Skip to content
#Security

Banking Cybersecurity: Battling DeepFakes & AI-powered Scammers - George Proorocu - at NDC Security in Oslo, Norway

#Security #Software #AI

Interesting. speech George from the Dutch bank ING about security in the age of deepfakes and AI, which can be used by scammers. Geord is considering 4 script:

  • C-level impersnation When fraudsters try to impersonate the top manager of the company and then ask to transfer money to a certain account. By the way, this type of attack has real ones. examples
  • Audio deepfakes When scammers call people and speak in the voice of their children, acquaintances or parents and ask to transfer money. The effectiveness of the attack is due to the fact that we, hearing a familiar voice, as well as personal information, believe that something serious has happened and are ready to follow the request of a loved one. - Deepfake interviews An example of an attack, when your engineer is interviewed, he is sent an offer, he opens it on a working computer. (stupidly). But it turns out that all this was fake and all the interviews were conducted by scammers who wanted to get into your network. An interesting vector of attack, but deepfake interviews are now used and vice versa - an interview is conducted by one person with a fake video of another person, and the one whose face was pulled over by the interviewed cool engineer goes to work. In the end, if it's done for the sake of pay, it's half the trouble, and if it's done to access the company's systems? - Investment scam Deepfakes in videos with famous people who advertise any scam. Here the fraud is that these people clearly would not advertise this scam, but a little help AI and further advertising is ready:)

Some of these examples are accompanied by a demo, where you can see how easily and simply with the help of open soruce tools you can put on someone else’s face and use it to call or pin someone else’s voice to the audio stream and continue to engage in phone scam. Technology has reached such a level that It is important to be careful not to trust calls that seem suspicious. It is necessary to be aware of possible frauds and that the picture and sound, especially when an incoming call, are not such strong guarantees and sometimes it is worth resetting the call and calling back your friend from the number from your notebook and checking whether he communicated with you before. Banks have anti-fraud systems and payment or transfer can be blocked if the bank seems suspicious, but this is not accurate.

P.S. George showed what deepfakes looked like a year or a year and a half ago and what they look like now and it's heaven and earth. If before there were sometimes glitches like in the Matrix, for example, when rotating the head, now even this is handled well. So this vector of attack is becoming more and more real.

#Security #Software #AI