Hitmetrix - User behavior analytics & recording

CEO Assaf Rappaport target of deepfake attack

Deepfake Attack
Deepfake Attack

Assaf Rappaport, CEO and co-founder of cybersecurity firm Wiz, recently shared how his company was targeted by a deepfake phishing attack. The attackers created an AI-generated voice message that sounded like Rappaport, attempting to trick employees into giving up their credentials. The voice message was nearly convincing, but it had one critical flaw.

Rappaport suffers from public speaking anxiety, which noticeably changes his voice when he speaks in public. The fake voicemail did not account for this difference, so it sounded off to employees who knew him well. The attackers made three key mistakes.

First, they used a recording of Rappaport speaking at a conference as the source material for the deepfake. His voice in this setting was affected by his anxiety. Second, they failed to recognize that Rappaport’s voice changes when he’s anxious, which employees immediately noticed.

Deepfake targeting in cybersecurity attacks

Third, targeting a cybersecurity company meant that the employees were highly vigilant and trained to spot unusual requests, like their CEO asking for credentials via voicemail. This incident highlights the importance of being cautious about unusual requests, even if they seem to come from a familiar source.

When in doubt, it’s crucial to verify the request through secure channels before taking any action. Although this attack was stopped, the perpetrators were not caught. Rappaport noted that the attackers used sophisticated methods that made it nearly impossible to trace their exact identity.

This shows the low risk and high reward associated with AI-driven phishing attacks, which continue to be a valuable tool for cybercriminals. Despite the failure of this attempt, it serves as a reminder to stay alert and proactive in defending against cybersecurity threats. The rise of AI and deepfake technology has brought new challenges to the cybersecurity landscape.

This event demonstrates how even the most advanced attacks can be undone by unexpected and human factors.

Total
0
Shares
Related Posts