Mimicking reality is the latest frontier of cybercrime and it’s a growing threat. Cyber criminals are increasingly deploying AI and machine learning to fool unsuspecting victims into believing that they’re seeing or hearing something that they’re not--and pulling off deepfake scams in the process.
Deepfakes involve manipulation of video footage or voice cloning to make a person appear to say or do something that they never said or did. Here’s a deepfake video of Facebook CEO, Mark Zuckerberg talking about how Facebook “owns” users and their data. The inaccurate claim plays on consumer concerns about data privacy on Facebook.
The hidden menace in fake video and audio scams
Aside from pushing conspiracy theories, deepfakes can also pose significant cybersecurity threats to your organization. In one of the earliest examples of this menace, cyber criminals used AI software to mimic the voice of a CEO (also known as “vishing”), demanding that an employee release $243,000 in funds to a supplier. The fraudulent transaction went through.
Deepfake technology is also troubling since it attracts a particularly smart and creative breed of cybercriminals who are keen to cover their tracks. A recent investigation by The New York Times followed a team of young engineers who use their part-time talents to develop the perfect deepfake. The endeavor, which is intended to warn the public about the dangers of such scams, found that innovative AI algorithms are making these scams more realistic and harder to detect.
Deepfakes are also ringing alarm bells in Congress. Senator Marco Rubio compared such scams to the modern equivalent of nuclear weapons.
Indeed, the disturbing rise of this cyber threat led us to include it as one of the top five cybersecurity trends for 2020 that security leaders must prepare for. But how?
Technology is only part of the solution to preventing deepfake fraud
While security performance management as a practice emphasizes due diligence around employee behavior, it can only do so much. Deepfake scams succeed by playing on a deep understanding of human behavior and what it takes to manipulate it via social engineering.
Knowledge sharing--not technology--should be the first line of defense against deepfakes. In the face of these increasingly sophisticated attacks, security leaders must step outside the security operations center (SOC) and communicate the risk of deepfake scams to business leaders across the organization. From there, they can work collaboratively to create a culture of awareness and protect the organization against risk.