Synthetic voice and video are no longer a novelty in fraud. The pattern now reported across finance and professional services is consistent: a convincing approach that appears to come from a senior executive, delivered by voice call or video, applying time pressure to an unusual payment or a change of bank details. The technical barrier has effectively disappeared, and compliance commentators are increasingly treating deepfake-enabled fraud as a governance issue that boards and regulators are expected to have addressed.
Most anti-fraud training is built around detecting a badly written email. Synthetic media defeats that entirely, because the signal people are trained to look for – poor language, an odd address, a generic greeting – is absent. Worse, the approach usually exploits something structurally true about the organisation: that a request from a senior person, marked urgent and confidential, is difficult for a junior member of staff to challenge.
The effective controls here are procedural rather than technological, and they are cheap:
The organisations that handle this well are not the ones with the best detection technology. They are the ones where a finance assistant can say “I need to call you back on the number we hold” to a director, and know that doing so is exactly what the organisation expects of them.