New, Sinister Scam Expected to Spread in 2020

By Ray Birch

REDWOOD CITY, Calif.–A credit union employee picks up the phone. On the other end is the voice of the CEO requesting that money be transferred to a new vendor he says the credit union has just selected. The employee follows orders and makes the transfer. The funds go to a scammer. And the voice of the CEO? It wasn’t the CEO.

Feature Deep Fake low res

Scams targeting CUs aren’t new, but a new ruse is more sinister than ever, and even more difficult to discover. And one security expert believes a new type of “deepfake” crime that leverages artificial intelligence is on the verge of exploding—adding credit unions could be a prime target.

“Credit unions need to watch out because they're small and they are the types of people who can be easily fooled by this crime,” said Richard Henderson, head of global threat intelligence at Lastline. “This crime is mind-boggling and terrifying.”

As CUToday.info reported, criminals recently used artificial intelligence-based software to impersonate the voice of one company’s CEO to demand a fraudulent transfer of €220,000 ($243,000). Law enforcement said the CEO of the U.K.-based energy firm thought he was on the phone with his boss, the CEO of his company’s German parent company, who was requesting that funds be sent to a supplier in Hungary. The fake-CEO caller said the request was urgent, and he directed the executive to pay within an hour.

“This is really terrifying and really interesting at the same time,” said Henderson. “I'm amazed that cybercriminals have been able to take advantage of AI so quickly to impersonate someone’s voice. But the use of artificial intelligence and machine learning has really exploded in the past couple years and people have been able to create extensive videos of people that are fake and are hard to detect they are fake.”

Deepfake Crime

“Deepfake” is the term used for this type of spoofing, having first been coined to refer to fake videos created via AI and advanced new video technologies.  

“The voice fake is a little more difficult because we have an innate ability to detect if things aren't perfect,” he said. “It has been very difficult for the machines to get tone and inflection and syntax all right to make the voice sound authentic. But recently, researchers at universities have been able to do that with voice recordings, picking up voice samples of someone speaking and reconstructing those to make the person say pretty much anything they want.”

The deepfake crime in the U.K. is suspected to be the first such attack, said Henderson, who believes it won’t be the last, especially as the level of sophistication required declines. “It doesn't require the greatest hackers in the world to get it done. The research is out there. Any cyber-criminal worth their salt who can do a little bit of work on their own can pull this off, and it's only going to get easier for them as time goes on. Now that Pandora's Box has been opened, cybercriminals are going to try this again and again.”

The Washington Post recently reported that the U.K. attack may not even be the first time such a deepfake vocal crime has happened. According to thePost, cybersecurity firm Symantec said it has come across at least three cases of deepfake voice fraud used to trick companies into sending money to a fraudulent account.

Commercially Available Software Used

The Wall Street Journal reported the attack on the U.K. company was carried out using commercial voice-generating software. Experts have stated that crooks are either typing in responses into their computer during their conversations, with the computer then generating the boss’ voice, or the crook is speaking into a microphone to generate the computerized response.

“What this really is, is the next evolution of the business email fraud scam that's been going on for a long time,” said Henderson.

As CUToday.info has extensively reported, business email scams have been on the rise. In those cases, crooks obtain information on a company’s CEO or senior executives, as well as the business, obtain samples of company emails, and create a fake message asking an employee to move money immediately out of the business into an account controlled by the crooks.

Appearing in Videos Raises Risk

Leaders of companies who have video and audio footage publicly available are prime targets, said Henderson. The could include credit union leaders who are increasingly appearing in video messages.

Henderson_R-60_Final

Richard Henderson

“They could be speaking at conferences, doing YouTube interviews…,” he said. “So any CEO with a decent online presence is going to have to come up with new ways of dealing with this type of crime.”

Traditional cybersecurity tools designed to keep hackers off corporate networks currently can’t spot spoofed voices, although cybersecurity companies have recently developed products to detect deepfake recordings.

Henderson stressed businesses need to get ahead of the latest threat, insisting the true defense will not come from technology, but instead from the leader of the company.

“There needs to be new policies and procedures to address this—special policies and procedures when you're dealing with things like wire transfers and moving money immediately,” he said.

While companies have been training employees to be wary of  business email compromise (BEC) scams,  educating them to ward off deepfake attacks is much harder, said Henderson.

‘Messes With Realities’

“It's going to be much more difficult to combat this crime, because people want to believe they're talking to the person they think they're talking to on the phone,” Henderson said. “This messes with people’s realities. The only real way to combat this is to have the CEO himself and say I will never call you and ask for this sort of thing. If we need to move money immediately, we're going to have a particular procedure in place. It's going to have to require you calling me back. It's going to require you to send me an email directly, and it will require me to send you to a special email address just for emergency wire transfers that only a limited number of people have access to. It will require a secondary sign-off from someone else in the company, preferably the CFO. You’re going to need multiple factors of authentication before you release the money.”

The reason business email scams work well, said Henderson, is because employees want to always please the boss, not make a mistake, and are often nervous when they receive a communication from the CEO. He said that a nervous reaction from employees is more likely to happen when they receive a phone call from their president.

What CEOs Need to Do

Not only are new policies and procedures needed to combat the crime, but CEOs may need to change their approach with staff, according to Henderson.

“CEOs are going to have to come out and say they will never get angry with employees if they say no to a money transfer request that breaks procedures,” said Henderson. “That's really the only way you're going to combat this, there's no other way around it. If you are the type of CEO who is used to getting your own way, if you're the type of person that tends to get angry and upset and expect people to jump when you say jump, you need to change your perspective and approach to interacting with people. If you don't change your perspective, what's going to happen is your employee is going to be scared when they get a call from you and they're going to want to respond immediately. And when they do, it's going to cost you tens—if not hundreds—of thousands of dollars.”

Section: Standard
Word Count: 1554
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/New-Sinister-Scam-Expected-to-Spread-in-2020