AI-driven fraud like deepfakes and social engineering scams are becoming more sophisticated — so how can businesses stay ahead?
In this episode, Aarti Samani, a leading fraud prevention expert, uncovers the risks and solutions businesses need to know. With experience working with global institutions like the US Department of Homeland Security, UK Home Office, and Mastercard, Aarti shares first hand insights into how AI is being weaponised and what organisations can do to defend themselves.
From deepfake fraud and AI-generated scams to biometric authentication and corporate risk strategies, Aarti breaks down real-world cases of businesses that fell victim to AI-driven cyber threats. She reveals the common vulnerabilities in organisations — from CFOs receiving fake invoices to HR departments unknowingly hiring AI-generated employees — and provides actionable strategies to mitigate these risks.
Aarti discusses her “Defending Against Deepfakes” masterclass, which helps businesses test their security measures through AI-driven vulnerability assessments. Whether you’re a business leader, security professional, or simply curious about the future of AI in fraud prevention, this conversation will give you essential knowledge to protect your organisation in the AI era.
0:00 Introduction: AI Fraud Threat
3:05 Future-proofing businesses against deepfake fraud
7:23 Human vulnerability & psychological impact of deepfake fraud
14:47 The importance of contextual awareness
18:54 Trust, curiosity & collaboration, striking a balance
25:36 Certification & ongoing engagement
Transcript
SPEAKERS
Speaker 1, Aarti Samani
Speaker 1 00:02
Aarti, Hello everyone, and welcome to another. What I’m going to have to say is very insightful and very valuable episode of sphere of being, because today I have as a very special guest, Aarti Samani. Now Aarti is an expert within the field of AI, from looking at this, from the fraud element, from a financial crime element, she’s also an extensive expert in AI and the threats with that that come around, such as deepfake, things like CEO fraud. And has worked with the likes of Nomura, the UK Home Office, the US Department for Homeland Security, a host of other organizations, including MasterCard, and she has also appeared on BBC. She is a sought after interviewee and also media commentator. She’s also a very, very in command keynote speaker, and is somebody that is keeping up to date and current, and in fact, actually stepping over the current and actually thinking it from a future proofing perspective, everything to do with AI threat. And this is something again, which in this market now, where AI is here, it’s here to stay, to be embraced and used, but we do also have to think of the darker side that can be brought about by AI as well. So Aarti, welcome. It is an absolute pleasure to have you on the podcast.
Aarti Samani 01:40
Thank you, Deborah, I’m delighted to be with you. Thank you for inviting me. I’m looking forward to this conversation.
Speaker 1 01:47
Oh myself as well. And so when we think about yourself getting into a career, what was it that attracted you to this type of work?
Aarti Samani 01:59
Yeah, thank you for asking that it’s a very interesting professional journey I’ve had. I’ve been lucky enough to work in a very diverse range of environment businesses, etc. So I started my career with corporates and working with organizations like Nomura, British Airways, UBS, et cetera, in investment banking tech, where we used AI long time ago before it became mainstream, and then I pivoted into working with high growth technology businesses, startups, scaling them internationally, taking AI, deeptech based products to market and commercializing them. So I led three businesses, two of them had very successful exit, and the third one is a category leader in the space. And that last business is a facial biometric verification for secure identity, remote identity verification. And I led the product and marketing team there and scaled the business. So we were dealing with a lot of deepfake fraud at that time, back in 2018 2019 when it was still very much an emerging threat vector, obviously generative. AI accelerated that whole process and catapulted us into the environment that we are in today, where deepfake and cloned voices are very prolific, very readily available, low barriers to entry. So my my work in deep tech and AI based products led me to working in biometric security products, which then led me to investigate deepfake and then particular interest for me was the human manipulation piece of how these fraud vectors or these attack vectors operate in So a combination of interest organizations that I’ve worked with and where market is very quickly moving to has led me to focusing on this at the moment. And
Speaker 1 03:57
you’ve mentioned the fact that things are moving so fast paced, I’d like you to assist our audience now with the fact that how can you help within your business to keep people beyond the fast pace and actually future proof their business in regards to the activities and the criminal ventures that people are now engaged in in this very leading edge technology.
Aarti Samani 04:32
Yeah, so this is a big question for everyone. How do we protect our organizations, but also ourselves, and until very recently, organizations have mostly relied on security technologies and processes with some employee awareness, user training, etc, put in place, especially when the phishing scam started to become big. Now. Way that AI is being utilized to manipulate human beings, it is becoming super critical to make sure that the people who are engaged with our businesses, whether that’s our employees, our partners, our customers, our suppliers, etc, the humans who are engaging with us are very much aware of what the threat vectors are out there, what kind of fraud happens, and how those frauds manifest within your working environment, within your digital space where you hang out online. So the way my organization or my business helps helps the market, is in three ways. So one is, we run awareness and education training programs and workshops. So they start at 60 or 90 minute master classes, and we can go into as detailed as is needed for a particular business. So once the education piece is done, then we do vulnerability assessment. So let’s to take deepfake clone voice scenarios, and they these attacks happen over a number of different surfaces. So it’s not just you receive an email and you’re spoofed. It’s not like that. It starts with an email. It might go onto a WhatsApp, it might manifest on an SMS somewhere, etc. So we follow that journey where the employee is going, and we simulate the deepfake scenarios that tests the vulnerability of the organization. And then finally, we can never rest on our Lawrence. So yes, we take all precautions to make sure that we are secure. However, if an incident should take place is the executive team prepared and ready to deal with that incident and therefore contained damage? So we run executive tabletop exercises, so it’s education, assessment, training, and then for the executives, we have a tabletop exercises to help them be prepared for any eventuality,
Speaker 1 07:02
and with an organization thinking about the vulnerabilities that they may have in place, what would you say would be one of the most overlooked areas of people’s businesses, where they say, If only you’d have come in six months ago before we’d had this attack.
Aarti Samani 07:26
It mostly vulnerability is in the human it’s in the human error. And it’s not because people deliberately make errors, but because these AI enabled fraud vectors are getting so hyper realistic. They are so realistic, it’s impossible to detect just with naked eye whether something is real or something is fake. It is impossible to hear a voice and establish that this is a real voice or it’s a clone voice. When you see a phishing email, it looks so real that it bypasses all the security gateways and lands in the inbox and an unsuspecting employee who is just trying to go about their day job and do the best work they can, they get caught out in this. So the vulnerability at the moment is coming from human errors and humans falling into these very hyper realistic attack vectors. And so that’s why I emphasize the education, training awareness piece very much. Because if it is top of your mind, then your human is is thinking about it. They they are, you know, at the back of their mind, they’re thinking, Oh, hold on, something doesn’t feel right here. Let me take a step back and take a deep breath and actually think before I execute on it. The other piece in the vulnerability, again, it’s not a technology related vulnerability, but it’s culture. So if people think something is wrong, but they feel a little scared and intimidated to ask questions from the executives that becomes problematic. So there are whole range of cultural issues. So your business culture can almost directly be tied to the risk exposure. So at the moment, given the rise of these human manipulation type fraud using AI, I see most vulnerability in the human element of the organization,
Speaker 1 09:24
and with such that the human element, what is the psychological damage that happens to somebody who has been unfortunate enough to be caught out by this? Yeah,
Aarti Samani 09:36
great question, and often most people don’t think about it, so let’s, let’s think about a scenario, right? So say you, Deborah, are employed in an organization. You’re doing great work, working very hard, you have unknowingly been a target of a deepfake fraud. That means you followed instruction. You followed all the processes and you executed the instructions that your manager gave you via video or via a phone call. What did you do? Wrong? Nothing right. You followed all the right steps. Three days later, your manager tells you, hey, Deborah, we have been a target of a deepfake attack. You made these fund transfers, they have now gone into a fraudulent account. How do you feel about it? You feel embarrassed, you feel betrayed. You feel you feel like you have been personally attacked, rather than your organization being attacked, when actually, in reality, your organization was attacked and you were just used as the pawn. So the mental health implication of a fraud like this is immense on employees. Now, the same thing happens in your personal life. For example, if an individual has been a target of any kind of fraud, specifically than deepfake fraud, etc, the the impact on them is awful, because not only they’ve lost money or data or some kind of there’s been some kind of reputation damage, but they feel unable to trust anyone anymore. They feel so vulnerable. And any phone call, any online interaction, any digital transaction they do, they are just so nervous about it, and they often seclude they they cut themselves away from society because they don’t know how or who to trust anymore. So often, the unspoken, the invisible scars of the AI, deepfake fraud, are the impact on the human beings, mental health and mental wellness.
Speaker 1 11:46
Thank you. Go for going into those details, Aarti, because it might be from an AI perspective of technology, but there is a human beingness about the end result, which is devastating, and I would, I was going to use Canby, but I think it is in whatever regard, in a financial deepfake fraud that’s been perpetrated successfully, that individual is always going to hold The responsibility and the shame, etc. With that in mind, when would you say it would be an ideal opportunity for an organization to work with you as part of their journey?
Aarti Samani 12:33
Immediately, and I say immediately, because 2025 is set to be the year of deepfake fraud, like literally every stat you see in online, in threat landscape, reports, etc, it is just exponentially rising. So I feel it’s not, it’s not in the interest of an organization to lose time in driving this awareness, this education program, to your staff at every level, whether it’s a company wide program or at a team level, with a deep dive, with certain teams who are responsible for security, who are responsible for culture and executives. Just yesterday, I was speaking to someone who is a group, CFO, of a large of a large organization, he received an email with a voice note from a board director instructing him to do certain things, and it’s only because he had received a training like this, he was able to stop back, think about the context of the conversation in the board meeting they had previously and therefore go and question that individual from whom this voice note had come, and it turned out that it was completely fake. Now, had the group CFO not been trained appropriately, or not been made aware of how these fraud manifests in his environment, he might have actually gone ahead and executed on the instructions. So it’s not just employees at sort of the middle management level or entry level. It’s all the way to the executive team and even the board who need to understand the implications of this, the context in which they appear in their environment, the attacker mindset, the psychology, and therefore how they should be using their psychology to counter the attack. So I would say, Please don’t lose time wherever you need to get help from to drive this awareness and education within your organization. Please do it, and I’ll be very happy to to have a call or conversation with anyone who’s interested.
Speaker 1 14:45
And you’ve mentioned a word a couple of times. Context, could you go into a little bit more detail about what that importance is around the context of. Of receiving something and how you then take subsequent action,
Aarti Samani 15:05
absolutely. So I’ll give you an example. A large consulting firm whom I will not name, their CEO was impersonated. That impersonated video went out to some of the leadership team, and it contained instructions to execute certain things. When that video and that email landed in the in the team’s inbox, it got quite far. Some of the team members did go quite far, and they followed the follow the instructions that were given to them, but at 1.1 individual stopped, and the reason they stopped is because this video was now asking them to go to a platform where the CEO normally never communicated or never used. So for example, the CEO usually communicated via email or slack or other business communication tools. One video asked them to move the conversation to WhatsApp, which they never used in the past. And this individual was diligent enough to think about the context for a second that, Oh, hold on, I have never spoken to them on WhatsApp. Why? Suddenly they are asking me to jump on a whatsapp call. That is extremely unusual, so that’s what I mean by context. Like, does this make sense in the context of the environment that you are operating in? So it is contextual awareness. It is critical thinking that we have to train our employees to deploy another example, and this is in a personal context. So someone I was speaking to the other day, they said her mother, this lady’s mother, received a phone call, which was in the voice of her grandson, and the voice said, Hey, Grandma, I’m in a lot of debt. You know, I spent all my student loan. I’m desperate for some cash. It’s the New Year, Christmas. I’ve used up all the money. Can you help me out by transferring 1000 pounds to my account? And the grandma was, yes, of course, I will help you. Of course. She doesn’t know how to do digital transactions, so she calls her daughter, my friend, and says, Can you help me out to do this transaction? And my friend is like, Wait, hold on. He just received cash as Christmas presents. So why is he out of cash? And so she did a bit of investigation, and she asked the mother, how did the conversation go? And the mother said, Corey called me and say, hey, hey, grandma, needs some cash. And said, Hold on. He never calls your grandma. Whenever he calls you, he calls you granny. So something is not fitting here. So when you put these pieces of information together, you hold back and you say, Hold on. Let me just cross verify before I do anything. So this is another example of contextual awareness, whether it’s in your personal environment or in your work environment. I think we are, we are at a place now that we have to be hyper aware, hypersensitive of everything around us.
Speaker 1 18:15
This is very interesting, because they’re choosing, as always has been the case of maybe a vulnerable person, a person that’s not necessarily technically savvy, but also the fact that people are busy and that there are numerous things to do and that to be hyper vigilant in this way, as an alerted state, on a continual level, what would people say from the level of, how do you show up like that with every single communication?
Aarti Samani 18:53
Yeah, this is this goes to the conversation of trust. So what we’re saying is that if your grandson calls you don’t trust him now, which is counter intuitive, right? Because you want to trust your grandson, you want to trust your colleagues, you want to operate as humans. We are wired to trust by default, and I will emphasize that we have to absolutely continue down the road of trusting your friends, family and colleagues. What I’m saying is be curious about the digital interactions you have with perceived friends, family and colleagues, because the digital version of that individual may not actually be who you think they are. So it’s it’s actually quite a difficult one to grapple as human beings, as as human beings. We want to trust everything we see, we hear, we want to believe everything, because that’s how we have grown up since birth, right? But now, unfortunately, the environment around us has been created. In such a way that the digital interaction has to always be treated with a level of curiosity, and we all have to know. So if I’m asking some pointed questions, it’s not because I don’t trust Deborah, it’s because I’m just a little curious about the face that looks like Deborah on my screen. Do you understand what I’m saying? So it’s driving that, that level of awareness to people say, hey, look, absolutely trust your loved ones, your colleagues. We are not fostering an environment of distrust. Here we are, however, saying, treat the digital versions of them with a little more caution and curiosity.
Speaker 1 20:45
Thank you, because once you’ve now, excuse me, excuse me, once you’ve taken that and people understand that they’re not going to be judged or mistrusted for, for the truth of themselves. It is that digital interaction, the way in which that platform presents itself from the digital world, that then removes it from the individual. And one can see that actually it is a process that’s being derived here, not an attack on the individual.
Aarti Samani 21:22
Exactly that. Yeah, you have to separate out the individual from the interaction that you are having with them online. And this is another part of the awareness and the education program that we work on, which is to help you train your clients in this so if you Deborah, are having a conversation with a client, and if you’re asking some pointed questions to your clients in order to verify that they are real, then they should not take offense at that that you are doing it to protect them and to protect yourself. So there is a whole arm of education, not just to your employees, but also to your clients, which is why I said at the start, it’s any human who is part of your ecosystem in your business should be made aware of this. So again, once you, once you establish that protocol with your clients, they then understand that it’s not that you don’t trust them, it’s just that you don’t trust the technology through which they are communicating with you.
Speaker 1 22:23
And this is interesting as well, from a supplier perspective too, paying invoices, etc, to what you would say, as a bona fide client, a supplier, that you’ve got to make sure, again, that supplier relationship ships are kept intact, but they know that there could be a level of security and some questioning around paying invoices that might not necessarily have been there previously exactly, and it worked. Yeah, to
Aarti Samani 22:52
close the loop on that, I was just this morning reading a stat in 2024, 53% accountants had been targeted with fake invoices from their suppliers, and those suppliers never invoice them, and we are talking hundreds of 1000s of pounds worth of invoices, some of which did get paid to fraudulent accounts because these individuals just trusted the email that came with the invoice, and they didn’t, they didn’t cross check that something feels amiss here, so you’re absolutely right that it’s, it’s the supply chain, the customer invoices, everything you have to just treat with extra cautiousness.
Speaker 1 23:37
So with a business, who would be the person that would work with you initially, who would bring you in initially? What does that title look like? Who would the person be within the organization?
Aarti Samani 23:50
Yeah, sure. So my experience have been quite varied. It’s anything from the CEO or the GM of the business or a given a group or a given region, to the security team the CISOs office. Sometimes a CMOS team marketers, because they want, they want, as part of their employees, summits, etc, to drive home a very serious message in an engaging way. And also it’s sometimes the human resources and the people team, because they’re actually being targeted heavily now. So recently, just end of last year, there was an incident where a security company had hired a remote it worker who turned out to be completely fake. So they pushed they post themselves as being located in United States, they had all the identity documents. Every interview was a deepfake video call. It turned out that they were situated in in a country in Asia, and the whole thing was completely fabricated. And when they they were employed and brought into the organization, they already started installing malware. On the company computer, which was given to them, and that’s how they were caught. So it’s really the finance team is targeted. The Human Resources team is targeted. The security team, whose responsibility it is to make sure that the security posture of the business is as tight as it can be. So it really my experience has been very different. Stakeholders engage with me in conversations, depending on the stage of the business and the sector that they’re operating in. And
Speaker 1 25:33
is there a form of certification that people can work towards to make sure that they see them at cell either that they can have an accreditation of some sort within this field.
Aarti Samani 25:45
So what we do is we run the master class, and then we run the vulnerability assessment. At the end of the vulnerability assessment, there is a report that is produced that shows how the employees performed, where there were gaps in the processes, and then wherever those gaps have been identified, there is a further micro training that is delivered in a 30/62, video clip, etc, to the appropriate individuals. So you have the full master class, you have the vulnerability report, and then you have micro training, and that vulnerability report actually, then the whole thing then becomes a certificate, not only to demonstrate that you are doing everything you can to keep your employees educated, but also it goes to the insurance policies as well, because there are certain insurance policies which don’t Cover organizations for deepfake and social engineering fraud unless they can prove that they have done sufficient training to their staff. So it goes as almost a proof for them to be covered by insurance underwriters also. And from
Speaker 1 26:55
a commercial perspective, would you say it’s advantageous to have this report to show future clients that you’ve given certification, yeah, or to go for tenders and bids that you would otherwise, you know, perhaps not it. You know, you’ve got something else that you can show
Aarti Samani 27:13
exactly that, yeah. So, just like you would have ISO certification or SOC two certification, at the moment, there isn’t an official there isn’t an official stamp of authority for deepfake training, but we by showing our reports and by showing evidence that you have been through our program, that’s absolutely an extra seal of confidence that You can give out in proposals, in bids, tenders, etc. It becomes a marketing differentiator for the organization as well to say that actually, we are ahead of these emerging threats. We know about them. We take them very seriously, and we make investment in this.
Speaker 1 27:57
And with this changing all the time, morphing into new areas. What is one of the best ways of working with you? Is it to have you in and that’s it? Or is it to work with you on a regular basis?
Aarti Samani 28:10
So one and done is never, is never the right answer for these type of things. Because employees, new employees join the organization. Some employees leave the internal workings, the processes change, etc. So our recommendation is to have two master at least two master classes a year, once every six months, and to run four vulnerability assessments. So one every quarter, you should run a vulnerability assessment to make sure that this is top of the mind for your team, that your processes, the controls, everything is still as tight as it could be. And then, of course, the incident response for executives that should be always fresh alive. Make sure that it’s almost second nature so everyone knows what they are doing, so at least we can contain the damage. So yeah, I always recommend a sustained engagement. And that doesn’t mean engage with me on a weekly basis, but you on a quarterly basis. We need to go in, we need to refresh and we need to be top of mind of all the people engaged with us.
Speaker 1 29:20
Aarti, Aarti, thank you so much to being a wonderfully insightful and I have to say, giving us so much value as a special guest. It has been a privilege, and I know I have learned quite a lot from listening to you. How can people get hold of you?
Aarti Samani 29:36
So I’m on LinkedIn. Aarti Samani, my email address and all the contact information are on my LinkedIn profile, so just look me up there. That is the easiest, the quickest way to get to me.
Speaker 1 29:51
Wonderful Aarti. And also, for anybody listening, it’s all going to be on the show notes as well. So it’s wonderful. Thank you so much for being. On the show. My
Aarti Samani 30:01
pleasure. Deborah, thank you for inviting me and helping me to drive awareness about this emerging threat vector which will impact every one of us. So thank you. I really appreciate that. It’s a
Speaker 1 30:13
pleasure and for everybody listening. Thank you for tuning in. This is such a worthwhile and valuable topic to be appraised of. Do have a discussion with Aarti. She is a wealth of information and is able to put things in a very easy to understand. But make no mistake, it’s incredibly valuable that the information that she provides you with, so to please do be in touch with her, it would be a conversation well worth having. And thank you for liking and subscribing to our channel, and if you are new, it’s wonderful to have you. What I always say is, please do share this, because ultimately, this might not be necessarily for you, but it could be absolutely to do with somebody else. But I would say everybody needs to be appraised of this, even if you know we think, Oh, our businesses are small. Don’t worry about that. Often small businesses attacked more than larger ones because they know that security systems might not be quite as what the large people have. So everybody be vigilant. Keep caring and make sure that you’re on top of the curve, especially where this is concerned. See you all again very soon. Bye. Bye.