Cybercriminals are increasingly turning to deepfake technology, and experts warn the threat is growing rapidly. Researchers recently reported a 39% increase in online conversations involving deepfake-as-a-service offerings. These services allow criminals to purchase or rent AI-generated audio, video, and image manipulation tools without needing advanced technical skills. Yep, that means pretty much anyone can do it, if they want to.
What once required specialized expertise can now be bought much like any other online service. Think phishing-as-a-service (PhaaS) or malware-as-a-service (MaaS). You can just head over the dark web, and you too can buy these tools…however we do not recommend it and actually, strongly discourage it.
The bad news for all of us non-cybercriminals is that the growing availability of these tools is creating serious risks for businesses and consumers alike. Criminals can clone an executive's voice to make business email compromise easy as 1-2-3 and authorize fraudulent wire transfers, create realistic video messages that appear to come from trusted leaders, or impersonate family members during emergency scams. You’ve probably heard of the scam where someone gets a call from a niece, grandchild, or someone else close claiming they need help immediately, only to find out it’s all fake. Perhaps you’ve heard of the “Mom, I lost my phone” scam? Well, these types of scams have all made the news within the past couple of years. And now, they’re multiplying faster than we can keep track.
Businesses are particularly vulnerable to deepfake-enabled social engineering attacks. A convincing voice call or video conference can be enough to trick employees into sharing sensitive information, approving payments, or granting access to corporate systems.
Individuals face similar risks. Scammers can use publicly available photos, videos, and social media content to create convincing fake messages that appear to come from friends, relatives, or public figures.
To reduce the risk, businesses can take a few steps to help. They should establish verification procedures that do not rely solely on voice or video communications. Financial transactions, account changes, and requests for sensitive information should require secondary (or more) verification through trusted channels.
Consumers should be cautious of urgent requests involving money, personal information, or account credentials, even if the request appears to come from someone they know. Consider creating family verification phrases or code words and independently confirming unusual requests through a separate communication method.
In a world where seeing and hearing are no longer reliable proof of identity; verification is becoming one of the most important security tools available. We should use it.