The AI Fraud Report: How Criminals Target Law Firms and Businesses

Table of Contents

Voice clones built from three seconds of audio. Job applicants who are not real people. Video calls where every participant is synthetic. This is a sourced look at how criminals are actually using AI against law firms and businesses right now, what it has already cost, and the verification habits that still stop it.

A split screen video call where the left half shows a normal looking executive on camera and the right half peels back to reveal a glitching wireframe construction underneath, exposing the same face as a synthetic model mid render
A split screen video call where the left half shows a normal looking executive on camera and the right half peels back to reveal a glitching wireframe construction underneath, exposing the same face as a synthetic model mid render

Every guide in this series so far has covered a version of the same underlying question: what happens to your data when you hand it to an AI tool. This one flips the question around. What happens when the AI is not yours at all, and it is being pointed at you.

Criminals have adopted generative AI faster than most legal and business teams have adopted defenses against it, and 2025 was the year the numbers stopped being anecdotal. The FBI’s Internet Crime Complaint Center tracked AI enabled fraud as its own distinct category for the first time in its twenty five year history, logging 22,364 complaints and 893.35 million dollars in confirmed losses, a figure the Bureau itself describes as a floor rather than a ceiling, since a complaint only gets tagged as AI related when a victim actually recognizes AI was involved, according to the FBI’s 2025 Internet Crime Report and analysis from Abnormal Security. Separately, a 2026 study from the security firm Surfshark, drawing on the AI Incident Database, Resemble AI, and OECD records, put documented global deepfake fraud losses at 3.7 billion dollars, with roughly 89 percent of that damage recorded in 2025 and the first half of 2026 alone, according to Brightside AI’s research summary. Deloitte’s forecasting team projects generative AI enabled fraud losses in the United States could reach 40 billion dollars a year by 2027, a number worth sitting with given how young this entire threat category still is.

This report is not a scare piece. It is a sourced accounting of what has actually happened, organized by attack type, with the verification habits that consistently stop each one. Every fraud category covered here shares one structural weakness a defender can exploit: it depends on convincing a specific person, in a specific moment, to skip a verification step they already know exists. That is a solvable problem, and the second half of this report is dedicated entirely to solving it.

What changed, in one paragraph

For most of the internet’s history, faking someone’s voice or face convincingly required specialized skill, expensive equipment, and hours of source material. That barrier is now gone. A usable voice clone can be built from three seconds of audio, according to research from McAfee cited across multiple 2026 industry reports, down from the many minutes of clean recording earlier voice cloning tools required just a few years ago. Real time video deepfakes, meaning a synthetic face mapped live onto a video call rather than a prerecorded clip, now run convincingly on consumer hardware, a capability security researchers at Palo Alto Networks’ Unit 42 found could be set up by someone with no prior experience in about an hour, using freely available tools, according to their detailed technical writeup. Independent research from Harvard, examined below, found AI generated phishing emails now perform on par with attacks written by skilled human experts, a threshold nobody expected to be crossed this quickly. The skill floor for convincing impersonation fraud has dropped from years of practice to an afternoon, and the rest of this report is about what that drop has already done.

Attack type one: voice cloning and AI powered vishing

The single fastest growing fraud vector in this entire report is also the simplest to explain: a criminal calls, sounding exactly like someone you trust, and asks for something urgent.

A soundwave from a short phone call is sampled by a glowing scanner and rebuilt into an identical looking synthetic waveform feeding directly into a second phone mid ring, with a small timer showing three seconds elapsed
A soundwave from a short phone call is sampled by a glowing scanner and rebuilt into an identical looking synthetic waveform feeding directly into a second phone mid ring, with a small timer showing three seconds elapsed

Security researchers at Pindrop, which analyzes contact center call traffic at scale, found that synthetic voice calls made up 0.33 percent of all contact center traffic in the fourth quarter of 2024, up 173 percent from the first quarter of the same year, according to figures compiled by StingRAI’s sourced statistics roundup. Consumer facing research tells a matching story from the receiving end: McAfee’s global study found that one in four adults had personally experienced a voice cloning scam or knew someone who had, and among people who received a cloned voice message, 77 percent of the group targeted for money reported an actual financial loss, according to figures reported by Memeburn’s deepfake statistics review. Separate 2026 research found deepfake enabled vishing, meaning voice phishing calls using a cloned voice, surged more than 1,600 percent in the first quarter of 2025 compared to the previous quarter in the United States, according to the same aggregated research.

Businesses, not just individuals, are absorbing real losses from this specific attack. Industry research on enterprise incidents puts the average business loss per deepfake related fraud event at close to 500,000 dollars, with some large enterprises reporting single incident losses as high as 680,000 dollars, and banks specifically reporting an average of 600,000 dollars per voice deepfake incident, with 23 percent of affected banks losing more than a million dollars in a single event, according to figures compiled by SQ Magazine’s fraud statistics research. One widely reported case, covered by U.S. Bank’s own fraud prevention guidance, involved a finance employee who received an urgent call that perfectly mimicked their chief executive’s voice. Believing the instruction was legitimate, the employee authorized a 243,000 dollar transfer, only learning afterward that the call had been an AI cloned voice from start to finish, according to U.S. Bank’s account of the incident.

What makes voice cloning specifically dangerous is not just its accuracy. It is how little source material a criminal actually needs to start. A public earnings call, a conference keynote, a podcast appearance, a voicemail greeting, even a short video posted to a company’s own website can all supply enough clean audio to build a working clone. McAfee’s research found that 53 percent of adults share their own voice online on a weekly basis through social posts, voice notes, and short videos, without ever considering that material as anything other than harmless personal content, according to additional figures reported by CallYourGirlfriend’s research summary. For a law firm partner or a company executive whose public speaking engagements are searchable on video, the raw material for a convincing clone of their own voice is often sitting in public view already, uploaded by the firm’s own marketing team.

Attack type two: real time video deepfakes

Voice cloning fools the ear. A newer and considerably harder to catch version of the same attack fools the eye as well, in real time, during a live video call.

Our companion guide to AI agent risk covers the best known example of this attack in depth: the 2024 case where a finance employee at the engineering firm Arup authorized 25.6 million dollars in transfers after joining a video call where every other participant, including the company’s chief financial officer, was an AI generated deepfake. We will not repeat that full account here, but it is worth restating the detail that makes it relevant to this report specifically: the employee’s initial instinct was correct. He suspected the request and asked for a video call specifically to verify it was real. The video call itself was the deepfake, which is exactly the failure mode this report’s later sections on verification are built to prevent.

The technical capability behind attacks like this has become dramatically more accessible since. Palo Alto Networks’ Unit 42 researchers demonstrated that a real time deepfake, meaning a synthetic face mapped onto a live video feed rather than a prerecorded clip, can be built and deployed by someone with no prior experience in roughly one hour, using freely available consumer tools and ordinary hardware, according to their published research. Gartner’s September 2025 survey of 302 security leaders found that 62 percent of organizations had already experienced at least one deepfake enabled attack in the prior year, splitting roughly 41 percent audio and 35 percent video, according to figures reported by Keepnet’s verified deepfake benchmark research. Independent testing of human detection ability found the problem is not a training gap that better awareness can close on its own: when researchers at iProov tested 2,000 consumers who had specifically been told to look for fakes, only 0.1 percent correctly identified every real and synthetic sample shown to them, and for video deepfakes specifically, human viewers caught the fake only 24.5 percent of the time, according to the same Keepnet research and confirmed independently by Trusona’s security research summary.

This is the single most important fact in this entire report: telling employees to look more carefully is not a viable defense against video deepfakes, because the visual evidence people rely on to trust a video call is no longer reliable evidence at all. The defense has to move to a different layer entirely, covered in the verification section later in this guide, rather than asking a person to outperform a detection rate that professional researchers specifically screening for fakes could not beat either.

Attack type three: AI written phishing and business email compromise

Phishing is the oldest attack in this report by decades, and AI has just made it dramatically more effective, at a scale defenders are struggling to match.

The clearest evidence comes from a controlled academic study, not a vendor’s marketing research. Researchers Fred Heiding, Bruce Schneier, and Arun Vishwanath ran a human subjects experiment comparing AI automated spear phishing against phishing written by skilled human experts, publishing their results through Harvard and later via arXiv. AI generated spear phishing emails achieved a 54 percent click through rate, statistically indistinguishable from the 54 percent rate achieved by expert human attackers, and more than four times the 12 percent baseline rate of generic, non personalized phishing, according to the study as reported by Adaptive Security’s detailed research summary. The reason is almost mundane once stated plainly: AI removes the grammatical errors, awkward phrasing, and cultural mismatches that trained employees have spent two decades learning to spot, without requiring the attacker to have any particular writing skill of their own.

The volume shift has been just as sharp as the quality shift. KnowBe4’s 2025 Phishing Threat Trends Report, drawing on a global detection network, found that AI generated content appeared in 82.6 percent of phishing emails analyzed, and a separate longitudinal measurement found AI generated phishing volume surged fourteen fold in December 2025 alone, rising from roughly 4 percent to 56 percent of all reported phishing attacks across a monitored network of four million users within a matter of weeks, according to Axis Intelligence’s detailed trend analysis. The same research found something specifically worth a defender’s attention: AI generated spear phishing was measured as 31 percent less effective than elite human red team attacks in 2023, roughly on par by late 2024, and 24 percent more effective by March 2025, a complete reversal that took under two years.

Business email compromise, the fraud category phishing most often leads to, is now the second most financially damaging crime type the FBI tracks, behind only investment fraud. IC3’s 2025 report recorded 3.046 billion dollars in confirmed BEC losses, up from 2.77 billion dollars the year before, with 86 percent of BEC losses moved by wire transfer or ACH, methods that are fast, and once funds clear, often unrecoverable, according to the FBI’s own 2025 annual report and analysis from dmarcian’s coverage of the findings. Within that total, the FBI specifically attributed more than 30 million dollars in BEC losses to attacks with a confirmed AI component, a figure the Bureau itself flags as almost certainly undercounted, since AI involvement is only logged when a victim or investigator specifically identifies it.

BEC attacks are also, structurally, some of the hardest fraud in this report to catch with technology alone. A compromised or convincingly spoofed email asking for a wire transfer contains no malicious link, no malware payload, and no domain for a spam filter to flag, according to analysis from Mimecast covering the 2025 IC3 findings. It is, in the plainest possible sense, a clean email that exploits trust and urgency at exactly the moment a person is making a financial decision, which is precisely why the verification protocols covered later in this report matter more than any spam filter or antivirus product ever could for this specific attack type.

Attack type four: the fake job applicant, and why your next hire might not be a real person

This is the case study in this report most people have never heard of, and it deserves the deepest treatment, because it represents a genuinely new category of risk: using AI not to steal from an organization, but to become an employee inside it.

An investigation board styled illustration with a world map and pinned photographs connected by red string, tracing a route from a laptop farm through a stack of stolen identity documents to a remote video interview and finally into a corporate network icon
An investigation board styled illustration with a world map and pinned photographs connected by red string, tracing a route from a laptop farm through a stack of stolen identity documents to a remote video interview and finally into a corporate network icon

On July 31, 2026, eleven allied governments, including the United States, Japan, South Korea, and for the first time France, Germany, Italy, and the Netherlands, issued a coordinated advisory warning that North Korean operatives are now using real time AI deepfake video to impersonate real people during live job interviews, defeating the identity verification checks most companies rely on during hiring, according to reporting from Tech Times. The threat group behind this scheme, tracked by the security firm CrowdStrike under the name FAMOUS CHOLLIMA, accounted for 47 percent of all state sponsored hands on keyboard intrusions against United States technology companies in the twelve months ending March 2026, according to CrowdStrike’s 2026 Technology Threat Landscape Report, making North Korean operatives the single largest state actor in direct access corporate infiltration tracked by the firm.

The mechanics are worth understanding precisely, because they explain why this scheme has been so hard to catch. Earlier versions of this fraud used prerecorded video or static photo substitution, techniques that basic liveness detection, meaning software that checks whether a video feed shows a real, live person rather than a recording, could often flag. The current version uses real time video inference: a deepfake model runs live during the call itself, mapping a stolen or synthetic face onto the operative’s actual video feed and routing the output through a virtual camera driver that the video conferencing software simply treats as a normal webcam, according to the same Tech Times reporting. To a hiring manager not specifically trained to probe for AI artifacts, the result is indistinguishable from an ordinary video interview. Researchers at Palo Alto Networks’ Unit 42 documented a case involving a Polish AI company that unknowingly interviewed the same operative twice, under two different synthetic identities, and noticed the second interview went unusually smoothly, because the operative had already seen the questions once before, according to their detailed case writeup.

The scale of this operation is not small. Earlier iterations of the same scheme, tracked before the shift to real time deepfakes, are documented to have infiltrated 309 United States companies, including an aerospace and defense contractor and a major television network, generating more than 17 million dollars in earnings funneled back to the North Korean regime, according to research from ID DataWeb. Broader estimates from security researchers put total annual revenue from North Korean remote IT worker schemes, including but not limited to the deepfake enabled cases, between 250 million and 600 million dollars a year, funding the country’s weapons development programs, according to 1Kosmos’ detailed research. In April 2026, the US Department of Justice announced sentences in one such case, with two US based facilitators, who had hosted company issued laptops in their own homes to make the fraud appear domestic, receiving 108 and 92 months in prison respectively, alongside 600,000 dollars in forfeiture, according to the same 1Kosmos analysis. Eight additional codefendants from a related scheme remain at large as of this research, named in a State Department reward offer of up to 5 million dollars.

Generative AI does not just supply the deepfake video. It runs the entire fraudulent employment pipeline. Microsoft’s March 2026 threat intelligence report on the scheme found that generative AI now writes the fraudulent applicant’s tailored resume, scripts interview answers, translates communications, and even debugs the malicious code the operative eventually deploys once hired, according to research covered by Hunter Strategy’s threat analysis. Microsoft’s guidance specifically flags HR software platforms as an underused detection surface, noting that automated, scripted queries against a company’s own job posting API, rather than the organic browsing pattern of a real applicant, is one of the clearest early warning signs available before a single interview even happens.

For a law firm, the exposure runs in two directions simultaneously. A firm hiring remote IT, paralegal, or administrative support staff carries the same infiltration risk as any other employer, with the added complication that a successfully placed operative gains access to privileged client files rather than ordinary corporate data. And separately, a firm advising a business client on an employment or immigration matter involving remote international hiring now has a documented, government confirmed reason to raise this exact scheme directly with that client, rather than treating it as a hypothetical.

Attack type five: wire fraud at closing, the scheme built specifically for law firms and title companies

A closing timeline unfolds along a diagonal ribbon from contract signing to closing day, with a hidden intruder icon quietly inserting itself into an email thread partway along, and a final wire transfer arrow forking into a legitimate destination and a diverted, fraudulent one
A closing timeline unfolds along a diagonal ribbon from contract signing to closing day, with a hidden intruder icon quietly inserting itself into an email thread partway along, and a final wire transfer arrow forking into a legitimate destination and a diverted, fraudulent one

If there is one fraud category in this report where a law firm sits at the exact center of the target list rather than at its edge, this is it.

Real estate closings move large sums of money on tight deadlines between parties who often have never met in person, which is precisely the combination of conditions wire fraud thrives on. Real estate related fraud losses reached 275.1 million dollars in 2025, a nearly 60 percent increase from the year before, according to the FBI’s figures cited in the National Association of Realtors’ reporting. A 2026 industry survey of more than 800 title and escrow professionals, conducted by the closing technology company Qualia, found that nearly 80 percent of title and escrow firms experienced a fraud attempt in the prior year, with 86 percent of respondents identifying phishing emails and business email compromise as the primary origin point of attacks, and 72 percent reporting they had experienced phishing directly, according to Qualia’s 2026 State of Wire Fraud report. Separately, more than one in five consumers reported receiving suspicious communications specifically during their own closing process, according to the same NAR reporting.

The mechanism is consistent enough across cases that it has become a template. Criminals compromise or convincingly spoof the email account of a real estate agent, title company, or closing attorney, then quietly monitor the ongoing communication thread for days or weeks, learning the closing date, the lender, the title company, and the exact dollar figures involved. Right before closing, they insert a message containing updated wire instructions that appears to come from a party the buyer already trusts, according to detailed analysis published by a luxury real estate wire fraud protection guide. One documented case involved a couple preparing to close on a new home who wired a 255,000 dollar down payment after receiving what appeared to be entirely legitimate instructions from their title company’s attorney, complete with accurate transaction details, correct branding, and appropriate timing. The funds never arrived, and the couple only learned the instructions were fraudulent on closing day itself, according to the same NAR reporting.

AI has changed this scheme in two specific, documented ways. First, AI generated emails now eliminate the grammatical errors and awkward phrasing that historically let attentive buyers catch a fraudulent message, according to research covered by a dedicated real estate wire fraud protection resource. Second, and more recent, is the arrival of voice cloning specifically targeting this scheme: security researchers have documented attackers cloning the voice of an attorney, a client, or a title company representative, then using that cloned voice on a phone call to redirect a wire transfer during closing, a specific evolution of the scam covered in detail by Slingshot Information Systems’ analysis of the trend, which notes that mid sized firms in the ten to fifty attorney range are increasingly the target profile, not just large firms, as fraud groups shift toward less defended, still lucrative targets.

One large commercial case illustrates how far into a transaction this fraud can reach. A reported 12 million dollar loss occurred after mediation had already resolved who was legally owed funds in a commercial real estate dispute, meaning the fraudsters had almost certainly been tracking the underlying deal long before the mediation phase concluded, according to reporting from HousingWire. The funds in that specific case were ultimately recovered, but the case illustrates a pattern worth internalizing: sophisticated wire fraud against a law firm is not opportunistic. It is a tracked, patient operation that waits for the single moment of maximum urgency and minimum scrutiny to strike.

Recovery, when it happens at all, depends almost entirely on speed. The FBI’s Recovery Asset Team, a unit specifically built to intercept fraudulent wires before they clear internationally, initiated 3,900 wire recovery actions in 2025 with a 58 percent success rate, according to figures reported in a dedicated real estate fraud protection resource. That success rate applies specifically to funds still inside the US banking system. Once money crosses into an international account, recovery odds fall close to zero, which is exactly why the verification protocols covered later in this report are framed around stopping a fraudulent wire before it is sent, not recovering it afterward.

Attack type six: AI generated malware and autonomous ransomware

Every attack type covered so far targets a person’s judgment. This one targets a network directly, and it represents the newest and least mature threat category in this report, worth understanding even though the scale is still emerging.

Security researchers have already documented working examples of AI generated malicious code operating in live attacks, not laboratory demonstrations. ESET researchers identified PromptLock, described as an AI powered ransomware strain that uses a large language model to generate malicious scripts dynamically at runtime rather than relying on a fixed, prewritten payload, targeting Windows, Linux, and macOS systems, according to coverage of Trend Micro’s 2026 threat predictions. Separately, the security firm Sysdig documented JadePuffer, which researchers describe as the first genuinely agentic ransomware observed in the wild, using AI to automate nearly every stage of an attack, from initial reconnaissance through data encryption and even generation of the ransom note itself, according to Forbes’ coverage of Sysdig’s research. Security researchers also identified MalTerminal, described as the earliest known malware sample built directly on top of a general purpose AI model, capable of generating ransomware or reverse shell code at the moment it runs rather than shipping with the malicious logic prewritten, according to SecurityWeek’s threat intelligence roundup.

The speed of the overall attack chain has compressed dramatically alongside this shift. Google Cloud’s Mandiant M-Trends 2026 report found that the median handoff time between an initial access broker, meaning the criminal who first breaks into a network, and the ransomware operator who actually executes the extortion, collapsed to 22 seconds in 2025, down from more than eight hours in 2022, according to Brightside AI’s analysis of the report. Once inside a network, AI assisted tools now accelerate lateral movement and data classification, identifying which specific files are most damaging to exfiltrate in hours rather than the days such reconnaissance previously required, according to Adaptive Security’s ransomware trend analysis.

One further development is worth naming directly and treating with the seriousness it deserves. In an incident Anthropic itself disclosed publicly, the company identified and disrupted a China linked state sponsored threat group that had misused Claude’s agentic coding capabilities to orchestrate a cyberattack, with the AI system carrying out an estimated 80 to 90 percent of the operation’s tactical work with minimal ongoing human direction, according to reporting from ISACA covering the incident. Anthropic’s own disclosure of the incident, rather than an outside researcher’s discovery of it, is itself a relevant data point: it reflects the kind of proactive threat reporting increasingly expected of frontier AI providers, and stands in useful contrast to several attack types elsewhere in this report that were only identified after victims had already lost money. It does not change the underlying finding, which security researchers describe as a preview of where this threat category is heading: agentic AI systems can now perform the bulk of a cyberattack’s tactical execution with only strategic direction from a human operator, a capability that closes the gap between having criminal intent and having the technical skill to act on it.

For a firm or business evaluating which AI vendor to trust with sensitive work in the first place, a question worth asking directly, and one our companion piece comparing AI vendors’ data practices addresses in depth, is whether a given provider has a demonstrated track record of catching and disclosing this kind of misuse of its own platform, rather than only responding after an outside party surfaces it. That track record is a meaningfully different signal than a vendor’s marketing claims about its own safety commitments, and it is one more reason the vendor evaluation questions covered in our broader series apply directly to the threat landscape documented in this report, not only to the data privacy concerns our other guides focus on most directly.

Attack type seven: synthetic identities and the collapse of document based verification

Underneath many of the attacks in this report sits a quieter, structural problem: the documents and photos organizations have relied on for identity verification for decades can now be manufactured convincingly, on demand.

Sumsub’s Identity Fraud Report for 2025 and 2026, drawing on an analysis of more than four million fraud attempts, found that synthetic identity document fraud rose approximately 311 percent year over year in North America, tracked alongside a broader shift toward sophisticated, multi step AI assisted identity fraud, which grew from 10 percent to 28 percent of all identity fraud cases in a single year, according to Keepnet’s summary of the Sumsub findings. Separately, identity verification firm Entrust documented a 40 percent year over year rise in injection attacks, meaning fraud attempts where a synthetic or manipulated image is injected directly into a verification system’s camera feed rather than presented to a physical camera, and found that one in five biometric fraud attempts now involves a deepfake specifically, according to DigitalApplied’s carefully sourced deepfake statistics review. In one especially striking data point, the identity verification company Smile ID traced more than 160,000 fraudulent verification attempts back to only 100 underlying facial identities in a single month, indicating that a small number of high quality synthetic faces are now being reused at industrial scale across many separate fraud attempts.

The financial exposure from this category is broad rather than concentrated in one industry. The US Federal Reserve has estimated that synthetic identity fraud, meaning fraud built on identities that combine real and fabricated personal information rather than impersonating one specific real person, accounts for roughly 6 billion dollars in annual credit losses across the American financial system, according to figures reported by Scam AI’s research compilation. For a law firm, the relevant exposure sits in client intake and know your customer processes: a firm that accepts scanned identification documents as sufficient verification for opening a new client matter, particularly in high value transactional or trust and estate work, is relying on exactly the category of evidence this section documents as increasingly unreliable.

This category also intersects directly with the anti money laundering obligations a growing number of law firms now carry, particularly firms handling real estate closings, corporate formation, or trust administration work in jurisdictions that have extended beneficial ownership reporting requirements to legal professionals. A synthetic identity that passes a firm’s document based client intake process does not just create a fraud exposure. It can create a compliance exposure as well, since a firm’s own onboarding records become the paper trail regulators examine if a matter later turns out to have involved a fabricated identity, independent of whether the firm itself was also deceived.

Attack type eight: AI enhanced romance and long term confidence fraud

Not every attack in this report unfolds in minutes. Some are built patiently over months, and AI has made that patience considerably cheaper to sustain at scale.

The FBI’s 2025 AI fraud category specifically attributed 19 million dollars in losses to romance and confidence scams carrying a confirmed AI component, according to the FBI’s 2025 Internet Crime Report, a figure that sits inside a much larger, longer running fraud category often referred to informally as pig butchering, where a scammer builds a long term romantic or friendly relationship with a target over weeks or months before introducing a fraudulent investment opportunity, typically involving cryptocurrency. What AI changes about this already well established scheme is the labor economics behind running it. A single human scammer previously needed to personally sustain a handful of convincing, emotionally engaged relationships at once, a genuinely time consuming constraint that limited how many targets one operator could work. Generative AI removes much of that constraint, letting a single operator maintain a synthetic persona, complete with a consistent generated face for video calls and AI drafted messages calibrated to a target’s own communication style, across dramatically more simultaneous relationships than a human alone could sustain.

Industry researchers tracking this shift describe it as the shadow side of the broader boom in AI companion products, where the same underlying technology that powers a legitimate AI companion application, a consistent synthetic persona capable of sustained, personalized conversation, is repurposed for fraud rather than companionship, according to CallYourGirlfriend’s research on the trend. This attack type rarely targets a business directly, but it belongs in this report for two reasons a legal or business audience should take seriously. First, trust and estate practices regularly encounter this exact fraud pattern when an older client’s finances have already been compromised by exactly this scheme before the firm becomes aware of it, often only once a family member raises concern about unusual account activity. Second, the same synthetic persona techniques underlying this fraud category, a consistent generated face and a calibrated communication style sustained over time, are directly transferable to the business email compromise and executive impersonation schemes covered earlier in this report, meaning the tooling behind a romance scam and the tooling behind a wire fraud scheme increasingly come from the same commoditized source.

Attack type nine: vendor and counterparty impersonation

Every verification habit recommended in this report so far assumes the fraudulent request appears to come from inside a trusted relationship, a colleague, an executive, a client. A closely related and increasingly common variation targets the relationships an organization has with its outside vendors and counterparties instead.

This variation follows the same business email compromise mechanics documented earlier in this report, with one meaningful difference: rather than impersonating someone inside your own organization, the attacker impersonates a long standing external vendor, supplier, or counterparty, requesting a change to payment or banking details for an invoice that would otherwise be paid without a second thought. Qualia’s 2026 wire fraud research, cited earlier in this report, specifically found that criminals frequently monitor a transaction thread for weeks before striking, a pattern that applies with equal force to vendor relationships as it does to real estate closings. A finance team that has paid the same vendor the same way for years is, precisely because of that comfortable routine, an easier target than a brand new relationship still receiving active scrutiny.

The defense here is a direct extension of the verification framework covered earlier in this report, applied specifically to external relationships. Any request to change payment or banking details for an existing vendor, regardless of how routine or well established that vendor relationship feels, should trigger the same out of band verification call to a phone number obtained independently of the request, not a number supplied in the email or message asking for the change. Firms and businesses that maintain a formal, written vendor payment change policy, requiring this verification step without exception regardless of the requester’s seniority or the deal’s urgency, consistently avoid the specific loss pattern this attack type is built to produce. The exception process is, not incidentally, exactly where most successful attacks in this category find their opening: a well liked, senior person requesting an exception to the normal verification process because a specific deal is unusually time sensitive.

A timeline of what has actually happened

As with every guide in this series, it helps to see the pattern across dated, verifiable incidents rather than treat any single case as an outlier.

2022. The FBI issues its first public service announcement warning that fraudsters are using deepfakes to impersonate job applicants during online interviews, an early version of the scheme covered in depth earlier in this report, at the time still relying on prerecorded video and photo substitution rather than real time inference.

January to February 2024. A finance employee at the engineering firm Arup authorizes 25.6 million dollars in transfers after joining a video call where every participant, including the company’s chief financial officer, is later confirmed to have been an AI generated deepfake, covered in depth in our companion guide to AI agent risk.

September 2023. The NSA, FBI, and CISA jointly publish Contextualizing Deepfake Threats to Organizations, the first major coordinated federal guidance specifically addressing organizational deepfake risk, recommending enhanced media authentication processes and deepfake detection capability as standard organizational practice.

April 2025. Palo Alto Networks’ Unit 42 first documents North Korean operatives using real time AI deepfake video during live job interviews, describing it as a logical evolution of an already well documented infiltration scheme.

2025, full year. The FBI’s Internet Crime Complaint Center logs 22,364 complaints carrying an AI descriptor, the first year the Bureau tracked AI enabled fraud as its own distinct category, totaling 893.35 million dollars in confirmed losses across investment fraud, business email compromise, romance and confidence scams, and deepfake enabled employment fraud.

March 2026. A suspected deepfake job applicant is caught infiltrating an online hiring interview at a Japanese IT company, raising concern about links to the broader North Korean scheme and confirming the tactic has spread beyond its original American targets.

April 2026. The US Department of Justice announces sentences for two American facilitators who hosted company issued laptops in their own homes as part of a North Korean remote IT worker scheme running from 2021 through October 2024, with over 600,000 dollars ordered in forfeiture.

July 31, 2026. Eleven allied nations, including the United States, Japan, South Korea, France, Germany, Italy, and the Netherlands for the first time, issue a coordinated advisory confirming North Korean operatives now use real time AI deepfake video to defeat live hiring interview screening at scale, treating it as a confirmed, active global threat rather than an isolated incident.

The pattern across this timeline, consistent with the rest of this report, is acceleration rather than a single dramatic event. Each entry represents the same underlying capability, convincing synthetic media produced cheaply and quickly, being applied to a new context faster than the guidance meant to counter it can be written and distributed.

Who these attacks actually target, and why the answer keeps surprising people

A persistent myth in fraud prevention holds that criminals chase the biggest possible target. The data in this report tells a more specific, and for a mid size firm or business, considerably less comforting story.

Age is one of the clearest predictors in the entire fraud dataset, and it cuts against the assumption that older adults are simply less tech literate. Within the FBI’s 2025 AI fraud category, adults aged 60 and older accounted for 352 million dollars of the total 893 million dollars in losses, roughly 39 percent, the single largest age bracket by a wide margin, according to the FBI’s own 2025 Internet Crime Report. This matters directly for law firms with a trust and estate or elder law practice, where clients in exactly this age bracket are making high value, often irreversible financial decisions with some regularity, frequently over the phone or through a family intermediary, precisely the conditions voice cloning fraud is built to exploit.

Mid size organizations, not just large enterprises, are increasingly the deliberate target rather than an afterthought. Industry reporting on the shift in law firm specific wire fraud found that criminal groups are increasingly moving away from pursuing only large enterprises and toward mid sized organizations specifically, according to Slingshot Information Systems’ analysis, which specifically named the ten to fifty person firm profile as an active target category, not a theoretical one. The logic is straightforward once stated: a large enterprise has a dedicated security team, a documented verification protocol, and staff trained specifically to spot exactly this kind of request. A ten to fifty person firm, handling comparably large sums of client money during a real estate closing or an estate settlement, frequently has none of those three things, making it a target that is both lucrative and comparatively undefended.

Professional services firms broadly, including law offices, consistently rank among the most targeted sectors in industry reporting on business email compromise and wire fraud, a pattern that holds because professional services firms routinely move large sums of client money through predictable, calendar driven transactions, exactly the combination of predictability and financial scale that makes a target worth a criminal group’s sustained attention.

Within a law firm specifically, exposure is not evenly distributed across practice areas. Real estate, trust and estate, and mergers and acquisitions practices concentrate the highest risk, because each combines large, infrequent transactions with a predictable, often publicly discoverable closing timeline, the exact conditions the organized fraud ring profile covered later in this report is built to exploit. Litigation practices, by contrast, carry comparatively lower direct wire fraud exposure but a growing evidentiary risk, covered in a dedicated section later in this report, as synthetic media becomes harder to reliably authenticate in a courtroom setting. A firm allocating limited security and training resources across a broad practice should weight that allocation toward the practice groups actually moving large, time sensitive sums of client money, rather than spreading verification training evenly across every department regardless of actual transaction exposure.

The economics behind the surge: fraud has become a service business

None of the attack types in this report require the criminal executing them to have deep technical skill anymore, and understanding why explains the growth curve better than any single statistic does.

A dimly lit storefront styled illustration displays a shelf of glowing product boxes labeled voice clone, phishing kit, and synthetic identity, each with a price tag, situated inside an underground marketplace scene
A dimly lit storefront styled illustration displays a shelf of glowing product boxes labeled voice clone, phishing kit, and synthetic identity, each with a price tag, situated inside an underground marketplace scene

Phishing as a service platforms, meaning ready made criminal toolkits sold or rented to less technically skilled operators, now power an estimated 60 to 90 percent of credential theft attacks, according to research compiled by GetAstra. Voice cloning tools sit on a similarly commoditized trajectory: the global AI voice cloning market itself, spanning both legitimate and abused uses, was valued at roughly 4.06 billion dollars in 2026 and is projected to reach 9.56 billion dollars by 2030, according to SQ Magazine’s market research, a growth curve that reflects both legitimate adoption and the reality that the same accessible tools power both. Consumer Reports’ own testing found that four of six major AI voice cloning tools evaluated lacked meaningful safeguards against misuse, meaning the barrier between a legitimate consumer product and a fraud enabling tool is, for a majority of tools tested, a matter of intent rather than access.

On the ransomware side, white label extortion services, meaning fully packaged ransomware operations criminal groups can rent rather than build, have specifically lowered the barrier to entry for new criminal organizations that have the intent to commit fraud but previously lacked the infrastructure to do so, according to ISACA’s industry analysis. The unifying story across every attack type in this report is the same one running through the ransomware, phishing, and voice cloning economics: what used to require a skilled criminal now only requires a criminal with intent and a credit card, and that shift in the underlying economics, more than any single technical breakthrough, is what has driven the surge in complaint volume and dollar losses documented throughout this report.

Know your adversary: four threat profiles behind these attacks

Not every attack in this report comes from the same kind of criminal, and knowing which profile you are likely facing changes what a realistic defense looks like.

A stylized most wanted board displays four labeled profile cards, a state sponsored operative, an organized fraud ring, a lone opportunist renting fraud as a service tools, and an insider threat, each card showing a silhouette, a method icon, and a small case file tag
A stylized most wanted board displays four labeled profile cards, a state sponsored operative, an organized fraud ring, a lone opportunist renting fraud as a service tools, and an insider threat, each card showing a silhouette, a method icon, and a small case file tag

The state sponsored operative. Best represented by the FAMOUS CHOLLIMA group behind the North Korean fake applicant scheme documented earlier in this report, this profile is patient, well resourced, and motivated by sustained access and revenue generation rather than a single large payout. It specifically targets hiring pipelines and long term employment relationships rather than a single transaction, and it is the profile least likely to be caught by a one time verification check, since the fraud is designed to survive initial onboarding and continue indefinitely.

The organized fraud ring. This profile runs the business email compromise and wire fraud schemes documented in this report’s third and fifth attack types, operating with the coordination and division of labor of an actual business, complete with reconnaissance specialists who monitor a target’s communications for weeks before a money specialist executes the final request. This profile is the most likely to target a specific, tracked transaction, such as a real estate closing or a settlement distribution, and the most likely to have already read months of a target’s email before making contact.

The opportunist renting fraud as a service tools. Enabled by the commoditized voice cloning and phishing kits documented earlier in this report, this profile requires the least skill and the least patience of the four, often running high volume, low sophistication attempts against many targets simultaneously rather than a single, carefully researched attack. This is the profile most likely to be caught by basic verification habits, precisely because the attack was never tailored closely enough to survive a callback to a known number.

The insider adjacent threat. This profile does not fit neatly into the other three, and it deserves its own category precisely because it is the hardest to defend against using external verification alone: a successfully placed fake employee, hired through the deepfake interview scheme documented earlier in this report, who is not attacking from outside an organization’s perimeter but operating with legitimate credentials from inside it. Defending against this profile requires the hiring stage scrutiny recommended earlier in this report, since once an operative is inside, ordinary fraud detection controls built around external threats are largely blind to them.

Matching a specific incident to one of these four profiles, even roughly, helps focus a response. A suspicious wire instruction that arrived after weeks of normal seeming email correspondence points toward an organized fraud ring and warrants scrutiny of the entire communication thread, not just the final message. A single, high volume, generic sounding phishing attempt points toward an opportunist and is often adequately handled by existing spam filtering and basic staff awareness. A remote hire who seems unusually reluctant to appear on unscheduled video calls, or whose video presence has subtle but consistent technical artifacts, warrants the hiring stage scrutiny associated with the state sponsored and insider adjacent profiles specifically.

These four profiles are not mutually exclusive, and the most damaging incidents documented in this report frequently combine more than one. The Arup case covered in our companion guide to AI agent risk shows the organized fraud ring profile executing with the technical sophistication more commonly associated with a state sponsored operation, a reminder that the resourcing gap between these categories has narrowed considerably as the fraud as a service economy documented earlier in this report has made sophisticated tooling available to groups that would once have lacked the capability to build it themselves. An organization’s incident response plan should account for this overlap rather than assuming a specific defensive posture is only relevant to one threat profile.

Why smart, careful people still fall for this

A common and unhelpful reaction to reading a report like this one is assuming the people in these case studies must have been unusually careless. The research says otherwise, and understanding why matters for building a defense that actually holds up under real conditions rather than one that only looks good on paper.

Every fraud category in this report is built around exploiting normal, adaptive psychology, not a personal failure of judgment. The Arup employee covered in our companion guide to AI agent risk did exactly what security training tells people to do: he was suspicious of an initial request and sought additional verification through a video call. The attack succeeded specifically because it anticipated that exact response and was built to defeat it. Behavioral researchers studying social engineering consistently identify the same small set of psychological levers behind almost every successful attack in this report: authority, meaning a request that appears to come from someone with legitimate power to make it; urgency, meaning a compressed window that discourages the slower, more careful thinking a person would otherwise apply; and social proof, meaning the request arrives embedded in a context, a familiar voice, a recognized face, an ongoing email thread, that already carries the weight of an established relationship.

AI has not invented any of these three levers. It has made each one dramatically cheaper and more convincing to construct. A criminal no longer needs to correctly guess which authority figure a specific target will trust, or spend weeks building a convincing enough relationship to exploit social proof. A cloned voice supplies authority instantly. A real time deepfake supplies social proof instantly. The urgency lever has always been free. What this means practically is that the target in every case study in this report was not the specific person who received the call or email. It was the underlying psychological pattern, and that pattern is remarkably consistent across intelligence, seniority, and industry, which is precisely why the defenses recommended throughout this report are structural rather than educational. Training people to recognize authority, urgency, and social proof as manipulation levers helps, and the training research cited earlier in this report shows it meaningfully reduces susceptibility over time. But the verification framework covered in this report exists specifically because training alone, even effective training, does not close the gap to zero, and the financial exposure documented throughout this report is large enough that a defense relying on zero failures across every employee, every time, under real pressure, is not a realistic bar to set.

Why humans cannot spot this anymore, in one uncomfortable chart

Every fraud category in this report ultimately asks the same question of the person on the receiving end: does this look, sound, or read as real. The research on human detection ability gives a consistent, sobering answer.

A dashboard styled illustration with three large circular gauges, the first needle barely moving to show 0.1 percent human detection of studio tested deepfakes, the second showing 24.5 percent for video specifically, and the third showing a sharp drop from 96 percent lab accuracy to 45 percent in real conditions for detection software itself
A dashboard styled illustration with three large circular gauges, the first needle barely moving to show 0.1 percent human detection of studio tested deepfakes, the second showing 24.5 percent for video specifically, and the third showing a sharp drop from 96 percent lab accuracy to 45 percent in real conditions for detection software itself

iProov’s controlled testing of 2,000 consumers, specifically instructed in advance to watch for fakes, found that only 0.1 percent of participants correctly identified every real and synthetic sample in the test set, according to research reported by Trusona. Isolating video deepfakes specifically, human viewers caught the fake only 24.5 percent of the time, according to the same research cited by Keepnet. Separate research from McAfee found that 70 percent of people were not confident they could tell a cloned voice from a real one even when specifically asked to consider the possibility, a finding echoed by industry survey data showing a similar share of consumers unsure they could distinguish a deepfake voice call from a genuine one.

Automated detection technology is not yet a reliable substitute for human judgment either, which is the finding most reports on this topic bury rather than lead with. Detection tools that achieve up to 96 percent accuracy under controlled laboratory conditions see that accuracy fall to 45 to 50 percent in real world deployment, according to the same research aggregated by StationX’s sourced statistics compilation. Consumer Reports’ testing, cited earlier in this report, found most consumer facing AI voice tools carry no meaningful built in safeguard against misuse, meaning the tools available to build a synthetic voice are, at present, considerably more mature than the tools available to reliably catch one.

This is precisely why every effective defense covered in the remainder of this report is structural rather than perceptual. None of the verification protocols that follow ask an employee to get better at spotting a fake. They ask an organization to build a process where spotting the fake is never actually necessary, because the request is verified through a channel a deepfake, however convincing, cannot reach.

There is a further wrinkle worth naming here, because it explains why this problem resists a simple technical fix. Detection researchers describe deepfake generation and deepfake detection as locked in what amounts to an ongoing arms race, where every advance in detection accuracy gets incorporated back into the next generation of generation tools within months, not years, since the same underlying model architectures researchers use to detect synthetic media are frequently the same ones criminals use to refine it. A detection tool that reliably catches today’s deepfakes offers no durable guarantee against next year’s, which is a meaningfully different situation than most other categories of cybersecurity defense, where a patched vulnerability generally stays patched. This is the specific, technical reason this report has argued throughout that the durable defense sits in verification process, not detection technology: a codeword and a callback policy do not degrade as the underlying AI models improve, because they were never trying to win the detection arms race in the first place.

The technology layer: detection tools and content provenance standards

While this report has argued throughout that structural verification habits matter more than detection technology, the technology layer is maturing and deserves a fair, specific accounting rather than dismissal.

Joint federal guidance from the NSA, FBI, and CISA specifically recommends organizations incorporate deepfake detection capability into standard cybersecurity practice, alongside enhanced media authentication processes, according to the Fordham University summary of the guidance. Detection tools in active use analyze facial expression consistency, blinking patterns, audio and video synchronization, and lighting or shadow inconsistencies, with named commercial tools including Microsoft’s Video Authenticator, Deepware Scanner, Reality Defender, and Truepic cited in the same guidance as representative examples of the category. A parallel and arguably more durable approach focuses not on detecting a fake after the fact, but on authenticating genuine content at the point of creation: the Coalition for Content Provenance and Authenticity, known as C2PA, has developed a technical standard allowing legitimate media to carry a cryptographically verifiable record of its origin and any subsequent edits, letting a recipient confirm a video or image is what it claims to be, rather than trying to detect what it is not.

The honest limitation of both approaches is the same one documented throughout this report: detection accuracy that looks strong in a laboratory has consistently underperformed in real world deployment, falling from 96 percent to 45 to 50 percent according to the research cited earlier. Provenance standards like C2PA face a different, more structural limitation: they only work if the legitimate content was captured using C2PA compliant hardware or software in the first place, and adoption across consumer devices and communication platforms remains partial as of this research. The realistic role for detection and provenance technology, based on the evidence gathered for this report, is as a supplementary signal that strengthens an existing verification process, not as a replacement for the codeword, callback, and segregation of duties habits this report recommends as the primary defense. An organization that deploys detection software as its sole safeguard, without the structural habits covered earlier in this report, is relying on a tool that, per the research cited above, fails more often in practice than its marketing materials suggest.

What regulators and law enforcement are already doing

The response to this threat category has moved from advisory to active enforcement faster than the earlier chatbot and agent risks covered in our companion guides, largely because the financial losses documented in this report are direct, individually attributable, and criminally prosecutable in a way a data privacy violation often is not.

The NSA, FBI, and CISA jointly published Contextualizing Deepfake Threats to Organizations in September 2023, the first major coordinated federal guidance specifically addressing organizational deepfake risk, recommending enhanced media authentication processes, staff awareness training, and integration of deepfake detection capability into standard cybersecurity practice, according to Fordham University’s summary of the joint publication. The FBI has since issued repeated, specific public service announcements, including a joint advisory with the American Bankers Association warning that criminals pose as loved ones, government officials, and executives, and specifically recommending that individuals and organizations establish codewords in advance to confirm authenticity during a suspicious call, according to KnowBe4’s coverage of the advisory. The FBI has separately warned specifically about deepfake enabled kidnapping and extortion schemes, where criminals generate fake proof of life video from a target’s own publicly available photos to extract ransom payments from family members, according to TechRadar’s coverage of the advisory.

Legislatively, 47 US states have enacted some form of deepfake specific legislation since 2022, according to figures compiled by StationX, covering areas ranging from election related synthetic media to non consensual intimate imagery to, in a smaller number of states, financial fraud specific provisions. At the federal level, the proposed DEEPFAKES Accountability Act continues to move through the legislative process as of this research, and industry analysts covered in CertifID’s research predict federal legislation establishing mandatory identity verification requirements for high value financial transactions is likely by 2027, a timeline that would place new, binding verification obligations directly on the kind of law firm and title company transactions covered in this report’s fifth attack type.

Recovery infrastructure has also matured meaningfully. The FBI’s Recovery Asset Team, discussed earlier in this report, exists specifically to intercept fraudulent wire transfers before they clear internationally, and its 58 percent success rate in 2025 reflects a genuinely functional, if time sensitive, recovery mechanism, provided a victim reports the fraud to IC3.gov within the narrow window before funds leave the US banking system entirely.

What this means if you run a law firm

Every fraud category in this report lands on a law firm with particular weight, because firms routinely combine three conditions criminals specifically look for: large sums of client money moving on predictable deadlines, a professional culture built around responsiveness to urgent requests, and comparatively modest dedicated security staffing relative to the dollar amounts being moved.

Trust account and IOLTA obligations add a layer of professional consequence that a typical business does not carry. A firm that wires client trust funds to a fraudulent account based on a deepfake voice or a spoofed email is not simply out the money. Depending on jurisdiction and the specific facts, the firm may face a professional responsibility inquiry over its handling of client funds, independent of whether the firm itself was also a victim of the fraud. This is precisely the scenario the verification protocols later in this report are built to prevent, and firms handling trust or escrow funds should treat those protocols as a professional obligation, not merely a security best practice.

The North Korean fake applicant scheme deserves specific attention from any firm hiring remote paralegal, IT, or administrative support staff. A successfully placed operative inside a law firm gains access to privileged client communications and case files, a materially different and more serious outcome than the corporate espionage or wage theft outcomes documented in cases against other industries. Firms should treat the detection guidance covered later in this report, particularly around video interview verification and reference checking, as directly applicable to their own hiring process, not just a concern for technology companies.

Client communication itself needs a rethink, given how convincingly a client’s own voice or writing style can now be imitated. A call that sounds exactly like a longstanding client, requesting an urgent change to settlement fund distribution instructions, deserves the same skepticism this report recommends for a call that sounds exactly like a firm’s own managing partner. The verification habit does not change based on which side of the relationship the impersonated party sits on.

What this means if you run a finance or operations team

The same fraud categories land differently, but no less seriously, on a business team responsible for payments, vendor relationships, and hiring.

Business email compromise and voice cloning both converge on the same organizational choke point: whoever holds the authority to move money without a second person’s sign off. Every case study in this report involving a large financial loss shares a common root cause, a single person, under time pressure, empowered to complete a transaction alone. The segregation of duties principle that already governs financial controls in a well run finance department is the same principle that defeats the majority of the attacks documented in this report, and the practical checklist later in this guide is built around applying that existing discipline specifically to AI enabled fraud.

Vendor and payment record changes deserve the single highest level of scrutiny in this report’s findings, because BEC attacks routinely masquerade as exactly that kind of routine, low drama request. A message asking a business to update a long standing vendor’s banking details, arriving through a channel that looks entirely normal, is one of the most common templates behind the 3 billion dollar BEC loss figure documented earlier in this report. Any change to payment instructions for an existing vendor relationship should trigger a verification call placed to a phone number already on file, never a number provided in the message requesting the change.

Hiring processes deserve the same scrutiny finance teams have historically reserved for payments. The North Korean infiltration scheme documented in this report specifically targets remote technical and IT roles, but Gartner’s own forecasting predicts that by 2028, one in four job candidates worldwide will be fake in some meaningful sense, according to research cited by 1Kosmos. A business hiring any remote role that grants access to sensitive systems or data should treat identity verification during the hiring process with the same rigor it already applies to financial approvals, not as a separate, lower priority concern.

Beyond law and finance: who else this report matters to

While this report is written primarily for legal and business audiences, the fraud categories documented throughout it reach several adjacent fields worth naming directly, both because readers in this audience often advise or work alongside these fields, and because the underlying verification framework applies without modification.

Human resources and recruiting teams sit at the center of the North Korean infiltration scheme covered extensively in this report, and the hiring stage screening indicators covered earlier apply with particular force to any HR function handling remote hiring at scale, independent of company size or industry. Given Microsoft’s own detection guidance specifically flags HR software platforms as an underused detection surface, an HR team’s own applicant tracking system is itself a source of useful signal this report recommends actively monitoring, not simply a records repository.

Real estate professionals, beyond the title and escrow companies already covered in this report’s fifth attack type, face the same wire fraud exposure from the buyer and seller side of a transaction, and agents advising clients through a closing should treat the verification guidance in this report as client education material worth actively sharing, not solely an internal operational concern.

Healthcare organizations handling remote patient intake or telehealth consultations face an emerging version of the identity verification challenges covered in this report’s synthetic identity section, particularly as remote care delivery continues expanding and identity verification for prescription and billing purposes increasingly happens without an in person visit. The same document based verification gap documented earlier in this report applies with particular consequence in a healthcare setting, where a successfully fabricated identity can enable prescription fraud or insurance billing fraud in addition to the financial exposure common to every other sector covered in this report.

Family offices and wealth management practices serving high net worth individuals carry a concentrated version of nearly every risk in this report simultaneously: the elder targeting pattern documented earlier, the large, infrequent transaction profile that gives criminals time to research a target patiently, and a client base whose public visibility, through media coverage, public filings, or philanthropic activity, often supplies unusually rich raw material for the voice cloning and impersonation attacks covered throughout this report.

Insurance brokers and carriers themselves increasingly need to understand this report’s findings from the underwriting side, not only the claims side. As the insurance section later in this report covers in more depth, coverage terms for social engineering and deepfake enabled fraud are evolving quickly, and a broker able to speak specifically to which verification controls a policyholder has in place is positioned to secure meaningfully better terms than one relying on generic cyber risk questionnaires that predate the attack types documented throughout this report.

A note on AI generated evidence in litigation

The fraud categories covered throughout this report create a second, quieter problem for law firms specifically: as synthetic media becomes harder to distinguish from genuine media, the evidentiary questions surrounding video, audio, and document evidence in litigation grow more complicated too, independent of whether a given matter involves fraud at all.

A recording or video submitted as evidence in a dispute can now, in principle, be challenged on authenticity grounds with genuine plausibility, given the detection accuracy limitations documented earlier in this report. Courts and rules committees have begun responding, though unevenly. Several jurisdictions have started developing specific evidentiary standards addressing the authentication of digital media given deepfake capability, generally requiring a stronger foundation, such as metadata analysis, chain of custody documentation, or expert testimony, before video or audio evidence is admitted without challenge, a shift that parallels the broader move toward content provenance standards like C2PA discussed earlier in this report. For litigators, this means the authentication foundation historically considered sufficient for video and audio evidence, a witness confirming it looks and sounds accurate, is becoming a materially weaker foundation than it was even a few years ago, and firms handling matters where video or audio evidence plays a central role should expect authentication challenges to become more common and more technically involved going forward, not less.

There is a related, more immediate concern specific to firms using AI tools for litigation support, covered in more depth in our companion guide to cloud AI risk: the hallucination risk documented in that guide, where an AI tool fabricates a citation or a fact with complete confidence, sits adjacent to but distinct from the fraud risk covered in this report. Both share a common underlying lesson worth restating here: AI generated content, whether a fabricated legal citation or a fabricated video of a person speaking, requires a verification step specifically because the content’s own apparent quality and confidence provide no reliable signal of its accuracy. A firm that has built strong AI output verification habits for legal drafting, as our companion guide recommends, is well positioned to extend that same skepticism to evidence authentication questions raised by the fraud categories in this report, because the underlying discipline, treating confident seeming AI generated content as unverified until checked, is identical in both contexts.

The insurance question, in more depth

Cyber insurance coverage for the fraud categories in this report is one of the fastest moving, least standardized areas in the entire insurance market, and it deserves more attention than a brief mention, given how directly it affects a firm’s actual financial exposure.

Social engineering fraud, the category that covers business email compromise, voice cloning, and deepfake enabled wire fraud, is frequently covered differently, and far more restrictively, than a straightforward hacking or ransomware loss under a typical cyber policy. Many policies require a specific social engineering fraud rider or endorsement, purchased separately from a base cyber policy, and impose meaningfully lower coverage limits on this category than on other cyber losses, reflecting insurers’ own concern about the loss trends documented throughout this report. Some policies condition coverage for this specific loss category on the policyholder having had a defined verification process, such as a callback confirmation requirement, already in place at the time of the loss, which makes the verification framework covered earlier in this report not just a security best practice but, potentially, a condition of the very coverage meant to backstop a failure of that framework.

Given how quickly this coverage area is evolving, a policy reviewed even a year ago may no longer accurately reflect current market terms or your own carrier’s specific requirements. Firms and businesses should confirm directly with their broker or carrier, on a recurring basis rather than only at renewal, exactly what social engineering and deepfake enabled fraud coverage their current policy includes, what dollar limits apply specifically to this category as distinct from the broader policy limit, and whether any verification control requirement, such as the callback policy recommended throughout this report, is a condition of that coverage. An organization that implements the thirty day defense plan covered earlier in this report is not only reducing its likelihood of a loss. It is very plausibly satisfying a coverage condition its policy already requires, whether or not anyone at the organization has specifically checked.

The verification framework that actually stops these attacks

Every attack type in this report, regardless of which of the four threat profiles above is behind it, shares one exploitable weakness: it depends on convincing a specific person to act without completing a verification step that already exists inside a well run organization. This section is the practical center of this report.

A security checkpoint scene shows a caller icon approaching a gate staffed by a checkpoint booth, with a glowing codeword challenge displayed on a screen and a second, separate callback phone line branching off to a verified contact icon before the gate opens
A security checkpoint scene shows a caller icon approaching a gate staffed by a checkpoint booth, with a glowing codeword challenge displayed on a screen and a second, separate callback phone line branching off to a verified contact icon before the gate opens

Establish a codeword for high stakes requests, and change it on a defined schedule. The FBI’s own joint guidance with the American Bankers Association specifically recommends this as a primary defense, and it works precisely because a codeword cannot be inferred from public audio or video, no matter how convincing the surrounding deepfake is. A firm’s codeword should be known only to the specific people authorized to request or approve high value transactions, communicated through a channel other than email, and rotated periodically rather than left static indefinitely.

Verify any request to move money or change payment instructions through a channel the requester did not provide. This is the single most important habit in this entire report, and it defeats the large majority of the attack types documented above. If a call, email, or message asks for an urgent wire transfer or a change to existing payment instructions, the verification call goes to a phone number already on file from before the request arrived, never a number provided in the message itself, and never simply calling back the number that just called you.

Treat urgency itself as a red flag, not as a reason to move faster. Every fraud category in this report depends on compressing the time available for a target to think. The FBI and ABA’s joint guidance is explicit on this point: stop and think before responding to any request delivered with unusual urgency or emotional pressure, regardless of how legitimate the surrounding context appears.

Separate the authority to initiate a transaction from the authority to approve it, for any amount above a defined threshold. This single structural control, already standard practice in a well run finance department, defeats the majority of large dollar losses documented throughout this report, because it removes the single point of failure every successful case study in this report shares: one person, alone, under pressure, with the authority to act.

Build video call verification into your process for any high stakes remote meeting, not just standard hiring interviews. Given that real time deepfakes can now be deployed by someone with no prior technical experience within about an hour, a video call alone is no longer sufficient identity confirmation for a large financial transaction or a sensitive hire. Consider a brief, unscripted request during any high stakes video call, such as asking the other party to turn their head fully to one side or perform a simple, unexpected physical action, which remains a meaningfully harder technical challenge for real time deepfake software to render convincingly than static or scripted movement.

Limit the public availability of executive voice and video, where reasonably possible, while accepting the limits of this control. Given that a working voice clone needs only a few seconds of clean audio, and that most executives have public facing video and audio already available through earnings calls, conference appearances, and marketing content, this control will never fully close the exposure. It is still worth pursuing selectively for the highest risk individuals in an organization, particularly anyone with standing authority to approve large transactions.

Screen remote hiring candidates for the specific indicators documented in the North Korean infiltration scheme. Watch for reluctance to appear on unscheduled or ad hoc video calls, inconsistent lighting or lag specifically around the face during a video interview, a reference check that resolves unusually quickly or entirely through email, and a candidate whose application arrived through an automated, scripted pattern against your job posting system rather than an organic application. None of these signals alone confirms fraud, but Microsoft’s own detection guidance treats this pattern of signals together as a legitimate basis for additional verification before extending an offer.

Building your defense in thirty days

The verification framework covered throughout this report does not require a large budget or a dedicated security team to implement. It requires a written plan and a firm commitment to following it without exception, and a staged rollout tends to actually get finished where an attempt to fix everything simultaneously often does not.

In the first ten days, establish your codeword and your verification callback policy, and communicate both clearly. Choose a codeword known only to the specific people authorized to request or approve high value transactions, share it through a channel other than email, exactly as the FBI and ABA’s joint guidance recommends, and write down, in one page, the specific rule that any request to move money or change payment instructions gets verified through a phone number already on file, never a number provided in the request itself. This single control, implemented alone, addresses the largest share of the financial loss categories documented throughout this report.

In the next ten days, formalize segregation of duties for any transaction above a threshold your organization defines, and extend your vendor payment change policy to require the same callback verification covered above. For a small firm or team where the same one or two people currently hold both initiation and approval authority for most transactions, this step may require genuinely rethinking who is authorized to do what, which is precisely why it deserves its own dedicated ten day window rather than being rushed alongside the codeword rollout.

In the final ten days, apply the hiring stage screening indicators covered earlier in this report to your current recruiting process, and run one live verification drill. Update your interview and reference check process to specifically watch for the North Korean infiltration scheme indicators covered earlier in this report, reluctance to appear on unscheduled video calls, unusually fast reference resolution, applications arriving through automated patterns. Then run a single, low stakes internal drill, having one team member place a deliberately suspicious sounding request to another, to confirm the codeword and callback habits established in the first twenty days actually get followed under real, if simulated, pressure, rather than existing only on paper.

By the end of thirty days, most organizations following this path have moved from having no structural defense against the fraud categories documented throughout this report to having the same core controls, a codeword, a callback verification habit, and segregated transaction authority, that already appear, in one form or another, behind nearly every successfully defended case referenced in the research for this report.

A sample tabletop exercise to test your defenses

Reading a verification policy is not the same as testing whether it survives contact with a genuinely convincing, well timed request. A short, low stakes tabletop exercise, run periodically rather than once, closes that gap.

Assign one person to play the attacker and one to play the target, with a facilitator observing. The attacker’s job is to construct a plausible, moderately urgent request using only information a real attacker could reasonably gather about your organization, a client name, a transaction type, a plausible dollar figure, without access to any information that would only be available to a genuine insider. The target’s job is to respond exactly as they would in a real situation, not as they know they are supposed to respond given that this is an exercise.

Run at least one scenario matching each of the three attack types most relevant to your organization from this report. For most law firms, that means a wire transfer redirection request styled after the real estate closing scheme covered earlier in this report, a voice call impersonating a partner or client requesting an urgent action, and a vendor payment change request. For most finance and operations teams, substitute a vendor impersonation scenario and an executive impersonation request for a policy or personnel change alongside the wire transfer scenario.

Debrief immediately afterward, focusing on what specifically triggered or failed to trigger the verification habit, not on assigning blame. The useful output of this exercise is not a pass or fail grade for the specific person who played the target. It is a concrete answer to the question this report has returned to throughout: did the codeword get requested, did the callback happen through an independently obtained number, and if not, specifically why not, in this person’s own words, in this specific moment. That answer is what reveals whether your written policy actually functions under realistic pressure or only exists on paper.

Repeat this exercise on a fixed schedule, and vary the scenario each time. A single tabletop exercise run once during onboarding provides a snapshot. A repeated, varied exercise, run quarterly for a firm handling frequent high value transactions, builds the same kind of durable, tested muscle memory the phishing simulation research cited earlier in this report found meaningfully reduces real world susceptibility over time. Firms that have run this exercise several times consistently report the same finding: the first run surfaces gaps nobody anticipated, often in the handoff between departments rather than within any single person’s individual judgment, and each subsequent run closes a smaller, more specific gap than the one before it, which is itself a useful signal that the underlying process is maturing rather than stalling.

What this actually costs, compared to what it prevents

Every control recommended in this report is inexpensive relative to the losses documented throughout it, and it is worth stating that comparison plainly, because cost is often the unstated reason a smaller firm or team delays implementing verification habits that are, in practice, close to free.

A codeword costs nothing to establish beyond the time it takes to agree on one and communicate it. A callback verification policy costs nothing beyond the modest inconvenience of an extra phone call before a large transaction proceeds, a cost measured in minutes against the average enterprise deepfake loss of close to 500,000 dollars documented earlier in this report. Segregation of duties may require redistributing existing authority among staff already on payroll, rather than hiring anyone new, for the large majority of small and mid size organizations this report is written for. None of the primary defenses covered in this report require purchasing detection software, hiring a dedicated security analyst, or engaging an outside consultant, though all three are reasonable investments for an organization with the budget and risk profile to justify them.

Set against that near zero implementation cost, the loss figures throughout this report tell their own story: a 243,000 dollar CEO voice clone loss, a 255,000 dollar real estate down payment, a 12 million dollar commercial mediation fraud, and a 25.6 million dollar deepfake video call loss, every one of which the verification habits in this report would very plausibly have stopped, based on the specific mechanics documented in each case. The asymmetry between the cost of the defense and the scale of the loss it prevents is, across every case study gathered for this report, not a close call.

Beyond the first response: building a fraud resilient organization year round

The thirty day plan above establishes the core defense. Sustaining it requires the same ongoing discipline any organizational habit needs to survive contact with a busy, distracted workday months after it was first introduced.

Run a brief refresher on the verification framework at a fixed interval, not only after an incident occurs. KnowBe4’s own research on phishing specific training, cited earlier in this report through the broader AI phishing statistics, found that regular, ongoing simulation and training reduced phishing susceptibility from a baseline above 33 percent to below 5 percent within a year, an improvement curve that depends specifically on repetition rather than a single onboarding session that is never revisited.

Rotate your organization’s codeword on a defined schedule, and treat a codeword that has never changed as effectively public information. A codeword shared once during onboarding years ago and never discussed again has had ample time to be mentioned in a meeting, written in an old email, or simply forgotten by the people meant to rely on it. Treat it the same way you would treat a shared password, with a defined rotation schedule rather than an indefinite lifespan.

Reassess your organization’s public facing audio and video exposure periodically, particularly for anyone with standing transaction approval authority. New conference appearances, podcast interviews, and marketing video get published regularly, and each one is potential raw material for the voice cloning attack type covered earlier in this report. This does not mean avoiding public visibility entirely, which is rarely realistic for a firm’s leadership, but it does mean periodically asking whether newly published material meaningfully increases a specific individual’s exposure, and adjusting that individual’s verification requirements accordingly if so.

Revisit this report’s threat categories against your own organization’s actual risk profile at least annually, given how quickly the underlying technology and the fraud schemes built on it have moved even across the research period covered in this single report. A verification framework built around today’s threat categories may need updating as new attack types emerge, the same way the North Korean infiltration scheme documented in this report evolved from static photo substitution to real time deepfake video within a few years of first being identified.

What to do in the first hours after a suspected fraud

Speed is the single largest factor separating a recovered loss from a permanent one throughout this report, and having a written plan before an incident happens is what makes fast action possible when judgment is least reliable.

Contact your bank immediately and request a wire recall, before doing anything else. Every hour funds sit in a receiving account before being moved onward increases the odds they can still be stopped. Banks can sometimes recall a wire within the first 24 to 72 hours if the funds have not yet cleared the receiving institution, a window that closes quickly and does not wait for an internal investigation to conclude first.

File a complaint with the FBI’s Internet Crime Complaint Center at IC3.gov immediately, not after internal review. This is what activates the FBI’s Recovery Asset Team, the unit responsible for the 3,900 wire recovery actions and 58 percent success rate documented earlier in this report. The window for this team to act closes as funds move through the international banking system, and internal deliberation before filing directly reduces the odds of recovery.

Preserve every communication related to the incident exactly as received, without deleting or forwarding in a way that alters the original. The email, call log, or video recording connected to the fraud is the evidence that both law enforcement and, if applicable, your cyber insurance carrier will need, and it is also what will let your own IT or outside security team determine which of the four threat profiles covered earlier in this report you are actually dealing with.

Notify every other party who might also be a target from the same attacker, immediately. If a fraudulent wire instruction reached you through a compromised email account belonging to a title company, a client, or a vendor, that same compromised account is very likely being used to target other people in the same transaction or relationship simultaneously. Silence to protect your own reputation in this moment actively increases someone else’s exposure.

For a law firm specifically, loop in your malpractice carrier and, where trust funds are involved, your state bar’s client protection or trust account guidance early, not as a last resort. Given the professional responsibility exposure discussed earlier in this report, treating this as a purely operational security incident rather than a matter with professional conduct implications is a common and costly mistake.

File a police report with local law enforcement, even when the financial loss has already moved beyond local jurisdiction. This creates the official record insurance claims and any eventual civil recovery effort will require, and it is a formal step many victims skip specifically because the crime feels too large or too fast moving for local police to meaningfully help with.

Where the money actually goes, and why recovery gets harder by the hour

Understanding the path a fraudulently obtained wire transfer typically takes helps explain both the FBI Recovery Asset Team’s success rate and its limits.

An isometric diagram shows a stack of coins flowing from a victim account through a chain of intermediate mule accounts arranged like descending platforms, crossing a dotted international border line partway down, with a clock icon showing elapsed hours at each stage and a padlock icon marking the point past which recovery odds fall sharply
An isometric diagram shows a stack of coins flowing from a victim account through a chain of intermediate mule accounts arranged like descending platforms, crossing a dotted international border line partway down, with a clock icon showing elapsed hours at each stage and a padlock icon marking the point past which recovery odds fall sharply

Funds obtained through the wire fraud and business email compromise schemes documented in this report rarely sit still. They typically move first into a domestic mule account, often belonging to an individual recruited, sometimes unknowingly, through a fraudulent job offer of their own, who then forwards the funds onward, taking a cut, before the trail crosses an international border into a jurisdiction with weaker mutual legal assistance cooperation. This is why the FBI’s Recovery Asset Team’s success rate applies specifically to funds still inside the US banking system, and why that same success rate falls close to zero once funds clear internationally, a distinction covered earlier in this report and worth restating here because it directly determines how a victim organization should prioritize its first hours of response.

The domestic mule account layer is also where a meaningful share of law enforcement disruption actually happens. The sentences documented earlier in this report’s timeline, against two American facilitators who hosted company laptops for a North Korean IT worker scheme, targeted exactly this layer of the operation, the domestic participants whose bank accounts and physical presence in the United States made them identifiable and prosecutable in a way an overseas operative often is not. For an organization that has been defrauded, understanding this structure explains why some recovery efforts succeed even after funds have technically left a victim’s own account: the money has not yet left the country, and every hour of delay in reporting narrows that window meaningfully.

Common myths about detecting AI fraud, corrected

A handful of persistent, well intentioned pieces of advice about spotting AI fraud no longer hold up against the research covered throughout this report, and repeating them uncritically can create false confidence.

Myth: bad grammar and awkward phrasing are reliable warning signs. This was genuinely useful advice for a decade, and it is no longer accurate. The 82.6 percent AI content prevalence and 54 percent click through rate findings documented earlier in this report exist specifically because AI generated phishing eliminates the linguistic tells this advice was built around.

Myth: a video call is sufficient identity verification for a high stakes request. The Arup case covered in our companion guide to AI agent risk, and the real time deepfake capability documented throughout this report, both directly contradict this assumption. A video call is evidence of a face and a voice, not evidence of a specific real person, once real time deepfake tools are this accessible.

Myth: only large, high profile organizations get targeted this way. The data throughout this report, particularly the finding that criminal groups are shifting deliberately toward mid sized organizations and the ten to fifty person law firm profile specifically, directly contradicts this. Smaller organizations are, if anything, an increasingly deliberate target precisely because they are less likely to have built the defenses this report recommends.

Myth: detection software will catch what a person misses. The gap between 96 percent laboratory accuracy and 45 to 50 percent real world accuracy documented earlier in this report shows detection technology is not yet a reliable safety net on its own. It is a useful supplementary tool, not a substitute for the structural verification habits this report recommends.

Myth: this is primarily a consumer problem, not a business risk. The 893 million dollar FBI figure, the 3 billion dollar BEC figure, the 275 million dollar real estate fraud figure, and the 3.7 billion dollar global deepfake estimate documented throughout this report are overwhelmingly composed of business and professional losses, not individual consumer scams, even though consumer facing coverage of this topic often focuses on the latter.

The road to 2027

Every trend documented in this report points in the same direction, and it is worth looking at that trajectory directly rather than only at the current snapshot.

A rising line chart climbs sharply from left to right across a horizon labeled 2024 through 2027, crossing three labeled milestone markers along the way, with the line's shadow cast forward past the current data point into a projected, dotted continuation toward a 40 billion dollar mark
A rising line chart climbs sharply from left to right across a horizon labeled 2024 through 2027, crossing three labeled milestone markers along the way, with the line’s shadow cast forward past the current data point into a projected, dotted continuation toward a 40 billion dollar mark

Deloitte’s Center for Financial Services projects that generative AI enabled fraud losses in the United States alone could reach 40 billion dollars annually by 2027, up from a base of several billion dollars only a few years earlier, a trajectory researchers describe as consistent with, not more alarmist than, the growth curves already documented throughout this report, according to figures cited by Brightside AI’s fraud research. The deepfake detection market itself, the industry built specifically to counter the threats in this report, is projected to reach 15.7 billion dollars by 2026, according to the same Deloitte research cited by StationX, a scale that reflects genuine, well funded investment in defense rather than an unaddressed problem.

None of this trajectory is fixed. Every dollar figure in this report describes what happened when verification habits had not yet caught up to the technology. The gap this report has documented throughout, between how convincing these attacks have become and how simple the defenses that still stop them remain, is closing in both directions at once: the attacks are getting more convincing, and the organizations that have adopted the verification framework covered in this report are seeing it work. The FBI’s own 58 percent wire recovery success rate, the codeword defense specifically validated by federal guidance, and the segregation of duties principle already standard in well run finance departments are not new inventions. They are old, boring, reliable controls that happen to be exactly as effective against an AI generated deepfake as they were against a much less sophisticated con decades earlier, because they were never built to detect a fake. They were built to make a fake unnecessary to detect in the first place.

Where this report connects to the rest of this series

This report has focused on a different threat direction than our companion guides: not the risk that your own AI tools expose your data, but the risk that someone else’s AI is being used against you directly. The two threats are more connected than they first appear.

Every attack type documented in this report depends on raw material, a voice sample, a writing style, an organizational chart, a client list, that has to come from somewhere. Our companion guide on cloud AI risk documents how much of that exact material routinely ends up sitting on a third party vendor’s servers, accessible to a breach, a subprocessor, or simply a less careful employee than the rest of the firm. An organization that minimizes how much of its own sensitive material lives inside a broad, cloud connected AI system is not just protecting that data from a privacy violation. It is shrinking the raw material available to build a convincing deepfake, a targeted phishing email, or a synthetic identity aimed at that same organization. This is not the primary reason to run AI locally, and this report is not the place to relitigate the fuller case made throughout the rest of this series. It is a genuine, secondary benefit worth naming plainly: less of your firm’s material circulating through systems you do not control is less material available to whoever eventually decides to impersonate you.

The agentic AI risks covered in our second companion guide intersect with this report even more directly. An AI agent with broad, standing access to your email, calendar, and payment systems, the exact configuration that guide warns against, is not only a privacy risk. It is a considerably faster, less supervised channel for exactly the kind of urgent, convincing seeming request this report’s fraud categories are built to exploit, should that agent itself ever be compromised or manipulated through the prompt injection techniques our companion guide documents in detail. The verification habits recommended throughout this report, a human checkpoint in front of any irreversible action, segregation between initiating and approving a transaction, apply with equal force whether the convincing request came from a deepfake human or a manipulated AI agent.

A glossary of terms in this report

Deepfake. Synthetic audio, video, or image content generated or altered by AI to convincingly depict a real person saying or doing something they did not actually say or do.

Voice cloning. A specific category of deepfake that synthesizes a target’s speaking voice from a sample of their real recorded speech, now achievable from as little as three seconds of clean audio.

Vishing. Voice phishing, meaning a fraudulent phone call designed to extract money, credentials, or sensitive information, increasingly enhanced by a cloned voice impersonating someone the target trusts.

Real time deepfake, or live inference. A synthetic video overlay applied to a live video feed as it happens, rather than a prerecorded clip, making the fake responsive to real time conversation and considerably harder to detect than static or prerecorded synthetic media.

Liveness detection. A security technique intended to confirm that a video or image feed shows a genuinely live, present person rather than a photo, recording, or synthetic overlay, increasingly challenged by real time deepfake tools that route a synthetic feed through a virtual camera the target system cannot distinguish from a genuine one.

Business email compromise, or BEC. A fraud scheme in which a criminal compromises or convincingly spoofs a legitimate email account or identity to trick an organization into making an unauthorized wire transfer or divulging sensitive information, without relying on malware or a malicious link.

Synthetic identity. An identity constructed by combining real and fabricated personal information, or generated by AI entirely, used to pass identity verification checks for fraudulent purposes such as employment, account opening, or credit applications.

Proof of life scam. An extortion scheme in which criminals generate a fake video or audio clip appearing to show a kidnapped or endangered person, built from that person’s own publicly available photos or videos, to pressure family members into paying a ransom for a kidnapping that never occurred.

Injection attack, in the identity verification context. An attempt to bypass an identity verification system by feeding a synthetic or manipulated image or video directly into the system’s data pipeline, rather than presenting it to a physical camera.

Recovery Asset Team. A specialized unit within the FBI’s Internet Crime Complaint Center dedicated to rapidly intercepting fraudulently wired funds before they clear internationally, activated by promptly filing a complaint at IC3.gov.

Phishing as a service. Prepackaged phishing kits and infrastructure sold or rented to criminals, lowering the technical skill required to launch a convincing, personalized phishing campaign at scale.

Fraud as a service, more broadly. The commoditization of fraud enabling tools, voice cloning, deepfake generation, phishing kits, and ransomware, into ready made products a criminal can rent or purchase rather than build, a structural shift this report identifies as the primary driver behind the growth documented throughout.

Frequently asked questions

How much has AI enabled fraud actually cost so far?
The most rigorously audited figure is the FBI’s own 2025 count, 893.35 million dollars in confirmed losses across 22,364 complaints, the first year the Bureau tracked AI enabled fraud as a distinct category. Broader industry estimates that include unreported and indirectly attributed losses, such as a 2026 study putting global deepfake fraud losses at 3.7 billion dollars, are considerably higher, and this report treats the FBI figure as a conservative floor rather than a complete accounting, consistent with the Bureau’s own description of it.

Can AI voice cloning really work from just a few seconds of audio?
Yes. Multiple independent sources, including McAfee’s widely cited research, confirm a usable voice clone with roughly 85 percent accuracy can be built from about three seconds of clean source audio, a threshold that has dropped sharply from the many minutes of source material earlier voice cloning tools required.

Is it true that people can no longer reliably detect deepfakes at all?
Controlled research supports this directly. iProov’s testing of consumers specifically instructed to look for fakes found only 0.1 percent correctly identified every sample, and video deepfakes specifically were caught only 24.5 percent of the time. This report’s verification framework is built around this finding rather than around asking people to get better at spotting fakes.

What is the North Korean fake job applicant scheme, in plain terms?
North Korean state sponsored operatives, tracked by security researchers under the name FAMOUS CHOLLIMA, use real time AI deepfake video during live job interviews to secure remote positions, primarily in IT roles, at companies worldwide, generating revenue that funds North Korea’s weapons programs. As of July 2026, eleven allied governments have jointly confirmed this as an active, global threat.

Does a codeword really stop a deepfake voice or video call?
Yes, and this is precisely why federal law enforcement specifically recommends it. A codeword is not something a deepfake, however visually or vocally convincing, can produce without already knowing it, because it depends on shared information rather than a reproducible appearance or sound.

What should a law firm do differently because of the risks in this report?
Beyond the general verification framework covered throughout this report, firms handling trust or escrow funds should treat wire transfer verification as a professional responsibility matter, not solely a security practice, and firms hiring remote staff should apply the interview stage scrutiny recommended in this report’s discussion of the North Korean infiltration scheme.

Is my cyber insurance likely to cover a loss from one of these attacks?
Coverage varies significantly by policy and insurer, and this is an actively developing area as insurers respond to the loss data summarized throughout this report. Confirm directly with your carrier whether social engineering, deepfake enabled fraud, and business email compromise are covered under your current policy, and whether coverage depends on having specific verification controls already in place at the time of the loss.

Are AI detection tools worth investing in?
They are a useful supplementary layer, not a primary defense. Given that detection accuracy falls from 96 percent in laboratory testing to 45 to 50 percent in real world conditions, this report recommends treating detection technology as one input alongside the structural verification habits covered throughout, not as a standalone solution.

How fast do I need to act if I suspect a fraudulent wire transfer?
As fast as possible. The FBI’s Recovery Asset Team achieved a 58 percent success rate in 2025, but that rate applies specifically to funds still within the US banking system, a window that can close within 24 to 72 hours and shrinks further once funds move internationally. File a complaint at IC3.gov and contact your bank immediately, before completing an internal investigation.

Is this threat likely to get better or worse over the next few years?
The data in this report points toward worse before better. Deloitte projects US losses from generative AI enabled fraud could reach 40 billion dollars annually by 2027. At the same time, federal guidance, state legislation, and organizational adoption of the verification practices covered in this report are all maturing in parallel, and the practices that already work, discussed throughout this report, do not depend on the underlying AI technology becoming any less convincing to remain effective.

Can criminals really infiltrate a company as a fake remote employee using AI, not just steal from it?
Yes, and this is one of the most significant findings in this report. The North Korean infiltration scheme documented throughout this report has placed operatives inside hundreds of documented US companies using real time AI deepfake video to pass live hiring interviews, with revenue from the scheme funding weapons development programs, according to eleven allied governments’ joint July 2026 advisory.

What is the single most effective defense covered in this report?
Verifying any request to move money or change payment or contact instructions through a channel the requester did not themselves provide, such as calling a phone number already on file rather than one included in the suspicious message. This single habit defeats the mechanism behind the large majority of the financial losses documented throughout this report, regardless of how convincing the surrounding deepfake, email, or phone call happens to be.

Do these attacks require a sophisticated, well funded criminal organization?
Not anymore. The fraud as a service economy documented earlier in this report has lowered the skill and cost barrier dramatically, and Consumer Reports’ own testing found most consumer AI voice tools carry no meaningful safeguard against this exact kind of misuse, meaning a single individual with no specialized technical background can now execute an attack that previously required organized criminal infrastructure.

How does this report relate to the AI privacy risks covered elsewhere in this series?
Our companion guides address what happens when your own organization’s data is exposed through the AI tools you choose to use. This report addresses a different direction entirely: what happens when someone else’s AI is used against you, regardless of which tools your own organization has adopted. The two risks share a common root, since data exposed through the risks covered in our other guides often becomes raw material for the fraud attacks covered in this one.

Is there any way to stop being a target of these schemes entirely?
No, and this report does not claim otherwise. The verification framework covered throughout this report is built around making attacks unsuccessful once attempted, not around preventing an attempt from happening in the first place, which is a more realistic and considerably more achievable goal given how cheaply these attacks can now be launched.

The numbers from this report, in one place

  • 893.35 million dollars, the FBI’s audited total for AI enabled fraud losses in 2025, across 22,364 complaints, the first year the Bureau tracked the category separately.
  • 3.046 billion dollars, total business email compromise losses reported to the FBI in 2025, the second highest crime category by dollar loss after investment fraud.
  • 3.7 billion dollars, a broader 2026 industry estimate of global documented deepfake fraud losses, with about 89 percent recorded in 2025 and the first half of 2026 alone.
  • 40 billion dollars, Deloitte’s projection for annual US losses from generative AI enabled fraud by 2027.
  • 54 percent versus 12 percent, the click through rate for AI generated spear phishing compared to generic phishing, per the Harvard human subjects study cited throughout this report.
  • Three seconds, the amount of clean audio needed to build a working voice clone with roughly 85 percent accuracy.
  • 0.1 percent, the share of consumers who correctly identified every real and synthetic sample in controlled deepfake detection testing, even after being specifically told to look for fakes.
  • 62 percent, the share of organizations surveyed by Gartner that had already experienced at least one deepfake enabled attack in the prior year.
  • 47 percent, the share of all state sponsored hands on keyboard intrusions against US technology companies attributed to the FAMOUS CHOLLIMA group behind the North Korean fake applicant scheme.
  • 58 percent, the FBI Recovery Asset Team’s success rate intercepting fraudulent wires still inside the US banking system in 2025, out of 3,900 recovery actions initiated.
  • 275.1 million dollars, real estate related fraud losses in 2025, nearly 60 percent higher than the year before.
  • 39 percent, the share of the FBI’s 2025 AI fraud losses attributed to adults aged 60 and older, the single largest age bracket affected.

The bottom line

Every attack type in this report shares the same underlying story: a technology that used to require rare skill and real patience is now cheap, fast, and available to anyone with basic intent. A voice clone that once required minutes of clean audio and specialized software now needs three seconds and a free tool. A convincing fake job applicant that once required a skilled operative willing to sit through an awkward, obviously scripted interview now passes a live video call in real time. A phishing email that once carried tell tale grammatical errors now performs as well as an attack written by a trained human expert.

None of this means the fight is unwinnable, and the data throughout this report is specific about why. Every large loss documented here, from a 243,000 dollar voice clone to a 25.6 million dollar deepfake video call, traces back to the same avoidable gap: a verification step that already existed somewhere in the organization’s own thinking, but was not actually required, in writing, without exception, at the moment it mattered most. A codeword. A callback to a known number. A second approver for a large transfer. These are not sophisticated defenses. They are the same basic disciplines that have stopped confidence fraud for generations, applied deliberately to a threat that has gotten dramatically better at everything except defeating them.

It is worth being honest, in closing, about what this report cannot promise. No verification framework, however well implemented, reduces the probability of a targeted, well resourced attack to zero, and readers who finish this report expecting a guarantee will not find one here, because none of the research gathered for this report supports one. What the evidence does support, consistently across every attack type documented above, is a much narrower and more defensible claim: an organization that has implemented the codeword, callback, and segregation of duties habits covered throughout this report is meaningfully harder to defraud than one that has not, and every large loss in this report’s case studies occurred at an organization missing at least one of those three basic controls at the moment it mattered. That is not a guarantee. It is, based on everything gathered for this report, the best available evidence of what actually works.

Heading into 2027, the organizations that come out ahead will not be the ones with the most expensive detection software. Based on every case study gathered for this report, they will be the ones that treated a codeword, a callback policy, and a segregated approval chain as non negotiable, boring, and permanent, rather than as a project to get to eventually. If your firm or business has read this far without those three things already in writing, the thirty day plan earlier in this report is a reasonable place to start today, not next quarter.

The oldest defense in this report is also, in the end, the most durable one. Long before AI, long before email, a careful business already understood that a large financial decision deserved a second look, a trusted verification, and a moment of deliberate friction before it became irreversible. Every technology covered in this report is new. The discipline that stops it is not, and that is precisely why it still works.

Nine attack types at a glance

For anyone who wants the condensed version of every attack type covered in this report in one scannable place, here it is, organized by mechanism and primary defense.

Attack typeHow it worksPrimary defense
Voice cloning and vishingA cloned voice, built from as little as three seconds of audio, delivers an urgent request by phoneCodeword confirmed on the call, plus callback to a known number
Real time video deepfakesA synthetic face is mapped live onto a video call, defeating visual identity confirmationOut of band verification, never trust the video call alone for high stakes requests
AI written phishing and BECGrammatically flawless, personalized emails impersonate a trusted party to request a transferCallback verification for any payment or instruction change, never reply to the message itself
Fake job applicantsReal time deepfake video defeats live hiring interview screening to place a fraudulent employeeUnscheduled video contact, independent reference checks, hiring pattern monitoring
Closing and escrow wire fraudA compromised email thread is monitored for weeks before fraudulent wire instructions are insertedVerbal confirmation of wire instructions through a number obtained before the transaction began
AI generated malwareAutonomous or AI assisted tools handle reconnaissance, lateral movement, and encryption with minimal human inputStandard technical controls plus rapid detection, since this attack type targets networks, not judgment
Synthetic identitiesFabricated or AI generated identity documents and photos defeat document based verificationVerification methods beyond static document review, layered identity checks
Romance and confidence fraudA sustained synthetic persona builds trust over weeks or months before requesting fundsFamily and advisor awareness, particularly for older clients managing funds independently
Vendor and counterparty impersonationA trusted external relationship is impersonated to request a change to payment detailsThe same callback verification applied to internal requests, extended to every vendor relationship

Every row in this table points back to the same small set of underlying defenses covered throughout this report: verification through an independently obtained channel, a codeword for high stakes requests, and a structural pause built into the process itself rather than a reliance on any individual’s ability to personally detect a fake in the moment. That repetition is the point. Nine different attack mechanisms, one durable set of defenses.

Sample verification policy language

For readers who want to move directly from this report’s findings to a written internal policy, here is starting language, built directly from the verification framework covered throughout this report, adaptable to your organization’s specific structure.

For a wire transfer and payment change policy: “No wire transfer, ACH payment, or change to existing vendor or client payment instructions shall be executed based solely on an emailed, texted, or verbally received instruction, regardless of the apparent seniority or urgency of the request. Before any such transfer or change is executed, the requesting party’s identity and the instruction itself must be confirmed through a real time phone call placed to a number independently obtained from a source other than the message or call containing the request, such as a number already on file prior to the request. This requirement applies without exception, including for requests that appear to originate from a firm partner, executive, or long standing client.”

For a hiring and remote onboarding policy: “All candidates for remote positions, and particularly positions granting access to client data, financial systems, or firm networks, shall undergo identity verification beyond a single scheduled video interview, including at minimum one unscheduled or ad hoc video contact and independent verification of at least one professional reference through a channel other than contact information supplied by the candidate. Recruiting staff shall be trained to recognize and escalate the specific behavioral indicators associated with fraudulent remote hiring schemes, including reluctance to appear on camera outside scheduled interviews and application patterns inconsistent with organic candidate sourcing.”

For an incident response policy specific to suspected fraud: “Upon reasonable suspicion that a transaction, communication, or hiring decision may involve AI generated impersonation or fraud, the responding employee shall immediately notify [named incident response owner], who shall, without awaiting full internal investigation, contact the firm’s bank to request a transaction hold or recall where applicable, file a report with the FBI Internet Crime Complaint Center at IC3.gov, and preserve all related communications in their original, unaltered form. Where client trust or escrow funds are implicated, [named incident response owner] shall additionally notify the firm’s malpractice carrier and relevant state bar authority without delay.”

These templates are starting points, not finished legal language, and should be reviewed by your own counsel before adoption, consistent with this report’s earlier note that nothing here constitutes legal advice. They are built specifically to translate the verification framework covered throughout this report into concrete, checkable organizational commitments, the same way a written security policy only protects an organization to the extent it is actually followed rather than simply drafted.

About this report

This report draws on FBI Internet Crime Complaint Center data, joint federal guidance from the NSA, CISA, and the American Bankers Association, peer reviewed academic research, and dated industry threat research from security firms including CrowdStrike, Palo Alto Networks’ Unit 42, Mandiant, Sysdig, and Sumsub, current as of the research window in the third quarter of 2026. Where figures from different sources disagreed, as happened repeatedly with widely circulated deepfake loss estimates during this research, we prioritized the FBI’s own audited figures and labeled broader industry estimates explicitly as estimates, a distinction covered directly in this report’s discussion of what the audited numbers actually show versus the larger, less rigorously sourced figures that often circulate alongside them. This report is not legal advice, and organizations facing an active suspected fraud should consult qualified counsel and law enforcement directly rather than relying on this report alone. Fraud tactics and the guidance meant to counter them continue to evolve, and readers should treat the verification framework in this report as a durable starting foundation, consistent with the decades old confidence fraud principles it is built on, rather than a complete or final answer to a threat category that, as this report has shown throughout, is still actively changing.

Sources and further reading

Every claim and statistic in this report is drawn from a named, dated, publicly available source, organized below by topic for anyone who wants to verify a figure or read further into a specific attack type.

Official government and law enforcement sources

AI enabled fraud losses and general statistics

Deepfake and voice cloning research

The North Korean fake applicant scheme

AI generated phishing and business email compromise

Law firm and real estate wire fraud

AI generated malware and ransomware

Defense guidance and verification protocols

Leave a Comment