AI-Era Threat Awareness
AI is changing the threat landscape. Learn to recognize AI-enhanced phishing, voice cloning, and deepfakes, and discover how to use AI tools safely at work.
What You Will Learn
Artificial intelligence is changing the threat landscape. Attackers use AI to create more convincing phishing emails, clone voices for phone scams, and generate deepfake videos. This module teaches you to recognize AI-enhanced threats and use AI tools safely at work.
- AI-enhanced phishing: why AI makes phishing harder to spot
- Voice cloning: phone scams that sound exactly like your colleagues
- Deepfakes: video and image manipulation
- AI tool data risks: how to use ChatGPT and similar tools safely
- Defense strategies: what still works when attacks are AI-powered
How AI Changes the Threat Landscape
AI tools have made attackers more efficient and their attacks more convincing. In the past, phishing emails were often easy to spot because of poor grammar, generic language, and obvious mistakes. AI can now generate flawless, personalized emails in any language. Voice cloning can replicate a person’s voice from a few seconds of audio.
Quick Check
You receive a voicemail from your executive director asking you to urgently process a wire transfer. The voice sounds exactly like them. What should you do?
AI-Enhanced Phishing
Attackers use AI to write phishing emails that are grammatically perfect, personalized, and culturally appropriate. AI can analyze your organization’s website, social media, and public records to craft emails that reference real projects, real colleagues, and real vendors.
The red flags from Module 01 still apply, but you need to be more vigilant. The old signs of phishing (poor grammar, generic greetings) may be absent. Focus on the request itself: is it asking for money, credentials, or sensitive data? If so, verify through a different channel.
Quick Check
You get an email from a vendor with a perfectly written invoice. The email references a real project and uses the vendor’s correct branding. But the bank account number is different from last time. What should you do?
Voice Cloning and Phone Scams
AI voice cloning tools can replicate a person’s voice from a 3-second audio sample. Attackers use this to impersonate executives, colleagues, or family members in phone calls or voicemails. The voice sounds real because it is a digital copy of the real voice.
Voice Cloning Defense
- Verify by calling back. If you receive an unusual request by phone, hang up and call the person back at a known number.
- Be suspicious of urgency. Voice cloning attacks always create urgency to prevent you from verifying.
- Establish a code word. For financial requests, agree on a verification code word with your executives and vendors.
- Do not trust caller ID. Caller ID can be spoofed. The number on your screen may not be the real source.
- Report suspicious calls. Tell IT or STM about any suspicious calls so they can alert the rest of your team.
Deepfakes: Video and Image Manipulation
Deepfakes are AI-generated videos or images that show people doing or saying things they never did. While deepfake video attacks are less common than email or voice attacks, they are growing. A deepfake video of your CEO asking for an urgent transfer could be very convincing.
The defense is the same as for voice cloning: verify through a different channel. If you receive a video request for money, data, or credentials, call the person directly to confirm.
Using AI Tools Safely at Work
AI tools like ChatGPT, Microsoft Copilot, and Google Gemini are powerful productivity tools. But they create data exposure risks when used with sensitive information:
AI Tool Safety Rules
- Never paste PHI, client data, financial data, or credentials into public AI tools. You are sending that data to a third-party company.
- Use enterprise versions when available. Microsoft Copilot for M365 and Google Gemini for Workspace have data protection agreements.
- Treat AI tools like any other cloud service. They need IT approval before use with work data.
- Do not trust AI output blindly. AI can generate incorrect information. Always verify facts.
- Do not use AI to generate or store passwords because the data may be retained by the AI provider.
What Still Works Against AI-Enhanced Attacks
The fundamental defense remains the same: verify before you act. AI makes attacks more convincing, but it does not change the nature of what attackers want. They want money, credentials, and data. The verify-first rule from Module 03 is more important now than ever:
- If a request involves money, verify by phone at a known number.
- If a request involves credentials or sensitive data, verify through a different channel.
- If something feels urgent, slow down. Urgency is the attacker’s weapon, AI or not.
- Report all suspicious contacts to IT or STM. Patterns help identify attack campaigns.
Key Takeaways
- AI makes phishing emails flawless and personalized. Focus on the request, not the grammar.
- Voice cloning can replicate a person’s voice from 3 seconds of audio. Always verify financial requests by calling back at a known number.
- Never paste PHI, client data, financial data, or credentials into public AI tools like ChatGPT.
- Use enterprise AI tools (Copilot, Gemini) with data protection agreements for work data.
- The verify-first rule still works. AI makes attacks more convincing, but verification through a different channel stops them.
Module Quiz
Select an answer for each question to reveal the correct response and explanation.
1. You receive a voicemail from your CEO asking you to urgently buy $2,000 in gift cards. The voice sounds exactly like them. What is likely happening?
2. Why are AI-enhanced phishing emails harder to spot than traditional phishing?
3. You want to use ChatGPT to draft an email about a patient case. The case details include patient names and diagnoses. What should you do?
4. What is a deepfake?
5. Despite AI making attacks more convincing, what defense still works?
Module 09 of 10 – Cybersecurity Essentials Training
