By Your Call Publishing | ,

Cyber Security Article - February/March 25

Are You Sure That Call Was Real?

By Alessia Widowski, Business Continuity & Compliance Consultant

In 2024, one in three people fell victim to scams involving AI-driven technologies and voice cloning. Imagine attending an urgent Zoom meeting set up by your manager, asking you to make an immediate payment to a supplier to improve business relationships. Or a vendor calls you up requesting an urgent update to their account details after a supposed data breach. Or receiving a phone call from a family member needing money. Acting in good faith on what seems like a legitimate request from people you know and trust, you comply - only to discover later that it wasn’t really them.

This is the unsettling reality of deepfakes, a threat growing rapidly and even catching large companies with advanced cybersecurity measures and trained personnel off guard.

In a world where criminals are now using advanced sophisticated AI tools to mimic voices, faces and expressions with startling accuracy, it has become easier to fool colleagues, friends and family members into believing requests for money or sensitive information are real. These scams are getting more sophisticated by day, posing serious risks for both individuals and businesses. Criminals know that people tend to follow instructions from authority figures, and they exploit employees’ trust and loyalty to gain access to sensitive information, resources or funds.

How to Spot a Deepfake

Detecting deepfakes can be challenging, but there are some common warning signs to watch out for:

  • Unnatural Facial Expressions or Eye Movements: Deepfake technology at this stage struggles with realistic eye movements and subtle facial expressions.
  • Mismatch in Voice and Lip Movements: If the audio doesn’t match the person’s lip movements precisely, or if there’s a slight delay, it could indicate a deepfake.
  • High-Pressure or Urgent Requests: Scammers often create a sense of urgency to push people into quick decisions. If a caller on video is pressuring you to act immediately, pause and verify the request through another channel. The same rule applies to emails and messages - urgency can be a major red flag!

Protecting Yourself and Your Business from Deepfakes

  • Verify Requests Through Other Channels: If you receive an urgent request, confirm it using a separate contact method - never use the same method to verify the request. Using multi-factor authentication for payments and sensitive data transactions also helps ensure the legitimacy of requests.
  • Head Movements: If you are not sure about the person on the video call, ask the person to turn their head sideways to 45 degrees. Deepfake technology struggles to maintain realism with certain angles and movements. (Be creative when asking for it, like ‘that’s an interesting book on your bookshelf’ prompting them to turn their head.) If you want to see how head-turning can affect a deepfake, there are some examples in a Metaphysics.ai blog post.
  • Trust Your Instincts: If something doesn’t feel right, don’t hesitate to take extra time to verify. Encourage your employees, colleagues and family members to do the same. Fostering a culture of caution and verification can help protect everyone from falling prey to financial loss or identify theft scams.

On a final note, always verify before you trust, and question before you obey. Staying cautious is your best defence against these evolving scams

Download Advertising Pack