2024-02-07 Deep Fake Scam

更新於 發佈於 閱讀時間約 9 分鐘

A few days ago, a fraud case involving HK$200 million occurred in Hong Kong. The scammer pretended to be the CFO of a multinational company's overseas headquarters and instructed the branch finance staff to join a confidential meeting. Using deepfake technology, the fraudster created a virtual video and provided "investment" guidance during this session. As per these instructions, the staff transferred a significant sum to various accounts without proper confirmation. Subsequently, when they contacted their colleagues at the UK headquarters, it became clear that they had been defrauded. They promptly reported this incident to the police after realizing what had transpired.

The rise of Deepfake technology has made what we previously referred to as "P-photos" even more difficult to defend. In the past, photos could be altered using Photoshop, leading many to question their reliability and usability as evidence. For ordinary individuals outside of Hollywood, distinguishing between real and fake imagery through such techniques is challenging.

Nowadays, with the rapid advancement of technology and network speed, along with improved computer performance and the widespread acceptance of online meetings following the COVID-19, hackers have greater flexibility in using fraudulent techniques. As a result, employees are at an increased risk of being deceived, making defense against such tactics more challenging.

With the rapid advancement of technology, it is becoming increasingly challenging to distinguish deepfake transformations, akin to the concept depicted in Matrix, the movie. Additionally, identifying participants at a conference by instructing them to perform certain actions can be very difficult. Consider a junior staff member who lacks opportunities to address executives but requests them to make gestures – this could signal disinterest in their job responsibilities.

This time, the scam is not a phishing the whole company staff, but it clearly targets the victim. The approach involved telling the victim that it was a confidential meeting and sending them a link to join, among other tactics. Can any clues be found from the emails received or from the ID of the person who logged into the meeting?

However, is there a non-technical way to prevent this scam from happening?

The author has not yet determined if the victim's company followed established procedures for transferring money. Normally, regardless of the amount, approvals are required for money transfers to ensure compliance with permissions and internal auditing controls. Smaller amounts can be approved by fewer people, while larger amounts require more signatures. Additionally, it's important to verify your own signature to prevent unauthorized use (there have been cases where executives' emails were hacked and funds were authorized). When approved by overseas headquarters, consider using an electronic signature solution like Docusign to safeguard against process interruption due to potential individual errors.

I am surprised that one person could have had access to such a large amount of money without proper oversight from an internal control or risk management perspective. If this individual had not fallen victim to a scam or been in a state of delirium, they could have potentially sent the funds to various accounts in an unregulated manner. This situation highlights insufficient risk management within the enterprise and ineffective regulation of staff authority.

In some cases, the CEO/CFO/COO of certain enterprises the author has worked with have to sign at least one signature before any payment above HK$1000 can be made. This requirement may seem strict, but it helps reduce the risks faced by the company.

 

留言
avatar-img
留言分享你的想法!
avatar-img
左先生的沙龍
23會員
102內容數
現職風險管理部總監、兼任大學資安講師及博士研究生。語言學、電腦罪案、工商管理及傳媒管理碩士學位。CISSP、CISA、CISM、CRISC、CHFI、PMP及ISO27001首席審計師資格。也是一名被資安生涯耽誤的詩人及酒徒,作品散見於網路及台港詩刊,持國際唎酒師資格......興趣太廣泛的大孩子。
左先生的沙龍的其他內容
2025/01/20
本文探討AI人工智慧的應用,涵蓋語音辨識、圖片辨識、翻譯、預測模型建立、資料分析及網路安全等面向,並說明AI如何提升效率及準確性,例如更精準的語音轉文字、更人性化的翻譯、更有效的資料分析及更快速的網路安全威脅偵測等。文章最後提及AI圖像生成的強大能力,並預告後續將深入探討AI運作機制及算力概念。
2025/01/20
本文探討AI人工智慧的應用,涵蓋語音辨識、圖片辨識、翻譯、預測模型建立、資料分析及網路安全等面向,並說明AI如何提升效率及準確性,例如更精準的語音轉文字、更人性化的翻譯、更有效的資料分析及更快速的網路安全威脅偵測等。文章最後提及AI圖像生成的強大能力,並預告後續將深入探討AI運作機制及算力概念。
2024/09/12
隨著生成式AI的興起,AI幻覺的問題日漸受到重視。AI幻覺指的是AI生成內容中的虛構與現實重疊現象,造成錯誤資訊的擴散。造成這一現象的原因包括訓練數據不足、模型缺失及惡意資訊注入。
Thumbnail
2024/09/12
隨著生成式AI的興起,AI幻覺的問題日漸受到重視。AI幻覺指的是AI生成內容中的虛構與現實重疊現象,造成錯誤資訊的擴散。造成這一現象的原因包括訓練數據不足、模型缺失及惡意資訊注入。
Thumbnail
2024/07/20
2024年7月19日,全球出現大規模的電腦擋機事故,相信就算不是在IT界發展的,對於微軟視窗的藍畫面也是略有所聞。微軟由很多年前的作業系統版本開始,就有藍底白字顯示錯誤的畫面,也就是所謂的「死機」。這就是世界聞名的Blue Screen of Death (BSoD)。
Thumbnail
2024/07/20
2024年7月19日,全球出現大規模的電腦擋機事故,相信就算不是在IT界發展的,對於微軟視窗的藍畫面也是略有所聞。微軟由很多年前的作業系統版本開始,就有藍底白字顯示錯誤的畫面,也就是所謂的「死機」。這就是世界聞名的Blue Screen of Death (BSoD)。
Thumbnail
看更多
你可能也想看
Thumbnail
創作者營運專員/經理(Operations Specialist/Manager)將負責對平台成長及收入至關重要的 Partnership 夥伴創作者開發及營運。你將發揮對知識與內容變現、影響力變現的精準判斷力,找到你心中的潛力新星或有聲量的中大型創作者加入 vocus。
Thumbnail
創作者營運專員/經理(Operations Specialist/Manager)將負責對平台成長及收入至關重要的 Partnership 夥伴創作者開發及營運。你將發揮對知識與內容變現、影響力變現的精準判斷力,找到你心中的潛力新星或有聲量的中大型創作者加入 vocus。
Thumbnail
今天在某平台上 真的是命運的安排 一則大言不慚的貼文就這樣推送到我眼前 看了熟悉的職涯經歷 瞄了一下帳號 果然是那位曾經跟我共事過的騙子 之所以會用騙子稱呼對方 是因為涵蓋目前服務的公司 我一共待過了三間外商 遇到過這麼多優秀的業務同事裡面 只有這一位 會虛報職稱...
Thumbnail
今天在某平台上 真的是命運的安排 一則大言不慚的貼文就這樣推送到我眼前 看了熟悉的職涯經歷 瞄了一下帳號 果然是那位曾經跟我共事過的騙子 之所以會用騙子稱呼對方 是因為涵蓋目前服務的公司 我一共待過了三間外商 遇到過這麼多優秀的業務同事裡面 只有這一位 會虛報職稱...
Thumbnail
看完《好棒的虛擬貨幣詐騙全解碼!網紅配合交易所騙光粉絲上千萬!》影片,發現很多人都有被詐騙受傷的經驗...
Thumbnail
看完《好棒的虛擬貨幣詐騙全解碼!網紅配合交易所騙光粉絲上千萬!》影片,發現很多人都有被詐騙受傷的經驗...
Thumbnail
前幾天我自己本人私人臉書,竟然被冒名我的粉專說要加好友(太歲爺上動土阿),我就乾脆加入他們來看看到底這些詐騙的手法長那些樣子
Thumbnail
前幾天我自己本人私人臉書,竟然被冒名我的粉專說要加好友(太歲爺上動土阿),我就乾脆加入他們來看看到底這些詐騙的手法長那些樣子
Thumbnail
《反詐之歌》 詐騙手段花樣多, 防騙之心不可挪。 陌生電話須警惕, 中獎信息莫輕信。 網路連結勿點擊, 轉帳匯款要斟酌。 個人資訊保護好, 騙子無機可奈何。 這是朋友幾乎受騙的經歷,是4月9日才發生的真人真事,大家一定要注意!   致我的親朋好友: 我是OOO,昨日早上親
Thumbnail
《反詐之歌》 詐騙手段花樣多, 防騙之心不可挪。 陌生電話須警惕, 中獎信息莫輕信。 網路連結勿點擊, 轉帳匯款要斟酌。 個人資訊保護好, 騙子無機可奈何。 這是朋友幾乎受騙的經歷,是4月9日才發生的真人真事,大家一定要注意!   致我的親朋好友: 我是OOO,昨日早上親
Thumbnail
連雲建設總經理蔡漢霖昨天請大家小心詐騙他數百萬元的王俊雄 Thoshio Oh。我恰巧領過這個詐騙者幾個月的薪水
Thumbnail
連雲建設總經理蔡漢霖昨天請大家小心詐騙他數百萬元的王俊雄 Thoshio Oh。我恰巧領過這個詐騙者幾個月的薪水
Thumbnail
投資詐騙日益增多,不再限於傳統的詐騙手段,而是藉由虛擬貨幣等新形式進行詐騙。從一場看似真摯的投資活動,到最後發現所有的投資項目都跟被羈押的一群人有關,這位投資者才意識到自己已經落入詐騙的陷阱。投資前應審慎評估各項資訊並尋求專業意見,避免成為投資詐騙的受害者。
Thumbnail
投資詐騙日益增多,不再限於傳統的詐騙手段,而是藉由虛擬貨幣等新形式進行詐騙。從一場看似真摯的投資活動,到最後發現所有的投資項目都跟被羈押的一群人有關,這位投資者才意識到自己已經落入詐騙的陷阱。投資前應審慎評估各項資訊並尋求專業意見,避免成為投資詐騙的受害者。
追蹤感興趣的內容從 Google News 追蹤更多 vocus 的最新精選內容追蹤 Google News