Scaut

Tag: AI & Deepfakes

  • The Escalation of AI in Fake Identity Crime: A Growing Concern

    The Escalation of AI in Fake Identity Crime: A Growing Concern

    The Rise of AI in Identity Fraud AI technologies, particularly those involving machine learning and deep learning algorithms, have become tools for creating sophisticated fake identities. These can range from generating realistic human images and forging documents to mimicking human behavior and voice. The accessibility of AI tools that can perform these tasks is alarmingly high, making it easier for criminals to create authentic-looking fake identities.

    Recent Notable Cases

    1. Synthetic Identity Fraud: One of the most common uses of AI in identity crimes involves the creation of synthetic identities. These are identities that are partially or entirely fabricated but are realistic enough to pass initial verifications. For example, a recent bust in Europe uncovered a large-scale operation where AI-generated faces were used on fake passports and IDs, enabling criminals to open bank accounts, secure loans, and even travel across borders undetected.
    2. Deepfake Technology: Another alarming trend is the use of deepfake technology, where AI is used to create video and audio recordings that are indistinguishable from real ones. A notorious case occurred in the UK, where a CEO was tricked into transferring funds by a fraudster who used AI to mimic the voice of the company’s director. The incident resulted in a loss of over $200,000.
    3. AI and Social Engineering: AI is also being used to automate elements of social engineering attacks. In a recent incident in the United States, AI was employed to generate background noises and realistic interactive scripts in phone scams, effectively persuading victims to disclose sensitive information.

    Implications for Security and Prevention The escalating use of AI in fake identity crimes poses significant challenges for security frameworks globally. Traditional security measures are often ill-equipped to detect the nuances of AI-generated falsifications, necessitating a new approach to cyber defense.

    Enhancing Detection and Response Organizations and governments are increasingly investing in AI-driven security systems that can counteract AI-assisted threats. These include the use of AI to detect anomalies in documents and communication patterns that human operators might miss. Moreover, there is a growing emphasis on public-private partnerships to share knowledge, tools, and strategies to combat these sophisticated frauds effectively.

    Legal and Ethical Considerations The misuse of AI in identity crimes also raises urgent legal and ethical questions. Legislators are being challenged to create laws that can keep pace with the rapid development of technology, focusing on the misuse of AI without stifling innovation. Additionally, there is a pressing need for ethical guidelines that dictate the responsible use of AI technologies in both development and deployment stages.

    Conclusion The use of AI in fake identity crimes represents a significant and growing threat to individual and organizational security. As AI technologies evolve, so too do the methods by which they can be exploited. It is imperative for continued investment in AI security measures, legislative action, and ethical considerations to mitigate these risks. Awareness and education will also play crucial roles in preventing such crimes, as informed individuals and institutions are better equipped to recognize and respond to these emerging threats.

  • AI helps create fake documents, recruiters often don’t recognise them

    AI helps create fake documents, recruiters often don’t recognise them

    This is something some people try to exploit, greatly helped by modern artificial intelligence (AI) tools like Midjourney and Dall-E. However, there are also many other tools, such as Verif Tools, subtitled Fake Document Generator.

    For about nine dollars you can easily order a fake photo of a Czech document. For example, the citizen may be lying on a table.

    A chauffeur for all the money

    Cases of document forgery and subsequent infiltration into Czech companies are cited by Petr Moroz, founder and head of SCAUT, a company that develops online tool for the so-called background check to screen candidates for jobs.

    “We have a lot of cases like: We have a sales manager come on board and while he was still on probation, he disappeared with a credit card, a car, a computer, and we never saw him again,” Moroz says.

    One of his earliest and exemplary “cases” was one that didn’t actually happen for him. The company made inquiries with SCAUT to check out the chauffeur who was supposed to drive the CEO’s cars. Such a screening would have cost the unnamed chain about two and a half thousand crowns, which the chain’s security officer refused after consideration.

    “The chauffeur was also supposed to drive the children of the CEO in question and have the keys to his house, so we proposed a comprehensive screening, including foreclosures or insolvencies. After a couple of months, we met with the worker again and he told me that the chauffeur was worth CZK 8.5 million on two stolen seven-seater Bavarians,” Moroz says, adding that after a retrospective check, the driver was found to have eighteen foreclosures.

    Moroz cites a case from a betting company as another example of companies failing to adequately vet their potential employees. In both cases, the employees were never seen in person, and recruitment was done online.

    “During our work with them, we also discovered a person who had created several fake profiles on the social networking site LinkedIn under which he was trying to respond to various job advertisements. He was confirming references to himself and actually managed to get into two companies. He was an Asian with a European passport, and in one company he was the head of development, and in the other he was a full-stack developer,” Moroz says.

    When the companies found out he had a fake identity, he stopped communicating with them and disappeared without another digital trace. He also withdrew his LinkedIn profiles. “But he could have had countless other such profiles, and since he has not been traced yet, he may continue his activities even now,” Moroz says.

    Moroz says the big problem also lies not just in direct recruitment but in referral through employment agencies. “This is because these candidates do not go to the end company through HR, but rather through the purchase of services,” Moroz adds.

    Other Czech companies have similar experiences. “We even found out that someone had a false education document that he forged himself, and we found out that one candidate had a dubious history in IT contracts,” says Jan Klouda, vice president of Vodafone and a member of the Critical Infrastructure Association.

    That’s why the company is conducting more thorough background checks on job candidates.** “Within the Critical Infrastructure Association, this is a topic that everyone is addressing and taking seriously,” Klouda adds.

    Recruiters often do not verify information

    Police crime statistics also show an increasing trend in falsifying public documents. They show that in the past five months of this year, the number of cases has already reached similar numbers to last year or the year before**.

    According to the ACFE, such fraud costs companies an average of five per cent of their sales each year, which in the case of ŠKODA Auto, for example, is over one billion euros.