25 ms·
Finance worker pays out $25M after video call call with deepfake CFO
- jbirer 3y agoLooks like an elaborate embezzling scheme to me.
- smeej 3y agoWhy embezzle from one company when you can steal from lots of them? This is an obvious and natural evolution of the kinds of attacks that have existed for years. It was bound to happen eventually. I think it's just sooner than people expected.
- djmips 3y agoMy feeling too. I doubt criminals actually have mastered realtime deepfake. It's plausible but on the balance it's more likely a 'plausible' excuse.
- bsdz 3y ago“(In the) multi-person video conference, it turns out that everyone [he saw] was fake,” This sounds like it required quite a bit of preparation, i.e. collecting data for each deep-faked participant including image/voice samples. If it's reaching this level of sophistication already then I suspect a new participant validation scheme is on its way for sensitive meetings.
- willsmith72 3y agothe scary part is how easy this would be to do right now, especially for a larger, higher-profile company. leadership is almost synonymous with an online presence in the form of podcasts, interviews, youtube videos, conference talks. combine that with public photo-sharing app profiles, and you're in business.
- sbarre 3y agoYeah C-suite execs are often on quarterly investor calls and those calls are made public as a matter of record aren't they?
- dist-epoch 3y ago$25 mil was on the stake. It would easily be worth it spending $1m on the perfect setup.
- irrelative 3y agoOnly if it works >4% of the time.
- jsnell 3y agoOnly if you intend to run the scam only once, or if all of the work is completely bespoke and not reusable for future attacks. That seems unlikely. I'm pretty sure there's actually a lot of economies of scale here, where the attackers' pipelines will become vastly more efficient and higher quality over time, with each attack requiring less manual work.
- escapecharacter 3y agospearphaking?
- ozr 3y agoIt's a sophisticated attack for sure, but the data collection really isn't too difficult now. A minute or two of audio is sufficient for voice, and a single good image.
- silexia 3y agoThe most likely explanation is the employee responsible here was actually the one who stole the money.
- layer8 3y agoIt seems that only the voices were deep-faked, and the video material was from genuine calls and downloaded before the attack: https://news.rthk.hk/rthk/en/component/k2/1739119-20240204.htm https://news.rthk.hk/rthk/en/component/k2/1739119-20240204.h...
- iamflimflam1 3y agoI would suggest that every CFO agrees some kind of secret challenge response with their staff and other execs.
- pliny 3y agoThe secret challenge exists and it is the phone number / email address / VC account of CFO. If CFO wants to order EMPLOYEE to send money, then EMPLOYEE should only do the action after making an outgoing call to CFO.
- makeitdouble 3y agoWhere it hurts is it can be a PITA to get hold of the CFO from the mere employee side, especially as the CFO was UK based. Basically, it was a well thought and well executed scam that perfectly fit the employee's situation.
- greenyoda 3y ago> it can be a PITA to get hold of the CFO from the mere employee side I'm guessing that someone who can authorize a $25M transaction is fairly high up in the corporate hierarchy, not that many levels away from the CFO.
- makeitdouble 3y agoFor a finance worker I actually wonder how much it means to transfer $25M. I have no idea, but I suppose moving funds from one subsidiary to another for instance wouldn't be for a few thousands only, and he's seeing money fly around day in day out. Would it feel the same as an infra engineer rebalancing a few millions of access from a cluster to another ?
- dools 3y agoThe CFO was on the call. You just say "cool I'm sending a 4 digit code to your mobile phone, read it back to me".
- monkeydust 3y agoWas expecting this to happen soon and I guess soon is now. Will Zoom, MS start to compete on participant authentication features they are probably going to add?
- DANmode 3y agoHeading in that direction https://www.microsoft.com/en-us/security/blog/2023/05/04/how-microsoft-can-help-you-go-passwordless-this-world-password-day https://www.microsoft.com/en-us/security/blog/2023/05/04/how... https://learn.microsoft.com/en-us/entra/verified-id/how-to-dnsbind https://learn.microsoft.com/en-us/entra/verified-id/how-to-d...
- smeej 3y agoMy money had been on 3-5 years, but it was definitely coming, and I guess I shouldn't be surprised it's here.
- Gustomaximus 3y ago> “(In the) multi-person video conference, it turns out that everyone [he saw] was fake,” This could be totally real, but also could one employee saying 'the CFO was on a call' and claim deepfake to make it an excuse? I guess it was a matter of time before this occurred. How long before scammers do bulk video calls to parents/grandparent pretending to be the kids saying they are in trouble and need $$$ ASAP. The even better question, is how can this be stopped or reduced and is there a new business there?
- cornholio 3y agoSeems like it can be stopped dead with standard crypto, smart cards and multifactor tokens, multiparty authorization etc. Ideally, issued by public authorities together with any other official ID, leveraging the strong security governments have already built around that process. The generic type of vulnerability referenced in the latter part of the article has sprung up after fintech tried to emulate traditional offline auth and KYC with things like scanned images of ID documents, face recognition and liveness detection. Anyone in the know could see these attacks coming miles away.
- loceng 3y agoCould you elucidate how exactly "standard crypto" would stop such a thing?
- sargun 3y agoI think the poster meant the prior meaning of the word 'crypto' -- cryptography, in which the CFO could sign and encrypt some message and then the message's authenticity could be verified.
- YetAnotherNick 3y agoHow does crypto add anything that just verifying email ID/phone number doens't provide. If you solution is to whitelist some certificates or key, you can as easily or even easier whitelist email IDs/phone number.
- makeitdouble 3y ago> Chan said the worker had grown suspicious after he received a message that was purportedly from the company’s UK-based chief financial officer. It wasn't just a fake call, and he had a paper trail of the order...at this point it's pretty hard to prevent this from happening, short of having every order double checked by some other independent entity.
- oldtownroad 3y agoit’s trivial to avoid. Do not accept instructions outside of the standard instruction channels. The only reason this scheme works is because of bad processes, bad training or a culture of fear (where employees feel compelled to comply with any demand regardless of process for fear of losing their job). If an employee routinely receives email or zoom instructions to transfer $25m without any sort of sign off then the company is completely at fault for terrible process.
- JumpCrisscross 3y ago> Do not accept instructions outside of the defined company processes Most non-enterprise companies have fairly loose wire protocols. That said, outgoing phone calls to two separate signers is a good, simple best practice.
- nikanj 3y agoThe standard instruction channels are so reliably shit, nobody bats an eye if they get an email saying ”Teams is on the fritz again, please join us on Zoom instead”
- logicchains 3y agoCorporate email clients usually have a way of marking non-internal emails, surprised this wasn't used.
- laboratorymice 3y agoDon't know the details here, but email is still very much broken, and a number of large companies, including in the financial sector, are spoofable even after checking the usual boxes.[0] [0]: https://news.ycombinator.com/item?id=37438478 https://news.ycombinator.com/item?id=37438478
- frenchman99 3y agoThis should like bad company processes all around. For a sum this high, you need more than just a video call. Get an email (if the tech team setup DMARC correctly, sending phishing from company-domain is near impossible). Talk through company chat (Slack, Teams, etc). Call a couple high ranking on their cell.
- miohtama 3y agoGood old face-to-face works. 25M is worth of a business class flight.
- smeej 3y agoIt's not the money. It's the time. Lots of companies move fast enough that a $25M deal won't wait as long as it takes to fly from HK to London.
- switch007 3y agoIf they want to do business like in the 21st century they can invest in 21st century security and polices. Otherwise get on the darn plane and do it 1970s style
- tetha 3y agoIt's one of the better ways to avoid getting scammed: Try to validate the communication in ways without relying on any information they gave you. If someone claims to be a police officer and hands you a number to call to see if they are real... don't use that number. Figure out the non-emergency number of the station they claim to be coming from independently and ask them. If a "new agent" from your bank calls you and gives you a "new number" to call them, figure out an official number of your bank and call that.
- mvc 3y agoYep. Previous scam victim here. This step would have halted the scam I fell for. Also, whenever paying new accounts, once you've independently reached the person you think you're talking to, always do a test transaction and make sure they get it before sending the rest.
- willsmith72 3y ago> Initially, the worker suspected it was a phishing email, as it talked of the need for a secret transaction to be carried out. However, the worker put aside his early doubts after the video call because other people in attendance had looked and sounded just like colleagues he recognized. this is the real problem. why oh why, after suspecting an email as phishing, would you then go on to even click ANYTHING, let alone join a video call? insanity. either stupidity or he's lying about suspecting the email. how many corporate security trainings does it take? this is just about 101. "if asked to do a secret task by a suspicious email, DONT do it"
- geraldwhen 3y ago“Secret transaction” is in the annual training of annual who handles money. That’s an immediate red flag, escalate to corporate governance officer.
- pavel_lishin 3y ago> how many corporate security trainings does it take? this is just about 101. "if asked to do a secret task by a suspicious email, DONT do it" It takes $CURRENT_NUMBER + 1. People are still, to this day, racking up thousands of dollars in iTunes gift cards on corporate cards and mailing them out, because they got a text from "the CEO". It happened at my spouse's work just last year. It'll continue happening again, forever, because to paraphrase P.T. Barnum, a sucker is hired every minute - in the probability distribution of humanity along that particular axis, there's always going to be some percentage at the bottom who'll fall for the most obvious scams. Sometimes repeatedly.
- IshKebab 3y ago> corporate security trainings Have you ever actually done corporate security training? It's very obviously 100% useless and not going to teach anyone anything. A company I worked for actually started sending test phishing campaigns which is a lot more effective, but I thought they were still pretty obvious and also it led to stupid people reporting them on Slack endlessly. Still, probably the best thing you can do.
- 3y ago
- saaaaaam 3y agoI have no idea how something like this can even happen. In a company of that size it should be actually impossible for a transaction like this to occur without clearly documented processes to ingest, review, authorise and pay transactions. I have clients where anything over even quite a low set limit (say €10k) requires multi-party authorisation - and it's very common for the person entering payments to be unable to authorise payments. That's just good practice. A payment should not be able to be queued without a PO number. If the payee is new, the bank details need to be verified by phone. Once approved as a destination account, that payee is set up in banking, and authorised by a finance clerk and someone more senior. At the point a payment is requested the PO and other details should be double checked against what is in the system. If there's a match, then the payment can be queued for authorisation. The person entering payments and the people approving payments should be entirely different - and it should be people, not a single person. When payments are entered, the payments should be reviewed by first authorisation - a finance manager, for example - and once that authorisation is conducted, depending on payment limits, another authorisation or authorisations will be carried out.
- BrandoElFollito 3y agoExactly. There are programatical barriers you cannot bypass alone. I can imagine a scan where the fake CEO gets a phone or laptop outside of the process "because CEO". This however will still be limited to generic, low value stuff handled by single people in a company. There is no way that a reasonably organized company can leak 40 MM USD.
- fallingknife 3y agoCitigroup leaked almost a billion, and it wasn't even fraud. https://www.npr.org/transcripts/1019909860 https://www.npr.org/transcripts/1019909860
- BrandoElFollito 3y agoYes, but this is due to three people trying willingly to bypass the system, and probably a shitty UI. They knew what they were doing, they just did it badly.
- nickdothutton 3y agoThere really ought to be a stronger sign of confirmed identity in business calls. Something cryptographic. Every single day I end up in business calls randomly scattered across teams, WhatsApp, FaceTime, zoom, and a half dozen other systems. Instead we get stupid cartoon avatars and the ability to put a funny backdrop behind us.
- DANmode 3y agoFor many of these "attacks", it could be thwarted as simply as opening the messages tab and seeing no prior history.
- pavel_lishin 3y agoI'm not sure if we have good enough systems in place, in terms of UX, for that to work. Imagine every C-level exec who's opened a top-urgent ticket with IT because their printer doesn't work (they forgot to plug it in/forgot it needs paper/it's not a printer, it's a paper shredder) trying to operate some form of key exchange software securely, while people capable of pulling off this sort of scam are targeting them. I don't think this is a problem that can be solved with technology.
- MichaelZuo 3y agoThis doesn’t sound correct, why can’t it be solved with sufficiently advanced technology i.e. software and devices? We already have facial verification systems in hundreds of millions of devices that are genuinely very difficult to spoof.
- pavel_lishin 3y ago> with sufficiently advanced technology Oh, you mean magic? :P
- BlueTemplar 3y agoWanna see a magic trick ? These $25M... waves hands gone !
- OfficeChad 3y ago[dead]
- mebassett 3y agoI have known two publicly traded companies that fell victim to similar sorts of scams (someone impersonating the cfo or ceo over the phone). One was defrauded out of a seven figure sum, the other got lucky and a bank involved stopped the transaction to verify again. I don't know how the first was able to keep it quiet, I only knew because I chatted with the people in question. I suspect that the deepfake angle makes it easier to admit that they were defrauded in this way. Talking about how something like this can happen in a big company is fun and all, but the scary thing is is that it is _so much easier_ to do these sorts of scams with deepfakes. Which means they will be deployed against "softer" targets, like you and me, and your parents and grandparents.
- mikkom 3y agoVC usually means venture capital(ist) so the title is very confusing.
- redsoundbanner 3y agowhat does it mean here?
- mikkom 3y ago> Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ That is the actual title of the linked article.
- mattmaroon 3y agoIt’s so strange to me when people change a perfectly good title into something worse here, but it happens so often I honestly think the site should just change the functionality.
- jacooper 3y agoThere is a character limit to be dealt with here.
- squigz 3y agoPretty sure there's plenty of room to include it.
- mattmaroon 3y agoCFO is one character longer, and if that really was the issue, which is very unlikely, I can think of 100 ways to shorten it without changing something important.
- ooterness 3y ago"Video conference"
- mattmaroon 3y agoJust because I am curious, and have not seen any software capable of fooling me in this regard, yet, what would somebody use to do this? Is this an already existing product that can create video representations of people I know so well it would fool me?
- sbarre 3y agoThere was a paper linked on here recently (last few months?) that showed off video call deepfaking using gaussian splatting, essentially using a webcam to "puppet" a very convincing 3D recreation of another person's head & shoulders in real-time.. I tried to find the link but my search-fu is not good today it seems.. I did find this, which seems related: https://blog.metaphysic.ai/the-emergence-of-full-body-gaussian-splat-deepfake-humans/ https://blog.metaphysic.ai/the-emergence-of-full-body-gaussi... There's also the fact from the article that this was an employee in Hong Kong on a video call with people supposedly in the UK, so it's also possible they took advantage of bad video quality to do this.. Get on video for the first minute or so, then, as we've all done, say "I'm going to turn off my video so my connection sounds better" etc...
- jacquesm 3y agoThis is where those 'security researchers' are helping to make such fraud easier. If you release these tools into the wild you are enabling criminals who by themselves would have no way to create these tools.
- sbarre 3y agoI don't recall them being security-related researchers though, but there are obviously security concerns, I agree.
- skriticos2 3y agoSecurity through obscurity does not work. As soon as deepfakes have proliferated on TikTok for stupid stuff, they'd inevitably be used for this kind of exploits by any adversary that is motivated enough to do a directed operation on a high value target. The researchers really just raise awareness on where things are going, but ultimately the solution will be to improve process and verify anything that has to do with money through specific internal company channels that are hard to forge - and anybody in a call like this that would not use them needs to automatically raise an alarm by procedure.
- xyst 3y agoHonestly, half the time I am interviewing random contractors around the world. I get a feeling they use OpenAI to answer questions. I have thrown out the typical “leet hacker” bullshit questions and rote memorization type stuff. Gone back to simply quizzing them on their own resume, digging into the finer details of what they did. Can’t deep fake experience, yet.
- the_duke 3y agoYep, Google/openai has become pretty common place in remote interviews. The funny thing is, I ask them to say say "I don't know" rather than the above, but they still do it... You can work around it by picking a difficult practical problem from your domain and talking through choices and their different tradeoffs.
- Slava_Propanei 3y ago[dead]
- welder 3y ago@dang can you change the title to: Finance worker pays out $25M after vid call with deepfake CFO Edit: maybe not zoom
- mintplant 3y agoIt's most expedient to email hn@ycombinator.com for things like this.
- jacquesm 3y agoWhere does it say it was Zoom?
- switch007 3y agoHoover, Walkman, Sellotape, Google, Bandaid, Kleenex…
- falseprofit 3y agoA good list of words that people make similar mistakes with…
- switch007 3y agoMistake? I’m confused. It’s not a grammatical or syntax issue. Some of those words are even in the dictionary…
- jacquesm 3y ago
- hinkley 3y agoAre we going to have to start using code phrases like in the Renaissance and in popular fiction? Don’t write a check unless you hear me mention aardvark or Mad King Ludwig.
- RobRivera 3y agoI literally thought the title meant a Venture Capitalist, not Video Call smh
- julietmatthew 3y ago[dead]
- matthewjuliet 3y ago[dead]
- diebeforei485 3y agoI think "power distance" (a cultural thing - both national culture and corporate culture) might play a role here. In some cultures, you do whatever the big boss asks you to do, regardless of procedure. (Media reporting suggests this can also be true at some US hardware tech companies).
- ladyanita22 3y agoHaving worked with Chinese people, let me tell you this is 100% accurate. It may (and probably will) happen in western countries as well, but the culture makes China, South Korea, Taiwan and Japan extremely vulnerable to this. No one I worked with was willing to refute, question or even raise any doubts if someone they perceive not at their level or, even better, below, was in the call.
- usrusr 3y agoOther countries are known for a culture of nothing ever happening without a piece of paper carrying an official-looking stamp. Those are laughably insecure, but the culture could easily be ported to public key signature. "Boss voice is only boss voice when it comes with a digitally signed transcript" shouldn't be too hard to introduce in "don't ever question your boss" cultures I think? Bosses might even enjoy the grandeur of showing off their status with an insignia-device. "Orders without proof of identity are irresponsibly bad form" could be surprisingly easy to establish.
- dotancohen 3y agoI think that you are unfamiliar with these cultures. In Japan, you would never ask the voice that sounds like the boss to prove his identity with a digitally signed transcript - even if that's a fireable offense. It is so culturally alien to them that it would never get through.
- Izkata 3y agoI think their idea is that the boss would be the one to introduce it ("Bosses might even enjoy the grandeur of showing off their status with an insignia-device.") and because of the culture it wouldn't be difficult for employees to adapt and go along with those new rules.
- thih9 3y agoWhat is the chance that a CFO gets in touch with a deepfake specialist and they split the profits? I’m not saying that this is what happened, I’m more focused on future scenarios.
- deleted 3y ago[deleted]
- willcipriano 3y agoI thought the value of these types of people are their people skills. Nobody would accuse me of great people skills and while I'd like to point to my technical acumen as the reason I can spot fakes like this easily, it's my primate brain that knows something is wrong.
- mvc 3y agoApparently the victim spotted it as a fake too. And then did what they thought was necessary to confirm the instruction.
- thih9 3y agoJust like security specialists can follow a phishing link, I'm sure employees with good people skills can be conned into sharing details with a deepfake colleague. Social engineering works because people think they could spot it.
- thih9 3y agoOr even better: have CEO & COO hold a secret emergency meeting with the CFO; after the money transfer the CEO & COO deny everything, claim they weren't there and were deepfaked.
- coding123 3y agoWouldn't only a CFO have the ability to move 25MM
- evanjrowley 3y agoA Boston-based finance worker also sent $6M to scammers back in 2023. Surely some social engineering was involved, but nothing about deepfake was mentioned: https://apnews.com/article/technology-boston-law-enforcement-2e9e3a4a9d9d5e35fd3699741df63dde https://apnews.com/article/technology-boston-law-enforcement... Deepfake was used in the 2023 MGM casino breach to convince tech support staff to do things that compromised their MFA Now we're seeing a combination of these for significantly higher gains.
- yoyoinbog 3y ago[dead]
- newhotelowner 3y agoA lot of upper midscale hotels in the USA are owned by Indians from India whose last name is Patel. Pretty much every single hotel gets a call from Mr. Patel at night asking to wire money due to an emergency. A lot of hotel employees fell for it and wire money. These employees even drill open the safe. Some even wire money from their personal account. This scam is mostly social engineering without any AI/Deepfake. It's going to be a fun time ahead for everyone.
- swyx 3y agothe patel motel cartel! https://www.nytimes.com/1999/07/04/magazine/a-patel-motel-cartel.html https://www.nytimes.com/1999/07/04/magazine/a-patel-motel-ca...
- BlueTemplar 3y agoHeh, reminds me a bit of how a South Korean cult is behind Sushi becoming popular...
- lisper 3y agoReference?
- lupusreal 3y agohttps://www.nytimes.com/interactive/2021/11/05/magazine/sushi-us.html https://www.nytimes.com/interactive/2021/11/05/magazine/sush... https://en.wikipedia.org/wiki/True_World_Foods https://en.wikipedia.org/wiki/True_World_Foods
- golergka 3y agoI thought the Norwegian fishing industry was behind it?
- kyawzazaw 3y agothat's just salmon specifically
- CaffeinatedDev 3y agoWar using AI begins :O
- bengalister 3y agoIn France there had been cases of employees wiring money convinced that they were talking to their CEO/CFO/lawyers over the phone. Many cases were due to a Franco-Israeli gang arrested in 2022/2023 that managed to make at least 38M Euros out of it. They impersonated CEOs without the help of deepfake AI. See https://www.europol.europa.eu/media-press/newsroom/news/franco-israeli-gang-behind-eur-38-million-ceo-fraud-busted https://www.europol.europa.eu/media-press/newsroom/news/fran...
- acjohnson55 3y agoThere is an entertaining podcast series on this called Persona:https://podcasts.apple.com/gb/podcast/persona-the-french-deception/id1625387454 https://podcasts.apple.com/gb/podcast/persona-the-french-dec...
- cozzyd 3y agoSpeaking of personas and apple ... I bet apple vision personas make attacks like this a lot easier if anybody ever uses them.
- DoodahMan 3y agoi reckon we're going to see this used for pump & dumps too at some point, ala a deepfake of some big pharma exec talking about acquiring some small biotech.
- noobermin 3y agoMany comments are saying how finance companies should do more authentication for large transfers and the common response for that is a few million transferred is routine in that field and authentication of transactions the size of the onr quoted in the article would be impractical. The response to that then is if 25M doesn't matter enough to verify in some way then companies shouldn't cry when it's stolen. Then losing a few million here and there which apparently isn't worth authenticating the transfer of is just the cost of business. It's either worth the extra controls or it's like snacks in the rec room, not worth worrying about.
- TacticalCoder 3y agoIt's also usually just one more call to get the stolen assets frozen. If it's already "gone", it's not really "gone" and can be clawed back. Such headlines are usually followed, a few weeks later by an headline reading not unlike this: "Three indicted in scheme involving deep-fake to steal $25m".
- aaron695 3y ago[dead]
- hnta2023 3y agoi'm not sure which i think is more likely: 1) a multiperson zoom of deep fakes fooled the worker 2) the worker was in on it as an inside man and the deep fake story is cover
- pvaldes 3y agoThis opens also the possibility to steal money and then pretend that you were fooled by AI impersonating your boss to give you orders that you can't refuse. Sending fake videos of your boss to yourself. Create a smog curtain and give the police a digital hare to chase that does not exist. Wow. Looks like the plot of a new Netflix series.
- mvc 3y agoI think there would be a good chance of getting caught if you did that. The police would be involved at this point and would definitely consider that as something to investigate before concluding the case.
- mikeyouse 3y agoIt's all about knowing the limits.. most theft like this isn't really reported / investigated by the police. Companies lose money in stupid scams and thefts all the time, it's usually just written off. $25M would obviously be investigated but $25k?
- cube00 3y agoThe old adage "follow the money" still holds, you'll be forever monitored until it shows up. It's even easier in the digital world where they don't need to park a pizza van outside your house.