Posted in

INTERVIEW: Ping Identity on how Deepfake is a threat to businesses and individuals

Ping Identity
Johan Fantenberg, Director at Ping Identity

In this interview with Johan Fantenberg, Director at Ping Identity, we discuss the growing threat of deepfakes to businesses and individuals, emphasizing their use in cyberattacks, identity fraud, and disinformation.

Deepfakes can deceive people into performing unauthorised actions, spreading misinformation, or damaging reputations. A Ping Identity survey shows that only 56% of respondents in APAC feel confident identifying deepfakes of their CEO, while 55% are worried about AI boosting identity fraud, says Fantenberg.

AI and machine learning are used both to create and detect deepfakes. Cybercriminals leverage large datasets to craft highly realistic deepfakes, mimicking human behavior. This makes detection harder, even for experts, as seen in an example where a deepfake of a CFO tricked a company into transferring $25 million.

“The importance of being aware of these threats and implementing robust security measures is becoming vital. Ensuring the authenticity of digital communications and protecting digital identities are crucial in the fight against the growing threat posed by deepfakes,” he says.

Challenges in deepfake detection arise as the technology evolves, making it difficult for both people and machines to distinguish real from fake. Businesses are advised to implement identity threat detection and response (ITDR) systems and decentralized identity (DCI) practices to mitigate risks.

To protect against deepfakes, organizations should adopt a multi-layered approach with identity and access management (IAM) solutions, multi-factor authentication (MFA), and biometrics. Employees should undergo regular training to recognize suspicious activity. Additionally, individuals and organizations should remain vigilant, verifying communications through trusted channels and reporting deepfakes to authorities.

Here’s the full interview on how deepfake can impact businesses

Business News Singapore: How big of a threat are deepfakes today, particularly to businesses and the average person?

Johan Fantenberg: Deepfakes have major implications for people’s security and privacy as well as discussions about cybersecurity and digital identity in a world that’s increasingly digital. Cybercriminals can deceive users into paying money, divulging personal information, or performing unauthorised transactions by using deepfakes in social engineering attacks. Deepfake content can aid in the spread of false information, making it more difficult for people to defend their reputations against false accusations or behaviours that are depicted.

According to a recent survey by Ping Identity, just 56% of respondents in APAC showed high confidence in their ability to spot a deepfake of their CEO, while 55% of respondents are extremely concerned that AI technology could boost identity fraud. The importance of being aware of these threats and implementing robust security measures is becoming vital. Ensuring the authenticity of digital communications and protecting digital identities are crucial in the fight against the growing threat posed by deepfakes.

What role do AI and machine learning play in both the creation and detection of deepfakes?

In 2023, identity fraud resulted in losses of over $635 billion, and account takeover attacks increased by 354% year over year as a result of identity theft. Deepfakes are among the most concerning use cases of artificial intelligence (AI), and the World Forum has placed disinformation as a top global risk for 2024. Today, Gen AI has made it feasible to make incredibly realistic deepfakes. Criminals are employing deepfakes to imitate human speech patterns, facial expressions, and body language in order to create false content that mimics real people and is often used maliciously. They do this by leveraging large video and audio datasets for training.

One of the most alarming examples of AI-powered threats to identity security is voice verification. Layered authentication, which combines voice verification with adaptive authentication, SMS, and email one-time passwords, is used by call centres, especially in the banking industry. It is essential that such layered authentication includes methods that can’t be easily spoofed or phished. For biometric authentication methods strong active and passive liveness detection capabilities are required.

The survey also revealed that nearly half (49%) of APAC organisations are having trouble striking a balance between security requirements and the desire to avoid interfering with user experience. Additionally, 99% of these organisations are having trouble with identity verification.

Key challenges in detecting deepfakes

3. What are the key challenges in detecting deepfakes, especially as the technology behind them becomes more advanced?

Think again if you believed that deepfakes were limited to tricking those without computer expertise. In a recent alert, the Cyber Security Agency of Singapore (CSA) highlighted a scenario in which con artists impersonated the chief financial officer of a global company using deepfake technology, deceiving a finance staff member into sending them USD 25 million. Deepfake detection is getting more difficult since the underlying technology is developing so quickly. Cybercriminals are becoming more skilled at using AI, and they are always coming up with new techniques to create deepfakes that are harder to spot and more realistic.

Present-day deepfakes can mimic subtle human gestures, voice tones, and facial emotions very well. This makes it challenging for both computers and people to distinguish between authentic and fake content. In order to protect data in this new paradigm, we as security professionals advise businesses to integrate Identity Threat Detection and Response (ITDR) with Decentralised (DCI) practices. ITDR solutions allow organisations to detect abnormal and suspicious activity by concentrating on identity signals in real time and comprehending the configurations, permissions, and connections between accounts while DCI solutions empower users to own and control their IDs and the claims about themselves they are willing to share.

Share methods by which businesses can protect their operations and employees from deepfake threats.

Organisations must emphasise how crucial it is to tackle deepfake dangers with a multi-layered strategy. When selecting a solution, protecting digital identities should come first. Identity and access management (IAM) solutions play a crucial role in supporting the detection of irregularities and ensuring that additional identity verification is obtained prior to access authorisation. They achieve this by improving detection capabilities and putting in place robust verification procedures like multi-factor authentication (MFA) and biometrics with liveness detection capabilities.

Password-less authentication

Making the switch to password-less authentication, which uses cryptographic functions instead of common credentials that are readily stolen as part of the verification process, is a helpful strategy to lessen security risks. This approach strengthens the security architecture and lessens the possibility of credential compromise. A newer approach to tackling deepfake circulating is placing watermarks in content to alert viewers. In the same way, watermarking technology could be used to label trusted content.

Furthermore, employees who regularly participate in awareness training are also more equipped to recognise suspicious activity and avoid possible dangers.

What advice can you give to individuals and organisations regarding spotting deepfakes and protecting themselves from being victimised?

Many fraudulent transactions go unreported until after money has been lost. Organisations must continue to be vigilant, proactive, and knowledgeable when identifying, detecting and protecting against deepfake attacks. For example, watch out for telltale signs of a deepfake, such as irregular blinking, discordant audio and video, or odd facial expressions, and immediately confirm the communication through another trustworthy channel.

Constant vigilance from individuals and organisations is necessary to counter such well-crafted attacks. This means identifying the source of all unsolicited enquiries and regularly verifying the legitimacy of digital communications. Furthermore, the appropriate authorities should educate the public to recognise and detect deepfakes and set up processes for the public to notify the government when they encounter harmful deepfakes.

Read More News

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading