Skip to main content
Advertisement
Live broadcast
Main slide
Beginning of the article
Озвучить текст
Select important
On
Off

In early September, cybersecurity experts warned about a new deception scheme: scammers collect audio and video materials of children published on social networks, create deepfakes based on them and call parents allegedly on their behalf with urgent requests to transfer money. Experts note that artificial intelligence has significantly reduced the cost of fraudsters' work. Details are in the "Izvestia" material.

Cleared phishing

"""""" Parents themselves are vulnerable targets for criminals, and in the rush of the beginning of the school year, they often do not look at any messages with the topics "class group", "electronic schedule", "new electronic diary"," Ivan Kostyrya, head of the monitoring and response team of SOC UserGate Factor, told Izvestia.

Школа
Photo: IZVESTIA/Pavel Volkov

"Modern attackers use AI for phishing to remove common markers like errors and incorrect layout, to generate malicious code and scripts, and to automate the attacker's routine," says Kostyrya. — There are special attack assistants, analogues of GPT. Phishing is becoming "clean" — there are fewer typos, the layout is better, and the deception strategies are becoming more refined. AI works as an amplifier here — it does not create fundamentally new types of attacks, but makes old schemes massive, cheap and as plausible as possible.

Focus on school

"""" The expert points out that AI generates grammatically perfect letters"from the teacher," "from the parent committee," "from the school administration," in any language and in the right tone. """"Real mailing lists are simulated: ""update the data in the electronic diary", "pay for meals", "fill out the questionnaire for the new school year". If an attacker has obtained the personal data of a child or parent from leaks, the letter contains an address by name and mentions a specific class. The goal is to lure the login and password from the diary, payment data, or force you to go to a phishing page for paying "school fees."

Deepfake Hell

Voice and image imitation attacks have become widespread over the past few years. Among them, extortion of funds from parents by cloning the child's voice in a short audio message. According to Kostyria, a common scheme is to call parents: "Mom, I have problems, I urgently need money." Hackers also use deepfakes with students for cyberbullying or extortion, including using pornographic content. According to the expert, fake voice messages from the "teacher" were repeatedly recorded to receive information or money.

— Intruders will not pursue a long duration or high-quality forgery. As a rule, it is based on emotions and pressure on the victim," explains Kostyrya.

Messenger as a gateway

The presence of AI bots in class and parallel chats is widespread, the algorithm disguises itself as a classmate or parent, collects information, links, and then launches malicious links or phishing. Chatbots for children can disguise themselves as services for ready-made homework, answer books, and neural networks for studying. In fact, these programs collect personal data or lead the child to malicious content.

— In messengers and social networks, schoolchildren are doubly vulnerable: they are both targets and "donors" of the material from which fakes are made, — says the expert.

Школа
Photo: IZVESTIA/Anna Selina

The expert focused on the dangers of so-called neural networks for solving homework. The true purpose of these apps and bots is phishing or installing password stealers. Malicious AI-generated scripts disguised as study programs collect money for scammers.

Split personalities

— If earlier AI was used to fake videos with celebrities, today the scenario of imitating the faces and voices of ordinary users, including children, is quite realistic. The quality of fakes is often extremely high," says Dmitry Anikin, head of data research at Kaspersky Lab. "

Хакер
Photo: IZVESTIA/Polina Violet

At the same time, it is difficult to distinguish a deepfake from the original even with careful viewing — attackers have already learned how to mask artifacts due to low resolution, background noise or short videos.

— Nevertheless, signs of deception can still sometimes be distinguished: in video, these are unnatural facial expressions, failures in articulation, strange reflections in the eyes, and in audio, sound instability and unnatural timbre, extraneous noise, or an attempt to replace a live conversation with a pre—recorded audio message, — explains Anikin.

Don't get into trouble

Experts recommend using proven verification methods. Any urgent requests should be checked through an alternative, independent channel (call the teacher directly, the official website of the school, not the link from the message). According to Ivan Kostyri, you should not follow links from unverified chats, even if they look like the official website of a bank or a school. It would not be superfluous to arrange a code word with the child for any alarm call or voice message. Another recommendation is to limit the publicity of children's accounts. Less public audio, photos, and videos means less material for voice cloning and deepfakes. The "ideal" text should be treated with a degree of skepticism — perfect grammar and official tone are no longer a sign of authenticity, but rather the opposite.

— Distrust and maintaining calm are the main ways not to fall for the tricks of scammers, — sums up Kostyrya.

Телефон
Photo: IZVESTIA/Polina Violet

Dmitry Anikin advises to teach children not to share unnecessary information about themselves on social networks.

— Reliable software solutions will provide effective protection: They block access to fraudulent and phishing sites, signal suspicious calls, and prevent malware installation," he concludes.

How to live in the clone world

The total forgery of video and audio on the Web leads to a fundamental crisis of trust, Ivan Kostyrya believes. The "picture by picture" check stops working. In the future, this may lead to people ceasing to trust any digital evidence, which will affect many areas — from legal proceedings to personal relationships, says the source of "Izvestia". The expert recalled cases when crimes were committed with the help of deepfakes. In 2019, the director of a British energy company transferred $ 243 thousand, believing the voice of the head. In Biysk, a woman transferred 25 thousand rubles, believing the fake voice of an acquaintance. In Minsk, scammers staged the kidnapping of a 15-year-old daughter, demanding a ransom in cryptocurrency. And this is just the beginning, the expert believes.

Голосовое сообщение
Photo: IZVESTIA/Yulia Grigorieva

"As technology becomes cheaper, the number of such attacks will grow, and protection will require not only technical solutions, but also a new level of digital literacy," says Kostyrya.

Переведено сервисом «Яндекс Переводчик»

Live broadcast