Part 5 of 12 — The New IT Reality
A series for CEOs and business leaders examining how IT challenges don't replace each other — they accumulate.

In February 2024, a finance worker at a multinational company in Hong Kong transferred $25.6 million to criminals. He did this after attending a video conference call with his Chief Financial Officer and several colleagues — all of whom instructed him to make the transfer.

Every person on that call was an AI deepfake. Every single one.

The employee had initially been suspicious. He'd received an email that seemed like a phishing attempt. But the video call convinced him. He could see his CFO's face. He could hear his voice. His colleagues nodded along. The meeting felt real because, to every human sense available through a screen, it was real.

This is not science fiction. This is not a theoretical risk for your next board presentation. This happened. The technology used is commercially available. And it is getting cheaper, more accessible, and more convincing every month.

The End of "Trust Your Eyes"

For decades, cybersecurity awareness training has relied on a simple set of rules: check the sender's email address, look for spelling mistakes, be suspicious of urgent requests, verify by phone if something feels wrong.

AI has rendered most of these obsolete.

AI-generated phishing emails don't contain spelling mistakes. They don't use awkward phrasing. They write perfect English, perfect Greek, perfect German — in whatever register, tone, and style matches the supposed sender. They can reference recent company events, ongoing projects, and internal terminology that only someone with insider knowledge would use.

Because the AI was trained on publicly available data about your company. Your website, your LinkedIn posts, your press releases, your employees' social media — all of it feeds the machine that crafts the perfect pretext.

Voice Cloning: Three Seconds Is All It Takes

Modern AI voice cloning requires approximately three seconds of sample audio to create a convincing replica of someone's voice. Three seconds.

Your CEO gave a keynote at a conference that's on YouTube. Your CFO was interviewed on a podcast. Your HR director has a welcome video on the company website. Every one of these is a voice sample waiting to be exploited.

In 2023, a mother in Arizona received a phone call from her daughter — sobbing, terrified, begging for help. A man's voice came on demanding ransom. The daughter was safe at home the entire time. The voice was cloned from a TikTok video.

Now transpose this to a business context. Your finance manager receives a call from the CEO: "I'm closing a confidential acquisition. I need you to wire €180,000 to this account. Don't discuss this with anyone — we'll announce on Monday." The voice is perfect. The tone is right. The number calling appears to be the CEO's mobile.

How confident are you that your finance manager would refuse?

Video Deepfakes: Seeing Is No Longer Believing

Real-time face-swapping in video calls is no longer a research project. It is available as a commercial service. The Hong Kong case demonstrated this at scale — multiple participants, sustained interaction, convincing enough to override an employee's initial suspicion.

The technology works by mapping a source face onto a target in real-time, with lighting adjustments, expression matching, and lip synchronisation that improves with each generation. Current systems can run on consumer hardware. Within two years, they will run on a smartphone.

The implications for business verification are profound. Board meetings, client calls, vendor negotiations, audit discussions — any video interaction can potentially be fabricated. The technology doesn't need to be perfect. It needs to be good enough that you don't question it during the three minutes it takes to authorise a payment.

CEO Fraud: From Nigerian Princes to Perfect Impersonation

Business Email Compromise (BEC) has been the most financially damaging category of cybercrime for years. The FBI's Internet Crime Complaint Center reported over $2.9 billion in BEC losses in 2023 alone. That was before AI made these attacks dramatically more sophisticated.

The evolution is worth understanding:

2015: Badly written emails from "the CEO" asking for wire transfers. Obvious to anyone paying attention.

2019: Well-crafted emails that spoofed internal email addresses, referenced real projects, and created convincing urgency. Required careful examination to identify.

2024: AI-generated emails with perfect language, followed by AI voice calls for verification, potentially supported by deepfake video. Virtually indistinguishable from legitimate communication through any single channel.

2026: Multi-channel, sustained impersonation campaigns where AI maintains consistent personas across email, voice, video, and messaging platforms simultaneously.

Each generation made the previous detection methods inadequate. We are now at a point where the technology of deception has outpaced the human ability to detect it through observation alone.

AI-Powered Content Flooding

The threat extends beyond targeted fraud. AI enables disinformation and manipulation at scales previously impossible:

SEO poisoning: AI generates thousands of convincing articles designed to manipulate search results, pushing legitimate content down and fake content up.

Fake reviews: AI-generated reviews indistinguishable from real ones, deployed at scale to boost or destroy businesses.

Impersonation campaigns: Fake social media profiles with AI-generated photos, posts, and interactions that build credibility over months before being deployed for fraud.

For businesses, this means your online reputation is more vulnerable than ever. A competitor — or simply a disgruntled customer — can deploy AI-generated negative reviews, fake complaints, and manufactured controversies at a cost approaching zero.

The Trust Crisis

The deeper problem isn't any single attack vector. It's the erosion of trust itself.

When you can't trust what you see in a video call, when you can't trust what you hear on a phone call, when you can't trust what you read in an email — how do you verify? How do you do business?

The answer isn't more technology. Not primarily. The answer is process.

Practical Defences That Actually Work

The most effective defences against AI-powered social engineering are, ironically, low-tech:

Callback verification on known numbers. Never act on a financial instruction received via email, call, or video without calling back on a number you already have on file. Not the number provided in the communication — a number from your records.

Multi-person authorisation. Any financial transaction above a threshold requires sign-off from multiple people through independent channels.

Code words. Establish verbal code words for high-value transactions that change periodically and are never communicated electronically.

Out-of-band confirmation. If the CEO calls asking for a transfer, the finance team confirms via a different channel — a walk to their office, a text message, a call to their personal phone.

Mandatory delays. Build cooling-off periods into financial processes. Urgency is the attacker's primary weapon. Removing the ability to act immediately removes most of the attack's power.

Regular training with realistic simulations. Not annual compliance videos. Monthly exercises using AI-generated phishing attempts tailored to your organisation.

The Greek Context

If you think Greek businesses are too small or too local to be targeted — think again. AI phishing now writes perfect Greek. Voice cloning works in any language. And Greek businesses, particularly those in shipping, energy, and professional services, handle transaction volumes that make them attractive targets.

The cultural factor matters too. Greek business culture often relies on personal relationships and verbal agreements. "I know his voice" is considered sufficient verification. In an era of AI voice cloning, this cultural norm becomes a vulnerability.


Key Takeaway

The arms race between AI attack and AI defence has begun. But the most powerful defence isn't technology — it's a culture where your finance team calls back on a known number before transferring money, no matter who appears to be asking.

Previously in the series: AI in Business: Between Salvation and Panic

Next in the series: The Energy Bomb of AI: Why Data Centers Are Reshaping Our World


Want to test how your organisation would respond to an AI-powered social engineering attack? Let's talk about realistic simulation exercises that reveal vulnerabilities before criminals do.