In 2024, an employee at engineering firm Arup transferred USD 25 million after a video call on which the financial “directors” turned out to be deepfakes. This is not a movie plot but, today, one of the fastest-growing vectors of financial fraud. Artificial intelligence has lowered the barrier to entry for social engineering: faking a superior’s voice or face is cheaper, faster and more convincing than ever.
This article focuses on financial scams powered by AI — deepfake, vishing and CEO fraud — and on how to realistically defend against them. For the broader picture of how attackers use AI across the entire attack chain, see the article how attackers use AI: deepfake, phishing and malware.
Why AI changes the economics of scams
According to ENISA Threat Landscape 2025, more than 80% of observed social engineering campaigns used AI-generated or AI-enhanced content in early 2025. The mechanism is simple: what once required language fluency, research and time can now be automated. Error-free phishing, personalized messages, a cloned voice of the CEO on a voicemail — all of it scales at almost no cost.
Dedicated tools have also appeared in the underground: WormGPT and FraudGPT (models “without guardrails” for generating criminal content) and fake sites posing as popular AI tools that in reality distribute infostealers. This shows that for criminals, AI is at once a tool of attack and a lure.
Deepfake and CEO fraud: the anatomy of a scam
CEO fraud, the “boss scam,” is a social engineering classic: the attacker impersonates a member of management and pressures a finance employee into making an urgent transfer or changing account details. AI adds an audiovisual layer to it.
A typical sequence:
- Reconnaissance — the attacker collects publicly available recordings of executives’ voices and images (talks, webinars, social media) as training material.
- Pretext — the employee receives an urgent, confidential request: an acquisition, a settlement, a “discreet” transaction, time pressure.
- Credibility — a deepfake on a video call or a cloned voice on a phone call removes the natural distrust (“it was the CEO, after all”).
- Execution — the transfer lands in an account controlled by the attacker; the funds are quickly moved out.
The scale is confirmed by data. According to a Gartner survey (302 cybersecurity leaders, March–May 2025), 62% of organizations experienced a deepfake attack within 12 months — including 43% audio and 37% video. CERT Poland, in turn, warns about deepfakes in investment scam campaigns (fake recordings and videos featuring the likenesses of well-known people).
Vishing: the scam you hear
Vishing (voice phishing) is a scam conducted by voice — by phone or via messaging apps. Voice cloning makes the caller sound like a trusted person. According to the CrowdStrike 2025 Global Threat Report, vishing saw a 442% increase — though this is a comparison of the first and second half of 2024, not the dynamics of the whole of 2025. Regardless of the exact figure, the trend is unambiguous: voice has ceased to be proof of identity.
How to defend — layers of defense
Defending against AI-powered scams does not rest on “spotting a deepfake by eye.” Judging the authenticity of an image or voice is unreliable and will only get harder. Effective defense shifts the burden from assessing the content to verifying the process.
1. Second-channel verification — the foundation
This is the single most important barrier. Every request for an urgent transfer, a change of a supplier’s payment details or a deviation from procedure must be confirmed through an independent, previously agreed channel — e.g. a callback to a number from the company directory (not the number given in the message). The rule is: don’t trust the channel the request came through.
2. Financial procedures resistant to pressure
- The four-eyes principle (dual approval) for transfers above a defined threshold.
- Limits and delays for new or changed recipient accounts.
- A clear policy: no “urgent and confidential” request exempts anyone from procedure — it is precisely time and secrecy pressure that is the warning sign.
3. Awareness and training
Employees — especially in finance, accounting and executive support — should know the deepfake and vishing scenarios and understand that asking for verification is expected, not offensive. Tie this to general anti-phishing hygiene: how to effectively protect your company from phishing and what phishing is and how to protect yourself.
4. The technical layer
- Phishing-resistant MFA (FIDO2/hardware keys) on privileged accounts and in payment systems — it makes it harder to take over the identity that would lend credibility to the scam.
- Email protections (DMARC/DKIM/SPF, BEC filtering) that limit domain impersonation.
- Enforcing procedures in tools (approval workflows in the finance system), not just “on paper.”
Warning signs
- Time and confidentiality pressure (“do it now, tell no one”).
- A request to skip a standard procedure or change an established process.
- Inconsistencies in the deepfake (facial expressions, lip sync, lighting, motion artifacts) — helpful, but never decisive.
- A change to a “known” supplier’s account number just before a payment.
Remember: no single sign is conclusive. Independent verification of the request is what decides.
Summary
Deepfake, vishing and CEO fraud have taken financial scams to a new level of realism, but their weak point remains the same: they require you to trust a request without independent verification. Companies that make second-channel verification a hard, non-negotiable procedure neutralize most of these attacks — no matter how convincing the faked voice or image. This is also part of the broader 2026 threat picture we describe in the 2026 cyber threat landscape report.
The content above is educational. Some of the market forecasts cited are projections, not established facts. If you want to build resilient verification procedures and test them in practice (e.g. with exercises and simulations), the nFlo team can help design and implement appropriate safeguards.
Sources and reference materials
- ENISA Threat Landscape 2025
- Gartner — survey of cybersecurity leaders (2025) on deepfake attacks
- CrowdStrike 2025 Global Threat Report
- CERT Poland (NASK) — warnings on deepfakes in investment scams
