FBI warning: crooks are using deepfake videos in interviews for remote gigs
- Reference: 1656483409
- News link: https://www.theregister.co.uk/2022/06/29/fbi_deepfake_job_applicant_warning/
- Source link:
The deepfake videos include a video image or recording convincingly manipulated to misrepresent someone as the "applicant" for jobs that can be performed remotely. The Bureau reports the scam has been tried on jobs for developers, "database, and software-related job functions". Some of the targeted jobs required access to customers' personal information, financial data, large databases and/or proprietary information.
"In these interviews, the actions and lip movement of the person seen interviewed on-camera do not completely coordinate with the audio of the person speaking. At times, actions such as coughing, sneezing, or other auditory actions are not aligned with what is presented visually," said the FBI in a [1]public service announcement .
[2]
To lend an air of authenticity to their applications, the dodgy job seekers used stolen personal identification information. The victims whose data was stolen reported their identities being used for pre-employment background checks and more.
[3]Big Tech falls in line with Euro demands to fight bots, deepfakes, disinformation
[4]Amazon can't channel the dead, but its deepfake voices take a close second
[5]We're now truly in the era of ransomware as pure extortion without the encryption
[6]FTC urged to probe Apple, Google for enabling ‘intense system of surveillance’
The FBI's warning does not offer any information about who might be behind this scam.
But the motive is clear: if attackers can get themselves hired, they'll have a chance to loot data, deliver ransomware, or worse.
[7]
Deepfaked job applicants aren't the only threat the Bureau has recently warned talent-starved IT shops to avoid. In May it [8]warned of North Korean cyberspies posing as foreign IT workers.
In that case, it wasn't clear if the workers were spies or just wanted to collect a paycheck many times larger than citizens of the hermit kingdom could earn in other occupations. ®
Get our [9]Tech Resources
[1] https://www.ic3.gov/Media/Y2022/PSA220628
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrwiyMUl2lJWeASrlCTVRQAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2022/06/17/eu_tech_deepfakes/
[4] https://www.theregister.com/2022/06/23/amazon_alexa_voice_mimicry/
[5] https://www.theregister.com/2022/06/25/ransomware_gangs_extortion_feature/
[6] https://www.theregister.com/2022/06/27/ftc_apple_google_surveillance/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrwiyMUl2lJWeASrlCTVRQAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/05/17/fbi_korea_freelancers/
[9] https://whitepapers.theregister.com/
Re: What role does the deep fake play?
This is an article brought out by a TLA to pave the path to plausibly denying major gaffes from politicians on live television.
It wasn't really Biden sniffing that girl's hair, it was a deep-fake
"In these interviews, the actions and lip movement of the person seen interviewed on-camera do not completely coordinate with the audio of the person speaking. At times, actions such as coughing, sneezing, or other auditory actions are not aligned with what is presented visually,"
I knew it! Every supposed member of my team in our online 'Teams' meeting is a bot.
How to stop it in it's tracks.
Tell the applicant that they have to show up at the HQ in person to sign various NDA/security forms, attend a manual H&S meeting on $Topic, then get their photo taken & fingerprints scanned for use on their corporate security ID badge. The applicant will try to get out of doing anything in person for obvious reasons, at which point their ruse falls flat.
Application photos & video stills show a thirty-something $Nationality1 female, but the person claiming to be the applicant is a sixty-something $Nationality2 male? Hmmmm...
Two faced
Just tell the person to show a print out containing a face next to them. If it is deep fake it will fall apart.
What role does the deep fake play?
It is not clear exactly what the deep fake is doing here. Is it just about the ethnicity of the applicant, in that the company would not employ someone who looks Korean or whatever? Or is this pretending to be actual people who put their real identifiable photograph on the web (seriously, who does that in this day and age of scammers scraping the web for photos)? If you are giving out security information just because an applicant looks a bit like a picture on the web deep fakes are the least of your problems.
It seems like if this is a security hole then it has been created by the companies for no good reason.