AI Automation

Deepfake Fraud in 2026: How AI-Powered Automation Protects Your Company's Payments

A convincing voice message from the CEO asking for an urgent payment used to be a rare, expensive attack. In 2026 the tools needed to create convincing impersonations are far more accessible, and the data is clear about who wins: companies with a verification process that does not depend on anyone's instinct in the moment.

Picture a finance employee on a busy afternoon. A message arrives that looks like it's from the CEO, followed by a voice note that sounds exactly like the CEO, asking for an urgent payment to a new supplier and asking that it stay confidential. Ten years ago, an attacker needed skill, time, and luck to pull this off. Today, cloning a voice and writing a flawless message takes a fraction of that effort, which is exactly why 2026 security reporting keeps returning to the same theme.

The useful part of that story is what the same data says about defense. The technology criminals use is also available to the companies they target, and the 2026 evidence suggests that well-designed security AI and automation can strengthen broader defensive operations, while payment-specific protection still depends on verification and approval controls that do not rely on recognizing a convincing fake. This article walks through what the latest data shows, three real attempts and what decided each outcome, one safeguard already built into European banking, and how a well-built automated payment workflow puts people and AI on the same side. It is general information, not security or legal advice, and a payment-security setup is worth designing together with your bank and IT security provider.

What the 2026 data actually says

Three recent sources, each measuring something different, are worth reading together.

Europol's Internet Organised Crime Threat Assessment for 2026, published on 28 April 2026 under the title "How encryption, proxies and AI are expanding cybercrime," points to online fraud as one of the fastest-growing areas of organised crime affecting the EU, in a landscape where schemes such as business email compromise sit alongside investment scams and other fraud types, according to Europol's published summary and coverage of the report. It also notes that readily available AI tools lower the skill needed to produce convincing social engineering. Europol's earlier EU-wide assessment, published in 2025, similarly describes online fraud as increasingly driven by AI-powered social engineering.

The FBI's 2025 Internet Crime Report, published in April 2026, is US data, and it's worth flagging that up front. It logged 1,008,597 complaints and roughly $21 billion in reported losses, with about $17.7 billion of that involving cyber-enabled fraud rather than technical intrusion. Business email compromise accounted for roughly $3 billion. For the first time, the report included a dedicated section on AI: 22,364 complaints that referenced AI, with about $893 million in reported losses. These are complaints that mention AI, not a measurement of how many attacks used it, and the true figure is hard to know.

IBM's 2026 Cost of a Data Breach Report, released on 29 July 2026 and based on 602 organizations breached between March 2025 and February 2026, adds a global view. The average breach cost reached a record $4.99 million. AI-driven attacks rose 56% year over year, and more than one in four malicious breaches now involves AI in some form, costing roughly $1 million more on average than malicious breaches without it.

What these sources have in common is where the loss happens. In the FBI data, the large majority of losses come from fraud that persuades a person to act, not from breaking into systems. That's the more encouraging reading of an alarming set of numbers: the weak point is a decision made under pressure, and decisions made under pressure are exactly what a well-designed process is built to protect.

The same technology is on both sides, and setup is the difference

IBM's 2026 report contains one of the clearest data points for anyone weighing whether to invest in AI. Organizations that used security AI and automation extensively across prevention, detection, investigation, and response averaged $4.00 million per breach, against $5.93 million for organizations that used none, a difference of $1.93 million, with breaches identified and contained about 65 days faster. It's an association, not proof that AI alone caused the difference, and IBM also finds that organizations with stronger foundational practices, such as identity and access management and encryption, did better overall. It's also worth being precise about scope: these figures describe security operations broadly, meaning prevention, detection, investigation, and response. They don't measure payment-approval workflows or deepfake payment fraud specifically, so they support the case that well-implemented AI and automation strengthen defense, not a measured result for the workflow described later in this article. The direction is consistent, though, and the adoption gap is striking: only 36% of the breached organizations used these tools extensively across the whole lifecycle.

The same report contains the other half of the lesson. Roughly one in five organizations reported a security incident involving an AI model or application, and among those, 92% were missing basic controls such as role-based access and multifactor authentication on their AI systems. In other words, the risk in that data wasn't AI itself, it was AI deployed without the access controls and governance a proper implementation includes. That's the practical case for working with a team that sets AI up deliberately, with scoped access, logging, and human approval where it matters, rather than switching tools on and hoping. We cover the related question of what happens when employees adopt AI tools on their own in Shadow AI: Why Banning AI Doesn't Work, and What Does, and the broader data-handling picture in Is Your Business Data Safe with AI?.

Three real attempts, and what decided the outcome

Three widely reported cases from 2024 show how these attacks actually play out, and what made the difference. They predate 2026, but they remain the best-documented examples of the pattern that current reporting describes.

In July 2024, according to Bloomberg's reporting, an executive at the Italian carmaker Ferrari received WhatsApp messages from a number that wasn't the CEO's usual one, then a phone call in which a deepfake voice convincingly imitated the CEO's accent while discussing a confidential acquisition and a currency-hedging transaction. The executive noticed subtle oddities in the voice and asked a question only the real CEO could answer, the title of a book he had recently recommended. The caller couldn't answer and hung up. Ferrari declined to comment publicly, and the company opened an internal investigation.

In May 2024, according to the Guardian, fraudsters targeting WPP created a fake WhatsApp account using a public photo of the company's CEO and set up a Microsoft Teams meeting with an agency leader, using a voice clone and YouTube footage. The attempt failed. WPP's CEO attributed that to the vigilance of the people involved and warned colleagues about the technique.

The contrast case is Arup, the engineering group, where the Financial Times reported in 2024 that an employee in Hong Kong made a series of transfers totaling roughly $25 million after a video conference in which the other participants were fabricated.

What decided the outcome in each case wasn't how good the fake was. It was whether a verification step existed and got used. Ferrari's executive relied on a spontaneous personal challenge question. That worked, but it depended on one person keeping a clear head and thinking of the right question under pressure, which is precisely what a process should not depend on.

A safeguard your bank already gives you: Verification of Payee

Europe has a concrete, regulated defense that many businesses haven't fully switched on. Since 9 October 2025, payment service providers in the euro area have had to offer Verification of Payee under the EU Instant Payments Regulation. Before a SEPA credit transfer is authorized, the payee's name is checked against the IBAN, and the payer sees a result: match, close match, no match, or unable to verify. Payment service providers outside the euro area have until 9 July 2027.

Two practical details matter. First, a close match or no match warns the payer but doesn't necessarily stop the payment: the payer can still proceed. Second, the regulation allows a narrow waiver: payers who are not consumers can opt out of the service when they submit multiple payment orders together as a package, such as a bulk payment file, and can opt back in. It isn't a general right for a business to switch verification off for all of its payments. It's worth asking your bank how verification is set up for your business, in particular whether any bulk or file-based payments are running without it, and treating a close-match or no-match result as a mandatory stop-and-verify moment rather than a warning to click through.

It's also worth being clear about its limits. Verification of Payee checks that a name and an IBAN belong together. It aims to reduce misdirected payments and swapped-IBAN invoice fraud, but it can't tell you whether the request to pay was genuine, and an account opened in the name of a plausible-sounding supplier can match perfectly. It's one layer, not the whole defense.

A framework for payment safeguards

This is a Kubera AI planning heuristic, not a security standard or certification, meant to structure a conversation between a finance team, a bank, and an implementation partner.

The Kubera Payment Safeguard Model has four layers:

LayerWhat it doesWho is responsible
1. Trigger rulesIdentifies which requests get extra checks: bank-detail changes, first-time payees, amounts above a threshold, requests marked urgent or confidential, requests arriving on an unusual channelThe business defines the rules, automation applies them consistently
2. Out-of-band confirmationConfirms the request through a contact channel recorded in advance, never through the number, link, or meeting invitation in the request itselfA person makes the call, automation creates and tracks the task
3. Two-person approvalRequires a second approver and a short hold on flagged payments, with evidence loggedTwo named people, enforced by the workflow
4. Bank-side controlsVerification of Payee switched on, payment limits, the bank's own alerts and call-back optionsThe business, together with its bank

The point of the model is that no single person has to spot a perfect fake. The attack works by creating urgency and secrecy, and each layer is designed to slow the request down at exactly the moment it is built to speed up.

Where AI genuinely helps, and where people decide

A well-built payment workflow uses AI where it is strong and leaves the decision with people, the same principle we cover in How Much Autonomy Should an AI Agent Have?.

AI is well suited to noticing what a busy person might miss: a payee that has never been paid before, an amount or timing that doesn't fit the pattern, a sender address that differs subtly from the real one, wording that leans on urgency and secrecy, or a bank-detail change arriving shortly after an unusual email. It can raise these as flags, open a verification task automatically, and keep a complete audit trail. What it should not do is approve or release a flagged payment on its own. Approval stays with named people.

It's also worth being realistic about deepfake detection tools. They are improving, but security guidance consistently treats detection as necessary but not sufficient, and pairs it with process controls. A process that works even when the fake is undetectable is stronger than one that depends on detecting it. This kind of workflow can be built on standard automation platforms such as those compared in n8n vs Make vs Zapier, connected to your existing accounting or payment approval tools.

Voice technology also works in the other direction. Because a caller often can't tell whether a voice is human, legitimate AI voice agents should clearly disclose that they're automated, a point we cover in our voice AI guide and in our EU AI Act guide. Labelling rules exist for AI-generated content, but criminals won't follow them, so they are not a substitute for your own verification process.

For context: what the US and European data can and can't tell you

The most detailed public loss data in this space comes from the US, through the FBI's complaint center, and it's worth reading as a US picture rather than assuming it transfers directly to Europe. Reporting systems, definitions, and victim reporting habits differ, and the FBI's AI figures count complaints that referenced AI rather than confirmed AI-driven attacks. On the European side, Europol's assessments describe the direction and the tactics clearly, but in the sources reviewed for this article we did not find an equivalent EU-wide, business-specific loss figure. The direction of travel is consistent across both, and so is the defense: verification processes that don't rely on recognizing the fake.

Where this plays out in practice

Illustrative scenario, not a specific Kubera client: a mid-size distributor's finance clerk receives an email and a voice message that appear to come from the managing director, asking for an urgent transfer to a new supplier and asking that it stay confidential. The company's payment workflow automatically flags the request because the payee is new, the amount exceeds the approval threshold, and the message language is urgent. It opens a verification task assigning a colleague to call the managing director on the number stored in the company's records, not the number in the message, and it requires a second approver. The bank's Verification of Payee check returns a close match, which the workflow treats as a hold. The managing director confirms they sent nothing, the payment is never released, and the incident is logged and reported to the bank. At no point did anyone need to decide whether the voice was real.

FAQ

Do we need an AI deepfake detection tool to be protected? It can be a useful extra layer, but it shouldn't be the foundation. Security guidance generally treats detection as necessary but not sufficient. A verification process that works even when the fake is undetectable is the stronger base.

Does Verification of Payee stop deepfake CEO fraud? Not by itself. It checks that a payee name and IBAN belong together, which helps against swapped-IBAN invoice fraud and misdirected payments. It can't tell whether the instruction to pay was genuine, so it works best as one layer alongside out-of-band confirmation and two-person approval.

Is our business really a target, or is this only about large companies? The best-known cases involve large firms because those are the ones reported publicly. The techniques scale to any business with a finance function, and Europol's assessments describe fraud targeting individuals, businesses, and financial systems. Smaller firms often have fewer approval layers, which is a reason to build them in.

Should we ban AI voice and video tools to reduce the risk? Restricting tools doesn't address how these attacks work, which is by persuading a person to bypass a process. A verification process addresses that directly. We cover why blanket bans tend to backfire in our Shadow AI article.

What should we do if a fraudulent payment has already been sent? Contact your bank immediately to ask about recalling the payment, since speed matters and recall options vary. Report the incident to the police as well. If personal data may also have been exposed, a GDPR breach assessment may be needed, and this is worth reviewing with your data protection officer or counsel. This is general information, not legal advice.

Is it allowed to record verification calls? Recording is a separate decision from making the call. The lawful basis, notice, and national rules depend on why and how calls are recorded, and it's often enough to log that verification took place and its outcome without keeping a full recording. Confirm the rules for the countries involved before deciding.

How does an automated payment workflow help if the attacker is convincing? It removes the need to be convinced or unconvinced. The workflow applies the same checks to every flagged request, whether or not the request seems legitimate, so an attacker's pressure and polish have nothing to work on.

Does the EU AI Act's labelling of AI-generated content protect us? Not directly. Labelling obligations apply to those who comply with them, and criminals won't. Your own verification process is what protects your payments.

Do staff still need training? Yes, alongside process. Training helps people recognize pressure tactics and follow the process under stress, and the process ensures the right steps happen even when someone is rushed. We cover how to build adoption in How to Onboard Your Team to AI Automation.

What's a sensible first step? Map how payments and bank-detail changes are actually requested and approved today, then identify which requests are high risk and which checks are currently missing. That map tells you where an automated workflow adds the most protection for the least disruption.

If you'd like to see where your payment and approval processes could be made harder to fake, and what a well-built, AI-assisted verification workflow would look like for your team, that's exactly the kind of design work worth doing before an urgent message arrives.

Discuss your automation project →

Back to blog