<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>deepfake Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/tag/deepfake/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/tag/deepfake/</link>
	<description>First with Security News</description>
	<lastBuildDate>Tue, 30 Sep 2025 06:37:43 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>deepfake Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/tag/deepfake/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Phishing evolves with AI and stealth</title>
		<link>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Tue, 30 Sep 2025 06:37:35 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[voice cloning]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98696</guid>

					<description><![CDATA[<p>Currently, phishing is going through a shift driven by sophisticated AI-powered deception techniques and innovative evasion methods. Cybercriminals are exploiting deepfakes, voice cloning and trusted platforms like Telegram and Google Translate to steal sensitive data, including biometrics, electronic signatures and handwritten signatures, posing unprecedented risks to individuals and businesses. This is according to cybersecurity and [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/">Phishing evolves with AI and stealth</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Currently, phishing is going through a shift driven by sophisticated AI-powered deception techniques and innovative evasion methods. Cybercriminals are exploiting deepfakes, voice cloning and trusted platforms like Telegram and Google Translate to steal sensitive data, including biometrics, electronic signatures and handwritten signatures, posing unprecedented risks to individuals and businesses.</p>
<p>This is according to cybersecurity and digital privacy company Kaspersky, which said it detected and blocked over 142 million phishing link clicks in Q2 2025, a 3.3% increase globally and a 25.7% increase in Africa from Q1.</p>
<p>AI has elevated phishing into a highly personalised threat, Kaspersky said. Large language models (LLMs) enable attackers to craft convincing emails, messages and websites that mimic legitimate sources, eliminating grammatical errors that once exposed scams. AI-driven bots on social media and messaging apps impersonate real users, engaging victims in prolonged conversations to build trust. These bots often fuel romantic or investment scams, luring victims into fake opportunities with AI-generated audio messages or deepfake videos.</p>
<p>Attackers also create realistic audio and video deepfake impersonations of trusted figures — colleagues, celebrities or even bank officials — to promote fake giveaways or extract sensitive information. For instance, automated calls mimicking bank security teams use AI-generated voices to trick users into sharing two-factor authentication (2FA) codes, enabling account access or fraudulent transactions. Additionally, AI-powered tools analyse public data from social media or corporate websites to launch targeted attacks, such as HR-themed emails or fake calls referencing personal details.</p>
<p>Employing new tactics to bypass detection</p>
<p>Phishers are deploying sophisticated methods to gain trust, exploiting legitimate services to prolong their campaigns. For instance, Telegram’s Telegraph platform, a tool to publish long texts, is used to host phishing content. Google Translate’s page translation feature generates links that look like https://site-to-translate-com.translate.goog/&#8230; and are used by attackers to bypass security solutions’ filters.</p>
<p>Attackers now also integrate CAPTCHA, a common anti-bot mechanism, into phishing sites before directing users to the malicious page itself. By using CAPTCHA, these fraudulent pages deflect anti-phishing algorithms, as the presence of CAPTCHA is often associated with trusted platforms, lowering the likelihood of detection.</p>
<p>A switch in hunting: From logins and passwords to biometrics and signatures</p>
<p>The focus has shifted from passwords to immutable data. Attackers target biometric data through fraudulent sites that request smartphone camera access under pretexts like account verification, capturing facial or other biometric identifiers that cannot be changed. These are used for unauthorised access to sensitive accounts or sold on the dark web. Similarly, electronic and handwritten signatures, critical for legal and financial transactions, are stolen via phishing campaigns impersonating platforms like DocuSign or prompting users to upload signatures to fraudulent sites, posing significant reputational and financial risks to businesses.</p>
<p>“The convergence of AI and evasive tactics has turned phishing into a near-native mimic of legitimate communication, challenging even the most vigilant users. Attackers are no longer satisfied with stealing passwords — they’re targeting biometric data, electronic and handwritten signatures, potentially creating devastating, long-term consequences. By exploiting trusted platforms like Telegram and Google Translate, and co-opting tools like CAPTCHA, attackers are outpacing traditional defences. Users must stay increasingly sceptical and proactive to avoid falling victim,” said Olga Altukhova, security expert at Kaspersky.</p>
<p>Earlier in 2025 Kaspersky detected a sophisticated targeted phishing campaign which was dubbed Operation ForumTroll, as attackers sent personalised phishing emails inviting recipients to the “Primakov Readings” forum. These lures targeted media outlets, educational institutions and government organisations in Russia. After clicking on the link in the email, no additional action was needed to compromise their systems: the exploit leveraged a previously unknown vulnerability in the latest version of Google Chrome. The malicious links were extremely short-lived to evade detection and in most cases ultimately redirected to the legitimate website for “Primakov Readings” once the exploit was taken down.</p>
<p>To be protected from phishing, Kaspersky recommends:</p>
<p>Verify unsolicited messages, calls, or links, even if they appear legitimate. Never share 2FA codes.<br />
Scrutinise videos for unnatural movements or overly generous offers, which may indicate deepfakes.<br />
Deny camera access requests from unverified sites and avoid uploading signatures to unknown platforms.<br />
Limit sharing sensitive details online, such as document photos or sensitive work information.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/">Phishing evolves with AI and stealth</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Deepfakes and South African law: remedies on paper, gaps in practice</title>
		<link>https://www.protectionweb.co.za/cyber-security/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Tue, 23 Sep 2025 07:46:19 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98654</guid>

					<description><![CDATA[<p>Deepfakes are forgeries of people’s faces, voices and likeness generated through artificial intelligence (AI). They create a serious digital deception. Deepfakes undermine constitutional rights, reduce trust in media and distort fairness in elections. While many countries have laws that address the risks caused by deepfakes, enforcement remains a challenge. Deepfakes began to be widely created [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice/">Deepfakes and South African law: remedies on paper, gaps in practice</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Deepfakes are forgeries of people’s faces, voices and likeness generated through artificial intelligence (AI). They create a serious digital deception. Deepfakes undermine constitutional rights, reduce trust in media and distort fairness in elections. While many countries have laws that address the risks caused by deepfakes, enforcement remains a challenge.</p>
<p>Deepfakes began to be widely created in 2017 after they’d first appeared on Reddit, a discussion website of forums where people exchange information. A Reddit user called Deepfakes shared an AI software tool that could superimpose celebrities’ faces on pornographic videos. AI-generated media became widely accessible through software apps that enable people to freely create deepfakes.</p>
<p>There are several types of deepfakes:</p>
<p>text deepfakes in the form of fake receipts and identification documents</p>
<p>photo deepfakes, often swapping faces and bodies using apps to create memes</p>
<p>audio deepfakes, where text-to-speech apps are used for voice cloning, often targeting politicians</p>
<p>video deepfakes, where face and movement are transferred onto someone else’s video, commonly used to create “revenge pornography”.</p>
<p>Deepfakes pose three main dangers:</p>
<p>They deceive audiences into believing fabricated media.</p>
<p>They enable cybercrimes, reputational harm and misrepresentation.</p>
<p>They can be published by anyone, including anonymous social media users.</p>
<p>The key issue is how law can protect people from the illegal use of their images, voices, and likenesses in deepfakes.</p>
<p>Since 2020, I have looked at laws that regulate deepfakes in South Africa and their implementation. My findings show that the biggest problem with deepfakes is law enforcement, rather than any lack of laws that prohibit the unlawful creation and distribution of deepfakes.</p>
<p>Deepfake threats</p>
<p>South Africa has seen notable cases that highlight the growing impact of deepfakes. In 2024, Leanne Manas, an award-winning South African broadcast anchor, was a victim when her image was used in fake endorsement of weight loss products and online trading on Facebook and TikTok.</p>
<p>South African-born businessman Elon Musk also appeared in a deepfake video that induced many South Africans to invest in a financial scam that promised high returns.</p>
<p>In 2025, Professor Salim Abdool Karim, the director of the Centre for the AIDS Programme of Research in South Africa, appeared in a deepfake video showing him making anti-vaccination statements while endorsing counterfeit heart medicine.</p>
<p>Legal protection in South Africa</p>
<p>South Africa has a mixed legal system that combines constitutional rights, legislation and common law rules to provide deepfake victims with remedies.</p>
<p>There are laws that provide remedies in both civil and criminal cases. For example:</p>
<p>Cybercrimes Act 19 of 2020: criminalises electronic publication of intimate private images without consent.</p>
<p>Electoral Act 73 of 1998: bans publishing false information to influence elections.</p>
<p>Films and Publications Act 65 of 1996: prohibits online distribution of private sexual photographs and films to cause harm.</p>
<p>Protection of Personal Information Act: prohibits misuse of personal information that infringes privacy.</p>
<p>Common law remedies</p>
<p>Anyone can claim violation of privacy if their private images are used without permission. They can also enforce their right to identity if a deepfake misrepresents them or gives a perpetrator commercial advantage.</p>
<p>I investigated these principles in an article about the impact of deepfakes on the right to identity in South Africa. Using South African cases, I found that the unauthorised use of a person’s identity attributes in a deepfake deserves protection.</p>
<p>The Supreme Court of Appeal confirmed, in Grütter v Lombard, that South African law protects a person’s identity from being exploited without permission. And this protection is supported by the constitutional guarantee of human dignity. Grütter and Lombard once practised on the same premises under the name “Grütter and Lombard”, but Grütter later left. Lombard kept using Grütter’s name without consent. The court ordered him to stop as it falsely implied an ongoing professional association and infringed Grütter’s right to identity.</p>
<p>In another case, a surfer’s magazine called ZigZag published a photo of a 12-year-old girl as a pin-up cover image. The court stressed that the key issue was whether an image was exploited for another’s benefit without consent. The defendants were ordered to pay compensation and costs.</p>
<p>Another case is that of South African television personality, beauty pageant titleholder, businesswoman and philanthropist Basetsana Kumalo. She sued a business that took photos of her while she was shopping in their store and used those images in an advertisement for their products without her permission. The court ruled that using someone’s likeness for false endorsements infringes identity and privacy, because it creates the misleading impression of support for the product, service or business.</p>
<p>These cases fit squarely into the deepfakes misuses, showing that false endorsement, election disinformation and non-consensual pornography on social media can trigger liability.</p>
<p>Enforcement challenges</p>
<p>While South African law provides remedies against deepfakes, four hurdles frustrate enforcement:</p>
<p>South African courts have capacity constraints and struggle to resolve backlogs.</p>
<p>Litigation remains a “rich man’s” option. The poor struggle to access justice or wait too long for pro bono help.</p>
<p>While South African courts can assert jurisdiction over global platforms like Meta and TikTok, serving court orders abroad and compelling compliance is still costly, and takedown notices are often enforced too late.</p>
<p>Perpetrators hide behind fake profiles and are hard to trace through the South African Police Service. Social media companies delay revealing the perpetrators’ true identities upon request.</p>
<p>These enforcement challenges can be addressed through capacity building and legal reform. AI research centres should work with law enforcement to train personnel and provide practical skills and tools for tracing and authenticating deepfakes. Parliament must update social media laws so that platforms are directly accountable for fast and fair action when people’s identities are misused in deepfakes.</p>
<p>Legal rules should set minimum standards that deepfake apps and platforms must follow. Rather than relying on age restrictions or consent alone, the law should require these tools to embed watermarking to signal that content is a deepfake, enable tracing of where it comes from, and make sure takedown systems actually work.</p>
<p>Justice on paper</p>
<p>South African law clearly prohibits the misuse of identity through deepfakes, but enforcement gaps leave victims exposed. Without affordable legal access, faster platform accountability, and effective international cooperation, illegal deepfakes will continue to increase.</p>
<p>Written by Nomalanga Mashinini, Senior Lecturer, University of the Witwatersrand.</p>
<p>Republished with permission from <a href="https://theconversation.com">The Conversation</a>. The original article can be found <a href="https://theconversation.com/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice-263850">here</a>.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice/">Deepfakes and South African law: remedies on paper, gaps in practice</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/deepfakes-and-south-african-law-remedies-on-paper-gaps-in-practice/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title>The alarming rise of AI impersonation: When seeing and hearing isn’t believing</title>
		<link>https://www.protectionweb.co.za/cyber-security/the-alarming-rise-of-ai-impersonation-when-seeing-and-hearing-isnt-believing/</link>
		
		<dc:creator><![CDATA[Ricardo Teixeira]]></dc:creator>
		<pubDate>Mon, 30 Jun 2025 08:50:06 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[MWR CyberSec]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98145</guid>

					<description><![CDATA[<p>Artificial Intelligence (AI) is rapidly evolving, bringing with it incredible advancements. However, this progress also unveils a darker capability: the power to convincingly impersonate individuals through AI generated voice and facial likenesses, commonly known as deepfakes. These sophisticated forgeries are no longer confined to internet memes; they are actively being used in elaborate scams, causing [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/the-alarming-rise-of-ai-impersonation-when-seeing-and-hearing-isnt-believing/">The alarming rise of AI impersonation: When seeing and hearing isn’t believing</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Artificial Intelligence (AI) is rapidly evolving, bringing with it incredible advancements. However, this progress also unveils a darker capability: the power to convincingly impersonate individuals through AI generated voice and facial likenesses, commonly known as deepfakes. These sophisticated forgeries are no longer confined to internet memes; they are actively being used in elaborate scams, causing significant financial, social, and reputational damage. This post delves into how these AI impersonation tools work, examines real-world case studies, and discusses potential mitigations.</p>
<h4><strong>History Of Deepfakes</strong></h4>
<p>The term “deepfake” burst into public consciousness in late 2017 and originated from Reddit, where a user of the same name shared manipulated pornographic videos, often of celebrities, by superimposing their faces onto existing footage. This initial, notorious application combined “deep learning” algorithms with “fake” media, and the release of underlying open-source code made the creation process available to everyone, allowing individuals with moderate technical skills to produce their own versions.</p>
<p>Since then, the technology has evolved at a breakneck pace, moving from these early, often discernible, manipulations to increasingly sophisticated and convincing fakes capable of being used for political disinformation, financial scams, and even live impersonations, marking a swift and concerning progression from niche internet phenomenon to a mainstream societal challenge.</p>
<h5><strong>Case Studies: The Real-World Impact of AI Impersonation</strong></h5>
<p>High-profile cases have demonstrated the devastating potential of this technology. The following two case studies served as the source of inspiration that drove the research MWR CyberSec did into this subject.</p>
<h5><strong>Case Study 1: The Elon Musk Deepfake Scams in South Africa</strong></h5>
<p>In South Africa, a series of sophisticated deepfake scams emerged, leveraging the likeness of Elon Musk and other prominent local billionaires like Johann Rupert and Patrice Motsepe. Scammers created convincing videos where these personalities appeared to endorse AI-powered cryptocurrency trading platforms. These deepfakes promised outlandish returns – for instance, turning a R4,700 investment into R30,000 in a single day.</p>
<p>The deepfake videos were remarkably well-produced, with “Musk’s” voice even mimicking local accents to enhance credibility. These videos circulated widely on social media, with some attracting hundreds of thousands of views. The consequence was substantial financial loss for numerous investors. In one documented instance, an individual invested and lost R5 million to one such scheme. While precise overall numbers are hard to ascertain, the widespread nature of these campaigns suggests that over 150 individuals could have fallen victim to this one specific campaign.</p>
<p>The following two videos show how one such deepfake scheme was created using a real existing interview of Elon Musk on Wall Street Journal and lip syncing it to a different audio source.</p>
<div style="width: 640px;" class="wp-video"><video class="wp-video-shortcode" id="video-98145-2" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-original-900w.mp4?_=2" /><a href="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-original-900w.mp4">https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-original-900w.mp4</a></video></div>
<p>&nbsp;</p>
<div style="width: 640px;" class="wp-video"><video class="wp-video-shortcode" id="video-98145-3" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-1-900w.mp4?_=3" /><a href="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-1-900w.mp4">https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-1-900w.mp4</a></video></div>
<p>This case highlights not only the commercial impact through direct financial losses but also the significant social impact, as it erodes public trust and preys on the familiarity and authority of well-known figures.</p>
<h5><strong>Case Study 2: Arup’s $25 Million Lesson in Live Deepfake Deception</strong></h5>
<p>In a chilling demonstration of how deepfakes can infiltrate corporate settings, a multinational engineering firm called Arup fell victim to a $25 million scam in 2024.</p>
<p>A finance employee based in the company’s Hong Kong office received an email, purportedly from the UK-based Chief Financial Officer (CFO), requesting urgent and confidential fund transfers.</p>
<p>Initially, the employee was sceptical about the email, however, he was then invited to a video conference call. On this call, attackers convincingly impersonating the CFO and other senior executives (whose likenesses and voices were deepfaked in real-time) assured the employee that the instructions were legitimate and allayed concerns. Convinced by what appeared to be a legitimate, multi-participant video meeting with trusted colleagues, the employee authorised transfers amounting to approximately $25 million (HKD 200 million) to accounts controlled by the fraudsters.</p>
<p>This incident was a stark wake-up call, proving that live, real-time deepfakes are now sophisticated enough to deceive professionals in a business environment. The attack resulted in massive financial loss and underscored the potential for severe reputational damage to organisations that fall prey to such schemes. It also highlighted the psychological manipulation involved, as the live video interaction effectively overrode the employee’s initial skepticism.</p>
<h4><strong>How These Things Actually Work: The Technology Behind the Deception</strong></h4>
<p>Deepfakes leverage sophisticated AI to superimpose existing images and videos onto source images or videos (for video deepfakes) or to synthesise a target person’s voice (for audio deepfakes). Here is a general overview of the process that goes into making a deepfake:</p>
<h5><strong>Phase 1: Data Collection</strong></h5>
<p>For both video and audio deepfakes, source material is required for the target person that will be deepfaked. Typically, a significant amount of high-quality video, images and audio is required of the target person in order to train AI models to perform the deepfake.</p>
<p>To perform training, processing has to be performed on the source data such as transcribing audio, cropping images, feature extraction, and various other actions that enhance the training process.</p>
<h5><strong>Phase 2: Model Training (Teaching the AI)</strong></h5>
<p>This is the most computationally intensive phase of the process. The source material gathered by the attacker is fed to a model and training is performed. For video content, this involves learning the unique facial features, expressions, and nuances that make up the target person. For audio training, it involves learning the characteristics of the target’s voice, including pitch, timbre, intonation and rhythm.</p>
<h5><strong>Phase 3: Generation &amp; Refinement (Creating the Fake)</strong></h5>
<p>Once the model has been trained, a deepfake can be produced. This can take the form of pre-recorded video or a live performance deepfake. The trained model from phase 2 generates the target person’s face or voice based on the input it receives from either a driving video or webcam and microphone.</p>
<p>For pre-recorded content, post processing and refinement could also be performed to make the deepfake look and sound more realistic. Lip syncing could be performed or visual artifacts might be edited or hidden with overlays.</p>
<h5><strong>Pre-trained models</strong></h5>
<p>Various pre-trained models are also available that can be used to produce deepfake content. These tools completely eliminate the need to perform vast source material gathering or training a model for millions of iterations, but rather allows a user to upload a short audio clip or even a single picture in order to start the deepfake process. The following video from research done by Bytedance shows just how advanced these pre-trained models can be.</p>
<div style="width: 640px;" class="wp-video"><video class="wp-video-shortcode" id="video-98145-4" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://byteaigc.github.io/X-Portrait2/clip/demo_withaudio/blackwoman_part1/comb_realoldwoman3-crop_new_drivenby_part1_2hs-yt-Pmk0_audio.mp4?_=4" /><a href="https://byteaigc.github.io/X-Portrait2/clip/demo_withaudio/blackwoman_part1/comb_realoldwoman3-crop_new_drivenby_part1_2hs-yt-Pmk0_audio.mp4">https://byteaigc.github.io/X-Portrait2/clip/demo_withaudio/blackwoman_part1/comb_realoldwoman3-crop_new_drivenby_part1_2hs-yt-Pmk0_audio.mp4</a></video></div>
<p>It should be noted that the tool mentioned above was not publicly available at the time of writing due to ethical concerns by the developers (Good!). It does however demonstrate that with the rapid progression of AI tools in our modern age, the limitations for creating deepfakes are becoming less and less of a barrier to entry for attackers.</p>
<h4><strong>Technical Shortcomings Seen In The Practical Application Of Deepfakes</strong></h4>
<p>During MWR’s own attempts at recreating these techniques, some technical shortcomings were encountered that could help identify poorly made deepfakes.</p>
<h5><strong>Audio Deepfake Shortcomings</strong></h5>
<ul>
<li>Unnatural Cadence and Pace: AI models can struggle with rhythm. Listen for speech that is unnaturally fast or slow, as this can cause the AI to generate noticeable glitches or distortions.</li>
<li>Volume Changes: Rapid volume changes from loud to quiet or vice versa can often lead to audio artifacting (that robotic sounding voice) being produced by the model.</li>
<li>Whispers: Whispering lacks strong vocal cord vibration (pitch), which is a key feature that audio models rely on. Consequently, cloned whispers often sound distorted, breathy, or may have bizarre tonal inclinations.</li>
<li>Context is King: The most powerful detection tool is your own familiarity with the person supposedly speaking. If you know them well, you may notice that their diction, tone, or emotional inflection is “off”. Trust your intuition if the voice sounds like them, but the way they are speaking doesn’t.</li>
<li>Vocal Range Mismatch: Real-time voice changers are particularly vulnerable when there’s a significant difference between the input and target voices. For example, if someone with a naturally high-pitched voice attempts to clone a very deep, low-pitched voice in real-time, the output may sound strained, tinny, or unstable. This doesn’t help that much in detecting these as an attacker would likely pick a target that more closely resembles their own voice.</li>
</ul>
<p>The audio samples below demonstrates some of the shortcomings:</p>

<a href='https://www.protectionweb.co.za/wp-content/uploads/2025/06/SD-Original.mp3'>SD-Original</a>


<a href='https://www.protectionweb.co.za/wp-content/uploads/2025/06/SD-Fake.mp3'>SD-Fake</a>

<h5><strong>Video Deepfake Shortcomings</strong></h5>
<ul>
<li>Masks: A deepfake model needs to constantly detect a face in the source video to overlay a target face onto it. If this detection is interrupted—perhaps by a hand passing in front of the face or gestures that the source video didn’t cover (think sticking your tongue out), or poor lighting, the “mask” can break. The results are often jarring and obvious, ranging from features being incorrectly mapped to the fake face momentarily vanishing altogether.</li>
<li>Unnaturally Smooth Skin: The deepfake generation process often involves compressing and then reconstructing facial features. This can lead to a loss of fine detail. Look for skin that appears unnaturally smooth, almost like a digital airbrush has been applied. Details like pores, wrinkles, fine hairs, or even stubble may be smoothed over or absent entirely, giving the person a doll-like appearance.</li>
<li>Irregular Gestures and Behaviour: This is another context-based clue. We all have unique mannerisms, head tilts, and hand gestures that accompany our speech. A deepfake may replicate a face perfectly, but if the gestures or expressions don’t match the person you know, it’s a major red flag. If a normally animated friend is suddenly stiff and inexpressive on a video call, or vice versa, it could indicate that you’re watching a digital puppet, not a real person.</li>
</ul>
<p>The video below demonstrates some of these shortcomings in an exaggerated manner:</p>

<a href='https://www.protectionweb.co.za/wp-content/uploads/2025/06/Shortcomings.mp4'>Shortcomings</a>

<h4><strong>Mitigations and Staying Vigilant: What Can Be Done?</strong></h4>
<p>The U.S. Department of Homeland Security (DHS), in its report “<a href="https://www.dhs.gov/sites/default/files/publications/increasing_threats_of_deepfake_identities_0.pdf">Increasing Threats of Deepfake Identities</a>” emphasises that the threat of deepfakes comes not just from the technology itself, but from our natural inclination to believe what we see and hear. Even less sophisticated deepfakes can be effective in spreading misinformation.</p>
<p>The DHS report outlines that there is no single, universal solution to the deepfake problem. Instead, a multi-pronged approach is necessary, encompassing the following phases of a deepfake attack:</p>
<ol>
<li><strong>Technological Innovation:</strong></li>
</ol>
<ul>
<li>Developing and improving deepfake detection technologies. This is an ongoing “cat and mouse” game as generation techniques become more advanced.</li>
<li>Exploring digital watermarking or authentication technologies that can help verify the authenticity of media.</li>
<li>This phase is largely dependent on developers and organisations that have to consider the ethical implications of what they are developing but also how these safety measures could be added.</li>
</ul>
<ol start="2">
<li><strong>Education and Awareness:</strong></li>
</ol>
<ul>
<li>Critical Evaluation of Media: Individuals need to be educated to critically evaluate online content, especially if it seems sensational or too good to be true. Look for inconsistencies in media, including unnatural features visible artifacting and what some call “uncanny valley”.</li>
<li>Source Verification: Always try to verify the source of information. Is it from a reputable news outlet or official channel? Be wary of content shared widely on social media without clear attribution.</li>
<li>Awareness of Impersonation Tactics: Understand that AI can be used to impersonate executives, colleagues, or public figures. For sensitive requests, especially those involving financial transactions or confidential information, use out-of-band verification (e.g. a phone call to a known number, or an in-person check if possible) before acting.</li>
</ul>
<ol start="3">
<li><strong>Regulation and Policy</strong>:</li>
</ol>
<ul>
<li>Developing legal frameworks and regulations to address the malicious use of deepfakes, including issues of consent, fraud, and defamation.</li>
</ul>
<ol start="4">
<li><strong>Public-Private Cooperation:</strong></li>
</ol>
<ul>
<li>Encouraging collaboration between government agencies, research institutions, and private sector companies (including social media platforms and tech developers) to share information, develop standards, and implement safeguards.</li>
</ul>
<h4><strong>Individual Precautions:</strong></h4>
<p>The DHS highlights different phases and threat actors, however, the core advice for individuals to protect themselves includes:</p>
<ul>
<li><strong>Be Skeptical:</strong> Approach unsolicited communications or unusual requests with caution, even if they appear to come from a known person.</li>
<li><strong>Verify Identity:</strong> If you receive a suspicious video call or audio message, try to verify the person’s identity through a different communication channel that you know is legitimate. Ask questions that only the real person would know.</li>
<li><strong>Look for Tell-Tale Signs:</strong> While deepfakes are getting better, some artifacts may still be present:
<ul>
<li>Unnatural eye movements or lack of blinking.</li>
<li>Awkward facial expressions or lip-syncing.</li>
<li>Blurring or distortion, especially where the face meets the hair or neck.</li>
<li>Strange lighting or skin tones.</li>
<li>Audio that sounds robotic, has an unusual cadence, or lacks emotional depth.</li>
</ul>
</li>
<li><strong>Report Suspected Deepfakes:</strong> If you encounter a malicious deepfake, report it to the platform where you saw it and, if appropriate, to law enforcement.</li>
</ul>
<p>AI-driven impersonation is a rapidly evolving threat that poses significant risks across personal, commercial, and societal domains. As the technology becomes more accessible and sophisticated, the potential for misuse grows. By understanding how these deepfakes are created, learning from real-world incidents, and adopting robust mitigation strategies that combine technological solutions with critical human awareness, we can better defend ourselves against this new wave of digital deception. Staying informed and vigilant is our first and most crucial line of defence.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/the-alarming-rise-of-ai-impersonation-when-seeing-and-hearing-isnt-believing/">The alarming rise of AI impersonation: When seeing and hearing isn’t believing</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-original-900w.mp4" length="6736165" type="video/mp4" />
<enclosure url="https://int.nyt.com/data/videotape/finished/2024/07/disinfo-musk/musk-overlap-1-900w.mp4" length="9472225" type="video/mp4" />
<enclosure url="https://byteaigc.github.io/X-Portrait2/clip/demo_withaudio/blackwoman_part1/comb_realoldwoman3-crop_new_drivenby_part1_2hs-yt-Pmk0_audio.mp4" length="3736284" type="video/mp4" />

			</item>
	</channel>
</rss>
