advertisement

Cybersecurity threats are enhanced by AI

Artificial intelligence (AI) can be a tremendous benefit to the workplace. In the wrong hands, however, it poses one of the largest cybersecurity threats to businesses today.

Although businesses laud the benefits of this tool that can help with marketing, record-keeping, research, and provide relief from the more mundane tasks that face them each day, these advances come with potentially adverse consequences. With every breakthrough in technology (and AI is a big breakthrough!) cybercriminals hunt for ways to use AI to their advantage, which can spell big trouble for a business.

What to be aware of

AI tools can retrieve information in a split second. Most businesses store proprietary data in their files, including payroll records (which contain employee Social Security numbers), a company’s financial records, sales figures, and confidential marketing and business strategy plans. In the wrong hands, this information can cause headaches and create liabilities. In the pre-AI world, it might have taken hackers days to mine the information they seek to use. With AI, they can do so in a matter of seconds.

AI can make hacking emails and videos look and sound convincing

Once a hacker gains access to a network, it’s easy to access LinkedIn or Facebook and create a convincing looking profile. Today’s AI tools have virtually eliminated the awkwardly worded, amateurish messages and profiles of before.

AI helps malicious actors create very real-looking emails, videos, voice messages and other forms of communication, including video deepfakes, and voice clones.

And this enhanced technology can have devastating consequences on the unsuspecting victims.

A hacker can mimic the personality of the CEO, for example and create email “rules” that will send important incoming emails to different folders where the “actual” CEO might not look (such as spam, or deleted folders). The hacker then looks for opportunities in the emails and begins correspondence.

An even greater sense of realism is achieved through video deepfakes, which can create realistic videos and voices of trusted company team members, leaving messages for employees to do such tasks as wire transfers or company records requests. Often the request will be accompanied by a message, “I’m in meetings all day so I cannot take incoming calls. Please RVSP by email.”

If a CEO impostor requests an email transfer of funds, and if an employee rightly asks the “CEO” for phone verification, the hacker can reply that he will call later from a conference room. That time delay allows said hacker to create and deliver a phone message in the actual CEO’s voice and style. If successful, the transferred funds go into an account the cybercriminal has created. Rarely if ever can these funds be recovered. This strategy can be used alongside business email compromise for layered attacks. Ninety-five percent of attacks on a system are delivered by email or phone.

What to watch for from cybercriminals: Common requests are to wire funds, or pay fake vendor invoices with updated banking details, and payroll or direct depositor changes from “employees.” Attackers use publicly available information such as LinkedIn and websites. Email spoofing is easier than ever, and hybrid work makes verification harder.

How can companies protect themselves against AI-enhanced cyberattacks?

• Be certain that your network has the latest software, and latest protection updates.

• But remember, employee training is crucial! More than 90% of network intrusions stem from human error — someone opens a suspicious email or link. Train employees to identify and recognize these threats. Supplement traditional generic phishing training with sessions where employees see AI-generated phishing emails and practice detecting the fakes. Remember — the best anti-hacking software and infrastructure is only as good as the people who use it.

• Implement multifactor authentication on all email accounts, especially finance and email systems

• Verify! Require verbal or in-person confirmation for financial transactions. Use email filtering and domain authentication (DMARC. SPF. DKIM). Train employees to question urgency and subtle changes in tone.

• For money movements, employ strict verification processes. Use code words or secondary authentication for sensitive requests. Limit public exposure of executive voice/videos where possible, and above all, educate the staff that “familiar” does not equal “authentic.”

• Utilize AI-enhanced security tools, such as email filtering and anomaly detection.

• Monitor for unusual behavior, not just known threats.

AI is a great tool. Just don’t let it be used against you by cybercriminals. A cybersecurity partner can answer questions and guide you through the steps if needed.

• Kyle Sallmen is director of IT and VCIO at Pulse Technology.