather a partial flag, for example an antivirus product but not its version number, you can make a second call to get the version.
  • At no point in the CTF may contestants say anything intended to make, or having the effect of making, the target company's representative fear for their safety or that of their loved ones or colleagues. Posing as law enforcement or government officials is illegal and not allowed.
  • Only employees of the target company may be called. This can include contract employees.
  • No harassing or obscene language will be allowed or tolerated.
  • Personal information that is not directly connected to the representative's job must not be requested or collected. This includes SIN, home address, children's names, etc.
  • The underlying idea of this contest: no one gets victimized. Social engineering skills can be demonstrated without engaging in unethical activities. The contest focuses on the skills of the contestants, not on the damage they can cause. Our goal is to raise awareness of the threat social engineering poses to organizations today. Depending on the nature of the breach, a violation of these rules earns a warning or a disqualification. A second violation means disqualification.
  • Use common sense: if something seems unethical, don't do it. If you have questions, ask a judge.

Phase 3

Shmooze Off

Saturday, October 31, from 9:30

  • All competitors from Friday move on to the Saturday runoff, at the SECTF village: introduction at 9:00, first call at 9:30.
  • Contestants call a randomly selected company. The target and flags are given to the contestant 30 minutes before their call. The contestant can use the audience to research the target, find numbers and contact names, and come up with a pretext.
  • The order of calls is chosen by rock paper scissors, random draw, or another random method agreed to by the contestants.

General rules and definitions

Flags
A custom list of specific bits of information that you have to discover during the information gathering phase and during your phone calls. The judging panel creates the list, and points are awarded for each item correctly found (and documented). The list comes with your information packet if you are selected to compete.
Scoring
A detailed scoring sheet is provided to all contestants. In general: half a point for each flag in the written report, plus the report quality score. Each flag captured during the call phase counts as a full point. During the Shmooze Off, each flag counts as one point. The overall winner is the contestant with the most points.
Registration fee
To prevent no-shows, all selected contestants must pay a fully refundable $25 deposit (the Eventbrite registration fee) to compete. The deposit is refunded when the contestant shows up at their time slot. Standby positions are held to replace no-shows, but standby contestants are not guaranteed a slot. Once notified of their selection, a contestant has 72 hours to pay the deposit, or they will be replaced by another contestant.

Village schedule

Subject to change. Social Engineering CTF room (308AB).

See the full Hackfest schedule

Friday October 30

Day 1: live calls

  1. 9:00

    Introduction and rules

  2. 9:15

    Call slot draw

  3. 9:30

    Contestant #1

  4. 10:15

    Contestant #2

  5. 11:00

    Contestant #3

  6. 12:00

    Talk FR 20 min

    "Level up" ta vie avec l'ingénierie sociale

    CynQuébec

    Manipulators' tactics, turned to make your life easier: spot the pushy seller, the scammer building your trust, and the small talk that isn't sincere.

    Full talk details
  7. 12:30

    Lunch break

  8. 13:00

    Contestant #4

  9. 13:45

    Contestant #5

  10. 14:30

    Contestant #6

  11. 15:15

    Contestant #7

  12. 16:00

    Contestant #8

  13. 16:45

    Contestant #9

  14. 17:30

    Contestant #10

  15. 18:00

    End of day 1

Saturday October 31

Day 2: Shmooze Off

  1. 9:00

    Introduction, review and day 2 call rules

  2. 9:15

    Call slot draw

  3. 9:30

    Contestant #1

  4. 10:30

    Talk EN 50 min

    Scammers Keep Winning: Why Humans and AI Fall for the Same Hustles

    Alex Kasper

    Ancient cons still work, on humans and AI agents alike. Using real attack recordings, a practical way to dissect an attack by what it wants you to believe and do, not by how it looks.

    Full talk details
  5. 11:30

    Contestant #2

  6. 12:15

    Lunch break

  7. 13:00

    Talk FR 50 min

    Persona Non Grata : Investigation OSINT d'une opération d'influence IA. De la fausse journaliste au wallet de crypto !

    Nadia Vigneault

    Katarina Vogel, a Brussels journalist with 12,400 followers, does not exist. The full OSINT investigation of an AI influence operation, from a Midjourney avatar to a crypto wallet tied to a sanctioned address, with every tool shown live.

    Full talk details
  8. 14:00

    Contestant #3

  9. 15:00

    Contestant #4

  10. 16:30

    Closing comments

  11. 17:40

    Closing ceremony and prizes

Past results

What real Canadian companies told our contestants over the phone.

2024

Some slight improvements, still far too much information given away

Targets

  • Quebec Ministry of Cybersecurity (MCN)
  • Sobeys
  • Bombardier
  • Quebecor
  • IKEA
  • CN
  • Best Buy

Statistics

  • 100%gave detailed information about their email client
  • 90%disclosed information about badges, security cameras or access control systems
  • 90%shared personal information and their work history with the company
  • 78%gave their operating system version, and 45% the exact service pack
  • 78%disclosed information about their Wi-Fi
  • 67%gave detailed information about their web browser
  • 45%visited a URL provided by their caller
  • 25%gave the location of their CCTV cameras

All the firewalls in the world are useless when someone can just call up your employees and get the keys to the kingdom. This year we literally had people opening up their task managers for the hackers.

Patrick Mathieu, Hackfest organizer

2023

Every target gave away information useful for a remote or on-site attack

Targets

  • CIMA+
  • Société de transport de Montréal
  • Princess Auto
  • Walmart
  • Omni Hotels
  • and more

Statistics

  • 100%disclosed information about their Wi-Fi
  • 100%disclosed their secure shredding provider and pickup schedule
  • 100%gave detailed information about their email client
  • 100%shared personal information and their work history with the company
  • 83%visited a URL provided by their caller
  • 83%gave their operating system and service pack version
  • 83%gave detailed information about their web browser
  • 83%gave detailed information about the internal network
  • 50%disclosed information about badges, security cameras or access control systems

All the firewalls and proxies in the world are useless when I can simply call up a company and get an employee to spill the beans. There's not even a log entry left after you've made the call.

Shane MacDougall, contest organizer

2019

321 calls over two days, 12.5 hours on the phone

Targets

  • 3M
  • Loblaw
  • CN
  • Irving Oil
  • L'Oréal
  • Ceridian

Statistics

  • 66%of companies revealed detailed information: operating system, email client version, antivirus, web browser, USB blocking (87.5% in 2017)
  • 100%of targets gave details about their video surveillance systems (63% in 2017)
  • 50%of companies shut the callers down
  • Some gave information after saying they were concerned

2018

Targets

  • Hydro-Québec
  • Bell Canada
  • National Bank of Canada
  • Bank of Montreal
  • Shell Canada
  • CN
  • Metro Inc.
  • Télé-Québec

Statistics

  • 100%gave their operating system and service pack version
  • 88%gave detailed information about their web browser
  • 75%visited a URL provided by their caller
  • 75%disclosed information about their Wi-Fi
  • 75%gave detailed information about the internal network
  • 75%shared personal information and their work history with the company
  • 63%disclosed their secure shredding provider and pickup schedule
  • 63%gave detailed information about their email client

2017

First edition

Marco Estrela (Gardien Virtuel) took first place with the most flags.

Is your organization listed above? For more detailed results, email [email protected].

All CTFs