Payment and impersonation
Cloned voices, faked video calls, perfect invoices, redirected bank details. The money branch, covered in depth in Fraud no longer needs a forger.
Old scams, industrialised. What changed and what still works against them.
Almost no AI scam is a new scam. What AI changed is the economics: polish, personalisation and volume that used to take skill now take a subscription. This page maps the family and routes you to the deep dives.
Usually nothing about the scam itself. Invoice fraud, executive impersonation, fake suppliers and phishing all predate AI by decades. What earns the label is how they are now made: fluent messages in any language and register, cloned voices, personalised approaches assembled from public information, and thousands of attempts run for the cost of one.
That shift matters for defence. Training that taught people to spot the fakes by their roughness now protects against attackers who no longer exist. The scams your business will actually meet are polished, are addressed to the right person by name, reference real projects and suppliers, and arrive in believable numbers.
One page in our series on the real risks of AI for a business: old entries on the register, with the likelihood turned up.
Cloned voices, faked video calls, perfect invoices, redirected bank details. The money branch, covered in depth in Fraud no longer needs a forger.
Phishing with flawless grammar and personal context, aimed at logins rather than payments. The stolen account then powers the other three branches.
Suppliers, customers, even job applicants who do not exist: AI-generated websites, references, profiles and interview performances that pass a casual check.
Fabricated compromising material, fake reviews at scale, and threats to publish AI-generated content unless paid. Damage does not require the material to be real.
Detection has moved
The old advice, look for bad grammar, generic greetings, strange phrasing, now selects for the least dangerous attackers. What remains are behavioural tells, because they are the parts the scam cannot remove without breaking itself.
Manufactured urgency. The scam needs you to act before you verify; a genuine counterparty survives an hour's delay. Channel switching. Requests to move from the channel where you could verify to one where you cannot. Verification resistance. Any pushback against a callback, a known number, or a second approver is itself the strongest signal you will get.
Which is why the safeguards are process rather than perception: callbacks on numbers you already had, out-of-band checks on any change of payment details, and dual approval that urgency can never bypass. The full set is on the safeguards page.
When it happens
Speed matters more than embarrassment. Contact your bank immediately if money moved, recalls sometimes succeed in the first hours. Preserve the messages rather than deleting them. Report it: in Australia through the ACSC, in the UK through the NCSC's reporting routes. Then tell your people what the attempt looked like, because the same campaign usually tries several doors.
Afterwards, treat it as free intelligence: re-score the register entry it exploited, and check the safeguard that should have held. Honest reporting inside the business is a safeguard too, and it only works where reporting is never punished.
Payment fraud through cloned voices and polished invoices, credential phishing with personal context, fake counterparties such as suppliers or applicants who do not exist, and extortion using fabricated material. Most are established scams with AI-grade polish, personalisation and volume.
Not by quality any more. The reliable tells are behavioural: manufactured urgency, requests to switch channels, and resistance to verification. If a request cannot survive a callback on a number you already had, treat that as your answer.
Payment authority is concentrated in a few people, verification often relies on familiarity rather than process, and the volume economics of AI mean attackers no longer skip small targets. The same campaign can try ten thousand small businesses for the cost that used to buy one attempt.
Bank first if money moved, since recalls sometimes succeed early. Preserve evidence, report through the ACSC in Australia or the NCSC routes in the UK, warn your own people, and then re-score the register entry the scam exploited while the details are fresh.
Not dependably, and building your defence on detection repeats the mistake that made these scams effective. Process safeguards, callbacks, out-of-band verification and dual approval, work whether or not the fake is detectable.
The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.
AI risk series
The real risks of AI for a business
The series hub: what counts as an AI risk, the four families, and where to start.
Fraud no longer needs a forger
Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.
Guardrails, safeguards, controls: what AI actually needs
Three words untangled, and the four families of AI-era safeguards.
Prompt injection: the attack your register hasn't heard of
Instructions hidden in ordinary content, and the safeguards that limit the damage.
How to run an AI risk assessment
Three ways to do it, compared, and the five steps.
The AI risk register
What every entry carries, with worked examples.
The AI policy your business actually needs
The full template, free on the page, and how to make it yours.
AI in risk management: what it can genuinely do
The four jobs AI does well, and the three things it must never own.
What is AI disruption?
A plain definition: the change is in your risks and plans, not just your tools.
See your own AI risk picture
The risks AI is driving against your objectives, scored for your business.