Deepfake scams: why we can no longer trust our own eyes and ears

  • Press
AI Cybersecurity
How can you protect yourself from an AI scam? Don't give in to time pressure, verify the request through a different communication channel, and never leave critical payments to a single person. This is the advice of Michal Srnec, Director Security and Risk at Aliter Technologies.

Key takeaways

  • Attackers increasingly aren't looking for a hole in the system, but for a path to the person.

  • AI can clone a voice, create a convincing video and craft a personalized message within minutes.

  • A voice or an image may no longer serve as proof of identity.

  • The basic defense is to stop, step back and verify the information through another route.

  • A critical transaction in a company should not depend on a single person.

What is social engineering and why does AI amplify it?

Social engineering is the manipulation of a person in order to gain access, money or information. It is not a new phenomenon. However, artificial intelligence has taken its possibilities to a whole new level: it can imitate a voice, create a convincing video and prepare a personalized message within minutes.

Cyber attackers therefore don't need to break through a company's complex technological security. Increasingly, it is enough for them to convince the person on the other end. "Attackers try to get the maximum out of minimal effort. Unfortunately, in recent years it has become clear that the weakest link is the human being," says Michal Srnec.

The Arup case: a deepfake video call worth $25 million

One of the best-known examples of technology misuse is the fraud against the company Arup. During a fraudulent video call, the attackers managed to impersonate the company's leadership and persuade the finance director to transfer $25 million. The case shows that a voice or an image alone may no longer be sufficient proof of identity.

How to recognize a deepfake scam?

Three warning signs:

  1. A non-standard request, for example a payment outside the usual process.

  2. Pressure from authority, meaning a request that comes from the "boss".

  3. Time pressure, meaning a demand for immediate action.

If a boss asks for an immediate transfer from a new number or through an unusual communication channel, the right response is not obedience, but verification.

How to verify a person's identity when a request seems suspicious?

Verification through an alternative communication channel works best. "If he called me via WhatsApp, I'll try to call via MS Teams and vice versa, or I'll use a private number. That's the first thing that helps a lot," explains Michal Srnec.

Don't rely on the person's appearance on screen either, because a voice can today be cloned relatively easily and realistic videos are becoming increasingly available. It is better to confirm identity through another mechanism, for example by logging into the company system and using multi-factor authentication.

How to protect company payments from fraud?

A critical transaction should not depend on a single person. Two principles can help:

  • The four-eyes principle: a payment is approved by at least two independent people.

  • Segregation of duties: the person who enters a payment cannot also approve it.

However, security should not mean a multitude of rules that paralyze the everyday running of a company. Measures should be proportionate to the risk. Routine operations can run simply, but for above-limit amounts, new suppliers or non-standard requests, an additional check should be added.

How to protect yourself from a deepfake scam at home?

The same principle works in the household. Agree with your family on a simple phrase or password that only family members know and that you will use in case of a suspicious urgent request. Ideally, tell it to each other in person and don't share it in the digital world.

The basic defense: stop and verify

"The basic defense is not to give in to time pressure. Step back and then start verifying the information, especially if it involves an unusual request," adds Michal Srnec.

Summary in questions and answers

What is a deepfake scam?

It is a scam in which attackers use artificial intelligence to imitate the voice, face or behavior of a real person, such as a boss or a family member, in order to persuade the victim to transfer money or reveal information.

Can a voice be cloned today?

Yes. According to Michal Srnec, a voice can today be cloned relatively easily, and realistic videos are becoming increasingly available.

How can I verify that my boss is really calling me?

Contact them through a different channel than the one you were reached on. If they called via WhatsApp, call via MS Teams or on their private number. Identity can also be confirmed by logging into the company system with multi-factor authentication.

What is the four-eyes principle?

It is a rule under which a transaction is approved by at least two independent people. It reduces the risk of a fraud getting through via a single manipulated person.

How can I protect myself from a scam within the family?

Agree on a secret password known only to family members and use it for suspicious urgent requests. Tell it to each other in person and don't share it digitally.

🎬 Watch the full video interview in the Slovak language here: TREND

decor

News and articles