AI Phishing and Deepfake Impersonation
Practice independent verification, holding payments, and reporting when an urgent voice, video, or message request appears to come from an executive or partner.
Practice role-based scenarios for workplace situations including deepfake impersonation, data entered into generative AI, and inaccurate answers or information exposure in internal AI services.
Address realistic AI voice and video impersonation and information leakage when using generative AI. Practice verification, stopping unsafe use, reporting, and decision-making.
Practice assessment, verification, reporting, and decision-making according to threat type and job role.
Practice independent verification, holding payments, and reporting when an urgent voice, video, or message request appears to come from an executive or partner.
Review information classification, stopping use, impact assessment, and reporting when work data appears to have been entered into an unapproved AI tool.
Practice verification, access permission checks, and issue reporting for inaccurate chatbot answers or information exposed beyond authorization.
Assess data impact, fallback procedures, and vendor and internal reporting during an external AI API or plugin outage or compromise.
Cover safe personal usage, service operations, and organizational incident response together.
Learn what information may be entered, how to verify outputs, and guidelines for approved tools, copyright, and personal data.
Verify and report deepfake voice and video, personalized phishing, and requests impersonating executives or partners.
Review inaccurate chatbot answers, information exposure, permission management, and risks from external APIs and plugins.
Use tabletop exercises to check incident reporting, service shutdown and fallback procedures, responsibilities, and approvals.
Verify suspicious requests, avoid entering sensitive information, and report to the appropriate contact.
Review logs and access records, scope the impact, and define account and service actions.
Review business impact, service continuity, internal and external communications, and decision responsibilities.
Report observable actions rather than reducing outcomes to a single AI response score.
Was the request verified through an independent channel?
Was sensitive input recognized and unsafe use stopped?
Were the right contact and approval path identified?
Are AI usage guidelines, fallback procedures, and roles in place?