AI-Powered Threats
Greta Hoffmann is head of finance operations at a mid-size pharmaceutical company in Cologne. In November she received an urgent voice message from someone who sounded exactly like her CEO, with the same cadence, the same regional accent, and the same way of trailing off at the end of sentences. The message asked her to approve an emergency wire transfer of €180,000 to a supplier before end of business. She was thirty seconds from approving it when she decided to call the CEO's mobile directly. He had no idea what she was talking about. The voice had been cloned using audio from a public conference recording.
Greta's instinct to verify saved the company. What shook her afterward was not that the attack happened; it was how good it was. She had been targeted by this kind of fraud before, and the old versions were obviously wrong. This one was not. That difference is what this lesson is about, and it is why the detection advice most organizations still teach has quietly stopped working.
Why AI Changes the Threat Equation
Fraud, phishing, and social engineering are not new. What AI has changed is the cost and scale of executing sophisticated attacks. Tasks that used to require skilled humans working for hours, such as crafting a convincing impersonation, personalizing a message to a specific target, or translating content into fluent local language, can now be automated and deployed at scale in minutes. The skill that used to be scarce has been packaged into tools, and packaged skill is cheap.
The result is a shift in two directions at once. Attacks that previously required substantial criminal resources are now accessible to low-sophistication actors, so the volume of credible attacks rises. At the same time, attacks that were already sophisticated have become harder to detect, so the ones aimed at you personally are better than they used to be. This is the core change: the floor of what is possible has dropped dramatically, and every assumption your security training makes about what a bad attack looks like was calibrated against the old floor.
Voice and Video Deepfakes
A deepfake is synthetic media, whether audio, video, or images, generated or manipulated by AI to portray something that did not happen. Deepfakes are produced using deep learning models trained on recordings of the target person, and the training material is usually not hard to obtain: earnings calls, conference presentations, recorded talks, podcasts, and social media video are all public by design. Convincing voice clones now require as little as a few seconds of source audio, which means that anyone who has ever spoken in public has already supplied the raw material.
Voice deepfakes are the most commonly weaponized form right now. The fraud pattern Greta encountered, a voice clone impersonating an executive to authorize a financial transaction, is sometimes called a virtual kidnapping or CEO fraud variant. Multiple organizations have lost six- and seven-figure sums to it. Video deepfakes are harder to produce convincingly, but the gap is closing. Fraudulent video calls using AI-generated faces have already been used in at least one documented case to impersonate a CFO in a Hong Kong company, resulting in a $25 million transfer. As generation quality improves and tools become more accessible, video fraud will become more common.
Why Deepfakes Are Dangerous Beyond Fraud
The financial angle is the most immediate, but it is not the only one. A deepfake video of an executive saying something offensive can damage a reputation even after it has been revealed as fake, because the correction never travels as far as the original and the impression outlasts the retraction. Deepfakes of compromising content can be used for blackmail and extortion against individuals. And there is a slower, more corrosive effect: as synthetic media becomes common, people become less trusting of media in general. Real recordings become disputable, and "seeing is believing" stops being a reliable rule.
The State of Deepfake Detection
Detection is an arms race, and not one defenders are comfortably winning. As detection improves, the people generating deepfakes improve in response. Deepfakes can currently be detected through forensic analysis, but detection is not foolproof, and it requires both time and expertise, neither of which is available to a finance manager holding a voicemail and a same-day deadline. As detection becomes harder and creation becomes easier, the practical conclusion for organizations is that process controls, not media forensics, are what stand between you and this class of attack.
AI-Enhanced Phishing
Phishing, meaning fraudulent messages designed to get you to click a link, reveal credentials, or take an action, is the most common form of cybersecurity attack. It used to be identifiable by obvious signals: poor grammar, generic greetings, suspicious sender addresses, and implausible scenarios. AI removes every one of those signals, because generating fluent, contextually appropriate text is exactly what the technology is best at.
Modern AI-enhanced phishing messages are written in fluent, grammatically correct prose in the target's language. They are personalized with specific details drawn from professional networking profiles, company websites, social media, and previous communications. They are styled to match the communication patterns of the impersonated sender, and they are tailored to the recipient's role, current projects, or recent organizational events. Where traditional phishing cast a wide net and hoped, AI-enhanced phishing lets a single attacker send large volumes of individually personalized messages, which means the economics of targeting high-value victims specifically now work in the attacker's favor.
A spear-phishing campaign, meaning one targeted at a specific individual, used to take a skilled attacker hours per target. AI can now generate thousands of personalized variants in the time it takes to brew coffee. The follow-through has changed too: if the target replies with a skeptical question, the attacker can generate a believable, in-character answer immediately rather than abandoning the attempt. Skepticism that used to end an attack now simply extends the conversation.
The implication is that traditional detection advice, such as "look for spelling mistakes" or "be suspicious of generic language," is no longer sufficient. A message being well-written is no longer evidence that it is legitimate. In fact, unusually polished and unusually well-informed unsolicited contact should now raise suspicion rather than lower it.
Social Engineering at Scale
Social engineering is using manipulation rather than technical exploits to get someone to take an action or reveal information. It works because humans are wired to trust, to respond to authority, and to act under urgency, and none of those tendencies are patchable. What AI adds is the ability to run the manipulation at scale, against many targets at once, with a consistency and patience no human operator could sustain.
Chatbot impersonation. An AI chatbot can impersonate an IT helpdesk, a bank's customer service function, HR, or technical support, engaging in extended, convincing conversations that build trust before making a request. The conversational quality is what separates this from the old scripted approach: a victim who tests the impersonator with an unexpected question receives a plausible answer.
Rapport building over time. Automated systems can conduct long-running relationship communications, gradually escalating requests only after apparent trust has been established. The attack that eventually asks for money may begin far earlier with something entirely innocuous.
Multi-channel coordination. A single campaign can combine an AI-generated phishing email with a spoofed phone call using a cloned voice, creating a coordinated story that feels far more credible than any single channel would. Corroboration across channels is exactly what people use to decide something is real, which is why attackers now manufacture it.
Misinformation and Disinformation
Misinformation is false information spread without intent to deceive, by people who believe it is true. Disinformation is false information spread deliberately to cause harm. AI amplifies both, because it removes the production cost that used to limit how much false content could be created and how well it could be tailored to a particular audience.
Before AI, a disinformation campaign required significant sustained human effort. Now a single operator can generate a large volume of content, each piece tailored to a specific audience, in a fraction of the time it once took. The generation can also be steered: an operator can watch which narratives are spreading and adjust what is produced to maximize reach. Content can be shaped to exploit emotional responses, creating outrage, stoking fear, or amplifying division, which is precisely what makes material spread.
The practical concern for most organizations is not primarily geopolitical, although that matters. It is more immediate: false information about your company, your products, your executives, or your industry can be generated and distributed at scale. A fabricated news article about a product recall. A synthetic audio clip of an executive saying something damaging. A wave of coordinated fake reviews. Monitoring what is being said about your organization online is increasingly necessary and increasingly difficult, because the sheer volume of AI-generated content makes manual review impractical.
AI-Powered Scams Against Individuals
Not every AI-enhanced attack targets a company treasury. Much of the harm falls on individuals, including your employees, and the patterns are worth naming because people who recognize them at home recognize them at work.
- Romance scams. A chatbot engages someone emotionally over an extended period, builds a relationship, and then requests money under a series of pretexts such as an emergency, travel costs, or an investment opportunity. Automation means one operator can sustain many such relationships simultaneously.
- Investment scams. AI generates convincing websites, documents, and testimonials for opportunities that do not exist, and can hold conversations that answer a cautious investor's questions in detail.
- Job scams. Fake job postings recruit victims and then request payment for training, deposits, or equipment. The entire recruitment process, including interviews and correspondence, can be managed automatically.
- Prize and lottery scams. Convincing communications tell people they have won something and must pay a fee to claim it. What has changed is the polish and the scale of delivery.
Recognizing AI-Enhanced Attacks
The traditional advice, such as "if it seems too good to be true" or "watch for bad grammar," still applies but is no longer enough. The signals below still work because they concern context and process rather than the quality of the artifact, and quality is what the attacker now gets for free.
- Urgency that bypasses normal process. "Approve this now before end of business" is a classic social engineering move regardless of how the message arrives.
- An unusual request from a familiar contact. A message from your CEO asking for an action you have never been asked to take before, even when the voice or the writing style seems exactly right.
- Unusual personalization in unsolicited contact. A stranger who knows details about your role, projects, or recent company events that would have taken real research is telling you something about the effort behind the message.
- Perfect language where you would not expect it. Flawless, well-styled prose in unsolicited communication is now a neutral-to-negative signal rather than a reassuring one.
- Slight audio or video inconsistencies. Background noise that does not match the claimed environment, lip sync that is fractionally off, unusual blinking patterns, or odd skin texture.
- A communication channel switch. Starting on email and then asking to move to a personal messaging app or an unmonitored channel is a red flag.
- Requests that would normally require multiple approvals handled by one person. Fraud frequently tries to short-circuit normal controls, and the attempt itself is the signal.
The single most effective defense against AI-enhanced impersonation is establishing a verification channel for sensitive actions. For financial transfers, personnel changes, or access grants above a defined threshold, always verify through a separate, pre-established channel. Call the person on a known number. Do not use contact information supplied by the message itself, because an attacker who controls the message controls that number too. This is what Greta did, and it is the only step in the whole sequence that mattered.
What Organizations Can Do
Individual vigilance is necessary but not sufficient, because vigilance fails predictably under deadline pressure and these attacks are designed to create it. Organizations need structural defenses that do not depend on any one person being alert on a bad afternoon.
Update your security awareness training. If your training still focuses on spotting spelling errors, it is calibrated to a threat that no longer exists. People need to understand voice cloning, personalized phishing, multi-channel attacks, and verification protocols, and they need to understand that a message being well-written proves nothing.
Establish explicit verification procedures for high-risk actions. Wire transfers, system access changes, and HR actions such as salary or bank detail changes should require out-of-band verification regardless of how legitimate the request appears and regardless of who appears to be making it. The procedure has to apply to the CEO, or it protects nobody.
Define a code word or verification question system for voice communications. Some organizations have introduced a simple challenge, a prearranged word or phrase, for high-stakes phone requests. It feels awkward until the day you need it, and the awkwardness is a very small price against the alternative.
Create an easy way to report suspected attacks without penalty. People who feel embarrassed about being targeted, or afraid of looking foolish, are less likely to report suspicious contact, and unreported attempts leave everyone else unwarned. Normalize the conversation, and treat a report about something that turned out to be legitimate as a good outcome rather than a false alarm.
Anti-Patterns
- Training people to look for bad grammar. Language quality was a useful signal when attackers wrote their own messages. Teaching it now actively misleads, because it tells people that a polished message is safe.
- Relying on individual vigilance instead of process. Urgency, authority, and trust defeat attention reliably. Controls that do not depend on someone being sharp at the wrong moment are what actually hold.
- Verifying through the channel that contacted you. Calling the number in the message or replying to the email confirms nothing, because the attacker supplied both.
- Exempting senior people from verification. Executive impersonation is the entire attack pattern. A verification procedure with an exception for the CEO has an exception exactly where the fraud aims.
- Treating deepfake detection as the answer. Forensic analysis takes time and expertise, is not foolproof, and is unavailable to the person holding a same-day payment request.
- Punishing or embarrassing people who report. Every unreported attempt is a warning the rest of the organization does not receive.
- Assuming the threat is only external and financial. Reputational deepfakes, extortion against individuals, and coordinated false content about your products do damage that no payment control prevents.
Practice Prompts
- Audit your own exposure. Find the publicly available recordings of your senior leaders' voices, such as conference talks, recorded webinars, and podcasts. That is the training material an attacker already has, and seeing it listed changes the conversation with leadership.
- Test the payment path. Walk through what would actually happen if an urgent transfer request arrived from your CEO this afternoon. Identify the first point at which out-of-band verification is mandatory, and whether anyone can waive it.
- Rewrite one training module. Take the section of your security awareness training that teaches people to spot bad grammar and replace it with voice cloning, personalization, and verification.
- Agree a challenge phrase. Establish a prearranged verification word for high-stakes phone requests within your leadership team, and rehearse using it once so it is not novel under pressure.
- Run a channel-switch drill. Ask your team what they would do if a known contact moved a conversation to a personal messaging app and made a request there. The answers will tell you whether the policy is real.
- Check the reporting route. Find out how someone in your organization reports a suspected impersonation attempt, how long it takes, and whether it feels safe to do. If nobody knows, that is the finding.
Reflection
- How much public audio and video of your executives exists, and has anyone in your organization ever treated that as an exposure rather than as marketing?
- If you received Greta's voicemail, would your process have stopped the payment, or would only your instinct have stopped it?
- Does your verification procedure apply to requests that appear to come from the most senior people, and would a junior employee feel able to enforce it?
- What does your security awareness training say about detecting fraudulent messages, and is any of it still accurate?
- Who would notice if fabricated content about your company or your executives began circulating, and how quickly?
- When someone in your organization last reported a suspicious contact, what happened to them, and what did that teach everyone watching?
Glossary
- Deepfake. Synthetic audio, video, or imagery generated or manipulated by AI to portray something that did not happen, produced using models trained on recordings of the target.
- Voice cloning. Generating a synthetic copy of a specific person's voice, now achievable from as little as a few seconds of source audio.
- Phishing. Fraudulent messages designed to get the recipient to click a link, reveal credentials, or take an action; the most common form of cybersecurity attack.
- Spear phishing. Phishing targeted at a specific individual, formerly hours of work per target and now generated in bulk with personalized variants.
- Social engineering. Manipulating people into revealing information or taking action, exploiting trust, authority, and urgency rather than technical vulnerabilities.
- Misinformation. False information spread without intent to deceive, by people who believe it is true.
- Disinformation. False information spread deliberately to cause harm, often as a coordinated campaign across multiple channels.
- Out-of-band verification. Confirming a request through a separate, pre-established channel using contact details you already hold, never those supplied in the request.
- Challenge phrase. A prearranged word or phrase used to verify identity during high-stakes voice communications.
Related Lessons
Social Engineering and AI-Enhanced Phishing goes deeper into the manipulation techniques introduced here, and Protecting Yourself & Your Organization covers the personal and organizational countermeasures in more detail. Secure AI Usage Practices for Organizations addresses the policy layer that turns these countermeasures into standing practice, while Incident Response for AI Security Breaches picks up at the point where an attack has succeeded and the question becomes containment. For the technical threat surface of AI systems themselves rather than attacks conducted with AI, see AI-Specific Security Threats & Defenses.
Closing
AI has not invented a new category of crime. It has removed the cost, the skill requirement, and the language barrier from crimes that already existed, which is enough to change what your defenses need to look like. The signals people were trained to watch for were signals of attacker effort, and effort is what has become cheap. What remains reliable is process: verification through a channel the attacker does not control, controls that apply to everyone including the person at the top, and a culture where reporting a suspicion costs nothing. Greta was thirty seconds from a wire transfer, and what saved her company was one phone call to a number she already had.
Key Takeaways
- AI has lowered the cost and raised the quality of attacks. Sophisticated fraud no longer requires sophisticated attackers, because convincing impersonation has been commoditized.
- Voice cloning is a real and present threat. A few seconds of public audio is enough source material, and organizations have lost six- and seven-figure sums to executive voice fraud.
- Well-written messages are no longer evidence of legitimacy. AI removes grammar and language errors as a detection signal, so scrutiny now rests on context, urgency, and process.
- Deepfakes damage more than balance sheets. Reputational harm outlives the correction, extortion targets individuals, and widespread synthetic media erodes trust in genuine recordings.
- Detection is not the defense. Forensic analysis is slow, expert, and imperfect, so structural process controls are what actually stop this class of attack.
- Establish out-of-band verification for high-risk actions. A pre-agreed verification channel for financial and access decisions is the most effective single countermeasure, and it must apply to senior people too.
- Security awareness training needs updating. Training that does not address AI-enhanced attacks leaves your people calibrated to a threat that no longer exists.
Frequently Asked Questions
Can I tell a deepfake by listening or watching carefully? Sometimes, and the signals are worth knowing: background noise that does not match the claimed setting, lip sync that is fractionally off, unusual blinking, odd skin texture. But detection is an arms race, forensic analysis needs time and expertise, and neither is available in the moment a payment is due. Treat your process, not your ear, as the defense.
How much audio does someone need to clone a voice? As little as a few seconds, and the source is usually public: conference presentations, recorded talks, podcasts, earnings calls, and social media video. Anyone who has spoken in public should assume the raw material exists.
Does out-of-band verification really have to apply to the CEO? Yes, because executive impersonation is the attack. A procedure with an exemption at the top has its gap exactly where the fraud is aimed, and the junior employee facing an urgent request from a senior voice needs a rule to point at rather than a judgement call to make alone.
Is a challenge phrase not a bit theatrical? It feels awkward right up until the moment you need it, and the cost is mild embarrassment on legitimate calls weighed against a transfer that cannot be recalled.
What should we do about false content circulating about our company? Monitor deliberately, because the volume of AI-generated content makes ad hoc review impractical, and decide in advance who owns the response. Fabricated recall notices, synthetic clips of executives, and coordinated fake reviews are organizational risks that no payment control addresses.
Skill.re