Episode 427 - Phishing, Voice Clones, Deepfakes

Episode 427 - Phishing, Voice Clones, Deepfakes

Author: MySecurity Media December 6, 2024 Duration: 18:18

Jane Lo, MySecurity Media Singapore Correspondent sat down with Syed Ubaid Ali Jafri, Head of Cyber Defense and Offensive Security at Habib Bank Limited (HBL), at Tech Week Singapore, to get his insights on the sophistication of these threats. We delved into:

Motivations for Attacks on Financial Institutions:

  • Financial gain and data exploitation are prime motivations behind phishing and cyber attacks targeting banks. Attackers seek customer data, card details, and account balances, which they can use to extort or sell for profit.
  • Financial institutions are particularly vulnerable due to their reputational concerns, leading some to pay ransoms to protect customer privacy.

Increasing Accessibility of Cybercrime Tools:

  • Advanced phishing tools, previously available only on the dark web, are now accessible on the surface web, enabling even less-skilled cybercriminals to launch attacks.
  • With the rise of AI, non-experts can craft convincing phishing emails, bypassing traditional spam filters and reaching unsuspecting targets.

Role of AI in Sophisticated Cyber Attacks:

  • Gen AI and voice cloning technology make phishing more personalized and convincing, allowing attackers to craft emails and messages that mimic the target’s language and communication style.
  • The evolution from simple phishing to sophisticated voice and deepfake attacks was also highlighted, showing how AI can now be used to clone voices and create realistic fake videos with as few as 15 images.

Challenges in Detecting AI-Driven Phishing and Deepfake Attacks:

  • Deepfake technology makes it challenging for the average user to distinguish between real and fake communications. Convincing voice and video deepfakes are increasingly used in spear-phishing, targeting specific individuals with tailored scams.
  • AI-powered tools generate flawless text, removing traditional phishing indicators like spelling errors or urgency cues, which previously helped users identify phishing emails.

Recommendations for Protection:

  • Users are advised to be cautious about what they share online, as personal information posted publicly can help cybercriminals tailor their attacks.
  • Security tools like deepfake detection software can help individuals identify fake voices or videos, though awareness and cautious online behavior remain critical.
  • Cybersecurity education is essential, with both vendors and users needing awareness of AI-driven threats to implement better protective measures

Recorded 10th Oct 2024, Tech Week Singapore 2024, 12.40pm.

#mysecuritytv


Produced by MySecurity Media, the Cyber Security Weekly Podcast operates from a simple, powerful premise: trust is the foundation of everything. When it erodes, progress halts. This isn't just a theoretical discussion; it's a practical, weekly analysis of how that trust is built, tested, and broken in our interconnected world. Each episode delves into the evolving landscape of threats, blending cyber and physical security into a single, crucial conversation. You'll hear directly from experts navigating these challenges, get clarity on new government policies affecting the sector, and learn about the tools and strategies emerging from leading industry suppliers. We move beyond headlines to provide context on why a particular breach happened, how a new regulation will play out, or what a conference announcement really means for professionals in the field. This podcast serves as a consistent, reliable resource for anyone responsible for safeguarding assets, data, or people, offering not just news updates but a deeper understanding of the trends that define risk and resilience. It's for those who know that staying informed is the first, non-negotiable step in maintaining that essential trust.
Author: Language: English Episodes: 50

Cyber Security Weekly Podcast
Podcast Episodes
Episode 459 - Providing cloud solutions in Malaysia [not-audio_url] [/not-audio_url]

Duration: 4:13
We speak with Hafis Murty, Head of Product Development with AVM Cloud as sponsors to the Cyber Security Asia 2025 Conference, Kuala Lumpur 21-22 April.Recognized as one of the premier cloud solution providers in Malaysia…
Episode 457 - Rolling out Privileged Access Management [not-audio_url] [/not-audio_url]

Duration: 4:03
We speak with Aaron Tay, Technical Solutions Consultant with Manage Engine, as sponsors for the Cyber Security Asia 2025 conference in Kuala Lumpur, 21-22 April.ManageEngine is a division of Zoho Corporation that offers…
Episode 456 - Introducing V Gallant CyberSecure at CSA 2025 [not-audio_url] [/not-audio_url]

Duration: 6:22
We speak with Fabian Lim, Business Development Manager for V Gallant.As sponsors for the Cyber Security Asia 20205 conference in Kuala Lumpur, 21-22 April, VCI Global introduced V Gallant CyberSecure, an AI-driven, milit…
Episode 455 - State of Cyber (Part 2) [not-audio_url] [/not-audio_url]

Duration: 57:22
After three lead episodes we review the key outcomes from the series with our esteemed speakers:Zeynep Soylu - Sydney Chapter PresidentChirag Joshi - Sydney Chapter Board MemberAbby Zhang (pending) - Auckland Chapter Boa…
Episode 454 - STATE OF TRUST [not-audio_url] [/not-audio_url]

Duration: 1:00:12
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta. We present the third session with the State of Trust – Critical to the success of every businessSpeakersJamie Norton - ISACA Board Memb…
Episode 453 - STATE OF PRIVACY [not-audio_url] [/not-audio_url]

Duration: 49:39
Welcome to the Indo-Pacific State of Cyber Series with ISACA and sponsored by Vanta. This session focuses on The State of Privacy - A Challenging Landscape: Lack of training or poor training tops reasons for privacy fail…