Deepfake CEO Fraud — The Next Wave of Business Email Compromise

In January 2024, a finance employee at Arup, a global engineering firm, joined a video call with who he believed were multiple senior colleagues, including the company’s CFO. Everyone appeared on camera. Everyone sounded right. By the end of the call, he had authorised 15 wire transfers totalling $25.6 million.

Every face on that call was an AI-generated deepfake. Every voice was synthetic. The employee had initially suspected phishing. The live video call removed his doubt entirely.

This case established the operational template for a new generation of financial fraud that is now targeting businesses at scale. In Q1 2026, AI-generated voice or video deepfakes were involved in approximately 40% of all business email compromise incidents; up from under 5% in 2023. A voice can be cloned convincingly from as little as three seconds of publicly available audio.

This is no longer a theoretical threat. It is happening to businesses right now, every day, at a rate that conventional fraud awareness training was not designed to address.

The Numbers Behind the Threat

The scale of deepfake CEO fraud in 2026 demands attention:

Deepfake fraud grew 3,000% in North America and now accounts for 6.5% of all fraud. The FBI’s 2025 Internet Crime Report logged 24,768 BEC complaints totalling $3.05 billion in losses, with AI-assisted deepfake involvement growing from under 5% of incidents in 2023 to 40% of incidents by Q1 2026. Average losses from AI-augmented BEC now exceed $4.1 million per incident — more than three times the $1.3 million average for traditional email-only BEC. CEO deepfake fraud now targets approximately 400 companies per day. Vishing and voice phishing grew 442% between the first and second half of 2024, and the first half of 2026 ran at twice the volume of the second half of 2025. US deepfake fraud losses reached $1.1 billion in 2025. Only 5% of voice clone victims ever report losses to authorities — meaning official figures represent a significant undercount of actual harm.

These numbers represent a fraud category that has moved from rare, sophisticated attacks on high-value targets to a commodity fraud technique deployed against organisations of every size.

How Deepfake CEO Fraud Actually Works

Understanding the attack requires understanding three distinct delivery mechanisms, each of which has matured significantly in 2026.

Voice Cloning — The Phone Call That Isn’t Real

Voice cloning is the most widely deployed deepfake fraud technique because it is the simplest. Modern AI voice synthesis tools can produce a convincing clone of a target’s voice from as little as three seconds of publicly available audio — a LinkedIn video, a company earnings call recording, a podcast appearance, a YouTube interview.

The attack flow is straightforward. The attacker identifies a target — typically a CFO, CEO, or senior finance official whose voice is available publicly — and generates a voice clone using a commercial AI service. They then call an employee with payment authority, impersonating the executive. The call appears to come from the executive’s number (caller ID can be spoofed trivially). The “executive” explains that an urgent, confidential wire transfer is needed — a time-sensitive acquisition, a regulatory payment, a sensitive supplier arrangement that cannot go through normal channels. The employee is told to act immediately and not discuss it with others.

This technique exploits the authority-compliance dynamic that phishing has always leveraged — but layered over a medium (a voice call) that employees have been conditioned to treat as a higher-trust channel than email. When the voice sounds exactly right, the brain’s fraud detection mechanism is largely bypassed.

A Swiss businessman transferred several million Swiss francs in January 2026 after a series of calls with what he believed was a trusted business partner — later confirmed to be a voice clone.

Deepfake Video Calls — The Meeting That Never Happened

The Arup case established that deepfake attacks are no longer limited to audio. Fully synthetic video calls — in which every participant is AI-generated and appearing to speak and move in real time — have become operationally viable.

The technology required has dropped in cost and complexity dramatically. Real-time deepfake video tools that can overlay a synthetic face onto a live video feed are now commercially available. The attacker needs source material — video footage of the impersonated executive — which is typically abundant in the age of corporate video content, conference recordings, and social media.

The attack scenario mirrors the Arup case: an employee receives a meeting invitation that appears to come from internal systems, joins what appears to be a Teams or Zoom call with senior colleagues, and is instructed to authorise a financial transaction. The presence of video — and multiple apparently real participants — overcomes the scepticism that a text-only or voice-only request might trigger.

62% of security leaders reported experiencing a deepfake attack in the prior 12 months in Gartner’s 2025 survey. Real-time video deepfakes represent the most dangerous evolution of this threat because they exploit the one verification mechanism employees had left: seeing someone on camera.

AI-Generated Email and Chat — The Impersonation at Scale

The third vector is lower-profile but higher-volume. AI-generated text — trained on a target’s writing style using samples from leaked emails, public posts, or corporate communications — can produce BEC emails that are grammatically flawless, contextually appropriate, and stylistically convincing. Unlike early BEC emails that were often detectable through poor grammar or awkward phrasing, AI-generated impersonation emails match the target’s vocabulary, sentence structure, and communication patterns.

This technique is most dangerous when combined with thread hijacking — where an attacker who has compromised a mailbox uses existing legitimate email threads as context for a fraudulent payment request. The combination of a real email thread, a syntactically perfect message, and a plausible business context makes AI-enhanced thread hijacking extremely difficult to detect.

81% of businesses that had been defrauded in a 2026 KPMG Canada survey said generative AI was used in the attack.

Why Traditional Defences Are Failing

The security controls that organisations deployed against first-generation BEC — email gateways, DMARC, user awareness training — were not designed to address deepfake attacks. Each fails in a specific and predictable way.

Email gateways cannot analyse phone calls or video streams. Deepfake voice and video attacks bypass email security entirely. They exploit communication channels — phone, Teams, Zoom — that email security tools have no visibility into.

Caller ID is not authentication. Phone number spoofing is trivial and requires no technical sophistication. A call appearing to come from the CEO’s mobile number is not evidence that it is the CEO.

Video calls are no longer trustworthy by default. The Arup case demonstrated that real-time video presence cannot be treated as identity verification. An employee being able to see someone on camera is no longer sufficient.

Awareness training has no measurable effect on voice clone susceptibility. Research consistently shows that employees cannot reliably distinguish AI-generated voices from real ones, regardless of training. The human auditory system was not evolved to detect synthetic voice synthesis at the quality levels achievable in 2026.

Urgency and authority override procedural controls. Deepfake CEO fraud specifically targets the moment when an employee receives an urgent instruction from a senior figure they trust. Under those conditions, the inclination to bypass normal approval processes is extremely strong — and awareness training alone is insufficient to counter it.

The Industries Most at Risk

Financial services organisations are primary targets because of their authority-based approval workflows — a single authorised wire transfer can move millions. Manufacturing and engineering firms are targeted because they routinely make large supplier payments that can be fraudulently redirected. Professional services firms — law firms, accountancies, consultancies — handle client funds and high-value transactions that make them attractive targets. Healthcare organisations are targeted both for financial fraud and for the value of the credentials and data that deepfake social engineering can unlock.

Smaller organisations are increasingly targeted precisely because they typically have less sophisticated verification procedures than large enterprises. A 50-person company is less likely to have implemented out-of-band verification protocols for wire transfers than a FTSE 100 firm.

Real Cases in 2026

Arup — $25.6 million (January 2024, template for 2026 attacks) The landmark case. A finance employee authorised 15 wire transfers after a video call in which every participant — including the apparent CFO — was AI-generated. This case is the operational template for the deepfake video call attacks deployed throughout 2025 and 2026.

Swiss businessman — millions of Swiss francs (January 2026) A senior Swiss executive transferred significant funds after a series of calls with what he believed was a trusted business partner. The calls were confirmed to be AI-generated voice clones of the real partner.

US financial institutions — ongoing The FBI’s Internet Crime Complaint Center reports a sustained campaign of deepfake voice and video fraud targeting US financial institutions and their corporate clients throughout 2025 and 2026, with individual incidents ranging from $500,000 to $15 million.

What Effective Defence Looks Like

Because deepfake attacks exploit trust in voice and video rather than email content, effective defence requires procedural controls rather than technical ones. No firewall blocks a phone call. No email gateway analyses a Teams meeting. The defences that work are organisational.

Out-of-Band Verification for All Payment Requests

Any request to initiate, modify, or approve a wire transfer — regardless of the channel through which it arrives, including a video call — must be verified through a separate, independently established communication channel before execution.

This means: if a request comes by phone, verify it by calling back on a number from your verified contact directory — not the number that called you. If a request comes via Teams or email, verify it by calling a known mobile number. The verification must use a different channel than the original request.

This single control defeats deepfake CEO fraud more effectively than any technical tool. An attacker who has cloned the CEO’s voice cannot also intercept a return call to the CEO’s verified number.

Payment Verification Protocols

Establish and enforce a formal payment verification protocol that applies regardless of who is making the request or how urgent it appears. Key elements include:

Dual authorisation — all wire transfers above a defined threshold require approval from two independent authorisers, contacted separately. A request from the CEO does not override this requirement.

Callback verification — any new payee or modified payment instruction requires a callback to a number from the verified supplier database, not the number provided in the request.

Time delay — implement a minimum processing time (24 hours) for new payees and modified payment instructions. Urgency is the primary social engineering lever — a mandatory delay defeats it structurally.

Safe word programme — establish a confidential shared phrase known only to executives and their assistants, to be used when an executive is making an unusual or urgent request. A request that does not include the safe word should trigger enhanced verification.

Reduce the Public Audio and Video Footprint

Voice cloning requires source material. Audit what audio and video of your executives is publicly available — earnings calls, conference presentations, podcast appearances, LinkedIn videos, YouTube content. Consider whether all of it needs to be public. Where executives must appear on video or audio publicly, this cannot be avoided — but awareness of the risk should inform how much content is made available and in what format.

Train Specifically on Deepfake Scenarios

Standard phishing awareness training does not address deepfake fraud. Supplement it with specific training that covers:

  • The existence and capability of voice cloning technology
  • The fact that video calls are no longer reliable identity verification
  • The specific scenario of an urgent payment request from a senior executive
  • The out-of-band verification procedure and when it applies
  • That any request to bypass normal procedures — regardless of how senior the requester appears — is a red flag, not an exception

Run tabletop exercises that simulate deepfake CEO fraud scenarios, including both voice and video attack formats.

Technical Controls That Help

While no technical control is sufficient alone, several contribute to defence:

Voice biometric analysis — some enterprise telephony and contact centre platforms now offer real-time voice authenticity scoring. This can flag AI-generated voice calls, though false negative rates remain significant.

Meeting authentication — Microsoft Teams and Zoom both offer verified identity features. Enable these in your meeting platform settings and train employees to check verification indicators before acting on requests made in meetings.

AI-generated content detection tools — several vendors now offer tools that analyse audio or video for AI generation signatures. These are most useful in forensic investigation after a suspected incident rather than real-time prevention, but they improve with each model generation.

DMARC, SPF and DKIM at enforcement — while these do not address voice or video deepfakes, they prevent your domain from being spoofed in the email component of a hybrid attack and remain essential baseline controls.

The Regulatory and Legal Landscape

46 US states have enacted deepfake-specific legislation as of 2026. In the UK, the Online Safety Act and the Computer Misuse Act both create criminal liability for deepfake-enabled fraud. Directors and officers of organisations that fail to implement reasonable controls against known fraud vectors face increasing personal liability exposure under both UK and US regulatory frameworks.

Organisations that handle client funds or operate in regulated industries — financial services, healthcare, legal services — face additional regulatory obligations around fraud prevention and may be required to demonstrate that specific controls against AI-enhanced fraud have been implemented.

Conclusion

Deepfake CEO fraud represents the most significant evolution in business email compromise since the technique was first documented. It moves attacks from email — a channel with established technical defences — to voice and video, channels for which no equivalent technical defence exists.

The Arup case proved that a sufficiently convincing deepfake video call will defeat an employee’s suspicion even when they have specifically considered the possibility that they are being defrauded. No amount of awareness training reliably overcomes the cognitive authority of seeing and hearing a trusted colleague in real time.

The defences that work are procedural — out-of-band verification, dual authorisation, mandatory time delays, safe word programmes. These controls are not complex or expensive. They require organisational commitment and cultural change: the normalisation of treating any payment request, regardless of its apparent source or urgency, as something that must be independently verified before execution.

The question is not whether your organisation will be targeted. At 400 deepfake CEO fraud attempts per day, the question is whether your verification procedures will hold when it happens.


PhishScout tracks live BEC and deepfake fraud campaigns. Submit suspected phishing at phishscout.net Sources: FBI IC3 2025 Annual Report · BrightSide AI · Gartner 2025 Deepfake Survey · KPMG Canada 2026 · CrowdStrike Global Threat Report 2025 · Pindrop 2025 Voice Intelligence Report · HIT Communications 2026

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *