As with every technological leap, the endless possibilities of generative AI arrive with endless risks. The same tools that can clone your own voice or face in seconds can clone your CFO’s. Over the past two years, that capability has become a documented method of corporate fraud, with cases spanning the world.
- In January 2024, a finance employee at the Hong Kong branch of a multinational firm joined a video conference in which the CFO and several colleagues were all AI deepfakes built from public footage. He made 15 transfers totalling about HK$200 million before checking with head office. No funds were recovered, and no systems were breached: the attack only needed a video call and a believable story. A second Hong Kong case that May followed the same template for around HK$4 million.
- In Xi’an, a mainland finance employee transferred RMB 1.86 million after a video call from her “boss,” whose face and voice had been cloned. She posted the receipt to an internal group, the real manager flagged it, and a rapid bank freeze recovered about RMB 1.56 million.
- In March 2025, a finance director in Singapore joined a video call where the CEO and other executives were deepfaked in real time, and wired US$499,000. Suspicion arose only at a second request, and fast cross-border police action traced and froze the full amount.
- In July 2024, an executive at Italian carmaker Ferrari received a call using a voice clone of CEO Benedetto Vigna. He asked a question only the real Vigna could answer, and the caller hung up.
A few lessons follow. First, these are not conventional cyberattacks. No network needs to be compromised, so the defence cannot be purely technical. Second, deepfakes invert a long-standing assumption: staff were taught to treat a familiar face and voice as proof of identity, but the video call has now become the point of attack itself. Third, the targets share a profile, a single employee authorised to move funds, placed under urgency and apparent senior instruction. In a fast-moving business environment, the very efficiency a lean finance team prides itself on removes precisely the friction that would otherwise catch a fraudulent request.
The barrier to entry is also collapsing. Voice cloning needs only seconds of audio, while video cloning can start from a single photo. The next escalation is automation: autonomous AI agents can run multi-step tasks with minimal supervision, identifying targets, sending the lure, and delivering the fake. Regulation has limits, too. China’s AI-labelling rules took effect on 1 September 2025, requiring AI-generated synthetic content to be marked as such, but naturally this is not something a criminal would adhere to. Liability ultimately turns on the degree of negligence, which makes documented procedures and training a genuine safeguard.
The defences, encouragingly, are inexpensive and procedural: verify unexpected payment instructions through a separate channel, require dual authorisation above set thresholds, and never approve a transfer on the strength of a video or voice call alone. Through PSU’s 20 years of operational experience, we help companies pressure-test these controls before a convincing fake arrives.
By Johan Magnusson, Consultant