< ciso
brief />
Tag Banner

All news with #deepfake fraud tag

106 articles

AI-Powered OSINT Raises Risk for Everyday Users

🛡️ AI is accelerating open-source intelligence gathering, lowering barriers for fraudsters to perform reconnaissance, generate malware, and exploit vulnerabilities. This makes social engineering and deepfake-enabled scams more scalable and convincing, as models can collate images, videos, and personal details at machine speed. Individuals should limit public exposure, review privacy settings, and use strong authentication to mitigate risks.
read more →

Interpol: AI now drives majority of African cybercrime

🔍 Interpol reports that AI-driven cybercrime accounted for 55% of all reported digital crime in Africa in its African Cyberthreat Assessment Report 2026. The report, compiled from data provided by 36 member countries, links AI-powered scams, social engineering and credential harvesting to a rise in losses from $192m in 2024 to $484m in 2025. It highlights threats such as AI-enabled deepfake sextortion, sophisticated BEC campaigns, AI-driven ransomware, and the growth of Cybercrime-as-a-Service platforms.
read more →

Why silent phone calls are a growing threat

📞 Silent phone calls — a brief ring followed by muted silence — are increasingly common and can come from benign sources like misconfigured devices or overloaded call centers as well as robocallers, AI dialers, debt collectors, stalkers, and outright scammers. These calls are often used to verify active numbers, harvest short voice samples, or test lines before follow-up contact. While a single silent ring rarely causes direct harm, repeated interactions can enable voice deepfakes and social-engineering attacks. The article explains motives, risks, and practical steps to reduce exposure.
read more →

Why screenshots can no longer be trusted proof

🛡️ Screenshots are merely images of what appeared on a screen and can be easily fabricated or altered. They may provide context but do not reliably prove who created the content or whether an underlying transaction actually occurred. Consumers and businesses should treat screenshots as supporting material only and seek original records, transaction references, or verification from the issuing service. Organizations must update verification processes to avoid fraud, operational costs, and reputational or regulatory harm.
read more →

FBI warns of deepfake videos used in IC3 scam

🛡️ The FBI has issued an IC3 public service announcement warning that scammers are escalating a long-running impersonation scheme by deploying deepfake videos of senior FBI officials and spoofed IC3 websites to re-defraud previous victims. Fraudsters combine social media impersonation, AI-generated video and lookalike complaint portals to harvest further data and payments. IC3 stressed it does not communicate via social platforms or request payment, and urged users to verify .gov domains.
read more →

Verification Step Emerges as New ATO Attack Surface

🛡️ Passkeys and passwordless flows are reducing credential stuffing, but attackers now target identity verification and recovery paths such as magic links, step-up flows, and re-enrollment. Generative AI has made impersonation and synthetic media widespread, increasing fraudulent verification attempts. Defenders must adopt biometric liveness, risk-based re-verification, intent binding, and network-effect signals to stay ahead as regulations and threats evolve.
read more →

NCA warns parents on risks of AI-generated content

🔒 The National Crime Agency (NCA) and Internet Watch Foundation (IWF) have launched a campaign to warn parents about the dangers of oversharing images and videos of their children online. The IWF reported a dramatic rise in AI-generated child sexual abuse material in 2025, prompting social media outreach and new guidance to help parents manage image consent and protect children. The campaign includes advice on privacy settings, discussing consent with family and schools, and steps to take if abuse is suspected.
read more →

AI Enables Faster, Cheaper, Harder-to-Detect Attacks

🛡️ A ReliaQuest report finds AI is making cyber-attacks cheaper, faster to scale, easier to customize and harder to spot while not fundamentally altering attacker tradecraft. Initially used for polishing phishing and basic scripting in 2024, by mid-2025 AI had expanded into deepfakes, AI-assisted scripts and an underground market for tools. Today AI appears embedded in workflows—generating phishing pages, web shells, and obfuscating code—and as the lure itself, with attackers leveraging trusted AI brands to trick users.
read more →

Tabletop simulates modern retail ransomware mayhem

🔍 The Semperis-run "Enter the War Room" tabletop at Infosecurity Europe simulated a ransomware and reputational attack on fictional supermarket BlueCart. Red-team operators exploited supplier trust, stolen credentials, weak MFA, and poor network segmentation to access AI supply-chain systems and exfiltrate loyalty data. Attackers combined misinformation, deepfakes, fake orders, and payroll disruption to magnify harm, while defenders focused on out-of-band communications, honeypots, and refusing ransom demands to limit impact.
read more →

INTERPOL: Cybercrime Surge in Asia and South Pacific

🔍 INTERPOL warns of a dramatic rise in cybercrime across Asia and the South Pacific driven by rapid digitalization, organized criminal networks, and uneven cybersecurity maturity. Phishing is identified as the most widespread and costly threat, while ransomware, AI-driven scams, deepfakes, and banking trojans have also surged. Authorities are scaling cross-border cooperation and resilience efforts to counter these threats.
read more →

New York man charged with AI-enabled cyberstalking

📢 A New York man was indicted on cyberstalking charges after allegedly creating multiple fake social media and email accounts to harass a former college classmate. The defendant is accused of distributing AI-generated nude images and fabricated racist messages across platforms including Instagram, LinkedIn, Reddit, X, Strava, and Yahoo between January and March 2025. Authorities say he used spoofed accounts to send images to the victim’s family and continued the campaign after the victim transferred to a Georgia college. Federal prosecutors emphasize that sharing intimate images without consent is a prosecutable offense and urge victims to report such abuse.
read more →

Cybercrime Escalates Across Asia-Pacific Amid Digitization

🛡️Interpol warns that cybercrime now accounts for 30% of crime in over half of Asia and South Pacific nations, driven by rapid digital adoption. The 2025/2026 Asia and South Pacific Cyberthreat Assessment, covering 18 countries, highlights online scams, infostealers, ransomware, deepfakes and BEC as primary threats. The report notes sharp rises in ransomware, DDoS and deepfake activity, and calls for improved cross-border collaboration and capacity building.
read more →

DOJ seizes deepfake nude sites under new law

🔒 The U.S. Department of Justice seized CFAKE.com and SOCFAKE.com after finding they hosted nonconsensual AI-generated nude images and videos, marking the first publicly announced domain seizures under the TAKE IT DOWN Act. The sites allegedly displayed sexually explicit deepfakes of politicians, celebrities, athletes, and others. The action followed a multinational probe involving Italy and France and led to an arrest in Nice and seizure of related cryptocurrency. The law, enacted in May 2025, criminalizes publishing intimate altered images without consent and requires prompt takedowns.
read more →

Google sues to dismantle AI-powered scam networks

🛡️ Google is taking legal, technical, and legislative steps to disrupt large-scale AI-enabled phishing and smishing campaigns. The company filed a civil lawsuit against the China-based “Outsider Enterprise,” coordinated with the FBI and telecom partners to block malicious texts, and is advocating bipartisan federal legislation to strengthen protections. Google also leverages AI-driven detection on Android and messaging defenses to intercept malicious messages at scale.
read more →

Google adds Android protection against AI call scams

📱 Google is rolling out a new fake call detection feature for Android 12+ devices, starting with Pixel phones and enabled by default. When both parties use Phone by Google and RCS-enabled Messages, the caller's device sends a silent encrypted confirmation to the recipient; if absent, the recipient's device pings the contact's phone to verify authenticity and shows a warning if the contact denies making the call. The feature aims to counter AI voice-cloning and number-spoofing scams.
read more →

How geopolitical turmoil fuels online gift and aid scams

⚠ Geopolitical tensions have created a fertile environment for opportunistic scammers who exploit fear and sympathy to harvest credentials, personal data, or direct payments. Common ploys include fake charities, romance and travel scams, fraudulent charges, investment schemes, sensational fake news and classic advance-fee cons. Scammers increasingly use convincing content produced with generative AI and impersonation tactics to bypass trust; verify independently, avoid unsolicited links or calls, and protect devices with reputable anti-malware.
read more →

ICO issues five-step guidance on AI-driven cyber risk

🔐 The ICO has published a five-step guide urging organisations to prepare for AI-enhanced cyber threats, including deepfake social engineering, adaptive malware and automated exploitation. It points readers to the NCSC's updated Cyber Assessment Framework and expects baseline adoption of Cyber Essentials and the UK Cyber Governance Code. The guidance emphasises robust patching, MFA, least‑privilege, supply‑chain vetting, DPIAs for high‑risk AI and human oversight of AI-enabled defences.
read more →

World Economic Forum: AI, Deepfakes, and Cyber Defense

🔐 At the World Economic Forum Annual Meeting on Cybersecurity 2026, Fortinet highlighted how AI and deepfakes are reshaping attack surfaces, with identity now a primary vector and attackers operating in structured, continuous campaigns. Discussions stressed that AI accelerates reconnaissance and exploitation while defenders contend with fragmentation, governance gaps, and inconsistent visibility. Fortinet urged platform consolidation, stronger identity and exposure management, and operationalized public-private collaboration to better align detection with response.
read more →

Meta smart glasses, Copy Fail bug, and deepfake hire

🔍 Meta’s smart glasses were found to upload audio and video to contractors in Nairobi for human labelling, prompting the dismissal of 1,108 workers after whistleblowers exposed the practice. The episode contrasts that privacy failure with a measured analysis of the Linux Copy Fail privilege‑escalation issue and an experiment by Jake Moore demonstrating how a convincing deepfake passed a remote job interview. Practical takeaways include patching kernels promptly, strengthening hiring verification, and demanding clearer vendor transparency.
read more →

Deepfake Voice Attacks Outpacing Organizational Defenses

🔊 Deepfake voice cloning now needs as little as three seconds of audio and freely available tools to produce convincing, real-time impersonations. Incidents spiked in 2025, with attackers focusing on finance, HR and IT teams to trigger fraudulent transfers or credential changes. The author warns that traditional security stacks rarely detect these social-engineering attacks and urges organizations to build human verification habits—verbal passcodes, callbacks and continuous simulation-led training from vendors like Adaptive Security.
read more →