Watch out - OpenAI is being spoofed as part of a major phishing attack
Cybercriminals are using AI tools in their phishing attacks, experts warn
New research from Barracuda has revealed threat actors are now using OpenAI in impersonation campaigns that target businesses across the globe.
The attack uses an email which impersonates OpenAI and sends an ‘urgent message’ to the victims recommending they update their payment information for their subscription, all through their handy direct link - a textbook phishing technique.
The operation was far reaching, with one email being sent to over 1,000 users. The first red flag was the sender's email address, which did not match the official OpenAI domain (e.g. @openai.com). Instead, it was sent from info@mta.topmarinelogistics.com.
AI powered
Worryingly, the email passed DKIM and SPF checks, meaning it was sent from a server that is authorized to send emails on behalf of the domain. The language in the email is common for phishing attacks, pressuring the user to take immediate action and creating fear and urgency.
This is far from the only AI related malicious campaign reported in the last few months. Earlier in 2024, a Microsoft report found 87% of UK organizations are more susceptible to cyberattacks thanks to the increasing use of AI tools.
That’s not to mention the rise in deep fake and convincing AI voice scams that have been targeting businesses and consumers. Already businesses around the world have lost millions to deep fake fraud, and almost half have been targeted at some point by this type of scam.
The introduction of machine learning algorithms that can uncover and leverage software flaws means that AI is leading to a dramatic increase in the number of attacks.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Despite this, research indicates that 90% of cyberattacks will still involve some element of human interaction, like with phishing attacks, so making sure everyone in your organization is trained to spot the signs of an attack is the best protection for a business.
More from TechRadar Pro
- Check out our pick of the best antivirus software
- Linus Torvalds slams AI as ‘90% marketing and 10% reality’
- Take a look at our best malware removal software choices
Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.