Fraud & Security

Deepfake Fraud Came for Banking: Six Defences That Actually Work

The FBI gave AI fraud its own line for the first time in 2026, at almost $893m. Here is what deepfake fraud actually does to banks and customers, and the six defences with evidence behind them.

The fraud category that did not exist a year ago#

On 6 April 2026 the FBI's Internet Crime Complaint Center published its annual report and, for the first time in roughly 25 years of publishing one, gave artificial intelligence a category of its own. Against it sat 22,364 complaints and nearly $893 million of reported losses in a single year. Total cybercrime losses came to almost $21 billion across 1,008,597 complaints, and losses reported by people over 60 rose 37% to around $7.7 billion (FBI, April 2026).

The bureau's description of the toolkit is unglamorous: fake social profiles, cloned voices, forged identity documents and "believable videos depicting public figures or loved ones".

Two things make this worth your attention now rather than next year. The first is that the loss figures are reported losses only, so they are a floor rather than a measurement. The second is that the law has started to move. Since 2 August 2026, Article 50 of the EU AI Act has required anyone deploying a system that produces deepfake content to disclose that the content is artificially generated (European Commission). Criminals will ignore that, obviously. Which is why the useful question is not whether fraud is rising, but which of your own habits still hold up when the voice on the phone is manufactured.

What a deepfake is, and why banks are the target#

A deepfake is media generated or altered by a machine-learning model so that a real person appears to say or do something they did not. The model is trained on samples of that person. Modern voice cloning needs only seconds of recorded speech, which any customer who has left a voicemail or posted a video has already supplied.

Banks are exposed at two separate points, and it helps to keep them apart.

The first is the human. Someone rings your accounts clerk claiming to be the managing director, or rings a pensioner claiming to be her grandson. Fraud investigators call this social engineering, and generative AI has not invented it. It has made it cheap and repeatable. The sector's own AI fraud workstream, run jointly by FS-ISAC, the American Bankers Association and the Bank Policy Institute, puts it flatly: "AI has not created new categories of fraud, but it is fundamentally reshaping the speed, scale, and credibility of existing scams" (FSSCC, 2026).

The second is the machine. When you open an account by photographing your passport and your face, software checks that the document is genuine and that the face belongs to a living person in front of the camera. That check is called liveness detection. Criminals attack it two ways. A presentation attack holds a printed photo, a mask or a screen up to the camera. An injection attack skips the camera altogether and feeds a synthetic video stream straight into the app using a virtual webcam. The second is harder to spot, because nothing was ever held up to anything.

The case everyone cites is still the clearest illustration. In early 2024 an employee of the engineering firm Arup in Hong Kong transferred about $25 million after joining a video conference in which every other participant, including the chief financial officer, was a fabrication (CNN, May 2024). No system was hacked. A process was.

The numbers, as far as anyone can count them#

Nobody publishes a clean total for deepfake losses, and any figure claiming to be one deserves suspicion. What exists are fragments, and they point in slightly different directions.

In the UK, total payment fraud losses reached £1.28 billion in 2025, up 4%. Authorised push payment fraud, where the customer is tricked into sending the money themselves, accounted for £576.4 million, up 19% (UK Finance, June 2026). Yet impersonation fraud, the category you would most expect a convincing voice clone to inflate, saw losses fall 12% and cases fall 11% over the same period. That is a fact worth sitting with before accepting any story about deepfakes overwhelming banking. British banks have spent years building defences against impersonation specifically, and the data suggests those defences are holding for now.

On the identity verification side the picture is busier. Entrust, which processes identity checks in 195 countries, reported that deepfakes accounted for one in five biometric fraud attempts in the year to September 2025, that deepfaked selfies rose 58%, and that injection attacks rose 40% year on year (Entrust, November 2025). That is vendor data from one provider's own traffic, not an industry census, and should be read as such.

The number you will see quoted most often is a projection, not a measurement. Deloitte estimated that generative AI could push US fraud losses from roughly $12.3 billion in 2023 to about $40 billion by 2027, a compound growth rate of 32% (Deloitte, May 2024). It is a modelled forecast. Treat it as a hypothesis about direction rather than a fact about the future.

Your eyes and ears are the weakest control in the building#

Researchers at University College London asked 529 people to identify deepfake speech. They managed it 73% of the time, and training made almost no difference. Their conclusion, published in PLOS ONE in August 2023, was that "humans are unable to reliably detect deepfake speech, whether or not they have received training" (UCL).

Video is worse. In a study of 2,000 consumers in the UK and US, only 0.1% correctly identified every real and fake item they were shown, and participants had been told in advance that some were fakes (iProov, February 2025).

Federal Reserve governor Michael Barr made the same point from the supervisor's chair in April 2025: "In the past, a skilled forger could pass a bad check by replicating a person's signature. Now, advances in AI can do much more damage by replicating a person's entire identity" (Banking Dive).

So "learn to spot the fakes" is not a control. It is a hobby. Training still matters, but for a different reason: organisations that trained staff on fraud recorded 47% lower losses, rising to 50% where managers and executives were also trained (FSSCC). What training buys is the habit of following a procedure, not a better ear.

Six defences that actually work#

Each of these shifts the decision away from your senses and onto something a fraudster cannot fake in the moment.

DefenceWhat it stopsWhere the evidence comes from
Hang up and call back on a number you already hadAny impersonation by phone or video, because the fraudster does not control the number in your own recordsFBI IC3 PSA I-120324-PSA; the sector workstream reports fraudsters "will likely end the interaction" when asked
Agree a code word in advanceFamily emergency and grandparent scams built on a cloned voiceFBI IC3 PSA I-120324-PSA
Require two people and a deliberate pause on large or unusual paymentsFake executive instructions, including live video callsFSSCC human-in-the-loop guidance
Move logins to passkeysAccount takeover, because a passkey cannot be read out, phished or spokenFSSCC; FinCEN Alert FIN-2024-Alert004
Stop letting a voice or a face be the whole proof of identitySynthetic onboarding and voice-authenticated phone bankingFinCEN red flags and mitigations
Use the payment rail's own checks before you sendMoney reaching a mule account under a name that does not matchPay.UK Confirmation of Payee; PSR review, July 2026

Three of these deserve a word more.

The callback is the cheapest and the most effective, and it works precisely because it inverts who initiated the contact. The FBI's advice is to hang up, look up the organisation's number independently, and ring it yourself (IC3, December 2024).

Passkeys are worth the small effort of setting up. A passkey is a cryptographic key stored on your phone or laptop and unlocked by your device's own screen lock. There is no code to intercept and nothing for you to repeat to a caller, which removes the whole family of attacks that depend on persuading you to say something aloud.

The payment rail check is the quiet success story. Confirmation of Payee, which verifies that the account name matches the name you typed, had passed two billion checks by March 2024 across more than 100 UK organisations (Pay.UK). After mandatory reimbursement rules took effect in October 2024, the Payment Systems Regulator found that APP fraud losses over Faster Payments fell by around 21%, worth roughly £73 million a year, while the share of losses reimbursed rose from 54% to 65% (PSR, July 2026). That is the clearest evidence available that changing the rules of the payment system does more than educating the public.

What the rulebooks now ask of banks#

FinCEN's alert to US financial institutions, issued in November 2024, reads like a checklist and is publicly available. Among the red flags: identity documents that contradict each other, third-party webcam plugins appearing during verification, reverse image searches that match known AI face galleries, and a customer who refuses multifactor authentication. Among the recommended steps: live verification checks, image metadata analysis, phishing-resistant multifactor authentication, and commercial deepfake detection software (FinCEN).

In Europe, the AI Act's transparency duties began to apply on 2 August 2026 and require deployers to tell people when they are looking at a deepfake. That helps with disclosure in legitimate settings. It does nothing about criminals, who were never going to label their work.

The facts and figures above are drawn from the cited reports and filings. My reading of how they fit together, and the ranking of the six defences, is interpretation. None of this is investment or legal advice.

Key takeaways#

  1. The FBI recorded 22,364 AI-enabled fraud complaints and nearly $893 million in losses in a single year, the first time the category has appeared in its annual report.
  2. Human detection is not a defence. People identified fake speech 73% of the time in the UCL study, and only 0.1% of 2,000 consumers spotted every deepfake in the iProov test.
  3. The UK data is more mixed than the headlines suggest. Total payment fraud rose to £1.28 billion, but impersonation losses actually fell 12% in 2025.
  4. Every defence that works moves the decision off your senses: a callback to a number you already had, a pre-agreed code word, a second approver, a passkey, a name check on the payment.
  5. Changing payment rules produced measurable results. UK APP fraud losses over Faster Payments fell about 21% after mandatory reimbursement began.

Frequently asked questions#

How much of my voice does a criminal need to clone it? Seconds of clear speech is enough with current tools. The FBI describes criminals generating "short audio clips containing a loved one's voice" to stage fake emergencies (IC3).

If my bank uses voice recognition, am I at risk? Voice should not be the only thing standing between a caller and your money. FinCEN's guidance points institutions towards layered checks including phishing-resistant multifactor authentication rather than a single biometric (FinCEN).

What is an injection attack? Feeding a synthetic video or image directly into an app's verification process using software such as a virtual webcam, bypassing the camera entirely. Entrust reported these rose 40% year on year to September 2025 (Entrust).

Will I get my money back if I am tricked by a deepfake? It depends where you bank. In the UK, 61% of APP fraud losses, or £354.3 million, were reimbursed in 2025 under rules that took effect in October 2024 (UK Finance). Other jurisdictions have no equivalent requirement.

Does asking someone to turn their head on a video call still work? Treat it as a weak signal rather than a test. The FBI lists visual flaws such as distorted hands and inconsistent shadows as things to watch for, but the detection research suggests you should not stake a payment on your own judgement (IC3).

I run a small business. What is the single highest-value change? A written rule that no payment above a set amount is released on the strength of a call or video alone, with a callback to a stored number and a second approver. That combination is what the financial sector's own workstream recommends for high-risk transactions (FSSCC).

Are the huge projected loss figures reliable? They are models. Deloitte's $40 billion figure for 2027 is a projection built on assumptions about adoption rates, not a count of anything that has happened (Deloitte).

Glossary#

Deepfake. Audio, image or video generated or altered by a machine-learning model so a real person appears to say or do something they did not.

Voice cloning. Producing synthetic speech in a specific person's voice from a short recording of them speaking.

Social engineering. Manipulating a person into taking an action, such as releasing a payment, rather than attacking a computer system.

Authorised push payment (APP) fraud. Fraud in which the victim is tricked into authorising the payment themselves, which is why it falls outside ordinary unauthorised-transaction protections.

Liveness detection. Software checks that confirm a real, living person is in front of the camera rather than a photograph, mask or recording.

Injection attack. Feeding synthetic media directly into an application's verification pipeline, bypassing the device camera.

Passkey. A cryptographic credential stored on your device and unlocked by its screen lock. Nothing is typed or spoken, so it cannot be phished or read out to a caller.

Confirmation of Payee. A UK service that checks whether the account name you entered matches the name registered to the account before the payment is sent.

References#

  1. Federal Bureau of Investigation, "Cryptocurrency and AI Scams Bilk Americans of Billions", press release on the 2025 Internet Crime Report, 6 April 2026: https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  2. FBI Internet Crime Complaint Center, 2025 IC3 Annual Report: https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  3. FBI Internet Crime Complaint Center, Public Service Announcement I-120324-PSA, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud", 3 December 2024: https://www.ic3.gov/PSA/2024/PSA241203
  4. FinCEN, Alert FIN-2024-Alert004, "FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions", 13 November 2024: https://www.fincen.gov/sites/default/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf
  5. Enhanced Artificial Intelligence Fraud Workstream (FS-ISAC, American Bankers Association and Bank Policy Institute), "AI-Generated Fraud in the Financial Sector", 2026: https://fsscc.org/wp-content/uploads/2026/03/FSSCC-AI-Generated-Fraud.pdf
  6. UK Finance, "Fraud remains a national security threat as criminals steal almost £1.3 billion", Annual Fraud Report 2026 press release, 15 June 2026: https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release
  7. UK Finance, Annual Fraud Report 2026 (full report): https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  8. Payment Systems Regulator review of the APP fraud reimbursement requirement, reported 1 July 2026: https://www.regulationtomorrow.com/2026/07/payment-fraud-falls-by-73m-following-psr-reimbursement-scheme/
  9. Pay.UK, "Confirmation of Payee reaches two billion checks", 18 March 2024: https://newseventsinsights.wearepay.uk/media-centre/press-releases/confirmation-of-payee-reaches-two-billion-checks-helping-protect-uk-consumers-against-fraud/
  10. Kimberly Mai et al., "Warning: Humans cannot reliably detect speech deepfakes", PLOS ONE, 2 August 2023, summarised by University College London: https://www.ucl.ac.uk/news/2023/aug/humans-unable-detect-over-quarter-deepfake-speech-samples
  11. PLOS ONE research article, full text: https://journals.plos.org/plosone/article?id=10.1371%2Fjournal.pone.0285333
  12. iProov, "Deepfake Blindspot" study of 2,000 UK and US consumers, 12 February 2025: https://www.iproov.com/press/study-reveals-deepfake-blindspot-detect-ai-generated-content
  13. Entrust, "Deepfakes, Social Engineering, and Injection Attacks on the Rise: 2026 Identity Fraud Report", 18 November 2025: https://www.entrust.com/company/newsroom/deepfakes-social-engineering-and-injection-attacks-on-the-rise
  14. Deloitte Center for Financial Services, "Deepfake banking fraud risk on the rise", 29 May 2024: https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html
  15. Banking Dive, reporting Federal Reserve governor Michael Barr's remarks on deepfakes, 17 April 2025: https://www.bankingdive.com/news/banks-fight-deepfakes-better-ai-federal-reserve-barr/745906/
  16. CNN, "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee", 16 May 2024: https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
  17. European Commission, "Guidelines on transparency obligations for providers and deployers of certain AI systems", covering Article 50 of the AI Act, applicable from 2 August 2026: https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations
  18. EU Artificial Intelligence Act, Article 50, Transparency Obligations: https://artificialintelligenceact.eu/article/50/