While most of the big corporations have developed AI models to make our lives easy, there are always those who use it for wrongdoings. One such instance is leveraging AI for “spoofing” to take control of digital accounts, including Gmail, the world’s most popular email service provider.
With more than 2.5 billion accounts, Gmail is an easy target for bad actors, who are using a new trick dubbed a “super realistic AI scam call,” which can fool even tech-savvy users.
Sam Mitrovic, the founder of CloudJoy and an expert on security products, recently published a blog about how he was duped online. He received an email mimicking an approval notification for his Gmail account recovery. The rejection was followed by a phone call with the caller ID showing “Google Sydney.”
Also Read: Google To Expand Gemini Live To Over 40 Languages
How Cybercriminals Used AI To Fool A User
A week later, Mitrovic got another Gmail recovery notification and a phone call. This call also came from a legitimate phone number listed on Google’s support page. The caller stated his account had been logged in from overseas for over a week, and the personal data related to the account had been downloaded.
He later got an email on his request, notifying him of the same issue but in text format. The email came from a Google domain, which could fool almost anyone. When the user got the call, he suspected it was a scam and started to investigate deeper. With the help of online forums, he confirmed it was a spoofing attempt to take over his Gmail account.
A legitimate phone number identical to Google Workforce support, an email with a Google domain spoofed using a Salesforce CRM, and a legitimate-sounding AI voice bot are more than enough to trick most users into falling for the scam.
Also Read: YouTube Shorts Update Increases Video Length To 3 Minutes
AI Voice Models Helping Scammers
Until a few years ago, these scams needed an actual person to make the voice call. However, with the advancements in AI, there are now realistic-sounding AI voice models, it has become simpler for scammers. Now, a bad actor can easily initiate thousands of these attempts at one time.
This instance shows that hackers use a combination of tricks, including fake emails, phone numbers, and AI bots to fool users. As of now, there is no foolproof way to prevent this from happening.
However, users can protect themselves from these scams by staying vigilant. In this day and age, our Gmail account is our digital identity, used for personal and professional reasons.