Prodefence is pleased to announce the publication—now available in both Romanian and English—of the educational guide “Artificial Intelligence & The Manipulation of Human Perception,” developed under the ADA program: “Analyze – Decide – Act.” As the initiator of the ADA project, Prodefence continues to invest in practical, structured resources that strengthen digital resilience and support safer decision-making in an increasingly complex information environment.

Why we launched ADA

The speed at which technology evolves has outpaced society’s ability to consistently assess risk, verify information, and respond responsibly to digital threats. Today, manipulation is no longer limited to human-driven persuasion. AI enables scale, automation, and precision targeting, amplifying influence operations, fraud, disinformation, and social engineering—often faster than individuals and institutions can react.

ADA was created to close this gap by turning high-impact topics into clear guidance, realistic scenarios, and actionable prevention and response steps.

What this publication addresses

This guide focuses on how AI can influence perception and decision-making, including:

  • Algorithmic amplification and attention manipulation that shapes beliefs and behaviors
  • Synthetic media and deepfakes (video, image, and voice) used in deception, reputational attacks, and fraud
  • LLM-enabled persuasion and automation, enabling scalable social engineering and narrative manipulation
  • Behavioral and psychological vulnerabilities that can be exploited through modern digital channels
  • Practical protection measures, including verification habits, decision discipline, and response actions when manipulation is suspected

The objective is not only awareness, but resilience—helping readers recognize signals, reduce impulsive reactions, and adopt safer digital routines.

Authors and strategic partners

Prodefence congratulates the authors Mircea Constantin Șcheau and Alexandru Ciprian Angheluș for delivering a professional and usable resource aligned with ADA’s mission.

We also acknowledge and appreciate the contribution of key partners and experts who supported the development of this guide, including Cloud Security Alliance Romania Official (a chapter of the Cloud Security Alliance), experts from the Romanian Intelligence Service (SRI)National Cyberint Center, the Romanian National Cyber Security Directorate (DNSC), and the Ministry of Internal Affairs of Romania Romanian Police.

From publication to impact

ADA is not a single release, it is a growing program. Through CyberAID and the CysEdu platform, Prodefence and partners will continue to expand the ADA knowledge base with additional guides, simulations, and learning content focused on real-world risks: phishing and fraud, manipulation, AI-driven threats, incident response behavior, and digital safety for diverse audiences.

We invite institutions, educators, professionals, and community stakeholders to engage with this publication, distribute it responsibly, and participate in the broader effort to strengthen societal resilience.

#Prodefence #ADA #AnalyzeDecideAct #ArtificialIntelligence #InformationIntegrity #Disinformation #Deepfakes #CyberResilience #CyberAwareness #MediaLiteracy #SocialEngineering

Have you ever received a message that “seems” real, but something doesn’t connect?

As part of the ADA – Analyze – Decide – Act campaign, we tested a phishing message using our AI-powered platform.

Result?

⚠️ Message identified as malicious, with detailed analysis in a few seconds.
💡 The AI recognizes manipulation, hijacks emotion, and provides the user with clear explanations.

Technology is not enough if it is not accompanied by education.

Soon, we are launching the cyber education and prevention platform  – an interactive space for children, parents, teachers, employees, managers and seniors.

Based on the concept of “Analyze – Decide – Act”, the platform offers you:
– Real attack
– Scenarios Phishing simulations and
– Interactive tests – quick reaction
– Guides content adapted to each type of user

🤖 With an AI assistant that teaches you how to recognize, avoid, and act.

📢 Official launch – coming soon!
Pay attention to details. A new era in cyber education is coming.

🤝 Project carried out within Prodefence, in partnership with CYSCOE – Cyber Security Cluster of Excellence.

#ADA #AnalizeazaDecideActioneaza #CyberEducation #SigurantaDigitala #AIvsPhishing #Prodefence #CYSCOE #CyberAwareness

Information analysis in criminal investigations remains a cornerstone of modern law enforcement, enabling authorities to connect fragmented data points into actionable intelligence. Whether dealing with cybercrime, homicides, robberies, or financial fraud, this discipline plays a pivotal role in identifying suspects, understanding criminal patterns, and ensuring operational efficiency.

In this context, Alexandru Anghelus, CEO of Prodefence and a leading cybersecurity expert, had the honor of participating in the Regional Conference of Intelligence Analysts, held in Iași and organized by the Territorial Intelligence Analysis Unit, in partnership with the Romanian General Police Inspectorate and the Central Intelligence Analysis Unit.

A Strategic Perspective on Cybercrime and Disinformation

During the conference, Mr. Anghelus delivered a keynote presentation on:

“Financial Fraud – Fake Cryptocurrency Trading Platforms and Fake News – The Role of Artificial Intelligence in Disseminating False Information.”

This session explored:

  • How fraudulent platforms operate to deceive users in the cryptocurrency ecosystem;
  • The techniques used to spread disinformation, especially through digital channels;
  • The dual role of artificial intelligence—both as a tool used by threat actors and as a defense mechanism in combating fake news and financial scams.

The presentation emphasized the growing convergence between cybercrime and traditional criminal activities, underscoring the need for enhanced capabilities in both digital forensics and intelligence analysis.

Prodefence’s Commitment to Security and Intelligence Collaboration

As a recognized member and contributor within CYSCOE – Cyber Security Cluster of Excellence, Prodefence brings its advanced expertise in cyber threat intelligence, digital investigations, and AI-driven analysis to support national and regional security efforts.

The conference reinforced the critical importance of inter-institutional collaboration and public-private partnerships. Prodefence advocates for a united front in strengthening Romania’s security posture—one that integrates innovation, shared intelligence, and operational agility.

On 21–22 November 2024, the Maritime University of Constanta hosted the first edition of the BlackSea Maritime Cybersecurity conference series, titled “Countering Cybercrime Threats in the Current Context of the Conflicts in Ukraine and the Middle East.” Organized by the Maritime Cybersecurity Centre of Excellence (MARCYSCOE), in partnership with major Romanian universities, the event brought together experts in cybersecurity, legal professionals, and researchers to address pressing challenges in cybercrime response during armed conflicts.

The conference focused on the legal and operational complexities of investigating cybercrimes in conflict zones, as the digital battlefield increasingly intersects with traditional warfare. It emphasized the urgent need for harmonized legal frameworks capable of supporting cybercrime investigations—especially against critical infrastructure—amid evolving hybrid threats.

Prodefence’s Strategic Role

Prodefence, a key player in Romania’s cybersecurity ecosystem, was prominently represented at the event by its CEO, Alexandru Anghelus, who also serves as President of CYSCOE – the Cyber Security Cluster of Excellence. Prodefence is a founding and driving force within CYSCOE, contributing advanced technical capabilities and strategic insights to the cluster’s mission.

At the conference, Alexandru Anghelus delivered a keynote focused on a real-world cybercrime case involving financial fraud through data theft via malware. His presentation broke down the technical attack vectors, data exfiltration mechanisms, and the investigative procedures employed to uncover and analyze the incident. This exemplified Prodefence’s deep expertise in cyber threat intelligence, digital forensics, and incident response.

Furthermore, Mr. Anghelus chaired a closed-door roundtable with representatives from law enforcement and academia specializing in cybercrime. The discussions explored:

  • innovative investigative methods for cyber incidents;
  • institutional cooperation models;
  • the need for robust education and training pipelines in digital forensics and cyber law.

A Trusted Name in Cybersecurity

Prodefence stands out as a trusted partner for public institutions and private entities seeking excellence in cybersecurity operations, digital investigations, and strategic advisory. Through its leadership in CYSCOE and direct involvement in high-impact events like BlackSea Maritime Cybersecurity, Prodefence reinforces its commitment to securing digital borders and supporting cross-sector collaboration in the face of modern cyber threats.

Alexandru Anghelus, CEO of Prodefence and President of the Cyber Security Cluster of Excellence (CYSCOE), recently participated as a cybersecurity expert in a high-level workshop organized by the Ministry of Economic Development and Digitalization of the Republic of Moldova, under the Moldova Cybersecurity Rapid Assistance initiative.

The event, supported by the E-Governance Academy (EGA), focused on advancing Moldova’s national cyber resilience and strengthening protection for its critical digital infrastructures. The workshop served as a collaborative platform for government officials, technical experts, and international advisors to align on best practices in cybersecurity implementation and capacity development.

Strategic Impact and Collaboration

Mr. Anghelus, in his role as an expert affiliated with EGA, contributed to discussions on operational security frameworks, threat response strategies, and institutional preparedness. His engagement builds upon Prodefence’s wider mission of supporting regional cybersecurity through technical expertise and public-private cooperation.

Although Prodefence and CYSCOE were not directly involved in the event, Mr. Anghelus’ participation reflects the level of recognition and trust placed in Romanian cybersecurity professionals on the international stage.

Acknowledgements

Special appreciation is extended to:

  • Cătălina Plinschi, Secretary of State for Digitalization, for her strategic leadership;
  • Mihai Lupașcu, Director of the Moldovan Cybersecurity Agency, for his commitment to advancing national digital security.

Gratitude is also due to fellow experts Elsa Neeme, Epp Maaten, and Vitalie Varaniță for their professionalism and constructive collaboration throughout the workshop.

“This initiative represents a meaningful step in building a secure digital future for Moldova. I was honored to contribute alongside a team of forward-thinking professionals who are shaping the region’s cybersecurity landscape.”
Alexandru Anghelus


Prodefence congratulates all stakeholders involved in this impactful effort to strengthen cybersecurity at the national level and reaffirms its commitment to contributing knowledge and leadership wherever it is most needed.

#CyberSecurity #Prodefence #EGA #DigitalResilience #Moldova #CriticalInfrastructure #CyberCapacityBuilding #InternationalCollaboration #CYSCOE #CyberLeadership #CyberExpertise #PublicPrivatePartnerships

Prodefence, as a strategic member of the Cyber Security Cluster of Excellence (CYSCOE), proudly represented the cluster at the Cybersecurity Workshop for Travel Agencies, held during the Romanian Tourism Fair at RomExpo.

Alexandru Anghelus, CEO of Prodefence and President of CYSCOE, delivered an expert presentation focused on a real-life fraud incident caused by a stealer-type malware attack. This malware harvested login credentials from various platforms, enabling cybercriminals to compromise a travel agency’s internal systems and carry out unauthorized financial transactions.

“The scenario revealed how cybercriminals leverage credential-stealing malware to infiltrate business systems and commit fraud. The case underscores the critical need for cybersecurity education and incident preparedness in the tourism industry.”
Alexandru Anghelus, CEO, Prodefence / President, CYSCOE

🎤 Workshop Contributors:

  • Prof. Gabriel Raicu and Prof. Remus Zăgan – Constanta Maritime University
  • Alexandru Anghelus – Representing CYSCOE, CEO of Prodefence
  • Dr. Alexandru Bobe – CiTyINNOHub
  • Fraga Țăriuc, President – Women4Cyber Romania
  • Orsolya Bakó – Women4Cyber Romania

Special thanks to Mihaela Patentasu, Cristian Barhalescu, and the National Association of Travel Agencies (ANAT) for facilitating this high-impact workshop focused on digital protection in tourism.

🔍 Topics Covered:

  • ⚠️ Cyber risks facing travel agencies without dedicated security strategies;
  • ✅ Immediate cyber hygiene practices that businesses can implement;
  • 📖 Real cyberattack scenarios and actionable lessons for the industry.

💡 Prodefence’s Commitment

Through its involvement in CYSCOE, Prodefence actively supports cybersecurity outreach and capacity building in vulnerable sectors. With deep expertise in cyber threat intelligence, incident response, and forensics, Prodefence helps Romanian businesses fortify their digital defenses.


Only through strong partnerships and ongoing education can we protect Romania’s digital economy from cyber threats.

#Prodefence #CYSCOE #CyberSecurity #TourismFraud #DigitalResilience #CyberEducation #StealerMalware #ANAT #RomExpo #CyberAwareness #AlexandruAnghelus #Women4Cyber #TravelIndustrySecurity #PublicPrivatePartnership

From October 29–31, Prodefence, represented by CEO Alexandru Anghelus, proudly participated in the Bucharest Cybersecurity Conference 2024, a landmark event bringing together leaders from government, industry, and academia to discuss critical developments in cybersecurity across Europe.

As both CEO of Prodefence and President of CYSCOE – the Cyber Security Cluster of Excellence, Alexandru Anghelus contributed to high-impact discussions alongside key figures such as Dan Cimpean, Director of the National Cyber Security Directorate (DNSC). His active role in the DNSC Cybersecurity Conference and the ENISA “Cybersecurity Resilience & Market” Forum marked a unique opportunity to address pivotal topics directly influencing the future of Europe’s cybersecurity landscape.

🔍 Key Themes Discussed:

  • Implementation of a Coordinated Vulnerability Disclosure (CVD) policy in Romania;
  • Enhancing cyber resilience in critical infrastructure sectors, including maritime and healthcare;
  • Addressing cyber risk management in maritime operations;
  • Understanding threats and vulnerabilities in the healthcare sector under the lens of evolving threat landscapes;
  • Aligning national strategies with NIS2, the EU Cyber Resilience Act, and other key European cybersecurity frameworks.

🔗 Collaboration at the Core

The conference was not only a platform for dialogue but a catalyst for public-private partnerships and cross-sectoral coordination. Prodefence reaffirmed its role as a trusted cybersecurity partner, contributing expertise in threat intelligence, incident investigation, and resilience planning for critical industries.

The roundtable engagements emphasized the need for skill development, policy innovation, and strategic alignment to safeguard Europe’s digital infrastructure in a time of increasing geopolitical and technological risk.

“At BCC 2024, we explored essential cybersecurity priorities with impact across industries. As Prodefence and CYSCOE, we remain fully committed to shaping a safer, more resilient digital Europe.”
Alexandru Anghelus, CEO of Prodefence

🙌 Acknowledgements

Prodefence congratulates the DNSC team and all partners involved for organizing a high-impact event that exceeded expectations in scope and substance. Special thanks to Dan Cimpean, Sebastian Dan, Mirabela Săvulescu, Aurel Huștea, Fraga Tariuc, Gabriel Dinu, Mihaela Curcă, and the entire organizing team for their dedication and excellence.


Stay tuned as Prodefence continues to contribute to national and European cybersecurity strategy through innovation, collaboration, and technical excellence.

#Prodefence #Cybersecurity #BCC2024 #ENISA #DNSC #ECCC #DigitalResilience #NIS2 #CyberResilienceAct #ThreatIntelligence #CYSCOE #PublicPrivatePartnerships #CyberLeadership

Alexandru Anghelus, President of the Cyber Security Cluster of Excellence (CYSCOE), participated in a press conference alongside Chief Police Inspector Florin Ionuț Zaborilă, head of the Cybercrime Investigation Unit at the Iași County Police Inspectorate. The event focused on addressing the growing wave of cyber threats impacting Romanian citizens.

📌 Topics Addressed by Alexandru Anghelus:

  • Online Fraud and Phishing: He emphasized how cybercriminals exploit seemingly legitimate messages to trick users into disclosing personal and financial data.
  • “Money Recovery” Fraud Schemes: Anghelus warned about an emerging tactic in which victims are falsely promised refunds, only to fall prey to new scams orchestrated by the same or affiliated threat actors.
  • Social Engineering: A major theme of the discussion was how attackers manipulate trust and digital illiteracy to breach systems and exploit individuals.
  • Cyber Protection and Awareness:
    • Promoting the use of two-factor authentication (2FA);
    • Encouraging individuals to pause and verify before taking risky online actions;
    • Stressing the importance of cyber education as a proactive defense.

📢 Public Recommendations Shared:

  • Stay informed by following updates and alerts from the National Cyber Security Directorate (DNSC).
  • Visit Prodefence (www.prodefence.ro) and Cyber AID for insights on how to detect cyber fraud and phishing attempts.
  • Reach out to DNSC (dnsc.ro) for advice and support in case of suspicious online activity or potential cyber threats.

🤝 Emphasizing Public-Private Collaboration

In his remarks, Alexandru Anghelus highlighted the essential role of cooperation between public institutions and the private sector in combating cybercrime. Only through joint action can we build a digital space that is secure, resilient, and trusted by all users.

CYSCOE commends all involved institutions for their dedication to defending the community against cyber threats and expresses gratitude to TVR Iași for their contribution in spreading public cybersecurity awareness.

▶️ Full interview and event footage: https://youtu.be/PO4k1iqoCmI

#CYSCOE #CyberSecurity #OnlineFraud #Phishing #CyberAwareness #DNSC #IPJ #PublicPrivatePartnership #DigitalSafety #AlexandruAnghelus #CyberLeadership #TVRIasi

Financial fraud and digital disinformation are two deeply interconnected phenomena, which have evolved, in the last two decades, from opportunistic, marginal practices into real criminal industries with a global impact. They erode trust in financial markets, destabilize economic and political institutions, and weaken social cohesion and democracy itself, by manipulating the masses and exploiting people’s cognitive vulnerabilities.

Essentially, financial fraud aims to obtain illicit gains by misleading victims, and disinformation serves as a multiplier of this effect, creating false narratives, legitimizing scams, and neutralizing warnings from authorities. The two naturally converge: for a fraud to succeed on a large scale, it needs an information framework to support it — and for disinformation to have an economic effect, it must be directed towards false financial opportunities.

In this context, the emergence and democratization of artificial intelligence (AI) tools has fundamentally changed the dynamics of these risks. On the one hand, AI has made it cheaper, faster, and more sophisticated to produce scams, deepfakes, and fake news — lowering the barrier to entry for malicious actors and increasing the effectiveness of their campaigns. On the other hand, the same technology has provided organizations and authorities with better defense tools: from systems for automatic detection of financial anomalies and suspicious behavior, to tools for analyzing networks and dismantling disinformation campaigns.

Today, attackers and defenders operate on the same technological terrain, in an ever-accelerating competition. Artificial intelligence has thus become a multiplier of human intent, capable of amplifying both risks and responsiveness.

This article aims to explore this complex and dual landscape: how fake cryptocurrency platforms are used to defraud users, how they rely on disinformation to ensure their success, and how artificial intelligence serves as both an accelerator of these threats and an essential countering tool. We will look at the mechanisms used by criminals, the impact on public trust, as well as best practices and emerging technologies in defending against this phenomenon.

Fake cryptocurrency platforms: financial fraud in the digital age

In the digital age, cryptocurrencies have simultaneously become a symbol of financial innovation and an opportunity for crime. The popularity of Bitcoin, Ethereum, and other digital assets has attracted millions of investors, as well as criminal groups that exploit a lack of financial literacy and insufficient regulation. Among the most prevalent methods are fake crypto trading platforms, which are elaborate, persuasive, and difficult to expose.

How do these platforms work?

Attackers use a combination of social engineering, technology, and behavioral psychology to create seemingly legitimate platforms. Typical features:

  • Professional design and fictitious legal details: sites with interfaces identical to those of established platforms, complete with copied legal terms, valid SSL certificates and convincing branding elements.
  • Trap domains: The use of domains that differ from the original ones by a character or extension (e.g., “.co” instead of “.com”).
  • Intense promotion: Social media ads, investment forums, unsolicited emails, all supported by auto-generated fake reviews.
  • AI-powered chatbots: to answer victims’ questions in real-time, reinforcing the appearance of legitimacy.

Why does it work?

These schemes succeed because they exploit:

  • people’s desire for quick gain (FOMO – fear of missing out);
  • excessive reliance on visual and testimonial appearances;
  • the real complexity of the crypto market, which makes it difficult to assess opportunities.

Impact:

  • Individual losses ranging from a few hundred to hundreds of thousands of dollars.
  • Destruction of the victims’ life savings.
  • Reputational losses for the legitimate crypto industry.
  • Contributing to global money laundering flows and financing other criminal activities.

Digital Disinformation: The Catalyst for Scams

Financial fraud at scale cannot exist without an information ecosystem to validate it. Disinformation plays this essential role, creating the ‘narrative’ that lends credibility to fraudulent platforms and blocks warning messages from authorities.

Common disinformation tactics:

  • Content blizzard: the massive publication of thousands of posts, fake news, reviews, which flood the information space, making it difficult to identify the truth.
  • Deepfakes: the use of images/videos of personalities that apparently promote the platform, to confer legitimacy.
  • Coordinated campaigns: thousands of automated social media accounts that repeat the same narrative, generating the perception of a majority.
  • Discrediting warnings: spreading conspiracy theories to weaken trust in regulators.

Consequences:

  • Emotional manipulation of victims.
  • Creating a climate of confusion and mistrust.
  • Weakening the effectiveness of the authorities’ response.

The Carnegie Endowment points out that these campaigns are rarely strictly financial: they often also serve political or geopolitical purposes, using the same arsenal.

AI role: Double-edged sword

Artificial intelligence has established itself as a decisive factor in the fight between attackers and defenders, becoming a multiplier of efficiency for both sides. The same technologies that can be used to detect fraud and disinformation are also easily used to produce them on a large scale and with a high degree of sophistication.

In the hands of the attackers

Attackers quickly adopted AI, exploiting its accessibility and power to expand their operations and mask their intentions. Among the most relevant uses are:

Content generation at scale

  • Language algorithms (such as LLMs) automatically produce texts, articles, reviews, and messages that appear genuine. They are tailored to the target audience, with specific tone and vocabulary, so as to increase the credibility of fake platforms.
  • Huge volumes of content can be generated in a matter of minutes, filling the information space with false narratives and covering legitimate messages.

Extreme customization

Using data collected from social media, data leaks, and OSINT, attackers personalize phishing messages according to each victim’s preferences, habits, and vulnerabilities.

  • An AI-generated email can include personal details that make it seem believable and hard to distinguish from genuine communication.
  • This hyper-personalization significantly increases the success rate of attacks.

Interaction automation

Intelligent chatbots, trained on specific scenarios, can respond to victims on fake platforms 24/7.

  • Chatbots can have complex conversations, answering questions, assuaging doubts, and convincing the victim that the platform is genuine.
  • This reduces the need for human personnel and increases the scalability of the operation.

Deepfakes

Image and video generation technologies are used to create materials in which public figures, executives or specialists appear (falsely) promoting the fraudulent platform.

  • During video calls or online conferences, deepfakes can convince victims that they are talking to someone they trust.
  • These materials increase the emotional pressure and credibility of the scheme.

In the hands of the defenders

On the other hand, AI also provides defenders with powerful tools to detect and counter attacks. Key uses include:

Anomaly detection

Specialized algorithms can analyze millions of transactions or interactions in real-time to identify unusual patterns.

  • They can flag suspicious activity, such as repetitive transactions, logins from unusual locations, or behaviors that don’t fit the user’s regular profile.
  • These systems are fundamental to protecting banks, exchanges, and exchanges.

Automatic content classification

Machine learning-based classification systems analyze text, images, and videos to assess the likelihood that they are false or misleading.

  • They can filter reviews, comments, and news in real-time, reducing the spread of misinformation.
  • They are used by social platforms, news agencies, and regulators.

Network analysis

AI enables mapping and analyzing relationships between thousands or millions of accounts, sites, and transactions.

  • By graphically analyzing these connections, investigators can identify key nodes and dismantle coordinated campaigns.
  • This technique is used in investigations into botnets, troll farms and money laundering networks.

Media Verification

AI tools that specialize in “media forensics” can analyze metadata, visual inconsistencies, and sound patterns to determine if an image or video has been manipulated. They can recognize deepfakes and artificially generated content, helping to protect public opinion and institutions from manipulation.

Artificial intelligence is undoubtedly a double-edged sword. In the hands of criminals, it can produce more convincing, cheaper, and harder-to-detect scams. In the hands of defenders, however, AI is becoming an indispensable ally, providing the ability to analyze data at scale, detect anomalies, and respond quickly to threats.

The success of the fight against fraud and disinformation depends not only on technology, but also on who uses it more effectively.

Recommendations

For users:

Although attackers are using increasingly sophisticated technologies, users can greatly reduce the risk of becoming victims through a combination of caution, information, and basic cybersecurity practices. Here’s how the most important measures can be applied correctly:

Always check the authenticity of platforms and URLs

  • Before investing money or entering personal data, carefully examine the site’s address.
  • Make sure that the domain is spelled correctly, with no extra or suspicious characters (e.g., “binancee.com” instead of “binance.com”).
  • Check for SSL certificates (the padlock icon in your browser), but keep in mind that this doesn’t guarantee legitimacy — only connection security.
  • Search the platform in the official lists of financial regulators (ex. ASF, SEC, FCA, etc.) to see if it is authorized.

Avoid decisions under emotional pressure

  • Attackers intentionally create a sense of urgency (offer valid “only today”, limited slots, timers), to prevent rational analysis.
  • Take a break, seek the advice of a friend or specialist and do not give in to the impulse.
  • Remember: Real investments don’t require instant decisions, and legitimate opportunities don’t disappear overnight.

Use multi-factor authentication and anti-phishing extensions‑

  • Enable multi-factor authentication (MFA) wherever possible — preferably with an authenticator app (Google Authenticator, Authy), not via SMS.
  • MFA adds an extra layer of protection, making it more difficult for attackers to gain access even if the password is compromised.
  • Install anti-phishing‑and website reputation check extensions (e.g. Netcraft, Malwarebytes Browser Guard, Bitdefender TrafficLight) to be alerted in case of sites known to be fraudulent.

Search for information from official sources

  • Before investing or filling in personal data, document from credible sources: government websites, regulatory authorities, recognized specialized publications.
  • Avoid relying solely on reviews or forums — they can be manipulated through disinformation campaigns.
  • Check the news about the platform in multiple independent sources and be skeptical of “too good to be true” promises.

These simple but essential practices can protect your savings and give you time to analyze situations with lucidity. In the face of increasingly sophisticated schemes, educated and vigilant users are the first line of defense against financial fraud and disinformation.

For organizations:

Organizations — be they financial institutions, technology companies, crypto platforms or online service providers — are frequent targets of attacks and at the same time vectors through which fraud or disinformation can spread. They bear the responsibility to protect their users, data, and reputation. Implementing proactive measures is essential to prevent incidents or limit their impact.

Deploy AI technologies for monitoring and detection

  • Artificial intelligence and machine learning algorithms are indispensable for analyzing the huge volumes of data generated by transactions and interactions.
  • They can detect anomalies, suspicious behavior, or coordinated campaigns before they cause significant damage.
  • Examples: detecting transactions with typical characteristics of money laundering, recognizing phishing attempts by analyzing the content of emails or identifying fake accounts on social networks.
  • It is essential that the models are constantly updated to keep up with the evolution of attack tactics.

Educate employees about emerging tactics

  • Employees are often the weakest link in the security chain, and attackers exploit this reality through phishing, social engineering, and deepfakes.
  • Organisations must invest in continuous training programmes, which include:
  • recognition of fraudulent messages and websites;
  • awareness of the risks related to data sharing;
  • Periodic phishing simulations to test the vigilance of the teams.
  • Education should be tailored to roles and levels of responsibility, not delivered generically.

Collaborate with authorities and other industry players

  • Cyber threats are rarely isolated — they are global and distributed.
  • Organizations must actively participate in the exchange of information within  threat intelligence sharing communities, together with authorities, competitors and other relevant entities.
  • Examples of such collaborations include participation in incident response centres (CSIRTs/CERTs), public-private partnerships or sectoral working groups.
  • The rapid exchange of indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs) enables faster and more effective responses to threats.

Develop clear incident response protocols

  • No matter how robust prevention is, no system is infallible. It is vital that organizations have well-defined response plans, tested and known by the teams.
  • An incident response plan should include:
  • rapid identification and containment of the threat;
  • internal and external notification (including to authorities and customers, where applicable);
  • remedial and recovery procedures;
  • post-incident review to identify lessons learned.
  • Periodic incident simulations (tabletop exercises) help maintain the organization’s readiness.

Organizations are not only potential victims, but also part of the defense ecosystem against fraud and disinformation. Success in protecting them and their users depends on:

  • adoption of appropriate technologies;
  • continuous training of staff;
  • cooperation with relevant partners;
  • clear and tested plans for crisis situations.

Investing in these measures not only reduces risk, but also protects customer reputation and trust — critical assets in any industry.

For authorities:

National and international authorities — governments, regulators, law enforcement agencies and multilateral institutions — have a crucial role to play in setting the framework within which both financial innovation and protection against abuse take place. As financial fraud and disinformation are amplified by artificial intelligence, authorities need to adopt proactive, pragmatic and well-calibrated measures.

Develop policies adapted to new technologies

  • Traditional regulations are often overtaken by the pace at which technology evolves.
  • It is essential that authorities create policies and regulations that:
  • they take into account the specifics of blockchain, cryptocurrency, AI and deepfake technologies;
  • establish clear responsibilities for platforms and providers;
  • protect consumers without stifling innovation. A clear but flexible framework helps the market to develop safely and prevents systematic abuses.

Invest in AI Defense Tools

  • Just as criminals use AI to attack, authorities must use the same technologies to defend themselves.
  • It is necessary to finance the development and implementation of:
  • automated fraud and disinformation monitoring systems;
  • network analysis algorithms for detecting coordinated campaigns;
  • forensic tools capable of identifying deepfakes and manipulated content. Investing in strengthened AI infrastructure reduces response time and increases the efficiency of investigations.

Encourage public-private partnerships and information sharing

  • No actor, whether governmental or private, can combat these threats alone.
  • It is vital to encourage cooperation between:
  • regulators, police and intelligence services;
  • financial institutions, technology platforms and research organisations;
  • international partners and regional alliances. The rapid exchange of indicators of compromise (IoCs), emerging tactics, and statistical data helps prevent attacks at an early stage and reduce their impact.

Financial fraud and disinformation are fueled by the same raw material: people’s trust and emotions. Artificial intelligence has exponentially amplified both the power of these threats and the ability to counter them.

Effective response requires:

  • Constantly adapted technology to keep up with attackers.
  • Continuous digital education, to raise the level of awareness and competence of citizens and professionals.
  • International collaboration across sectors, as threats do not respect national borders.

AI is neither good nor bad by nature — just a multiplier of human intent. In the right hands, it can become the most powerful weapon in the defense of truth and financial security.

Introduction

The growing dependence on digital infrastructure in various sectors has exponentially increased the risk of cyber threats. These threats can lead to catastrophic consequences if not properly managed, especially in essential services. Cyber-attacks can disrupt critical operations, compromise sensitive data and cause financial and reputational damage. The NIS 2 Directive seeks to address these risks by mandating robust cybersecurity measures in critical sectors.

Essential services such as energy, transport, banking and healthcare are the backbone of modern society. Disruption can have far-reaching consequences, affecting not only the immediate sector, but also the economy and public safety. As cyber threats become more sophisticated, it is crucial to implement comprehensive cyber security strategies to protect these services from potential attacks.

This paper aims to highlight the importance of implementing these measures by examining potential threats and their impact on essential services. By understanding the risks and the necessary cybersecurity measures, we can better protect critical infrastructure and ensure the continuity of essential services.

Overview of the NIS 2 Directive

The Networks and Information Systems (NIS) 2 Directive is a key piece of EU legislation designed to improve the cyber security of critical infrastructure. It extends the scope of the original NIS Directive, increasing the obligations for Member States and operators of essential services to enhance their cybersecurity capabilities.

Key objectives of the NIS 2 Directive

  • Strengthening cyber security: Improving the security of networks and information systems across the EU.
  • Increased cooperation: Improved cooperation between Member States and the European Union Cyber Security Agency (ENISA).
  • Harmonization of regulations: Ensure consistent cybersecurity requirements across Member States.
  • Improve incident reporting: Establish mandatory reporting of significant cyber incidents to relevant authorities.

Key provisions

  • Broad scope: Includes additional sectors such as health, digital infrastructure and space.
  • Risk management: requires operators to adopt risk management practices, including technical and organizational measures.
  • Incident Response: Mandates the development and implementation of incident response plans.
  • Supply chain security: emphasizes the need to address cyber security risks in the supply chain.

Key services and potential cyber threats

  • Energy
  • Transportation
  • Banks
  • Financial market infrastructures
  • Health sector
  • Drinking water supply and distribution
  • Digital infrastructure
  • Public administration
  • Spazio

Banks

Description:

Banking involves financial institutions offering services such as deposits, loans and foreign exchange. It is essential for economic stability and personal financial security.

Potential Cyber Threats:

  1. Banking System Outages:
    • Description: Cyber attacks can disable banking systems, preventing transactions and access to funds, causing widespread financial disruption.
    • Impact: It affects both individuals and businesses, causing significant economic losses and loss of confidence in financial systems.
    • Examples: DDoS attacks targeting banking infrastructure, such as attacks on several banks in Europe in 2012.
  2. Fraudulent transactions:
    • Description.
    • Impact: Leads to direct loss of money and can cause major reputational damage for financial institutions.
    • Examples: phishing attacks and malware that compromise customers’ bank accounts, such as the Carbanak incident, which stole more than $1 billion from banks around the world.
  3. Customer data security breaches:
    • Description: Security breaches affecting customer data can lead to identity theft and financial fraud, undermining trust in financial institutions.
    • Impact: It affects millions of customers, leading to financial losses and potential lawsuits against banks.
    • Examples: major security breaches such as the Equifax incident in 2017, which exposed the personal data of 147 million people.
  4. ATM network compromise:
    • Description: Attacks on ATM networks can lead to unauthorized cash withdrawals and service interruptions.
    • Impact: It causes financial losses for banks and customers and can create panic among ATM users.
    • Examples: attacks on ATM networks, such as the Jackpotting attack, where ATMs were manipulated to release money in an unauthorized way.

Mitigation Strategies:

  • Real-Time Monitoring and Response: deploy advanced monitoring systems for rapid threat detection and response.
  • Data Encryption: using advanced encryption to protect sensitive customer and transaction data.
  • Multi-Factor Authentication: Implement multi-factor authentication to ensure secure access to bank accounts.
  • Customer Education: Educate customers on recognizing and avoiding phishing attempts and other social engineering methods.
  • Collaboration and information sharing: Promote collaboration between banks and law enforcement agencies to share threat intelligence and best practices.
  • Incident Response Planning: Develop and regularly update incident response plans to ensure rapid and effective responses to cyber incidents.

By understanding these potential threats and implementing robust mitigation strategies, the banking sector can increase resilience against cyber-attacks and ensure the continued provision of essential services.