ADVERTISEMENT

How to fight deepfakes – a new guide

OWASP has published a guide discussing how AI is being exploited to execute cyberattacks and how to address these risks.

Deepfakes

Image by Cybernews.

Nihad A. Hassan
Nihad A. Hassan Contributor
January 1, 2025 Updated: July 30, 2025 5 min read
Neilc Jesse William McGraw emmaw chrissw
Get our latest stories today on Google News
Add us as your Preferred Source on Google.

What is deepfake content, and how is it produced?

  • Text content: ChatGPT, Claude, and Google Gemini
  • Images: DALL·E 2, Stability AI and Wombo
  • Video: Synthesia, Deepbrain AI, Elai and Pictory
  • Audio: AudioCraft, AssemblyAI, AWS Transcribe and ElevenLabs

Objectives of deepfake attacks

  • Financial gain through fraud by impersonation
  • Job interview fraud
  • Impersonation to further cyberattacks (such as initial access)
  • Mis/Dis/Mal information

Preparation

  • Authentication evasion: For example, using an AI-generated voice to convince the technical support employee to reset the target user account password.
  • Impersonation: Such as a CEO fraud scheme to request making illegal transfers from a CFO. A recent example happened in early 2024 when a finance worker at a multinational company was deceived into transferring $25 million to fraudsters who used deepfake technology to impersonate the company's chief financial officer during a video conference call.
  • Reputational damage: Impersonating key employees and top management and spreading video/audio recordings of them giving incorrect statements about their company work or hateful speech to damage the company's reputation against the public.
  • Deepfake employment interviews: Threat actors use deepfake videos and stolen personal data to convince HR personnel to hire them during online job interviews. The final aim is to gain some level of corporate access to sensitive data or IT systems as a part of their new job role.
  • Misinformation: spreading fabricated information (audio, video, and images) using AI technology to spread rumors and impact a particular company's stock prices or to prevent other companies from partnering with it. Misinformation can also spread via text content, such as spreading fake news.

Risk analysis

Defense assessments

  • Sensitive data disclosure – Review your business policies about sharing and accessing sensitive information, including HR and third-party provider information.
  • Helpdesk: Audit sensitive workflows such as password rest routine, authorizing computing devices for multi-factor authentication (MFA), and how authentication failure should be handled.
  • Financial transactions: Audit how financial transactions are executed within your company. Ensure strict personal verifications before releasing funds to external partners.
  • Event response: Evaluate how your organization responds to deepfake incidents. This includes its detection, communication, and containment strategies.
ADVERTISEMENT

Establishing a deepfake incident response plan

  • Incident identification and verification: Establish workflows or protocols to quickly verify whether a particular media content is authentic or synthetically generated using detection tools and human expertise.
  • Response escalation: Define clear guidelines for escalating deepfake incidents to relevant teams - legal, technical, communications, or executive leadership.
  • Mitigation strategies: Identifying what actions your organization should take to contain the impact of the deepfake incident, such as issuing counter-statements, disabling compromised user accounts, or notifying stakeholders about the incident to avoid any legal liability or public embarrassment.

Deepfake awareness training

Event-specific guidance

Financial gain through fraud by impersonation

Impersonation for cyberattacks

Job interview fraud

Mis/Dis/Mal Information

  • Political manipulation: Interfering in elections by spreading fabricated media to influence voters, destabilize governments, and undermine public trust in democratic processes.
  • Corporate sabotage: Spreading fabricated news or announcements to impact stock prices, disrupt market stability, or damage competitors' reputations.
  • Social engineering and fraud: Employing extortion tactics by threatening organizations with the release of fabricated content designed to harm their reputation unless they pay money to the attackers.
  • Health disinformation: Circulating false claims to undermine public trust in healthcare institutions. For example, encouraging people from taking vaccines by fabricating adverse effects, which can impact the stock value of pharmaceutical companies producing the vaccine.
ADVERTISEMENT