Eero Nevaluoto
Senior Engineer, Intelligent Group
Eero is a certified cybersecurity professional (Azure Security Operations Analyst, CompTIA CySA+, Security+) who specializes in threat detection and compliance automation.
AI has industrialized fraud. The same models your teams use for productivity now let attackers write flawless phishing at scale, clone a voice from a few seconds of audio, and put a synthetic version of your CFO on a video call. The craft that used to gate these attacks — good grammar, a convincing voice, a believable face — is now a commodity. And executives are the target.
We run managed detection and response for our clients, so we see the downstream of these campaigns. The defense is not a single product. It is a layered posture of technical controls, human training, and process.
Why is AI-generated phishing so much more effective?
AI-generated phishing is more effective because it removes every tell that used to give an attack away. Hoxhunt’s research found that AI-generated phishing achieved roughly a 54% success rate against targets, compared to about 12% for human-written phishing. The emails are fluent, personalized from public data, and produced at a volume no human team could match — four times more effective, at a fraction of the cost.
What does a deepfake attack actually look like?
A deepfake attack impersonates a trusted executive over voice or video to authorize a fraudulent action — usually a wire transfer. The reference case is Arup, the global engineering firm: in 2024, an employee in its Hong Kong office was deceived by a video call in which every colleague present, including the CFO, was an AI deepfake built from public footage. The result was 15 transfers totaling about $25.6 million in a single day, as reported by CNN and Hong Kong police.
Arup is not an outlier; it is a preview. Deloitte’s Center for Financial Services projects that generative-AI-enabled fraud losses in the US could reach $40 billion by 2027, up from $12.3 billion in 2023 — a 32% compound annual growth rate. The economics now favor the attacker.
Why do executives get targeted specifically?
Executives get targeted because they combine authority, public exposure, and transaction power. Their voices and faces are on conference recordings, earnings calls, and YouTube — ample training data for a clone. They can authorize large payments. And staff are conditioned to act fast on an urgent request from the top. That is the exact profile a deepfake fraud is built to exploit.
How do you defend against AI-industrialized fraud?
You defend with layers, because no single control catches all of it. The stack that works:
- Managed detection and response (MDR). 24/7 monitoring catches the account compromise, anomalous access, or lateral movement that often precedes or follows the fraud attempt.
- Out-of-band verification for money movement. Any payment or banking-detail change must be confirmed through a second, pre-agreed channel — a callback to a known number, never the one in the request.
- Continuous phishing simulation and training. Since AI phishing beats untrained users most of the time, the workforce has to be tested against realistic, AI-grade lures, not the clumsy templates of five years ago.
- Verification code words for executives. A shared secret phrase for high-stakes voice or video requests defeats a clone that has the face and the voice but not the word.
- Email authentication and anomaly filtering. Enforce DMARC, DKIM, and SPF, and layer AI-aware email security that flags tone, urgency, and impersonation patterns.
Where does this connect to the rest of your AI posture?
Deepfake and phishing defense is the offensive mirror of the governance work. The same models that create shadow AI risk inside your walls are being weaponized against you from outside, and the identity discipline you apply to agentic AI is the same discipline that limits the blast radius when an executive account is compromised.
Test your defenses against AI-grade attacks
We run MDR, realistic phishing simulation, and executive-impersonation tabletop exercises for mid-market and enterprise clients — so you find out how your people and controls hold up before an attacker does.
The bottom line
The barrier to convincing fraud has collapsed, and the loss curve — from $12.3 billion to a projected $40 billion — is pointed the wrong way. You cannot train your way out of this alone, and you cannot buy a single box that stops it. Layered detection, out-of-band process, and continuous human testing are what keep a synthetic CFO from moving your money.