Voice messages are becoming increasingly popular, and cybercriminals are taking notice. The growing trend in audio content spans various mediums, including audiobooks, podcasts, and social audio networks like Airchat. According to recent studies, voice messages are particularly favored by younger generations, with 84% of Gen Z reporting frequent use.
The Threat of Audio Deepfakes
As voice messages gain traction, so does the risk of them being exploited by malicious actors. The first notable use of AI-generated audio deepfakes in a scam occurred in 2019, when scammers impersonated a UK-based energy firm’s CEO to steal $243,000. Since then, the use of audio deepfakes in fraudulent activities has surged, with a reported 245% increase in audio and video deepfakes in Q1 of this year compared to the previous year.
Aaron Painter, CEO of Nametag, a security solutions provider, highlights that audio deepfakes are a powerful tool for cybercriminals, especially in identity-related attacks. Account takeover attacks, where bad actors gain control of an individual’s accounts, are particularly valuable targets. By leveraging audio deepfakes, attackers can convincingly impersonate individuals to gain access to sensitive information or spread ransomware.
One common method is SIM-swap attacks, where criminals transfer a victim’s phone number to a new SIM card, allowing them to receive verification codes and gain access to financial accounts. Painter predicts an increase in such attacks, emphasizing that the rapid advancements in deepfake technology make it easier for criminals to execute these schemes.
The Next Wave of Cybercrime
Roman Zrazhevskiy, CEO of MIRA Safety, warns that the rise in voice messaging could herald a new wave of cybercriminal activity. Drawing parallels with the evolution from email fraud to text-based phishing, he believes voice messages will be the next frontier. Basic fraudsters might use voice memos to solicit sensitive information like passwords or banking details. More sophisticated criminals could impersonate trusted contacts to exploit victims further, often seeking financial gain.
Zrazhevskiy also anticipates a spike in malware attacks, where victims are tricked into downloading malicious apps through seemingly trustworthy voice messages. The accessibility of deepfake technology means even those with limited technical expertise can create convincing audio fakes, exacerbating the threat.
Younger Users at Greater Risk
Jason Glassberg, co-founder of Casaba Security, notes that younger users, though aware of phishing and smishing risks, may not be as vigilant with voice messages. Voice messages can be more convincing, making it easier for cybercriminals to deceive them. Glassberg foresees audio deepfakes being used in various malicious attacks, from stock market manipulation to virtual romance scams.
Cybersecurity expert Michael Hess adds that audio deepfakes could also pose significant risks in legal settings. For instance, a hacker could create a fake audio recording of a crucial witness, potentially influencing the outcome of a trial.
Detecting Audio Deepfakes
As audio deepfake technology evolves, so do the tools to detect them. However, it’s a constant battle, with bad actors often staying one step ahead. Painter suggests evaluating the context of the message, such as the sender’s identity and the communication channel, as the best approach to identify potential deepfakes.
Jason Glassberg offers several tips for detecting audio deepfakes: listen for unnatural noises or edits, pay attention to breathing patterns, and be wary of out-of-character remarks. Additionally, verifying the authenticity of a message through a different communication channel can be a prudent step.
Conclusion
The increasing popularity of voice messages brings new opportunities and challenges. While they offer a convenient way to communicate, they also present new avenues for cybercriminals. Staying informed about the risks and adopting vigilant practices can help mitigate these threats. As technology continues to advance, both users and security professionals must remain proactive in safeguarding against the evolving landscape of cybercrime.

Discover more from Open Security Labs
Subscribe to get the latest posts sent to your email.







