Large Language Model (LLM) AI is raging across industries, sending shockwaves of awe and horror in equal measures, and raising so many questions.
Are services like OpenAI's ChatGPT a threat or friend? If they are detrimental? Should they be regulated? Can we leverage the power of AI in organisations to protect ourselves better and, automate our digital and physical worlds?
In this blog, we will explore scams generated using LLM AI, and what we can do to remain vigilant against the security risks that arise as you join the AI Party!
Like any highly disruptive technology, the good comes with the bad. We saw this, with the advent of the Cloud, bringing benefits galore and the pundits applauded the innovation.
However, not many folks talked about the darker side of the Cloud. This includes soaring carbon emissions from data centres, data security, migrating workloads, and exposing not one, but many customers to a data breach, data sovereignty, and information ownership.
These problems are still being grappled with today. Regulations such as GPDR and digital privacy laws are only just starting to catch up.
In March 2023, Elon Musk sponsored a petition with other scientists, researchers, and technology leaders to pause AI, due to the profound and detrimental impact it could have on society. Microsoft, Google, AWS, and Meta (Facebook) formed an industry working group in July 2023. The Frontier Model Forum was formed to investigate making AI transparent and safe across the industry.
So, how can we make our organisations safe against threat actor-driven AI?
Awareness: Understanding what threat AI could pose for your organisation.
Research: Keeping track of proof of concepts regularly published on this topic.
Use and understanding:How to make AI work for you?
Awareness: Understanding what threat AI could pose for your organisation
Large Language Model AI such as ChatGPT fundamentally makes research, coding, and complex language tasks very easy for bad actors and lowers the barrier of entry to cybercrime for everyone.
The primary, and in fact, the greatest threat to an organisation, is business email compromise (BEC). Email scams overshadow any other cyber incident cost by a significant margin. Email is the communication highway for your organisation. Most of these attacks are launched from overseas countries where English may not be the first language and, in the early days, (see below example) invoice and supply scams were easy to spot.
Article 1: An example of an overseas-based, human-produced email invoice scam.