• Discounts and special offers
  • Subscriber-only articles and interviews
  • Breaking news and trending topics

Already a subscriber?

By signing up, you accept Moneywise's Terms of Use, Subscription Agreement, and Privacy Policy.

Not interested ?

Top Stories
A photo of a woman taking a peace sign selfie shutterstock.com / PeopleImages

AI is helping scammers steal fingerprints from selfies, make scam calls and hijack your summer reservations — learn how to protect your data

Cyber scams are getting much more sophisticated, thanks to AI — and the latest worry is that scammers could replicate your fingerprints from social media photos.

The hype started with posts claiming that hackers could extract your fingerprints from photos — like peace sign selfies — and then enhance them with AI. From there, they could use your unique fingerprint ID to gain access to your accounts or launch identity theft and phishing attacks.

Advertisement

And, unlike a password that can be changed, biometric data — like your fingerprint, face, retina or voice — cannot.

But could this happen to you?

“This sounds like the stuff out of spy novels or Mission Impossible,” Vyas Sekar, a professor at Carnegie Mellon University, told CBS News. “In theory, it’s possible, especially if people are posting high-resolution images.”

Still, a hacker would also need access to a device that required a scan of your fingerprint, like your phone or laptop. It’s more likely a hacker would choose a “high-value target,” Sekar said, such as a person with access to a high-security facility.

High-profile personalities could potentially be more of a target. This happened back in 2014, when hacker Jan Krissler of the European hacker network Chaos Computer Club used photos of former German defense minister Ursula von der Leyen — now President of the European Commission — to recreate her fingerprint.

While the likelihood of a hacker stealing your fingerprint is fairly slim, authorities in Oklahoma have gone so far as to warn the public about the misuse of AI and high-resolution social media images to potentially steal biometric data.

Advertisement

The Wagoner County Sheriff’s Office is warning residents that stolen data could be used to breach fingerprint security systems on phones, laptops and other personal computing devices, according to KFOR News. This stolen data could also be used with phishing scams, identity theft schemes, fake account recovery attempts and impersonation fraud.

Common scams to watch out for

Hackers don’t need a copy of your fingerprint to target you for scams and fraud. Other types of attacks, such as voice cloning and AI impersonations, are easier to pull off.

Almost anyone can make a deepfake these days, thanks to the democratization of generative AI (GenAI).

“It’s already possible to go online and learn how to make a convincing deepfake, based on a mere three seconds of recorded audio of someone’s voice — using off-the-shelf, publicly available software,” according to KPMG. “On top of this, there is an emergence of ‘deepfake-as-a-service’ as a lucrative market on the dark web.”

Scams also tend to spike in summertime, according to Norton’s threat intelligence team. “People are understandably distracted, spending more on travel and tickets, tapping confirmation links without a second look,” Leyla Bilge, global head of scam research for Norton, said in a release.

But this summer, AI will do even more heavy lifting for cybercriminals.

Advertisement

“Voice cloning has made phone-based imposter scams harder to detect, and deepfake technology has made romance fraud and investment schemes more convincing,” according to Norton.

A “trending” scam to be aware of this summer is reservation hijacking, where scammers use lookalike booking platforms to “hijack” your reservation details and then attempt to trick you into sharing payment details or other sensitive information. It’s easy to fall for, since the scammers have your reservation number, making it look legit.

Other trending scams this summer include fake tickets for sold-out concerts, festivals and sporting events, as well as fake gambling sites for major sporting events like the World Cup. Ongoing scams include crypto and investment scams, tech support scams and AI romance scams.

Must Read

Join 250,000+ readers and get Moneywise’s best stories and exclusive interviews first — clear insights curated and delivered weekly. Subscribe now.

How to protect your data

The Wagoner County Sheriff’s Office recommends taking precautions against potential biometric fraud, such as not posting close-up selfies that clearly show fingertips or palm details and using multi-factor authentication.

Multi-factor authentication requires you to provide two or more forms of verification to access an account or system, such as a password and biometric data. That way, even if someone steals your password (or replicates your fingerprint), they can’t get into your device if they can’t pass the second or third verification process.

Advertisement

Use a strong password (not something like “password123”), as well as anti-malware software, spam filters and caller ID protection. Keep your software up-to-date with the latest security patches. And, on social media, adjust your privacy settings and limit the amount of personal information you share online.

But technological barriers can only go so far if you unwittingly give away information to scammers. Keep up with the latest scams, and be cautious of calls, emails or texts asking for your personal or financial information, such as passwords or your Social Security number.

Don’t click on suspicious links in unsolicited messages and hang up on suspicious calls, even if the phone number looks legit (phone numbers can be spoofed).

“Instead, contact them using a website you know is trustworthy. Or look up their phone number. Don’t call a number they gave you or the number from your caller ID,” recommends the Federal Trade Commission (FTC).

And, if they insist you pay with cryptocurrency, a wire transfer, a payment app or gift cards, that’s a big red flag.

If you suspect you’ve been a victim of online fraud, contact your local police and the FBI Internet Crime Complaint Center (IC3).

You May Also Like

Share this:
Vawn Himmelsbach Contributor

Vawn Himmelsbach is a veteran journalist who covers tech, business, finance and travel. Her work has been featured in publications such as The Globe and Mail, Toronto Star, National Post, CBC News, Yahoo Finance, MSN, CAA Magazine, Travelweek, Explore Magazine and Consumer Reports.

more from Vawn Himmelsbach

Explore the latest

Disclaimer

The content provided on Moneywise is information to help users become financially literate. It is neither investment, tax nor legal advice, is not intended to be relied upon as a forecast, research or investment advice, and is not a recommendation, offer or solicitation to buy or sell any securities, enter into any loan, mortgage or insurance agreements or to adopt any investment strategy. Tax, investment and all other decisions should be made, as appropriate, only with guidance from a qualified professional. We make no representation or warranty of any kind, either express or implied, with respect to the data provided, the timeliness thereof, the results to be obtained by the use thereof or any other matter. Advertisers are not responsible for the content of this site, including any editorials or reviews that may appear on this site. For complete and current information on any advertiser product, please visit their website.

†Terms and Conditions apply.