Deepfakes as Corporate Espionage Tool

Categories:

It’s late afternoon. You’re in a meeting, half-listening to a video call, when, all of a sudden, the CFO pops up on screen.

That’s unexpected since you had no planned meetings. What’s going on?

And as you two are having a proper conversation, you can’t help but think that something’s off. Her face looks the same, her voice sounds the same.

But still, you can’t shake the feeling that something’s off.

There’s an urgency in the way she’s acting, plus she’s asking you to forward some sensitive files to an external partner you’ve never heard of.

And then she’s suddenly asking for you to sign off on a quick payment. It all sounds, to say the least, strange.

But regardless, nothing about this request seems overly unusual (nothing she hasn’t asked you before, nothing you haven’t done before), so you do as instructed.

Except… that wasn’t her in the video. 

This is the reality of deepfakes in business today. It was all fun and games when deepfakes were used to create trendy memes on TikTok, but scammers quickly caught up and tinkered with innovative ways of scamming businesses out of money.

Corporate security no longer has to worry only about weak passwords, and this is quite a few steps above that.

Deception has gone digital, and the question is no longer whether a company will see a deepfake attempt… but when. 

Deepfakes and Corporate Espionage

A PowerPoint to video converter is harmless enough in a workplace. Well, not really. 

A malicious attacker can exploit all kinds of technologies, including this one, and use them for deepfakes to manipulate files and even executive messages.

The scariest thing of all is that corporate espionage is easier than ever now. Nobody needs to break into a secured system; they need to fool people into believing what they see and hear.

The entry point is trust, not your password.

Actual Tactics Hackers Use with Deepfakes

Deepfakes are already in use, and criminals are no longer bothering with traditional hacking techniques as much.

They’re turning to AI so they can imitate people and create convincing, but 100% fake content.

Below are some of the most common ways deepfakes are being used against businesses today. 

Impersonating Executives (in Video Calls)

This is one of the most alarming uses of deepfakes – the creation of real-time avatars that look and sound like company executives. 

Scammers (criminals) are able to join a video call and pretend they’re in a C-suite role (executive position), which will deter the employee from questioning any requests that are being made.

And why would they; it’s not like they would if a scam wasn’t involved, right?

But the issue here is that the staff member might wire millions after a ‘regular meeting’ with a completely fake executive giving them ‘urgent’ instructions.

The executive looked like the real deal, they sounded like the real person, so from the employees’ perspective, everything looked legit – even though they were speaking with an AI-generated avatar.

Manipulating Audio (next-level Fake Emails)

People often think that deepfakes are all about visuals (video). But that’s not really true. In fact, audio is likely the worst of the two, because there’s less that could go wrong from the scammers’ perspective, making them even more effective.

These aren’t called deepfakes, but rather it’s commonly known as voice cloning.

Just imagine, you’re at work and you get a voicemail from your boss asking you to confirm a payment or share confidential information. Except, even though it sounded EXACTLY like your boss, it wasn’t your boss. 

Or, let’s take it a step further – you get a call. And you have a proper back-and-forth conversation with your boss. A usual Tuesday, as they’d say, right? Well, turns out, you’ve just been scammed.

Your boss never called you, but rather you spoke with someone who’s likely on the other side of the planet who used AI to fake their voice into sounding like that of your boss, and it all happened in real-time.

Now pair this with a basic fraudulent email. You’ll see the cloned audio as proof. The combination of traditional BEC with AI-generated audio is already being used a lot, so be aware.

Social Engineering via Training Materials

Don’t think that deepfakes are just about using ‘fake executives’ to get you. Some of them look like nothing more than ‘ordinary training’ or the ‘usual compliance videos’ that are sent to employees on a regular basis. 

While they look legit, they contain harmful instructions or embedded malware (in links; don’t click anything if you aren’t sure).

Employees (usually) trust the content because they have no obvious reason not to, which means they’re likely to click on a (potentially) dangerous or malicious link or follow steps that can compromise the entire system.

This type of social engineering works really well, and it’s not hard to see why.

It doesn’t raise any red flags right away because the fake looks like your ordinary company business.

How to Protect Your Business from Deepfake Espionage

The real challenge when battling deepfakes in corporate espionage is in building a solid (and reliable) defense against them.

And it’s not one single tool or one single policy, but a mix of smart checks and better habits. Of course, a little healthy doubt will help, too. 

Start with stronger authentication. You can’t have a payment or sensitive information go through based on one call or message because that’s like asking for trouble.

Always add extra steps, like multi-factor authentication, so that one fake video can’t cause an expensive mistake easily. 

At the same time, think about implementing new software. Modern tools are getting better at spotting manipulated video and audio.

Sure, at the moment they aren’t perfect, but regardless, they’re useful. Until they get better, think of them as an extra roadblock the attacker has to go through.

Another extremely important factor to think about is training.

Every employee (because any one employee can be targeted) needs to be aware of all the advanced deepfake (and similar) scams, and they have to know how to recognize them and what to do if they encounter one.

Awareness is a key determining ingredient in scam prevention.

If they know that (almost) everything can be faked, employees will be more inclined to double-check a request before they act on it.

Conclusion

Anyone who says deepfakes aren’t scary as heck is either lying or doesn’t know enough about them.

Luckily, as advanced as deepfakes have become, businesses don’t have to sit there and wait for a catastrophe to happen.

If a company can learn to treat deepfakes the same way they treat phishing emails or malware, they’re already one step ahead. 

The key is to stay curious and careful, and a tiny bit skeptical.

Trending News

Related Stories