Deepfake and AI-driven impersonation threats are rapidly emerging as a top concern for financial institutions. During a recent webinar, Deepfakes and The Future of Security Awareness, we polled 85 financial institution professionals about the threats deepfakes pose. Based on the survey responses, the data reveals clear results:
Overall, organizations recognize the risk, but many have not set up systems and processes to mitigate the growing risk of deepfakes.
Deepfake attacks are actively happening at organizations. Nearly 25% of respondents reported a known deepfake or AI impersonation incident, and another 21% were unsure. This aligns with the assumption that roughly 1 in 4 organizations reported a suspected or confirmed incident, and it suggests that not only are deepfakes occurring, but some are likely going unrecognized.
This uncertainty is consistent with the nature of AI-driven attacks, which are designed to blend into normal business communication and take advantage of our natural reactions. We are less likely to question something when it feels real, comes from someone familiar, creates a sense of urgency, and feels overwhelming.
Deepfake attacks don’t succeed by hacking systems; they succeed by hacking us.
These attacks can look like:
Financial Institutions should assume attempts are already occurring, regardless of whether they’ve been formally detected. To address this gap, financial institutions should focus on strengthening both employee awareness and organizational responses by:
1. Strengthen Detection and Reporting
Train employees to recognize common tactics including messages that convey urgency, authority, emotional pressure and unexpected requests. Employees should know when to pause, verify the request through a trusted channel, and report suspicious communications.
2. Formalize Response Procedures
Include deepfakes and AI impersonation attempts in existing incident response procedure. Clearly define how employees should report a suspected incident, who should be notified, and how the institution will investigate and respond.
3. Validate Your Readiness
Many organizations assume they would recognize an impersonation attack, but without testing, that confidence may be misplaced. Use tabletop exercises and realistic simulations to identify gaps and give employees practice responding to these situations.
Social engineering (38%) and voice cloning (36%) are the top concerns for financial institutions. It’s still important to educate on high-profile scenarios, such as fake videos or vendor impersonation. However, respondents are most concerned about everyday interactions, during which an attacker could take advantage of an existing relationship or familiar voice.
Unlike traditional phishing, deepfake social engineering attacks are becoming more personalized, and are difficult to distinguish from legitimate requests.
Voice cloning introduces another layer of risk because organizations have traditionally trusted a familiar voice as a means to confirm someone’s identity. What was once considered a strong authentication method can now be replicated with alarming accuracy.
|
Deepfakes pose as an emerging fraud and access threat that is directly tied to core operational risks such as wire transfer fraud, account takeover, help desk exploitation, and other social engineering attacks. The following are ways to increase awareness within your organization:
1. Focus on High-Risk Interaction Points
Organizations should prioritize controls around areas where trust-based decisions are made, including financial transactions, account changes, internal approvals, and help desk requests.
2. Enforce Verification and Call Backs
Processes that rely heavily on caller identity, recognized voices, and familiar communication patterns may no longer be sufficient on their own. Additional verification steps should be considered for high-risk requests like only using trusted channels, calling back using a previously established contact method, and, finally, no exceptions. Verifications apply to everyone, even if they are an executive or an important vendor.
3. Align Training with Real-World Attack Scenarios
Employees should be trained not just to recognize suspicious messages, but to question the context, the story being presented, and any sense of urgency.
Lastly, we wanted to understand how confident institutions were in their employees’ ability to recognize deepfake attacks and whether they are actively preparing through exercises and testing.
Based on this feedback, roughly 8% of respondents reported high confidence in their employees’ ability to detect AI-driven threats, while the majority reported only moderate or low confidence.
At the same time, most organizations have not tested their response capabilities in realistic scenarios, which could factor into why the confidence in identifying deepfakes is low.
Together, this information highlights a critical disconnect:
A significant risk exists that goes beyond awareness and affects employees' ability to recognize, verify, and respond appropriately to threats. To address this gap, here is what financial institutions should focus on.
1. Conduct Scenario-Based Exercises
Use realistic simulations to test how employees make decisions during a deepfake or AI impersonation attempt. These exercises can uncover gaps in procedures, communication, and coordination across the institution.
2. Reinforce Through Repetition
Regular testing and reinforcement help ensure that employee confidence is backed by practical experience and proven processes, not just theoretical understanding.
3. Create a Strong Security Culture
Establish an environment where employees feel comfortable to report suspected attacks and do not hesitate to report due to feeling embarrassed or ashamed.
Financial institutions need documented processes, consistent verification procedures, regular testing, and the ability to demonstrate those efforts to regulators and auditors.
Tandem helps organizations move from awareness to operational readiness by providing tools to document, manage, and validate security and compliance activities across the organization.
Tandem Incident Management provides pre-built incident response workflows that help organizations:
Tandem Phishing and Training enables organizations to:
Tandem Risk Assessment helps teams document:
Tandem Audit Management provides a centralized system for:
Deepfakes in banking refer to the use of artificial intelligence to create realistic audio, video, or written content that impersonates real people. In financial institutions, this is used in fraud schemes where attackers pose as executives, employees, or customers. These impersonation attempts are designed to appear legitimate, making them difficult to detect and highly effective in gaining access to systems, data, or funds.
Deepfakes are most often used to support social engineering attacks, during which individuals are manipulated into taking action. In financial environments, this typically involves fraudulent requests related to payments, account access, or sensitive information. Attackers may use AI-generated emails or cloned voices to create urgency and trust, increasing the likelihood that employees will follow instructions without verifying the request.
Banks and credit unions are especially at risk because their operations depend heavily on trusted communications and quick decisions. Employees regularly handle transactions, make account changes, and respond to requests that often seem normal and expected.
Deepfake attacks exploit these normal workflows by making fraudulent requests look legitimate, which increases the chance of human error and successful fraud.
The most common deepfake attacks in financial institutions are not video manipulations but rather subtle impersonation attempts embedded in everyday communication. These include AI-generated phishing emails, voice cloning used in phone calls, and fake executive requests. These attack types are effective because they align closely with how employees already communicate and conduct business.
Employees can detect potential deepfake scams by focusing on context rather than just content. Many attacks include signs such as urgency, requests that bypass standard procedures, or situations that do not match normal business practices. The most effective response is to pause and verify requests involving sensitive actions, especially when they involve financial transactions or access to confidential information.
Preventing deepfake fraud requires strengthening verification processes and reducing reliance on trust alone. Financial institutions should ensure that high-risk actions require multiple forms of validation and cannot be completed based solely on a single communication channel. Enforce employee use of trusted channels, callback using a previously established contact method, and establish that there are no exceptions. Verifications apply to everyone, even if they are an executive or an important vendor
Preparation requires more than awareness. Financial institutions need to ensure their teams can respond effectively in real-world situations. This includes training employees on realistic attack scenarios, validating response procedures through exercises, improving how incidents are reported and analyzed, and creating a strong security culture that makes employees comfortable to report. Organizations that regularly test their readiness are better equipped to identify gaps and respond quickly when an actual attack occurs.