Research · AI Security

Deepfakes & AI-Enabled Fraud

Generative AI makes it cheap to fake voices, faces and writing. Attackers use it to impersonate executives, bypass identity checks and scale phishing. Defenses depend as much on process as on detection technology.

Common attack patterns

  • Voice or video impersonation of executives to request urgent payments or data.
  • Synthetic identities and manipulated documents used to open accounts.
  • Attempts to defeat voice or face-based identity verification.
  • Highly personalized phishing and business email compromise written by AI.
  • Fake job candidates using AI-altered video and identities.

Why it matters

Traditional warning signs, such as poor grammar or an unfamiliar voice, are becoming unreliable. A convincing call or video meeting can pressure employees into acting quickly. Detection tools help but are not reliable enough to be the only defense, especially as generation quality improves.

Controls that help

  • Out-of-band verification for payment changes and sensitive requests, using contact details already on file.
  • Multi-person approval for high-value transactions.
  • Code words or verification steps for executive requests.
  • Layered identity proofing that does not rely on voice or face alone.
  • Training that shows employees realistic deepfake examples.
  • Clear permission for employees to pause and verify, even when a request appears to come from a senior leader.

Common pitfalls

  • Relying on staff to spot fakes by eye or ear.
  • Payment processes that can be completed by one person on one call.
  • Treating deepfakes as only a reputational issue.

How to get started

  • Review payment and vendor-change processes for single points of failure.
  • Add deepfake scenarios to security awareness training and exercises.
  • Assess identity verification methods used for customers and employees.
  • Prepare a response plan for deepfakes of your executives or brand.

Questions leaders should ask

  • Could a convincing call from our CEO trigger a payment today?
  • Do our identity checks rely on voice or face alone?
  • Have employees seen realistic deepfake examples in training?
  • How would we respond to a deepfake of one of our executives?

Research Reports

In-depth guides, ebooks and certification prep.

Browse all reports →