All Resources
News·15 Apr 2026·6 min read

Deepfake Voice Cloning Is Now a Board-Level Fraud Risk for Banks

Deepfake fraud attempts against financial institutions surged from roughly one per month to seven per day in 2024, with attack volume growing more than 162% through 2025. In the first half of 2025 alone, deepfake-related fraud losses exceeded $410 million, and industry projections put generative-AI-enabled fraud across the financial sector at roughly $40 billion annually by 2027. Some single incidents now exceed $680,000 in loss.

Voice is the easy part

Voice cloning has become the leading deepfake attack vector because it requires so little source material - as little as three to five seconds of sample audio, easily obtained from a voicemail greeting, a conference call recording, or a public interview, is now enough to produce a convincing clone. Video deepfakes are being used for two distinct purposes: bypassing know-your-customer (KYC) identity verification during onboarding, and impersonating executives during live calls to authorise fraudulent payments. The highest-profile case to date involved a $25 million loss after fraudsters used a deepfake video to impersonate a CFO on a video call.

What this means for banks, insurers, and payment platforms

  • Voice and video should no longer be treated as inherently trustworthy authentication factors for high-value transactions or account changes - verify through a second, independent channel for anything above a defined risk threshold.
  • KYC and onboarding flows that rely solely on a selfie or a short video need liveness-detection and deepfake-detection controls specifically, not just generic fraud scoring.
  • Train staff who handle payment authorisation and executive requests on the specific pattern of deepfake CFO/executive fraud - urgency, unusual payment instructions, and a request to bypass normal approval steps are the consistent tells, regardless of how convincing the voice or video is.
  • Regulators are starting to treat deepfake detection capability as an expected control, not a novelty - institutions that can't demonstrate it are already facing enforcement scrutiny in 2026.

Have a security question of your own?

Talk to a Security Expert →