DeepTrust reposted this
Co-Founder @ DeepTrust | Voice and video call security built for social engineering and deepfakes | Author of Noah's Ark newsletter
Autonomous voice-based scams are here... AI now allows attackers to automate and scale personalized voice phishing and social engineering from 1:1 to 1:many. As reported by Bill Toulas in the article below, UIUC researchers Richard Fang, Dylan Bowman, and Daniel Kang evaluated how ChatGPT-4o can be used to automate these types of attacks. Key Quotes: "Overall, the success rates ranged from 20-60%, with each attempt requiring up to 26 browser actions and lasting up to 3 minutes in the most complex scenarios". "Bank transfers and impersonating IRS agents, with most failures caused by transcription errors or complex site navigation requirements. However, credential theft from Gmail succeeded 60% of the time, while crypto transfers and credential theft from Instagram only worked 40% of the time". "As for the cost, the researchers note that executing these scams is relatively inexpensive, with each successful case costing on average $0.75". "The AI agents that perform the scams use voice-enabled ChatGPT-4o automation tools to navigate pages, input data, and manage two-factor authentication codes and specific scam-related instructions. Because GPT-4o will sometimes refuse to handle sensitive data like credentials, the researchers used simple prompt jailbreaking techniques to bypass these protections".