Vendor or partner impersonation

How a vendor relationship becomes a vulnerability

External partners, vendors, and suppliers are often vital for a company’s operations, which is exactly why attackers impersonate them.

Third-party relationships are invaluable—and easily manipulated

Vendor impersonation and partner impersonation are some of the most underestimated risks enterprises face right now. These are relationships built on trust, and they operate across external systems that are inherently harder to monitor and verify. Unlike internal communications, the channels aren’t as secure. An attacker posing as a trusted supplier just needs to send a realistic email, a cloned voice message, or a fake invoice to break through defenses.

A financial institution (and Pindrop customer) believed initially they only had a problem with deepfakes in hiring. After only deploying Pindrop Pulse® for meetings to their hiring team, an employee outside their recruiting team flagged a supposed “vendor” as suspicious. They asked for access to Pulse and, within seconds, caught a deepfake.1

Real world example

A cybersecurity company reported attackers using AI to create realistic email threads and fake invoices that looked legitimate. Payments were approved and sent before anyone realized the vendor wasn’t real.2

[!CTA]

title: Humans reliably catch AI manipulation only ~50% of the time³

text: A coin toss. That’s how good humans are at catching deepfakes. Technology purpose-built for detection is just better at spotting deepfakes than humans. This tech looks at the subtle qualities like resonance, timbre, and facial movements that separate human media from AI.

Read the datasheet to learn how it works.

button: Download the datasheet

[/]

Sources and disclaimers

Conclusion

Continue reading

Move from understanding to action

Fight back against AI attacks with Pindrop.

Schedule a demo