Updated
Updated · ZDNet · Aug 21
Security Experts Urge FIDO2 Keys, Passphrases After $25 Million Deepfake Fraud
Updated
Updated · ZDNet · Aug 21

Security Experts Urge FIDO2 Keys, Passphrases After $25 Million Deepfake Fraud

3 articles · Updated · ZDNet · Aug 21

Summary

  • $25 million in fraudulent wire transfers at Arup has become a cautionary example for experts arguing that companies need low-tech checks such as hardware keys, verbal passphrases and out-of-band callbacks.
  • 73% detection accuracy in one UCL study — improving just 3.84% with training — underscores why face and voice recognition no longer reliably authenticate callers, while later research found human detection closer to chance.
  • Experts say the bigger risk now extends beyond one-off scams to long-term infiltration, citing a 2024 KnowBe4 case in which a fake hire linked to North Korea received a company workstation before being caught uploading malware.
  • CISA-backed FIDO2 or PIV credentials, no-exception passphrase rules, dual authorization and role-based secret phrases are being recommended for high-risk workflows, with resets triggered by compromise or role changes rather than fixed 90-day cycles.

Insights

If seeing and hearing are no longer proof of reality, how can your company stop AI impostors from stealing millions?
Could the remote employee you hired months ago actually be a state-sponsored AI clone plotting a devastating cyberattack?