Incident 839: Une arnaque par hameçonnage pilotée par l'IA utilise un faux appel Google pour tenter de pirater Gmail, selon un expert en sécurité
Description: Des escrocs ont utilisé une voix générée par l'IA pour se faire passer pour un représentant de Google et tenter de voler les identifiants du compte Gmail de l'expert en sécurité Sam Mitrovic. L'appel d'hameçonnage piloté par l'IA utilisait un faux numéro de téléphone Google et une fausse adresse e-mail, donnant ainsi une apparence légitime à l'arnaque. Mitrovic a souligné que le comportement professionnel de l'appelant, associé à la voix générée par l'IA et à un numéro lié à Google, pouvait facilement tromper les utilisateurs peu méfiants.
Editor Notes: Timeline notes: On October 7th, 2024, Sam Mitrovic, a security expert, is reported to have received an unsolicited Gmail recovery notification and a missed call seemingly from Google. A week later, on October 14th, 2024, Mitrovic is also reported to have received a similar recovery notification, followed by another call, which he answered. Please also refer to Incidents 941 and 942.
Outils
Nouveau rapportNouvelle RéponseDécouvrirVoir l'historique
Le Moniteur des incidents et risques liés à l'IA de l'OCDE (AIM) collecte et classe automatiquement les incidents et risques liés à l'IA en temps réel à partir de sources d'information réputées dans le monde entier.
Entités
Voir toutes les entitésPrésumé : Un système d'IA développé et mis en œuvre par Unknown scammers , Google , Gmail et Unknown spoofing technology, a endommagé Sam Mitrovic.
Statistiques d'incidents
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
4.3. Fraud, scams, and targeted manipulation
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Malicious Actors & Misuse
Entity
Which, if any, entity is presented as the main cause of the risk
Human
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Post-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Intentional




