3 ms·
This article is about the retail version of this kind of fraud. Impersonating CEOs is a thing, and the dollar amounts are much larger. The attackers created AI
by Animats 3mo ago
This article is about the retail version of this kind of fraud.
Impersonating CEOs is a thing, and the dollar amounts are much larger.
The attackers created AI-generated video and audio replicas of the CFO and other executives of the global engineering firm. These deepfakes were deployed in a live video call – not as a pre-recorded video, but as a real-time conference with multiple participants. The finance employee saw and heard his superiors in what appeared to be a normal conference situation. The instructions came through clearly and consistently. Urgency was created by framing the situation as a supposed corporate acquisition. Within a single session, he approved 15 individual transfers to various accounts in Hong Kong.[1] That fraud yielded US$25 million.
[1] https://www.securitytoday.de/en/2026/04/04/deepfake-attacks-c-suite-ai-voices-ceo-fraud/ https://www.securitytoday.de/en/2026/04/04/deepfake-attacks-...
- dredmorbius 3mo agoThe possible silver lining of enterprise-scale fraud is that it might be the pain which finally pushes telephony / voice comms to adopt true call-level authentication and security. This need not be a centralised security / authentication / identification system, but the protocols must be standardised and near-universally applied. If these rely on some hardware token (YubiKey, NFC ring, RSA keyfob OTP, or even a smartphone's native ID features). The other side of this is that networks and carriers who transact largely fraudulent traffic must be penalised for this. I'd like to see both financial and technical penalities, e.g., ruinous fines, with a sufficiently large balance disqualifying the carrier from interconnect rights, and the right for terminating / bridging carriers to reject traffic in proportion to the level of malicious traffic logged. (This also implies some distributed facility for monitoring traffic from various comms networks and sharing that information with carriers and other security provisioning parties.) A worse outcome would be a two-tiered system in which large enterprises have access to reasonably fraud-free comms, and the rest of the world does not.