As if perpetrating cybercrimes – particularly spear phishing – weren’t easy enough for any aspiring hacker or established organized crime ring, it has just become even easier for bad actors to successfully attack organizations. Whether to steal sensitive intellectual property, extract ransoms via service interruptions or simply to heist millions of credit card and Social Security numbers from encrypted databases, hackers are now using the same contemporary, powerful technology used by the legitimate businesses they seek to victimize to power criminal activity. The rise of artificial intelligence or “AI” is transforming business operations across every business function. And the promise of transformative results is just as alluring to the criminal as it is to the legitimate businessperson. Today, AI powered spear phishing is exploding in popularity prompting many to seek a proportionate AI driven defense response. However, using fire to fight fire in this regard is not a viable strategy.
The lack of awareness regarding External Data Privacy Management or EDPM was already a critical vulnerability for InfoSec pros and the organizations they serve. As they struggle to come to terms with the mounting threat posed by unsecured external data (and how it powers social engineering attacks), criminals are leaping way ahead of CIOs’ and CISOs’ embryonic efforts to address EDPM. Bad actors have embraced nearly limitless, cutting-edge, AI tech to supercharge their criminal activity. Most organizations were already behind in fielding effective defenses. Now, they may never be able to catch up. Unless they quickly come to a fulsome understanding of the AI threat and its roots.
This document will shine a light on how AI is being harnessed by bad actors to launch spear phishing and other social engineering attacks against large organizations. It will illustrate how AI powered assaults are orders of magnitude more powerful than the non-AI variety attacks. It will provide evidence in support of claims that AI powered spear phishing attacks are not only on the rise but have quickly become the most prevalent strategy for hackers. The document will also examine a recent, devastating and high-profile case in which a global brand was brought to its knees by an AI powered spear phishing attack. Finally, it will offer some insights into the best practices for getting ahead of this crippling trend so that your organization won’t become the next victim.
Why are Spear Phishing Attacks the Choice for Hackers Using AI?
One thing we know about hackers (and all thieves) is, they prefer stealing to working because it is far easier to take something than it is to make something. It is for this precise reason that spear phishing – out of the broadening array of cybercrime strategies – has emerged as the most popular vector for cybercriminal activity in recent years. As Privacy Bee research has repeatedly proven*, social engineering attacks (which includes spear phishing) are particularly low-effort/high-reward propositions for cyber criminals. This is because, as we’ve illustrated repeatedly in published research, the availability of unsecured external data makes it far easier to steal IP or exact a ransom than to build, market and distribute products or services.
* See Privacy Bee white papers, “Mitigating Exposed PII Dramatically Lowers Risk of Data Breach via Social Engineering“ and “External PII Exposure Fuels Social Engineering, Data Breaches” for examples.
Respected IT tech journal, TechMonitor writes about how the arrival of generative AI is arming criminal organizations with the ability to generate scalable spear phishing attacks with unprecedented precision. Especially because the use of Natural Language Generation (NLG) yields phishing messages that are not as easy to spot as the clunky human intelligence forebears. Gone are the poorly-worded, bad-grammar messages often written by non-English speakers in far-flung locales. TechMonitor writes, “By jailbreaking mainstream models like ChatGPT or using dark web variants like WormGPT, hackers are now capable not only of automating the care and attention required to write a devilishly good phishing email but also doing so at a scale hitherto impossible using traditional methods.”
CNBC reports “Security experts have noted that AI-generated phishing emails actually have higher rates of being opened — [for example] tricking possible victims to click on them and thus generate attacks — than manually crafted phishing emails”. But, what is it about spear phishing that makes it such an effective ploy and how does AI make an already effective scam more effective?
The first step in understanding the efficacy of spear phishing versus regular phishing is explained quite well by Microsoft. In a 2022 article titled, “What is Spear Phishing?” Microsoft explains the difference. They write, “When someone is fishing, they’re casting a baited hook into a body of water, hoping for a bite from any fish that might swim by. Spear fishing is significantly more targeted, a fisherman is looking for a specific fish and is planning to snare it with a spear, as opposed to a lowly hook.”
Among the array of known social engineering attacks, phishing is an email scam that aims to deceive a large number of undefined individuals by enticing them to click on a link that introduces malware to their device or persuading them to disclose sensitive information such as passwords or account numbers. Hackers only expect a small fraction of the recipients of the phishing email will be deceived, so this requires a hacker to cast a wide net of thousands or even hundreds of thousands of phishing emails to be sent.
On the other hand, spear phishing is a much more precise form of attack. In this scenario, the attacker conducts thorough research on their targets. Unlike a generic message sent to thousands of targets, a spear phishing attempt might mimic the email address of someone like a manager or boss and request specific login credentials. This type of attack is tailored to a single person, or a small group identified by a social engineer as susceptible to the scam. If successful, the attackers can gain access to personal or confidential company data, enabling them to engage in fraudulent activities or use the information as leverage for ransom.
Typically, regular phishing attacks prioritize quantity over quality, employing generic messages sent to unsuspecting individuals in an attempt to illicitly obtain sensitive information. These messages often lack detail and quality, making them easily identifiable by both spam filters and vigilant recipients. While individual instances of phishing on a small scale are generally unsuccessful, the overall success is deemed worthwhile due to the one or two victims who fall for the scheme on a large scale.
In contrast, spear phishing attacks adopt a more meticulous approach, utilizing carefully curated information about the target to facilitate the extraction of sensitive data through channels such as email, text, or phone calls. Although the success-to-failure ratio in spear phishing is higher, the results are not as extensive on a large scale, primarily due to the time-intensive nature of implementing a spear phishing attack—until the advent of AI.
When AI technology is integrated into spear phishing tactics, the outcomes become astonishing. Scammers, armed with data obtained from breached websites, data broker files, social media profiles, public records and other sources of unsecured external data, can leverage AI to analyze and structure the information for highly targeted spear phishing attacks. For instance, a scammer aware of your recent vacation stay at a particular hotel may send an email, posing as the hotel billing department, and requesting account verification for a supposed bill, thereby tricking you into divulging credit card information.
Instead of relying on a single cybercriminal manually executing a targeted attack, scammers can now train AI to perform the social engineering tasks, enabling interactions with individuals on a much broader scale and consequently increasing the likelihood of success. In short, AI allows the hacker to circumvent the high-volume broadcast method of regular phishing and leapfrog over the more effective but time-consuming work of developing spear phishing strategies. Today, the AI mostly automates the process of finding appropriate targets within an organization, discovering relevant context clues from the wide array of available, unsecured external data sources, then even drafting the appropriate email content and deploying the attack.
Worst of all, the AI can replicate this process countless times in very short order – something that would have taken a hacker far more time to accomplish manually. For these reasons, it is perhaps not at all surprising that AI powered spear phishing has become the method of choice for scammers and hackers today.
Five Ways Hackers Deploy AI Spear Phishing
Here are the five leading ways AI enhances phishing activities compared to those powered solely by humans:
- AI-Enhanced Social Engineering: AI technology takes the often-extensive legwork out of crafting social engineering strategies. The AI can employ sophisticated social engineering techniques, crafting persuasive and personalized phishing emails tailored to each recipient. The extensive data available to threat actors makes it more challenging for individuals to recognize the scam.
- Convincing Content Generation: AI algorithms can produce realistic content, including phishing emails and websites, that closely mimic legitimate communications in terms of language, style, tone, and other aspects. This creates significant challenges for security solutions and software which struggle to tell the difference between fraud and actual business communications.
- Increased Attack Scalability: AI technology automates phishing campaigns at each stage of the attack. From email creation and distribution to management of responses. AI automation allows criminals to target a larger audience simultaneously, making it more likely the attacks will be successful.
- Adaptive Evasion Techniques: Security systems struggle to keep pace with AI empowered phishing campaigns and tactics because AI algorithms adapt based on feedback. Hackers can circumvent anti-phishing measures or email filters, using AI to constantly refine their strategies and stymying the process of detection and mitigation.
- Accurate Targeting: AI technologies are far better suited for gathering and analyzing vast volumes of publicly available information about individuals and organizations than a team of humans. The collected data is then utilized by the AI to generate custom spear phishing campaigns for specific individuals based on their interests, vulnerabilities, or preferences. The efficacy of the AI developed spear phishing campaign increases the probability of success, because the messages appear applicable and authentic to the recipients.
Evidence of the Growth of AI in Spear Phishing Attacks
Financial media stalwart Forbes magazine reporting suggests the market to combat AI spear phishing is on fire. By many accounts, the threat landscape surrounding AI is growing by leaps and bounds. British cybersecurity firm, Darktrace observed a 135% increase in novel social engineering attack between January and February 2023 alone! Growing at a rate of greater than 100% monthly is a terrifying prospect for those tasked with protecting against spear phishing attacks.
While the use of AI specifically in spear phishing is a very new development, the overwhelming response from solution providers – new and existing – is only just beginning to come into focus. And though the growth will almost certainly become even more dramatic, industry watchers are already seeing the kind of growth rates among AI-specific defense providers that occur only when it becomes certain a novel threat is real.
Forbes writes, “Thankfully, SMEs can also utilize AI to fight fire with fire. While AI is being exploited by cybercriminals to accelerate their malicious agendas, it is also being harnessed by security professionals to strengthen defense mechanisms and detection capabilities.”
“As a result”, Forbes notes, “the market value of AI-empowered cybersecurity is forecast to grow to over $46 billion by 2027, a significant step up from its $10 billion valuation in 2020.”
Those growth rate figures are supported by research data compiled by Statista says, “The AI in cyber security was worth over ten billion U.S. dollars in 2020 and was forecast to increase to 46.3 billion U.S. dollars by 2027.”
Emerging AI Powered Spear Phishing Tactics
Spear phishing using AI does not stop at simply applying AI to the task of identifying targets and developing strategic scam messaging. Nor does it end with simple automation of the processes involved in email generation and distribution. This powerful new technology is being used to polish the language used in the emails, making them much less obvious than the human generated messages which are often conspicuous due to poor grammar/spelling and awkward syntax. Spear “Vishing” attacks even utilize AI to produce so called, “Deepfake” audio messages which mimic a supervisor’s voice on voicemail messages directing subordinates to perform such tasks as transferring funds (to fraudsters’ accounts) or reset passwords or multifactor authentication defenses.
In an information sheet released in 2023 by the US Cybersecurity and Infrastructure Security Agency (CISA) in conjunction with the FBI and NSA, the threat of natural language generation AI (NLG) is explained. CISA cautions, “Synthetic media threats broadly exist across technologies associated with the use of text, video, audio, and images which are used for a variety of purposes online and in conjunction with communications of all types. Deepfakes are a particularly concerning type of synthetic media that utilizes artificial intelligence/machine learning (AI/ML) to create believable and highly realistic media.”
CISA continues, “The most substantial threats from the abuse of synthetic media include techniques that threaten an organization’s brand, impersonate leaders and financial officers, and use fraudulent communications to enable access to an organization’s networks, communications, and sensitive information.”
Malicious actors may use deepfakes, employing manipulated audio and video, to try to impersonate an organization’s executive officers and other high-ranking personnel. Malicious actors may employ convincing audio and video impersonations of key leaders…”
Defending Against AI Powered Spear Phishing
Most contemporary strategies for defending against AI in social engineering attacks like spear phishing adopt the “fight fire with fire” attitude toward the challenge referenced in the Forbes article earlier. Most of the current thinking focuses on applying AI to help detect the use of AI in spear phishing attacks so they can be flagged and removed before they have the opportunity to do damage. There are three AI powered defenses most frequently mentioned in current industry literature. These are:
Machine Learning – wherein AI is used to analyze large volumes of data to learn to identify phishing attacks that would likely be undetected by traditional security solutions. Analyzing things like senders’ email addresses, email body content, links, attachments, etc., the machine can identify anomalies that could be indicative of a phishing attack.
Natural Language Processing – wherein AI is used to review and analyze thousands or even millions of emails – across multiple internal and external business channels to seek out common patterns that could be indicative of phishing.
User Behavior Analysis – wherein AI is deployed to analyze user behavior patterns that could signify phishing attempts are in progress. The AI in this case monitors user activity – logins, link clicks, attachment downloads and message replies – to uncover potential phishing attacks.
Other experts recommend more draconian measures to combat the use of AI in social engineering attacks. Characterized as an “arms race” some call for the release of AI chatbot technology to compete with the improving language and sophisticated strategies perpetrated by hackers using AI for spear phishing. Some even suggest a temporary interruption in the release of AI technology for public use, allowing security providers additional time to field defenses that can effectively identify AI-generated social engineering scams.
While it is true that AI tech has revolutionized how hackers deploy phishing attacks and while the above strategies – machine learning, NLP and user behavior analysis – are certainly useful but costly tools organizations could use in fielding a defense. Yet, none of the AI powered defenses address the root of the problem.
No amount of artificial intelligence is going to stem the tide of unsecured external data, without which no social engineering could occur. Whether manually generated or produced at lightning speed by AI, spear phishing and other social engineering attacks rely on context clues and relevant personal information about their targets. Convincing email appeals cannot be made by AI or otherwise without this kind of data. Deploying AI to interrupt spear phishing is treating the symptoms, but not the illness. To illustrate this fact, consider the recent case of MGM Grand as a $100 million object lesson.
AI Powered Spear Phishing Breaks the Bank at MGM Grand Casinos
Without warning, all hell broke loose at more than two dozen hotel and casino operations around the world run by MGM Grand. On September 11, 2023, hotel guests began finding their digital hotel room keys would not unlock their doors. Slot machine players found their digital gambler’s cards were not being accepted at slot machines and in fact many of the slots were visibly offline. MGM Grand’s many websites went dark. Customers were trapped in elevators for hours because computer-operated systems were down. With great hesitation, MGM Grand made a vague announcement suggesting they were grappling with a “cybersecurity issue”.
It took roughly 10 days for the casino company to return to normal operations although there were still reports of intermittent issues impacting MGM Rewards and other programs. But the bad news was just beginning. On October 5th 2023, MGM delivered more bad news to its customers. It seems the hack had also included unauthorized access to the personal information of an undisclosed number of customers. The information included names, genders, dates of birth, driver’s license, passport and even Social Security numbers!
In the ensuing investigation it was revealed that a hacker collective known as “Scattered Spider” used a ransomware attack to shut down this global casino operation. Known by the FBI and other law enforcement agencies as being “experts” in social engineering and vishing strategies, it was determined (with a high degree of likelihood) that Scattered Spider was able to inject its ransomware via a “vishing” attack which is the voicemail version of a spear phishing attack. It was later discovered that the likely target of the spear phishing attack was MGM’s IT help desk which was fooled into revealing credentials to critical information systems.
Around the same time as the MGM attack, Caesars Entertainment, another global casino/hotel chain revealed to the US Securities and Exchange Commission that it had paid millions of dollars ransom to hackers who had succeeded in deploying a ransomware attack via social engineering of a third-party IT support vendor. Caesar’s operations were not interrupted though because they quickly paid the ransom. MGM did not comply with ransom demands and was hobbled for weeks. While it is difficult to prove with certainty, it is largely believed that these seemingly coordinated attacks were likely devised using AI to accurately identify the correct target, generate the highly relevant content and deepfake the voice used in the vishing attack.
Like many companies victimized by breaches and attacks, the casino companies were not forthcoming with all the details of their embarrassing failures. Hacker groups are not always truthful in their claims of responsibility for obvious reasons either. So, some of the conclusions to be drawn are not entirely complete. However, we do know that Caesars reported paying millions and MGM reported disrupted operations would cause more than $100 million in losses in its 3rd quarter financial statements.
The longer-term ramifications of allowing customer data to be stolen in the breach are still yet to be calculated. However, there is the initial cost associated with offering credit monitoring services to all the affected customers. There is also the opportunity loss associated with customers deciding to patronize competing hotel/casino properties that may be perceived as more cautious with their personal information and information security in general.
If these victimized casino operators had been employing AI powered strategies to guard against the spear phishing threat, would they have been able to avoid being victimized? Privacy Bee suggests almost certainly, the answer would be “no”, because AI defenses do nothing to remove access to the unsecured external data used to generate social engineering attacks.
How EDPM is Superior to AI in Preventing Spear Phishing
Avoiding social engineering attacks and the resulting data breaches depends on securing external data privacy. This means scrubbing the external data of all relevant employees (both internal and third party) from the many sources of PII available. Removing identifiable information that can be used by AI to generate phishing and other scams from hundreds of data brokers, people search sites and public data sources sounds like an insurmountable task. But it is achievable, and it is truly the only way to protect against falling victim. Privacy Bee for Business is a leader in delivering EDPM solutions that are proven effective at reducing the digital attack surface and adding the necessary data privacy layer of protection atop the rest of the traditional information security practices already widely in use.
It is recommended that all organizations avail themselves of these easy to deploy scans and metrics to determine their existing level of vulnerability when it comes to EDPM.
Privacy Bee’s Employee Risk Management (ERM) is an easy but powerful way to get visibility into your External Data Privacy risk. After just a few minutes to load and configure your employees (usually an exported CSV from your HCM software), Privacy Bee automatically begins scanning hundreds of external sources, searching for any exposed privacy risks on each employee. Any discoveries are flagged as an exposure and affect that person’s aggregated Privacy Risk Score.
ERM helps quickly paint a full picture of an organization’s real-time cyber risk from external privacy exposures. The results provide stark illustration of how much unsecured external data an AI can easily find on every employee within an organization. This privacy intelligence platform is 100% free for all businesses, powered by Privacy Bee.
Privacy Bee’s External Data Privacy Audit another web-based privacy app for quickly and easily scanning employees PII exposure. This tool set lets you build an extensive audit, identifying privacy exposures and vulnerabilities, then extrapolates potential financial impact across your company. It’s a critical view into risk assessment, operational inefficiencies, emerging cyber risk, and External Data Privacy Management. It makes clear what is at risk by continuing to permit hackers’ AI access to external employee data.
The EDPA provides unified employee audits, bringing together real-time dark web monitoring with 24/7 active clear web monitoring (Data Brokers, People Search Sites, paste sites, and more). Delivering a centralized view into public employee exposures, and insight into the tangible financial impact it has within your organization.
Privacy Bee’s Vendor Risk Management (VRM) extends the privacy bubble to targets outside your organization but who may have a degree of access to your sensitive information systems – including software providers and/or contract development resources. This solution evaluates all your vendor/partner organizations for Electronic Data Privacy risks. It then reports simple Privacy Risk Scores on each company, highlighting each vendor’s risk at a glance. Analytics further break vendors down by department, risk tier, and more, with all thresholds fully customizable. While most vendor risk software stops at the report, Privacy Bee VRM keeps going, offering to work with all your 3rd party vendors 1-on-1 to decrease their vulnerabilities, effectively de-risking your company. In the Caesar’s Entertainment example, it was a third-party vendor the hackers’ AI targeted and exploited with a spear phishing attack to gain unauthorized access.
While all these (and other) audits and monitoring services are for use at no cost, removing employee PII from all unsafe locations on the net is what reduces the risk and the attack surface. While this is a function your organization could take on as an internal activity, most organizations prefer to outsource the removal service for your employees and vendors identified as at risk to Privacy Bee. Privacy Bee has teams of experts working 24x7x365 to scrub client employees’ PII from all unsafe corners of the internet.
Putting EDPM solutions like these in place does more to protect against being victimized by artificial intelligence-powered spear phishing than employing AI to “fight fire with fire”. And the cost of Privacy Bee EDPM is a small fraction of what it would cost to buy or build AI security solutions internally.
Speak with Privacy Bee to discuss the External Data Privacy Management at your company.
