Generative AI makes it easy to create realistic fake voices, faces and videos. Attackers use them.
Threats
- Voice cloning fraud: calls impersonating executives or relatives requesting urgent payments.
- Video call impersonation: fake participants in meetings.
- Identity fraud: synthetic faces and documents defeating onboarding checks.
- Disinformation: fake statements by public figures.
- Harassment: non-consensual synthetic imagery.
Organisational Defences
- Verification procedures: confirm payment and sensitive requests through a separate, known channel, regardless of how convincing the request seems.
- Code words or call-backs for high-risk requests.
- Training: make staff aware that voices and video can be faked.
- Liveness and document checks for identity verification.
Detection
Detection tools exist, but attackers adapt; detection alone isn't reliable. Process controls matter more.
Provenance
Content credentials and watermarking standards help establish where media came from. Adoption is growing but incomplete.
Response
Have a plan for responding to deepfakes of your executives or brand, including takedown requests and communication.