AI-Powered Fraud: A New Category of Cyber Threat
The past 18 months have seen a step-change in the sophistication of fraud targeting businesses. Criminals now have access to generative AI tools capable of cloning voices from seconds of audio, creating video of individuals saying things they never said, and crafting personalised phishing emails indistinguishable from genuine communication. What was previously confined to well-resourced nation-state actors is now available to criminal groups with modest budgets — and the results are landing in the inboxes and phone logs of businesses across the country.
Voice Cloning and the CEO Fraud Evolution
Business email compromise has been the dominant fraud type for several years. The newer variant — voice cloning fraud — takes the same basic approach but adds a layer of authenticity that makes it far harder to detect. In a typical attack, a criminal calls a finance team member impersonating the CEO or CFO, using a voice cloned from audio scraped from public sources: interviews, conference presentations, LinkedIn videos. The "CEO" instructs the finance officer to make an urgent payment to a new account, often with a plausible business explanation. The instruction sounds exactly like the real person. Without a verification protocol in place, many finance teams comply.
Several documented incidents involving businesses in the Asia-Pacific region in 2025 resulted in losses exceeding $500,000 from a single call. In one widely-reported international case, a finance worker authorised transfers of approximately USD$25 million after a video call with what appeared to be multiple senior company executives — all of whom were deepfakes.
AI-Enhanced Phishing: The End of "Obvious" Scams
Traditional phishing emails were detectable by poor grammar, generic salutations, and implausible scenarios. AI-generated phishing has eliminated most of these tells. Modern phishing attacks use large language models to craft emails that perfectly mimic the writing style of a known contact, reference specific recent events or conversations, and present entirely plausible scenarios. The email appears to come from a trusted colleague and contains information that only that person could plausibly know — because the attacker has scraped that information from email chains, LinkedIn, and company websites.
These attacks are substantially harder for staff to detect through intuition alone. They require process-based defences — verification protocols, approval workflows, and out-of-band confirmation — rather than relying on staff to spot an "obvious" scam.
Synthetic Identity Fraud and Business Onboarding
AI-generated synthetic identities — fictitious individuals with AI-created photo IDs, voice profiles, and document sets — are increasingly being used to defraud businesses during customer or supplier onboarding. Financial service firms, professional services companies, and businesses that extend credit face the greatest exposure here. A synthetic identity that passes standard KYC checks can be used to establish credit relationships, receive goods or services, and disappear — leaving the business with unrecoverable losses.
Deepfake Video in Corporate Governance
Beyond fraud targeting finance teams, deepfake technology is being used in corporate governance attacks — creating false video evidence of board decisions, creating deepfake content to damage executive reputations, or manipulating video communications to extract sensitive information. While these attack types are currently less common than voice cloning, the NCSC has flagged them as a growing concern for larger organisations.
What Cyber Insurance Covers for AI Fraud
Coverage for AI-powered fraud depends significantly on how your cyber insurance policy is structured. Social engineering fraud coverage — which responds to losses from BEC and similar deception-based attacks — is the most relevant component. This coverage typically applies when an employee is deceived into authorising a fraudulent payment or action through electronic communication, including AI-generated voice or video.
However, social engineering fraud coverage often has sub-limits substantially lower than the overall policy limit, and some policies require specific conditions to be met (such as verification procedures being in place). It is worth reviewing the social engineering section of your current policy — or if you are obtaining cover for the first time, specifically asking about the sub-limit and conditions for this coverage.
Reducing Your Exposure: Process Controls That Work
Cyber insurance provides the financial backstop, but the most effective defence against AI fraud is procedural. A mandatory out-of-band verification call using a pre-verified number for any payment instruction above a defined threshold is the single most effective control. "Above a defined threshold" should be set at whatever level a loss would cause material impact — for many businesses, this is $5,000–$10,000. If the instruction is genuine, the verification call takes 60 seconds. If it is fraudulent, it stops the loss entirely.
About the Author
CyberCover Team is part of the CyberCover team — dedicated to making cyber insurance transparent and accessible for NZ businesses of all sizes.