Trending Topics

Six deepfake lessons companies can learn from Marco Rubio’s spoof attack
US government security is in the spotlight again, after it emerged that an AI-generated impostor of secretary of state, Marco Rubio, made contact with at least three foreign ministers. But it’s not only high-profile figures such as Rubio who are being targeted by AI deepfakes – even small businesses are coming under attack from highly convincing impostors.
It’s now the work of minutes to create a convincing voice clone, using everyday AI tools that are freely available on the internet. With only a few seconds of real voice audio samples, the AI can generate sound clips that are difficult to tell apart from the real thing.
Businesses must be on guard for such attacks. Here are the lessons your company learn from the Rubio incident and others like it.
Everyone is a target
Don’t assume this is the type of thing that only happens to high-profile public figures. A survey carried out last year by forensics firm Regula claimed that almost half of businesses had been targeted by a deep fake audio or video fraud. The barriers of entry are now so low that it’s an everyday crime.
Change voicemail greetings
With only a short voice sample needed to create a convincing clone, business leaders are being advised not to make it easy for the scammers. “One of the things I recommend you do is to change your voicemail to not be your voice,” Enrique Salem, former CEO of security firm Symantec told Cybernews earlier this year.
Even ‘secure’ apps are insecure
The Rubio attackers reportedly created a Signal account displaying the name “[email protected]” to conduct their attack. Signal is often regarded as a secure app because of its end-to-end encryption, but it doesn’t prevent spoof attacks such as this. “Using an app like Signal allows you to set whatever profile name you’d like, but text messages also come with impersonation-related risks, as phone numbers can be spoofed,” said Truman Kain, senior researcher at security firm Huntress. “It’s on the person receiving the message to verify who they’re talking to.”
Train staff to be on guard
It’s important that staff are warned of the possibility of deepfake attacks. They should be particularly wary of messages asking them to do something unusual, such as transferring large sums of money or resetting passwords.
Also train staff to spot some of the telltale signs of cloned AI voices, such as long pauses or unnatural speech patterns. However, don’t rely on these alone, as AI clones are becoming ever more sophisticated. “It won’t be long before voice cloning technology advances to the point that attackers can easily place real-time phone calls (not just voice messages), impersonating the voice of their choice,” warns Kain.
Implement a call-back policy
To lower the risk of such attacks, companies should implement a call-back policy where they are required to call back employees on an approved number before sharing any sensitive information.
Focus on weak links
Your security training and policies need to be particularly focused on the staff most likely to be targeted by such attacks. Finance directors, PAs and IT staff are particularly vulnerable.
It’s not only in-house staff who are at risk, but contractors too. The recent ransomware attacks on Marks & Spencer and other British retailers were reported to have been instigated by targeting IT contractors, convincing them to reset passwords for employees. Make sure contractors are applying the same security procedures as your in-house team.
