Learning Objectives:
-
Understand the nature and growing sophistication of deepfake technology.
-
Analyse how deepfakes are being used in financial scams and social engineering attacks.
-
Recognise the erosion of traditional verification controls.
-
Identify strategies for defending against deepfake-enabled fraud.
2.1 The Rise of Deepfake Technology
Deepfakes are AI-generated synthetic media that can convincingly impersonate individuals. The technology has advanced rapidly, stripping out the red flags and errors that were once present . Deepfake fraud attempts nearly doubled in the UK to 94% in 2025, second only to France at 96%, followed by Spain (84%) and Germany (53%) . The financial sector is a prime target, with 72% of EU countries expecting more sophisticated attacks using AI, particularly involving deepfakes and AI-generated identity documents .
The central bank of Italy, Banca d’Italia, issued a warning in early 2026 about fake images, videos and articles circulating online that unlawfully used the name and image of the central bank’s governor, Fabio Panetta . These materials portrayed him in a completely fabricated manner as taking part in television programs or other media contexts, sometimes in association with the promotion of investment platforms, using an AI technique known as deepfake .
2.2 Deepfake Financial Scams
Agentic AI fraud represents a sophisticated shift where fraud operations are designed for higher success rates, higher financial impact, and greater resistance to traditional controls . This coordination of many techniques into a single attack is the hallmark of agentic AI fraud.
Common Deepfake Scam Types:
Investment Scams: Scammers use AI-generated videos, cloned voices, and manipulated images of political leaders, public officials, business figures, celebrities, and financial personalities to promote fake investment opportunities . Victims are directed to websites, messaging groups, or supposed investment advisers who persuade them to deposit money into fraudulent platforms. In the UK, investment scam losses reached £97.7 million in the first half of 2025, up 55% year over year .
Romance Scams: Perpetrators meticulously construct their approach, gradually building emotions, trust, and psychological dependence on victims before luring them into investing. The danger is that victims make these transactions almost entirely voluntarily, unaware that they are being psychologically manipulated .
Business Email Compromise (BEC): Voice-cloning and deepfake tooling now defeat call-centre and helpdesk verification steps that once relied on human judgment . Passwords, SMS codes, and app-based push approvals all depend on a human making the right call under pressure. AI is specifically built to exploit that moment .
2.3 The Erosion of Trust
AI has fundamentally changed the trust equation in digital financial interactions. Traditional trust signals are being exploited, and traditional verification methods are being circumvented. The danger is that these scams do not look like the old, badly written fraud messages we were used to seeing . They are more polished, localised, emotionally persuasive, and sometimes use familiar faces or institutions to appear credible .
Cybersecurity experts warn that the key message to the public is simple: do not trust a video, voice note, or online advertisement merely because it appears to feature a known person. In the age of AI, seeing is no longer believing .
2.4 Defensive Strategies
Financial institutions must adapt their defensive strategies to counter deepfake-enabled fraud:
Phishing-Resistant Authentication: Phishing-resistant hardware authentication closes the one gap passwords, OTPs, and push notifications can’t . FIDO2/WebAuthn hardware authentication is explicitly recognised as phishing-resistant by NIST and major regulators .
Enhanced Identity Verification: Stronger digital identity verification, including the use of biometrics and AI-powered verification tools, is essential .
Public Awareness and Education: Public awareness campaigns should emphasise that verification is the first line of defence. The best option is to verify and validate; there is really no other reliable way to identify these deepfakes as they are becoming extremely close to reality .
Cross-Sector Coordination: From a national perspective, financial security frameworks must evolve from compliance-focused controls to intelligence-led, real-time fraud prevention, including customer education, stronger incident reporting, better information sharing between institutions, and regular updates to cyber and financial risk frameworks .