
By all accounts, AI-driven scams are on the rise in business, taking the forms of deepfake voice calls, video chats. and of course, e-mail.
At least 60% of 200 companies recently surveyed by Experian report fraud losses “somewhat or significantly higher” than previous years, and 77% are responding with larger fraud management budgets. Respondents identified AI-generated phishing attacks as their leading AI-related fraud concern (cited by 53%), followed by AI-assisted first-party fraud (51%), document forgery (45%), automated bot attacks (40%) and deepfake voice scams (37%).
While there isn’t a fixed number of AI scams, “there are a handful of core categories that continuously and rapidly evolve as technology advances,” said Cody Tyler, CISO and managing director at EXOS. “Most AI-driven scams fall into
major categories like impersonation scams, phishing and social engineering, financial and investment scams and business email compromise. AI hasn’t created entirely new scam categories, it’s supercharged existing ones.”
Plus, “the common thread through AI scams is less about who you are and more about what you have access to or how easily you can be convinced,” Tyler added. “Employees with access to money or sensitive systems and organizations with limited cybersecurity resources can find themselves more at risk of being targets.”
For example, with what is known as CEO fraud, “scammers use cloned audio of a company executive’s voice to instruct an employee to wire funds immediately,” said Noe Ramos, vice president of AI operations for Agiloft. “It works because the voice is real, the authority feels legitimate, and urgency short-circuits skepticism. Several companies have lost hundreds of millions to a single phone call.”
Typically, AI scams fall into two categories: hyper-personalized phishing attempts and biometric impersonation,” according to Stanislav Kazanov, head of GRC, cybersecurity and sustainability at Innowise. “The most popular form of phishing is AI-enabled business email compromise, or simply BEC. Years ago, phishing emails were easy to recognize. Things like grammatical errors or weird generic phrases gave them away. Now, you can’t rely on these telltales. Attackers often feed a target’s LinkedIn profile and other publicly available information into an LLM to draft highly context-sensitive emails that mimic the writing mannerisms and style.”
To combat AI fraud, companies are responding with AI to strengthen their defenses, the survey report’s authors observe. Eighty percent of respondents to the Experian survey report using machine learning or generative AI within fraud management environments to help identify suspicious activity, improve identity verification and enhance fraud detection capabilities.
Voice cloning is especially an area of concern. These scams are built on a “three-second audio clip from a voicemail greeting, which is enough for fraudsters to replicate a CEO’s voice and authorize a wire transfer,” said Victor Smushkevich, founder at CallSetter AI. “Someone calls an office mimicking the owner, requests an urgent payment, and the front desk complies because the voice sounds perfect.”
The good news is that defense against voice cloning scams “is brutally simple, Smushkevich added. ”Every financial request over the phone gets a mandatory callback to a verified number, no exceptions. AI-generated voices still stumble on unscripted follow-up questions, so asking something only the real person would know breaks the illusion fast.”
The bad news is that fraudsters keep perfecting the delivery of their malevolent messages, and AI is helping them to do that. “We can talk all day about the AI scam variations, and it will be pointless: by the time that we’re done, schemers would’ve come up with something new,” said Kazanov.
The typical signs people are told to look for, “like lip sync issues, blurry hands, and plastic skin are being patched in real time,” agreed Olga Polishchuk, vice president of investigations at ZeroFox.
Unfortunately, AI-generated scams are shifting as fast as AI itself. “People have starting to be aware of more traditional scam tactics like phishing emails, suspicious texts and robocalls over the years. Fraudsters see we’re on to that, and they’ve moved on,” said Scott Edwards, director of fraud risk management at BOK Financial. In its place, deepfakes are on the rise.
It’s still possible at this point to detect “unnatural speech patterns and visual inconsistencies that can be easily identified when you know what to look for,” said Polishchuk. “Be aware of anything that seems off, like tone and speech. Although AI may mimic a voice, in general it will sound more unnatural and robotic, or there will be an inconsistency between what the person says and how they say it.”
The telltale signs of fake AI or deepfakes include “audio latency, unnatural cadence, visual glitches or lip-syncing that’s a fraction off,” according to Danny Jenkins, who is a former ethical hacker and ransomware responder and currently CEO of ThreatLocker. “The even bigger sign, however, is behavior: urgency, emotional pressure, and requests for money or sensitive information. If the person contacting you is a vendor or loved one, call them directly to check if the communication was real.”
It’s not members of the C-suite getting scammed the most, “but the employees who are trained to execute the C-suite’s requests without asking too many questions,” said Polishchuk. “Additionally, companies are unwittingly onboarding state-sponsored actors as employees, such as North Korean IT workers, which is a target profile no one anticipated before.”
If a scam is detected, the best course of action is to take steps to limit the damage,” said Tyler. “We recommend to our clients first securing all accounts and systems, reporting the incident, assessing the broader impact and notifying affected parties. By following these steps, financial, operational and reputational damage can be reduced.”
There are a range of tools, apps, and services to help shield organizations against AI scams, but “no single, holistic solution that bridges the gaps, even for a single type of content,” said John Maly, an intellectual property expert. “All these tools are still in their infancy. Meanwhile, deepfake AIs continue to find ways to make their fakes less detectable as such.”
The best defense to protect one’s business against AI scams is your brain; we’re entering a new, much less safe era, and we’ll need to reprogram our own behavior to be more skeptical and cautious of any remote interactions with other people. Knowing who you can trust is no longer enough; now you need to ask whether you can trust whether you’re even talking to the person or organization you think.”
