Don’t Fall for It: Staying Cyber-Safe in the Age of AI

Fall brings changing leaves, cooler weather and plenty of familiar signs that the season has arrived. However, when it comes to what we see and hear online, appearances can be deceiving.

Generative AI can create remarkably convincing emails, images, voices and even videos. Those capabilities can help us work and create, but they also give cybercriminals new ways to make scams more believable.

Don’t Fall for a Familiar Face, Voice, or Email

Imagine receiving a message from your supervisor asking you to urgently send a document or approve a transaction. You see their name, you recognize their face, and/or you hear their voice. Would you question it?

Increasingly, you should.

The rise in sophisticated cyber scams have kept pace with the proliferation of AI. A recent Gartner survey found that 41% of cybersecurity leaders surveyed had experienced at least one social-engineering incident involving a deepfake during an employee audio call in the previous 12 months. More than a third reported an incident involving video.

AI hasn’t changed one of the most important cybersecurity lessons: an unexpected or unusual request deserves a second look.

If someone asks for money, passwords, sensitive information or an unusual action, verify the request using a method you already trust. Call a known phone number, start a new Teams conversation or contact the person directly rather than relying on the contact information in the original message.

Turn Over a New Leaf With Your AI Habits

AI tools themselves also deserve some caution. Before putting information into an AI prompt, ask yourself: Would I be comfortable sharing this information outside the University?

For University work, use University-approved AI tools while signed in with your Syracuse University credentials, and don’t put confidential or sensitive University information into personal or unapproved AI services.

And remember that confident doesn’t mean correct. AI can produce inaccurate or even completely fabricated information. Check important facts and original sources before relying on AI-generated content.

Three Tricks for Safer AI Usage

  1. Protect what you share. Don’t give sensitive information to AI tools that aren’t approved for it.
  2. Question what you receive. AI can make phishing emails, voices, images and videos more convincing.
  3. Verify before you trust. When something important or unusual is requested, confirm it independently.

AI offers tremendous opportunities for teaching, learning and working at Syracuse University. A little skepticism; and a few good security habits, can help make sure the tricks don’t outweigh the treats.