• About
  • Subscribe
  • Contact
Thursday, May 8, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home People Culture and Behaviour

Conversational scams jumped 1,200% in 2022

FutureCISO Editors by FutureCISO Editors
May 9, 2023

Image by Thomas Ulrich from Pixabay

Share on FacebookShare on Twitter

Conversational scams that deployed a range of platforms, including SMS, messaging apps and social media, have grown by 1,200% in the past year, according to research data analysed by cybersecurity firm Proofpoint.

This growth has seen conversational threats become the highest category of mobile abuse by volume, overtaking package delivery, impersonation and other kinds of fraud in some verticals.

Source: Proofpoint

According to Proofpoint, growth in conversational threats shows no sign of slowing and has continued through Q1 2023.

Adam McNeil, Proofpoint

Adam McNeil, senior threat research engineer at Proofpoint, said: "Conversational abuse through text and social media is particularly concerning because threat actors spend time and effort (often weeks) building trust with their targeted victims by striking up what starts out as a benign, innocuous messaging conversation designed to trick them, thus circumventing technical and human defences.”

“There are many variations of these attacks and mobile users should be very skeptical of any messages from unknown senders, especially considering how artificial intelligence tools are making it possible for threat actors to make their attacks more realistic than ever."

Adam McNeil, Proofpoint

Ultimately, these attacks are a manifestation of social engineering. Skilled manipulators take advantage of ubiquitous mobile communications to cast their net wide and land as many victims as they can.

Pig butchering operations

Last year, these conversational scams now widely known as pig butchering (a term which originated in China) have victimised countless of people globally in operations that involve a complex web of job fraud, human trafficking and online cryptocurrency fraud.

Thousands of people – most of them from Southeast Asia – have been lured by social media advertisements promising well-paid jobs in Cambodia, Laos and Myanmar, only to find themselves divested of their passport, identity documents and mobile phone. They were taken to large compounds and forced to work 18-hour days to swindle strangers worldwide through various messaging and social media platforms.

Related:  Growth in API and apps is a new target for threat actors

Law enforcement authorities of multiple countries have said the pig butchering operations are being run by Chinese gangsters with ties to gambling across Southeast Asia and are trying to recover losses incurred during the pandemic lockdowns.

“The fact that attackers have adopted conversational lures in email and mobile, and across both financially motivated and state-sponsored attacks suggests that the technique is effective,” said McNeill.

“Society’s receptivity to mobile messaging makes it an ideal threat vector, as we tend to read new messages within minutes of receiving them.”

Adam McNeil, Proofpoint"

In the US, the FBI has recently noted a sharp increase in the number of victims of conversational scams, losing more than US$3 billion to cryptocurrency scams, of which pig butchering is now a leading example. And of course, romance scams, job fraud and other long-standing forms of conversational attack are still fixtures in the threat landscape.

The conclusion of a romance scam—the Bitcoin wallet had received over $2,500 in Bitcoin at time of writing (Source: Proofpoint)

“In addition to financial losses, these attacks also extract a significant human cost. Pig butchering and romance scams both involve an emotional investment on the part of the victim. Trust is earned and then abused, which can prompt feelings of shame and embarrassment alongside the real-world consequence of losing money," said McNeil.

AI will take conversational scams to the next level

With recent advances in generative AI, conversational scammers may not need human help much longer, according to McNeil.

The release of tools like ChatGPT, Bing Chat and Google Bard heralds the arrival of a new kind of chatbot, capable of understanding context, displaying reasoning, and even attempting persuasion.

Related:  99% of businesses in APAC struggle with identity verification 

“And looking further ahead, AI bots trained to understand complex tax codes and investment vehicles could be used to defraud even the most sophisticated victims.”

Left, a common pig butchering image. Right, a similar—but unique—image generated for this post using Midjourney (Source: Proofpoint)

Coupled with image generation models capable of creating unique photos of real-seeming people, McNeil noted that conversational threat actors could soon be using AI as a full-stack criminal accomplice, creating all the assets they need to ensnare and defraud victims.

“And with advances in deepfake technology, which uses AI to synthesise both audio and video content, pig butchering could one day leap from messaging to calling, increasing the technique’s persuasiveness even more.”

Adam McNeil, Proofpoint
Tags: Artificial IntelligenceCambodiaChinaconversational scamscybersecuritycyberthreatsLaosMyanmarpig butcheringproofpointsocial engineeringsocial mediaSoutheast Asia
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses
  • Weak password reuse crisis remains

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl