1 min read
North Korea Responsible for $1.5 Billion Bybit Hack
Originally Published April 9, 2025
7 min read
Cyber Florida SOCAP Team
:
September 16, 2026
Originally published: 07/02/2025
Deepfake technologies pose a threat to a wide range of entities, including but not limited to:
Synthetic media generated by artificial intelligence (AI), commonly known as deepfakes, are rapidly multiplying and becoming more sophisticated. We are currently witnessing a significant surge in deepfake incidents; for instance, there was a 257% rise in recorded incidents from 2023 to 2024, and the remainder of 2025 alone surpassed the total incidents of the previous year.
The potential impacts are severe and varied. These include substantial financial losses for organizations and individuals, as seen in the $25 million fraud at Arup, in which executives were impersonated via a deepfake video. Deepfakes are key in disinformation campaigns that erode public trust and can influence political outcomes, such as through fake calls targeting voters. Furthermore, the technology is used to create non-consensual explicit content and enhance the effectiveness of social engineering attacks.
As outlined in Section I, targets span from the general public and public figures to corporations (particularly in finance) and government entities. Addressing this emerging threat requires a multi-layered strategy. Organizations must implement robust cybersecurity policies, conduct continuous employee awareness training, deploy technical safeguards, and enforce strict verification protocols. Also, individuals need to develop media literacy, enhance personal data security, and be skeptical of certain online information. Official bodies, such as the FBI, are increasingly issuing warnings and guidance, indicating a move towards more collaborative defense.
Threat Type: The threat involves the malicious use of deepfakes, which are AI-generated synthetic media (audio, video, or images) carefully crafted to impersonate real individuals or fabricate events that never occurred. The primary technology empowering deepfakes is Generative Adversarial Networks (GANs). A GAN consists of two neural networks: a 'generator' that creates the fake content and a 'discriminator' that attempts to distinguish the fake content from authentic examples. Through an iterative, adversarial training process, the generator becomes progressively better at creating realistic fakes that can deceive the discriminator, and ultimately, human perception. This technology is leveraged by increasingly accessible software, with tools like Iperov's DeepFaceLab and FaceSwap, and services like Voice.ai, Mur.ai, and Elevenlabs.io for voice cloning.
If successful, deepfake attacks can lead to:
Deepfake technology is accessible to a wide spectrum of malicious actors. This includes individual fraudsters, online harassers, organized criminal enterprises focused on financial gain, and potentially state-sponsored groups deploying deepfakes for complex disinformation campaigns and political interference.
The versatility of deepfakes is seen through various high-profile incidents:
T1566 Phishing: Deepfakes, especially audio (voice clones), are used in vishing (voice phishing) campaigns, aligning with sub-techniques like T1566.003 Spearphishing Voice.
T1591.002 Create/Modify Content: Deepfakes inherently involve creating or modifying content to deceive, related to broader information operations or influence campaigns.
Policies: Develop and enforce robust cybersecurity policies to address the risks posed by deepfake attacks. Integrate deepfake scenarios into incident response plans and conduct regular practice incidents.
Awareness/Training: Implement continuous security awareness training for all employees, leadership, and relevant third parties. Training should cover deepfake identification, the psychological tactics used by attackers (e.g., urgency, authority bias), and established reporting procedures.
Technical Safeguards:
Enforce strong Multi-Factor Authentication (MFA) across all systems and users, prioritizing stronger methods for critical access points.
Deploy AI-powered detection tools for high-risk communication channels (e.g., video conferencing, customer service calls).
Adopt a Zero Trust security architecture, assuming no user or device is inherently trustworthy without continuous verification.
Monitor for Virtual Camera Software in Logs: For live deepfake attacks, attackers may use virtual camera software like Open Broadcaster Software (OBS) to feed the manipulated video into the meeting application. If logging is enabled for platforms like Zoom or Microsoft Teams, security teams can review logs for camera device names. The presence of uncommon camera names like 'OBS Virtual Camera' can be a strong indicator of a deepfake attempt, since this software is not typically used by employees for standard meetings.
Verification and Controls:
Preventative Measures:
Increase Media Literacy and Critical Thinking:
Recognize Potential Red Flags:
Protect Personal Data:
Verify and Report:
Deepfake statistics 2025: how frequently are celebrities targeted?, accessed June 7, 2025, https://surfshark.com/research/study/deepfake-statistics
Cybercrime: Lessons learned from a $25m deepfake attack | World …, accessed June 7, 2025, https://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/
Understanding the Hidden Costs of Deepfake Fraud in Finance – Reality Defender, accessed June 7, 2025, https://www.realitydefender.com/insights/understanding-the-hidden-costs-of-de epfake-fraud-in-nance
Top 5 Cases of AI Deepfake Fraud From 2024 Exposed | Blog – Incode, accessed June 7, 2025, hps://incode.com/blog/top-5-cases-of-ai-deepfake-fraud-from-2024-exposed/
Gauging the AI Threat to Free and Fair Elections | Brennan Center for Justice, accessed June 7, 2025, https://www.brennancenter.org/our-work/analysis-opinion/gauging-ai-threat-free-and-fair-elections
FBI warns of fake texts, deepfake calls impersonating senior U.S. …, accessed June 7, 2025, https://cyberscoop.com/i-warns-of-ai-deepfake-phishing-impersonating-government-ocials/
Top 10 Terrifying Deepfake Examples – Arya.ai, accessed June 7, 2025, https://arya.ai/blog/top-deepfake-incidents
Deepfake threats to companies – KPMG International, accessed June 7, 2025, https://kpmg.com/xx/en/our-insights/risk-and-regulation/deepfake-threats.html
Cybercrime Trends: Social Engineering via Deepfakes | Lumi Cybersecurity, accessed June 7, 2025, https://www.lumicyber.com/blog/cybercrime-trends-social-engineering-via-dee pfakes/
Investigation finds social media companies help enable explicit deepfakes with ads for AI tools – CBS News, accessed June 7, 2025, https://www.cbsnews.com/video/investigation-nds-social-media-companies-he lp-enable-explicit-deepfakes-with-ads-for-ai-tools/
How to Mitigate Deepfake Threats: A Security Awareness Guide – TitanHQ, accessed June 7, 2025, https://www.titanhq.com/security-awareness-training/guide-mitigate-deepfakes/
Deepfake Defense: Your Shield Against Digital Deceit | McAfee AI Hub, accessed June 7, 2025, https://www.mcafee.com/ai/news/deepfake-defense-your-8-step-shield-against-digital-deceit/
FBI Warns of Deepfake Messages Impersonating Senior Ocials …, accessed, June 7, 2025, https://www.securityweek.com/i-warns-of-deepfake-messages-impersonating-senior-ocials/
FBI Alert of Malicious Campaign Impersonating U.S. Officials Points to the Urgent Need for Identity Verification – BlackCloak | Protect Your Digital Life™, accessed June 7, 2025, https://blackcloak.io/i-alert-of-malicious-campaign-impersonating-u-s-ocials-points-to-the-urgent-need-for-identity-verication/
AI's Role in Deepfake Countermeasures and Detection Essentials from Tonex, Inc. | NICCS, accessed June 7, 2025, https://niccs.cisa.gov/training/catalog/tonex/ais-role-deepfake-countermeasures-and-detection-essentials
What is a Deepfake Aack? | CrowdStrike, accessed June 7, 2025, https://www.crowdstrike.com/en-us/cybersecurity-101/social-engineering/deepfa ke-aack/
Determine Credibility (Evaluating): Deepfakes – Milner Library Guides, accessed June 7, 2025, https://guides.library.illinoisstate.edu/evaluating/deepfakes
Understanding the Impact of Deepfake Technology – HP.com, accessed June 7, 2025, https://www.hp.com/hk-en/shop/tech-takes/post/understanding-impact-deepfake-technology
19. Deepfakes: Definition, Types & Key Examples – SentinelOne, accessed June 7, 2025, https://www.sentinelone.com/cybersecurity-101/cybersecurity/deepfakes/
en.wikipedia.org, accessed June 7, 2025, https://en.wikipedia.org/wiki/Deepfake#:~:text=While%20the%20act%20of%20cr eating,generative%20adversarial%20networks%20(GANs).
What are deepfakes? – Malwarebytes, accessed June 7, 2025, https://www.malwarebytes.com/cybersecurity/basics/deepfakes
Complete Guide to Generative Adversarial Network (GAN) – Carmatec, accessed June 7, 2025, https://www.carmatec.com/blog/complete-guide-to-generative-adversarial-network-gan/
How to Get Started with GANs: A Step-by-Step Tutorial – Draw My Text – Text-to-Image AI Generator, accessed June 7, 2025, https://drawmytext.com/how-to-get-started-with-gans-a-step-by-step-tutorial/
Detection of AI Deepfake and Fraud in Online Payments Using GAN-Based Models – arXiv, accessed June 7, 2025, https://arxiv.org/pdf/2501.07033
What is a GAN? – Generative Adversarial Networks Explained – AWS, accessed June 7, 2025, https://aws.amazon.com/what-is/gan/
Overview of GAN Structure | Machine Learning – Google for Developers, accessed June 7, 2025, https://developers.google.com/machine-learning/gan/gan_structure
Unlocking the Power of GAN Architecture Diagram: A Comprehensive Guide for Developers, accessed June 7, 2025, https://www.byteplus.com/en/topic/110690
We Looked at 78 Election Deepfakes. Political Misinformation Is Not an AI Problem, accessed June 7, 2025, https://knightcolumbia.org/blog/we-looked-at-78-election-deepfakes-political-misinformation-is-not-an-ai-problem
What is a deepfake? – Internet Maers, accessed June 7, 2025, https://www.internetmaers.org/resources/what-is-a-deepfake/
Don't Be Fooled: 5 Strategies to Defeat Deepfake Fraud – Facia.ai, accessed June 7, 2025, https://facia.ai/blog/dont-be-fooled-5-strategies-to-defeat-deepfake-fraud/
Top 10 AI Deepfake Detection Tools to Combat Digital Deception in 2025 SOCRadar, accessed June 7, 2025, https://socradar.io/top-10-ai-deepfake-detection-tools-2025/
How to Spot Deepfakes – Fake News – Dr. Martin Luther King, Jr. Library at San José State University Library, accessed June 7, 2025, https://library.sjsu.edu/fake-news/deepfakes
Contributing Security Analysts: Derek Kravetsky
1 min read
Originally Published April 9, 2025
1 min read
Originally Published June 26, 2025
1 min read
Originally published: 04/07/2025 I. Targeted Entities Energy Sector Healthcare Sector Transportation Sector Financial Services Critical...