{"id":1101,"date":"2024-11-01T13:18:38","date_gmt":"2024-11-01T19:18:38","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=1101"},"modified":"2024-11-02T09:13:27","modified_gmt":"2024-11-02T15:13:27","slug":"the-growing-threat-of-ai-impersonation-fraud-deepfakes","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/11\/01\/the-growing-threat-of-ai-impersonation-fraud-deepfakes\/","title":{"rendered":"The Growing Threat of AI Impersonation Fraud &#8211; Deepfakes"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" width=\"545\" height=\"305\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/Picture1.png\" alt=\"\" class=\"wp-image-1102 lazyload\" style=\"--smush-placeholder-width: 545px; --smush-placeholder-aspect-ratio: 545\/305;width:1200px;height:auto\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/Picture1.png 545w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/Picture1-300x168.png 300w\" data-sizes=\"(max-width: 545px) 100vw, 545px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><figcaption class=\"wp-element-caption\">iStock Photo<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine a world where anyone\u2019s voice or face can be convincingly faked, blurring the line between real and fake. This is the growing threat of deepfake technology, allowing cybercriminals to impersonate people with striking resemblance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What are Deepfakes?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deepfakes are advanced synthetic media that can convincingly imitate people using altered images, audio, and videos<sup>1<\/sup>. The term combines &#8220;deep learning&#8221; with &#8220;fake,&#8221; reflecting its reliance on complex algorithms to create lifelike impersonations<sup>2<\/sup>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Growing Risks of Deepfake Technology<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals are increasingly leveraging deepfakes to impersonate executives, employees, and clients, undermining trust in financial transactions and heightening risks of identity theft and disinformation. Imagine a junior employee on a video call with executives; a convincing deepfake of a high-ranking official could persuade even a cautious employee to comply with fraudulent requests<sup>3<\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Below are some recent incidents that highlight the risks posed by deepfake technology:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <a href=\"https:\/\/techcrunch.com\/2024\/10\/28\/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice\/\">CEO of Wiz<\/a>, a cloud security company, revealed that a deepfake impersonated him to target employees for credentials<sup>4<\/sup> (October, 2024).<\/li>\n\n\n\n<li>A <a href=\"https:\/\/www.theguardian.com\/us-news\/2024\/sep\/26\/ben-cardin-dmytro-kuleba-deepfake-ukraine\">US Senato<\/a>r was targeted by a deepfake impersonating a Ukrainian diplomat on a Zoom call, attempting election interference<sup>8<\/sup> (September 2024).<\/li>\n\n\n\n<li>An <a href=\"https:\/\/www.nytimes.com\/interactive\/2024\/08\/14\/technology\/elon-musk-ai-deepfake-scam.html\">82-year-old retiree<\/a> lost over $690,000 to a scam involving a manipulated Elon Musk video that promised quick returns on investments<sup>10<\/sup> (Aug, 2024).<\/li>\n\n\n\n<li>The cybersecurity firm, <a href=\"https:\/\/blog.knowbe4.com\/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us\">KnowBe4<\/a> fell victim to deepfakes during hiring interviews, inadvertently hiring a North Korean attacker<sup>5<\/sup> (July, 2024).<\/li>\n\n\n\n<li>The CEO of WPP, the largest ad firm in the world, was&nbsp;<a href=\"https:\/\/www.theguardian.com\/technology\/article\/2024\/may\/10\/ceo-wpp-deepfake-scam\">targeted with a deepfake attempting to solicit money<\/a>&nbsp;and personal details over virtual conferencing<sup>6<\/sup> (May, 2024).<\/li>\n\n\n\n<li>A <a href=\"https:\/\/ca.finance.yahoo.com\/news\/british-engineering-giant-arup-revealed-030558740.html\">finance worker<\/a> at Arup, a UK engineering firm, was tricked into transferring $25 million after being convinced by deepfakes impersonating the CFO and other executives during a video call<sup>7<\/sup> (May, 2024).<\/li>\n\n\n\n<li>A <a href=\"https:\/\/www.washingtonpost.com\/dc-md-va\/2024\/04\/26\/baltimore-ai-voice-audio-framing-principal\/\">school principal<\/a> in Baltimore was placed on leave after deepfake audio featured him making racist comments, which turned out to be a fabrication by a colleague<sup>9<\/sup> (April 2024).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These cases highlight a critical truth: attackers have and will continue to exploit every tool at their disposal, and AI has made it easier and cheaper.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How deepfakes are made:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Creating a deepfake is not as simple as using a photo app; it requires substantial data and computing power. A dataset of images, audio samples, or videos is first collected for the person being mimicked. Then, using the generative adversarial network (GAN), the AI learns how to replicate the person&#8217;s voice, appearance, and mannerisms<sup>11<\/sup>. Finally, this learned model is applied to generate new content, where the person appears to say or do things, they never actually did<sup>11<\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are several methods for creating deepfakes, with one of the most popular methods being the use of generative adversarial network (GAN). A GAN consists of two AI systems in a continuous competition: the generator, which creates fake content that looks real, and the discriminator, which judges whether the content is real or fake<sup>11<\/sup>. The generator uses the information it has learned to produce deepfakes that must then deceive the discriminator, which evaluates the generator&#8217;s images by comparing them to the real images<sup>11<\/sup>. As the process iterates countlessly, each round makes the fake content more and more difficult to distinguish from the real image<sup>11<\/sup>.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another method involves autoencoders, which specialize in face replacement and swapping. Deepfake applications use two autoencoders, enabling the transfer of images and movement from one image to another, resulting in realistic-looking content<sup>12<\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What are deepfakes used for<sup>2<\/sup>:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deepfake technology has a range of applications, both legitimate and malicious. Some notable uses include:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Celebrity face swaps, scams and hoaxes, automated disinformation attacks, election manipulation, identity theft and financial frauds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What kind of deepfakes exist<sup>1<\/sup>:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Textual deepfakes, video deepfakes, audio deepfakes, social media deepfakes, real-time or live deepfakes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to spot deepfakes<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While detecting deepfakes can be challenging, watch for these common signs<sup>12<\/sup>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Limited eye movement, lack of blinking, rigid expressions, and misaligned facial features.<\/li>\n\n\n\n<li>Distorted body shapes, jerky or misaligned head and body movements or disappearing body parts.<\/li>\n\n\n\n<li>Inconsistent shadows, unusual skin tones, flickering, blotchy patches, and mismatched lighting.<\/li>\n\n\n\n<li>Overly perfect hair without texture, blurred jewelry, or artifacts around the neck and face.<\/li>\n\n\n\n<li>Poor lip-syncing with speech or mismatched audio.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Combating deepfakes<\/strong><sup>11,13<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As deepfakes grow more sophisticated, several strategies are emerging to counter their misuse:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Social Media Rules<\/strong>: Platforms like Facebook, Twitter and YouTube are deploying deepfake detectors and tagging or removing manipulated content around sensitive topics.&nbsp;<\/li>\n\n\n\n<li><strong>Detection Technologies<\/strong>: AI tools like DeepTrace, Reality Defender that detect and analyze manipulated media, acting like antivirus for deepfakes.&nbsp;<\/li>\n\n\n\n<li><strong>Employee Training<\/strong>: Educating employees on recognizing deepfakes and using multi-step verification can prevent social engineering.<\/li>\n\n\n\n<li><strong>Internal Protocols<\/strong>: Implementing multi-step verification, zero trust policies, and transaction authentication helps prevent unauthorized actions.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Next steps, <\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deepfakes impact individuals, businesses, and governments alike. While strategies exist to combat them, a coordinated effort is essential. Strengthening verification processes and cybersecurity protocols, ongoing education and vigilance will be key in adapting to the evolving landscape of AI-driven fraud<sup>14<\/sup>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>&nbsp;References<\/strong><\/p>\n\n\n\n<div class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-4fc3f8e1 wp-block-group-is-layout-flex\">\n<ol class=\"wp-block-list\">\n<li>Zenarmor. Do you believe your eyes: Deepfake explained. 2024&nbsp;<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.zenarmor.com\/docs\/network-security-tutorials\/what-is-deepfake\">https:\/\/www.zenarmor.com\/docs\/network-security-tutorials\/what-is-deepfake<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">2. FORTINET. What is a deepfake?.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/deepfake\">https:\/\/www.fortinet.com\/resources\/cyberglossary\/deepfake<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">3. ClearOPS. Mitigating Deepfake Phishing in Corporate Structures: Essential Steps for AI Governance.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.clearops.io\/website-blog-post\/mitigating-deepfake-phishing-in-corporate-structures-essential-steps-for-ai-governance\">https:\/\/www.clearops.io\/website-blog-post\/mitigating-deepfake-phishing-in-corporate-structures-essential-steps-for-ai-governance<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">4. Sarah Perez. TechCrunch Security News article \u2013 Wiz CEO says company was targeted with deepfake attack that used his voice. Oct 28, 2024.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcrunch.com\/2024\/10\/28\/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice\/\">https:\/\/techcrunch.com\/2024\/10\/28\/wiz-ceo-says-company-was-targeted-with-deepfake-attack-that-used-his-voice\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5. Stu Sjouwerman, KnowBe4 \u2013 How a North Krean Fake IT Worker Tried to Infiltrate Us.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.knowbe4.com\/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us\">https:\/\/blog.knowbe4.com\/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">6. Nick Robins-Early. The Guardian. CEO of world\u2019s biggest ad firm targeted by deepfake scam. May 10, 2024&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.theguardian.com\/technology\/article\/2024\/may\/10\/ceo-wpp-deepfake-scam\">https:\/\/www.theguardian.com\/technology\/article\/2024\/may\/10\/ceo-wpp-deepfake-scam<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">7. Kathleen Magramo, CNN British engineering giant Arup revealed as $25 million deepfake scam victim. May 17, 2024&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ca.finance.yahoo.com\/news\/british-engineering-giant-arup-revealed-030558740.html\">https:\/\/ca.finance.yahoo.com\/news\/british-engineering-giant-arup-revealed-030558740.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">8. Robert Tait, CNN. US senator targeted by deepfake caller posing as Ukrainian diplomat. Sept 26, 2024.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.theguardian.com\/us-news\/2024\/sep\/26\/ben-cardin-dmytro-kuleba-deepfake-ukraine\">https:\/\/www.theguardian.com\/us-news\/2024\/sep\/26\/ben-cardin-dmytro-kuleba-deepfake-ukraine<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">9. Paul Schwartzman and Pranshu Verma. Baltimore principal\u2019s racist rant was an Ai fake. His colleague was arrested. April 26, 2024.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.washingtonpost.com\/dc-md-va\/2024\/04\/26\/baltimore-ai-voice-audio-framing-principal\/\">https:\/\/www.washingtonpost.com\/dc-md-va\/2024\/04\/26\/baltimore-ai-voice-audio-framing-principal\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">10. Stuart A. Thompson. How \u2018Deepfake Elon Musk\u2019 Became the Internet\u2019s Biggest Scammer. Aug 14, 2024&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.nytimes.com\/interactive\/2024\/08\/14\/technology\/elon-musk-ai-deepfake-scam.html\">https:\/\/www.nytimes.com\/interactive\/2024\/08\/14\/technology\/elon-musk-ai-deepfake-scam.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">11. Bart Lenaerts-Bergmans, CrowdStrike \u2013 What is a Deepfake Attack?. April 16, 2024.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.crowdstrike.com\/en-us\/cybersecurity-101\/social-engineering\/deepfake-attack\/\">https:\/\/www.crowdstrike.com\/en-us\/cybersecurity-101\/social-engineering\/deepfake-attack\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">12. FORTINET. What is a deepfake?.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/deepfake\">https:\/\/www.fortinet.com\/resources\/cyberglossary\/deepfake<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">13. Matt Seldon. AI and Advanced Tech Cybersecurity Industry News: Deepfake Technology Poses Major Threat to Financial Sector; FS-ISAC Issues Guidance. Oct 25, 2024.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.hstoday.us\/subject-matter-areas\/ai-and-advanced-tech\/deepfake-technology-poses-major-threat-to-financial-sector-fs-isac-issues-guidance\/\">https:\/\/www.hstoday.us\/subject-matter-areas\/ai-and-advanced-tech\/deepfake-technology-poses-major-threat-to-financial-sector-fs-isac-issues-guidance\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">14. Homeland Security. Increasing threat of Deepfake Identities.&nbsp; 2021&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/increasing_threats_of_deepfake_identities_0.pdf\">https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/increasing_threats_of_deepfake_identities_0.pdf<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Imagine a world where anyone\u2019s voice or face can be convincingly faked, blurring the line between real and fake. This is the growing threat of deepfake technology, allowing cybercriminals to impersonate people with striking resemblance. What are Deepfakes? Deepfakes are advanced synthetic media that can convincingly imitate people using altered images, audio, and videos1. The &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/11\/01\/the-growing-threat-of-ai-impersonation-fraud-deepfakes\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The Growing Threat of AI Impersonation Fraud &#8211; Deepfakes&#8221;<\/span><\/a><\/p>\n","protected":false},"author":688,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1101","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Cynthia Omajugho","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/cynthia-omajugho\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/688"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=1101"}],"version-history":[{"count":3,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1101\/revisions"}],"predecessor-version":[{"id":1126,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1101\/revisions\/1126"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=1101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=1101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=1101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}