Summer 2023 | Page 16

Do Lawyers Need to Be Concerned About Deepfakes ?

By Mark Bassingthwaighte
The short answer is yes , everyone does ; but the reason lawyers need to be concerned requires a longer explanation .
What is a Deepfake ?
The word “ deepfake ” comes from combining the words “ deep learning ” with the word “ fake .” A deepfake is digital content that can be created using powerful techniques from machine learning and artificial intelligence to manipulate existing or generate new visual and audio content that can easily deceive others who view or hear it . Deepfakes aren ’ t by definition all bad , for example , deepfake technology is used by the film industry . It ’ s only when a bad actor creates a deepfake for use in furtherance of a cyberattack , fraud , extortion attempt , or other scam that they become a serious concern .
Isn ’ t Creating a Deepfake Crazy Hard to Do ?
Not anymore . Jai Vijayan , contributing writer at Dark Reading recently stated : “ It ’ s time to dispel notions of deepfakes as an emergent threat . All the pieces for widespread attacks are in place and readily available to cybercriminals , even unsophisticated ones .”
Researchers with the security company Trend Micro expressed similar concerns in an online post with this opening statement : “ The growing appearance of deepfake attacks is significantly reshaping the threat landscape . These fakes bring attacks such as business email compromise ( BEC ) and identity verification bypassing to new levels .”
They went on to say that more serious attacks will be forthcoming because of the following issues :
1 . “ There is enough content exposed on social media to create deepfake models for millions of people . People in every country , city , village , or particular social group have their social media exposed to the world .
2 . “ All the technological pillars are in place . Attack implementation does not require significant investment and attacks can be launched not just by national states and corporations but also by individuals and small criminal groups .
3 . “ Actors can already impersonate and steal the identities of politicians , C-level executives , and celebrities . This could significantly increase the success rate of certain attacks such as financial schemes , short-lived disinformation campaigns , public opinion manipulation , and extortion .
4 . “ The identities of ordinary people are available to be stolen or recreated from publicly exposed media . Cybercriminals can steal from the impersonated victims or use their identities for malicious activities .
5 . “ The modification of deepfake models can lead to a mass appearance of identities of people who never existed . These identities can be used in different fraud schemes . Indicators of such appearances have already been spotted in the wild .”
Why Do Lawyers Need to be Concerned ?
I would hope it would be self-evident . Due to the amount of other people ’ s money law firms are responsible for coupled with the amount and variety of sensitive and confidential information lawyers maintain , law firms have been and will continue to be an attractive target for cybercriminals and scammers . The only thing that is changing is the sophistication of the attacks .
As a lawyer , you need to know a tool that enables someone to create a deepfake of you exists . That deepfake could be used to hack your Amazon Alexa ; manipulate a colleague , family member , friend , or employee into moving money ; hijack your bank account ; bypass an identity verification process ; or even to plant fake evidence in an attempt to blackmail you . All that person needs is a good photo or a short voice recording . How many people do you know , including yourself , who have already posted all kinds of audio , video , and photos in the social media space ? You and I both know it ’ s practically all of us .
My purpose in sharing all of this is not to instill fear . Rather , it is to create awareness and an appropriate level of concern . We all need to continue to stay abreast as to how the attack vectors continue to change in order to have an opportunity to be proactive in our efforts to avoid falling prey to these ever evolving cyberattacks and scams .
ALPS Risk Manager Mark Bassingthwaighte , Esq . Since 1998 , he has been a risk manager with ALPS , the nation ’ s largest direct writer of professional liability insurance for lawyers . In his tenure with the company , Mr . Bassingthwaighte has conducted over 1,200 law firm risk management assessment visits , presented numerous continuing legal education seminars throughout the United States , and written extensively on risk management , ethics , and technology . Mr . Bassingthwaighte is a member of the State Bar of Montana as well as the American Bar Association , where he currently sits on the ABA Center for Professional Responsibility ’ s Conference Planning Committee . He received his J . D . from Drake University Law School .
16 THE GAVEL