Propaganda - Digital impersonations
AI-generated impersonation for identity theft might be found at the intersection of “Harm to the Person” and “Deception.”
ENTITY
3 - Other
INTENT
1 - Intentional
TIMING
2 - Post-deployment
Risk ID
mit709
Domain lineage
4. Malicious Actors & Misuse
4.3 > Fraud, scams, and targeted manipulation
Mitigation strategy
1. Implement mandatory Multi-Factor Authentication (MFA) for all critical accounts, favoring authenticator apps or hardware tokens over SMS-based methods, and establish out-of-band verification protocols (e.g., pre-validated callback numbers or secret codes) for high-risk transactions or sensitive requests to counteract deepfake and spoofing attacks. 2. Integrate advanced AI-powered identity verification solutions featuring Liveness Detection and Presentation Attack Detection (PAD) algorithms to continuously analyze biometric inputs for temporal and spectral artifacts, thereby distinguishing between a live human and an AI-generated deepfake or synthetic identity. 3. Institute mandatory, recurrent training programs utilizing scenario-based learning to educate personnel on the psychological tactics (e.g., urgency, secrecy) and technical indicators (e.g., unnatural pauses, visual inconsistencies, spoofed email domains) characteristic of AI-enhanced social engineering and deepfake impersonation scams.