
Chief Executive Officer
Published: September 28, 2026

AI impersonation fraud uses cloned voices, deepfake video and AI-written messages to pose as executives, vendors or candidates.
It is mainstream: 62% of organizations saw a deepfake attack in the past year (Gartner, 2025).
The biggest single loss on record is about $25 million, sent by an Arup employee after a video call where every other attendee was a deepfake.
Legacy tools inspect links, attachments and sender domains. They do not check whether the face or voice on a live call is real.
AI impersonation protection combines real-time, cross-channel deepfake detection with out-of-band verification for payments and access changes.
Start with the highest-risk workflows: wire approvals, vendor bank changes, help desk resets and remote hiring.
Enterprise AI impersonation fraud is a social engineering attack in which criminals use generative AI to convincingly copy the face, voice or writing style of someone an employee trusts, then use that trust to trigger a payment, a data transfer or an access change.
It is a newer form of the classic impersonation attack. What changed is cost and quality. A convincing voice clone once required studio recordings. Research from McAfee found that three seconds of audio can produce a clone with roughly an 85% voice match, and most executives have hours of conference talks, earnings calls and podcasts online.
AI impersonation protection is the set of technical controls and business processes that detect synthetic media and verify identity before a high-risk action goes through.
In This Article
Most attacks follow the same pattern: research the target, pick a trusted identity, create urgency, and move the victim to act before they check. The channel varies.
Attack type | How it works | Typical goal |
|---|---|---|
Deepfake video calls | Attackers join a Zoom, Teams or Meet call wearing a real-time face and voice swap of an executive, sometimes with several fake colleagues present. | Urgent wire transfers, confidential deal payments |
Voice cloning (vishing) | A cloned voice calls or leaves a voicemail for finance, IT or the help desk. CrowdStrike reported a 442% jump in vishing between the first and second half of 2024. | Password and MFA resets, payment approvals |
AI-written phishing and BEC | Large language models write flawless emails and texts in an executive's tone, often following up on a real thread. | Invoice fraud, vendor bank account changes |
Official and executive impersonation by text | The FBI warned in May 2025 of a campaign using texts and AI voice messages posing as senior US officials to build rapport, then steal account access. | Credential theft, onward targeting of contacts |
Deepfake job candidates | Fraudsters use face swaps and synthetic identities to pass remote interviews. See our guide to deepfake job candidates and HR verification. | Insider access, payroll fraud, data theft |
The strongest attacks mix channels. An email sets up the request, a cloned voice confirms it, and a short video call closes it. That is why deepfake detection fails without cross-channel awareness.
Reported AI fraud losses are already near $1 billion a year in the US, and analysts expect them to grow roughly 32% annually.
Metric | Figure | Source |
|---|---|---|
Organizations hit by a deepfake attack in the past 12 months | 62% | |
US losses reported to the FBI with an AI link, 2025 | $893 million across 22,364 complaints | |
Business email compromise losses, 2025 | $3.05 billion | |
Projected US generative AI fraud losses by 2027 | $40 billion, up from $12.3 billion in 2023 | |
Largest known deepfake video call loss | About $25 million (HK$200 million) |
The FBI notes its AI figure only counts cases where victims recognized and reported AI use, so true losses are almost certainly higher. For a fuller dataset, see Deepfake Statistics 2026.
In early 2024, a finance employee at engineering firm Arup's Hong Kong office received a message from the "CFO" about a confidential transaction. The employee was suspicious until a video call showed the CFO and several familiar colleagues. Every one of them was a deepfake. The employee made 15 transfers totaling about $25 million. Read the full breakdown in what the Arup attack teaches about deepfake CEO fraud.
The lesson: seeing and hearing someone is no longer proof of identity.
Most security stacks were built to find malicious code, not a fake person. AI impersonation attacks often carry no malware, no bad link and no spoofed domain.
Email security scans links, attachments and sender reputation. A text-only request from a compromised or lookalike account can pass every check.
MFA and SSO confirm that a device or account is trusted. They say nothing about who is speaking on a live call.
Awareness training asks people to spot fakes. Real-time deepfakes are now good enough that trained staff struggle, and McAfee found 70% of people are not confident they can tell a cloned voice from a real one.
Point tools cover one channel. An attack that starts in email and ends on a Teams call slips between them.
The Verizon Data Breach Investigations Report continues to find the human element in most breaches. That makes the people layer the attack surface, which is the idea behind human layer security.
Effective AI impersonation protection has five layers: real-time detection, cross-channel coverage, clear signals for employees, out-of-band verification, and policies that match the threat.
Real-time deepfake detection. Analyze live video, audio and images while the conversation is happening, not after the money has moved. Multiple detection models reduce the chance that one new generation technique slips through.
Cross-channel coverage. Protect video conferencing, phone calls, messaging, files and email from one platform, so a multi-step attack is seen as a single event.
Clear signals for employees. A simple indicator, such as green, yellow or red, tells staff whether to trust, pause or stop, without requiring them to judge pixels.
Out-of-band verification. For payments, bank detail changes and credential resets, confirm through a second, pre-registered channel. Never use contact details supplied in the request itself.
Policy and training that match the threat. Give finance, HR and help desk teams permission to slow down any urgent request, even from the CEO.
Netarx Identity Key (NIK) is built around this model. It detects GenAI impersonation across Zoom, Teams, Webex, Meet, voice, messaging and email, and shows a traffic light signal in real time. Learn more about why a dedicated detection layer is now a baseline requirement, or see how this fits a broader human defense strategy.
Start with the workflows where one convincing call can move money or grant access.
Map high-risk workflows: wire approvals, vendor bank changes, payroll updates, help desk password and MFA resets, and remote hiring.
Require out-of-band callback verification for any payment or bank detail change above a set threshold.
Set a code word or internal verification step for executives and their assistants.
Deploy real-time deepfake detection on video conferencing and voice before email-only tools are expanded.
Add identity checks to remote interviews and onboarding.
Reduce executive voice and video exposure where practical, and monitor for cloned profiles.
Run a deepfake tabletop exercise with finance, HR, IT and communications.
Update the incident response plan with steps for suspected synthetic media, including who can freeze a payment.
Track metrics: attempts detected, payments paused, time to verify.
Many teams now manage these steps as an ongoing trust program. Our guide to TrustOps explains how to run it, and our overview of social engineering attacks covers the wider threat.
Enterprise AI fraud works because it turns trust into an attack vector. The fix is not asking employees to become deepfake experts. It is giving them real-time signals they can act on, and processes that make verification routine.
Ready to see AI impersonation protection in action? Book a demo, try NIK, or explore more guides in the Netarx Resource Center.
SOURCES & REFERENCES

Chief Executive Officer
CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.
AI impersonation protection is a combination of technology and process that detects deepfake video, cloned voices and AI-generated messages, and verifies identity before employees act on a request. It protects the people layer that traditional security tools do not cover.