By Ray Birch
CHICAGO—With the threat from fraud already top-of-mind for most credit union leaders, a new warning is being shared over even more sophisticated risks posed by artificial intelligence and third parties, says one expert.
The chief challenge: AI is making crooks’ attacks even more difficult to detect.
“When you look at your third-party risk, it’s important today to really look in the mirror and identify if you have a good inventory of who your critical partners are—high, medium and low in terms of their importance to your business,” advised Kory Daniels, global chief information security officer at Trustwave. “Look at what type of compliance or regulatory concerns you have in the data. Do you even have a good inventory of that? And then, beyond regulatory compliance, know what is your threat exposure tolerance, or what is your exposure risk given the nature of the data transactions.”
The New Achilles Heel
Daniels said Trustwave is seeing an increase in the exploitation of financial institutions by threat actors leveraging those third-party relationships.
“They are saying, how can we find the Achilles heel of an organization, particularly financial services, who have made significant cybersecurity investments?” he stated. “And they are coming in through the third parties.”
As CUToday.info reported, in the first month following a new rule requiring credit unions to report cyber-incidents to NCUA, the agency is reporting it received 146 such reports, more than half of which were due to third-party compromises.
Daniels said the criminals see third parties as an easier access point to banks and credit unions, and understand financial services organizations are highly interconnected.
“This interconnection ranges from inter-bank connections, connections to the central banks and regulatory agencies, heavy use of third-party vendors and support providers, and the use of third-party code, web services, and APIs, among others,” he explained. “This interconnectedness leads to an exponential increase in attack surface and threat vectors.
“They see third-party organizations as a more successful opportunity to get a direct pathway to a financial services organization,” continued Daniels. “Financial institutions should really be paying attention to third-party risk right now.”
A Twist on Phishing Scams
Trustwave has found that with the advancement of AI, criminals are leaning more on phishing scams to penetrate organizations, because AI makes their attacks harder to detect.
“Trustwave SpiderLabs consistently finds that phishing is one of the most effective methods attackers use to gain an initial foothold in financial services organizations,” Daniels said. “However, this method is highly dependent on the quality of the lure, the writing style, and the contextual and grammatical clues given in the phishing email. These issues have often been the weakness of phishing attacks, particularly as security awareness training has continually taught personnel what to look for.”
LLM Risk
But now there is generative AI and large language models (LLMs). LLM is a type of language model notable for its ability to achieve general-purpose language understanding and generation.
“The quick maturity and expanded use of LLM technology makes the crafting of phishing emails even easier, more compelling, highly personalized, and harder to detect,” Daniels explained. “Our team regularly encounters and analyzes phishing emails with malicious attachments or links against our financial services clients. We see that as LLM technology progresses, creating these compelling phishing emails will likely easier, and they will be more effective as an attack vector. We’re also seeing an increase in deepfakes as a result of more sophisticated technology.”
Deepfakes are videos of a person in which their face or body has been digitally altered so that they appear to be someone else.
A ‘Revolutionary’ Threat
Daniels added that lately Trustwave has seen the emergence of LLMs like WormGPT and FraudGPT on underground forums, highlighting the potential cybersecurity risks posed by their criminal use.
“WormGPT and FraudGPT can craft convincing phishing emails without many of the red flags that we teach users to identify phishing emails by including items like picking out misspellings, grammar mistakes, and general clumsiness of writing that may indicate that the author is not a native speaker,” he said. “This has really revolutionized the way threat actors can increase the speed and effectiveness of their attacks, as well as their likelihood of success.”
Like all financial institutions, credit unions remain prime targets for fraudsters, Daniels reminded. Trailing only behind the healthcare industry, the financial services sector ranks second in terms of the cost of a data breach. In 2023, the average cost of a data breach in the financial services sector amounted to $5.9 million, compared to the industry average of $4.4 million, according to data from the Ponemon Institute, Daniels noted.
A Double-Edged Sword
He said being heavily regulated is a “double-edged sword.”
“While it incentivizes increased protections, it can also make it complex and expensive for financial institutions to implement and maintain effective cybersecurity programs,” he said.
Daniels noted consumers anchor their financial decisions on trust, and especially with credit unions.
“If trust is eroded by the compromise of personal data or account information, customers can and will take their money elsewhere. This means they are a prime target for cyber criminals who will try to exploit this dependency on trust,” he said.
