News: 1694629814

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Uncle Sam warns deepfakes are coming for your brand and bank account

(2023/09/13)


Deepfakes are coming for your brand, bank accounts, and corporate IP, according to a warning from US law enforcement and cyber agencies.

In a report published on Tuesday, the NSA, the FBI, and the government's Cybersecurity and Infrastructure Security Agency (CISA) warned that threats from "synthetic media" pose a growing threat.

That is to say, criminals and spies are expected to use AI-generated material to gain access to systems by impersonating staff or hoodwink customers. Think: someone using machine-learning tools to pretend to be a CFO to transfer money out of a business account, or a CTO to make an IT support worker grant an intruder or rogue user admin privileges, or a CEO to tell customers to dump their products.

[1]

The Feds note targets for these kinds of shenanigans specifically include military, government employees, first responders using the national security systems, defense industrial base firms, and critical infrastructure owners and operators.

[2]

[3]

And "synthetic media" is just what it sounds like — fake information and communications spanning text, video, audio, and images.

As technology improves, it's getting more difficult to tell the [4]real deal from deepfake media that uses artificial intelligence and machine learning to produce highly realistic, believable messages and content.

[5]

"The most substantial threats from the abuse of synthetic media include techniques that threaten an organization's brand, impersonate leaders and financial officers, and use fraudulent communications to enable access to an organization's networks, communications, and sensitive information," Uncle Sam warned in a Cybersecurity Information Sheet

[6]PDF

.

While the Feds say that there's only "limited indication" that state-sponsored criminals are using deepfakes they caution that the increasing availability of free deep-learning tools make it easier and cheaper to mass produce fake media.

To this point, the government agencies cite the Eurasia Group's list of top risks for 2023, which puts generative AI in the [7]No. 3 spot . It's a chilling read: "Resulting technological advances in artificial intelligence (AI) will erode social trust, empower demagogues and authoritarians, and disrupt businesses and markets."

[8]Don't worry, folks. Big Tech pinky swears it'll build safe, trustworthy generative AI

[9]Pope goes fire and brimstone on the dangers of AI

[10]Ukraine busts bot farm spreading Russian infowar propaganda and fraud

[11]Deepfakes being used in 'sextortion' scams, FBI warns

The US government's concerns about synthetic media also includes disinformation operations designed to sow false information about political, social, military and economic issues, causing unrest and uncertainty.

We've seen examples of this already this year, both in America and abroad.

[12]

In May, a [13]fake image of an explosion near the Pentagon went viral after being shared by multiple verified Twitter accounts. In addition to [14]causing general confusion , the AI-generated photo also prompted a brief dip in the stock market.

A month later, several Russian TV channels and radio stations were compromised and aired a [15]deepfake video of Russian President Vladimir Putin declaring martial law. Of course, [16]phony images and social media posts are also favored by Putin's goons.

Criminals are also increasingly using fake media in attempts to defraud organizations for financial gain, according to the alert. As we said above, these typically deploy a combination of social engineering along with manipulated audio, video, or text to [17]trick employees into transferring funds to attacker-controlled bank accounts.

Beware of CEOs asking for money

The FBI and friends cite two examples from May: in one, miscreants used synthetic visual and audio media techniques to impersonate the CEO of the company, calling a product line manager over WhatsApp and claiming to be the CEO.

"The voice sounded like the CEO and the image and background used likely matched an existing image from several years before and the home background belonging to the CEO," the deepfake threat report says.

In another example, also from May, criminals used a combo of fake audio, video and text messages to impersonate a company exec, first over WhatsApp and then moving to a Teams meeting that appeared to show the executive in their office. "The connection was very poor, so the actor recommended switching to text and proceeded to urge the target to wire them money," the Feds wrote. "The target became very suspicious and terminated the communication at this point."

The Cybersecurity Information Sheet also includes several recommendations for spotting deepfakes, and not falling victim to these schemes. Safeguards include using deepfake detection and real-time verification technologies, and taking preventative measures such as making a copy of media and hashing both the original and the copy to verify an actual copy.

As always, verify the source and make sure that the message or media is coming from a reputable — and real — organization or person.

It's also a good idea to have a plan in place to respond to and minimize potential damages caused by deepfakes. Create an incident response plan that details how security and other teams should respond to a variety of these techniques, and then run tabletop exercises to rehearse the plan. ®

Get our [18]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZQIxL66409qwZ1iR@LWJKAAAAZE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQIxL66409qwZ1iR@LWJKAAAAZE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQIxL66409qwZ1iR@LWJKAAAAZE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2023/02/11/deepfake_news_anchors/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQIxL66409qwZ1iR@LWJKAAAAZE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://media.defense.gov/2023/Sep/12/2003298925/-1/-1/0/CSI-DEEPFAKE-THREATS.PDF

[7] https://www.eurasiagroup.net/live-post/top-risks-2023-3-Weapons-of-mass-disruption

[8] https://www.theregister.com/2023/09/12/nvidia_adobe_palantir_ai_safety/

[9] https://www.theregister.com/2023/08/09/pope_ai/

[10] https://www.theregister.com/2023/07/20/ukraine_busts_russian_bot_farm/

[11] https://www.theregister.com/2023/06/08/ai_deepfakes_sextortion_fbi/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQIxL66409qwZ1iR@LWJKAAAAZE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/05/31/twitter_value_decline/

[14] https://www.cnn.com/2023/05/22/tech/twitter-fake-image-pentagon-explosion/index.html

[15] https://www.independent.co.uk/news/world/europe/deepfake-putin-martial-law-state-media-b2353005.html

[16] https://www.theregister.com/2023/07/20/ukraine_busts_russian_bot_farm/

[17] https://www.theregister.com/2020/07/27/in_brief_ai/

[18] https://whitepapers.theregister.com/



Email Doesn't Need Deepfakes

Claverhouse

YOUR SHIPMENT REF..909538722XI Am Diplomat Leislie Rogers

The delivery officer appointed by the HOMELAND SECURITY DEPARTMENT chief of staff (Hon. Alejandro Mayorkas) to convey your ATM CARD to you worth US$5,800,000.00 Five Million, Eight Hundred Thousand Dollars

I want to let you know that I'm about to proceed to your home to deliver these ATM card packages to you following directives from the Homeland Security Chief Of Staff, so please reconfirm your delivery address below to avoid wrong delivery of the package.

1)Your Name

2)Your delivery address

3)Your Tel

Please reconfirm the delivery address and needed details right away so I can proceed immediately and deliver your consignment box package to you.

Re: Email Doesn't Need Deepfakes

Version 1.0

I'm relatively confident that we are secure when we get lots of deepfakes all the time, I suspect I should be worried if they weren't trying to hack us all the time - that would make me think we had been hacked.

I was writing this and got a phone call, I answered, "Ock ows it gun fur yu, cannu ear may, you're nut replayin ... har owe deaft" but they never responded so I assume that was an AI spam phone call?

Re: Email Doesn't Need Deepfakes

Throatwarbler Mangrove

While I don't disagree, more sophisticated fake messages make it easier to entrap less gullible or more perceptive people.

CEO, CFO, CTO...

heyrick

Easy to tell it's bollocks - those guys never talk to the little people, and rarely say anything that hasn't been passed through multiple levels of legal and HR. I mean, if the Boss Man could randomly open his mouth and let words fall out, he'd probably be as nutty as Musk (who doesn't appear to have babysitters handlers).

We have a passphrase because of the "Hi mum" scam

Diogenes

Because of this technology the kids & us have a phrase that we have agreed on to verify that it is us if we make a "we need monies" call. We did this at the start of last year. SWMBO has done the same with her siblings, as I have with my brother.

Both SWMBO & I have in just the last 3 weeks received a couple of very good fake calls purporting to be from our son, but without the phrase we just hang up, and then phone him just to be sure.

Bit harder to do in a corporate environment.

The door is the key.