The Register Home Page

back to article Nearly half of businesses suffered deepfaked phone calls against staff

A survey of cybersecurity bosses has shown that 62 percent reported attacks on their staff using AI over the last year, either by the use of prompt injection attacks or faking out their systems using phony audio or video generated by AI. The most common attack vector is deepfake audio calls against staff, with 44 percent of …

  1. MachDiamond Silver badge

    It used to be..

    ...... video, or it didn't happen. Now it's going to be "IRL" or it's deepfake.

    The Backyard Starship series has a trope where people disbelieve that aliens have arrived on Earth. It's all AI slop and disinformation or some sort of viral marketing thing that will turn out to be for some game, movie or useless thing.

  2. Pascal Monett Silver badge
    Thumb Down

    Something confuses me

    The title says nearly half of businesses, but then it starts by saying :

    "A survey of cybersecurity bosses has shown that 62 percent reported attacks on their staff using AI over the last year "

    Seems to me that that means it's not half of businesses, but half of cybersecurity businesses, which is not the same thing.

    Also, if 40%+ of all businesses had been attacked, I think we would have heard of it before this survey.

    That title is misleading clickbait.

  3. Anonymous Coward
    Anonymous Coward

    How to be immune to prompt injection attacks

    "either by the use of prompt injection attacks or faking out their systems using phony audio or video generated by AI"

    My systems and processes are immune to prompt injection attacks - because I do actual work, not expect Artificial Idiocy to do it for me.

  4. teebie

    Prompt injection attacks aren't attacks using AI, they are attacks against AI.

  5. MachDiamond Silver badge

    AI social engineering

    In a big company, which makes the best sort of target, not that many people will recognized the voice of the C-level execs unless those execs do a lot of presentations. There's also the question of why somebody 8 levels down on the org chart would get a direct call rather than instruction/requests coming down the chain and communicated to them via a boss they know. Companies will need to start doing better communications so any requests for information or certain information will not come from out of the blue. Somebody would need to get a call and respond to an email they already have to send information to the requester. Again, most staff won't have the CEO's email address used for sensitive business so they'd be sending the info to their direct boss perhaps with a call beforehand from the phone number they already have. If they call their boss and tell them they are ready to send the information and the boss says "What?", an intrusion can be stopped. Text is right out and should never be used for anything sensitive.

    If email accounts and phone numbers have been hijacked, the company will be in for a rough week and should have had a more proactive in-house IT department.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like