Cyber Security

Your CEO’s Earnings Call Is Training Data for the Next Attack

By Ghonche Alavi, Director, Cyber at Crisis24

Across boardrooms worldwide, directors are debating AI governance frameworks, scrutinizing AI adoption strategies and asking their management teams hard questions about deployment and ROI. At the same time, many of those same directors and C-suite leaders are vulnerable to AI-enabled attacks of a sophistication that would have required state-level resources just a few years ago.

And many are completely unaware of these threats.

AI has fundamentally altered the accessibility of attacks targeting this cohort and their families. What was once the domain of well-funded intelligence services and elite cybercrime syndicates is now available to virtually any threat actor with a laptop and a subscription. The implications for corporate governance are significant and so far, largely unaddressed.

The democratization of sophistication

Voice cloning that produces a convincing replica of a CEO’s speech now requires as little as three seconds of source audio. For a leader at a prominent company, that source material is abundant in earnings calls, conference keynotes and podcast interviews. The same executive’s likeness, sufficient for real-time deepfake video, can be trained from publicly available footage in a matter of hours using commercially available tools.

Furthermore, large-language models (LLMs) can ingest written content such as an executive’s LinkedIn posts, shareholder letters and quoted remarks in the press and generate messages that replicate their tone, vocabulary and phrasing with unnerving accuracy. The result is spear-phishing content that is far more convincing than the generic attempts most security awareness training is designed to catch.

Industry data suggests that most organizations experienced at least one deepfake-enabled social engineering attempt in the past year, but stats like these don’t capture just how targeted and personalized these attacks have become. For attackers, the return on investment has skyrocketed: A convincing impersonation of a CFO instructing a wire transfer now requires an afternoon of prompt engineering and a few publicly available datasets, instead of months of surveillance and social engineering expertise. While the barrier to entry has collapsed, the potential payoff measured in fraudulent transfers, data exfiltration or reputational damage has not.

The attack surface that enterprise security cannot see

Enterprise cybersecurity programs are typically designed to protect networks, endpoints and data within a defined corporate perimeter. They are not designed to protect an individual whose risk profile extends to personal email accounts, home networks, family members’ devices, professional advisors, executive assistants and service providers who hold privileged access to schedules, locations and sensitive information.

This is the executive’s personal attack surface, and it is largely invisible to the corporate security function. My own experience working with corporate clients and high net-worth individuals consistently identifies personal email accounts and home networks as the number one attack vector, rather than heavily guarded corporate networks.

A compromised personal email reveals sensitive materials received in unmanaged personal email accounts, while a breached home network provides a lateral path into corporate systems. It’s common to find home networks with flat architecture, consumer-grade equipment and no segmentation between IoT devices, family laptops and the executive’s work machine. The vulnerabilities my team encounters on these networks are not exotic: Weak passwords, default administrative credentials on network device interfaces and unencrypted authentication protocols are routinely the entry points that attackers exploit.

AI amplifies and accelerates all of this, as well as enabling ever more sophisticated and hard-to-detect social engineering attacks. A cloned voice note from a trusted colleague, sent via a personal messaging app, bypasses corporate email filters. AI tools also enable threat actors to rapidly construct a detailed pattern of life from openly available personal information that previously took weeks of manual surveillance to assemble, which can easily crossover into physical security risk.

The most sophisticated attacks we see in practice frequently target an individual rather than the enterprise itself, knowing that the individual is the weakest and most consequential link in the security chain.

A question of governance, not just technology

The governance frameworks being built for enterprise AI adoption typically do not extend to the AI-enabled threat environment that targets individual leaders. Taking a step back, risk cannot be eliminated entirely and incidents will occur, but in our experience the organizations that recover fastest have clarity of governance before a crisis hits. This includes having pre-defined decision-making authority, mapped escalation pathways, set thresholds for activating response protocols and named individuals who make the important calls under pressure.

It’s an area where the boardroom conversation about AI needs to expand, because strength of preventative controls is no longer enough. Effective board oversight requires treating executive cyber exposure as a matter of leadership continuity, fiduciary responsibility and enterprise resilience. If a CEO is successfully targeted with an AI-driven cyber-attack, that could well be a material event for a publicly traded company, whether through financial fraud, reputational harm or the compromise of sensitive data.

Practical steps to address the risk

At the highest level, boards should consider integrating executive cyber protection into the remit of the risk or audit committee, rather than leaving it buried within the organization’s IT security budget.

Within organizations, secondary verification on a separate channel should be required before taking sensitive actions such as initiating high-value wire transfers, with the requirement embedded into policy rather than relying on individual judgement under pressure. Security leaders should consider mandating independent assessments of the personal digital exposure of senior executives and their families, conducted by specialists who understand the specific threat model.

Additionally, incident response plans and tabletop exercises should account for the specific scenario of AI-enabled executive impersonation, including pre-agreed protocols for authenticating the identity of senior leaders during a crisis.

AI has dramatically increased vulnerability at the crossover of corporate and personal risk, which is a point where most organizations have the least visibility and the weakest controls. For boards and leaders engaged with AI governance, the larger questions of ROI, ethics and responsible use deserve the attention they are receiving. But amid those debates, it is worth remembering the more prosaic but potentially just as consequential risk closer to home.

Author

Related Articles

Back to top button