Identifying and Countering AI threats in a New Era of Cybercrime
Download resourcesAbout this session
Gaurav Khot, Distinguished Architect at Ping Identity, catalogues how AI is weaponizing identity fraud across the entire user journey and lays out layered countermeasures. He opens with a 2024 case of a finance executive wiring $25 million after a live deepfake video call impersonating his CFO, plays a synthetic Morgan Freeman clip to show how convincing today's fakes are, and cites a survey where only 52 percent of respondents believed they could recognize a deepfake of their own CEO. He walks through AI-amplified schemes at each stage of an identity lifecycle: synthetic and stolen identities passing hiring checks (including a North Korean state actor caught mid-process at a bank), AI-scaled phishing emails with none of the old grammar tells, voice-cloned grandparent scams, session hijacking, and support-desk impersonation bypassing voice biometrics. His countermeasures center on multimodal, continuous verification, document authentication with liveness and injection detection, device and data triangulation across multiple providers, phishing-resistant MFA (FIDO/passkeys), dynamic risk-based authorization instead of static rules, and verifiable credentials as tamper-proof, privacy-preserving, delegable proof of identity throughout a user's journey, including re-verification after hiring. A short Q&A distinguishes continuous verification from real-time multimodal risk signaling.
This session will explore the evolving landscape of AI-driven cyber fraud, offering a step-by-step look into how modern scams—from deepfakes to voice cloning—are reshaping digital threats. Designed for cybersecurity professionals, IT decision-makers, and business leaders alike, attendees will gain actionable insights into recognizing emerging attack vectors, understanding real-world use cases, and implementing adaptive defenses. Whether you're building awareness or deploying cutting-edge fraud prevention strategies, this session provides essential knowledge to stay ahead in the age of AI-enhanced cybercrime.
Key takeaways
- Do not rely on human judgment to catch deepfakes in high-value calls; only about half of people believe they can spot one, and live video/voice clones are convincing today with as little as 10 seconds of source audio.
- Layer document authentication, liveness detection (including injection detection for spoofed video streams) and biographic attribute matching across multiple independent data providers rather than trusting a single identity check.
- Deploy phishing-resistant MFA (FIDO/passkeys) to close the gap that legitimate-looking phishing sites exploit even when username and password checks pass.
- Move from static authorization rules to dynamic, risk-signal-based authorization (IP velocity, impossible travel, device reputation) so friction like MFA prompts scales with actual risk instead of hitting every user equally.
- Use verifiable credentials to re-establish trust at multiple points in a user's journey, for example re-verifying a hire after onboarding, since a one-time KYC check does not prevent 'someone else shows up for the job' fraud.
Speakers

Gaurav Khot has over 30 years experience in the software industry, with about 10 years working on building Decentralized Identity solutions at Ping Identity & ShoCard. He is responsible for the product architecture of some of the key components that… Read moreRead less
Gaurav Khot has over 30 years experience in the software industry, with about 10 years working on building Decentralized Identity solutions at Ping Identity & ShoCard. He is responsible for the product architecture of some of the key components that make up the PingOne Multi-tenant SaaS platform. Gaurav comes to Ping as a part of the acquisition of ShoCard in 2020. As the CTO of ShoCard he led the engineering team that built the Decentralized Identity platform that is the basis for PingOne Neo. Before starting ShoCard, Gaurav was the CTO of multiple successful startups in the online advertising space. He has also held various Architect level positions at several large companies like Yahoo! and AOL Online.
