How fraudsters are using AI to target financial institutions

Over a third of fraud attempts targeting financial institutions are using AI, according to a report by digital identity company Signicat and consultancy Consult Hyperion.
The research highlights the rapidly evolving threat landscape, with fraud prevention decision-makers agreeing that AI will drive almost all identity fraud in the future, leading to more victims than ever before.
Alarmingly, around three-quarters of organisations cite a lack of expertise, time and budget as hindering their ability to detect and combat AI-driven fraud.
This lack of expertise and organisational interest is particularly alarming when you consider one report statistic: deepfake fraud attempts saw a 2,137% increase over the past three years.
Taking over accounts
The report unveils a concerning shift in the tactics employed by fraudsters.
Three years ago, AI was primarily used to create new or synthetic identities and forge documents.
Today, AI is being employed more extensively and at scale for deepfakes and social engineering attacks.
Account takeovers, once considered primarily a consumer issue, have become the most common fraud type for business-to-business organisations.
Fraudsters exploit weak or reused passwords to compromise existing accounts, often using deepfakes to impersonate the account holder.
Deepfake attacks
Deepfakes, which use AI to generate realistic but fabricated audio and video content, now represent a staggering 6.5% of total fraud attempts.
The World Economic Forum last year reported that the banking sector is particularly concerned by deepfake attacks, with 92% of cyber practitioners worried about its fraudulent misuse.
The high cost of deepfake fraud is also felt across other industries.
In 2023, 26% of smaller and 38% of large companies experienced deepfake fraud resulting in average losses of up to US$480,000 each.
Deepfake fraud is not just an issue for smaller businesses, though.
Last year, the UK's Financial Conduct Authority (FCA) sounded the alarm over the risks associated with “deepfake” fraud.
Nikhil Rathi, managing director of the FCA, said that that AI could disrupt the financial services sector in “ways and at a scale not seen before”.
And deepfake attacks at scale are already being felt.
In May 2024, engineering giant Arup fell victim to a deepfake fraud costing £20m (US$26m) after an employee was tricked into participating in a video conference featuring a digitally recreated version of the company’s CFO.
This incident highlights the sophistication and potential impact of deepfake attacks on even the largest organisations.
Detecting deepfakes
While the threat of deepfake fraud is growing, there are giveaways which can help identify these deceptive tactics.
Security company Kaspersky previously outlined several indicators of a deepfake video, such as unnatural blinking patterns, inconsistent lip movements and background irregularities.
However, as AI technology continues to advance, so too do the capabilities of deepfakes, making them increasingly difficult to detect.
Using AI to fight AI
Fortunately, the same AI technology which creates deepfakes can also be leveraged to fight it.
AI systems can be trained to spot the subtle anomalies and inconsistencies that may indicate a deepfake, providing a powerful defence against this emerging threat.
McAfee & Intel, for instance, have joined in a collaboration called Deepfake Detector to do just that. Among other tools, Deepfake Detector uses audio detection to spot the subtle differences in real videos and AI generated ones.
But in addition to leveraging AI for detection, organisations must implement robust procedures to prevent social manipulation at the individual level, which, according to cybersecurity firm Avast, is often the weakest link in the security chain.

