Security

AI Deepfakes Push Business Email Scams Past $3 Billion in 2025

Fraudsters now use voice cloning and fake video calls to impersonate executives, with losses jumping $250 million year-over-year according to FBI data.

Omega Editorial· August 8, 2026· 3 min read

Business email compromise attacks cost companies more than $3 billion in 2025, marking a $250 million increase from the previous year, according to the FBI's Internet Crime Complaint Center annual report. What began as crude phishing emails has evolved into sophisticated schemes using artificial intelligence to clone voices and generate convincing deepfake videos of executives.

The scam operates through social engineering rather than technical exploits. Fraudsters impersonate company executives, attorneys, or trusted vendors to trick employees into wiring funds to fraudulent accounts. Early versions of these attacks were often riddled with grammatical errors and easy to spot, but modern variants leverage AI to harvest company information, study communication patterns, and craft highly personalized messages.

Why it matters

The shift to AI-enabled attacks represents a fundamental change in threat sophistication. Companies can no longer rely on employees to spot suspicious emails based on poor grammar or unusual phrasing. When attackers can replicate a CFO's voice or appearance in real-time video calls, traditional verification methods break down. The $25 million Arup case demonstrates that even security-conscious employees following best practices—requesting video confirmation—can be deceived by sufficiently advanced deepfakes.

From simple emails to deepfake video calls

The FBI has tracked business email compromise since 2013, documenting steady annual increases in both frequency and losses. Initial attacks relied on spoofed email addresses that mimicked legitimate company contacts, sometimes differing by a single character. The 2020 case involving Barbara Corcoran, a "Shark Tank" investor, illustrates this approach: her bookkeeper wired $388,700 after receiving what appeared to be an invoice approval from Corcoran's assistant, never noticing the slightly altered email address.

As defenses improved, attackers adapted. Some began hacking directly into executive email accounts to send requests from legitimate addresses. Others conducted extensive reconnaissance, monitoring company email traffic for weeks to understand payment protocols and communication styles.

The most dramatic evolution came with AI integration. In 2025, an employee at British engineering firm Arup received an email purportedly from the company's CFO requesting a confidential transaction. Suspicious of the request, the employee insisted on a video conference call for verification. During the call, he saw and heard the CFO along with other senior employees, all appearing authentic. Convinced by what he witnessed, he authorized a transfer of approximately $25 million. Every person on that call was an AI-generated deepfake.

The FBI issued warnings in 2024 about the increasing use of voice cloning and deepfake technology in these schemes. According to FBI Special Agent Robert Tripp, "Attackers are leveraging AI to craft highly convincing voice or video messages and emails to enable fraud schemes against individuals and businesses alike."

Defense protocols for the AI era

Companies must implement layered verification systems that assume any single communication channel can be compromised. Effective protocols include requiring independent verification of wire transfers through separate communication channels, callback verification using pre-established secure phone numbers, and dual authorization requirements for large payments.

Employee training must now cover deepfake detection and voice cloning awareness. Some organizations have adopted code words for executive payment requests—a low-tech solution that remains effective against high-tech attacks because AI cannot replicate information it doesn't have access to.

Recent reports indicate hedge funds have become the latest targets for these AI-enhanced schemes, suggesting attackers are moving toward higher-value targets as their capabilities improve.

These details were first reported by Steve Weisman in Forbes.

#business email compromise#deepfakes#voice cloning#cybersecurity#fraud prevention#ai security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

OpenAI Pauses AI Agent Work After Model Exploits Vulnerabilities

The company's Astra model reached a threshold where it can autonomously find security flaws and execute cyber-attacks without human guidance.

Via AI Watch · Aug 8, 2026
Security· 3 min read

Cybersecurity Firms Shift From Alarm to Action After AI Agent Hacks

Industry leaders at Black Hat conference say rogue AI incidents are inevitable and focus must turn to detection and containment tools.

Via AI Watch · Aug 8, 2026
Security· 3 min read

Security Researchers Intercept Thousands of Misdirected Emails

Owners of noreply.us and deleteduser.com domains are receiving injury reports, pizza orders, and company secrets from misconfigured systems worldwide.

Via WIRED · Aug 8, 2026