
okay so this is my talk uh has anybody seen a version of this talk before yeah okay this is the full version uh you've seen little bits of it this is the the whole thing so this is called anything online can be faked I'm going to show you some quick simple and cheap ways to do it and I'm also going to show you ways to spot them so before we start how about me uh I started as a scam beta in 200 five and switch to concentrating on actually helping people who had either been scammed or were possibly about to be scammed uh just the next year I hate the smell of coffee this is important to know because it
will come up at the end of this uh I can't have caffeine uh steroid cream steroid sprays anything like that can be really bad panic attacks so I avoid coffee like the plague and about cancer.com that was created in 2012 uh we are just a small volunteer group uh just three of us with but between us we've got over 45 years of experience uh we've been referenced by worldwide media we've worked with law enforcement and also we've worked with Academia in fact people who year earlier from University of War uh I've work to them so let's begin simply Li about it uh you're going to see a lot of emails don't worry about the text in them you don't have to read
it if you look at the presentation after when it gets released you can read it but you don't need to right now this one is claiming to be Cara Harris uh it's obviously not carela Harris because that email address at the top says mrs. Cara Harris aol.com and the real Cara Harris would not be using AOL but we will discuss emails in a little bit as well so this is another one this is supposed to be Chase Bank but again Chase Bank would not be using a Gmail account now still on it back in 2014 I give a talk to the dating site industry in Germany and this is one of the slides I used in
that all these ladies are from a single dating site and they all obviously using stoling images of the same person as it happens we know who this person is uh she's Danielle delone and she and I uh uh follow each other on Twitter and chat from time to time now this is 10 years ago so you might be thinking well they can't still be using them can they this is from a few weeks ago I from the same dating site and all I did was say search for females in Nigeria and Ghana and I found 14 of them within a space of maybe 15 minutes so she is aware that the scammers have got to images in the usern
them I'm aware who it is but let's pretend that we don't know who the images are of so suspend your disbelief for a moment and pretend you have no idea who jie actually is what we're going to do is use a plugin for Chrome which is called search by image and if you see now it's going to right click and we have search by image on there if we look it's got Google B you can't see the other two but there t and Yandex as well and when we do that it'll open up open up in different tabs and it will show that the first one shows you it's Angelina Julie the second one's going to pop up in a minute and
that's also going to show you it's Angelina Jolie the third one is going to come up in a moment and again it's going to say Angelina Jolie and when the fourth one appears that's going to Angelina Jolie as well so we just four search engines one right click we manage to work out exactly who these St images are of when I look at something a little different I've never shown this before in in a presentation uh post it how do you convince somebody that you're real uh online send them something offline have a look at these this is a handwritten letter with a photograph of a lady whose name I can never remember remember the uh this is another
one and this one I believe is J and there's that one but if we look closely at them do you see what I see they the exact same text the exact same writing but different females I have them here I'm going to hand them out I'm going to come across a moment how I can pass it around okay you can see they're actually handwritten letters and printed photographs these are the only ones I've ever seen like this it's uh it's kind of weird I'll be honest today I've you all the time I've been doing this I've never seen it so Photoshop this is me this is my us driver license I made this in 15 minutes
and it's got quite a few Easter eggs in it uh for example the date of birth is April 1st that's in April fo day the expiry date is April Fools Day the address is the headquarters of the FBI and I in no way shape or form a 5' 10 and £130 trust me I've never been either this is a passport that was stolen um it's got the watermark on it because we've taken this from our gallery and using the thing I did earlier with search by image I decided to see when this image was first used and if we look at it we can see it first appeared in 2016 just a quick search found us this
it also found us this a driving license so there the scanner has two documents already perfectly legitimate looking and they are being used and abused while I was taking images of these this popped up in our Forum now let me just check you can see on here pretty well as well yeah if you look at the date of birth the date of expiry The Sur name and the name you can see that the scam is copy and pasted background over the original text and then put in their own text for it the text is slightly smaller it's slightly darker and it's slightly different front as well which we can see if we look at the
r on the name and we look at the r on ukr we can see the r on them we got a bit of a curve to it whereas the nationality doesn't they haven't aled the image on this at all so let's look at one where they have put a new picture on there supposedly Joe Biden we look at this one and it's very obvious that it's fake uh look at the watermark on it do you notice that the watermark does cover any of her [Music] face these are the kind of things we' be looking at you can also see on the USA bit just above it the color is slightly different between just above and on the
image this uh this is another easy one to spot because if you look at the thing that he's holding you'll see that it's at an angle but the text is perfectly horizont Al uh if you also look closely you can see there are witness marks where this gamma has copy and pasted things across and blanked out certain pages of it but then there are some IDs that you look at and you just instantly know that fake like this one yeah leave it up I do I do like that one I'll be honest with you figer makers are the people that the scamers P to make their fake websites for them and they will do it using one
of two methods they'll either use a template or they will scrape an actual website and then copy that text onto their fake website if we look at this one we can see we have two identical websites the only difference being they have different uh logos on them and different names but other than that they are absolutely identical and what we would do on this we could simply do another right click do another image search and see what else turns up but we'll try a different method this time and I'm going to show you another two template ones and what we will do is look at some of the text on it I don't know how well you can read the text on
this but if we take the fourth paragraph down copy that into Google we only get eight hits but out of those eight hits three of them tell that it's a scam email so by simply taking a sentence of text from this website we've identified it as a fake another thing scam will do is actually create a website name and then what we do is we try to identify them as fake so that we can report them in this case we have Pacifica International logistic lines.com and we go to H.D domain tools.com which is a brilliant site and if we look at that we will see that it was created in May of 2023 and expired in May of
2024 however you can already see that the account is being suspended and that was because of us we actually reported this one because when you look at the registry details they give a fake name and a fake address and that is against the terms of service of the providers so some uh website HS will turn on and say well it's not our responsibility if they are running a fake website on it but if they are running a website with fake details no big no no so we want to get that one killed simply by proving that those the the name and address I were fake and this is a scraped one now the one on the left which is cic or syic is
the genuine one and the one on the on the right sorry is Tech essential which is a fake one but they've scraped the details from the original website the only reason that those triangles look different is because that was actually a moving background so other than that they are identical and again what you do with these if you look for the text you look for the images and you try to search through see if you can find other versions of it on other sites as proof that either it's fake or as proof that you can uh show this the people the actual website it was taken from now we look at emails next I did
say earlier that we'd look at emails there are three ways to fake an email very simply the first one if you go to Gmail and it says create a new email account when it says put in your name put put any the email address you want you do that then that's how you get this it appears to be from hm treasury but right next to it is the Gmail email address was easily done but then easily disproven another method which looks a little bit more official we see this when it's got richy sunx and minister. comom now you might think well minister. comom has to be genuine no Minister doc is from mail.com which is a free email provider and if we
look at this again I don't know how clear it'll show up on there but we have at politician. comom and at presidency. comom as well now can anybody here think of any reason why somebody would genuinely need one of these email accounts cuz I sure as heck can't and our third method we're going to use an email spoofer I uploaded this to my website on a hidden and password protected directory don't take that as a challenge okay and I've taken an email that was originally from a Gmail account but made it appear as if it is Joe Biden at White house.gov you put in the details you put in the email addresses you want to send
it to and then when you send it if you hover over that email address it actually says that it is from White House there are two ways to spot these the first one is that the scammer cannot actually access that email account so he has to give you another email account and he'll probably say something like contact me at my personal email address which might be Mighty joebiden 69@gmail.com I hope nobody owns that if they do I'm going to try to get it and the other thing you can look at are the email headers now email headers are accessed in several different ways they're all similar but they're all slightly worded differently so it could
be view Source view original VI headers properties uh something like that I can't tell you exactly which one you would use cuz everyone is slightly different but if we look at this we scroll down to the bottom cuz a lot of what you'll see will look like complete Go De cook but scroll to the bottom and work your way up slowly and you will see that you have an X PHP script there and that shows that this was sent from scams survivor.com then that hidden directory and m. PHP and it also has an IP address so we know what website it was actually sent from and we know the IP address where it was sent from too but IP
address is going to be faked and we'll come to that in a moment too the next upep we're going to look at phon proofing now we've faked the the president of the United States email address let's fck the phone number next if all you want is a geographical number then easiest thing to do this is where I use Skype um you will see we use an area called 419 because I thought that was funny at the time but the top one there is what we actually use for our website and the bottom one is what I use when I'm contacting scammers and pretending to be an America and if you want an actual phone number that you want to
choose there's an app email uh sorry an app website for that this is one that I've used in the past and all you need to do is you put credit on it and then you put in your number the number you want to call and the number you want to appear as it'll then say form this number and put this cod in and it will actually phone up the person and it will appear as if you are from that number number as you can see here this is the White House's number pH in my mobile phone and right next to it we actually have um there the phone number on the website as well now next up we're going to look at
vpns uh VPN is a virtual private Network it's basically a piece of software that will make it appear as if you're in another part of the world and I use um um what is my IP address to check IPS and when we look at this we can see that I am supposedly in London IP address is one of those things where if you're just using a normal internet connection it'll show general area it won't actually show exactly where you are it's not like programs like CSI where they can zoom in and see the person sitting there on the computer at the time uh if you run a VPN and in this case I'm using fast VPN there are
lots of other vpns out there this just the one that I use I click on United States New York and then when I look at what is my IP address again I appear to be in New York and United States so how can we spot these we can actually use the website that it's showing right now if you look at the top left hand corner you can see my IP and then IP lookup and if you go to IP lookup it shows you the ISP it shows you the location but the thing you need to look at is the assignment which is in green on this image and it's got the likely Dynamic IP that means it's probably a
genuine one if you had likely proxy server or confirmed proxy server that would be a VPN so everything I've shown you has been free to use and as you can see just very simple to do now we're going to start talking about AI cuz everybody's talking about AI these days and we're going to completely fabricate it these two people do not exist they come from a site called thisp person does not exist.com and every time you hit F5 it'll come up with a new face they're completely random you'll never get the same one twice and what we need to look at when we do these are the backgrounds the hair and the hands so we start off with the hair and if we
look really closely at these we can see on the right hand side as you're looking at it next to ey on both of the images you can see hair that isn't quite natural it kind of starts and ends where it shouldn't and the lady in the red you can see uh it's it's there this little bits the one on the right you can see it's like a a t so you have to look really close ly because AI has gotten a lot better at doing hair but it still isn't perfect then his hands oh boy this hands one lady has got five fingers and the other lady is doing her best impression of a [Music]
rabbit again we look at these backgrounds and we see each and every time the background is been a blur or plain the reason for this is that AI still struggles a bit sometimes with with backgrounds and if you look really really closely and I mean you do have to look really closely you might spot some subtle signs that it's actually AI generated can you see them you do have to look close then chat GPT is uh some Brant software really handy if you go to it and you say I would like you to write me a scam email and you give it a scenario it'll say no I can't do that it's against the law it's unethical so I won't do it you
could go and pay for some other software for example fora GPT or you could try rewarding it and asking it in a different way and all I did with this is say I have a friend and I need to send him a letter this is what I need to tell him can you write the letter for me and yes it wrote it it's telling him that I have a trunk box for 105 million that we found inside mine's former residence yes but it did WR it doesn't always work um I tried it with a day and wi scam and it realized it was a scam I wouldn't do it um chck GPT has tells and you need to look um don't
worry about the text itself just look at the patterns that we're going to start seeing I show you some more so that one we're showing you now is the Saddam hin one this is an email I sorry this is a story I just asked chat gbt to write me a story and this is what it did uh can anybody work out what that tell is yet let's add some color to it to make it a bit easier okay what we're going to do is take every paragraph and and we're going to color in the sentences so the first sentence will be black the next one will be red the next one will be blue the next one will be green and so
on and when we do that do you see that pattern appearing now I'll show you another one what I did is took 100 paragraphs and I checked out how many sentences were in each and every paragraph and this is what I found 67% of the time when I asked chat GPT to tell me a story it only had two sentences in the paragraph in only 2% of cases were it four or more so in all 90% of the time those email sorry those stories or those letters only had two or three sentences in them so now we're going to look at virtual cams uh this is actually the oldest software that we going to be
talking about here and it's been around for 17 years I believe I used to use this when I was breting scammers in the Philippines cuz they would want me to appear on webcam and obviously I didn't want to show my face to a scammer so I would use this software and just a plain blue image that's all you need is a single blue image and you get it to play this as your virtual webcam and you're going to say no oh look my webcam is broken it's only displaying a blue screen or you can upload a video of static and get it to play the video static and go no no my webcam doesn't work this is a quick video and a I can
have a rest with my voice and B because it's so fiddly trying to do everything and talk at the same time this is manic Cam and when we talk about sex aution scammers using a virtual webc cam this is how they do it right now I've got a video playing of somebody called ly luck if the person was talking to the scammer this is what they would see as their webcam so what we'll do now is go one step further with it pull up another piece of software we'll call it VCW now if we change from the movie to desktop and click on a section of the desktop this is already set up for it
click on okay now we are seeing this it's the same principle it's a video again but this time it has buttons on there and you can click on it and it will jump to certain parts of the video and then jump back so we click on Wave you here it says playing wave then once wave is played it'll jump back to probably something like chat one there you go click on smile it's going to smile and then again it's going to jump back same with big smile we're not going to do four but if you click that it'll jump to a further part of the video again and then it'll all keep going from that point instead so how do you know
that the scammers are using this software very simple get them to do something that wouldn't have been pre-recorded something like hold up a copy of today's newspaper or even something really silly like take off one shoe and wave it about that's the simplest way that you can tell that people are using a virtual webcam because they aren't able to to do these kind of unusual things now we saw sorry uh now we saw on that one that there were only four options we can see on this one it's got 10 options uh I blanked out the person's face on this and their name because we don't know who they are uh sex option is a particularly horrible kind of scam
that we've unfortunately been dealing with uh since we started we've dealt with over 40,000 cases people have taken their own lives after being scammed this way um so let me say this to you if you or anybody you know ever gets caught up in this scam talk to somebody about it please uh we've seen too many people take their own lives we don't want to see anymore uh you can get over this scam and it's actually fairly simple to do so um this scammer will try to use particularly threatening language to keep you panicked but you can deal with it and it does get better and after that I'd like to um like mve a little bit we're going to
look at race mods back in the old days cuz I started doing this in 2005 and back then if a scanner needed to have a female voice he would either have to get a family member or a girlfriend to do it or he would try to pretend to be a female himself I'm going to play you an example of that and this is the only time I have ever laughed during a scammer call uh but when you hear it you'll understand why this is a scammer called Ibrahim and he's about to introduce me to his daughter excuse me I want you to talk to my baby I I can talk to your baby this time yeah yeah yeah okay
then okay let me get my baby okay then I know what's coming this is new hello
yeah my dad my dad my D you are his friend I was not his friend believe you me I was not his friend then I'm going to play another quick video and it's going to have another annoying sound on it but it's not my laughing or the kind of pretending to be a little girl this time so just be prepared because it is kind of annoying this is my voice normally now I'm going to click play on a sound generator here with a 500 HZ frequency as you can hear that this is normal if we went to go to a different voice that just aled the pitch you should now hear it a lot higher if we click on an AI
voice this is what this looks like I'm me going to click on another AO voice to hear that sound like it w so what we listening to when we hear these things at background like this we want to see if we can hear the Picture People in the background our cars H past listen for these kind of things to see if we can spot them and that seems to be pretty much sure we could really tell if this was a fake Voice or [Music] not now we're going to steal some these voice this time and clone it so what I've done for this is gone on to YouTube downloaded a couple of videos ripped the
audio out of it and where they were background noises or the interviewer talking I've cleaned them up running through audacity again a brilliant piece of software if you've never heard of it run it through there and now I'm about to do this with it and that's use a site called play. HT and what we're going to do here is create a new clone really simple this is and watch how quickly it's done as well so we click on instant we pull across that file of the audio that we made so you need it to be at least 30 seconds best quality you can get we put in a name for it and then we say yes we've got the
relevant permissions then click on create clone what it's going to do now is upload that and it'll run you through its own AI software to try to give you a bet quality version of it now because I've already done this with audacity I don't need to do it so I'm going to just click on the normal version and then once I've done that which will happen in a moment there you go and click on finish and now that clone is ready click on use I put some text across and if you're a multi python F you might recognize this text click on now generate now it has a speed uh option where you can slow the
voice down or speed it up there a couple other options on there as well I'm not going to use any of them I'm just going to do it as is and that is all done if you if you not have B click regenerate try it again and I'm going to show you three examples now I'm using these three people purely because they have voices that everybody recognizes the first one was particularly hard because this person talks really really fast but tell me how good you think this is and remember this is only from about a minute or so of captured [Music] audio th velocity of an unladen European swallow is something like 20.1 mil per
hour or 29.5 ft per second however some have been clocked at 46 milph in the past here's the voice going to know the air speed velocity of an unladen European swallow is something like 20.1 mph or 29 9.5 ft per second however some have been clocked at 46 mph in the past I another one the air speed velocity of an unladen European swallow is something like 20.1 m per hour or 29.5 ft per second however some have been clocked at 46 mph in the past so I'm going to confuse the software and to do so I'm just going to get it to spell Mississippi I type in Mississippi then M do I Dot and so on the a I can't even spell it
correctly when I typed it in but the important thing about this is that letter I at the start of a sentence the letter i goes up in pitch and unless it's a question at the end it'll drop down so what's going to happen when we try to do this and just have the letter i as the only thing in a sentence Mississippi m i SS I I PP I you see I that's not right and we know that is AI [Music] generated and when I did this I thought well I wonder what my voice would sound like my voice sounds terrible honestly I sound a cross between German and South African and I can demonstrate that for
you with this the velocity of a un European swallow is something like 20 1 m per hour 29.5 ft per second however some are being clocked at 46 miles per hour in the past so if you want to avoid having voice stolen by AI be Welsh nice tip I'm talking to Welsh I had my fake B Johnson and decided to get it to speak Welsh uh do anything you speak Welsh here oh I could make something up then good I I'm going to use the word uh the sentence which just means please close the door and if you don't believe me you can look it up it's not swearing or anything I promise you and I did this to
my fake Boris Johnson and I think I broke the software the
exactly so yeah be Welsh again be Welsh we're going to take the voice thing and go one little step further what we're going to do is get an image of the person and we're going to make it appear as if the face is actually moving and their mouth is moving so it looks like they're actually saying what we created you're going to see this on a big screen so it's going to look a lot more obvious that it's fake but imagine having this on small like 2 3 in video being sent to you by on your phone by a relative apparently Microsoft has got some new software that blows this out of the water uh but they haven't released
it yet the air speeed velocity of an unladen European swallowed is something like 20.1 milph 29.5 ft per second however some have been clocked at 46 mph in the past I mean it's not bad is it so we're going to do some face swapping next and what I've got is a piece of software and to speed things up I've already uploaded a video of Alex Kingston talking about if she'd ever come back to Doctor Who and I've uploaded a photograph of Angelina Jolie and I've told it to swap Alex Kingston's face for Angelina Jolie's face and it's very GPU intensive and if you're interested when I did this and this is going to be in real time and I will say
that in the video as well uh I use an RTX 3060 for it I'm going to show you this in real time as I said earlier this is an RTX 3060 being used I just said that too we have Alex Kingston's face from the video and Angelina Jolie's face to replace it if you look at the top of the screen as well you see it also has stream face swap and image face swap with the stream face swap it lets you use your webcam and instead of putting up a video you can actually have that and I'll demonstrate that in the next slides it has fast mode it has various other modes as well but to be honest with you fast
mode is absolutely perfect and that's how quick this is again that was in real time now I said about the stream face SW I'm going to show you that now and this is my face uh I'm going to put Dar Breen's face over mine because we have kind of a similar shaped head so let's see how that looked and I'm going to show you the simplest way to be able to uh show that this is a fake this is me with notice a little Dar T at the back he's a little East regular often see when I do TV interviews watch what happens when I put my hand in front of my face you're going
to see that my fingers are going to start disappearing my eyes and my ey BS and my nose are going to start jumping up and down and twitching and then eventually when I cover up enough of my face it's going to say I don't see a face there anymore and it just turns itself off so that's all you have to do if you not sure that somebody is using one of these just get them to do this so this is a still from that Alex Kingston video and I'm going to show you the result that I got and remember how quick uh this was oh my gosh if I was offered um a chance to come back um for any sort of a
storyline I would i' bite their hand off and say yes yes absolutely it's pretty good yeah what we're going to look at on this is where the face and The Mask meet what the next one I'm going to show you it's one of the stock videos and I put T my hak's face over it watch this part of the head cuz this is uh where that mask starts an ends and you'll notice that it's kind of flickering and bluring and again you have to zoom in close to look at these things but when you when you see them you can't then see
them do you see it
[Music] moving so then in closing what have we learned anything online can be faked as the tit says we can fake a person's face we can fake their voice we can fake their email address their phone number absolutely anything uh incredibly simply and what we need to be doing is getting that information out there so that when people do searches they will find out the fact that it is a scam and who the real imag is and so on are from remember I said at the beginning that I hate coffee there there wasn't genuinely a reason for that uh my friend and I had a conversation in the car uh a while back and I said I was talking to him about
the presentation and I said if you ever get a call claiming to be me and they say I mean d needs at the moment can you lend me some money this is what you do ask me if I F go for a coffee after if I say yes is a fake have this conversation with your friends and family to come up with something like um a question an answer or a phrase that everybody knows or just something about you that only your friends and family would know and that's pretty much the presentation here but just to finish off I'm going to play you a couple of silly little things that I made while I was
making this um may need to amuse myself but I think uh you might like them to
yeah it's Mr Bean bis Johnson singing with yeah I know I'm the very model of a modern major general I have information vegetable animal and mineral I know the Kings of England and I quote the fights historical from Marathon to watero in order categorical and one last one for you uh how many of you have seen the movie uh spinal tap yeah yeah if you've never seen it you need to watch it absolutely hysterical uh mockumentary well there a bit in there where the guitarist is talking about how we amp goes up to 11 cuz 11 is louder than 10 and what I've done I've taken my fake B Johnson and a fake Donald Trump
and had them interact and do that bit the numbers all go to 11 look right across the board 11 11 11 and oh I see and most Ms go up to 10 10 exactly does that mean it's louder is it any louder well it's one louder isn't it it's not 10 you see most bloke you know will be playing at 10 you're on 10 here all the way up all the way up all the way up you're on 10 on your guitar where can you go from there where I don't know nowhere exactly what we do is if we need that extra push over the cliff you know what we do put it up to 11 11 exactly
one louder why don't you just make 10 louder and make 10 be the top number and make that a little louder these go to 11 well thank you very much for listening to this does anybody have any questions excellent excellent again thank you very much and also thank you to the people from B for organizing all list uh they've done a brilliant job all day so don't applaud me applaud them