Trend Micro has released a new report outlining the increasing adoption of generative AI and deepfark technology by cybercriminals, highlighting the growing risks of business fraud, identity theft, and online tor schemes.
Deepfakes move to mainstream
This report shows that Deepfake-enabled cybercrime has been developed at both scale and maturity, and that the generator AI tools are used for a variety of malicious purposes. Originally intended to support content creators, these tools are now being used by cybercriminals, spoofing executives, circumventing established financial management and compromising internal HR processes.
Research shows that the accessibility and affordability of AI-generated media has significantly reduced barriers to cybercriminal intrusion. Ready-to-made platforms that produce video, audio and image deepfakes now require little technical expertise on the part of the user. As a result, the reliability of digital trust and traditional identity verification systems are being challenged by increasingly compelling synthetic media.
Andrew Philp, ANZ Field CISO at Trend Micro, said, “AI-generated media is not only a future risk, but a real business threat. Executives are seeing financial safeguards that have been violated, their employment processes have been circumvented and by surprise ease. They'll be rebuilt from scratch.”
The findings in the report confirm that attackers have easy access to guides, toolkits, and off-the-shelf solutions intended for content creation, but can be reused for cybercriminal activities. These resources are actively traded within the crime community, leveraging plug-and-play deepfake solutions that provide step-by-step techniques to bypass onboarding checks and enable less experienced perpetrators to take advantage of sophisticated attacks.
Business risks and real-world impacts
The application of Deepfake Technologies has attracted attention in several key areas highlighted in the Trend Micro report. The financial sector is increasingly trying to bypass customer (KYC) requirements using AI-generated media, and uses forged identification documents and credentials to promote anonymous money laundering activities.
Companies are also facing CEO scams. In CEO scams, Deepfake audio or video is spoofing senior executives. These attacks can take place in real time during meetings or conference calls, making detection more difficult for unsuspecting teams. Such cases expose businesses to potential financial losses and reputational damages, as sensitive inside information can be compromised.
The recruitment department is another area chosen for concern. The report details cases in which job seekers use deepfake video or audio to impersonate actual candidates and pass interviews, thus providing unauthorized access to confidential systems and data from within the organization.
Growing and accessible cybercrime ecosystem
This study describes thriving underground ecosystems built around the growth of these AI-powered tools. Tutorials and toolkits for creating deepfakes and implementing fraud operations are widely available, reducing the need for technical proficiency. Face swapping tools and voice clones are offered as services, allowing you to access professional grade results with minimal investment.
Trend Micro emphasizes that these trends represent the urgent need to adopt proactive measures. This includes updating the certification process, educating employees on social engineering risks, and incorporating synthetic media detection mechanisms into cybersecurity strategies.
Mitigation and Staff Perception
To address the evolving threat landscape, this report advocates a comprehensive approach focusing on minimizing risk and protecting internal processes. Specific recommendations include regular staff training to recognize social engineering tactics, reviewing existing security authentication protocols, and investing in technologies that can detect deepfake media.
Trend Micro's research reminds us that as generative AI technology continues to advance and become more accessible, vigilance and adaptability become critical components of maintaining organizational security and digital trust.
