Deepfake Fraud: The New Threat to Financial Services Firms
AI-generated video and voice now target finance teams directly. See how deepfake fraud reaches your firm, and the controls that actually stop it.
Nerdster Team
Picture your finance manager on a video call with your CFO and two colleagues she recognises. She sends the payment they ask for. Every face on that call was fake.
That happened in Hong Kong in February 2024, and it cost the firm $25 million. It is now the case everyone in financial services quotes, because it broke the last assumption we had left: that seeing someone made it real.
Fraud teams and identity-verification vendors all report the same direction of travel: deepfake attempts against financial institutions are rising sharply year on year. Your firm does not need to be a bank to be on that list. Here is how the attacks run, and what stops them.
How deepfake fraud reaches your finance team
A familiar face on a video call is still unverified
Real-time face-swapping is no longer specialist work. Attackers take video of your executives from LinkedIn, conference recordings, or your own website, and wear their faces on a live call.
They aim at whoever can move money: a finance team member, an executive assistant, an operations lead. The call carries the authority of a senior colleague and the urgency of a deadline, and both of those exist to stop your process being followed.
Expect a cloned voice to authorise the payment
Voice cloning needs only a few seconds of sample audio. Results calls, panel appearances, podcasts, and voicemail greetings all supply it. The cloned voice then rings your finance team to push a payment through, usually from a spoofed number that matches the executive’s real one.
Synthetic identities passing your KYC checks
Deepfakes are not only used against you directly. AI-generated faces, paired with stolen personal data, are used to open accounts and can clear basic KYC steps, including video verification. If you onboard clients remotely, this is your exposure.
The paperwork that arrives with the call
Generative AI produces convincing invoices, contracts, and authorisation letters. On its own, a forged document might not clear your checks. Backed by a video call that appears to confirm it, it usually does.
Why attackers pick financial services firms first
Three things put your sector at the front of the queue.
- Large payments are routine. A six-figure instruction raises no eyebrow in a business where six-figure instructions are Tuesday.
- Speed is a virtue in your culture. Trading desks and deal teams are trained to move fast. Attackers are counting on it.
- Your senior people are public. Fund managers, partners, and C-suite executives carry public profiles thick with the video and audio these models need.
Defences that work against a convincing fake
Verify every payment on a second channel
This is the control that does the most work. Any payment instruction or sensitive request arriving by video, voice, or email gets verified through a different channel before anyone acts. Call back on a number you already held, not the one that called you.
Set the rule in writing: above a defined threshold, no single channel is enough to authorise a payment. Informal guidance will not survive a convincing caller.
Agree a challenge phrase no deepfake can know
Some firms rotate a code word that has to appear in any conversation about authorising payment. It is unglamorous and it works. A deepfake can copy a face and a voice. It cannot know this week’s phrase.
The executive footage attackers train on
Look at how much executive audio and video you publish. Do results call recordings need to stay up permanently? Should conference talks sit behind a form? Does every leadership profile need video?
This is not about hiding. It is about choosing your attack surface deliberately instead of accumulating one.
Detection where your calls already happen
Deepfake detection tools now analyse calls for the artefacts a synthetic face leaves behind: inconsistent lighting, unnatural blinking, audio drifting out of sync, odd compression. None of them is conclusive on its own, and they will not replace your verification rule, but they add a layer that catches the lazier attempts.
Ask your IT provider what your conferencing platform supports today and what is on its roadmap, rather than assuming the feature already exists.
Training your team to doubt a face they recognise
Run security awareness training that covers deepfakes specifically. Your team needs to know four things:
- Deepfake technology is cheap, accessible, and convincing
- A video call is not proof of identity
- Exactly which verification steps they must follow, every time
- How to report a suspicion without feeling foolish
That last point carries more weight than the rest. The people who fall for this are experienced and capable. If reporting costs them face, you find out late.
Tighten the payment controls that stop fraud structurally
Your strongest defences are the boring ones you already know:
- Dual authorisation above a threshold
- Separation between whoever creates a payment and whoever approves it
- Callback verification for new payees and any change of bank details
- A cooling-off period on urgent or unusual requests
Showing your regulator you planned for deepfake fraud
The FCA expects regulated firms to fold AI-generated threats into their fraud risk assessments as part of operational resilience. If you suffer a loss and cannot show that reasonable preventive measures were in place, the supervisory conversation that follows is likely to be the harder part.
Write the deepfake scenario into your risk assessment, and keep the evidence that you tested it.
Respond in the first five minutes
If you suspect a deepfake attempt:
- Stop. Do not complete the requested action.
- Verify through a channel the caller did not choose.
- Tell your IT security team immediately.
- Preserve recordings, chat logs, and anything else from the interaction.
- Report to Action Fraud, and if you are FCA-regulated, decide whether a regulatory notification is required.
Harden your firm against a convincing fake
We help hedge funds, private equity firms, and wealth managers put layered hedge fund IT security in place against AI-enabled fraud: detection where it helps, communication security, payment controls, and training your team will remember under pressure. We size it to the threat your firm actually faces.
If you would like a clear view of how your firm would hold up against a deepfake-enabled attack, contact Nerdster for a free IT assessment. We will talk you through what we find and where we would start.