Financial Institutions Bracing for Tsunami of Voice-Based Cyber Attacks

Protecting the enterprise telephone system from voice-based attacks may be the lynchpin in the battle against the growing wave of cyber-threats in the form of social engineering, vishing and ransomware. It is time to take Voice Security seriously.

In this article:

Financial Institutions are Highly Targeted

As guardians of vast amounts of personally identifiable information (PII) and monetary resources, it’s no surprise that banks, insurers, brokerage firms and investment organizations would be disproportionally targeted by cybercriminal intruders. These organizations, in fact, are 300 times more likely than other organizations to experience a cyber-attack.

Notably, protection of that personal information is critical to these institutions and the people they serve as it is commonly used for customer ID verification and account access. When falling into criminal hands, stolen PII becomes the essential ingredient for cyber-fraud.

Now, the level of risk for cyber-attacks on financial institutions just got a lot worse.

 

The Recent Successful Cyber-Attack on National Public Data

The unfolding story of the recent massive hack on National Public Data – an organization that aggregates data for background checks, has dramatically escalated the fraud threat level for financial institutions.

The April 2024 breach and subsequent leak, revealed through an August class action lawsuit filing, reports the release and exposure of sensitive personal data for nearly 2.9 billion individuals (that’s nearly nine times the entire current population of the United States). The records include names, addresses, phone numbers, email addresses, social security numbers, names of parents and siblings – in other words, data that is commonly used for ID verification and account access authorization is now in the hands of social engineering criminal impostors and threat agents.

Considering the level of success cyber-thieves were already enjoying and the massive package of exploitable customer data that can now be used to feed their criminal endeavors, there is clear urgency in the need to strengthen the financial industry’s cybersecurity shields – particularly around voice.

Financial Communications: The Importance of the Telephone

The relationship between financial institutions and their customers is uniquely high-touch with person-to-person interactions commonly handled through the phone.

The personal, interactive nature of telephone conversations supports quick issue resolution, particularly when dealing with issues of a complex or sensitive financial nature. In the process, these interactions help the organization build trust and brand loyalty with its customer base.

Unfortunately, enterprise telephone systems (aka, the voice channel) have increasingly become a conduit for cyber-criminals who recognize in it a fresh opportunity for criminal exploitation.

Voice-Based Threats: The Basics

To understand how the telephone (voice) has become a potent threat vector for financial institutions, and how those institutions can better protect themselves, it is important to first identify the various forms of voice-based threats, how they specifically impact financial organizations, and what it is about the financial sector that makes it so vulnerable to these forms of attack.

At the most rudimentary level, voice-based cyber-threats fall into two categories: 

Nuisance Threats:  Inbound phone calls which inhibit, or are a barrier to, an individual or organization reaching optimal performance. Threat types include: Robocalls, Voice Spam, Spoof Calls.

Nefarious Threats:  Inbound phone calls which pose a significant and substantial malicious threat to an individual or to the organization. Threat types include: Social Engineering, Vishing (Voice Phishing), GenAI-Based Attacks, Voice Spam Storms, Spoof Calls.

Definitions: Top Voice-Based Threats

There is a broad and ever-evolving number of voice-based attacks which impact financial institutions. The most pervasive and detrimental are:

Social Engineering: Social engineering is the broad term for manipulation tactics used by skilled threat agents to influence or deceive a targeted victim into taking actions or providing information needed to perpetrate fraud.

Vishing: Vishing (Voice Phishing) is a form of social engineering perpetrated through voice calls. The attacker(s), often impersonating a trusted source or customer, utilizes a combination of spoofed (digitally altered) caller IDs and personal information gained through public sources, social media, or harvested from prior data breaches, to boost credibility, gain trust, and then manipulate the call recipient into taking actions or providing compromising information.

GenAI-Based Attack: In this scenario, the criminal visher targets a specific internal group or demographic, usually starting with a robocall campaign carrying a pre-recorded message that has been AI-generated to match the voice of a trusted superior or colleague with an action request. Those that respond may be further targeted.

Gen AI applications can be used to harvest information on potential attack targets, generate interactive scripts, mask caller identity through audio manipulation, and create malware code used in ransomware attacks.

Voice-Based Threats: Trends in the Financial Sector

No doubt any employee at the end of a business line can attest to the growing amount of voice spam coming across the network. More alarming, however, is the steady acceleration of Nefarious call activity targeting financial institutions. As high call-volume organizations that value personal interaction with their customers, financial institutions have become magnets for phone-based fraudsters intent on exploiting that human connection to access customer accounts or organizational data. 

With the digitalization of voice calling and ready access to personal information via public sources or found in the vast cache of stolen data on the Dark Web (note afore mentioned National Public Data breach), these anonymous deceivers can easily disguise their identity through spoofed (digitally manipulated) Caller ID numbers and socially-engineered personas. Once a voice connect is made, they apply psychological manipulation to lure their unsuspecting targets into divulging account or network-compromising information. 

When perpetrated on an employee with access to internal systems (IT, Human Resources etc.) or contact center agents who may be particularly vulnerable when in a customer support, tech support, or accounts management position, the damage could be catastrophic if resulting in a breach. Fallout can include loss of proprietary information, compromised customer personal identifying information (PII), hijacked accounts, financial theft, malware intrusion, ransomware extortion, loss of customer trust, and regulatory fines and/or class action litigation.

 

Social Engineering Creates Initial Access

The profile of a voice-based cyber-attack is no longer that of a lone perpetrator. Today’s sophisticated campaigns are more often driven by multi-department underground organizations working as a coordinated unit, with social engineering a key component. Common players behind these attacks include specialists trained to:

  • Gather intel/personal data harvested from public sources, social media, or stolen from prior hacks;
  • Serve as Initial Access Broker who probes potential organizations for network vulnerabilities and then sells that knowledge to hacking groups;
  • Carry out the actual live call utilizing social engineering and psychological manipulation to extract compromising information from the call recipient;
  • Use that compromised information to gain initial access, infiltrate systems, and steal funds, exfiltrate data and/or deploy ransomware;
  • Act as negotiators for terms of payment in the event of a successful ransomware deployment

 

Vishing is Growing Problem

As a relatively low-tech threat tactic, voice phishing (vishing) is surprisingly effective. According to the 2024 State of Vishing report from Social Engineer, more than 25% of vishing attempts on employees over the past year resulted in a security breach. What’s more, such attacks are on the rise, with a reported 260% increase from 4th quarter 2023 compared to the same 2022 timeframe.

 

GenAI Makes Cybercriminals More Powerful & Effective

To make matters worse, voice-based threat agents are now also harnessing the power of GenAI  applications to fortify their deceits. These applications can be used to identify high-value vishing targets and gather impersonation-supporting personal information. What’s more, using GenAI speech synthesizing capabilities, voice phishers can actually sound like the trusted source they pretend to be.

The use of voice cloning (deep fake) technology is becoming more prevalent as user-friendly Generative AI applications are now readily accessible to the general public or sold in bootleg form through the Dark Web. The familiar voice not only gives the call greater credibility, but it may also evade detection by fraud prevention applications that depend on voice biometrics (analysis of audio qualities) to separate known callers from potential scammers.

As GenAI continues to expand in content and sophistication, so, too, will its exploitation by criminal agents. In fact, according to this CFO magazine report, 85% of cybersecurity leaders now say recent cyberattacks are already being augmented by GenAI application.

 

Ransomware Attacks Up Significantly

When cyber breaches result in a ransomware event, the consequences can be especially devastating. Financial services, by their very nature, have become prime targets for ransomware-wielding extortionists.

Ransomware is a type of malicious encryption software that, if deployed as part of a hacking scheme, locks users out of their electronic systems until a ransom is paid. According to a report from cybersecurity provider Sophos, ransomware attacks on financial services have increased from 55% in 2022 to 64% in 2023, which is nearly double the 34% reported in 2021. Only a small percentage of victimized organizations were able to thwart the attack, while 81% of attacked organizations reported data encryption.

As documented in their Cybersecurity and Financial System Resilience report, the Federal Reserve Board cites the rise of criminal Ransomware as a Service (RaaS) organizations as a primary driver in the sharp increase of such attacks, with a growing league of hacker wannabes able to simply purchase the necessary malware code (now commonly AI-generated) from underground providers.  

The fallout of a successful ransomware attack in the financial sector is substantial, with the mean cost of recovery now at $2.58 million per event.  

 

Hacktivists, a New & Expansive Threat to the Financial Ecosystem

Monetary gain is not the only motivator for criminal hackers. Financial institutions are also prime targets for a growing league of ideologically-motivated, technologically savvy activists, or “hacktivists”.

Fueled by geo-political tensions, hacktivists are motivated, not by financial gain but, rather, by a drive to inflict political or economic damage through institutional sabotage. 

The digitalization of internal records and interconnectivity of financial organizations into the broader national economic infrastructure makes financial organizations particularly attractive to hacktivist targeting since compromising one organization’s internal networks could potentially lead to a systemic cascade of damages. This concern is supported by recent postings from the International  Monetary Fund (IMF) detailing the alarming rise in cyber threats to financial organizations and the risk they pose to overall economic stability.

In fact, according to the IBM Cost of a Data Breach 2024 report, attacks intended primarily to cause lasting and expensive damage have, in recent years, proved more costly than either ransomware attacks or data exfiltration attacks.

The High Costs of a Data Breach in the Financial Sector

It’s something of an irony that, as one of the most highly-regulated industries in the world, the financial industry is also among the most likely to be hacked by cybercriminals whose actions threaten the welfare of the very people and institutions such directives are designed to protect.

 The reality is, with vast amounts of customer data and financial resources under their care, financial organizations are being held to an especially high standard when it comes to data protection and cyber-security.

 Nevertheless, not only are data-breaching attacks on these institutions far more common than for other industries (three-quarters of financial services organizations have suffered a breach over the past five years), but they are also more costly.

 

Industry Metrics Confirm the Problem is Getting Worse

According to the IBM Cost of a Data Breach 2024 report, financial companies spent $6.08 million on average dealing with data breaches. That is an 11% increase over the prior year and 22% higher than the overall global average.  Much of this increase, according to the report, is due to the rising cost of lost business (including loss due to system downtime, lost customers, and reputation damage), and cost of recovery efforts.

 

Regulatory Costs:  Know Your Customer

These costs include escalating regulatory fines, particularly those related to Know Your Customer (KYC) Fraud. KYC is a standard applied to financial service operations and enforced by the Financial Crimes Enforcement Network (FinCEN) that ensures customers’ identities and risk profiles are accurately verified prior to financial interactions. Any event resulting in a data breach could be considered a KYC violation.

 According to this Markets Media report, fines related to KYC infractions reached a record high of $51 Million in the first half of 2024. Banks were on the receiving end of the most stringent enforcement actions at $136 million.

 What’s more, when a breach of personal customer information occurs, class action lawsuits like that recently settled by Capital One for $190 Million are common, citing the organization’s failure to take “reasonable” cybersecurity measures to protect their customers’ data.

Cybersecurity Spend Goes Up…are you protected?

A recent McKinsey & Company report reveals that financial institutions are now committing, on average,  nearly 13% of their overall IT budget to cybersecurity, targeting fraud, phishing and social engineering as top risk priorities. And yet, only 31% of respondents to the survey felt their organization had the level of protection needed to mitigate those risks.

Why? Because traditional security measures simply aren’t enough when addressing the voice security threat.

 While employee training is important, 58% of working adults surveyed for the 2024 Proofpoint State of the Phish Report admit to taking actions that expose them to common social engineering tactics despite knowing the risk. Two recent studies reveal that human error is behind 88-95% of all data breaches. And while many financial organizations rely on Multi-Factor Authentication (MFA) to confirm the identity of a caller, the perception that MFA provides adequate protection against skilled threat agents is belied by the facts: According to Fraud.net, 30% of fraudulent callers are now able to successfully defeat MFA through use of stolen/harvested PII and social engineering.

Clearly, humans make imperfect voice firewalls, and standard employee training and caller authentication applications are simply not enough as voice-related attack incidents continue to accelerate.

Voice Security…Yes, there is a cyber-solution for that.

Voice-based cyber-threats have one common element – they require a direct connection between the threat agents and their human targets. So, the more an organization can reduce the possibility of suspicious calls reaching human endpoints for confirmation, the less chance criminal vishers will be able to socially engineer, and potentially breach, their intended victims.

In other words, as voice-based threat agents become more sophisticated and better armed, organizations can no longer continue to place the burden of defense on the unprotected people at the other end of the call. In order to clearly close the gap in their attack surface, financial organizations must integrate the de-weaponization of voice calls into a broader, comprehensive cybersecurity and risk management strategy.

One step to take now for immediate impact:  Implement a technology solution that removes unwanted, distracting, and potentially criminal calls from all incoming voice traffic Before those calls have a chance to reach their human endpoint.

One standout solution is the Mutare Voice Traffic Filter. VTF is a call control and voice security software solution that analyzes incoming call data at the start of the call flow. It detects and removes those calls that are clearly unwanted while redirecting to another resource those deemed suspicious based on multiple layers of call data analysis.

The application includes a fail-safe voice CAPTCHA feature that adds an extra layer of vetting to calls of ambiguous nature to further separate live callers from bots as an added form of protection against false negative flagging.

What’s more, VTF includes a tool to capture and integrate call data into the organizations’ SIEM/XDR security systems for expanded detection of emerging, complex cyber-threat campaigns. This is an especially important feature for financial institutions since a common pretext of attacks generated from sophisticated criminal enterprises involves reconnaissance probing from a number of different angles. For optimal XDR threat detection performance, it is important that data from all network activity, including voice, be aggregated and analyzed for suspicious trends.

VTF is highly adaptable to the evolving IT infrastructure landscape and can be deployed on-premise, in the cloud, or in mixed environments, and includes an API for cloud contact center (CCaaS) platform integration.

Considering the unique vulnerabilities of the financial sector ecosystem, implementing a solution like Voice Traffic Filter is just one part of a comprehensive cybersecurity defense strategy, but an invaluable one that closes a dangerously gaping Voice Security hole that currently exists for so many organizations.

To learn more, click Here,