AI-Powered Scams: How Hackers Steal Accounts & Use Deepfakes

by priyanka.patel tech editor

The seemingly personal messages arriving on Zalo and Facebook are increasingly likely to be crafted not by a friend or family member, but by sophisticated artificial intelligence. A growing wave of scams targeting users of these popular social platforms is leveraging AI to steal accounts and defraud victims, prompting warnings from law enforcement in Vietnam and raising concerns about the evolving threat landscape.

The core of the scam relies on deceptively simple tactics: phishing links delivered via SMS, disguised as enticing offers – photo contests, singing competitions, or even notifications of alleged policy violations. Once a user clicks and enters their credentials, their account is compromised. But the fraudsters aren’t immediately cashing in. Instead, they’re using AI to meticulously study the victim’s communication patterns, contacts, and relationships, building a digital profile to convincingly impersonate them.

This impersonation is where the danger escalates. Scammers then contact the victim’s friends and family, often via SMS, fabricating urgent emergencies – accidents, hospitalizations, or desperate financial needs – and requesting money. The sophistication of these scams is amplified by the emergence of “deepfake” technology, allowing criminals to create realistic fake videos and audio recordings. Victims requesting a video call to verify the identity of the person asking for money may be shown a pre-recorded video that convincingly mimics their loved one, with the call abruptly disconnected under the guise of a poor connection.

One recent case involved a woman in Ho Chi Minh City, identified only as H., who received a message on Facebook from a profile appearing to belong to a close friend requesting 50 million Vietnamese Dong (approximately $2,000 USD). According to reports, after a video call that seemed to confirm the friend’s identity, she transferred the money, only realizing she’d been scammed after contacting her friend through a known phone number. Similarly, a man in Hanoi, identified as T., had his Zalo account hacked. Scammers then flooded his contact list with requests for loans, and a friend unknowingly transferred 20 million VND ($800 USD) before the hack was discovered.

Authorities are sounding the alarm. The Thanh Binh district police in Dong Thap province are urging citizens to avoid clicking on suspicious links, sharing one-time password (OTP) codes, and to independently verify any requests for money from known contacts via phone or in person. “Cybercriminals are intensively using AI and deepfake technology to create extremely realistic forgeries, making it very difficult for users to distinguish between real and fake,” explained Vu Ngoc Son, a cybersecurity expert, in a statement reported by Khoa Hoc Doi Song. “The risk of fraud in cyberspace is therefore ubiquitous.”

How AI is Changing the Game

The use of AI isn’t simply about creating convincing fakes; it’s about automating and scaling the fraud process. Ngo Minh Hieu, another cybersecurity expert, notes that AI is now used to handle everything from initial contact and chat interactions with victims to analyzing their psychological profiles, significantly increasing the efficiency of these scams. This automation allows criminals to target a far larger number of potential victims simultaneously.

The speed and sophistication of AI-powered scams are outpacing traditional security measures. Previously, scammers relied on mass, untargeted phishing attempts. Now, they can tailor their approach to each individual, making the scams far more believable, and effective. The ability to generate realistic deepfakes adds another layer of deception, eroding trust in even video communication.

Protecting Yourself: A Multi-Layered Approach

Experts recommend several steps to protect against these evolving threats. Enabling two-factor authentication (2FA) on all accounts is crucial, adding an extra layer of security beyond just a password. Limiting the amount of personal information shared on social media can also reduce the amount of data available to scammers. And, critically, users should avoid conducting financial transactions solely based on text messages or video calls.

A simple, yet effective, rule of thumb is the “5-second rule”: before transferring any money, take five seconds to verify the information through official channels. This means contacting the person directly through a known phone number or email address, rather than responding to the request within the suspicious message.

Das 2020 vom Cybersicherheitsexperten Ngo Minh Hieu mitbegründete Anti-Phishing-Projekt hat zum Ziel, die Vertrauenswürdigkeit von Websites zu überprüfen und vor unsicheren Webseiten zu warnen. Nutzer können Daten beitragen, indem sie schädliche Links auf chongluaodao.vn melden.

New Tools to Combat Phishing

Recognizing the growing threat, organizations are developing new tools to support users identify and avoid phishing scams. The Anti-Fraud Project, for example, recently updated its website, chongluaodao.vn, to include chatbots and AI-powered tools that can analyze websites for malicious content. Users can submit a link to the site, and the system will compare it against a database of known scams and third-party data to determine its safety. The site also offers an “AI Analysis” feature that uses artificial intelligence to assess a website’s risk level based on factors like domain name, content, and hosting information, providing a risk score from 1 to 10.

This proactive approach to identifying and flagging potentially fraudulent websites is a crucial step in combating the increasing sophistication of online scams. However, experts emphasize that technology alone is not enough. Vigilance and a healthy dose of skepticism remain the most important defenses against these evolving threats.

As AI technology continues to advance, the battle against online fraud will undoubtedly become more complex. The Vietnamese authorities are continuing to investigate these incidents and are working to raise public awareness about the risks. Further updates on this evolving situation, including any new enforcement actions or public safety advisories, will be released through official government channels.

If you’ve been targeted by a scam, or suspect fraudulent activity, report it to your local law enforcement agency and the social media platform where the incident occurred. Share this information with your friends and family to help them stay safe online.

You may also like

Leave a Comment