Back to all blogs
Discover why banks can no longer trust video calls and how AI-powered fraud, deepfakes, and impersonation are creating new security risks.

Abhishek Kaushik
Aug 8, 2026
Your company's chief financial officer is on a video call with you and several of your colleagues. They describe a deal and ask you to wire the money. You know these people. You've worked with them for years. You've seen them in person. You've heard their voices. You've gotten to know their mannerisms. So you wire $25 million.
Everyone on the call was a deepfake.
In early 2024, scammers used real-time deepfake technology to trick a global design and engineering firm, Arup. The scammers deepfaked multiple executives on a video conference, and the employee who received the call, though initially suspecting a phishing attempt, was convinced once he saw what appeared to be his coworkers on screen.
The deepfake threat is real and growing. According to Surfshark, deepfake-related fraud has cost the global economy $2.19 billion, with $1.65 billion of that in 2025 alone. Financial services continue to be the primary target, and the technology behind these attacks is getting cheaper, faster, and more accessible by the day.
If you’re a financial services professional, it’s no longer a question of if your organization will be impacted by deepfake fraud, but when.
The False Sense of Security in Video Calls
For years, video has been the gold standard for remote communication because it allows for a more personal connection. A video call lets you see the other person and get a better sense of who they are.
This hierarchy is no longer a strength, but a weakness.
It's getting harder to tell real from fake. In fact, according to JP Morgan, people are only right about 40% of the time.
Your brain knows something is off, but it can't tell you what it is.
Deepfake scams are taking advantage of a cognitive blind spot by targeting the most trusted channel in a bank's communication stack — video. If you see a familiar face on screen, you're more likely to let your guard down and be tricked.
In banking, where a single authorization can move millions, this blind spot can be very expensive.

How Real-Time Deepfakes Actually Work
Real-time deepfake technology has come a long way since the days of crude face-swaps and is now capable of producing convincing synthetic video and audio with very little source material and limited technical know-how.
According to the Financial Services Information Sharing and Analysis Center (FS-ISAC), it takes just 20 to 30 seconds of audio to clone a voice. This audio can come from a conference presentation, a podcast appearance, a YouTube video, or even a voicemail greeting. AI models can then produce speech in the target's voice that is nearly indistinguishable from the original.
FS-ISAC reports that it's now possible to create a convincing deepfake video in just 45 minutes using open-source software and publicly available content such as LinkedIn profile photos and recorded webinars.
To pull off a real-time deepfake attack, an attacker can run face-swapping software on their own computer that maps their facial movements onto a synthetic rendering of the target's face. This output can then be fed to a virtual camera driver, which video conferencing platforms like Zoom or Microsoft Teams will treat as a standard webcam input. To the other participants on the call, the attacker will appear to be the person they are impersonating.
In 2020 and 2021, it was easy to spot a deepfake. By 2024 and into 2025 and 2026, these artifacts have largely disappeared. Advances in generative adversarial networks and diffusion models mean that synthetic media now passes casual visual inspection and increasingly evades automated detection systems as well.
The Financial Toll: Deepfake Fraud by the Numbers
The threat of deepfake fraud is real and growing.
In 2026, Surfshark reported $2.19 billion in deepfake losses, with $1.65 billion of that occurring in 2025. The United States was the most targeted, with $712 million in losses, 43% of which were in the corporate sector through executive impersonation and unauthorized transfers.
Fourthline's research found that deepfake-related fraud losses in the first half of 2025 exceeded $410 million, with some individual incidents surpassing $680,000. FS-ISAC, Deloitte, and other industry leaders project that generative AI-enabled fraud will continue to drive losses, with the potential to reach $40 billion annually by 2027.
The FBI’s Internet Crime Report for 2025 documented $3.046 billion in losses from 24,768 business email compromise (BEC) incidents in the United States. As the BEC category continues to converge with deepfake technology, fraudsters are combining synthetic voice and video with traditional email-based social engineering to create multi-channel attacks that are more difficult to detect and more convincing than either method alone.
According to a Medus survey, 53% of finance professionals have been the target of deepfake schemes, and 43% have fallen victim to one. Given the professional risk and embarrassment involved, it's likely that the true number of successful deepfake attacks in financial services is even higher than these numbers suggest.
Metric | Figure | Source |
|---|---|---|
Global deepfake fraud losses (cumulative) | $2.19 billion | Surfshark, 2026 |
Losses in 2025 alone | $1.65 billion | Surfshark, 2026 |
H1 2025 deepfake fraud losses | $410+ million | Fourthline, 2026 |
Projected AI-enabled fraud by 2027 | $40 billion/year | FS-ISAC / Deloitte |
U.S. BEC losses (2025) | $3.046 billion | FBI IC3, 2025 |
Finance professionals targeted by deepfakes | 53% | Medus survey |
Finance professionals who fell victim | 43% | Medus survey |

When Video Calls Became Attack Vectors
Let's take a look at some real-world examples of deepfake fraud in action.
The $25 Million Hong Kong Video Call. In February 2024, an employee at Arup, a multinational firm based in the UK, was tricked into authorizing $25 million in transfers across fifteen transactions after receiving an email about a confidential deal and joining a video call with his CFO and coworkers. The fraud was not discovered until the employee called the head office to verify the instructions.
The $35 Million UAE Bank Heist. In early 2020, a bank manager in the UAE received a call from a man he recognized as a director at a company with which the bank had a relationship. The director said his company was preparing an acquisition and needed $35 million to complete the deal. The bank manager, confident in the voice identification, authorized the transfer. The voice was generated using AI-based cloning technology and the money was laundered through multiple countries.
1,100 KYC Bypass Attempts in Indonesia. In late 2024, Group-IB's Fraud Protection team investigated a deepfake fraud at an Indonesian financial institution, where fraudsters had used malware, social media, and dark web markets to obtain victims' identity documents and create AI-generated deepfake photos that bypassed the financial institution's Know Your Customer (KYC) process. Over 1,100 attempts were uncovered. The deepfakes were able to defeat facial recognition and liveness detection systems, resulting in $138.5 million in potential financial damage over a three-month period.
In all three cases, the deepfakes were able to bypass the targeted organization’s security measures, which were considered robust, by exploiting the human tendency to trust what we see and hear.
Video KYC Under Siege
Video-based Know Your Customer verification has become the latest deepfake attack surface, with fraudsters using AI to impersonate real people on camera. By using liveness detection prompts such as blinking, turning their head, or speaking a phrase, organizations can be assured that they are interacting with a real person and not a deepfake.
Fraudsters are using Virtual camera applications to replace their device's live camera feed with recorded or AI-generated video that appears to be a normal camera input to the video conferencing or KYC application. They are also using app cloning tools to create isolated environments on a single device that appear as separate devices to the institution's security systems, which makes it harder to correlate multiple fraudulent applications to a single attacker.
Using just a single photo of the victim, an attacker can produce a real-time video feed of themselves that looks like the victim and will pass facial recognition matching and liveness detection checks.
Most liveness detection systems are designed to defeat static photo attacks and simple video replays, but not AI-generated media. As a result, they are easily bypassed by advanced deepfakes that can convincingly replicate eye blinks, head rotation, and mouth movement. There is little technical literature on the vulnerability of liveness detection to deepfakes, so many institutions are deploying defenses that have not been tested against current-generation attacks.
At a financial institution with 2 million customers, Group-IB found 1,100 deepfake accounts, or a deepfake fraud rate of 0.05% of the total. If this rate holds across Indonesia's 166 million-person economically active population, it would translate to $138.5 million in losses over three months.
Why Detection Alone Is a Losing Strategy
The intuitive reaction to the deepfake threat is to focus on detection, but this is not enough as a standalone strategy.
The race between deepfake generation and detection is on, but it's an unfair one. Deepfake generation technology is advancing at a faster pace and with fewer resource constraints than deepfake detection technology. As a result, it's getting easier and cheaper to produce a convincing deepfake. Open-source models are readily available, and the compute requirements for real-time face-swapping have dropped to the point where consumer-grade hardware can run the software. By contrast, detection requires continuous investment in training data, model updates, and integration with existing verification workflows.
Real-time detection remains a challenge. There are no tools for detecting virtual camera injection or face-swapping at the application layer, and it's difficult to analyze a live video call or KYC session without disrupting the user experience. Furthermore, the ability to train detection models is limited by a lack of high-quality deepfake training datasets that can keep up with the rapid pace of new generation techniques.
It's also important to remember that no single solution is foolproof. While deepfake detection tools can be a valuable part of a defense-in-depth strategy, it's critical to avoid developing a false sense of security that the detection layer will catch what humans cannot, as this can lead to complacency and leave organizations vulnerable to new and emerging threats.
Instead of asking "can we detect fakes?", the more productive framing is "should we be relying on this channel for trust decisions at all?" Detection is important, but it can't be the only line of defense. The foundation must be architectural — systems designed so that no single channel, including video, can serve as the sole basis for authorizing a transaction or verifying an identity.
What Banks Should Do Instead: A Post-Video-Trust Framework
If video can no longer be trusted, banks need to treat it that way. Here are five principles for banks to consider as they rethink identity and authorization in the age of real-time deepfakes.

1. Eliminate single-channel trust. No matter who they are, if you can't be sure that the person on the other end of a video call is who they say they are, you can't trust them. For any high-value request, you need to be able to verify their identity through a separate, pre-established channel that's independent of the one they're using to make the request. This could be a phone call to a known number, a message through an authenticated messaging system, or an in-person check. The key requirement is that the verification channel must be independent of the channel through which the request was received.
2. Implement continuous authentication. In the past, if you could prove your identity once, you were trusted for the duration of the session. But this is no longer enough. Deepfake attacks can clear an initial check and then operate freely. To combat this, continuous authentication validates identity throughout a session using behavioral biometrics such as typing patterns, mouse movements, and navigation habits, along with transaction pattern analysis and device fingerprinting. The goal is not a single yes-or-no decision but an ongoing confidence score that can trigger re-verification if anomalies emerge.
3. Deploy multi-layered KYC. In 2026 and beyond, video verification will be just one part of a multi-layered KYC process that also includes device intelligence, geolocation analysis, IP reputation scoring, document cross-referencing, and behavioral analytics. No single layer should be enough to approve an application or authorize access, and any layer can flag risk. If one layer fails, it should not be overridden by success in another.
4. Build a culture where questioning is expected. Train your employees to question any request, even if it appears to come from the CEO, CFO, or a board member. Use challenge-response protocols, such as pre-established code words for high-value transactions, that are difficult for deepfakes to replicate. Make it clear that this is standard practice and not an act of suspicion.
5. Pressure-test with red-teaming. Roleplay a deepfake attack on your own company to see if your employees can spot it. If they can't, an attacker will. Red-teaming should extend to third-party vendors and partners, too. If you don't know how often they train their employees to identify deepfakes, that's a vulnerability.
The Regulatory Landscape Is Catching Up
Regulators are starting to focus on AI-generated media, but the regulatory framework is still a patchwork that's changing quickly.
The EU AI Act, which entered into force in 2024, includes specific rules for deepfakes under Article 50. As of August 2, 2026, deployers of AI systems that generate or manipulate video, audio, or images that constitute a deepfake will be required to disclose that the content has been generated or manipulated using AI. In addition, Providers of AI systems generating synthetic content will be required to mark their outputs in a machine-readable format that is detectable as artificially generated. These transparency obligations will have a significant impact on the financial sector, which will need to adapt its verification processes accordingly.
The Digital Operational Resilience Act (DORA), which became enforceable on January 17, 2025, requires financial entities across the European Union to have in place the necessary ICT risk management measures to ensure operational resilience in the event of a cyberattack. This includes ensuring that financial institutions operating within the EU can demonstrate that their security controls can identify and respond to deepfakes and other synthetic media attacks that could be used to commit fraud or otherwise cause harm.
The regulatory writing is on the wall. Financial institutions that get ahead of the curve by investing in deepfake fraud detection and mitigation will be better positioned to meet compliance requirements for operational resilience, third-party risk management, and incident reporting. Those that wait for regulators to act will be playing catch-up and scrambling to implement solutions under the gun.
Conclusion
The rise of real-time deepfake technology has made it impossible to trust what you see and hear, with $2.19 billion in global losses and counting.
Deepfake fraud is here, and it's costing companies tens of millions of dollars in a single incident. It's bypassing KYC systems that were previously considered robust, and it's exploiting the human tendency to trust familiar faces and voices. The technology to create deepfakes is getting cheaper, easier to use, and more widely available.
It's time to stop relying on video as a trust anchor. The technology exists to authenticate users continuously and accurately through continuous authentication models, and it's critical for organizations to invest in it now.
In banking, it's more important than ever to focus on building trust through technology rather than relying on human intuition.
Citations
CNN (February 2024) — Reporting on the $25 million Arup deepfake video call fraud in Hong Kong. https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
Surfshark (April 2026) — Research analysis documenting $2.19 billion in global deepfake fraud losses, with $1.65 billion reported in 2025. https://surfshark.com/research/chart/deepfake-fraud-countries
Fourthline (January 2026) — Analysis of deepfake fraud in financial services, including $410 million in H1 2025 losses and $40 billion projected annual AI fraud by 2027. https://www.fourthline.com/blog/deepfakes-in-financial-services
FS-ISAC (October 2024) — Report on deepfake threats to financial institutions, including data on voice cloning requiring 20-30 seconds of audio and video deepfake production in approximately 45 minutes. https://www.fsisac.com/newsroom/deepfake-technology-poses-new-threats-to-financial-institutions-fsisac-provides-guidance
Forbes (October 2021) — Reporting on the $35 million UAE bank heist using AI voice cloning technology. https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-bank-fraud-uses-deep-fake-voice-tech-to-steal-millions/
Group-IB (December 2024) — Investigation of 1,100+ deepfake fraud attempts at an Indonesian financial institution, detailing virtual camera injection, app cloning, and KYC bypass methods. https://www.group-ib.com/blog/deepfake-fraud/
EU AI Act, Article 50 — Transparency obligations for providers and deployers of AI systems generating deepfakes, effective August 2, 2026. https://artificialintelligenceact.eu/article/50/
DORA (Digital Operational Resilience Act) — EU regulation establishing ICT risk management requirements for financial institutions, enforceable January 17, 2025. https://www.digital-operational-resilience-act.com/
JP Morgan (June 2026) — Analysis of deepfake fraud in payments, including the statistic that humans correctly identify deepfake videos only 40% of the time. https://www.jpmorgan.com/insights/payments/security-trust/deepfake-fraud-prevention-strategies


