Focus this month | Social Engineering and Deepfake Fraud

Social Engineering and Deepfake Fraud: How to Protect Your Business

Most businesses put their cybersecurity budget where it's easy to see. Firewalls, antivirus, backup and recovery, all doing exactly what they're built to do.

But none of it stops someone picking up the phone and just asking for what they want.

That's social engineering and it's quietly become the way most successful cyberattacks get in, not through malware sneaking past a firewall, but through one person trusting another at the wrong moment.

It doesn't look like a hack anymore

Ask someone to picture a cyberattack and they'll probably think of shady code, flashing red warnings, a hoodie in a dark room. That's not really what it looks like anymore.

More often it's an email from the MD, asking finance to push through a payment before a call in 10 minutes. Or a voicemail from a supplier chasing an invoice, with bank details that have "recently changed."

Deepfakes are what's shifted this. Cloning a voice used to take real effort and a fair chunk of audio to train from. Now a few seconds pulled off a podcast or a recorded meeting can do it.

Why it works so well

Social engineering doesn't exploit a gap in your systems. It exploits how people are built to behave.

Most of us are wired to be helpful, to respond fast when someone senior asks for something, and to trust colleagues and suppliers we've dealt with before. An attacker doesn't need to break through a firewall if someone inside just opens the door.

And urgency does most of the work here. It pushes people out of careful thinking and into reaction mode, which is exactly the state a convincing fake is counting on.

Spotting it before the money moves

A good chunk of these attempts still come in through familiar routes such as email or an account that's already been quietly compromised without anyone noticing. Our endpoint security and network security services, powered by tools like Sophos, WatchGuard and ESET, give us eyes on unusual logins and odd account behaviour, so the warning signs show up before a fraudulent payment or request lands on someone's desk.

What happens when someone gets caught out?

No amount of training makes a team immune. If a social engineering attempt does lead to a compromised account or a file that shouldn't have been changed, a proper backup and recovery setup is what turns that into an annoying afternoon instead of a genuine crisis.

A few things worth doing

  1. Make sure to verify anything involving money. If the request came by email, ring the person back on a number you already have, not one sitting in the message itself.

  2. Treat urgency as a warning sign. A genuine request can survive a five-minute callback.

  3. Talk to your team about this properly, not just a line in a policy document but actual examples of what a faked voice or video might sound and look like.

  4. And take a look at who can actually approve payments or system changes. Keep that list short and make sure everyone on it knows why.

Technology can flag plenty of these scams, but it can't stop someone believing a voice they recognise. The businesses that get this right generally aren't running more software than everyone else, they’re just prepared and well trained for this scenario.

If you'd like to find out where your business might be exposed, get in touch with our team today to learn more.


Found this article of interest? Join our free webinar on Thursday 1st October all about the world of Deepfakes! Featuring TV Cybersecurity Expert, Jake Moore.

Jake Moore, Cybersecurity Awareness Specialist at ESET, goes deeper into deepfakes and social engineering in our upcoming webinar: Cybersecurity: You've Got This! on Thursday 1st October.

Be sure to book your place, don’t miss it!

Next
Next

Webinar | Cybersecurity: You’ve Got This!