Cyber executive fraud scams are a longstanding issue prevalent in various sectors around the globe. Historically, these scams have leveraged an executive’s hacked email account, or an account appearing to be from them, to imitate the executive and request employees to transfer large amounts of money into a fraudster’s bank account. Over time, these scams have become increasingly sophisticated and costly, often involving detailed scrutiny of an executive’s emails, identification of ongoing projects, crafting emails sounding identical to the executive’s mannerisms, and careful calculation of the executive’s likelihood of availability.
On Law.com, it is reported that these frauds have now evolved by making use of deep fake videocalls featuring an AI-generated video of multi-national company’s CFO and co-workers. In a recent instance, a deep fake video convinced an employee of the HK branch to make 15 transfers totaling HK$200M (approximately US$25M) into five local HK bank accounts. The deep fake, seemingly a recording, was not capable of interaction or responding to questions and had limited head movements. Reportedly, a live hacker orchestrated the scam from behind the scenes, manipulating the deepfake to instruct the employee to make the transfers.
This incident underscores the urgent need for increased education and intervention measures within corporations to avoid such scams. As technology continues to evolve, our understanding of it and our defense strategies must also improve accordingly.