The loss figure is now difficult to dismiss
The financial impact of AI-enabled fraud is becoming more visible, even though public reporting still captures only part of the problem. The FBI’s Internet Crime Complaint Center recorded 22,364 complaints referencing artificial intelligence in 2025, with reported losses of $893,346,472, according to a summary of the IC3 data by Eyesift.
That figure should be read carefully. It covers complaints referencing AI, not voice fraud alone, and it reflects reported losses rather than the total cost of attempted attacks, internal investigation, customer remediation, regulatory response and reputational damage. It is nevertheless a useful signal for risk committees: AI is no longer just improving the presentation of an old scam. It is making impersonation more credible at the precise point where many controls still rely on human judgement.
Deloitte’s Center for Financial Services projects that US generative-AI-enabled fraud losses could reach $40 billion by 2027, up from $12.3 billion in 2023. That is the aggressive scenario, with a conservative projection of around $22 billion, per Deloitte’s May 2024 analysis. Separately, 25.9 percent of polled executives said their organisation had experienced at least one deepfake incident targeting financial or accounting data in the prior 12 months, in a Deloitte poll of more than 1,100 C-suite executives in 2024.
These are not forecasts that a compliance officer can manage with awareness training alone. They describe a control problem involving people, process, telephony and transaction authority.
Arup showed how the workflow breaks
In early 2024, a finance employee at engineering firm Arup transferred about $25 million after joining a video call with AI-generated recreations of the company’s CFO and colleagues. The incident was confirmed by Arup and described by CNN Business, the World Economic Forum and Deloitte, with the details also cited in a FinCEN alert.
The sequence matters. The initial contact was a phishing email before the deepfake call. The attack therefore did not need to defeat a single technical gate. It moved through a familiar business process, established context, created apparent authority and then used a live conversation to support a payment decision.
Arup’s CIO, Rob Greig, described the incident as technology-enhanced social engineering. No systems were compromised and no data was affected. He also said he created a real-time deepfake of himself using open-source software in about 45 minutes. The lesson is not that every video call is fraudulent. It is that a convincing call can be used as one component in a broader attack against an otherwise ordinary approval workflow.
For a regulated firm, the relevant question is not whether a staff member can identify a synthetic face in a demonstration. It is whether the firm can prevent an unauthorised payment, beneficiary change, password reset or VIP servicing action when the caller sounds familiar, knows the case details and appears to be a senior colleague or trusted customer.
Policy is catching up, but legislation is not a control test
The policy response is developing. The Preventing Deep Fake Scams Act was reintroduced in February 2025, with a proposed cross-agency task force involving federal financial and law-enforcement bodies, including Treasury, the Federal Reserve and FinCEN, as reported by Allure Security.
That proposal is important because it recognises that synthetic-media fraud crosses institutional boundaries. It does not, however, tell a firm whether its own telephone procedures will withstand an attack.
FinCEN Alert FIN-2024-Alert004, issued on 13 November 2024, warns financial institutions about generative-AI deepfake fraud and executive-impersonation vishing. The alert endorses live audio and video verification, while also warning that attackers can generate synthetic audio and video responses to live prompts. It is advisory guidance, not a binding rule, but it makes a critical point: verification alone is not enough when the verification channel can itself be manipulated.
A caller may answer personal questions, repeat a one-time phrase or respond naturally to an employee’s challenge. The control may appear to have worked while the underlying identity remains untrusted. Firms need a combination of independent-channel verification, transaction limits, dual authorisation, call recording and escalation rules. They also need to know whether staff actually follow those controls under pressure.
Training is necessary, but evidence is better
Training helps people recognise urgency, secrecy and unusual requests. Identity checks can add friction. Neither proves that the end-to-end workflow will survive a capable vishing attempt.
Per Pindrop’s 2025 Voice Intelligence & Security Report, deepfake voice-fraud attempts rose 1,300 percent in 2024, based on that vendor’s telemetry. The same report says US contact-centre fraud attempts occurred roughly every 46 seconds, with synthetic-voice attacks growing fastest in insurance and then banking. These figures are single-vendor observations, not a universal measure of the market, but they reinforce the operational concern.
The defensible control is a test in which authorised specialists place controlled calls against real processes. Can an employee pause a payment when the apparent CFO is insistent? Does a beneficiary-change request trigger a genuinely independent callback? Can a service team refuse a password reset when the caller supplies convincing personal information? Is the exception logged, escalated and reviewed?
This is the purpose of the DeepBlocker Vishing Readiness Assessment. In a fixed-scope engagement lasting two to three weeks, an authorised AI red team tests selected phone workflows and returns sealed evidence of who was fooled, which controls were bypassed and where the process broke. The output is designed for the board, the insurer and the regulator, not just for a training administrator.
The widening gap is not between firms that care about voice fraud and firms that do not. It is between firms that assume their controls work and firms that have tested them under realistic conditions.
Subscribe to the intelligence for evidence-led analysis of AI voice fraud and the controls that withstand it.