Here's how crooks will use deepfakes to scam your biz
- Reference: 1664349846
- News link: https://www.theregister.co.uk/2022/09/28/trend_deepfake_video/
- Source link:
Cyber criminals are taking advantage of this easy access to resources, and using deepfakes to build on today's crime techniques, such as business email compromise (BEC), to make off with even more money, according to Trend Micro researchers. Not only that, but deepfakes are being used in web ads to make Elon Musk, security specialists, and others appear as though they are endorsing products to which they have no connection with.
"The growing appearance of deepfake attacks is significantly reshaping the threat landscape for organizations, financial institutions, celebrities, political figures, and even ordinary people," the security outfit's Vladimir Kropotov, Fyodor Yarochkin, Craig Gibson, and Stephen Hilt [1]warned in research published on Tuesday.
[2]
Specifically, corporations need to worry about deepfakes, we're told, as criminals begin using them to create fake individuals, such as job seekers to scam their way into roles, or impersonate executives on video calls to hoodwink employees into transferring company funds or data.
[3]
[4]
Over the summer, the FBI said it has received increasing numbers of complaints relating to the use of [5]deepfake videos during interviews for tech jobs that involve access to sensitive systems and information.
Once they've convinced someone to hire them, deepfake actors can use fake identities to trick unsuspecting customers or coworkers into sharing payment info, or use this network access to explore IT assets, steal corporate data, deliver ransomware or worse.
[6]
Just last month a Binance PR exec claimed crooks created a deep-fake "AI hologram" of him to [7]scam cryptocurrency projects via Zoom video calls.
"It turns out that a sophisticated hacking team used previous news interviews and TV appearances over the years to create a 'deep fake' of me," Patrick Hillmann, chief communications officer at the crypto hyper-mart, [8]claimed at the time. "Other than the 15 pounds that I gained during COVID being noticeably absent, this deep fake was refined enough to fool several highly intelligent crypto community members."
The Binance deepfake is notable as Trend Micro says the topic of how to bypass verification using deepfakes has been a hot one on underground forums since 2021. In general, many of these forums' users are looking for ways to scam online banking and digital finance verification, according to the security researchers. They explain:
It is likely that criminals interested in these services already possess copies of victims' identificatory documents, but they also need a video stream of the victims to steal or create accounts. These accounts could be used later for malicious activities like money laundering or illicit financial transactions.
Additionally, deepfake production tools are bought and sold on nefarious online souks — or available in the open on [9]GitHub — along with bots that can make deepfake video creation easier, the researchers added, citing the Telegram bot RoundDFbot as one example.
Deepfake + existing scam = more money for crooks
Trend Micro says criminals are using deepfakes for a variety of tried-and-true attack methods and scams, and the researchers expect to see more of these in the near future.
This includes messenger scams and BEC, which have [10]proven extremely profitable even without phony videos. Miscreants can use deepfakes to impersonate executives or business partners to request money transfers, thus making these scams even more believable to the targeted victims.
[11]
Also, criminals can use stolen identities in combination with deepfake videos to open new bank accounts or create government services accounts, the security researchers warn. Similarly, criminals can take over accounts that use video calls to verify identity.
"They can hijack a financial account and simply withdraw or transfer funds," Kropotov, Yarochkin, Gibson, and Hilt wrote. "Some financial institutions require online video verification to have certain features enabled in online banking applications. Obviously, such verifications could be a target of deepfake attacks as well."
While we've already seen deepfakes used in disinformation campaigns, notably related to the Russian invasion of Ukraine, these phony videos can also be used in extortion-related attacks – imagine fake "evidence" being created to force organizations to pay a ransom, the researchers note.
Trend Micro also puts Amazon's Alexa "on the target list of deepfake criminals." Alexa isn't alone, though. Any device that uses voice recognition — whether to reorder cat food or to open the door to a secure wing of a hospital, for example – could be hijacked by deepfakes.
[12]FBI warning: Crooks are using deepfake videos in interviews for remote gigs
[13]Binance exec says scammers made a 'deep fake hologram' of him to fool victims
[14]Amazon can't channel the dead, but its deepfake voices take a close second
[15]FBI: Cyber-scams cost victims $6.9b-plus worldwide in 2021
The good news is that organizations can take steps to protect themselves. Top of this list is using multi-factor authentication, which, according to the security biz, "should be standard for any authentication of sensitive or critical accounts."
Use three things to authenticate users, it advises: something the user has, something the user knows, and something the user is.
Also, train staff in what to look and listen out for when it comes to deepfake technology. "For verification of sensitive accounts (for example bank or corporate profiles), users should prioritize the use of the biometric patterns that are less exposed to the public, like irises and fingerprints," the researchers advised. ®
Get our [16]Tech Resources
[1] https://www.trendmicro.com/en_us/research/22/i/how-underground-groups-use-stolen-identities-and-deepfakes.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YzQbP1kd26xzHKpZzt@AwAAAAAY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzQbP1kd26xzHKpZzt@AwAAAAAY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzQbP1kd26xzHKpZzt@AwAAAAAY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/06/29/fbi_deepfake_job_applicant_warning/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzQbP1kd26xzHKpZzt@AwAAAAAY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/08/23/binance_deepfake_scam/
[8] https://www.binance.com/en/blog/community/scammers-created-an-ai-hologram-of-me-to-scam-unsuspecting-projects-6406050849026267209
[9] https://github.com/iperov/DeepFaceLab
[10] https://www.theregister.com/2022/05/05/fbi_cyber_scams/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzQbP1kd26xzHKpZzt@AwAAAAAY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2022/06/29/fbi_deepfake_job_applicant_warning/
[13] https://www.theregister.com/2022/08/23/binance_deepfake_scam/
[14] https://www.theregister.com/2022/06/23/amazon_alexa_voice_mimicry/
[15] https://www.theregister.com/2022/05/05/fbi_cyber_scams/
[16] https://whitepapers.theregister.com/
Hard to Understand
It's hard to believe that companies can get scammed out of money just by someone calling up and saying "transfer some money here, please". I get invoices bounced all the time because the P/O reference format is wrong, the line item description doesn't match, the delivery hasn't been matched in the system, I'm not "on the system", etc. Similarly, I've worked on installing ERP systems and no money or product moves without a purchase req., a P/O, an order acceptance, goods receipt, inspection, etc. and all the records have to match before anyone will cut a payment. None of the companies I've worked for would send money or product anywhere just cos the boss told them to or on the basis of a zoom call with a VIP client, so what sort of companies are these that just send money willy-nilly to someone who looks like someone they know?
Re: Hard to Understand
You're lucky you haven't worked for a shouty boss then. There are plenty and it's sometimes hard to spot them in advance.
Re: Hard to Understand
I've had a lot of experience shouting at SAP and it doesn't 't help*, so a shouty boss wouldn't make a difference.
*Well, it helped me, but it never got anything done
Re: Hard to Understand
It happened to us. FD received an email apparently from the MD, asking him to transfer some money, and he did it, before clocking that something was fishy. Unfortunately I never got to see the message, so I don't know how convincing it was, or what reason was given for requesting the transfer. We did get the money back, fortunately. I guess some confluence of events can cause you to drop your guard momentarily, and just forget to ask "is this legit?"
"use fake identities to trick unsuspecting customers or coworkers into sharing payment info"
How stupid are people ?
Do people really give payment details to a new hire ?
Dear Lord, maybe we do deserve an asteroid.
"...deepfakes are being used in web ads to make Elon Musk, security specialists, and others appear as though they are endorsing products..."
I would automatically give anything Elon Musk endorses a wide berth.
An easy fix?
" increasing numbers of complaints relating to the use of deepfake videos during interviews for tech jobs that involve access to sensitive systems and information "
Even in the absence of deepfake tech, you'll never know whether the person at the other end of zoom is the person you should really be talking to. So make a physical face to face interview a mandatory part of the recruitment process. I'd never engage even a commercial subcontractor without having a real physical meeting (preferably on their premises).