NY Regulators Sound Alarm Over AI-Enhanced Social Engineering Attacks
New York State Department of Financial Services
In a recent Industry Letter addressing statewide financial organizations and affiliates, the New York State Department of Financial Services (NY DFS) warns of the imminent threat posed by criminal agents utilizing the power of AI in their cyberattacks.
While referencing the Department’s Cybersecurity Regulation Part 500 which details mandated data protection requirements for covered entities, the advisory notes that its intent is not to impose additional requirements. Rather, the intent is “to be a tool to assist Covered Entities in understanding and assessing cybersecurity risks associated with the use of AI and the controls that may be used to mitigate those risks.”
When detailing the most concerning AI-enhanced attack vectors, it’s no surprise that Social Engineering tops the advisory’s list.
Social Engineering, after all, is all about human manipulation through deception and, according to security experts at KnowBe4, social engineering tactics are behind 70 to 90% of all data breaches. Increasingly concerning, however, is that 85% of enterprise cybersecurity leaders now say recent cyberattacks are already being augmented by GenAI applications.
What that means is threat actors are supercharging their attacks and evading conventional authentication safeguards by using readily-available GenAI tools to look like, sound like, and interact like someone their victims know and trust.
In fact, the NY DFS specifically calls out vishing (voice phishing) as a growing and increasingly more virulent form of cyber-attack on financial institutions.
As high call-volume organizations overseeing troves of financial resources and personal data, we already know these organizations are clear magnets for phone-based cyberthieves intent on exploiting that human connection. What’s more, it’s apparent that even a well-trained employee force creates an inadequate firewall when direct human-to-human voice contact is involved.
According to the 2024 State of Vishing report from Social Engineer, more than 25% of vishing attempts on employees over the past year resulted in a security breach.
We can only assume that statistic will get worse as GenAI applications proliferate in numbers and sophistication, and criminal impostors continue to add these voice altering/voice cloning capabilities to their vishing attack toolkits.
Note that, as a powerful regulatory body, the NY DFS has the authority to impose stiff penalties on organizations that it determines have failed to meet required cybersecurity protection standards. According to the NY DFS advisory, this now extends to protection against AI-generated threats.
To that point, here is where the advisory gets interesting. Under the “Controls and Measures to Mitigate AI-related Threats” section, it states the following:
“The Cybersecurity Regulation requires Covered Entities to assess risks and implement minimum cybersecurity standards designed to mitigate cybersecurity threats relevant to their businesses – including those posed by AI. These cybersecurity measures provide multiple layers of security controls with overlapping protections so that if one control fails, other controls are there to prevent or mitigate the impact of an attack.”
While intentionally vague in its definition of “minimum cybersecurity standards,” the advisory clearly supports a layered strategy combining recommended policies, practices, and technical controls to address and reduce risk in an ever-evolving threat landscape.
As a leading developer of voice threat defense technologies, Mutare is in full support of this approach. No single practice or solution can possibly promise adequate protection against such a broad-based, highly complex, and continuously evolving threat vector but, instead, should be part of a well-integrated holistic approach as recommended by the NY DFS and outlined in more detail in this set of industry-standard Best Practices.
Mutare has focused our Voice Security solution development expertise on closing the enterprise voice network vulnerability gap. This gap provides an unprotected pathway for voice-based criminal intruders 24 x 7 x 365.
By examining the forensics of individual calls and activity within the voice traffic itself, Mutare’s Voice Firewall detects and deflects the majority of nuisance and nefarious calls Before those calls can reach and possibly compromise their intended human targets – and in so doing, we render AI-enhanced calls pointless.
As part of an organization’s overall cyber-defense ecosystem, the Voice Firewall (aka, Voice Traffic Filter) provides both voice threat protection and intelligence by capturing and integrating voice traffic data into the organizations’ SIEM/XDR security systems for expanded detection of emerging, complex cyber-threat campaigns. Such data is an invaluable resource when included in the organization’s risk assessment practices.
Equally important, our Voice Firewall has flexible deployment alternatives (cloud, on premise, CCaaS via API) and can be easily integrated and added to most organization’s security infrastructure.
So, when answering the call from NY DFS – or really, any data protection regulator – for implementing “minimum cybersecurity standards designed to mitigate cybersecurity threats,” one clear answer is a Voice Firewall, like Mutare’s Voice Traffic Filter, as a front-end fortress within a multi-layered, coordinated cyber-defense strategy.
