{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"},"incident":{"title":"LastPass employee rebuffs WhatsApp deepfake audio call impersonating the CEO","date":"2024-04","date_precision":"month","victim_org":"LastPass","sector":"Technology","country":"United States","primary_vector":"Voice Clone / Audio Deepfake","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Business Email Compromise"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"LastPass said an audio deepfake of chief executive Karim Toubba, likely built from publicly available recordings, was used in calls, texts and voicemails sent to an employee over WhatsApp.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 10 April 2024 a LastPass employee received a series of WhatsApp calls, texts and voicemails from an account impersonating chief executive Karim Toubba, using AI-generated audio of his voice. The employee judged the approach suspicious, did not engage, and reported it to the internal security team. LastPass said there was no impact and published details to warn other organisations.","how_it_worked":"The attacker chose WhatsApp precisely because it sits outside corporate monitoring and is easy to spin up with a profile picture and a plausible number, but that choice also made the contact anomalous: LastPass does not conduct business there. The trust signal was the cloned voice of a chief executive whose recorded talks are publicly available, delivered as urgent voicemail after unanswered calls to create a sense that the boss needed something immediately. The employee weighed the mismatch between the claimed seniority of the sender, the unusual channel and the manufactured urgency, and treated the combination as a social engineering signature rather than an emergency.","lessons":"A published rule that executives never make urgent requests on consumer messaging apps, plus a no-blame reporting path, converts an out-of-band channel from an attacker advantage into a detection signal.","confidence":"Confirmed","sources":[{"title":"Attempted Audio Deepfake Call Targets LastPass Employee","url":"https://blog.lastpass.com/posts/attempted-audio-deepfake-call-targets-lastpass-employee","publisher":"LastPass"},{"title":"LastPass: Hackers targeted employee in failed deepfake CEO call","url":"https://www.bleepingcomputer.com/news/security/lastpass-hackers-targeted-employee-in-failed-deepfake-ceo-call/","publisher":"BleepingComputer"},{"title":"LastPass employee targeted via an audio deepfake call","url":"https://securityaffairs.com/161760/cyber-crime/lastpass-employee-targeted-deepfake.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-lastpass-employee-rebuffs-whatsapp-deepfake-audio-call-impersonating-the"}}