The account is fake, the voice is a copy, but the trap is real: Be careful who you are talking to!

Thanks to advancing technology, cybercriminals can hide their identities and locations much more easily. Cybersecurity company ESET has issued warnings that criminals can carry out fraud via WhatsApp using next-generation social engineering attacks.

12punto

Machine learning and artificial intelligence are advancing at a rapid pace and are becoming increasingly accessible to the masses. Today, thanks to powerful computer technologies and media attention, artificial intelligence has reached global interest. Ever since the concept of artificial intelligence became popular with films like Blade Runner and The Terminator, people have been wondering about the potential of what this technology could create in the next step. Cybersecurity experts, on the other hand, are warning that we may soon encounter creative and highly sophisticated attacks with harmful consequences.

NEXT-GENERATION SOCIAL ENGINEERING ATTACKS

Cybercriminals target the individuals they want to trap or their social circles, copying voice samples belonging to these people from sharing platforms. They usually choose the people they want to trap from among business owners or senior executives. They create fake voice messages with the voice samples they have cloned. To make their attacks more sophisticated, criminals also take over the WhatsApp account of the targeted person and send fake voice messages to the person they are targeting or their social circle.

HOW TO TAKE PRECAUTIONS AGAINST VOICE CLONING FRAUD?

Follow business and approval processes

Verify people and processes; for example, verify all payment requests with the person (supposedly) sending the request, or even double-verify if necessary, and ensure that transfers are approved by two employees in your company.

Follow the latest trends in the technology world and adjust your employees' training and security features accordingly.

Organize special awareness training for your employees.

Use multi-layered security software.

Limit the amount of personal information you share online. If possible, avoid publishing your address or phone number.

Limit the number of people who can see your posts and other content on social media.

Be careful against phishing scams and other attempts to obtain your personal information.

Use two-factor authentication (2FA), such as an authentication app or a hardware authentication device.