Deepfake_Vishing_Attacks_InCyber_Montreal_2024.pptx

julie52115 1 views 15 slides Sep 16, 2025
Slide 1
Slide 1 of 15
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15

About This Presentation

Presentation given at InCyber Montréal in 2024 about deepfakes and vishing attacks and how to detect and prevent them.


Slide Content

PALAIS DES CONGRÈS QC, CANADA OCT. 29-30, 2024

Deepfake et Vishing : les arnaques dopées à l’IA Deepfake and Vishing, AI-doped scams ​

Deepfake et Vishing : les arnaques dopées à l’IA Deepfake and Vishing, AI-doped scams ​ PALAIS DES CONGRÈS MONTREAL, QC, CANADA 2024 OCT. 29-30 @FICAmNord @fic-north-america EN/FR

INTERVENANTS SPEAKERS Julie BRUNIAS Cybersecurity Expert

Stats Deepfake​ Statistics about Deepfake: 71% of people don’t know​ what deepfakes are​ ​Cost as little as 1.36 USD​ ​ Targets : ​ Retool ( Sotfware Development)​ Hong Kong CFO 25.6 million USD​ Taylor Swift​ Political actors (Biden, Justin Trudeau...)​ 57% think they can spot one​ ​ AND YOU ?​

Stats Vishing​ Statistics about Vishing: 77% success rate​ 3/4 businesses lost money​ ​ 40% increase in attacks targeting seniors ​ ​ ​ 60% think they can spot one​ (source Norton) ​ AND YOU ?​

Recent Vishing scams Recent Vishing Scams : February 2024 Change Healthcare (USA) In February 2024, Change Healthcare experienced a significant vishing attack that led to a data breach, disrupting operations across 94% of hospitals under its network (source: KeepNetLabs ) March 2024 Rogers Communications (Canada) Rogers Communications reported a vishing attack where scammers posed as technical support representatives, tricking employees into providing access to internal systems. The breach led to the exposure of customer data and financial losses (source: BankInfoSecurity ) April 2024 CDK Global (USA) In April 2024, CDK Global was targeted by a vishing scam, resulting in substantial financial losses and data theft (source: Bolster.AI ) May 2024 Royal Bank of Canada (Canada) RBC faced a vishing scam where fraudsters impersonated bank officials, targeting customers to extract sensitive banking information (source: BankInfoSecurity ) June 2024 Snowflake (USA): In June 2024, customers of Snowflake were affected by a vishing attack that led to data theft and extortion attempts (source: Bolster.AI ) https://keepnetlabs.com/blog/top-30-phishing-statistics-and-trends-you-must-know-in-2024 https://bolster.ai/blog/2024-state-of-phishing-statistics-online-scams https://www.bankinfosecurity.com/hackers-breach-canadian-isp-rogers-a-7971

Deepfake : can you spot them ? Deepfake: can you spot them ? DEMO :

Deepfake : can you spot them ? Deepfake: can you spot them ? VIDEO :

Deepfake : can you spot them ? Deepfake: can you spot them ? VIDEO :

How to prevent such attacks ? How to prevent such attacks ? Educate users about the existence of deepfakes and vishing ​ ​ Make sure they can spot them (like in a phishing campaign) ​ ​ Provide them with a procedure of what to do when they have a doubt ​ Restrict recording of meetings ​ if a recording is necessary, ​ try to keep it faceless (or use an avatar) ​ ​ Use MFA to connect to company communication tools Monitor file sharing outside the ​ Company ( eg DLP, CASB) ​ ​ Or restrict file sharing websites ​ Inform users of criminal consequences ​ If any recording is leaked or a record ​ Is made without consent

Detection Tools Detection tools you can use: Intel fake catcher : Real time deepfake detector to analyse live video feed ​ https://download.intel.com/newsroom/2022/new-technologies/FakeCatcher-Infographic.pdf ​ ​ Attestiv : Upload video and social media links, it provides a report ​ https://video.attestiv.com/dashboard/video ​ ​ Sentinel : Upload video and get a report ​ ​ Deepfake o Meter : Upload a video and know if its a deepfake ​ https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/landing_page ​ ​ DeepFakeDetector : Upload a video OR audio and get a report ​ https://deepfakedetector.ai ​ ​ Deepware : Upload a video OR a link and get a report ​ https://scanner.deepware.ai/ ​ ​ KeepNetLabs Vshing detection tool ( also Smishing and Quishing ) ​ https://keepnetlabs.com/pricing Lipsyncer.ai : allows to upload a video (or use a sample ) and play any audio or text that you generate https://www.lipsyncer.ai/

Common Lips Moves Common lips moves :

→ Antonio GRAMSCI L’IA sera ou bien la meilleure ou la pire chose qui arrivera à l’humanité ​ AI is likely to be either the best or worst thing to happen to humanity. Antonio GRAMSCI