Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (2024)

Elliot Seeto

Executive Coach - Cybersecurity - Pax8 APAC Academy

  • Report this post

On Monday I posted an exercise on how gaining basic personal information about someone, access to social media and the use of some easily available A.I. tools to create a deepfake can be used to craft a relatively simple but successful scam.It didn't get a lot of looks for whatever reason. But that's OK, if it potentially helped 1 person I'm good.Here is an actual example of it playing out in real life though.#AI is good, possibly even game changing. But it can also be good for the bad guys. Don't ignore your #cybersecurity training, it can be one of your first defenses against a #CyberAttack.

A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera House in $25 million fraud fortune.com

24

7 Comments

Like Comment

Ben Opit

GTM Strategy and Partner Success across the entire Microsoft Biz Apps stack, operational best practices, reducing risk, improving productivity.

8h

  • Report this comment

Elliot I don’t have access to see the report but how would our partners begin to educate on how to look out for this? I mean it was clearly well orchestrated.I was thinking about approval flows when it comes to paying money and educating the accounts team but this is way beyond that. What are the best ways ahead here?

Like Reply

1Reaction

Mike Ouwerkerk

DON'T CLICK ON THAT!!! | Live Cyber Awareness Training | Fun, Engaging, Effective

22h

  • Report this comment

It's ramping up, and people are largely not prepared for this!

Like Reply

4Reactions 5Reactions

Dave Carey

Founder | Cybersecurity Architect | vCISO | CISSP | Collaborator | Educator on a mission to help businesses mature their cybersecurity program. Over 25+ yrs in IT & Cybersecurity.

21h

  • Report this comment

Good advice. If only more companies were actually training their employees.

Like Reply

3Reactions 4Reactions

Yaye Caceres

Founder & Product maker at TypeflowAI

15h

  • Report this comment

Raise awareness. Question assumptions. Stay vigilant against evolving threats.

Like Reply

1Reaction 2Reactions

See more comments

To view or add a comment, sign in

More Relevant Posts

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    Is your Inbox getting flooded by Marketing Spam?Probably not a new tip for many but it was a game changer for me.Was able to halve my unread emails from my Inbox by setting up a quick rule to identify the keyword "unsubscribe' and send it straight to 'Deleted items'.Amazing!Be careful though, you might end up missing key updates from sources you actually want to read.Go check those and set a rule up for those.

    • Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (11)

    16

    17 Comments

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    "We need to make #Cybersecurity (for SMB's) easier, approachable and simple" Jason Murrell talking about how the Cyber Security Certification Australia (CSCAU) is helping MSP's support #SmallBusiness get better with online safety.Full video of the latest episode of this #CyberCollective podcast in the comments:

    25

    1 Comment

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    "We need to make #Cybersecurity (for SMB's) easier, approachable and simple" Jason Murrell talking about how the Cyber Security Certification Australia (CSCAU) is helping MSP's support #SmallBusiness get better with online safety.Full video of the latest episode of this hashtag#CyberCollective podcast in the comments:

    Vimeo vimeo.com

    14

    1 Comment

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    Let's explore how your #personaldata being leaked can be used for targeted #scams and how easy someone can be socially engineered to make bad decisions especially with easily found #AI tech.All I need for this example is a name, phone number, country and date of birth. Stuff that would be easily obtained from the many #databreaches we hear about.Let's call this person Sarah Walters.I search social media sites and find various matches to that name and if they have a public profile, I could have everything I need to put my plan into place.I have verified the location and date of birth to give me the best chance that I have the right person.I noticed that Sarah is an avid Justin Bieber fan with loads of public post. I see that she has recently attended a concert at (xx location)Now I have everything I need.I use some like Parrot AI to create an deepfake voice recording as Biebs.Call and leave a Voicemail, something to the tune of "This is Justin, just calling you to thank you for coming to my concert at X. As one of my biggest fans, and as your birthday is coming up, you have been selected to join me for an all expenses paid trip to Vegas for my upcoming concert for you and 3 friends.Contact my team at rewards@beliebers.net to claim your place.Can't wait to see you there."If Sarah is a hardcore fan, all common-sense would go out the window.Sarah emails, details are shared to appear real. Then they say, for legal reasons we need to take a holding deposit for each person to ensure we abide to US travel laws, blah blah.That will be $500 each for your group of 4.Sarah throws out all potential suspicions and has no idea about US law and doesn't care because emotion overrides critical thinking.Make the transfer because " I just won Biebs tickets baby", who wouldn't!Now why would I give people ideas, you might say? Well this is just an example but these things are already happening.Get help, do some training and be better Cyber prepared.

    • Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (22)

    2

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    This is an excellent article by Rosalyn Page on how effective, simple low-tech #CyberAttacks can be.I won't rehash the article as it is a great thought provoking read. While there are some technical controls that could be put into place to mitigate some of these risks such as disabling or limiting only authorised USB drives to access systems, there is a much more effective method to reducing this #Risk.#SecurityTraining!Not just your run of the mill training platform though, but it should include a comprehensive training program that incorporates ways of validation.Training without validating that the users actually understand and utilise the training in their day to day lives is like changing a tyre without checking that the nuts are properly tightened before you drive off.Something bad will probably happen.Comprehensive training doesn't need to be complex though, in fact, sometimes simpler is better. It just needs to be thorough and digestible to the everyday person.Good training also helps users to protect themselves outside of work and in their private lives. It might be that little thing that stops them from handing their money over to that Nigerian prince or worse.

    Low-tech tactics still top the IT security risk chart csoonline.com

    13

    4 Comments

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    #Cybersecurity for SMB's is difficult for the many MSPs to deal with as their are no specific laws, regulation or guide lines to follow. In this Episode we look at the Cyber Security Certification Australia (CSCAU) new #SMB Standards and #Certification process to support MSPs and SMBs on improving their cybersecurity through industry-led, affordable, and regularly-updated methodologies. I am joined by our MSP voice: Adam Cliffe, MD and Security Advisor at ADITS and our SME: Jason Murrell, Independant Chair at the Cyber Security Certification Australia (CSCAU) and Co-Founder of the MurFin Group

    Cyber Collective - How The CSCAU Can Help SMB's Be Cyber Prepared

    https://www.youtube.com/

    21

    7 Comments

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    When I read articles like this, stating a need for 5000 new workers in the #cybersecurity industry each year to keep up with demand, it is interesting to see many Security focused vendors going through lay-offs. What's even more interesting and disappointing is the limited support of #SmallBusiness in last night's Australian federal #budget. And no mention of cybersecurity either. Although I wasn't expecting there to be, so no surprise there.This is not a current government issue though. Granted there are other pressing matters, like the cost of living and housing crisis' to deal with. But when I hear politicians say "Small business are the life blood of Australia" or #Cyber Safety is a priority for all Australians", well it's kinda hard to take them seriously when there is no follow through or support.I believe we already have a viable solution to help make sure small businesses can reduce their #Risk.The #MSP and #TSP community!But they need support.I'm neither here nor there when it comes to politics but action is needed. Time for governments to step up regardless of party lines and put their money where their mouths are.Cybersecurity is not a partisan issue, it's something that can affect us all regardless of political affiliation.

    This industry needs 5000 new workers every year just to keep up afr.com

    26

    16 Comments

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    "Cbeyr Scrietuy is smtoehnig taht all slmal and mdiuem biusesnes msut tkae srioelsuy"According to Social media, if you can read this, you're a Genius.That's a bit of a stretch but it does show a persons capacity to think differently. Can you read it?The trick here is that as long as the first and last letters are in its correct place than the person should be able to read it.I could read things like this fairly easily without explanation and I am far from a genius (So says my wife). Thought everyone could. But I've seen different results.- Some couldn't read it at all- Some struggle with it but could read it once the understood the pattern- Some (like me) read it with some thought and recognised that the letters were scrambled- Others read it normally and didn't notice that it was scrambled."Cool story bro, Why are you spamming me with this crap Elliot?"Simple 'cognitive tests' like this can help identify different strengths and weakness in your team. Having too much of one can throw a team off balance. There is a bunch of cognitive and personality tests available that you could use to get a good balance within your teams to not only be efficient but be able to work together. When it comes to your security teams, this can be extremely important to get right. During an incident, if your teams don't work well together, things get missed or ignored, which can be impactful during an IR play. It also highlights that everyone is different and needs different ways of training. Not everyone can do an annual online #securityawareness training and be expected to remember it on top of their everyday workloads.As an example, I am not a text book training type person. I learn through experience. Getting my hands dirty, speaking to people and asking questions is how I learn.Different methods need to be considered when delivering #SecurityTraining. This is part of rolling out a successful program, build it for everyone.

    17

    5 Comments

    Like Comment

    To view or add a comment, sign in

  • Elliot Seeto

    Executive Coach - Cybersecurity - Pax8 APAC Academy

    • Report this post

    Are we getting it wrong and focusing on the wrong things when it comes to #cybersecurity?The stats seem to point that way. Most statistics global point to human error being the key contributor to a #cyberbreach or incident, usually anywhere between 70-95%. Yet Security training for SMBs is typically a low priority.The controls we put into place are there to mitigate issues when mistakes happen. But why can't we reduce the mistakes through training at the same time?

    Data breaches are getting worse - and many are coming from a familiar source techradar.com

    25

    8 Comments

    Like Comment

    To view or add a comment, sign in

Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (45)

Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (46)

2,454 followers

  • 1,742 Posts
  • 2 Articles

View Profile

Follow

More from this author

  • Should MSPs Join AISA and attend their events? Elliot Seeto 10mo
  • Is the Essential Eight doing more Harm than Good? Elliot Seeto 11mo

Explore topics

  • Sales
  • Marketing
  • Business Administration
  • HR Management
  • Content Management
  • Engineering
  • Soft Skills
  • See All
Elliot Seeto on LinkedIn: A deepfake ‘CFO’ tricked the British design firm behind the Sydney Opera… (2024)
Top Articles
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 6327

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.