He Disguised Himself as a Homeless Person to Test a Company’s Cybersecurity. Tomáš Volný Describes the Most Common Hacker Attacks
August 18, 2026 | 31-minute listen
Companies invest in firewalls, antivirus software, and modern security systems, yet attackers still regularly manage to break in. According to Tomáš Volný, Head of the Security Operations Center at axelum, technology is not the biggest threat.
“The most common weakness in companies is people,” he says in the Business Club podcast. According to Volný, phishing emails and phone calls in which attackers impersonate, for example, IT staff remain among the most effective ways to gain access to corporate systems.
Volný looks at cybersecurity from both sides of the fence. In the past, he worked as an ethical hacker, testing the security of banks and other organizations. His work included “red team” operations, in which the team attempted to break into companies using the same methods as real attackers. He admits that this sometimes required unconventional approaches.
One of them involved disguising himself as a homeless person so that, as part of a security test, he could search through company waste and gather information about suppliers or internal processes. “I even had a perfume that actually smelled bad so that no one would come near me,” Volný recalls. According to him, companies often imagine a hacker as someone sitting in a basement, without considering that the person they pass in the hallway may not be supposed to be there at all.
Hackers Can Remain in a System for Weeks
According to Volný, even modern security tools are not a cure-all. Many companies invest in attack detection systems but configure them incorrectly or fail to maintain them after deployment. The result is either a flood of false alerts or, conversely, a real attack going unnoticed. “When real hackers get in, they often remain undetected for weeks and can do whatever they want,” Volný warns. He believes companies should continuously improve their security and regularly test it through simulated attacks.
Artificial intelligence is also bringing significant changes. According to Volný, both defenders and attackers are already using AI. Hackers use it to create more convincing phishing campaigns or identify system weaknesses more quickly, while security teams use AI for automation and faster incident analysis. However, he warns that companies often adopt AI too hastily. For example, if they use generative AI to develop applications without sufficient oversight or enter sensitive internal data into AI tools, they may inadvertently create new security risks.