AI Deepfakes Push Business Email Scams Past $3 Billion in 2025
Fraudsters now use voice cloning and fake video calls to impersonate executives, with losses jumping $250 million year-over-year according to FBI data.
Business email compromise attacks cost companies more than $3 billion in 2025, marking a $250 million increase from the previous year, according to the FBI's Internet Crime Complaint Center annual report. What began as crude phishing emails has evolved into sophisticated schemes using artificial intelligence to clone voices and generate convincing deepfake videos of executives.
The scam operates through social engineering rather than technical exploits. Fraudsters impersonate company executives, attorneys, or trusted vendors to trick employees into wiring funds to fraudulent accounts. Early versions of these attacks were often riddled with grammatical errors and easy to spot, but modern variants leverage AI to harvest company information, study communication patterns, and craft highly personalized messages.
Why it matters
The shift to AI-enabled attacks represents a fundamental change in threat sophistication. Companies can no longer rely on employees to spot suspicious emails based on poor grammar or unusual phrasing. When attackers can replicate a CFO's voice or appearance in real-time video calls, traditional verification methods break down. The $25 million Arup case demonstrates that even security-conscious employees following best practices—requesting video confirmation—can be deceived by sufficiently advanced deepfakes.
From simple emails to deepfake video calls
The FBI has tracked business email compromise since 2013, documenting steady annual increases in both frequency and losses. Initial attacks relied on spoofed email addresses that mimicked legitimate company contacts, sometimes differing by a single character. The 2020 case involving Barbara Corcoran, a "Shark Tank" investor, illustrates this approach: her bookkeeper wired $388,700 after receiving what appeared to be an invoice approval from Corcoran's assistant, never noticing the slightly altered email address.
As defenses improved, attackers adapted. Some began hacking directly into executive email accounts to send requests from legitimate addresses. Others conducted extensive reconnaissance, monitoring company email traffic for weeks to understand payment protocols and communication styles.
The most dramatic evolution came with AI integration. In 2025, an employee at British engineering firm Arup received an email purportedly from the company's CFO requesting a confidential transaction. Suspicious of the request, the employee insisted on a video conference call for verification. During the call, he saw and heard the CFO along with other senior employees, all appearing authentic. Convinced by what he witnessed, he authorized a transfer of approximately $25 million. Every person on that call was an AI-generated deepfake.
The FBI issued warnings in 2024 about the increasing use of voice cloning and deepfake technology in these schemes. According to FBI Special Agent Robert Tripp, "Attackers are leveraging AI to craft highly convincing voice or video messages and emails to enable fraud schemes against individuals and businesses alike."
Defense protocols for the AI era
Companies must implement layered verification systems that assume any single communication channel can be compromised. Effective protocols include requiring independent verification of wire transfers through separate communication channels, callback verification using pre-established secure phone numbers, and dual authorization requirements for large payments.
Employee training must now cover deepfake detection and voice cloning awareness. Some organizations have adopted code words for executive payment requests—a low-tech solution that remains effective against high-tech attacks because AI cannot replicate information it doesn't have access to.
Recent reports indicate hedge funds have become the latest targets for these AI-enhanced schemes, suggesting attackers are moving toward higher-value targets as their capabilities improve.
These details were first reported by Steve Weisman in Forbes.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

