top of page

Deepfakes and AI: The Existential Threat Reshaping Finance and Payments

  • Writer: Drew Sullivan
    Drew Sullivan
  • 1 day ago
  • 3 min read
Billions at Stake with AI-enabled Fraud
Is it live or Memorex? AI and Deep Fakes are just getting started.

The $25.6 million Arup heist in early 2024 marked a watershed moment. A finance staffer in Hong Kong joined a video call with what appeared to be the CFO and several colleagues. All were synthetic deepfakes. Instructions led to 15 wire transfers totaling HK$200 million (~$25.6M USD). No systems were hacked—pure social engineering amplified by AI.


This wasn't isolated. Deepfake-augmented Business Email Compromise (BEC) attacks are scaling rapidly, moving from opportunistic to industrialized operations. For financial institutions and the payments industry, the implications are profound: eroded trust, ballooning losses, regulatory pressure, and a fundamental shift in how identity, authorization, and payments must be secured.


The Scale of the Threat: Billions at Stake with AI-enabled Fraud


Deepfake and AI-enabled fraud have moved from niche experiments to mainstream criminal tooling. The FBI's 2025 Internet Crime Report documented $893 million in losses tied to AI-related complaints (a new tracked category), with BEC alone exceeding $3 billion overall. Deloitte projects generative AI could drive U.S. financial fraud losses to $40 billion by 2027, up from $12.3 billion in 2023—a 32% compound annual growth rate.


In payments and fintech, the numbers are even more alarming. Deepfake incidents in fintech surged dramatically, with synthetic identity fraud and real-time impersonation attacks becoming primary vectors for account takeover and new account fraud. Losses from deepfake fraud in early periods already topped hundreds of millions, with individual incidents frequently exceeding $500K–$680K.


Financial institutions face dual risks:

  • Internal/Enterprise: Executive impersonation for wire fraud (as in Arup), vendor payment diversion, and internal approval bypasses.

  • Customer-Facing: Synthetic identities for onboarding, loan fraud, and account takeovers via deepfaked biometrics or video calls.


Payments ecosystems—reliant on speed, APIs, and trust signals—are particularly vulnerable. AI lowers the barrier for low-skill attackers while enabling sophisticated, automated campaigns at scale.


Why the Payments Industry Is Ground Zero


Payments depend on verifiable intent and identity. Deepfakes undermine both:

  • Voice/video cloning defeats callback verifications and video meetings.

  • Synthetic agents and personas target agentic/automated payment flows.

  • Real-time deepfakes enable "live" social engineering that bypasses traditional filters.


J.P. Morgan and others note that deepfakes target payment authorization workflows directly, where human trust has historically been the final control. With the rise of embedded finance, BaaS, and AI agents initiating transactions, the attack surface expands exponentially.


FATF's horizon scan on AI/deepfakes highlights risks to AML/CFT, including automated laundering and impersonation that defeats KYC and liveness checks.


Regulatory and Insurance Headwinds


Regulators are responding:

  • CISA/NCSC joint advisories warn treasury teams specifically.

  • EU AI Act transparency obligations (deepfake labeling) enforce from August 2026.

  • FTC actions target AI impersonation fraud.


Insurers like Lloyd’s and Munich Re are tightening deepfake BEC claims, demanding documented multi-factor verification, procedural controls, and forensic evidence. Policies increasingly require explicit AI-risk language or endorsements.


Defenses: From Reactive to Architectural Resilience


Financial institutions and payment providers must move beyond detection alone. Key layers include:

  • Payee binding and verification: Lock banking details with out-of-band confirmation.

  • Deterministic rules in ERP/payments systems: Automate policy enforcement and anomaly detection at approval.

  • Continuous identity verification: Liveness + behavioral signals resistant to real-time deepfakes.

  • KYA (Know Your Agent) frameworks: Visa Trusted Agent Protocol (TAP), Mastercard Agent Pay, and Stripe tools for secure agentic commerce.


J.P. Morgan emphasizes real-time account validation, reduced false positives, and layered tech + human processes.


The Path Forward


The Arup case was a warning shot. Deepfakes don't just steal money—they erode the foundational trust in digital finance and payments. Institutions that treat this as a payments security imperative—investing in resilient architecture, KYA, procedural controls, and insurance alignment—will lead. Others risk existential operational and reputational damage.


The era of "I spoke to them on a call" as sufficient authorization is over. In an AI-augmented world, verification must be continuous, multi-channel, and machine-enforced.


What are your organization's top deepfake defenses today? Share in the comments or reach out for a deeper discussion on payments-specific controls.

Comments


Discover solutions for Global B2B Fintechs
More Insights

Never miss an update

bottom of page