Blog article
Black Hat USA is a cybersecurity event held in Las Vegas, drawing security researchers, red teamers, CISOs, and practitioners from around the world.
The event includes four days of Training, a Summit Day, and a two-day main conference featuring groundbreaking Briefings, open-source tool demos in Arsenal, and a dynamic Business Hall. The main conference runs August 5-6, 2026, at Mandalay Bay. We’ll be there from the Welcome Reception on Tuesday, August 4, at 16:00.
Black Hat USA is where a lot of the industry’s most consequential research gets its first public airing.
AI is everywhere on this year’s schedule, and it should be. A large share of the Briefings this year cover AI in some form, and the same theme carries through much of the sponsor lineup as well, with many describing their own product as AI-powered or agentic in some way.
Not one Briefing session covers domain spoofing or CEO impersonation directly, and on its own, that’s not surprising. Briefings reward novel research. Domain spoofing is a mature, well-understood problem, not an emerging one.
What is harder to explain is why it keeps winning anyway. The FBI’s Internet Crime Complaint Center consistently ranks BEC among the costliest cybercrime categories it tracks each year, with reported losses of almost $3 billion in 2024.
Cybercriminals don’t need a language model to send an email that looks like it came from your CEO. The attack generally follows a familiar pattern: attackers study a company’s vendors and HR staff, learn the CEO’s tone and travel schedule, then send the fraudulent request while that executive is away and hard to reach for a quick check.
It doesn’t require malware, just a message convincing enough to get a payment approved. An unprotected domain and a believable reason to move money will do the job.
AI belongs at the center of this year’s conversation. But so does the fact that a lot of enterprises still haven’t gotten DMARC, SPF, and DKIM right, and that’s exactly what lets a spoofed email slip through instead of getting blocked.
Leave room in your schedule for the conversations you didn’t plan for, too. Some of the best insights at Black Hat happen outside the sessions and meetings already on your calendar.
If domain protection and CEO impersonation are on your radar, visit the Sendmarc team at Booth #5748 in the Business Hall. If for nothing else, you’ll enjoy the activation and walk away with a Tony’s Chocoloney.
This year, we’re asking a simple question: could your CEO’s domain be impersonated right now? Find out at our test station.
“I’m really looking forward to engaging with other security practitioners and seeing demos from many of the industry’s most advanced solutions as well as those from emerging startups.
I feel like Black Hat has the right mix of educational tracks, the expo floor, after-hours events, and team-building opportunities. This year will be different though, as I’ll be taking a few shifts at the Sendmarc booth, a first for both myself and Sendmarc!”
– Dan Levinson, Customer Success Director
“A lot can happen in a year. Last year’s Black Hat marked the beginning of a partnership I’m incredibly proud of, one that continues to gain momentum.
I’m humbled to work alongside such a talented team, and each new connection brings growth. I can’t wait to see my Sendmarc crew (who deal with far tougher travel than I do) and see our strategic partners all in one place.”
– Rob Bowker, Regional Manager: North America
“Due to the development of frontier AI models, 2026 has been a year with many predictions and pronouncements about the changing practice of cybersecurity. At Black Hat, we get to see how many of these predictions have come to bear by those on the very forefront.
One thing has become clear to me over the last year – cybersecurity is as much a community effort as it is an internal practice, and at Black Hat we get to see that community on full display.”
– Kieran Frost, Chief Operating Officer
“Looking forward to hearing directly from security leaders on how they’re thinking about domain impersonation and DMARC enforcement at scale.
We’re especially keen to talk to teams managing complex, multi-domain environments – that’s where the path to enforcement gets complicated, from SPF lookup limits to sprawling sender inventories to unclear ownership across business units, even when the end goal is the same. Come find us at Booth 5748 if you want to compare notes.”
– Karyn Strybos, Marketing Manager
“I’m looking forward to connecting with partners, customers, and cybersecurity leaders to explore how security priorities are evolving across Latin America.
Black Hat is a unique opportunity to strengthen strategic relationships, uncover new business opportunities, and accelerate the adoption of innovative cybersecurity solutions throughout the region.”
– Eliana Puente, Account Executive
The Sendmarc team will be at Black Hat USA, starting with Tuesday’s Welcome Reception and continuing in the Business Hall through Thursday, alongside over 400 exhibitors.
We talk to enterprises with the same handful of problems: senders they can’t account for, DNS records that drift as tooling changes, and boards asking for proof that communications are actually protected.
If any of these sound familiar, it’s worth a conversation about how we can help you:
This is what our team gives enterprises control over – every day. Swing by Booth #5748 for a live look at your own domain, and pick up a bar of Tony’s Chocolonely chocolate while you’re there, or set up time with us now if your show schedule is already filling up.