AI Security & Cyber Threats · AI-Generated Phishing & Social Engineering
How are deepfakes being used in business email compromise scams
Deepfakes are being used in business email compromise scams by combining AI-generated video or voice impersonation of a company executive with a fraudulent request — typically an urgent wire transfer — adding a convincing layer to a scam category that previously relied on email alone, causing real documented losses.
Key takeaways
- Deepfake video or voice impersonation adds a convincing new layer to a scam category that previously relied on email alone.
- Typical scams involve an urgent, executive-impersonating request for a wire transfer or sensitive data.
- Documented real cases have resulted in substantial financial losses for targeted companies.
- Verification procedures independent of the communication channel being used remain the most effective defense.
Adding a Convincing New Layer to an Existing Scam Category
Deepfakes are being used in business email compromise scams by combining AI-generated video or voice impersonation of a company executive with a fraudulent request, typically for an urgent wire transfer or sensitive data, adding a convincing audio or visual layer to a scam category that historically relied on text-based email alone.
What Business Email Compromise Looked Like Before Deepfakes
Traditionally, this scam category involved attackers impersonating an executive or trusted business partner via a spoofed or compromised email account, requesting an urgent payment or sensitive information, relying entirely on the written request appearing legitimate enough and the request feeling urgent enough that the recipient didn’t independently verify it.
How Deepfakes Extend This Playbook
By adding a fabricated video call or cloned voice message that appears to confirm the same fraudulent request, attackers can overcome a target’s growing skepticism toward email-only requests, since a video or voice call impersonating a familiar executive provides a seemingly stronger form of confirmation than text alone — even though that confirmation is itself artificially generated.
Why Documented Cases Show Real, Substantial Financial Losses
This isn’t a purely theoretical risk — publicly documented cases have involved companies transferring substantial sums of money after employees were deceived by a deepfake video or voice call that appeared to come from a genuine senior executive, reflecting real, realized financial harm rather than only a hypothetical future concern.
Why Urgency Remains a Core Part of the Attack
Similar to traditional business email compromise, these deepfake-enhanced scams typically rely heavily on manufactured urgency — framing the request as time-sensitive and requiring immediate action — specifically to discourage the target from pausing to independently verify the request through a separate channel before acting.
Why Independent Verification Remains the Most Effective Defense
Because the core vulnerability is that a convincing-seeming confirmation replaces genuine verification, the most effective defense doesn’t depend on being able to detect that a video or voice is artificially generated — it depends on organizational policies requiring independent verification of any unusual financial request through a separate, previously established channel, regardless of how convincing the original request appeared.
Why Organizations Are Increasingly Updating Internal Policies in Response
Given documented losses from this specific scam pattern, many organizations have begun updating internal financial approval policies to explicitly require this kind of independent verification for large or unusual transactions, reflecting a recognition that technical detection of deepfakes alone isn’t a sufficient organizational defense.
Bottom Line
Deepfakes are being used in business email compromise scams to add a convincing video or voice layer to fraudulent executive impersonation requests, and documented real cases have resulted in substantial financial losses — making independent verification through a separate, previously established channel, rather than reliance on detecting the deepfake itself, the most effective organizational defense.
Go deeper
Frequently asked questions
What is business email compromise, and how do deepfakes change it?
Business email compromise is a scam category where attackers impersonate a company executive or trusted partner to request a fraudulent payment or sensitive information, and deepfakes add a convincing audio or video layer to this impersonation, going beyond text-based email alone to include a fabricated video call or voice message that appears to confirm the request.
Has this kind of deepfake-enabled scam actually succeeded against real companies?
Yes — there have been publicly documented cases of companies transferring substantial sums of money after employees were deceived by a deepfake video or voice call impersonating a senior executive, reflecting genuine, realized financial losses rather than only a theoretical risk.
Related questions
- Can AI clone someone's voice well enough to fool a phone call verification?
- Are AI generated phishing attacks increasing the volume of scams companies see?
- Can ai detect deepfake voice calls in real time during a phone call?
- How do deepfake detection tools actually work?
- Why are AI chatbots themselves becoming targets for social engineering scams?
- How realistic have AI-generated phishing emails become?
Sources
- [1]Business email compromise guidance — FBI Internet Crime Complaint Center
- [2]Cybersecurity threat research — Cybersecurity and Infrastructure Security Agency
Written by Editorial Team
Last updated July 29, 2026
Get one well-sourced answer a week
No spam. Unsubscribe anytime.