Picture a finance manager at a respected engineering firm, sitting at his desk on an ordinary Friday afternoon in Hong Kong. An email arrives from the company’s UK based chief financial officer, marked urgent, referencing a confidential transaction that needs to happen quietly and quickly. He is skeptical. He has sat through the security trainings. He knows what a phishing email looks like, and this one has the faint, unplaceable wrongness of one. He almost lets it go.
Then an invitation arrives for a video call. He joins, and there, on his screen, is the CFO he has seen in a hundred company town halls, along with several other colleagues whose faces and voices he recognizes immediately. They are discussing the deal casually, the way real executives discuss real business, and they ask him directly to proceed with the transfers. Every doubt he had a few minutes earlier evaporates, because doubt cannot survive the sight and sound of people you know, talking to you, in real time, on camera. Over the following days, he authorizes fifteen separate transfers totaling roughly twenty five million dollars. Every single person on that call, other than him, was a fabrication. Not an actor. Not a lookalike. A piece of software.
This is not a hypothetical scenario built to illustrate a point. It happened in January 2024, it happened to a real company called Arup, and it is, as of this writing, still the largest publicly documented deepfake fraud incident in the world. It is also, this piece will argue, simply the most dramatic data point in a much larger, much quieter shift that has already reached far beyond corporate boardrooms, into family phone calls, romantic relationships formed entirely online, job interviews conducted over video, and the very question of whether a face or a voice can still be trusted as proof that the person behind it is real. This piece is the most comprehensive treatment this series has attempted of a single fraud category, because deepfake fraud is not really one category at all. It is the technology underneath every other fraud this series has documented, applied to the single oldest and most trusted form of verification human beings have ever had, the direct evidence of our own eyes and ears.
The size of what is actually at stake, and why the numbers you have read are probably wrong
Before going further, this piece needs to do something that will feel unusual for a topic this alarming. It needs to slow down and be honest about which numbers describing this problem are actually real.
Search for deepfake fraud statistics and you will find, within minutes, a genuinely dizzying spread of headline figures. Global losses of 200 million dollars in a single quarter. A full billion dollars lost in the United States alone in a single year. A cumulative global total approaching four billion dollars. A projection of forty billion dollars by 2027. These numbers are not simply different ways of describing the same thing. Several of them directly contradict each other, sometimes while citing the exact same underlying source. One widely cited 2026 research firm, drawing on the AI Incident Database and other public records, reports a cumulative global total of 3.7 billion dollars. A separate outlet, citing what appears to be the same underlying research provider, reports a considerably lower cumulative figure of 2.19 billion dollars for what should be a comparable time period. Neither publishes enough methodology for an outside reader to reconcile the difference, and a detailed 2026 audit of the entire category, published by industry research firm DigitalApplied, put this bluntly, describing the space as dominated by numbers nobody audits, billion dollar loss figures with no primary source, and four digit surge percentages that contradict each other, some of them recycled forecasts being quietly reported as if they were measurements of something that already happened.
There is, however, one number in this entire landscape that rests on something closer to solid ground, and it deserves to anchor everything else in this piece. In its 2025 Internet Crime Report, released in early 2026, the FBI’s Internet Crime Complaint Center, known as IC3, broke out AI enabled fraud as its own distinct category for the first time in the center’s roughly twenty five year history. Across 22,364 complaints specifically flagged with an AI descriptor, IC3 logged 893.3 million dollars in losses for 2025. That decision to formally separate AI enabled fraud from the broader, undifferentiated fraud statistics IC3 has published for decades is itself a meaningful signal, reflecting the agency’s own internal judgment that this category had grown large and distinct enough to merit its own dedicated accounting, a judgment that carries considerably more institutional weight than any individual vendor’s marketing driven estimate.

That breakdown is worth sitting with in detail, because it complicates the popular image of deepfake fraud as primarily a story about voice cloned CEOs and fabricated video calls. Investment fraud, much of it tied to cryptocurrency schemes rather than corporate wire transfer scams, accounted for roughly 632 million dollars, or about seventy one percent of the entire audited total. Business email compromise incidents that specifically involved an AI element added another 30 million dollars. Romance and confidence scams, the subject of a dedicated section later in this piece, contributed 19 million dollars. And a newer, stranger category, deepfake enabled employment interview scams, where a fraudulent applicant uses a real time video filter to interview for a job under a false identity, typically to gain network access rather than a paycheck, accounted for roughly 13 million dollars. Adults aged sixty and older bore 352 million dollars of the total, close to thirty nine percent, confirming what fraud investigators have said anecdotally for years, that older adults remain disproportionately targeted by this entire category of crime.
DigitalApplied’s own audit is explicit that widely circulated larger figures, including specific claims of 1.8 billion dollars lost to voice cloning scams alone, or 2.3 billion dollars stolen from elderly victims attributed directly to the FBI, have no identifiable primary source and directly contradict the audited IC3 report, failing basic arithmetic before they even fail on sourcing. None of this means the broader problem is smaller than the alarming headlines suggest. It almost certainly is not, for a reason this piece will return to directly. Congressional analysis cited across multiple 2026 research reports estimates that fewer than five percent of voice clone fraud victims ever file a report at all, meaning even a rigorously audited government figure like IC3’s is best read as a firm floor rather than a ceiling. What it does mean is that the honest, defensible way to discuss this problem’s scale is to lead with the one number that has actually been through an audit, treat everything larger as a plausible but unverified estimate of the true, unreported total, and treat any specific vendor forecast, however professionally produced, as a projection rather than a measurement. The single most consistently cited projection in this space comes from Deloitte’s Center for Financial Services, which in 2024 forecast that generative AI enabled fraud losses in the United States alone would climb from 12.3 billion dollars in 2023 to approximately 40 billion dollars by 2027, a 32% compound annual growth rate. That figure appears, cited correctly and consistently, across nearly every serious piece of research reviewed for this article, which is itself a meaningful signal, since forecasts that hold up under that much independent scrutiny are considerably more trustworthy than the untraceable headline totals surrounding them.
A taxonomy: the different kinds of deepfake fraud
The term deepfake gets used as a single catch all in casual conversation, but the underlying fraud actually splits into several genuinely distinct categories, each with its own technology, its own attack pattern, and, as later sections of this piece will show, its own specific defense.
Voice cloning fraud, sometimes called audio deepfake fraud or synthetic voice fraud, uses AI generated speech modeled on a real person’s voice to conduct fraudulent phone calls, voicemails, or voice messages. This is currently the most mature, most accessible, and most widely deployed category, for reasons the next major section of this piece explains in technical detail. Video deepfake fraud, the category that produced the Arup case, uses AI generated or AI manipulated video, frequently combined with cloned audio, to impersonate a real person in a live video call or in pre recorded footage. Real time deepfake fraud, a technically demanding subcategory of video deepfake fraud, refers specifically to synthetic video and audio generated live, during an actual ongoing call, rather than pre rendered footage played back to a victim, and it is the specific capability that made the Arup attack, and the romance scam variants covered later in this piece, possible at all. Synthetic identity fraud uses AI generated faces, voices, and biographical details to construct an entirely fictional person from scratch, rather than impersonating someone who actually exists, a category security researchers describe as the fastest growing form of financial fraud broadly, distinct from impersonation because there is no real victim whose identity is being stolen, only a convincing fiction being used to open accounts, pass verification checks, or build long term trust in a scam. And non consensual intimate imagery, covering sexually explicit deepfakes created and distributed without a victim’s consent, sits in a genuinely different legal and ethical category from the financially motivated fraud that makes up the bulk of this piece, though, as the regulatory section later in this article shows, it has become the single area where federal lawmakers have moved fastest and most decisively.
A further useful way to categorize this fraud, layered on top of the technical taxonomy above, is by attack timing and duration, since the defensive playbook differs considerably depending on which pattern a given attack follows. Synchronous attacks, including the Arup case, the Ferrari near miss, and the grandparent scam pattern covered later in this piece, unfold in real time, demanding an immediate decision under manufactured urgency, and are specifically vulnerable to the callback verification defense this piece recommends throughout, since interrupting a live, urgent interaction to independently verify breaks the attacker’s control over the pacing entirely. Asynchronous attacks, by contrast, including the deepfake job candidate pattern and much of the pig butchering ecosystem covered in this piece’s discussion of romance scams, unfold over days, weeks, or months, relying not on manufactured urgency but on patient, gradual trust building, and require a genuinely different defensive posture centered on ongoing verification and skepticism sustained over time rather than a single, decisive verification moment.
Understanding which category, and which timing pattern, a specific attack falls into matters enormously in practice, because, as this piece will demonstrate repeatedly, the defense that works against a cloned voice on a phone call is meaningfully different from the defense that works against a live video call, which is different again from the defense that works against a fabricated online dating profile that never had a real photograph behind it at all.
Anatomy of the year’s biggest heist: the Arup story
Statistics describe scale. A single, thoroughly documented case makes the actual mechanics and human experience of deepfake fraud considerably easier to feel, in the same way this series has anchored its earlier pieces in the Uber versus Fetch mobile fraud case, the PillPack TCPA settlement, and the Fashion Nova review suppression scandal.
The target was Arup, a London headquartered multinational engineering and design firm with a genuinely storied history, the kind of company whose past work includes the Sydney Opera House. Founded in 1946 and employing roughly eighteen thousand people across more than thirty countries, Arup had, by 2024, built exactly the kind of large, geographically distributed finance operation that makes an organization simultaneously more resilient in some respects and more exposed in others, resilient because no single office holds sole authority over major transactions, exposed because that same distribution means employees routinely handle requests from senior colleagues they may have met only a handful of times, primarily through exactly the video conferencing infrastructure this piece has already identified as newly vulnerable. In mid January 2024, a finance employee in the company’s Hong Kong office received a message that appeared to come from Arup’s own UK based chief financial officer, referencing a secret transaction that needed to be handled with discretion. According to Hong Kong police, who later detailed the incident publicly, the employee’s first instinct was correct. He suspected the email was a phishing attempt, exactly the kind of red flag every corporate security training tells employees to watch for.
What happened next is the part of this story that makes it genuinely instructive rather than simply alarming. Rather than pushing back against the employee’s skepticism with more urgent emails, the attackers did something considerably more sophisticated. They invited him to a video conference. On that call, the employee saw and heard the CFO, along with several other colleagues he recognized from prior meetings, town halls, and internal communications. The visuals were realistic. The voices matched. The people on screen discussed the transaction the way real colleagues discuss real business, casually, with the specific institutional shorthand and context that a stranger could not easily fake. Every single participant on that call besides the employee himself was an AI generated fabrication, built from publicly available video and audio of the real executives pulled from past webinars, conference recordings, and internal company meetings.
Convinced, the employee proceeded with the transaction over the following days, ultimately making fifteen separate wire transfers totaling approximately 25.6 million dollars, equivalent to roughly 200 million Hong Kong dollars, sent to five different Hong Kong bank accounts. The fraud was discovered only when the employee, following up on the unusual request through Arup’s actual corporate headquarters, learned that no such transaction had ever been authorized, no such meeting had ever taken place, and the executives he believed he had spoken with had no knowledge of any of it. By the time the discrepancy surfaced, the money was gone. As of early 2025, according to reporting on the case, none of the stolen funds had been recovered, and the Hong Kong police investigation remained ongoing.
Arup’s own Chief Information Officer, Rob Greig, addressed the incident directly once the company confirmed itself as the victim in May 2024, months after Hong Kong police had first disclosed the scheme without naming the firm involved. Greig was careful to draw a specific, important distinction in how the company characterized what had happened, confirming that no company systems had been compromised and no data had been breached, framing the incident instead as what he called technology enhanced social engineering rather than a traditional cyberattack. That framing matters considerably for how any organization should think about defending against an incident like this. Arup did not fail because its firewalls were weak or its network was penetrated. It failed because a piece of software convincingly impersonated trusted human beings, and no purely technical security control was ever positioned to catch that.
What the Arup case reveals: the tell that exposed it, and the one that almost worked
Buried inside the detailed accounts of the Arup incident is a specific technical detail worth drawing out on its own, because it captures both how convincing this technology has become and exactly where its current limits still sit.
According to reporting on the incident, during the fraudulent video call, the deepfake CFO asked the real employee to introduce himself to the group, a small, ordinary piece of meeting etiquette that would seem to demand nothing suspicious of the fabricated participants in return. What never happened, according to the same reporting, was any direct, spontaneous conversation between the deepfake colleagues themselves. The fake CFO and the other synthetic participants spoke to the human victim. They did not meaningfully speak to each other, the way real colleagues naturally interject, agree, disagree, or joke among themselves during an actual meeting. That absence is not an accident of the attackers’ storytelling choices. It is very likely a genuine technical limitation of the deepfake technology available at the time, since generating multiple simultaneous synthetic participants convincingly reacting to each other in real time is a considerably harder problem than generating one synthetic participant responding to a single human target.
This detail did not save Arup’s employee, who reported no memory of finding the interaction suspicious for that specific reason. But it points directly toward one of the most consistently recommended defensive practices covered later in this piece, and it is worth stating plainly here first. A deepfake attack is built to convince a single target that a specific request is legitimate. It is considerably less equipped to survive a genuine, spontaneous, unscripted conversation among multiple real people who were not part of the original script, which is precisely why callback verification through an independently retrieved phone number, rather than continuing a conversation inside the same channel the request arrived through, remains one of the single most effective defenses against this entire category of fraud, a theme this piece will return to in considerably more technical depth once it has walked through how the underlying voice and video cloning technology actually works.
The Arup case was also, notably, not an isolated event even within Hong Kong specifically. A second, smaller deepfake video call scam struck a separate UK based multinational’s Hong Kong office not long afterward, this time resulting in a loss of roughly 4 million Hong Kong dollars, about 512,000 US dollars, using an almost identical playbook, a fraudulent WhatsApp message from a supposed CFO followed by a convincing deepfake video call. Hong Kong police, addressing the pattern publicly, explicitly noted this was the second such live deepfake video incident the force had encountered, a detail suggesting an established attack template rather than a one time, unusually resourced operation.
The pattern repeats: when familiar voices become weapons
Arup’s story is the largest publicly documented case, but it sits inside a genuinely large and growing pattern of comparable attacks, and two further cases are worth understanding both because they involve recognizable names and because one of them shows exactly what a successful defense actually looks like.
In July 2024, Ferrari came remarkably close to becoming the next headline case. A senior executive at the Italian automaker received a call on WhatsApp from someone whose voice closely matched that of chief executive Benedetto Vigna, complete with a convincing approximation of his distinctive accent, discussing an urgent matter tied to a confidential acquisition and requesting a financial transaction. The executive, rather than proceeding on the strength of a familiar voice alone, challenged the caller with a specific personal verification question, something only the real Vigna could plausibly answer. The attacker, unable to respond convincingly, disconnected the call. No funds were transferred, and Ferrari launched an internal investigation immediately afterward. The case is instructive precisely because it is a near miss rather than a catastrophe, and it demonstrates directly that the single cheapest, lowest tech defense against a voice cloning attack, a genuine, spontaneous challenge question the attacker cannot have scripted in advance, can defeat even a highly convincing clone in real time.
A considerably older case, dating to 2019, established this entire category of fraud in the public imagination years before Arup, and it remains one of the most widely cited examples in security research precisely because it was, at the time, so genuinely novel. The chief executive of a UK based energy firm’s German parent company called one of the firm’s own managers, instructing an urgent transfer of approximately 220,000 euros, roughly 240,000 US dollars, to a Hungarian supplier, citing time pressure and confidentiality. The voice, according to the company’s insurer, carried the slight German accent and the exact vocal characteristics of the real chief executive. The manager complied, and the funds were only recognized as stolen once a second, similarly suspicious request arrived and the company’s fraud detection systems intervened. The case predates the current generation of AI voice cloning tools by several years, built instead on earlier, more limited voice synthesis technology, which makes its success at the time all the more telling about how little sophistication is actually required to exploit trust in a familiar voice, a vulnerability that has only grown more exploitable as the underlying technology has improved dramatically in the years since.
How voice cloning actually works
Understanding why these attacks succeed requires understanding, at least at a functional level, what is actually happening technically when a fraudster clones a voice, since the mechanics explain both why detection has proven so difficult and why the defenses that do work look the way they do.
Modern voice cloning separates a human voice into two distinct components a machine can model independently. The first is identity, meaning the timbre, pitch, cadence, and accent that make a specific voice recognizable as belonging to one particular person rather than anyone else. The second is content, meaning the actual words being spoken. A neural network trained on a sample of someone’s real speech learns to isolate and represent that first component, the identity, as a kind of mathematical fingerprint, often called a speaker embedding, while a second generative system, frequently built around what researchers call a vocoder, takes that fingerprint and fuses it with entirely new, arbitrary text, producing synthetic speech that carries the target’s vocal identity while saying anything the attacker chooses to type.
The detail that should concern any organization thinking about its own exposure is exactly how little raw material this process actually requires. Research from McAfee, now cited consistently across nearly every serious piece of 2026 industry analysis on this subject, found that just three seconds of sample audio is sufficient to produce a voice clone with roughly eighty five percent accuracy, good enough in practice to convincingly fool family members, customer service representatives, and, as the cases above demonstrate, trained corporate finance professionals.

That accuracy climbs further with slightly more source material. A clone built from three to ten seconds of audio, still a genuinely trivial amount, roughly matching the length of a typical voicemail greeting or a few seconds pulled from a public interview, pushes accuracy toward ninety percent by some benchmarking, while a clone built from a longer sample, around three minutes, considerably more available for any public figure with even a modest media presence, can reach accuracy high enough to sustain an extended, multi minute phone conversation without detection. Security researchers increasingly describe this as having crossed what they call the indistinguishable threshold, the point at which the underlying technology has moved from merely convincing to functionally impossible for an ordinary listener to reliably distinguish from a genuine recording, regardless of how carefully that listener is paying attention.
What makes this threat genuinely difficult to contain, rather than simply difficult to detect, is how accessible the underlying tools have become. Open source voice synthesis models, including publicly available systems that security researchers specifically named in 2026 analysis, now run on entirely ordinary consumer laptop hardware, requiring no specialized infrastructure, no significant technical expertise, and no meaningful financial investment beyond a working internet connection to download the software itself. The barrier to entry for producing a convincing voice clone has collapsed from something requiring genuine technical sophistication to something within reach of essentially anyone motivated to try, a shift that maps directly onto the accelerating attack volume covered throughout this piece.
The specific channels through which attackers harvest the source audio needed to build a clone in the first place deserve mention, since they reveal just how many ordinary, everyday activities now double as potential exposure points. Public facing content remains the richest and most commonly exploited source, earnings calls, conference keynotes, podcast interviews, YouTube videos, and social media clips, all readily available and, crucially, entirely legal to download and reuse. Voicemail greetings represent a second, more intimate source, often overlooked precisely because they feel private despite being freely accessible to anyone who calls the number and lets it ring through. Data breaches add a third channel, since customer service call recordings, virtual assistant interaction logs, and other stored audio swept up in a broader corporate data breach can hand an attacker hours of usable source material all at once, far beyond the mere seconds this piece has already established as sufficient. And, increasingly, attackers have simply begun calling a target directly under an unrelated pretext, a wrong number, a survey request, a fake customer service callback, purely to harvest a few seconds of natural speech before the actual attack ever begins, a technique security researchers describe as audio phishing, deliberately engineered to sound mundane enough that the target never suspects the call itself was the first stage of the attack.
How video deepfakes actually work
Video deepfakes build on similar underlying principles but add a considerably more complex second layer, generating not just synthetic speech but a synthetic, moving, visually convincing face to accompany it, synchronized in real time to match both the audio and the natural movements a live video call demands.
The technology underlying real time video deepfakes, the specific capability that made the Arup attack possible, works by training a model on existing video and image footage of a target, extracting the underlying facial geometry, expressions, and movement patterns, then using that trained model to generate a live, synthetic video feed that can be piped directly into a standard video conferencing application, appearing to the software, and to the human on the other end of the call, as an ordinary webcam feed. Publicly available applications built specifically for this purpose, including one named directly in security research covering romance scam tactics, allow an attacker to conduct a live, real time video call using another person’s face, layered convincingly over the attacker’s own live movements and expressions, a capability that directly undermines what security professionals had, until relatively recently, considered one of the more reliable verification methods available, asking a suspicious contact to jump on a quick video call to confirm they are who they claim to be.
The technical demands of real time video generation remain genuinely higher than those of voice cloning alone, which is part of why video based attacks, while devastating when they succeed, remain somewhat less common in the current threat landscape than pure voice cloning attacks, and why the Arup case’s specific limitation, synthetic participants who never meaningfully interacted with each other, likely reflects a genuine current constraint on how many simultaneous, independently convincing synthetic participants a single attack can sustain at once. That constraint is very unlikely to remain a reliable defense for long. Every piece of research reviewed for this article agrees on one central point: the generation side of this technology is improving considerably faster than the detection side, and any defense built around a specific, current technical limitation of deepfake generation should be treated as temporary rather than durable.
The underlying computational requirements for real time video deepfakes have fallen dramatically over a remarkably short period, mirroring the same accessibility collapse this piece has already documented for voice cloning specifically. Where early real time face swap technology genuinely required specialized graphics hardware and meaningful technical configuration, current generation tools increasingly run acceptably on consumer grade equipment, with cloud based rendering services further lowering the barrier for attackers unwilling or unable to invest in local hardware at all, another direct illustration of the deepfake as a service commercialization trend covered in detail later in this piece. Security researchers specifically flag that this accessibility shift has occurred over a timeframe measured in a small number of years rather than a decade, a pace of capability diffusion considerably faster than most previous categories of fraud enabling technology, and one that has left defensive infrastructure, both technical and regulatory, visibly struggling to keep pace throughout every section of this piece.
The old verification tricks that no longer work
For years, security professionals and everyday consumers alike relied on a small set of informal verification heuristics to confirm a suspicious contact’s identity, and it is worth being explicit about which of those heuristics this technology has already defeated, since outdated advice continues to circulate widely.
Asking someone to hop on a quick video call used to be considered close to a gold standard verification method, since faking a live, responsive video feed was, until recently, assumed to require resources far beyond an ordinary scammer’s reach. Real time deepfake tools have directly eliminated that assumption. Security researchers covering romance scam tactics specifically warn against treating willingness to video call as proof of identity, noting that real time deepfake software can now fake a live call convincingly enough to include on demand gestures and natural seeming reactions to a conversation partner’s own words and questions. Listening closely for vocal imperfections, an unnatural pause, a slightly robotic cadence, was, until quite recently, a genuinely useful skill. The three second, eighty five percent accuracy benchmark covered earlier in this piece reflects just how unreliable that skill has become, and formal research backs up the intuition directly. Human participants asked to identify high quality video deepfakes in controlled studies correctly spotted them only about a quarter of the time, a figure covered in more detail in the dedicated detection section later in this piece. And checking whether an image reverse searches to a known, existing photograph used to reliably expose a stolen or reused profile picture. AI image generation has closed that gap as well, producing entirely original, non existing faces specifically because a face that has never existed anywhere else on the internet cannot be found through a reverse image search no matter how thoroughly a skeptical target checks.
The throughline across all three defeated heuristics is the same, and it is the central insight this piece keeps returning to from different angles. Every traditional verification method relied on some specific technical limitation of the fraud technology available at the time. As that technology has improved, each of those limitations has closed in turn, one by one, and there is no reason to expect the next widely trusted heuristic to hold up any better than the last three did. This is precisely why the defensive recommendations covered later in this piece shift deliberately away from detection, trying to spot the fake, and toward process, building verification steps that remain valid regardless of how convincing the fake becomes.
Beyond the boardroom: romance scams and pig butchering
Corporate wire fraud captures headlines because of its scale in any single incident, but the largest share of deepfake enabled harm by total dollar volume, and very likely by total number of victims, happens far from any boardroom, inside relationships that never should have existed in the first place.
Romance scams cost American consumers roughly 1.14 billion dollars in reported losses in 2023 alone, according to the FTC’s own Consumer Sentinel Network, spread across more than 64,000 individual reports, with a median individual loss of 2,000 dollars. That figure has continued climbing since, with more recent FBI data showing romance and confidence scam losses among adults sixty and older alone rising from 389 million dollars in 2024 to 584 million dollars in 2025, a fifty percent increase in a single year.

Business email compromise losses among that same older adult population rose in almost exact parallel, from 385 million dollars in 2024 to 568 million dollars in 2025, a pattern researchers attribute directly to older adults disproportionately managing family trusts, small business finances, and estate accounts, making them a specifically attractive target for exactly the kind of AI enhanced impersonation covered throughout this piece.
The most financially devastating variant of this entire category has become what researchers call pig butchering, a term borrowed from a Chinese language metaphor describing the practice of fattening a pig before slaughter, referring to the deliberate, patient cultivation of trust and emotional investment over weeks or months before a victim is guided toward a fraudulent cryptocurrency investment platform. University of Texas research cited across multiple 2026 industry reports estimates that pig butchering schemes have extracted at least 75.3 billion dollars globally since January 2020, a figure researchers explicitly caveat as likely far below the true total given chronic underreporting. FBI data shows investment fraud losses, the category dominated by pig butchering schemes, climbing from 3.31 billion dollars in 2022 to 5.8 billion dollars in 2024, and blockchain analytics firm Chainalysis separately estimates roughly 17 billion dollars was stolen through cryptocurrency scams and fraud broadly in 2025 alone, with the average individual crypto scam payment jumping 253% in a single year, from 782 dollars in 2024 to 2,764 dollars in 2025.
Deepfake technology has transformed this entire category by defeating the specific verification tactics that used to give cautious daters some real protection. Security researchers covering elder targeted romance scams are explicit about the shift. AI now generates entirely original profile photographs that fail a reverse image search because the underlying face was never a real person to begin with, and the same real time deepfake video technology covered earlier in this piece lets a scammer appear convincingly as the fabricated romantic partner on a video call, defeating what used to be considered one of the most reliable available verification tests. AI powered chatbots layer a further capability on top of this, maintaining consistent, emotionally engaged text conversations around the clock, across what researchers describe as many simultaneous victims at once, a scale of operation no individual human scammer could ever sustain manually.
The demographic picture here deserves particular attention, because it cuts against a common and genuinely dangerous assumption. Research on the subject is explicit that the belief that only elderly or less educated people fall victim actively prevents younger, well educated victims from recognizing their own vulnerability or seeking help when they are targeted, and UK fraud data shows the gender split among victims has narrowed to a nearly even 51 to 49 percent split between women and men over the past several years, a considerable shift from the older stereotype of romance fraud as targeting primarily older women. What has not shifted is underreporting. Canada’s Canadian Anti Fraud Centre estimates that only five to ten percent of victims ever report what happened to them, meaning the true annual scale of this category, already measured in the tens of billions of dollars globally, may run ten to twenty times higher than official figures capture, driven substantially by shame and embarrassment that keep victims silent long after the financial damage is done.
Cryptocurrency exchanges themselves have become a secondary target inside this same ecosystem, and the mechanism deserves specific mention because it shows deepfake technology being weaponized not just against individual victims but against the identity verification infrastructure meant to protect an entire financial system. Industry research covering the pig butchering ecosystem describes AI now being used to generate realistic synthetic identity documents, fabricate video verification footage, and conduct live know your customer interviews using deepfake technology, allowing fraud operations to open and operate legitimate seeming cryptocurrency exchange accounts at industrial scale, accounts later used to launder proceeds from exactly the kind of romance and investment scams described throughout this section.
The organizational structure behind many large scale pig butchering operations adds a further, genuinely disturbing dimension to this category that distinguishes it sharply from the other fraud patterns covered in this piece. Investigative reporting on the pig butchering industry, particularly operations based in parts of Southeast Asia, has documented large scale compounds where trafficked workers, many held against their will, are forced to run these scam operations under threat of violence, meaning a meaningful share of the human beings actually typing the messages and, increasingly, operating the AI tools covered throughout this piece, are themselves victims of a separate, serious crime layered underneath the financial fraud experienced by the scam’s ultimate target. This detail matters for how the entire category should be understood, since it means pig butchering sits at the intersection of financial fraud, human trafficking, and AI enabled deception simultaneously, a genuinely rare convergence that has drawn attention from human rights organizations and financial crime investigators alike, and one that international law enforcement coordination has struggled to address given the cross border, multi jurisdictional nature of the compounds involved.
The detection technology arms race
If the preceding sections leave the impression that human judgment alone is no longer a reliable defense against this category of fraud, the formal research bears that impression out with genuinely stark precision, and understanding exactly how stark matters for calibrating any organization’s actual security posture.
A 2025 study from identity verification firm iProov, cited consistently across 2026 security research, found that human participants correctly identified high quality video deepfakes only 24.5% of the time, meaning untrained observers performed considerably worse than a coin flip when asked to distinguish real video from convincingly generated fakes, a finding that echoes, in a different medium, the chance level human detection result this series documented in its earlier coverage of AI generated fake reviews.

Purpose built detection technology performs considerably better, though the gap between laboratory performance and real world performance deserves close attention, since it is exactly the kind of gap that creates dangerous overconfidence in organizations that have not tested their tools under realistic conditions. Intel’s FakeCatcher system, one of the more widely cited detection tools in this space, achieves accuracy around ninety six percent under controlled laboratory conditions, but that figure drops to somewhere between forty five and fifty percent once deployed in genuine production environments, according to industry analysis, meaning roughly half of real world deepfakes still slip past even a well regarded, purpose built detection system operating outside a controlled test setting. The detection technology market itself is growing rapidly in direct response, with industry analysts projecting the space to reach 15.7 billion dollars by 2026 at a compound annual growth rate near forty two percent, though the same analysts are candid that this represents a reactive investment chasing a threat that evolves faster than detection can keep pace with, since every new generation of generative model tends to render the previous generation’s purpose built detectors at least partially obsolete.
That treadmill dynamic is worth stating plainly, because it directly shapes the defensive recommendations covered later in this piece. Detection technology continues to lag meaningfully behind generation technology, and every credible security researcher covering this space in 2026 agrees that organizations betting primarily on technical detection to catch pace with generation are, in the words of one security firm’s own analysis, betting against the trend line. This does not mean detection tools are worthless. It means they function best as one layer inside a broader defense, never as the sole or primary safeguard a business or individual relies on.
The commercial detection market itself has grown considerably beyond Intel’s FakeCatcher, and it is worth naming a few of the other major players to give a fuller sense of how this space is actually structured. Reality Defender, a security firm focused specifically on enterprise deepfake detection, has built partnerships with major financial institutions and government agencies to screen high stakes communications in real time. Pindrop, whose own 2025 Voice Intelligence report is cited elsewhere in this piece, has built its detection capability specifically around contact center and call authentication, reporting that voice phishing attempts against the call centers it monitors rose roughly 170% year over year alongside 12.5 billion dollars in associated contact center fraud losses across 2024. Sensity AI and Deepware round out a further tier of specialized detection vendors focused respectively on media authenticity verification and consumer facing deepfake scanning tools. None of these vendors, individually or collectively, claim to have closed the production accuracy gap this piece has documented in detail, and the more credible among them are explicit in their own marketing that their tools function as one input into a broader human and process driven verification workflow, not a standalone, fully automated solution.
The FBI itself, in publishing its 2025 Internet Crime Report, included a set of practical detection cues worth citing directly, precisely because they come from the same audited source that anchored this piece’s opening discussion of financial scale, rather than from a vendor with a product to sell. IC3’s own published guidance highlights lip sync mismatches and physical cues that fail to align naturally with video, such as a cough or a sudden movement that does not match what the audio track suggests should be happening, subtle artifacts that remain, for now, genuinely difficult for even sophisticated generation tools to fully eliminate, though, consistent with the treadmill dynamic described above, there is no guarantee these specific cues will remain reliable for long.
The law finally catches up: the TAKE IT DOWN Act
For years, the honest legal answer to what happens when someone creates and distributes a damaging deepfake of a real person was, in most of the United States, genuinely unclear. That changed decisively in 2025, and the shift arrived first, and most forcefully, in the specific category of harm that lawmakers found politically easiest to act on quickly.
The TAKE IT DOWN Act, signed into federal law on May 19, 2025, became the first federal statute directly targeting nonconsensual intimate deepfakes, making it a federal crime to knowingly publish nonconsensual intimate visual depictions of adults or minors, explicitly including AI generated digital forgeries rather than only genuine, unaltered photographs or videos. The law carries real criminal weight, with penalties reaching up to two years in prison for depictions of adults and up to three years where the victim is a minor. Critically, the Act also imposes a direct operational obligation on online platforms rather than only targeting individual perpetrators, requiring platforms to remove flagged nonconsensual content within forty eight hours of a victim’s notice, a deadline enforced directly by the Federal Trade Commission, with the platform compliance deadline itself landing on May 19, 2026, just weeks before this piece was researched. Legal analysis of the Act is explicit that Section 230, the long standing federal law generally shielding online platforms from liability for content posted by their users, does not immunize platforms from this specific removal obligation, nor does it protect the individual creators of deepfake content from state level criminal prosecution.
Two further federal bills, both still moving through Congress as of mid 2026 rather than settled law, round out the current federal picture and are worth understanding precisely because their unsettled status itself signals where the legal fight is likely headed next. The DEFIANCE Act, formally S.1837, would create a federal civil cause of action specifically for victims of nonconsensual intimate deepfakes, allowing them to sue creators and distributors directly in federal court for liquidated damages of up to 150,000 dollars per violation, rising to 250,000 dollars where the underlying conduct involved actual or attempted sexual assault, stalking, or harassment. The bill passed the United States Senate by unanimous consent on January 13, 2026, a genuinely notable show of bipartisan agreement, but remained pending in the House of Representatives as of this writing. The NO FAKES Act, formally S.1367, takes a considerably broader approach, proposing to establish a comprehensive federal right of publicity covering any person’s AI generated voice and visual likeness, living or deceased, a framework that would, if enacted, apply directly to the corporate voice cloning and video impersonation fraud covered throughout the earlier sections of this piece, not only to intimate imagery. As of mid 2026, the NO FAKES Act remained in committee, meaning, as multiple legal analyses reviewed for this piece are careful to note, it should not be relied upon as current, enforceable law by any organization assessing its own legal exposure today.
The state patchwork: from the ELVIS Act to a tracker with 170 active bills
While federal legislation has moved slowly and selectively, state legislatures have moved considerably faster and considerably more broadly, producing a genuinely complex patchwork any organization operating across multiple states now needs to navigate.
Tennessee holds the distinction of passing the first state law written specifically to address AI voice cloning as its own category of harm. The ELVIS Act, formally the Ensuring Likeness Voice and Image Security Act, took effect July 1, 2024, extending the state’s existing right of publicity framework to explicitly cover any readily identifiable simulation of a person’s voice, whether generated through AI or any other technology, and specifically targeting tools whose primary purpose is creating unauthorized voice replicas rather than only targeting the end use of a specific fake. The law’s name is itself a deliberate nod to Tennessee’s status as the home of the American music industry in Nashville and Memphis, reflecting the specific lobbying pressure from musicians and performers concerned about unauthorized AI voice replication of their own recorded work, a concern that maps directly onto the corporate and consumer fraud covered throughout the rest of this piece even though the law’s original political impetus centered on artistic and commercial voice rights rather than fraud prevention specifically. The law provides for civil damages alongside a Class A misdemeanor criminal charge, and, notably, extends postmortem protection for ten years after a person’s death, joining a small group of states, including California, New York, Indiana, Nevada, and Texas, that specifically extend right of publicity protections to deceased individuals, with protection periods ranging from ten years under Tennessee’s framework up to fifty years under Nevada’s and Texas’s respective statutes.
The broader state level picture has expanded rapidly enough that keeping track of it has become its own small industry. Legislative trackers covering this specific category counted 170 distinct AI related bills addressing deepfakes across 39 states as of mid 2026, a volume of legislative activity that would have been difficult to imagine even two years earlier.

Within that broader wave, roughly 28 states had enacted laws specifically targeting deepfakes in political communications as of early 2026, generally following one of two distinct regulatory approaches. Some states impose outright bans on deceptive synthetic media depicting political candidates, typically activated within a defined window before an election ranging from thirty to one hundred twenty days depending on the state. Others favor disclosure requirements instead, mandating that any political advertisement using AI generated content carry a conspicuous label identifying it as altered, an approach legal analysts note has become increasingly favored over outright bans specifically because disclosure requirements face meaningfully lower constitutional challenges than content bans do, a distinction that matters considerably for which approach is likely to survive judicial review over time.
State approaches to penalty structure vary considerably, and a few representative examples illustrate just how differently individual states have chosen to calibrate consequences for comparable underlying conduct. New Jersey’s framework criminalizes knowingly disclosing explicit synthetic media without consent, imposing a fine up to 1,000 dollars and up to one year in county jail for a first offense, escalating to a fine up to 10,000 dollars and up to five years in state prison for a second or subsequent offense, with penalties reaching up to ten years where the depicted individual is a minor. Pennsylvania takes a different structural approach entirely, generally treating deepfake fraud as a first degree misdemeanor but elevating the charge to a third degree felony specifically when the underlying conduct involves a scheme to defraud, coerce, or commit theft, directly capturing the corporate wire fraud pattern covered earlier in this piece within its most serious penalty tier, while separately building in an affirmative defense for content creators who took reasonable steps to clearly disclose that their content was not genuine.
The practical takeaway for any organization operating nationally, rather than in a single state, is that compliance today effectively means designing policy around the strictest applicable state standard, since no single federal framework yet exists to supersede or harmonize this rapidly expanding patchwork, a pattern this series has already documented playing out in its earlier coverage of AI disclosure requirements for influencer marketing and synthetic performer regulation.
What corporate insurance is starting to require
Beyond direct legal exposure, deepfake fraud has begun reshaping a considerably less visible but increasingly consequential corner of corporate risk management, the terms under which businesses can actually insure themselves against exactly this kind of loss.
Cyber insurance case studies covering the Arup incident have become a genuine teaching tool within the insurance industry itself, and the underlying coverage question is less straightforward than it might first appear. Insurance analysis of the Arup case specifically breaks down the layered nature of the financial exposure involved, noting that a loss like this typically spans direct cash loss to the organization, the lost operational use of those funds while frozen or unrecoverable, potential impact to financial reporting and shareholder confidence, the direct costs of investigation and remediation, and potential litigation or regulatory fines that may follow, a considerably broader financial footprint than the headline stolen amount alone suggests. Whether a standard cyber insurance policy actually covers a loss like this depends heavily on specific policy language, since, as Arup’s own CIO was careful to frame publicly, the incident involved no compromised systems and no breached data, technically sitting closer to social engineering fraud than to the kind of network intrusion many cyber policies were originally written to cover.
Insurers have responded by tightening underwriting requirements rather than simply raising premiums uniformly across the board. Regula’s own 2024 research, cited across multiple 2026 industry analyses, found that ninety two percent of businesses surveyed had already absorbed direct financial consequences from synthetic media fraud, a near universal exposure rate that has pushed insurers toward requiring documented, specific verification protocols, callback procedures, multi person authorization thresholds, and employee training programs, as a condition of coverage for social engineering and wire fraud losses, rather than treating deepfake resistant process controls as an optional best practice. Financial sector losses per affected company now average roughly 603,000 dollars, according to the same Regula research, with fintech firms specifically reporting the steepest average exposure at 637,000 dollars per incident, a gap researchers attribute directly to fintech’s heavier reliance on fully digital onboarding and real time payment infrastructure, where a convincing synthetic identity or voice can move money before any human reviewer ever meaningfully intervenes.
That sector level variation extends well beyond financial services specifically, and it is worth understanding for any organization trying to calibrate how seriously to weigh this risk relative to its industry peers. Healthcare organizations, handling both sensitive patient data and increasingly digital, remote verification processes for everything from telehealth appointments to prescription authorization, have reported a distinct exposure pattern centered on deepfake enabled impersonation of both patients and clinical staff, a risk regulators have begun addressing through updated telehealth identity verification guidance in several jurisdictions. Professional services firms, Arup’s own industry, face a particular structural vulnerability tied directly to how these organizations operate, frequently coordinating large, time sensitive financial transactions across genuinely globally distributed teams who may never have met most of their counterparts in person, precisely the environment in which a convincing but entirely fabricated video call colleague is least likely to trigger the kind of instinctive skepticism a small, tightly connected team might apply more readily. Retail and ecommerce businesses, by contrast, report their heaviest synthetic media exposure concentrated specifically in the customer facing fraud covered in this piece’s earlier discussion of synthetic identity fraud, account takeover attempts using AI generated identity verification footage, rather than the executive impersonation pattern dominating the corporate case studies covered earlier in this piece.
The defenses that actually work: process over detection
Every technical and legal thread in this piece converges on a single, consistent practical conclusion, one that security researchers across the sources reviewed for this piece state with unusual unanimity. Detection technology will keep lagging behind generation technology for the foreseeable future, which means the defenses that actually hold up are the ones that remain valid regardless of how convincing a fake becomes, rather than the ones that depend on successfully spotting the fake in the first place.
Callback verification through an independently retrieved phone number stands out as the single most consistently recommended defense across every source reviewed for this piece, and its underlying logic is worth stating plainly. If a request arrives through any channel, an email, a text message, a WhatsApp call, a video conference invitation, the recipient should end that specific interaction and independently initiate a new one, using a phone number pulled from an official company directory or a previously saved, trusted contact, never a number provided within the suspicious message itself. This single step defeats every category of attack covered in this piece simultaneously, because it removes the attacker’s ability to control the channel the verification happens through, regardless of how convincing their voice, video, or writing style has become.
Pre established code words, sometimes called safewords, extend the same underlying principle into situations where an immediate callback is impractical. A unique word or phrase, agreed upon in advance and known only to a small, trusted group, whether that is a family unit protecting against grandparent scams or an executive team protecting against wire fraud, provides a verification mechanism an attacker cannot have anticipated or scripted around, since no amount of publicly available audio or video footage would reveal a private agreement that was never discussed anywhere the attacker could have observed it. Multi person authorization for significant financial transactions adds a further structural layer specifically aimed at the kind of high value corporate fraud the Arup case exemplifies, requiring that no single employee, however senior or however convinced, can independently authorize a transfer above a defined threshold without at least one other person, ideally reached through a separate, independently verified channel, confirming the request’s legitimacy.
A further, more subtle recommendation deserves specific attention because it addresses the supply side of this entire problem rather than only the defensive response to an attack already underway. Security researchers increasingly recommend that executives and other likely high value targets actively audit and, where possible, request takedown of public audio and video content, webinar recordings, conference appearances, podcast interviews, and social media video, on the straightforward logic that every public recording represents potential raw material for a future voice or video clone. This recommendation comes with an honest caveat worth stating directly. Completely eliminating a public figure’s audio and video footprint is rarely realistic, and researchers generally frame this as reducing exposure rather than eliminating it, on the assumption that a sufficiently motivated attacker targeting a genuinely high value target should be assumed capable of finding enough source material regardless.
Building an organizational deepfake defense program
Translating the individual defenses above into a genuine, sustained organizational program requires more than a single policy memo, and the case studies throughout this piece suggest a handful of specific structural practices consistently separate organizations that catch an attempted fraud from those that do not.
Build the callback verification and code word protocols directly into written financial authorization policy, rather than leaving them as informal, commonly known but never formally required practices, since Ferrari’s own near miss succeeded specifically because a single executive independently chose to challenge an urgent request rather than because a formal, mandated policy required it. Formalizing the requirement removes the burden from any individual employee’s judgment in a high pressure, urgency driven moment, exactly the moment this piece has shown deepfake attacks are specifically engineered to exploit. Run realistic, scenario based training rather than purely informational awareness sessions, given that the research cited throughout this piece consistently shows detection based training alone provides limited protection once an attack has genuinely crossed the indistinguishable threshold described earlier, meaning the more durable training investment teaches employees to reflexively follow a verification process under pressure, not to trust their own ability to spot a fake by ear or by eye.
Treat multi person authorization thresholds as a genuine circuit breaker, not a bureaucratic formality, calibrated specifically to a level where a determined attacker cannot simply route around the requirement by targeting a single sufficiently senior employee empowered to bypass it alone. Given the insurance research cited above, review cyber and crime insurance policy language specifically for how it treats social engineering and deepfake enabled fraud, since Arup’s own framing of its incident as social engineering rather than a system breach illustrates exactly the kind of coverage gap a business can discover only after a loss has already occurred, when it is too late to negotiate better terms. And build a specific, rehearsed incident response plan for exactly this scenario, given how directly the Arup case shows that early detection, in that case triggered by one employee’s decision to independently follow up with headquarters, made the difference between a contained incident and funds that, as of this piece’s research, remain permanently unrecovered.
When the fraud wears a familiar face: celebrity and brand impersonation
Everything covered so far in this piece involves an attacker impersonating someone to deceive a specific, individual target. A parallel, commercially devastating category runs in a different direction entirely, using a real, recognizable public figure’s stolen likeness to defraud thousands of strangers simultaneously, and it sits close enough to this series’ core focus on advertising and marketing fraud that it deserves dedicated treatment.
Financial scam advertisements built around fabricated celebrity endorsements have become a genuinely widespread phenomenon across social media platforms, using AI generated video and voice to show a recognizable public figure, frequently a business leader, television personality, or financial commentator, apparently endorsing a cryptocurrency platform, an investment scheme, or a trading application they have no actual connection to whatsoever. The format has become common enough that consumer protection researchers now treat it as a distinct, named category of fraud rather than an occasional novelty, and the underlying mechanics mirror exactly the voice and video cloning technology described earlier in this piece, simply redirected from targeting a single victim toward advertising fraud aimed at mass audiences through paid social media placement. A viewer scrolling past a video ad featuring a recognizable face and a familiar voice, endorsing a financial product in a tone and cadence that matches years of genuine public appearances, has essentially no reliable way to distinguish the fabrication from the real thing using casual observation alone, a direct extension of the same detection gap this piece’s earlier sections have already documented in exhaustive technical and academic detail.
The financial scale of this specific pattern, while harder to isolate cleanly from the broader investment fraud totals covered in this piece’s opening section, shows up repeatedly inside the FBI’s own 632 million dollar investment fraud figure, since a meaningful share of the cryptocurrency and trading scheme victims counted in that total report having been drawn in specifically by a celebrity endorsed advertisement they had no reason to doubt. Consumer complaints tracked by the FTC increasingly cite specific, recognizable public figures by name, business commentators, technology executives, and television personalities whose likeness has been repeatedly and independently fabricated across dozens of unrelated scam campaigns, suggesting certain faces have become specifically, repeatedly targeted precisely because their genuine public reputation for financial credibility makes the resulting fabricated endorsement considerably more persuasive than a randomly chosen face would be.
The legal remedy available to a public figure whose likeness has been stolen this way runs directly through the right of publicity frameworks covered in this piece’s regulatory sections, and this is precisely the connection that makes the NO FAKES Act’s currently stalled status in Congress so consequential for this specific fraud category. Absent a comprehensive federal right of publicity, a celebrity or executive whose likeness has been used in a fraudulent advertisement must currently pursue remedies through a patchwork of inconsistent state laws, platform reporting mechanisms with famously inconsistent enforcement, and, in the most severe cases, direct litigation against the advertisement’s actual publisher, a considerably higher barrier than the streamlined federal cause of action the NO FAKES Act would create if eventually enacted. Several public figures have already spoken out publicly about discovering fraudulent AI generated advertisements using their likeness without consent, describing the experience as simultaneously a personal violation and a genuine threat to their public reputation, since viewers who lose money to a scheme fraudulently endorsed by a recognizable face frequently, understandably, associate at least some of their anger and distrust with the real person whose stolen likeness lent the scam its credibility, regardless of that person’s total lack of actual involvement.
For advertising platforms themselves, this category creates a genuinely difficult content moderation problem that sits directly adjacent to everything this series has already documented about the broader challenge of policing automated, AI generated content at scale. A platform capable of running the kind of purpose built detection described earlier in this piece, achieving meaningful accuracy only under carefully controlled conditions, faces the same real world performance gap when trying to screen paid advertising submissions at the volume major platforms process daily, a problem structurally similar to the invalid traffic detection challenges this series documented in its earlier coverage of programmatic advertising fraud, simply applied to the authenticity of an advertisement’s own content rather than the authenticity of the traffic viewing it.
The deepfake as a service economy
Understanding why this technology has spread so far, so fast, requires understanding that a genuine commercial marketplace has grown up specifically to supply it, lowering the barrier to entry for fraud far below what individual technical sophistication alone would suggest.
Security researchers tracking underground marketplaces describe a maturing ecosystem offering deepfake generation as a purchasable service, in some cases requiring no more technical skill from a buyer than placing an order and providing sample source material, with pricing structures that make this category of fraud accessible to operators with genuinely minimal upfront capital. This mirrors, in a genuinely striking way, a pattern this series has already documented in an entirely different corner of digital fraud. Earlier pieces in this series covered how the content syndication and lead generation fraud economy runs through openly operating brokers and resale networks, and how mobile app install fraud has increasingly shifted toward rented, real hardware infrastructure specifically built to defeat detection. The deepfake fraud economy has developed a parallel commercial layer of its own, transforming what once required genuine machine learning expertise into a purchasable commodity service, complete with customer support, quality guarantees, and, according to some security researchers’ own undercover investigations, tiered pricing based on how convincing and how customized the final output needs to be.
The specific service tiers this ecosystem has developed mirror, in structure if not in content, an entirely ordinary software as a service business. Entry level offerings provide pre trained, generic voice or face swap tools requiring the buyer to supply their own source material and technical setup, priced accordingly low. Mid tier offerings include custom model training on client supplied source footage, effectively producing a bespoke, ready to use clone of a specific target, priced considerably higher and typically requiring some verification of the buyer’s stated intent, verification security researchers note is trivially easy to falsify. The highest tier, reserved for the most sophisticated operations and priced well beyond casual reach, includes live, real time deployment support, effectively renting out the operator’s own technical infrastructure and expertise to run an attack like Arup’s in real time on the buyer’s behalf, collapsing the technical barrier to entry for even the most demanding category of attack down to little more than the willingness to pay for it.
This commercialization matters enormously for how any organization should calibrate its own threat model. The relevant question is no longer whether a potential attacker personally possesses the technical skill to build a convincing deepfake. It is simply whether that attacker possesses the financial incentive and a small amount of capital to purchase the capability from someone else who already has. That shift, from skill dependent to purely capital dependent, is precisely what security researchers point to when explaining why deepfake fraud volume has grown so much faster than the underlying pool of genuinely skilled AI practitioners could plausibly account for on its own.
A distinct and strange new category: the deepfake job candidate
One further, genuinely novel fraud pattern deserves its own dedicated treatment, both because it inverts the usual victim relationship this piece has described throughout, and because the FBI’s own audited data, covered at the start of this piece, specifically breaks it out as a named category worth thirteen million dollars in confirmed 2025 losses.
Deepfake enabled employment interview fraud works by having a fraudulent job applicant use real time video filtering technology, the same underlying real time deepfake capability that powered the Arup attack, to interview for a legitimate remote position under a fabricated identity, frequently while a different, unseen person actually answers the technical or behavioral interview questions from off camera. The motivation is rarely the job itself in any conventional sense. Security researchers investigating this pattern have found it disproportionately associated with attempts to gain legitimate seeming network access to a target company’s internal systems, sometimes tied to state sponsored actors seeking to place operatives inside sensitive technology companies under cover of ordinary employment, and sometimes tied to more conventional financial fraud, where a successfully placed fake employee gains access to payroll systems, customer data, or internal financial approval workflows that can later be exploited directly.
The remote hiring boom that followed the shift toward distributed work has created precisely the operating conditions this specific fraud pattern depends on. A hiring manager conducting a first round interview with a candidate located in a different country, communicating exclusively through video conferencing software, has genuinely limited ability to apply the kind of in person social cues, a firm handshake, direct eye contact unmediated by a screen, the general physical presence of another human being in a shared room, that made this specific fraud pattern considerably harder to sustain in a pre remote work hiring environment. Technology companies specifically, given both their outsized reliance on fully remote technical hiring and the elevated value of the network access a successfully placed fraudulent employee could obtain, have reported disproportionate exposure to this pattern relative to industries with more hybrid or in person hiring norms.
The defense against this specific variant differs meaningfully from the corporate wire fraud defenses covered earlier in this piece, precisely because the fraud unfolds over a hiring process measured in days or weeks rather than a single urgent phone call. Security guidance addressing this pattern specifically recommends requiring at least one interview stage to occur in person or through a verification method resistant to real time video filtering, cross referencing a candidate’s stated work history and credentials independently rather than relying solely on documents the candidate themselves provides, and treating any candidate who consistently avoids camera activation, cites unstable internet connectivity as a recurring excuse, or shows subtle audio and video synchronization inconsistencies during required video calls as worth additional scrutiny before an offer is extended. Given how directly this pattern intersects with the network access risks security teams already spend considerable resources defending against, several organizations have begun formally incorporating deepfake specific screening into their standard technical hiring pipeline, treating it as a genuine extension of existing background check processes rather than a separate, novel concern requiring entirely new infrastructure.
The international picture: how other jurisdictions are responding
The United States is not moving alone on this front, and any organization operating internationally needs to understand that the regulatory pressure described throughout this piece’s earlier sections is part of a broader, only loosely coordinated global response rather than an isolated American development.
The European Union’s AI Act, referenced in this series’ earlier coverage of AI disclosure requirements for chatbots and influencer marketing, contains provisions directly applicable to deepfake fraud as well, requiring that AI generated or manipulated content that appreciably resembles existing persons, objects, places, or events be clearly labeled as artificially generated or manipulated, with the relevant transparency obligations building on the same Article 50 framework this series has covered in detail in its earlier reporting on chatbot disclosure requirements. China has moved through its own distinct regulatory path, requiring that AI generated content, including synthetic voice and video, carry both visible and embedded metadata labeling, a technically stricter approach than most Western frameworks currently require, reflecting the Chinese government’s broader, more comprehensive approach to platform content governance. The United Kingdom has addressed deepfake fraud primarily through amendments to its existing Online Safety Act framework alongside targeted criminal law provisions specifically covering nonconsensual intimate deepfakes, running roughly parallel to, though not identical in scope or timing to, the United States’ own TAKE IT DOWN Act.
Singapore and South Korea, both significant financial and technology hubs in their own right, offer a further useful point of comparison, since each has moved toward mandatory disclosure requirements specifically for AI generated content used in political and financial contexts, with South Korea in particular imposing criminal penalties for deepfakes distributed during officially designated election periods, reflecting a regional regulatory pattern that has generally moved faster and with greater specificity on election related synthetic media than most Western jurisdictions have managed, even as broader commercial fraud provisions remain comparatively less developed than the United States’ own, now considerably more mature, state level patchwork.
The practical effect for any business operating across multiple of these jurisdictions simultaneously mirrors a pattern this series has now documented repeatedly across influencer marketing, B2B lead generation, and fake review regulation alike. A single piece of AI generated content, whether that is an advertisement, a corporate communication, or a customer facing interaction, can realistically need to satisfy the EU AI Act’s labeling requirements, relevant US state and federal law, and any locally applicable regulation simultaneously, a compliance burden that shows every sign of continuing to grow more complex rather than converging toward a single global standard anytime in the near future.
Small businesses face this threat with the fewest resources to fight it
Nearly every case study covered in this piece so far involves a large, well resourced organization, Arup, Ferrari, a multinational energy conglomerate. That emphasis reflects which incidents make headlines, not which organizations actually carry the greatest relative risk, and it is worth correcting directly before this piece turns to its practical recommendations.
Small and medium sized businesses face a version of this threat that is, in several important respects, considerably more dangerous than what a large enterprise experiences, even though the individual dollar amounts involved are typically far smaller. A small business owner, unlike a large corporation’s finance department, frequently has no dedicated security team, no formal multi person authorization policy, and no established callback verification protocol at all, relying instead entirely on personal relationships and informal trust built up over years with a small number of known vendors, clients, and banking contacts, precisely the kind of trust a convincing voice or video clone is specifically engineered to exploit. Where Arup’s twenty five million dollar loss, however catastrophic in absolute terms, represented a survivable, if painful, hit against a large, financially stable organization, a comparable proportional loss for a small business, even one measured in tens of thousands of dollars rather than millions, can represent an existential threat capable of ending the business entirely.
The specific attack patterns small businesses report differ somewhat from the large enterprise case studies covered earlier in this piece as well. Rather than a fabricated multinational executive team on an elaborate video call, small business owners more commonly report voice cloned calls impersonating a known, trusted supplier or long standing client, requesting an urgent change to payment or delivery details, a pattern that exploits exactly the kind of close, personal vendor relationships small businesses tend to rely on more heavily than large enterprises with more formalized, arm’s length procurement processes. The three second voice cloning benchmark covered earlier in this piece applies with particular force here, since a small business owner has likely spoken with a genuine trusted vendor contact many times over the phone, providing more than sufficient source audio for a convincing clone without the vendor’s own organization ever needing to be directly compromised at all.
The practical recommendation for small businesses, given genuinely limited security budgets relative to the large enterprises this piece has focused on throughout, is to prioritize the single highest leverage, lowest cost defense covered in this entire piece above all others. Callback verification through an independently saved phone number costs nothing to implement and requires no specialized technology, making it, for a small business with limited resources, considerably more valuable per dollar invested than any detection software or insurance product this piece has covered, a genuinely accessible first step available to any organization regardless of size or budget.
The psychology underneath every case study in this piece
Stepping back from the individual technical and legal detail covered throughout this piece, a single psychological mechanism recurs across every single case study, from Arup to Ferrari to the grandparent scam pattern to pig butchering, and naming it explicitly helps explain why familiarity with the technology alone does not reliably protect anyone against it.
Every successful attack covered in this piece combines a convincing synthetic identity with manufactured urgency, deliberately compressing the target’s available decision making time to prevent exactly the kind of independent verification this piece has recommended throughout. The Arup employee was told the matter was confidential and time sensitive. The grandparent scam target is told a grandchild is in immediate legal jeopardy. The romance scam victim is guided toward an investment opportunity framed as available only for a limited window. This is not a coincidental stylistic similarity across otherwise unrelated fraud categories. It is a deliberate, well understood exploitation of a genuine, well documented feature of human cognition, the fact that decision quality under manufactured time pressure reliably degrades, and that urgency itself short circuits the kind of careful, deliberate verification a target would otherwise be capable of applying given more time.
Security researchers and behavioral psychologists studying this pattern describe it using a framework borrowed from classic confidence fraud research, predating AI entirely, but newly supercharged by synthetic media’s ability to make the fabricated identity half of the equation dramatically more convincing than it has ever been before. The technology covered throughout this piece did not invent manufactured urgency as a fraud tactic. It removed the single remaining check that used to reliably counteract it, the target’s own ability to recognize, by sight or by sound, that something about the person applying that pressure was not who they claimed to be. Understanding this helps explain why the process based defenses recommended throughout this piece, callback verification, code words, mandatory pauses before high value transactions, work as well as they do. Each of them functions, at its core, as a deliberately engineered interruption to exactly the urgency this psychological pattern depends on, restoring the decision making time and independent verification opportunity the attack was specifically designed to remove, regardless of how convincing the underlying synthetic voice or video ultimately is.
What 2027 looks like for synthetic media fraud
A handful of forward looking signals from the research in this piece point toward specific, foreseeable shifts worth carrying directly into next year’s planning, rather than a vague continuation of the trends already described.
The financial trajectory, even accounting for this piece’s own methodological caution about unaudited headline figures, points firmly in one direction. Deloitte’s own projection, the single most consistently corroborated forward looking figure in this entire research base, places generative AI enabled fraud losses on a path from 12.3 billion dollars in 2023 toward roughly 40 billion dollars by 2027.

That chart deserves one final methodological note in the same spirit as the opening section of this piece, since presenting these two figures side by side without explanation would risk exactly the kind of statistical sleight of hand this piece has spent considerable effort pushing back against. The FBI’s 893.3 million dollar figure and Deloitte’s 40 billion dollar projection are not directly comparable measurements of the same thing. IC3 captures a narrower, specifically reported and specifically AI attributed subset of consumer complaint driven fraud. Deloitte’s figure projects the full, considerably broader universe of generative AI enabled fraud across consumer and enterprise contexts alike, including categories far less likely to generate an individual IC3 complaint at all, corporate wire fraud resolved quietly through internal channels, synthetic identity fraud embedded inside broader financial crime statistics, and the vast unreported share of romance and pig butchering losses covered earlier in this piece. Read correctly, the chart shows one solid, audited floor and one credible, independently corroborated ceiling projection, with the true current figure almost certainly sitting somewhere in between, closer to the ceiling than the floor given how consistently underreporting has been documented throughout this piece.
Beyond the raw financial trajectory, a handful of more specific, structural shifts are worth watching closely through the remainder of 2026 and into 2027. The gap between detection technology’s laboratory performance and its real world performance, covered in detail earlier in this piece, shows no sign of closing on its own, and the same underlying dynamic driving that gap, generation technology improving faster than detection technology, is structurally unlikely to reverse without some meaningful shift in how much investment flows toward defensive research relative to the continued, largely separate commercial investment flowing into generative AI capability broadly. The regulatory patchwork described throughout this piece’s legal sections is very likely to keep expanding rather than consolidating, with the DEFIANCE Act’s unanimous Senate passage suggesting real momentum toward federal civil remedies even as the broader NO FAKES Act framework remains stalled, and state legislatures showing no sign of slowing their own independent activity given the 170 bills already tracked as of mid 2026. And the specific technical limitation that exposed the Arup attack, synthetic participants unable to convincingly interact with each other in real time, should be treated as a temporary artifact of 2024’s technology rather than a durable defense, consistent with this piece’s repeated finding that every previously reliable verification heuristic in this space has had a limited shelf life.
When the target is your own family: grandparent scams reinvented
Beyond the corporate and romantic contexts covered so far, one further category of voice cloning fraud deserves dedicated treatment specifically because it targets the single relationship most people would consider least likely to ever be exploited this way, and because its emotional mechanics differ meaningfully from every other fraud pattern covered in this piece.
The so called grandparent scam predates AI voice cloning by decades, traditionally relying on a caller simply claiming to be a panicked grandchild in some kind of trouble, counting on an older relative’s protective instinct and the genuine difficulty of confidently recognizing a voice over a poor quality phone connection. AI voice cloning has transformed this long standing con from a crude, easily doubted impersonation into something considerably harder to dismiss, since the three second, eighty five percent accuracy benchmark covered earlier in this piece applies with equal force here, meaning a scammer who has harvested even a brief public video, a social media clip, or a voicemail greeting from a target’s actual grandchild can produce a voice clone convincing enough to survive a genuinely panicked, emotionally overwhelmed phone call.
Consumer protection agencies have documented the financial toll of this specific pattern with genuine precision, and the individual loss figures involved are frequently far larger than the median romance scam loss cited elsewhere in this piece, since a single grandparent scam call often demands the target’s entire available savings in one urgent, one time transaction rather than the gradual, extended extraction pattern characteristic of pig butchering schemes. Law enforcement agencies across multiple states have documented individual losses ranging from a few thousand dollars up to entire retirement accounts liquidated within hours, with courier based cash pickup schemes, where a local accomplice physically collects cash from the victim’s home rather than relying on a traceable wire transfer, becoming an increasingly common variant specifically because it defeats the bank level fraud detection that has grown more sophisticated around traditional wire transfers and cryptocurrency payments alike.
The specific emotional architecture of this scam is worth understanding on its own terms, since it explains why even people who intellectually understand that voice cloning exists remain vulnerable when the moment actually arrives. The call typically opens with genuine sounding distress, a claim of a car accident, an arrest, or a medical emergency, deliberately engineered to trigger an immediate protective response before the target has any real opportunity to pause and apply careful judgment. A second voice frequently joins the call shortly afterward, posing as a police officer, a lawyer, or a bail bondsman, adding a layer of apparent official authority specifically designed to discourage the target from hanging up to independently verify the story, and demanding payment through channels deliberately chosen to be difficult to trace or reverse, wire transfers, cryptocurrency, or physical cash picked up by a courier, rather than any payment method that would allow a bank or law enforcement agency to intervene before the money is gone.
The defense recommended by researchers and law enforcement agencies covering this specific pattern mirrors, almost exactly, the corporate callback verification principle covered earlier in this piece, simply adapted to a family context. Hang up and independently call the family member directly, using a number saved from before the suspicious call rather than any number provided during it, and treat any request for urgency or secrecy, an insistence that other family members not be told, or that the matter be resolved before anyone else can weigh in, as a red flag in its own right, since genuine emergencies rarely come with an explicit demand that you tell no one else. Family level code words, the same defensive concept covered earlier in this piece’s discussion of corporate defenses, have been specifically and repeatedly recommended by consumer protection agencies as a low cost, high value defense against exactly this scenario, a single agreed upon word or phrase that a genuine family member would know and a cloned voice, however convincing, cannot have any way of producing without it having been deliberately shared with the attacker in advance.
Media authenticity and the wider trust problem
Everything covered so far in this piece involves a deepfake being used as an active instrument of fraud, deceiving a specific target into taking a specific harmful action. A related, more diffuse harm deserves brief treatment here as well, because it shapes how the entire fraud landscape covered throughout this piece is likely to evolve over the next several years.
As synthetic audio and video have become genuinely difficult to distinguish from authentic recordings, a second, less obvious problem has emerged alongside the direct fraud risk, one researchers describe as the liar’s dividend. Once a population broadly understands that convincing fake audio and video exist, genuine, authentic recordings become newly deniable, since anyone caught on tape or on camera doing or saying something damaging now has a plausible alternative explanation available that did not meaningfully exist a few years earlier. This dynamic has direct, practical relevance for any organization thinking about deepfake fraud purely as an inbound threat, since it also creates an outbound risk, the possibility that genuine evidence of a real organizational failure, a real executive’s real damaging statement, or a real customer complaint, gets dismissed by a skeptical public as a possible fabrication, complicating both legitimate crisis communication and legitimate legal proceedings in ways that extend well beyond the direct financial fraud this piece has focused on throughout.
Legal scholars covering this dynamic have begun documenting real cases in which defendants in unrelated criminal and civil proceedings have attempted to challenge the authenticity of genuine, unaltered video and audio evidence purely on the general grounds that deepfake technology now exists, forcing courts to develop new evidentiary standards and, in some jurisdictions, new expert witness qualification requirements specifically for authenticating digital media before it can be admitted. This represents a genuinely novel legal burden that did not meaningfully exist a decade ago, and it compounds directly with everything this piece has already covered about detection technology’s real world limitations, since the same production accuracy gap that makes it hard to catch a fake in real time also makes it hard to definitively prove authenticity after the fact, even when the underlying recording is entirely genuine.
Journalism and legal evidence verification have both had to adapt meaningfully to this new reality, with news organizations increasingly building dedicated authentication workflows for any sensitive audio or video submission before publication, and courts beginning to grapple directly with how existing rules of evidence should handle authentication challenges for digital recordings in an environment where the underlying technology to convincingly fabricate such evidence is now, per the accessibility findings covered earlier in this piece, within reach of essentially anyone with an ordinary laptop and an internet connection.
Expanding the detection toolkit: what technical verification actually looks like in practice
Earlier sections of this piece established that detection technology lags meaningfully behind generation technology, and that laboratory accuracy figures do not reliably translate into real world performance. That finding should not be read as an argument against technical detection entirely, and it is worth walking through, in slightly more practical detail, what a genuinely layered technical verification approach actually involves for an organization serious about building real defensive capability.
Digital watermarking and content provenance standards represent one of the more promising structural approaches currently being developed, distinct from after the fact detection because they aim to embed verifiable authenticity information directly into genuine content at the moment of creation, rather than trying to retroactively distinguish real from fake after a piece of media already exists in the wild. The Coalition for Content Provenance and Authenticity, a cross industry standards body whose members include major technology and media companies, has developed specifications for exactly this kind of embedded provenance metadata, allowing a video or image to carry a verifiable, tamper evident record of its own editing history. The practical limitation, acknowledged by researchers working in this space, is adoption. A provenance standard only provides meaningful protection once it achieves genuinely broad adoption across camera manufacturers, editing software, and distribution platforms simultaneously, and as of 2026, that level of universal adoption remains a work in progress rather than an achieved reality, meaning the absence of a provenance marker on a given piece of content currently proves very little, since most legitimate content in circulation was never created with a provenance aware tool in the first place.
Liveness detection, a technique borrowed from biometric security systems originally designed to prevent someone from fooling a facial recognition system with a photograph, has been adapted specifically to counter real time video deepfakes, prompting a call participant to perform a specific, unpredictable physical action, turning their head at a particular moment, touching a specific part of their face, or reacting to a randomly generated instruction, on the logic that a live, real time deepfake rendering pipeline may introduce detectable latency or visual artifacts when asked to respond to genuinely unscripted, unpredictable prompts in real time, a defense that directly exploits the same kind of technical limitation this piece’s earlier discussion of the Arup case identified in that specific attack’s inability to sustain convincing spontaneous interaction between multiple synthetic participants.
Blockchain based timestamping offers a narrower but genuinely useful verification tool for specific high stakes scenarios, allowing an organization to cryptographically timestamp and hash a piece of genuine content at the moment of its creation, creating an immutable, independently verifiable record that can later prove a specific piece of authentic content existed in a specific form at a specific time, useful less for detecting fakes directly and more for establishing an unambiguous, tamper proof baseline of what a genuine communication actually said, a capability with obvious relevance for the kind of executive communications and financial authorizations that made the Arup attack possible in the first place.
None of these three approaches, individually or combined, closes the detection gap this piece has documented throughout entirely. Each represents a genuinely useful additional layer, most valuable specifically when combined with the process based defenses covered earlier in this piece, callback verification, code words, and multi person authorization, rather than treated as a replacement for them.
The fraud with no real victim: synthetic identity fraud
Every case study covered so far in this piece involves a real person’s actual identity being stolen and impersonated. A distinct, financially enormous category works differently, constructing an entirely fictional person from scratch, and it deserves its own dedicated treatment precisely because its mechanics, its victims, and its defenses all differ meaningfully from the impersonation fraud covered throughout the rest of this piece.
Synthetic identity fraud combines real, often stolen fragments of genuine personal data, most commonly a real Social Security number, frequently belonging to a child or a deceased individual whose number is unlikely to be actively monitored, with entirely fabricated biographical details, a fictional name, a fictional date of birth, a fictional address history, to construct a complete, internally consistent identity that has never belonged to any actual living person. Financial industry researchers consistently describe this as the fastest growing category of financial fraud in the United States, distinct from traditional identity theft precisely because there is no single, identifiable living victim whose credit gets directly damaged the way a genuine identity theft victim’s would be, which has historically made synthetic identity fraud considerably harder for financial institutions to detect and considerably slower for law enforcement to prioritize, since no individual consumer shows up demanding a fraud investigation the way a traditional identity theft victim reliably does.
AI generated faces and voices have supercharged this category considerably beyond what was possible even a few years earlier. Where synthetic identity fraud once required a fraud operation to either use a stolen photograph, itself potentially traceable back to a real, identifiable person through reverse image search, or skip visual verification entirely, generative AI now allows fraud operations to produce entirely original, non existing faces for use in identity documents, account applications, and video verification calls, faces that fail reverse image search precisely because they were never real photographs of anyone at all. Combined with the AI generated identity document fabrication techniques covered earlier in this piece’s discussion of cryptocurrency exchange fraud, and the live, real time deepfake video capability covered in the technical sections on voice and video cloning, a sufficiently resourced fraud operation can now construct a synthetic identity capable of passing a bank’s video based know your customer verification process, opening real accounts, building a real credit history over months or years of patient, deliberately unremarkable activity, and eventually executing what the industry calls a bust out, maxing out every available credit line simultaneously before disappearing entirely, leaving financial institutions holding losses tied to a borrower who, in the fullest sense, never existed in the first place.
The financial services industry’s own response to this threat illustrates a genuinely different institutional posture than the process based defenses this piece has recommended for the impersonation fraud covered elsewhere throughout the article. Rather than relying primarily on human judgment and verification habits, banks and lenders have invested heavily in automated identity resolution systems that cross reference application data against a considerably broader set of third party databases than a single institution’s own records could ever provide alone, credit bureau history, utility records, device fingerprinting, and behavioral biometrics tracking how an applicant actually types and navigates a form, layered together specifically because synthetic identities, however convincing any single data point might appear in isolation, tend to reveal themselves through the absence of the kind of messy, inconsistent, genuinely lived history a real person’s data trail naturally accumulates over years.
The defense against synthetic identity fraud differs meaningfully from the process based defenses recommended throughout the rest of this piece, precisely because there is no real target individual to warn, no family member to establish a code word with, and no executive whose voice needs protecting. Financial institutions have instead had to build detection around behavioral and data consistency signals specific to this fraud type, watching for identity applications where the underlying data elements, while individually plausible, do not cohere the way a genuine person’s history naturally would, a Social Security number issued in a decade inconsistent with the applicant’s claimed birth year, an address history with no genuine utility or public records trail behind it, or a credit history that begins abruptly with no earlier gaps or thin file period a genuine young adult’s credit history would typically show. This detection approach mirrors, in a genuinely direct way, the metadata and behavioral pattern analysis this series’ earlier coverage of fake review detection described in detail, applied here to financial identity rather than product feedback, a reminder that the underlying detection philosophy this series has recommended throughout, layering multiple independent, hard to simultaneously fake signals rather than trusting any single check, holds up consistently across genuinely different fraud categories.
A practical checklist for your organization
Confirm your organization has a formally written, mandatory callback verification policy for any financial request arriving through email, text, voice call, or video conference, requiring an independently retrieved phone number rather than any contact information provided within the request itself. Establish pre agreed code words for high risk categories of communication, both at the organizational level for executive impersonation risk and, where relevant, at the family level for elder targeted voice cloning risk. Set multi person authorization thresholds for financial transactions at a level genuinely resistant to a single senior employee being individually targeted and convinced. Review your cyber and crime insurance policies specifically for how they define and cover social engineering and deepfake enabled fraud, rather than assuming standard cyber coverage automatically applies. Run scenario based training that rehearses the verification process under simulated pressure, rather than relying on informational sessions alone. Audit your organization’s own public facing audio and video footprint, particularly for executives and other likely high value targets, and consider what content can reasonably be restricted without meaningfully harming legitimate business needs. Build a specific, rehearsed incident response plan for suspected deepfake fraud, including clear escalation paths that do not depend on the single employee who first receives a fraudulent request recognizing it as such on their own. If your organization runs remote hiring at any scale, add deepfake specific screening steps to your interview process, including at least one verification stage resistant to real time video filtering. And if your business advertises through third party platforms, review how those platforms police fraudulent use of real people’s likeness in paid placements, since your own brand’s advertising environment carries real reputational exposure from exactly this category of fraud even when your organization is not the direct target.
Questions organizations ask most often
A handful of specific questions come up often enough in conversations about this threat that they deserve direct, sourced answers.
Is my organization actually at risk, or is this mainly a threat to large multinational companies like Arup. Every piece of research reviewed for this piece suggests risk is broadening rather than narrowing. Regula’s finding that ninety two percent of surveyed businesses had already experienced some direct financial consequence from synthetic media fraud suggests this is no longer a threat reserved for the largest, most visible organizations, and the underlying technology’s collapsing cost and technical barrier to entry means smaller organizations are increasingly viable targets, not protected by relative obscurity the way they might once have been.
Can detection software alone solve this problem if we simply invest in a good enough tool. Based on the research throughout this piece, no. The gap between Intel FakeCatcher’s ninety six percent laboratory accuracy and its forty five to fifty percent real world production accuracy is the clearest available evidence that detection technology, however sophisticated, should function as one layer within a broader defense rather than a standalone solution.
What is the single highest leverage first step if we have done nothing to prepare for this threat so far. Implement mandatory callback verification for financial requests. Every case study in this piece, from Ferrari’s successful defense to Arup’s catastrophic loss, traces back to whether or not an independent, out of channel verification step actually happened, and this specific control costs nothing to implement, requires no new technology, and directly defeats every category of attack covered throughout this piece simultaneously.
Are deepfakes illegal everywhere in the United States now. No, and this is a genuinely important distinction given how quickly the legal landscape has moved. Federal law, through the TAKE IT DOWN Act, currently covers nonconsensual intimate imagery specifically. Broader deepfake fraud, including the corporate wire fraud and voice cloning scenarios covered throughout most of this piece, is addressed through a patchwork of state laws that varies considerably in scope and penalty, and through existing federal wire fraud and identity theft statutes that predate deepfake technology entirely but can still apply to the underlying fraudulent conduct.
How can an older family member protect themselves specifically against a grandparent scam style voice cloning attempt. Establish a family code word in advance, one that would never be shared publicly or over an unverified call, and commit as a family to always independently calling back a known number before acting on any urgent, emotionally distressing request, regardless of how convincing the voice on the phone sounds. This single, low cost habit defeats the specific emotional urgency this scam is engineered to exploit, since it creates a mandatory pause before money moves, precisely the pause the scam is designed to prevent through manufactured panic.
Should our organization ban employees from posting any video or audio content publicly, given how easily it can be used as source material for a clone. Most security researchers stop short of recommending a total ban, recognizing that eliminating a public figure’s entire audio and video footprint is rarely realistic or even fully achievable in a modern business environment. The more practical recommendation is a genuine risk audit of existing public content, particularly for the specific individuals most likely to be targeted, senior finance and executive staff, followed by a deliberate, ongoing policy decision about future public appearances, rather than either an absolute ban or an unexamined status quo.
Is it possible to fully insure against deepfake fraud losses today. Not comprehensively, based on the research in this piece. Coverage depends heavily on specific policy language and how a given loss gets characterized, with the Arup case itself illustrating the ambiguity, since the incident involved no compromised systems and no breached data, sitting closer to social engineering than to the network intrusion many cyber policies were originally written around. Reviewing policy language specifically for social engineering and deepfake enabled fraud coverage, well before any incident occurs, remains the only reliable way to know where an organization actually stands.
The bottom line
Deepfake fraud succeeds for a reason this entire series has traced across every fraud category it has examined, from bot traffic to fake reviews to synthetic leads. A real decision, carrying real financial or emotional stakes, gets made based on a signal that is supposed to represent genuine human presence, and once someone works out how to fake that signal convincingly enough, the incentive to do so follows the money exactly where it leads. What makes this specific category different from everything else this series has covered is the target. Every other fraud in this series exploited a number, a click, a lead, a review, a follower count. Deepfake fraud exploits something considerably more fundamental, the basic human trust in the direct evidence of a familiar face and a familiar voice, evidence human beings have relied on to identify each other for the entire span of our species’ existence, now rendered unreliable within the span of a single technological generation.
The honest conclusion this research supports is neither panic nor complacency. Detection will keep lagging behind generation for the foreseeable future, which means the organizations and individuals who protect themselves successfully will be the ones who stopped trying to spot the fake and started building verification processes that do not depend on spotting anything at all. The Arup case cost twenty five million dollars specifically because a callback to a known, trusted number never happened before the money moved. Ferrari’s near miss cost nothing at all because, at the critical moment, it did. That gap, a single independently verified phone call, is small enough to implement by the end of this week, and large enough to be the difference between this piece’s two most instructive case studies.
There is a broader pattern worth naming plainly in closing, one this entire series has now documented across bot traffic, connected television advertising, influencer marketing, mobile app installs, B2B lead generation, fake reviews, and now deepfake fraud. Every single one of these categories represents the same underlying story told through a different medium: a system built on an assumption of human authenticity, scaled to a size where verifying that authenticity individually became practically impossible, and then exploited systematically by whoever worked out the gap first. Bot traffic exploited the assumption that a click came from an interested person. Fake reviews exploited the assumption that a star rating reflected a genuine experience. Deepfake fraud exploits the single deepest version of that same assumption, that a familiar face and a familiar voice, appearing together in real time, could only ever belong to the actual person they seem to represent. That assumption, arguably the oldest form of trust human civilization has ever depended on, is the one currently being tested most directly, and how individuals, organizations, and regulators respond to that test over the next several years will likely shape the baseline level of trust available in digital communication for a generation to come.
None of this means retreating from digital communication, video calls, or the genuine convenience AI tools increasingly offer across legitimate business and personal use. It means treating verification as a permanent, structural feature of how trust gets established going forward, in the same way multi factor authentication became a permanent, unremarkable feature of digital security over the past decade, rather than a temporary inconvenience to be tolerated until the threat eventually passes. The threat covered throughout this piece is not going to pass. It is going to keep improving, and the only durable answer is a verification habit robust enough that it never has to depend on staying one step ahead of whatever the technology can convincingly fake next.
References
Every figure and case study in this piece traces to one of the sources below.
Scale and financial data
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report, the first IC3 report to break out AI enabled fraud as its own category. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- DigitalApplied, Deepfake Fraud Statistics 2026: What the Data Actually Shows, an audit of widely circulated but unverifiable deepfake fraud figures. https://www.digitalapplied.com/blog/deepfake-fraud-statistics-2026-what-the-data-shows
- Deloitte Center for Financial Services, Generative AI Is Expected to Magnify the Risk of Deepfakes and Other Fraud in Banking, 2024 projection. https://www2.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk.html
The Arup case and corporate wire fraud
- CNN, British Engineering Giant Arup Revealed as Deepfake Scam Victim That Lost 25 Million Dollars. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong/index.html
- CFO Dive, Deepfake Scam Costs Engineering Giant Arup 25 Million Dollars. https://www.cfodive.com/news/deepfake-scam-engineering-firm-arup-25-million-fraud-hong-kong-cfo/716501/
- South China Morning Post, Hong Kong Police Arrest 6 Over HK 200 Million Deepfake Video Conference Scam. https://www.scmp.com/news/hong-kong/law-and-crime/article/3255181
- Motor1, Ferrari Nearly Fell for Deepfake Voice Scam Impersonating Its CEO. https://www.motor1.com/news/725316/ferrari-deepfake-scam-ceo/
- BBC News, Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case. https://www.bbc.com/news/technology-48908736
Voice and video cloning technology
- McAfee, The Artificial Imposter: McAfee Report on AI Voice Cloning Scams. https://www.mcafee.com/blog/privacy-identity-protection/artificial-imposters-cybercriminals-turn-to-ai-voice-cloning-for-a-new-breed-of-scam/
- Brightside AI, The State of Deepfake Detection in 2026. https://www.brightside.ai/blog/deepfake-detection-statistics-2026
Romance scams and pig butchering
- Federal Trade Commission, Consumer Sentinel Network Data Book 2023, romance scam loss figures. https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2023
- Chainalysis, 2026 Crypto Crime Report, pig butchering and cryptocurrency scam loss figures. https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/
- HCSK, 2025 Senior Scam Review, elder fraud loss figures drawn from FBI IC3 data. https://www.hcsk.org/2025-senior-scam-review
Detection technology
- iProov, The Threat of Deepfakes Report 2025, human video deepfake detection accuracy study. https://www.iproov.com/blog/deepfakes-detection-report
- StationX, Deepfake Statistics 2026, Intel FakeCatcher lab versus production accuracy. https://www.stationx.net/deepfake-statistics/
Legal and regulatory sources
- Congress.gov, TAKE IT DOWN Act, Public Law 119 12, official legislative text and status. https://www.congress.gov/bill/119th-congress/senate-bill/146
- Congress.gov, DEFIANCE Act, S.1837, official legislative text and status. https://www.congress.gov/bill/119th-congress/senate-bill/1837
- Congress.gov, NO FAKES Act, S.1367, official legislative text and status. https://www.congress.gov/bill/119th-congress/senate-bill/1367
- Tennessee General Assembly, ELVIS Act, official state legislative text. https://www.capitol.tn.gov/Bills/113/Bill/HB2091.pdf
- LegalClarity, Deepfake Laws by State: A 2026 Overview, tracking 170 AI bills across 39 states. https://legalclarity.org/deepfake-laws-by-state/
Corporate insurance and organizational defense
- Regula, 2024 Deepfake Fraud in Business Survey, corporate financial exposure and insurance implications. https://regulaforensics.com/news/deepfake-fraud-survey-2024/

I manage ClickBaton.com and ROIpad.com our product positioning intelligence platform. I am always open to new partnerships, collaboration and speaking directly with founders who are looking to test our products. Please feel free to connect with me on linkedin.