{"id":10482,"date":"2026-01-06T02:54:52","date_gmt":"2026-01-06T02:54:52","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10482"},"modified":"2026-01-06T02:54:52","modified_gmt":"2026-01-06T02:54:52","slug":"actual-world-ai-voice-cloning-assault-a-crimson-teaming-case-examine","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10482","title":{"rendered":"Actual-world AI voice cloning assault: A crimson teaming case examine"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"content-body\">&#13;<\/p>\n<p>As an moral hacker, I put organizations&#8217; cyberdefenses to the check, and &#8212; like malicious menace actors &#8212; I do know that social engineering stays some of the efficient strategies for gaining unauthorized entry to non-public IT environments.<\/p>\n<p>The Scattered Spider hacking group has repeatedly confirmed this level in its social engineering assaults concentrating on IT assist desks at main enterprises, together with on line casino giants <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/caesars-social-engineering-breach\/695995\/\" rel=\"noopener\">Caesars Leisure<\/a> and MGM Resorts, in addition to British retailer Marks and Spencer. In such assaults, a menace actor impersonates a reliable worker and convinces the assistance desk to reset that person&#8217;s password, typically utilizing an authoritative tone or sense of urgency to govern the opposite particular person into granting account entry. Such basic <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/How-to-avoid-and-prevent-social-engineering-attacks\">social engineering<\/a> techniques typically handle to bypass technical defenses solely by exploiting human behavioral weaknesses.<\/p>\n<p>I&#8217;ve used phone-based social engineering in my very own crimson teaming technique for years, and up to date enhancements in deepfake and voice cloning know-how have made such <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Generative-AI-is-making-phishing-attacks-more-dangerous\">voice phishing (vishing) assaults much more efficient<\/a>. On this article, I&#8217;ll stroll you thru a current, real-world instance that demonstrates how simply menace actors are actually utilizing AI-enabled deepfakes and voice cloning to deceive finish customers. CISOs should check their organizations&#8217; means to face up to such assaults, in addition to educate staff on what these strategies seem like and methods to cease them.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"How an AI voice cloning attack tricked a seasoned employee\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>How an AI voice cloning assault tricked a seasoned worker<\/h2>\n<p>As a part of a crimson teaming train, a big enterprise just lately requested me to attempt to hack into the e-mail account of certainly one of its senior leaders. Usually, you want the next three parts to realize entry to an e-mail account:<\/p>\n<ol class=\"default-list\">\n<li>The e-mail tackle.<\/li>\n<li>The password.<\/li>\n<li>A way of bypassing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/multifactor-authentication-MFA\">MFA<\/a>.<\/li>\n<\/ol>\n<p>On this case, the goal&#8217;s e-mail tackle itself was listed publicly. His info had additionally been uncovered in a number of public information breaches, with the identical password apparently in use throughout a number of separate accounts. I surmised he was doubtless to make use of the identical password for his company account login, as properly.<\/p>\n<p>Defeating the corporate&#8217;s MFA, Microsoft Authenticator, was the trickiest a part of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/whatis\/definition\/red-teaming\">crimson group<\/a> train. I made a decision the perfect methodology can be to name the goal and impersonate a member of the corporate&#8217;s IT group, utilizing voice cloning.<\/p>\n<p>First, I recognized the names of the group&#8217;s IT group members <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/How-to-avoid-LinkedIn-phishing-attacks-in-the-enterprise\">on LinkedIn<\/a> after which additional researched them on Google. I discovered that one of many senior IT leaders had given a presentation at a convention, with a 60-minute video of the session publicly out there on YouTube. It&#8217;s doable to clone somebody&#8217;s voice with simply three seconds of audio, so I used to be assured an hour-long recording would allow a really correct and convincing duplicate.<\/p>\n<p>I extracted the audio from the YouTube video and used a device known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchenterpriseai\/feature\/ElevenLabs-and-the-risks-of-voice-generating-AI\">ElevenLabs<\/a> to create a voice clone. I then tried to log in to the goal&#8217;s e-mail account utilizing the password I had discovered uncovered in earlier third-party information breaches, and as anticipated, it labored.<\/p>\n<p>The profitable login triggered Microsoft Authenticator, sending the goal an MFA push notification on his cellphone. I known as him, utilizing the AI voice cloning software program to impersonate the IT group member in our real-time dialog. I defined to the goal that the IT group was conducting inside upkeep on his account, resulting in the MFA immediate, and requested him to enter the two-digit quantity from my display into his Microsoft Authenticator app. Fully satisfied, he typed within the quantity, thereby giving me entry to his e-mail and SharePoint.<\/p>\n<p>The goal had been with the corporate for 15 years on the time of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/Explaining-cybersecurity-tabletop-vs-live-fire-exercises\">crimson group train<\/a>, so his account held a treasure trove of knowledge. If I had been a malicious hacker, I might have began sending e-mail from his actual e-mail tackle, doubtlessly tricking additional employees members or purchasers into opening malicious paperwork or authorizing monetary transactions.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Lessons learned\">\n<h2 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"\/>Classes realized<\/h2>\n<p>This instance demonstrates why I&#8217;ve been unsurprised to see legal teams more and more turning to vishing-based social engineering as a dependable methodology for gaining preliminary entry to focus on environments. As soon as a menace actor has accessed a Microsoft enterprise account &#8212; particularly one with elevated privileges &#8212; compromising the community and working ransomware on all endpoints and essential servers is comparatively easy.<\/p>\n<p>To guard towards these kinds of assaults, CISOs should guarantee IT assist groups comply with clear and constant verification procedures in conversations with finish customers. Most significantly, organization-wide <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/security-awareness-training\">safety consciousness coaching<\/a> ought to educate all staff about these kinds of assaults, the psychological methods they make use of and greatest practices for verifying that somebody is who they declare to be.<\/p>\n<p><i>Rob Shapland is an moral hacker specializing in cloud safety, social engineering and delivering cybersecurity coaching to corporations worldwide.<\/i><\/p>\n<\/section>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>&#13; As an moral hacker, I put organizations&#8217; cyberdefenses to the check, and &#8212; like malicious menace actors &#8212; I do know that social engineering stays some of the efficient strategies for gaining unauthorized entry to non-public IT environments. The Scattered Spider hacking group has repeatedly confirmed this level in its social engineering assaults concentrating [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[717,690,6312,4908,2501,1776,7269,2571],"class_list":["post-10482","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attack","tag-case","tag-cloning","tag-realworld","tag-red","tag-study","tag-teaming","tag-voice"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10482","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10482"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10482\/revisions"}],"predecessor-version":[{"id":10483,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10482\/revisions\/10483"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10484"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10482"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10482"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10482"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 07:58:23 UTC -->