By Ray Birch
WASHINGTON—How ready are credit unions to fight a new wave of fraud driven by generative AI?
One security expert says a great deal will depend on whether CUs lean on existing methods to train staff to spot the new attacks, or embrace new approaches.
Kelly Miller, managing director and leader in FTI Consulting’s cybersecurity and data privacy communications practice, shared that advice with CUToday.info following a growing number of news reports that describe frighteningly authentic-looking AI-generated scams that are easily fooling staff into making missteps that not only cost the organization money but also bring down entire systems.
Generative AI is a type of artificial intelligence that can create new content, such as text, images, audio, and videos. It uses generative models to produce output in response to specific prompts, which are natural language requests sent to the model. Deloitte's Center for Financial Services predicts that generative AI could enable fraud losses to reach $40 billion in the United States by 2027, up from $12.3 billion in 2023.
“We can be sure that cyber threat actors and scammers are adopting generative AI to enhance their spear phishing tactics, making their attacks more convincing and harder to detect,” Miller said. “One of the most concerning advancements is AI’s ability to replicate a human voice—and it’s convincing.”
Crooks Don’t Need Much
With just a few seconds of audio, which can be lifted from social media video or a voicemail, AI-powered voice synthesis tools can create incredibly realistic imitations, Miller explained.
“If you're doing a promotional video on your LinkedIn page, for example, or even if even if the threat actor had access to a voicemail from you, it only takes a few moments of audio to create something pretty convincing,” Miller said. “These audio deepfake tools are easy to use and widely available for free or at a low cost. A Google search of ‘create audio deepfake’ will give any bad actor powerful tools in just moments. I can’t stress enough how convincing these deepfakes can be. Even tech-literate users can be tricked. With such easily accessible technology, it’s easy to imagine how previously unsophisticated scammers can now pull off new feats.”
The advanced spear fishing tactics are not just limited to duping individuals into transferring money, they can also be used to gain the information needed to obtain credentials to infiltrate a credit union’s systems for purposes of encryption or data exfiltration, Miller noted.
The best thing financial institutions can do to defend against these evolving threats is proactive education, emphasized Miller.
“Any security training program should keep pace with tech advancements,” she said. “Don’t just dust off the same training as last year. Run phishing tests regularly and incorporate audio and video deepfakes. Engaging, real-time educational content should be delivered regularly to both staff and members. For example, share periodic roundups of scams encountered at your institution, with detailed examples, so employees and members know exactly what to look out for. This content can be plugged into your regular communications channels, such as newsletters or marketing campaigns.”
Build A Communications Strategy
Miller also recommended credit unions build a communications strategy to be able to quickly “correct the record” against any misinformation.
“If fraudsters impersonate your employees to extract information from members, you must be able to swiftly provide verifiable information,” Miller said. “Monitoring social media and online discussions about your organization is essential to detect any emerging threats or fraudulent activity. Establish a rapid content approval process to post official statements on your website as a single source of truth. Regularly remind employees and customers of your communication policies—such as, ‘We will never ask for your password over the phone.’”
Miller said she does not have a true sense of how well credit unions are prepared to defend against these new threats.
“However, I will say that with any financial institution, the more prepared you are the better,” she said. “You don't just dust off the phishing education program you had last year, or rely on a communication strategy that's a couple years old. At this point the bad guys are fast, and they're moving even faster. So, financial institutions would be very wise to make sure they're updating this training regularly. They should be talking to their boards to make sure they're meeting the growing challenges from these threat actors that are targeting financial institutions.”
