Skip to content

Security1 publisher2 min readPublished

SecurityWeek argues for in-call deepfake detection with help desk breaches it never ties to AI

SecurityWeek says awareness training has failed against help desk vishing, citing attacks that cost MGM an estimated $100 million. The fix it profiles is Netarx's live-call scanner for cloned voices and spoofed devices, but in both breaches it cites, callers talked help desk staff into granting access.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • In 2023, Scattered Spider callers posing as employees got casino help desk staff to reset passwords and bypass MFA.
  • Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million, according to SecurityWeek.
  • In the Brinks Home case, disclosed in August 2026, ShinyHunters talked a help desk employee through a Microsoft Entra authentication step and got immediate access.
  • Almost five million Brinks Home customer records and 41 GB of corporate data were then published on a public hacking forum.
  • SecurityWeek describes Netarx's system as more than 40 AI models scanning communications in progress and analyzing more than 1,000 signals per interaction.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Help desks that reset passwords or complete MFA steps for callers remain open to a playbook that two linked groups ran against casinos in 2023 and against Brinks Home in 2026.
  • constraint Netarx leaves the decision to hang up with the employee, so the tool still depends on the human judgment SecurityWeek says cannot be relied on.
  • decision Moving budget from training to in-call deepfake detection on this evidence means paying for synthetic-media checks that the cited breaches do not show were needed.

SecurityWeek says there is little empirical evidence that awareness training works against social engineering [15]. It says humans cannot be expected to spot manipulation built for their psychology, and that AI deep fakery is making the tricks harder to see [16]. The AI is in the argument. The incident accounts describe callers posing as employees, and a caller talking a staff member through an Entra step [1][5][13].

Netarx's checks come in two kinds. One looks for synthetic media. In cloned voices that means unnatural background silencing and compression artifacts. On video it means lip movements that do not match the audio, unnatural blinking and warping around hairlines [8][9]. The other kind tests whether the device on the call belongs to its authorized user, using device fingerprints, EXIF data, compression signatures and location mismatches [8].

In my view only the device checks apply to the breaches SecurityWeek cites. I'd also expect the first fix in both cases to be procedural: limiting what help desk staff may reset or approve for a caller, whatever the caller sounds like. In the Brinks Home case the employee completed the authentication step on the attacker's behalf [5].

No single signal decides the verdict [10]. The combined signals drive a light on screen during the call. Green means identity and device are verified. Amber means the source is unknown or the metadata looks wrong. Red means synthetic media was found [11]. SecurityWeek calls automatic blocking extreme, so the employee decides whether to disengage [11]. The casino attackers rang in asking for password resets [1]. I'd expect staff to act on amber only if the genuine employees who call with the same request rarely trigger it. The article does not report detection or false-positive rates [14].

SecurityWeek says use of this kind of detection is increasing and improving, and it names one product, Netarx [18]. It calls Netarx an early case of technology supplanting human detection and says it will not be the last [17]. Netarx's NIK runs on Windows, macOS, Chrome, iOS and Android. The company also publishes an Impact Database of incidents where human deception was decisive [12].

What to watch

  • Detection and false-positive rates for Netarx on live calls, ideally measured by a tester other than the vendor.
  • Any finding from Brinks Home or investigators on whether the August 2026 caller used a synthetic voice.
  • New help desk vishing disclosures attributed to ShinyHunters or Scattered Spider.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories