Precision Social Engineering
精準化社交工程
Operation & Monitoring
Risk Description
When an attacker combines synthesized voice with the target's public information to conduct real-time interactive fraud; due to unmitigated control gaps, because the caller answers detailed questions correctly, the victim's verification attempts paradoxically reinforce their trust, triggering compliance exposure and operational reputational costs.
Framework Mappings
NIST AI 600-1Information Integrity
MITRE ATLASAML.T0052
EU AI ActArt.50
NIST AI RMFMANAGE 2.4
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 4
Risk Treatment & Implementation Guidance
Deploy AI-content detection for synthetic voice and maintain multi-factor identity verification for sensitive operations; Establish out-of-band verification independent of real-time interaction trust; Educate staff and customers on recognizing and responding to synthetic-voice fraud