Axios Codebook

June 13, 2023
Happy Tuesday! Welcome back to Codebook.
- ππ» Hello from Amazon Web Services' security conference in Anaheim, California. Stay tuned for more updates from the event later this week.
- π¬ Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,172 words, a 4.5-minute read.
1 big thing: Generative AI is making voice scams easier to believe
Illustration: Sarah Grillo/Axios
Generative AI has already lowered the bar for cybercriminals looking to clone someone's voice and use it in their schemes.
Why it matters: Cybercriminals now need as little as three seconds of someone's voice to successfully clone it and make it usable in a scam call thanks to generative AI tools, researchers at McAfee have found.
- People are already losing money from these incidents: In a recent McAfee survey, 77% of victims in AI-enabled scam calls said they lost money. More than a third of those victims lost more than $1,000.
The big picture: Scam phone calls have often taken the form of mass robocalls pretending to be a health care provider, the Internal Revenue Service or even a provider looking to extend someone's auto warranty.
- AI-enabled voice scams use generative AI-enabled voice-cloning services to take these one step further and make the calls seem like they're coming from a loved one.
How it works: So far, these AI-enabled voice scams are building on an age-old scheme that targets family members and loved ones.
- In the original scam, someone would call pretending to be the police and claiming that a friend or family member needs money quick to get out of legal trouble.
- Now, using AI, the scammer can pretend to actually be someone's child or other relative using a clone of the real relative's voice.
- Legitimate tools let the scammer respond in real time as they type out sentences in their voice-cloning apps.
- Some scammers even go as far as to research personal information about the victim's relative to make the call more believable.
What they're saying: "It's just a very easy-to-use medium, and the attacker doesn't have to have really any expertise in artificial intelligence," Steve Grobman, chief technology officer and senior vice president at McAfee, told Axios.
Between the lines: Government officials are already seeing signs of generative AI leading to increased voice scams.
- Federal Trade Commission chair Lina Khan said earlier this month that she's seen AI "turbocharge" fraud and scams, including voice calls.
By the numbers: Nearly half of adults (45%) said in McAfee's survey, released last month, that they would respond to a voice note or voicemail from a friend or loved one asking for money.
- 48% also said they'd send money if they got a note saying a friend or loved one was having car trouble or was in an accident.
The intrigue: The AI voice-cloning tools criminals are using also have legitimate use cases, making an outright ban on their use impossible, Grobman said.
- Some of those use cases include helping people with speech impediments communicate or assisting authors recording the audio versions of their books, he said.
Yes, but: AI-enabled voice scams require significant effort that not all criminals will be willing to make.
- Telecom providers are also in the last stages of rolling out call authentication technology that should help flag even more robocalls and spam calls as they come in, John Haraburda, director of product management at data communications provider Transaction Network Services, told Axios.
Be smart: Experts suggested that people adopt codewords between themselves and loved ones to use during calls of distress to ensure that they're legitimate.
- Another easy way to ensure the person on the other end of the line is who they say they are is to hang up and immediately call them back, if possible, Haraburda said.
2. CISA eyes near-term update on secure-by-design
Illustration: Natalie Peeples/Axios
The No. 2 official at the country's cyber defense agency told Axios he's optimistic that companies will apply the agency's new set of secure-by-design principles without much, if any, regulatory force.
Driving the news: Nitin Natarajan, deputy director of the Cybersecurity and Infrastructure Security Agency, spoke with me on the sidelines of the National Retail Federation's cyber conference in Dallas last week.
- Natarajan said the agency is actively working on an update of those principles based on recent feedback from the private sector about what is and isn't feasible.
What they're saying: "We've gotten a lot of great feedback, a lot of positive feedback," Natarajan said. "Organizations want to participate."
- "To us, it's less about having a stick to force that engagement," he added. "If we collectively put out good products and good steps that people can utilize, the uptake should be there."
Catch up quick: CISA released a set of secure-by-design principles in April that encourages software manufacturers to rethink how they design their products to keep the number of possible security vulnerabilities low.
- Some of the principles include sharing information about vulnerabilities they uncover, shifting the burden of security to themselves rather than the customer, and maintaining a leadership structure that prioritizes security.
The big picture: Secure-by-design is a core tenet of the Biden administration's national cybersecurity strategy, which also calls for holding companies liable for at-fault cyber incidents.
- But while the national cyber strategy is seeking out regulations to ensure liability, CISA believes manufacturers will voluntarily sign on to these principles on their own.
- "We're not law enforcement, we're not the intelligence community, and we're not the military," Natarajan said. "We are truly in a role where we just want to help."
The intrigue: CISA jointly published the principles with the FBI, the National Security Agency and international allies in Canada, the U.K., Germany, the Netherlands and New Zealand.
- Each of those countries is also collecting its own set of feedback from the private sector, Natarajan told Axios, and the agency is working closely with the State Department on those international engagements.
What's next: Natarajan said he doesn't have a precise timeline on when to expect an update to the secure-by-design principles, but he noted that it was "definitely a shorter term than longer term."
3. Catch up quick
@ D.C.
πͺ The Justice Department charged two Russian nationals with laundering cryptocurrency as part of the notorious Mt. Gox hack. (Axios)
π A newly declassified report from the Office of the Director of National Intelligence details how the U.S. government purchases data about Americans for surveillance purposes. (Wired)
πΊπ¦ CISA director Jen Easterly said at an event this week that the intelligence sharing that happened in the lead-up to the war in Ukraine can be a model for addressing China's cyber threats. (CyberScoop)
@ Industry
π₯ A hospital in Illinois says it's closing its doors partly because of a 2021 ransomware attack, becoming the first hospital to link its shutting down to such an incident. (NBC News)
@ Hackers and hacks
π°π΅ North Korea state-sponsored hackers have stolen roughly $3 billion in crypto in the last five years. (Wall Street Journal)
πΊ Ofcom, Britian's communications regulator, says it's responding to a data breach connected to the recently discovered security flaw in the MOVEit file-transfer tool. (Reuters)
π©Ί Hackers stole roughly half a million people's personal and health information in a ransomware attack on a Tennessee-based payments vendor. (TechCrunch)
4. 1 fun thing
The entrance to Disneyland (left) and the Ferris wheel at California Adventure Park in Anaheim, California. Photos: Sam Sabin/Axios
I've been to L.A. a handful of times, but this time I finally made it to Disneyland and Disney California Adventure Park.
- Fun fact: If it's your first visit, Disneyland will give you a pin to commemorate the trip. What a treat.
βοΈ See y'all on Friday!
Thanks to Scott Rosenberg for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.


