{"id":8505,"date":"2023-11-22T12:00:00","date_gmt":"2023-11-22T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/2023\/11\/22\/your-voice-is-my-password-the-risks-of-ai-driven-voice-cloning\/"},"modified":"2023-11-22T12:00:00","modified_gmt":"2023-11-22T10:00:00","slug":"your-voice-is-my-password-the-risks-of-ai-driven-voice-cloning","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2023\/11\/22\/your-voice-is-my-password-the-risks-of-ai-driven-voice-cloning\/","title":{"rendered":"Your voice is my password \u2013 the risks of AI-driven voice cloning"},"content":{"rendered":"<p>The recent <a href=\"https:\/\/www.welivesecurity.com\/en\/cybercrime\/the-grand-theft-of-jake-moores-voice-the-concept-of-a-virtual-kidnap\/\">theft of my voice<\/a> brought me to a new fork in the road in terms of how AI already has the potential of causing social disruption. I was so taken aback by the quality of the cloned voice (and in that extremely clever, yet comedic, style by one of my colleagues) that I decided to use the same software for \u201cnefarious\u201d purposes and see how far I could go in order to steal from a small business \u2013 with permission, of course! Spoiler alert: it was surprisingly easy to carry out and took hardly any time at all.<\/p>\n<blockquote><p>&#8220;AI is likely to be either the best or worst thing to happen to humanity.&#8221; \u2013 Stephen Hawking<\/p><\/blockquote>\n<p>Indeed, since the concept of AI became more mainstream in fictional films such as Blade Runner and The Terminator, people have questioned the relentless possibilities of what the technology could go on to produce. However, only now with powerful databases, increasing computer power, and media attention have we seen AI hit a global audience in ways that are both terrifying and exciting in equal measure. With technology such as AI prowling among us, we are extremely likely to see creative and rather sophisticated attacks take place with damaging results.<\/p>\n<h2>Voice cloning escapade<\/h2>\n<p>My previous <a href=\"https:\/\/www.welivesecurity.com\/2020\/02\/05\/how-catch-cybercriminal-tales-digital-forensics-lab\/\">roles in the police force<\/a> instilled in me the mindset to attempt to think like a criminal. This approach has some very tangible and yet underappreciated benefits: the more one thinks and even <em>acts<\/em> like a criminal (without actually becoming one), the better protected one can be. This is absolutely vital in keeping up to date with the latest threats as well as foreseeing the trends to come.<\/p>\n<p>So, to test some of AI\u2019s current abilities, I have once again had to take on the mindset of a digital criminal and ethically attack a business!<\/p>\n<p>I recently asked a contact of mine \u2013 let\u2019s call him Harry \u2013 if I could clone his voice and use it to attack his company. Harry agreed and allowed me to start the experiment by creating a clone of his voice using readily available software. Luckily for me, getting hold of Harry\u2019s voice was relatively simple \u2013 he often records short videos promoting his business on his YouTube channel, so I was able to stitch together a few of these videos in order to make a good audio test bed. Within a few minutes, I had generated a clone of Harry\u2019s voice, which sounded just like him to me, and I was then able to write anything and have it played back in his voice.<\/p>\n<p>To up the ante, I also decided to add authenticity to the attack by <a href=\"https:\/\/www.welivesecurity.com\/2020\/04\/20\/hey-there-using-whatsapp-your-account-hackable\/\">stealing Harry\u2019s WhatsApp account<\/a> with the help of a <a href=\"https:\/\/www.welivesecurity.com\/2021\/05\/27\/i-hacked-friends-website-sim-swap-attack\/\">SIM swap attack<\/a> \u2013 again, with permission. I then sent a voice message from his WhatsApp account to the financial director of his company \u2013 let\u2019s call her Sally \u2013 requesting a \u00a3250 payment to a \u201cnew contractor\u201d. At the time of the attack, I knew he was on a nearby island having a business lunch, which gave me the perfect story and opportunity to strike.<\/p>\n<p>The voice message included where he was and that he needed the \u201cfloor plan guy\u201d paid, and said that he would send the bank details separately straight after. This added the verification from the sound of his voice on top of the voice message being added to Sally\u2019s WhatsApp thread, which was enough to convince her that the request was genuine. Within 16 minutes of the initial message I had \u00a3250 sent to my personal account.<\/p>\n<figure><img decoding=\"async\" alt=\"Figure_01\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-1.jpeg\" title=\"\"><\/p>\n<p>I must admit I was shocked at how simple it was and how quickly I was able to dupe Sally into being confident that Harry\u2019s cloned voice was real.<\/p>\n<p>This level of manipulation worked because of a compelling number of connected factors:<\/p>\n<ol>\n<li>the CEO\u2019s phone number verified him,<\/li>\n<li>the story I fabricated matched the day\u2019s events, and<\/li>\n<li>the voice message, of course, sounded like the boss.<\/li>\n<\/ol>\n<p>In my debrief with the company, and on reflection, Sally stated she felt this was \u201cmore than enough\u201d verification needed to carry out the request. Needless to say, the company has since added more safeguards to keep their finances protected. And, of course, I refunded the \u00a3250!<\/p>\n<h2>WhatsApp Business impersonation<\/h2>\n<p><a href=\"https:\/\/www.welivesecurity.com\/2020\/04\/20\/hey-there-using-whatsapp-your-account-hackable\/\">Stealing someone\u2019s WhatsApp account<\/a> via a SIM swap attack could be a rather long-winded way to make an attack more believable, but it happens far more commonly than you might think. Still, cybercriminals don\u2019t have to go to such lengths to produce the same outcome.<\/p>\n<p>For example, I have recently been targeted with an attack that, on the face of it, looked believable. Someone had sent me a WhatsApp message purporting to be from a friend of mine who is an executive at an IT company.<\/p>\n<p>The interesting dynamic here was that although I am used to verifying information, this message arrived with the linked contact name instead of it showing up as a number. This was of special interest, because I did not have the number it came from saved in my contacts list and I assumed it would still show as a mobile number, rather than the name.<\/p>\n<p><img decoding=\"async\" alt=\"Figure 2 \u2013 Fake WhatsApp business account\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-2-fake-whatsapp-business-account.jpeg\" title=\"\" width=\"\"><\/p>\n<\/p>\n<div>\n<figure><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-3-whatsapp-business.jpeg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" alt=\"Figure 3 \u2013 WhatsApp business\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-3-whatsapp-business.jpeg\"><\/a><\/figure>\n<figure><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-4-whatsapp-business-detail.png\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" alt=\"Figure 4 \u2013 WhatsApp business detail\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/2023-11\/figure-4-whatsapp-business-detail.png\"><\/a><\/figure>\n<\/div>\n<p>Apparently the way they finagled this was simply by creating a WhatsApp Business account, which enables adding any name, photo and email address you want to an account and make it immediately look genuine. Add this to AI voice cloning and voila, we have entered the next generation of <a href=\"https:\/\/www.welivesecurity.com\/2015\/12\/30\/5-things-need-know-social-engineering\/\">social engineering<\/a>.<\/p>\n<p>Fortunately, I knew this was a scam from the outset, but many people could fall for this simple trick that could ultimately lead to the release of money in the form of financial transactions, prepaid cards, or other cards such as Apple Card, all of which are favorites among cyberthieves.<\/p>\n<p>With machine learning and artificial intelligence progressing by leaps and bounds and becoming increasingly available to the masses recently, we are moving into an age where technology is starting to help criminals more efficiently than ever before, including by improving all the existing tools that help obfuscate the criminals\u2019 identities and whereabouts.<\/p>\n<h2>Staying safe<\/h2>\n<p>Going back to our experiments, here are a few basic precautions business owners should take to avoid falling victim to attacks leveraging voice cloning and other shenanigans:<\/p>\n<ul>\n<li>Do not take shortcuts in business policies<\/li>\n<li>Verify people and processes; e.g., doublecheck any payment requests with the person (allegedly) making the request and have as many transfers as possible signed off by two employees<\/li>\n<li>Keep updated on the latest trends in technology and update the training and defensive measures accordingly<\/li>\n<li>Conduct ad hoc awareness training for all staff<\/li>\n<li>Use multi-layered security software<\/li>\n<\/ul>\n<p>Here are a few tips for staying safe from SIM swap and other attacks that aim to separate you from your personal data or money:<\/p>\n<ul>\n<li>Limit the personal information you share online; if possible, avoid posting details such as your address or phone number<\/li>\n<li>Limit the number of people who can see your posts or other material on social media<\/li>\n<li>Watch out for phishing attacks and other attempts luring you into providing your sensitive personal data<\/li>\n<li>If your phone provider offers additional protection on your phone account, such as a PIN code or passcode, make sure to use it<\/li>\n<li>Use <a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\">two-factor authentication<\/a> (2FA), specifically an authentication app or a hardware authentication device<\/li>\n<\/ul>\n<p>Indeed, the importance of using 2FA cannot be understated \u2013 make sure to enable it also on your WhatsApp account (where it\u2019s called <a href=\"https:\/\/faq.whatsapp.com\/1920866721452534\">two-step verification<\/a>) and any other online accounts that offer it.<\/p>\n<\/figure>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/your-voice-is-my-password\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI-driven voice cloning can make things far too easy for scammers \u2013 I know because I\u2019ve tested it so that you don\u2019t have to learn about the risks the hard way.<\/p>\n","protected":false},"author":5,"featured_media":8506,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-8505","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8505"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8505\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8506"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}