Well, anyway, Chief, I think we should strengthen our security measures. Absolutely, but we'll need a countersign so that when I come to your apartment later to question Tanya, we'll know we're not speaking to impostors. Just to be on the safe side, Chief, why don't we use a double countersign? Good idea.
Oh, here's a good one. I'll say that migrating birds fly low over the sea. You say shadeless windows emit no light. Then I'll say the wingless dove protects its nest, and you say the toothless tiger rules a restless jungle. Have you got that?
Right, Chief. Do you guys recognize the old TV show Get Smart? Yeah?
So, you might be wondering why at an identity conference do we have a clip about signs and countersigns from Get Smart. We're going to get into that during the entire talk here, but my name is Navroop Mitter, and I'm the founder and CEO of ArmorText. We've been recognized by industry analysts as a leading provider of secure out-of-band communications for incident response, security operations, and threat intel sharing.
And the connection may not be obvious, but there's definitely a connection between the need to have better identity validation and your secure out-of-band communications during a crisis. John, over to you.
Hi, I'm John Tolbert, Director of Cybersecurity Research here at Kupinger Coal, covering a number of different topics, including fraud prevention, which is relevant for our discussion today. I just realized we need the clicker to move from slide to slide. There we go. That's us. Contact information. There you go. My beard was blacker back then, I just realized.
So, yeah, about fraud. So there's lots and lots of it, as we all know. We've been talking about it a bit here and there for the last couple of days. Statistically, just reflecting from some of the things I may have mentioned yesterday, 99% of companies have reported account takeover attempts, and 63% of the time they've been successful. So think about the impacts of that, even on a workforce side.
Typically, we talk about account takeovers, and we're talking on the consumer side, but this is happening in the enterprise, too. So when organizations suffer these kinds of account takeovers, that's often the toehold into the organization, such that they can launch other attacks. And one of the things that we're concerned about in this talk today is impersonation attacks. What do you do in the event malicious actors get into your organization and then can much more easily impersonate CFOs, CEO, line managers, and whatnot?
Yeah, it's rather interesting. If you look at the statistics, there's been a 3,000% increase in attacks. One in two companies now say that they've been subject to an impersonation attack. Yeah.
Yeah, there have been signs of that. I mean, and think about identity verification. We've seen a 700%, I think, roughly increase in face-swapping attacks. So even when you have, let's say, employees or contractors that are signing on, getting onboarded, there have been many, many cases of illegitimate people getting credentials because they're using fake IDs and AI-generated photos and things like that. So I think this actually brings us to our next slide here, right? We are currently in an arms race for adversaries and the deep fake detection technologies that are in use.
If you think about the slide that's behind me here, right, we've got image generation, voice generation, virtual avatars, and video creation technologies that were all developed with legitimate use in mind, media and entertainment, and a whole host of other things, including your marketing efforts. The reality is, is these same tools are being leveraged by the fraudsters. If we look at the upper left-hand corner, right, in the red, we've got these same logos that we see for legitimate use cases being used now for illegitimate use.
We go down to the lower right, and we've got a whole set of deep fake detection technologies. This is by no means a comprehensive overview, right? This is much like a cram into one slide. But when we think about it, ultimately, these folks are in a cat-and-mouse game. The deep fake detection technologies get better at detecting a deep fake. The adversary now finds a new countermeasure to get past the latest detection capabilities. And they're going to constantly be in this arms race, one-upping each other.
And when we actually look at the way the technologies are working in the field today, we find that even in this arms race, we're already losing the battle. I know this is going to contradict what some of the vendors out here will want you to hear, but when we look at a recent study that just came out, I think, about a month ago in Australia, right, the Australian CSIRO, I think that's their national security agency, sorry, their national science agency, alongside SKKU University out of South Korea, they did an assessment of the leading 16 providers of deep fake detection technologies.
And what they found was not, and actually this is a quote, they found that none could reliably identify real-world deep fakes. Top 16, none could identify the deep fakes.
Of course, that can be a problem if you care about fraud and identity verification. Yeah, you know, we were just talking in an earlier session about voice cloning.
And, you know, there was a story in the papers just a few days ago about the rise of audio messages being sent through social media and messaging apps that, you know, might say something like, hey, mom, I lost my wallet, I lost my phone. You know, please send some money to this bank account, it's my friend's bank account.
And, you know, all they need to get going with that by them, you know, the malicious actors, the fraudsters, all they really need is about five seconds of audio and then they can manipulate that and say, you know, whatever you as a malicious actor type into the blank to make it say. That's right. And a study that was just published in Nature actually found that humans can only reliably detect that an AI voice had been used and that you were now talking machine 60% of the time. That means about 40% of the time they could not figure it out. And that's in a laboratory setting.
So if you think about the scenario that John is describing, that's duress. You're now worried that your child might be in danger. Who knows your voice better than your mom? Not every mom falls for this, but enough have fallen for it that it's made the headlines. And the point is, is under duress, it's going to be even more difficult to rely on the human training element to detect the deep fakes. We're going to have to find other methods that we can reliably use that are incurvious to simple technology-based issues.
Because at the end of the day, you could spend and buy one of these detection technologies in the lower right, right in the green box, and then find that they're not keeping up with the pace of current attacks and suddenly have to re-spend on something brand new all over again. Most of us don't have unlimited budgets.
Yeah, to your point, you know, about voice cloning, I mean, some of the things that we've learned about that is, you know, right now there are limitations to how high quality of a product can they make. And, you know, there are certain things that you can do to kind of detect that. Like sometimes they add reverb, you know, that doesn't exactly sound natural. It will compress it. It doesn't have the natural, like, ups and downs of normal human speech. But these are things that you don't really pay attention to when you are under duress, like you were saying, Navroop.
And besides, you know, if we take the time to teach everybody, okay, if you get a message and you're not quite sure if it's real, listen to see if there's some unnatural reverb in the background. I mean, three to six months from now, the bad guys are going to figure out that that's the thing that can get them caught and change that. So it can be difficult, I think, to detect deep fakes, you know, especially given the number of different media that they can come through.
I mean, we're just talking about voice right now, but video. Of course, there was the Hong Kong situation. And there are a number of these tools that you see here. Some are open source. Some are apps that you can download. They're on the App Store.
So, you know, there are a lot of these things that are legitimate tools that are just being misused. It's not like they're all bad software designed specifically for malicious actor use either.
Now, there is plenty of that as well. Now, when we're thinking about duress, there are few greater things that create duress in the enterprise than an actual cyber attack or a breach.
And so, John, I know you had some thoughts about the increased vulnerabilities here. Yeah, just a short one. The studies show that once an enterprise has been attacked, they're highly at risk for a follow-up attack within six weeks. And I think the same thing goes personally. If a fraudster knows you're going to fall for something, then they're going to come back in a short period of time later.
Yeah, and when you actually think about some of the things that take place during attacks, and this is kind of that intersection of why this topic of identity validation is so important during an incident, it's that likely you're going to wind up in a situation where your communications, particularly those of your incident responders, your legal and other security professionals, are actually being surveilled. Now, if we think about what took place during the attack on Microsoft, Microsoft has had to say this publicly in their own 8K filing with the U.S.
Securities and Exchange Commission last March in 2024, the communications of their cybersecurity and their legal professionals were surveilled by the adversary. So if Microsoft can't protect Microsoft on Microsoft while Microsoft is being breached, how are they going to protect your communications during a breach? If the adversary is able to insert themselves into the communications and listen in to your remediation and response efforts, how are you supposed to conduct those without them staying a step ahead? Good point. And I can actually add to that.
Recently I was working on some yearly reports, yeah, just multiple attacks are actually, as a matter of fact, there's a thing in 2025, and I could say that there's this diversion of attack and then you're being attacked once and then actually that's not the real attack, the target of the attacker. And it's like the similar logic, what I can say is like the drug dealers are sending the bait first and then the bigger one is like being processed behind the scenes. So it has the same logic of this.
And we have seen a huge portion of attackers using AI in their second attack and then causing more damage eventually, yeah. Yeah, absolutely. Distraction over here while you're committing the real crime over here. Exactly. You oftentimes see that with physical and cyber or cyber to physical. You see them going both directions now. We've seen elements of that.
In the case of some of those, again, impersonation was actually being used to potentially create a situation where you might engineer a flash mob to show up in a certain location to distract all personnel so you can actually launch your cyber attack in parallel to this flash mob that has shown up where the celebrities who are being impersonated were never even there in the first place. This is actually part of another talk we gave recently to a bunch of physical heads of security for large banks.
But this thing brings us full circle to where we started, that video of the signs and counter signs. If we think about repurposing low-tech espionage techniques, right, this is Cold War era spy craft, you actually have the opportunity to potentially start to use approaches that don't require significant investment and that will continue to work even when one of the detection technologies isn't necessarily able to keep up. Things like signs and counter signs or challenge and response verification kind of fit into the same category, right?
These are engineered to elicit a certain response, and should I say something like what the video was showing earlier and I get the wrong response, I should then be suspect of whether or not I'm speaking to the right individual. So on a video call, I might have some sort of personal question that I know that only this respondent would have access to, or I might have a set of pre-approved, pre-stored questions to ask and statements that are somewhat ridiculous, that just like the, this is the shadeless tiger in the jungle, would be the right response to get back, right?
I could actually have that at scale, stored in out-of-band comms capability, something that could be actually used during an incident. The visual recognition signals or pre-arranged behavioral cues and even, frankly, the distinctive physical totems, these kind of all go into roughly the same category as well. I could indicate that, hey, if we are under duress, if there's an actual incident taking place and I'm calling you about identity, I'm going to expect to see you tapping your index finger or your middle finger twice every so often during a call.
Or, hey, remember that challenge coin that we introduced that everyone has to have, otherwise they're buying drinks at the bar? Well, during incident calls, I expect to see that challenge coin flash at the very beginning when you're putting it into your breast pocket. Whatever the case may be, you can actually use visual cues, behavioral cues, or even physical totems to help address whether or not this is the real person.
And you want to be sure to actually kind of think through their use so that in case a set of calls from a previous incident had been intercepted, that the same visible signs couldn't be replicated during this latest deepfake. Yeah, and this is something that works on the personal level too for those cases where, you know, social media messages come and asking for money.
Yeah, absolutely. This is actually a recommendation we've made to parents and grandparents. Establish these with your children and grandchildren as well so that you can actually use the same techniques there. This is something I'm talking to my aging parents about now every day as well. I will never call you asking for money. If I need money, I'm going to my brother or my sister-in-law. I'm not coming to you. And here are the codes that I'm going to use to let you know I'm okay or not. We need to start doing the same thing in the enterprise.
Now, this brings us to a little bit of story time. I know we've all been through a number of breaches and a number of security incidents. There are two that I think we want to talk about today. There was one in which there was a CISO, a chief information security officer, who suddenly received a frantic call from his staff. He had just left for vacation, you know, had just gotten off a flight. He's now in a foreign country, receives a call from his staff, and they say everything is down. Networks are down. We cannot get to a single system.
And he's like, all right, well, you guys have trained for this. Let's start executing the incident response plan. The problem is the incident response plan is stored on an internal system and they don't have access to it. No one has access to the updated plans, the updated contact lists, comms capabilities. Everything is out. Eventually, the CISO says, you know what? I actually have a printed copy in my desk drawer at the house, but there's no one home. I can't reach the neighbors. I'm authorizing you to break into my home. CISO authorized his personnel to break into his home.
He alerted the alarm company that he was doing so, so the alarm would be turned off. The police would not respond. In this case, this occurred in an era where deep fakes weren't at the level, where they had to worry about whether or not that was a legitimate person calling the CISO or whether it was a legitimate CISO now interacting with the personnel authorizing a break into their home. And the alarm company didn't have to worry about that either. But in an era of deep fakes, the question is, what if? So there are two things.
One, all of those communications plans and response plans, prox and procedures, should have actually been placed in some sort of out-of-band capability that would be available to you even during instant response. Despite them being there, if you do have to seek authorization from people and you're concerned about the potential identity, these same identity validation techniques we were just talking about, the signs and countersigns, the challenge and response, the physical totems, should have been employed to validate who was on both sides of that call. Agreed. Yeah.
The second story I think we were going to talk about actually involves something a little different. In this case, rather than bring down the enterprise and make it so that they were scrambling, right, actually in the last story, even once they got those procedures back up, because everything was down and now there was some doubts about things, you know, it took them a few days to start to actually start to implement things because it took a little while to coordinate all that. But this next story is actually worse in many ways. The adversary did not bring down the network.
The adversary actually surveilled. But prior to them being discovered on the network, they actually did something rather interesting. They took the SharePoint and they found that the contact list for everyone and the instant response plans were on the SharePoint. So they modified the contact list to insert their own contact details. Imagine what you could do if they legitimately dial you into the conference call now. They're like, hey, we don't trust people dialing in. We're not seeing that passcode.
We're going to dial outbound to every person to make sure we bring you in through your vetted number. You're picking up on your cell phone. We know it's you. They dialed you in. And yet what you really did was dial in the adversary and let them listen into your entire response and remediation effort. Same kind of thing. Out-of-band capabilities would have helped, but also having all those contact list IRPs, et cetera, in an immutable, some sort of out-of-band capability would have been tremendously valuable. So you're going to want to look for those two things. So we're up at time.
I guess I'll just summarize my part in saying, yeah, we're back at the point that I think we have to consider low-tech ways of doing identity verification from time to time as the situation dictates. Yeah, and I think there is a little bit of hope for the future. We haven't announced it yet technically, which is why marketing made me pull some of the details off of this slide. My marketing team is going to kill me for even having it here.
But we actually are working on ways to actually have better just-in-time in-crisis out-of-band identity validation that actually feeds into your out-of-band comms capabilities so you actually have the ability to do everything we were just talking about in a more streamlined fashion, somewhat technology-enabled, rather than being fully dependent on only manual processes. We're going to have to find better ways because otherwise the deepfakes are going to keep beating us. All right. Thank you very much.
Thanks, Nivrup. Yeah. Cheers. APPLAUSE