How AI is changing our IT security
CEO fraud scam

At the beginning of the year, the phone rang at one of the Bauerfeind subsidiaries. On the line: Rainer Berthan, Chief Executive Officer of Bauerfeind AG – at least allegedly. But this phone call was what is known as CEO fraud. In this scam, criminals try to manipulate people with decision-making authority in a company. They call with a spoofed telephone number and, in the worst-case scenario, even with the voice of the CEO.
“Attackers even have ways of integrating available recordings of the person’s actual voice into AI technology to create a whole new message – using words the person never even said,” Michael Illgen explains. The Information Security Officer is dealing with the question of how Artificial Intelligence (AI) is changing IT security. AI is a double-edged sword for IT security. This technology can help prevent cyber attacks but makes it harder for employees to recognize them. “Attacks are getting more professional and it’s getting increasingly difficult to tell reality and fiction apart, on all channels.”
In the worst-case scenario of this example of the CEO fraud scam, the attackers may obtain internal information that they will use for further scams. In the next step, they may send malware by email. Or money is demanded straight away as happened in a current case in Hong Kong. In February, an employee of an international company transferred almost 24 Million Euros to fraudsters in a video conference full of participants that were generated using Artificial Intelligence.
Great vigilance is therefore required, whether during a call, video conference, in emails or messenger services such as WhatsApp. “I always recommend checking via a different familiar communication channel that the situation is as stated and that any demands are authorized.”
Alarm bells should sound immediately when time pressure is exerted or secrecy is demanded. In general, Michael Illgen urges: be suspicious! For your own protection and for the sake of the company.
This video shows how AI-based fraud works: https://www.youtube.com/watch?v=_jtfazvwysM
A security researcher dubbed the person on the right with Turkish text for demonstration purposes.