
When your phone rings, it could be anybody on the other end of the line. You think it’s your boss or a close friend, or someone in a position of authority, like at your bank or a government agency, and they have an “urgent” request for some sensitive information. It all sounds so real, however in many cases these days, it’s not real, they are not who they say they are, in fact they may not even be “human.” Instead, it could be an AI deepfake, and before you know it, you’re deep into a sophisticated scam that can threaten your accounts, your identity.
You shouldn’t feel bad, it’s getting more difficult to separate fact from fiction, as these attacks are happening all the time, more people are being fooled. These attacks are not only getting more convincing, but they’re also more widespread than ever as simple AI tools have unleashed a wave of deepfakes that are getting harder to detect.
Deepfake technology and identity deception have evolved from digital “party tricks” into a legitimate cybersecurity crisis, debunking the assumption that human oversight is a reliable security measure. Synthetic media—generated using advanced artificial intelligence tools like “Generative Adversarial Networks (GANs),” transformer models, diffusion models, and voice-cloning platforms—allows bad actors to clone facial expressions, vocal cadences, and personal mannerisms from just seconds of public source material, and it’s convincing too. As accessibility surges and the technical skills required to pull off these attacks drop, deepfakes are escalating from a novelty into a serious risk that threatens financial systems, organizational trust, national security, and anyone who happens to pick up the phone and encounter a scammer on the other line.
At its technical core, a deepfake relies on generative AI architectures that use neural networks against each other, and then a generator creates synthetic audio, video, or imagery indistinguishable from reality. Open-source tools like DeepFaceLab and voice-cloning platforms like ElevenLabs can target publicly available assets—“by scraping source content from LinkedIn, YouTube, podcast appearances, earnings calls, or Instagram.” For executives, “5 to 10 minutes of clean public footage is typically more than enough.” In some cases, “only three seconds of clean referencing audio” is enough to produce a convincing clone. This means that all recorded speech can be manipulated by an attacker.
Historically, identity security subscribed to the belief that while automated machines could be fooled by printed photos or replayed audio, an attentive human could spot a forgery with certainty. Cybersecurity experts like Abhilasha Bhargav-Spantzel and Ibrahim Waziri Jr. assert that this foundational assumption is no longer relevant, but the cyber industry has failed to catch up to the new reality. The synthetic media landscape has advanced so drastically that even top industry experts, such as Hany Farid, publicly acknowledge they can no longer trust their own eyes to distinguish real media from manipulated media.
The cybersecurity ecosystem faces a massive structural shift as AI-driven impersonation has the potential to become an operationalized social engineering tool. As reported in CrowdStrike’s Global Threat Report and reported in the RSA Conference blog, criminals actively leverage these capabilities to create complex vishing, video conference deception, and automated fraud campaigns at scale. Between mid-2024 and late 2024 alone, “voice phishing (vishing) attacks surged by 442%,” driven directly by AI impersonation capabilities.
This shift in capabilities was highlighted by a high-profile multimillion dollar incident at Arup, an engineering firm. In this case, a finance employee was tricked into attending a video conference where every single participant—including the Chief Financial Officer—was a digitally generated deepfake constructed entirely from open-source intelligence. Believing he was following legitimate instructions from familiar colleagues, the employee “authorized transfers totaling roughly $25.6 million” to scammers without a single core IT network or database being breached. Chief Information Officer Rob Greig described this as “technology-enhanced social engineering” rather than a traditional cyberattack. This illustrates that standard security systems can be bypassed when attackers manipulate human targets directly.
The economic toll of these synthetic media scams is growing globally and exponentially. For example, global deepfake fraud losses totaled “$335 million in 2024, grew to $2.5 billion in 2025 and then passed $764 million in just the first half of 2026. Recorded global losses are at approximately $3.7 billion, with 2025 and 2026 accounting for 89% of that overall figure.”
Social media serves as the largest entry point for these attacks, driving “$1.73 billion (47%)” of total losses through fraudulent celebrity or public figure investment promotions. Impersonation fraud—encompassing synthetic facial verification, face-swapping, voice cloning, and unauthorized account openings—"accounts for $911 million (25%).”
Federal reporting mirrors this trend. The FBI’s Internet Crime Complaint Center broke out AI-enabled fraud as a distinct category in its 2025 Internet crime report, “recording 22,364 complaints totaling $893.3 million in adjusted losses.” Investment schemes dominated this tally at “$632 million, while business email compromise with AI elements brought $30 million.” According to the FBI, older demographics bear a disproportionate burden, with adults aged 60 and older incurring “$352 million—or roughly 39%—of all reported U.S. AI fraud losses.”
According to The Hill, joint research from Gallup and the Stop Scams Alliance indicates that “12% of successful scams in 2025 involved AI or deepfakes, impacting 15.1 million American victims and driving $68 billion in overall scam-related losses.”
Organizations are struggling to keep up with the technical asymmetry of deepfakes. Meanwhile, the market keeps growing. According to Markets and Markets, the global deepfake AI market is projected to surge from “$0.85 billion in 2025 to $7.27 billion by 2031, registering a compound annual growth rate (CAGR) of 42.8%” during this period. This growth is driven by a “rapid expansion in enterprise applications that require synthetic media generation, detection, and real-time liveness verification.” At the same time the advancements in “generative AI models are enabling faster, cheaper, and more convincing deepfakes, pushing governments and companies to invest heavily in detection infrastructure.”
Even more alarming is the fact that while commercial detection algorithms boast up to 96% accuracy in controlled testing environments, their effectiveness drops to “50% and 65%” in real-world conditions and environments.
At this stage defensive readiness lags behind awareness. Organizations are taking the threat seriously, with “71% considering deepfake defense a top priority over the next year to 18 months.” However, “two-thirds of organizations have not invested in defense against AI-augmented threats.” Part of the problem is that defense costs more than offense.
The cyber insurance market is attempting to shift in response. Insurers are increasingly “reexamining AI risk and responding in divergent, and at times inconsistent, ways.” Some carriers “are clarifying coverage through endorsements, while others are narrowing or eliminating coverage through broad exclusions, revised coverage forms, or underwriting changes.”
A blog post from Harbour Insurance notes that “traditional cyber policies were designed around data breaches, ransomware, and network security failures. AI introduces additional vectors: data leakage through prompts, model errors that cause financial harm at scale, vendor outages that halt AI-dependent operations, and deepfake-enabled fraud that exploits AI-generated content.”
Businesses need to be aware that insurers are aware of the problems that AI can create and want to know how they are controlling it.
Policyholders now face heightened risk of AI-related claims “falling between traditional coverage lines or being subject to competing exclusions across the insurance tower.”
Because deepfakes are considered a commercial hazard as well as a national security risk, new legislation is emphasizing enforcement frameworks.
The World Economic Forum's Global Risks Report 2026 ranks “misinformation and disinformation as the world’s most severe short-term risk for the second consecutive year, citing AI-generated deepfakes and synthetic audio sophisticated enough to deceive informed audiences.”
At the federal level, provisions in the National Defense Authorization Act (NDAA) instruct defense and intelligence agencies to monitor synthetic media as a legitimate national security threat, integrating deepfakes into broader defense strategies alongside foreign propaganda and conventional cyber warfare.
On the regulatory side, Congress passed the TAKE IT DOWN Act in 2025, the first federal law targeting nonconsensual intimate deepfakes. The statute penalizes unauthorized distribution and mandates rapid platform removal without requiring victims to demonstrate any financial, personal, or reputational damages. While there still exists no comprehensive federal legislation that covers all deepfake applications, state legislatures are working quickly to fill that void, knowing the danger is so immediate and acute.
Spotting deep fakes is not going to be easy. Recent reports indicate that both Anthropic and OpenAI see cybersecurity defensive measures and protection as a potential lucrative sector for their AI programs. However, they are also helping to fuel the growth of AI as an attack vehicle, with more tools, training and access to programs that can easily create deep fakes and the capability to create more sophisticated attacks.
It’s going to take some combination of training, AI, human intervention, to thwart these new sophisticated attacks. Layers will be needed as reliance on any one of these elements will not be enough. At CYRIN we are working to create these new scenarios, using AI, hands-on training and the human element which will be needed to pull all the threads together.
We continue to work with our industry partners to address major challenges and set up realistic scenarios that allow them to train their teams and prepare new hires for the threats they will face. Government agencies have been using CYRIN for years, training their front-line specialists on the real threats faced on their ever-expanding risk surface.
For educators, we consistently work with colleges and universities both large and small to create realistic training to meet the environment students will encounter when they graduate and enter the workforce. In an increasingly digitized world, training and experiential training are critical. A full-blown cyberattack is not something you can prepare for after it hits, no matter who the adversary.
Our training platform teaches fundamental solutions that integrate actual cyber tools from CYRIN’s labs that allow you to practice 24/7, in the cloud, no special software required. Our new programs, including our new “mini labs,” AI, and Digital Twins, can create real-world conditions for you to practice before you must act. Cyber is a team effort; to see what our team can do for you look at our course catalog, or better yet, contact us for further information and your personalized demonstration of CYRIN. Take a test drive and see for yourself!