Finance teams face growing deepfake fraud risks
As corporate finance teams work through the changing market of threats, they are confronting a rising menace: deepfake fraud. This type of scam utilizes artificial intelligence to craft convincing video and audio interactions, leaving teams vulnerable to exploitation. The Federal Reserve has sounded the alarm on the growing use of AI-powered scams, where scammers leverage generative tools to produce synthetic media. Deloitte estimates that by 2027, losses due to generative AI tactics, including deepfakes, could soar to $40 billion in the United States. This staggering projection shows the operational risks these attacks pose to businesses, their chief financial officers, and finance teams.
A notable incident in Hong Kong
A recent, high-profile case in Hong Kong illustrates the severity of the threat. A finance employee participated in a video conference that appeared to include his chief financial officer and several colleagues. The employee was instructed to transfer $25 million into five different bank accounts across 15 transactions. However, it was only after the transfers were completed that the employee discovered he was the sole real person on the call; the others were deepfakes. This incident highlights a systemic failure, where inadequate safeguards were in place, rather than a lapse in individual judgment.
Read Also: Wealth managers scramble to fix AI readiness gaps
Scammers predominantly target chief financial officers and their finance teams because they are at the heart of business operations, wielding the authority to approve payments, modify supplier details, and manage significant sums of money. Fraudsters are well aware of this vulnerability and exploit it to gain access to corporate funds.
The limitations of visual detection methods
Finance leaders can instruct their teams on several techniques to identify manipulated media. One approach involves recognizing visual inconsistencies in deepfakes, such as unnatural blinking, inconsistent skin textures, mismatched lighting and shadows, face blurring, and audio-video synchronization issues. Another method is to detect audio anomalies in voice deepfakes, which may exhibit characteristics like robotic undertones, flat speech patterns, and a lack of natural pauses or breaths. If team members notice any of these signs or suspect they are interacting with a deepfake, they should report it immediately. Nevertheless, these methods should be viewed as a temporary solution, as scammers continually update their tactics to evade detection.
As detection methods improve, the quality of generated deepfakes also advances. Therefore, it is key to recognize that detection alone is insufficient to combat the deepfake problem. Once a weakness becomes widely known, scammers exploit newer technologies to overcome it, rendering detection methods less effective.
Read Also: BlackRock’s Preqin Deal Boosts Private Credit Transparency
Shifting the focus from detection to verification
Given the limitations of detection, a more robust approach is needed, one that incorporates verification into the communication process itself. By preventing fraud from the outset, finance teams can avoid the cat-and-mouse game of detecting deepfakes while scammers continually adapt their strategies. To effectively combat deepfakes, financial teams should adopt a human verification mindset, asking not “is this video manipulated?” This mindset is the foundation of proof of human technology, which establishes cryptographic proof that a unique human is behind an interaction, using privacy-preserving cryptography such as zero-knowledge proofs.
Developing a defense strategy
The financial sector presents a compelling use case for proof of human technology, as it faces significant impersonation and fraud risks. By integrating this technology, finance teams can add a stronger signal of trust to high-stakes conversations, ensuring that a real human, rather than an AI-generated impersonation, is participating in the interaction. Additional precautions include reverse-searching suspicious images and videos, enabling multi-factor authentication, and limiting the personal media shared publicly to reduce the risk of convincing impersonation.
