Industry Briefing

The six high-cost AI attacks every CISO needs to know

Here’s what AI attacks actually look like

Discussions about AI-powered attacks happen behind closed doors, tucked away in internal incident reports and confined to candid exchanges between peers at industry conferences. This secrecy leaves security leaders with an near-impossible task: responding to threats they can’t see.

That’s why we’re breaking down the anatomy of AI attacks: what they look like, how they work, and why they’re able to slip past traditional defenses.

Here are the stakes: A multi-million dollar wire transfer after a deepfake video call.1 A North Korean operative moving through your hiring pipeline.2 An IT helpdesk handing over SSO credentials to someone posing as an employee.3

Attacks like this are playing out at companies everywhere, everyday. And with AI-driven attacks growing by nearly 14x in six quarters,4 organizations can’t afford to treat this as low-risk threat.

The scams are here. Is your security strategy ready for them?

  • Fake job candidates
  • Executive impersonation
  • IT helpdesk attacks
  • Contact center attacks
  • Vendor or partner impersonation
  • Wealth management scams

AI has forced security leaders to doubt the channels they trust

Talk to a CISO right now and one word keeps coming up: uncertainty. Uncertainty about how AI attacks will reshape security strategies. Uncertainty about where to invest. Uncertainty about where the real risk even lives.

That’s exactly why we created the CISO Deepfake Defense Council.The Council brings together a select group of highly regarded security executives from seven Fortune 500 enterprises and other category-leading organizations across a broad cross-section of industries, including technology, financial services, healthcare, life sciences, defense, enterprise software, cryptocurrency, and cybersecurity. The Council is focused on delivering strategic guidance to help enterprises understand, prepare for, and defend against deepfakes—one of the fastest-emerging threats to trust and identity.

We interviewed these leaders individually and as a group, probing to understand how they’re thinking about the new enterprise threat landscape.

Takeaways from the CISO Deepfake Defense Council

  • Unauthorized access is just one step in a longer attack chain
    Impersonation (deepfakes or otherwise) opens the door. Once a bad actor gets in, they become an insider threat, often with the access they need to cause system-wide damage.
  • Telling the difference between a good bot and bad bot is about to be critical
    As companies incorporate AI into their workflows and authorized agents begin handling tasks, companies will need a way to discern what is an approved use of AI and what is suspicious, unauthorized activity.
  • Attackers are playing in blindspots
    It’s nearly impossible to defend against what you can’t see. That’s why bad actors attack the channels that seem low-risk or protected (e.g., hiring or vendor comms). Without visibility, leaders can struggle to calculate exposure.
  • Perceived weak points vary across industries
    One security leader points to helpdesk impersonation as a critical risk, another points to contact center attacks. This variation seems to be driven by industry-specific priorities. For example, financial services may prioritize high-risk customer or client interactions that can end in direct financial losses. Leaders from other industries may perceive different interactions as more vulnerable.
  • Companies need detection that works with them, not against them
    Adoption of deepfake detection needs to integrate seamlessly into existing workflows. Roadblocks will directly impact whether people utilize the tool when its needed.
“A healthy immune system needs to be proactive, anticipating threats before they attack. In the age of deepfakes, enterprises need to approach defense in the same way: building their cybersecurity strategy for resilience and adaptability.”Jim Routh, Chairman of The CISO Deepfake Defense Council and former 6X CSO/CISO in financial services and healthcare

How CISOs think about the new threat landscape

Council members mapped AI attacks by reputational and financial risk. Answers varied, but six threats rose to the top.5 This briefing covers those six.

New threat landscape

Sources and disclaimers

Fake job candidates

Continue reading

Move from understanding to action

Fight back against AI attacks with Pindrop.

Schedule a demo