LastPass successfully prevented a deepfake audio scam where cybercriminals used AI-generated voice technology to impersonate CEO Karim Toubba in an attempted social engineering attack via WhatsApp against a company employee.
LastPass experienced an attempted deepfake audio scam where threat actors used AI-generated voice technology to impersonate CEO Karim Toubba. The attack involved a series of calls, texts, and at least one voicemail sent to a LastPass employee via WhatsApp, featuring an audio deepfake of the CEO's voice. The employee recognized red flags including the unusual use of WhatsApp for business communication and typical social engineering tactics such as forced urgency. The employee appropriately ignored the messages and reported the incident to LastPass's internal security team. The company confirmed there was no impact to their security posture or operations. LastPass publicized the incident to raise awareness about the growing threat of deepfake technology being used for executive impersonation fraud. The report also references other similar incidents, including a February 2024 case where a Hong Kong multinational company employee was tricked into paying HK$200 million (approximately US$25.6 million) to scammers using AI-generated deepfake technology, and an August 2022 incident involving Binance where scammers used a deepfake hologram of their communications officer.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Using AI systems to gain a personal advantage over others such as through cheating, fraud, scams, blackmail or targeted manipulation of beliefs or behavior. Examples include AI-facilitated plagiarism for research or education, impersonating a trusted or fake individual for illegitimate financial benefit, or creating humiliating or sexual imagery.
AI system
Due to a decision or action made by an AI system
Intentional
Due to an expected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed