Independent analysis of artificial intelligence in business
Efficiency Innovations
Home / Accounting & Finance
Accounting & Finance

How Criminals Use AI to Commit Business Fraud

Most of this publication's fraud coverage examines AI on defense. This article examines the offense, because the same technology a finance department evaluates for monitoring is already in production on the other side: writing the phishing email, cloning the executive's voice, generating the video call, fabricating the invoice, and assembling the synthetic identity. The controls that survive this shift are the ones that never trusted eyes and ears in the first place.

The defining case: In January 2024, a finance employee in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House, received an email from someone claiming to be the company's UK-based chief financial officer, requesting confidential transactions. He suspected phishing. His doubts were resolved by a video conference in which the CFO and several colleagues appeared and instructed him to proceed. He executed 15 transfers totaling roughly $25 million to five Hong Kong bank accounts. Every other participant on the call was an AI-generated deepfake, built from publicly available video and audio of Arup executives. The fraud surfaced only when he followed up with headquarters. No Arup system was compromised; the funds have not been recovered.

The Arup case earned its place as the standard reference because of what it did not require. There was no malware and no network intrusion; the company's own chief information officer described it as technology-enhanced social engineering rather than a traditional cyberattack. The victim wasn't careless; he suspected the initial email and was talked out of his suspicion by a fabricated meeting in which familiar faces agreed with each other. And the production values were not exotic: the deepfakes were assembled from conference footage and interviews any company posts publicly, with the fake participants issuing directives and avoiding extended conversation. The lesson for every business is uncomfortable and simple. Seeing and hearing a trusted colleague is no longer identity verification, and every fraud control built on the assumption that it is has quietly expired.

The Toolkit

Fluent, personalized deception at scale. The oldest tell in business email compromise was the language: the odd phrasing, the grammatical slip, the generic greeting. Generative AI removed it. Fraudulent payment requests, vendor correspondence, and executive impersonations can now be written fluently in any language, personalized from the target's LinkedIn, press releases, and vendor relationships, and produced in volume. BEC was already among the most damaging fraud categories when it required skilled human writers; AI removed the writers as the bottleneck. The urgency mechanics described in this publication's analysis of AP fraud exposure are unchanged; what changed is that every attacker now writes like a native-speaking colleague who knows the account.

Cloned voices. Seconds of audio from an earnings call, a webinar, or a voicemail greeting are enough to synthesize an executive's voice, and voice is exactly what legacy payment controls trust: the phone call confirming the wire, the CFO's verbal approval, the vendor calling to update banking details. Voice-clone attempts against businesses are now routinely documented, including a reported attempt to impersonate the chief executive of LastPass to an employee, and the attack fits neatly into AP workflows because a confirming phone call is what a diligent employee would ask for. The callback control still works, with one adjustment: the call must go out, to a number the company already had on file, never back to whoever is asking.

Deepfake video. Arup demonstrated the ceiling: a multi-participant meeting in which every face and voice except the victim's was synthetic. The technique has since become a pattern rather than an incident, with police and insurers reporting similar schemes against other firms. What makes video especially dangerous is its psychological role as the escalation path: it's where a suspicious employee goes to resolve doubt, which means the fabricated meeting doesn't just deceive, it specifically defeats the victim's own diligence.

Fabricated documents. Generative tools produce invoices, receipts, purchase documentation, bank letters, and supporting records that are visually and structurally convincing, matched to a real vendor's template and engineered to pass automated capture. This lands directly on the AP process this publication has examined in depth: an extraction pipeline reads what the document says, not whether the obligation behind it exists, so document quality no longer distinguishes real from fake. The screens that still discriminate are the contextual ones examined across the AI in Accounts Payable section: does a purchase order and receiving record stand behind the invoice, does the vendor's behavior match its history, has the banking destination changed.

Synthetic identities. AI-generated faces and assembled identity fragments now defeat remote onboarding checks. In the same Hong Kong investigation that surfaced the Arup case, police reported fraudsters using stolen identity cards for 90 loan applications and 54 bank account registrations, deceiving facial recognition systems with AI on at least 20 occasions. For businesses, the same technique manufactures vendors that pass registration checks and employees who pass remote hiring, complete with references, documents, and a face for the interview call.

The expensive assumption is that fakes look fake. Every tool in this catalog exists to make the fraudulent request indistinguishable from the workflow it imitates.

Why the Math Favors the Attacker

Two economic facts drive the trend. The first is cost collapse: what the Arup attackers assembled required commodity AI services, public footage, and days of preparation, capability accessible to organized crime rather than nation states. The second is preparedness lag: the ACFE and SAS's 2026 benchmarking of anti-fraud professionals found only 7 percent of organizations consider themselves prepared for deepfake-enabled fraud, while Deloitte's financial services researchers have projected generative AI could push fraud losses toward $40 billion in the United States by 2027. Cheap offense, unprepared defense, and a technology that improves monthly is not a stable equilibrium, and the targets are shifting downmarket accordingly: the mid-size company with concentrated wire authority, thin verification procedures, and executives who post video content is precisely configured for this attack class.

The Controls That Still Hold

The defense follows from the offense's one limitation: AI fakes the channel, not the world. Synthetic media can put a convincing CFO on a call; it can't answer a callback placed to the CFO's known number, satisfy a second approver on an independent channel, or conjure the purchase order behind a fabricated invoice. The durable controls are therefore procedural and deliberately analog. Out-of-band verification for every vendor banking change and every unusual payment instruction, outbound, to contact details already on file. Multi-person, multi-channel approval for large transfers, with no single meeting, call, or email sufficient to move money, and explicit policy that urgency and confidentiality claims trigger more verification, not less, since manufactured urgency is the constant across every scheme in this catalog. Deepfake-aware training that rehearses the specific scenario: the familiar face on the call asking for a quiet exception. And underneath the human procedures, the behavioral monitoring layer this publication's AP fraud coverage describes, because a deepfake that defeats every person still produces transactions, and fifteen wires to five new accounts in a day is exactly the pattern deviation that anomaly screening exists to catch. Some of this adds friction to legitimate work. That's not a defect; slowing down the moment when money moves on the strength of a face, a voice, or a document is the entire point, because those are precisely the things that can now be manufactured.

The adversarial framing this publication used in its fraud detection analysis deserves the last word: both sides of this contest are now using AI, and the defensive question is no longer whether the request looks legitimate. Everything looks legitimate. The question is whether the transaction, the change, and the behavior fit the company's own history, verified through channels the attacker doesn't control.

Sources and Notes

  • Arup case: Hong Kong police reporting (February 2024) and Arup's confirmation (May 2024) that fake voices and images were used; approximately $25 million (HK$200 million) across 15 transfers to five accounts; deepfakes constructed from publicly available footage; discovery via follow-up with headquarters; no systems compromised per Arup's chief information officer, who has publicly discussed the incident as technology-enhanced social engineering; funds unrecovered as of the most recent reporting. As reported by CNN, CFO Dive, the World Economic Forum interview with Rob Greig, and Hong Kong police statements.
  • Hong Kong police additionally reported related deepfake fraud operations using stolen identity cards for 90 loan applications and 54 bank account registrations, with facial recognition systems deceived by AI on at least 20 occasions.
  • ACFE and SAS, 2026 Anti-Fraud Technology Benchmarking Report: 7 percent of organizations report preparedness for deepfake-enabled fraud; first edition measuring fraudster use of technology. Deloitte Center for Financial Services projection of generative AI-enabled fraud losses approaching $40 billion in the US by 2027.
  • Reported voice-clone impersonation attempt against LastPass's chief executive, per the company's public disclosure and subsequent coverage.
  • Related analysis: AI Accounting Fraud Detection, Why Accounts Payable Is a Fraud Target, How AI Detects Vendor Fraud, and the AI in Accounts Payable section.