LastPass targeted by deepfake scam

Published:

spot_img

LastPass Targeted by Deepfake Call Impersonating CEO: Cybersecurity Alert

LastPass, the password manager giant with over 25 million users, recently fell victim to a deepfake call impersonating the company’s CEO, Karim Toubba. In a blog post, LastPass disclosed that one of its employees received a series of calls, texts, and a voicemail featuring an audio deepfake from a threat actor posing as Toubba on WhatsApp.

The use of WhatsApp, a communication channel not commonly utilized by the company, raised suspicions, prompting the employee to report the incident to the security team. Fortunately, LastPass confirmed that the deepfake attack had no impact on the company’s overall security.

This isn’t the first time LastPass has faced security challenges. In 2022, the company admitted to being hacked, resulting in the exfiltration of internal data that was later used to access customer data.

Deepfake technology, which uses generative AI to create fabricated videos or audio, is a growing concern globally. A study by University College London revealed that humans struggle to detect these hoaxes, posing significant security risks.

In a separate incident in February, fraudsters used deepfake technology to orchestrate a fake video conference call, deceiving a finance worker into transferring $25 million.

Acknowledging the threat posed by deepfakes, major tech companies like Google, Meta Platforms, Microsoft, and OpenAI have joined forces to prevent the spread of deceptive AI content during the 2024 global election cycle.

As the prevalence of deepfakes continues to rise, it is crucial for companies to remain vigilant and implement robust security measures to protect against such sophisticated attacks.

spot_img

Related articles

Recent articles

Unlock Full Criminal Access to Your Small Business for Just $600 on the Dark Web

The Rising Threat of Cybercrime: Small Businesses at Risk In today's digital landscape, many believe that cyber threats mainly target large enterprises. However, a recent...

Activision Pulls Call of Duty Game Following Player Hacks

Activision Suspends Call of Duty Title Following Security Concerns Overview of the Incident In a significant move, Activision has temporarily removed Call of Duty: WWII from...

The Evolving Role of the CISO in an AI-Driven World

The Future of Cybersecurity: Insights from Roland Daccache Roland Daccache, the Senior Manager of Sales Engineering for the Middle East and Africa at CrowdStrike, sheds...

Active Exploitation of Critical Vulnerability in Wing FTP Server (CVE-2025-47812)

Critical Vulnerability in Wing FTP Server Exposed: What You Need to Know Overview of the Vulnerability A severe security flaw affecting the Wing FTP Server has...