Deepfake Fraud, Human Trust, and the Rise of Fake Remote Workers
Deepfake attacks are an operational threat. In a conversation hosted by Veriff’s Brand Director Chris Hooper, Aarti Samani, outlines how AI-enabled threat vectors are now targeting the most human part of a business: HR. Deepfake hiring scams and fake worker fraud is spreading across US, UK and Europe.
“Deepfakes exploit human trust, human instinct, and human systems. And that means humans have to be part of the defence.”
Fraudsters Know Where to Find the Gaps
Instead of attacking where defences are strongest, deepfake scammers are looking for soft spots, and they’ve found one in HR. While security teams are (almost) prepared, other departments aren’t.
“They’re not targeting security teams anymore. They’re targeting HR. They’re targeting finance. They’re impersonating vendors. They’re creating cloned voices and synthetic faces, and using them where trust is assumed.”
The techniques are convincing, and designed to evade suspicion. Deepfaked candidates simulate poor internet connections, blur their backgrounds, and lean on AI copilots to respond during interviews. Once hired, they disappear into Slack, Zoom, and internal systems, often never turning on their camera again.
If your organisation is hiring remotely, simulating a deepfake worker attack is one of the most effective ways to reveal blind spots in your process.
Culture, Risk, and the Psychology of Exploitation
Technology isn’t the only vulnerability. According to Samani, business culture itself is now a security factor.
“If your teams are stressed, exhausted, disconnected from leadership, or operating without context, they’re more likely to fall for a deepfake. Fraudsters know how to use urgency, flattery, or fear to push people into action.”
Organisations need to build psychological safety and improve internal transparency, but they also need experiential training that shows teams how these attacks feel in real-time.
What Rest of 2025 Will Bring
Samani sees three emerging trends:

- Agentic AI fraud: automated agents running end-to-end scams
- Localized attack models: perfected in one country, scaled globally
- SMBs as sandboxes: small businesses used to test and refine attacks before targeting enterprises
“We’re already seeing it. Deepfake worker scams started in the U.S. They’re now spreading into Europe. Digital arrest scams are moving from Asia into Western markets. It’s evolving fast.”
The Path Forward
For organisations wondering what to do, Samani’s answer is clear:
“Make human defence part of your cybersecurity strategy. Not just on demand training, but live experiential training, simulated vulnerability assessments, and executive engagement also. You can’t outsource this. You have to prepare your people.”
She emphasises that security is not just CISO’s responsibility. HR, marketing, finance, and sales all have a role to play. Each team has data, systems, and relationships that are vulnerable. Each can be an attack surface, but also a strong line of defence.
“If you don’t think like an attacker, you’ll always be reacting. This is the time to get ahead of the threat.”
Transcript
Read Transcript
Chris Hooper (00:02.049)
Hello everybody and thank you for joining us. My name is Chris Hooper and I am brand director here at Veriff and today’s conversation is all about the subject of deep fake fraud. It’s something that we’ve touched upon on many of our podcasts and webinars about the subject of fraud and I think it’s something that is long overdue, it’s its own exploration. So today’s conversation is a very exciting one, one I’ve been looking forward to for a long time. And joining me to talk about this is Arti Samani who is a world renowned expert and speaker on this subject.
Aarti, welcome first of all and thank you for joining us. Would you mind just giving us a brief intro into yourself and your role and your work in this subject?
Aarti Samani (00:38.373)
Yeah, thank you, Chris. Lovely to be here. Thank you for inviting me to talk about this topic, which is actually very important at the moment, something I feel very passionate about just because it is impacting so many individuals as well as businesses. So I’m Arti Samani. I’m the founder of a firm called Shreem Growth Partners, and we focus on deep fake fraud prevention services. So that includes empowering the humans in the
humans in the chain, so employees, executives, customers, partners, whoever it is, giving them information, awareness, context, showing them how deepfake fraud can manifest in their environment. We also create multi-platform simulations in deepfake fraud, because as you know, Chris, deepfake is not a one-platform thing. It might start on social media. It will follow you on email.
finally ending on a live video call, right? So we simulate that multi-platform deepfake fraud and we ethically launch it on the organization in collaboration with the executive team to identify where the vulnerabilities are and where the business needs to do more work in order to kind of fortify their defenses, which is not just dependent on technology and people. And the reason
we do this and the reason I want to focus on the human aspect of it is because deep fake is the type of fraud that exploits human trust and human emotions and therefore the solution cannot just be technology. humans have to form part of the solution. Also the tech is moving so quickly that it’s impossible for the defensive technology, the protection technology to keep up with the offensive tech.
which is what the bad actors are using. Now, we already employ people in our organization, so let’s use that very valuable asset that we have and help them defend themselves as well as our businesses.
Chris Hooper (02:45.304)
Love it. Yeah, that’s a great intro. And I think just for my own sort of personal curiosity, really, one of the things I always ask people when I have these types of conversations is what your kind of route into this world was, because the answers I’ve had to this question are so varied. I people have come from, I come from a journalism background myself, but folks come from financial services or, you know, we’ve had sort of victims of crime who want to do something about it and sort of change the system. So I’m really curious what your route in is this. What’s sort of your experience, if you like, and your journey to where you are right now.
Aarti Samani (03:14.051)
Yeah, it’s one of those things that you never thought you would do this, right? I didn’t grow up wanting to be a deep fake fraud prevention expert, but I worked in technology all my career. So I’ve worked in deep tech, AI based products, commercializing them, taking them to market in corporate. So also financial services, investment banking techs are very familiar with fin crime and the risk based approach that we take in that context.
Chris Hooper (03:17.603)
Yeah.
Aarti Samani (03:42.055)
The second phase of my career was working with high-growth technology scale-ups. One of them was a biometric face verification business. So we were dealing with deep fakes back in 2018, 2019 when tech was picking up, but it was mostly revolved around celebrity deep fakes or known personality deep fakes. But in anticipation of where we might be, I did a lot of work on deep fakes at the time.
And that kind of became a journey that I traveled on. And then recently, because the fraud is picking up so, it’s like wildfire, isn’t it? It’s everywhere. So I kind of thought, well, I’m in a unique position where I know this attack vector inside out. I understand human psychology and human behavior, and I understand deep tech and AI very, very well. So when you put it all together, it’s, it makes me, it positions me.
very well to work in this space and to help organisations.
Chris Hooper (04:46.882)
Yeah, lovely to hear. You kind of touched on my first question about this then, which is what the threat level is today, I suppose. You mentioned this is something that, as far back as 2018 and maybe before that too, that this is something that’s been evolving since then. for me personally in the world, the very first view on this is that we’ve seen a real acceleration of this over the last probably two years, I would say. But where are we today? What’s the threat level? How would you describe things?
Well, what is it that we, what’s our level of awareness that needs to be about this subject at the moment?
Aarti Samani (05:18.311)
Yeah, sure. So the threat level is high. it’s a red alert, right? Basically. So a couple of stats I can cite. In 2024, deepfake fraud was attempted every five minutes in the context of identity verification. Another stat I can throw out there is 400 CEOs are targeted every minute from deepfake.
fraud, so CEO impersonation, 400 companies are targeted by CEO impersonation, which is deep fake fraud. it’s just all around us. Individuals are not recognizing it. They may be target and they don’t even know it. Like they may be in a romance scam, which is powered by deep fake, and they don’t even know it until it’s too late. In United States, there is the whole fake worker issue. So all these
deepfake-powered fake workers are in the system and organizations don’t even know about it. Then there are businesses who have been victims of deepfake fraud, and they have talked about it very openly. But there are others who have not, because of reputation damage, embarrassment factor, not wanting to spook customers, not wanting to spook the market to implicate stock prices.
There’s a lot that we don’t hear about, but it doesn’t mean it’s not there. It is just everywhere. And the reason it’s everywhere is because it’s easier to break into humans than it is to break into technology. So deep fake is great because you can target the humans directly, you can exploit them, and you don’t have to worry about breaking into the system. It’s the path of least resistance. It plays on our instincts. We are taught to…
trust what we see and hear from the time they grow up. We are taught to trust authority and not question them. All these things make it a very, very effective form of attack vector, high return on investment, low barriers to entry. So if you think about the fraud as a business, just makes it as perfect, like it has perfect recipes for a successful business. And that’s why we see it all around us.
Chris Hooper (07:23.374)
Mm.
Chris Hooper (07:36.236)
Yeah, absolutely, absolutely. We’re sort of seeing the same thing at Verif actually too. And I think that it’s, as you say, it’s kind of the perfect storm it almost feels like, doesn’t it now, where we’ve got this very sophisticated machinery, which is sort of scalable and easily available and actually quite cheap to purchase these days as well. So fraud as a service is something that I feel like is very much a growth industry at the moment, which is quite alarming. And you mentioned some of the types of fraud, how they sort of take shape, I suppose.
Have there been any kind of real-world examples that you could point to and things that have been in the news that people may have heard of that have utilized this type of technology?
Aarti Samani (08:12.807)
Yeah, absolutely. So like the most known case is the deep fake CFO in Hong Kong, right? So British company, Hong Kong office targeted impersonation victim, the CFO target victim, the execution victim, a finance controller in their team over a period of a few days, built trust, final strike, invited the financial controller on a Zoom call. Every face on that call was a deep fake except the victim themselves.
and convince them to transfer 25 million US dollars. Now this is the most well publicized, the well known case that you can find online, but there are several others, right? So more recently we had the Italian Defense Ministry targeted and here the attackers deep faked or impersonated some of the people working in the ministry and reached out to some
very high profile business owners, fashion houses in Italy saying, some of our Italian citizens have been held hostage by hostile nations and we desperately need funds to free them and bring them home. Like an example of a deep fake fraud. There is the Admiral’s ethics crypto trading platform which has been operating out of Georgia and 85 people call center run like a call center business trick.
over 6,000 people into a parting with $35 million, right? All powered by deep fake. And this is in an individual capacity. More recently, we had the fake of the YouTube CEO, Neil Mohan. His video was used to send out to content creators, asking them or telling them that YouTube terms and conditions and monetization models have been updated. Click on the link to accept it and…
log in to your account and click on the link, giving away credentials, installing malware through malicious links. The biggest one is the fake worker scam that is going around in the United States and now coming into Europe, where remote jobs or jobs advertised remotely in technology are applied for by workers in nation-state.
Aarti Samani (10:33.127)
who conduct interviews through a deepfake video call, get the job, and then they do what they are mandated to do. In Asia, there is hostile sort of digital arrest scams where fraudsters pretend to be police inspectors, investigators, tax collectors, et cetera, and really force people into believing that they owe a lot of money.
And if it wasn’t paid, then they would be prosecuted, imprisoned, etc. So it’s amazing how creative these folks get and how these attacks manifest. It’s just mind-boggling.
Chris Hooper (11:15.214)
It really is, it’s terrifying and some of the numbers you mentioned in there are astoundingly high in terms of the profit margins on these if you like and that kind of thing too. One of the really interesting ones that you mentioned there actually is this kind of fake worker scam that’s sort running at the moment, especially in the US but I think more so across the world as well as things move forward. this is something that seems to be relatively new and well, I I think quite, well, I say relatively new, it’s something that’s come to attention relatively recently, should maybe phrase it that way.
Aarti Samani (11:22.459)
Yeah.
Aarti Samani (11:43.749)
Yeah.
Chris Hooper (11:44.81)
It seems to be really, really worrying as well, in this sort age of remote work and sort of the importance of IP and that kind of thing, how all of a sudden businesses are very open to a fake employee getting a job there and getting access to God knows what data. And it’s one of those things that is really kind of cross industry. Nobody is safe from that. That’s not something that is just financial services or just marketplaces as we sort of break things up by vertical here.
but something that applies to everyone. And I think that that is probably going to be, my mind at least, the biggest use case for these defensive platforms in the long run. But I’m really curious about how businesses in particular, those who have been working in the B2B enterprise space, how are they being targeted? Obviously we’ve mentioned this fake employee route. Are there other things too that they should be aware of?
Aarti Samani (12:36.367)
Yeah, absolutely. I mean, this is a game of whack-a-mole, right? Someone described it as a cat and mouse the other day. I was on a call. But it’s a whack-a-mole. You kind of you thwart one and it appears in a different form in another place. It’s like the manifestation changes. That’s why they’re called shape-shifters, right? So the kind of frauds that the enterprises are seeing at the moment, like vendor impersonation, is a classic. So actually, let me take a step back.
Deep fake fraudsters know that the security teams are on high alert, right? So they are not necessarily targeting the security team where the defenses are the most strong. They are targeting peripheral teams. So fake worker targeting the CTO and the HR offices in an organization. Vendor impersonation, payment fraud, et cetera, targeting the finance team, the CFO’s office.
Group executives against each other. So if you’re a large enterprise and you have a group CEO, a regional CEO, et cetera, so executives targeted and played against each other. these guys, these people are very clever and there is a whole science, whole, yeah, science of fraud design, right? So how do we design the fraud in a way which is
delivering the highest return on investment in the quickest time taking the path of least resistance. So that’s why we see a lot of vendor impersonation, which is where a voice note, a cloned voice note or a deep fake video is utilized, sent to the finance team to say, hey, I’m from company XYZ, we are your partners or your suppliers.
And just to inform you, our bank details have changed. Please update it and make sure this forthcoming invoice is paid into this account. And in lot of cases, when I’ve spoken with finance teams, they say they corroborated this information with their executives. But the executives also receive a similar message from their counterpart in the vendor organization. So the executive thinks, yeah, this must be valid. Then the finance person receives
Aarti Samani (14:56.559)
something similar from their counterpart, they must think it’s valid. When they corroborate, they are corroborating false information against each other and two negatives is making a positive in this case. And so they lose money. So it’s just amazing how they are kind of targeting people. The other thing which is not often talked about is when people are targeted, remember employees are individuals, right?
We are not just professionals, we are humans who have a whole other life outside of our work environment. When that individual is targeted in their personal space from deep fake fraud, they are now a liability and a risk to the organization. And that’s how they get to the enterprises, right? So they get to the enterprises. So if someone is in a romance scam, unknown to them, they are unknowingly and
quite naively revealing information like, I had a great day at work today. We closed deal XYZ. Suddenly, you’ve given a data point, right? Or we’re traveling for a sales kickoff on this date to this location, and we have a full on agenda to discuss ABC. You’ve given a data point. All these data points go into the fraud design, which culminates into a very, effective attack, right?
It’s targeting from multiple angles. The other thing you mentioned earlier, like fraud targets businesses of all sizes, all sectors. SMBs, small and medium sized businesses, are now used as gateways to get to the enterprises. So I was speaking to a company just two days ago, a six people company based in the United States. They have some very high profile clients.
They have become a target of deepfake fraud from some of these IT workers and the motivation has been to reach the clients that they are serving. it’s like attack from all sides and so that’s why I call it a game of pack a month. Like you stop one and the other one pops up.
Chris Hooper (17:09.89)
Yeah, I love that analogy and I think it’s something that we’ve kind of seen here at Verif with our work here too. have cross linking across industry. we have, obviously there’s a number of industries that we work in and if we see some activity in a certain one, we know that that’s a threat to watch out for in others too. But kind of what we’re seeing too is that financial services companies are the end target if you like, but further down the chain is where the weakness is. And as you mentioned, humans are often the weakest link in the chain.
people are being targeted on social media platforms or dating platforms just to get access to that person in the hope that further down the line they can start to access their financial accounts too. And so, you know, it’s a really tough one for financial services to legislate against because really the problem is happening way, way, way downstream. And it’s a really tricky thing to sort of get your head around, I think, that this kind of joined up nature. And I guess the real, the only real way to sort of fight against that sort of thing is to have that visibility of what’s happening in other industries too.
But what would you say about the importance here around verifying authenticity of people, be they customers or new employees or whatever it may be? Surely it’s more important than ever.
Aarti Samani (18:14.695)
Absolutely, like you can’t stress enough the importance of verifying authenticity, verifying them as a human being, but also the human being who claim to have the identity that they have, etc. So really important at every stage, from the moment an individual is born, they are given an identity with a name and a birth certificate to the point when they leave the world, they’re given a death certificate, right?
And during that whole process, there has to be an identity which carries forward at every step of the way and one that can be verified securely without being broken into. Now therein is the challenge, right? How do you do that? You know, over a lifespan of 70 years, 80 years, how do you carry that identity forward, especially when we have such large surface area that we are working in at the moment?
But, you know, and that’s where companies like Whereif, who invest a lot of, who make a lot of investment in technology R &D to verify identity become really, really important and play a major part in defending and securing.
Chris Hooper (19:30.36)
Yeah, absolutely. Let’s just talk a little bit more. I we mentioned some of the industries, if you like, that are kind of experiencing some of this stuff, but what, if we’re talking about the sectors and the personas who are most at risk here, which would you identify as being where the of the main watch out would to be? Or is that kind of just a futile exercise and it’s kind of across the board? What would you say to that?
Aarti Samani (19:49.103)
I would say it is a futile exercise. And the reason I say that is because think about, so attackers are not thinking, how am I going to attack this business necessarily? They’re thinking, I have these assets, how am I going to use these assets to get more? Right? And then what are the motivations? So initially it was thought that money is the only motivation and the driver behind a lot of these frauds and scams.
Chris Hooper (19:50.871)
Yeah.
Aarti Samani (20:17.349)
We know differently now, right? We know that it’s not just money, sensitive data, other kinds of information, credentials, access to your customers, access to your staff database. Like all of these are assets of value that every business holds and needs to guard, right? So if you’re an SMB, what do you have? Well, you have a bank account, you have customers.
You have data and you probably have some sensitive information about your customers, right? So already you have assets of value that the attacker might want. Now, if you’re in regulated industries, the value of those assets is much higher, right? And therefore it’s worthwhile them investing more time in creating a very well designed fraud. So you see a whole range. You see like petty criminals or pickpockets that target SMBs.
Chris Hooper (21:01.102)
Mm.
Aarti Samani (21:12.951)
use them as sandbox environment almost, right? So small businesses have lower awareness, lower security guards, therefore they become a sandbox environment to try and test out some of these attack vectors. Once the technique is perfected, it is then utilized to target the larger enterprises. it’s, hearing engineering firms, FS obviously, e-commerce, lawyers.
Chris Hooper (21:25.294)
Mm.
Aarti Samani (21:39.463)
tech businesses, like I’m hearing across the board where people are now, leaders are coming forward to talk about this and even security companies have been targeted, right? We heard about a very big case last summer of a fake remote worker and that was a listed security business. So if they can be targeted, then you can imagine every other business is at risk.
Chris Hooper (21:51.342)
Mm.
Chris Hooper (22:07.724)
Yeah, absolutely. And I think let’s stay on that subject because I think that’s the, as I said, we mentioned earlier on in the conversation here that I think that that sort of fake employee angle feels like the one that is the real sort of top of mind for folks at the moment or should be. And I think maybe the reason for this is that the sort of the customer identity verification piece is kind of, it’s been going a while. It’s sort of, it’s become, it’s pretty good. think most companies who have the need to Veriffy remote customers
Aarti Samani (22:14.96)
it.
Chris Hooper (22:36.654)
have got the systems in place that allow them to do so now. That’s not necessarily the case for other teams within the business, right? And you mentioned sort of the HR or recruitment team. And I think that’s sort of weakness is feels like the one that’s being exploited or is likely to be most exploited next. So let’s just talk about that kind of fake remote worker’s piece. Cause I think that how is it exactly that fraudsters are using deep fakes there to exploit or find holes in the hiring process, do you think?
Aarti Samani (23:02.203)
Yeah, sure. So firstly, it starts on the platforms, right, where jobs are advertised. So a ton of fake profiles on social media everywhere. And those profiles are made to believe like they have a lot of experience, they’ve worked in a lot of high profile businesses, got great educational credentials, etc. When jobs are advertised on these platforms, the workers apply for them or they have a team, right? They have a team. So there’s one of
a segment of the team who’s responsible for job applications. jobs, they’re applied and they go by numbers. Thousands and thousands of jobs are applied for. Then comes the CV review process, right? So they hiring managers or recruiters or HR managers, they review the CVs and they think, okay, this is great. They don’t often…
do a cross-check of the information. They might look at the resume, they might do a superficial search online to see that the resume corroborates with other information that’s out there, but they don’t necessarily do a reverse check of the picture, for example, and other forms of checks. So the CV goes through, then comes the interview process. Now the interview process for a remote job is often through a video call. That video call is where the first use of deepfake happens in this kind of fraud.
So on a call like you and I are speaking on, the individual who is doing the interview, who is the interviewer, will take on a different face. The interviewee will take on a different face. You don’t know this is real or not. The tech is so good that unless you are forensically looking for signs of sort of blurriness, et cetera, you can’t really tell that this is not a real face.
Especially when people use virtual backgrounds as well, it often gets blurred and that blur kind of goes into the face and the whole image is just a bit disturbed. If they complain about bad network connection, et cetera, we’re kind of, you know, let that pass, right? Yeah, okay, we all have connectivity issues. But that’s where the first use of deepfake happens. They are often very good at the interview process. They know their stuff.
Chris Hooper (25:10.958)
Mmm.
Aarti Samani (25:21.531)
But sometimes there’s also cases where they are using copilot. So when the interviewer asks the question, they are reading the responses of the copilot, right? And that’s a good telltale sign. But then when they are recruited, when they’re hired, they have to go through identity and background check. Now, this is the next place where deepfake is utilized. So you know this space very well, right? So identity documents are forged and they’re available.
very cheaply on the dark web. The aliveness detection is where DeepFake is utilized. So the whole identity process, like you say, in a customer perspective, it is fairly stringent, fairly tight. But when it comes to employees, for some reason, we are more trusting because we want these people as our colleagues, right? So the process there is a little bit weaker. So we now need to go through a KYE.
I hope, right? Like we have KYC, which works very well, still holds in there, but on the whole, it’s kind of getting there. But KYE, know your employee, is the one which is very, very weak at the moment. So when I speak to my clients, I always advise them to partner with their security teams to do these checks very, very thoroughly and apply the same stringent measures that they would apply in a KYC type scenario.
Chris Hooper (26:47.406)
That was going be my next question actually is sort of what tips would you give to sort of hiring managers or sort of HR teams that can sort of help them sort of navigate these waters. As I say, the technology is available and very likely that your business is using it for customer verification. is it just that or is there more to it than that in terms of the process that they go through when it comes to sort of making sure that their system is as robust as it can be?
Aarti Samani (27:12.475)
Well, there is more, right? Because KYE is at the end of the process. So it’s after you have decided to bring this individual on board. The start of the process is when you receive an application from someone, right? So at that point, you must verify, is this a genuine applicant or is this a fake profile? Now, this is where I’m working with a business partner to create a product to verify the LinkedIn profiles, which to…
understand what the confidence level in that profile is of how authentic or how AI generated this might be. Now, LinkedIn, for example, has the verification badge, but we all know that that process that you go through to get the verification badge is very, very insecure. For example, you can use your work email address and verify your work email address to get the badge and you would be classified as a verified profile.
But that is really, really not very secure at all because I know fake profiles who have that badge, who’ve used their work email address to verify and they haven’t been real. So that’s the first step. Like, let’s go through the profile, look at some of these red flags and understand whether this could be a real applicant or not. Like, what is our confidence level there? Then we bring them to the interview process, right? At that point, we need to be visually looking for signs of
of fake on the video calls, on the interview calls. And that could be sort of visually looking at signs or it could be sort of by asking questions and they’re not mutually exclusive. You have to do both. So any reluctance to get on the camera is a red flag. Constant network issues for every interview is a red flag that we need to be looking out for.
But also when someone claims to be located in a certain place, they claim to have been to a certain university, let’s ask softer questions to validate that information informally, right? So until now, hiring managers have been trained to do a competency check, make sure they have the right skills for the job that they are being recruited for, et cetera. But let’s now also ask.
Aarti Samani (29:33.041)
questions that do authenticity check, right? And I always advise every organization, you should have your own set of questions which do the authenticity check, right? You do the culture check, you do competency check, now let’s do authenticity check as well. And then of course you can deploy the technology as well, which is deep fake detection technology identifying during these kinds of remote video calls, et cetera. So there is a before.
precaution that you have to take. There is the during process and then there is the post process, which is where the KYE and some of the identity verification checks come in.
Chris Hooper (30:13.612)
Yeah, it sounds to me that a lot of what you were talking about there comes down to, I mean, largely about awareness, I guess. And as you mentioned, that some of these deep fake videos and things like that are very hard to see with the naked eye unless you know what you’re looking for. So I think that sort of stems back to training as well, doesn’t it? And I think, there a piece around this where this is just an area that all employees will need to have some sort of level of training and awareness management when it comes to…
detecting this type of thing because HR is the one at the moment but that’s not to say that in the future other teams might be sort vulnerable to this too. Do you think that’s the area that most businesses fall down on at the moment?
Aarti Samani (30:50.375)
Absolutely. So I said at the start of our conversation, deepfake targets humans and therefore humans have to be part of the defense, right? So when you ask people, hey, do you know about deepfake fraud? Most people will say, yeah, we know deepfake. You Taylor Swift was deepfaked, Elon Musk is deepfake and selling investment opportunities, et cetera. Most people, 90 % of the people do not know.
how these will manifest in their professional or personal environment beyond investment scams. So there is a large gaping hole right there. If people do not know what this fraud is, what is the context and what it looks like and how it’s likely to show up for you, what chance have we got in them being able to spot it and therefore stop it?
information awareness piece becomes very, important. Now, a lot of the times organizations tell me, yeah, we have awareness programs, they’re on demand learning platforms. And when I look at those platforms, are the very classic, here’s a scenario, here’s a checkbox, which is the right option, right? Now, DeepFake does not work like that. So these L &D platforms, which are designed…
on demand for the phishing simulation that happened 10 years ago do not work in these emerging threats. So what we have to do is show them we have to have our employees experience it in a safe environment. It’s an experiential fraud versus a binary like it’ll happen, not happen, right? Because it is so elusive. It is such a shape-shifter that unless you’ve experienced it, your triggers are not on alert.
So we need to create awareness programs and learning and training, is elevating the retention and recall rate. So when they are faced with this, that voice is in their head, that video of the training program is in their head, that case study is in their head, right? So we need to be thinking in that direction. And unfortunately, a lot of organizations just are not.
Chris Hooper (33:06.478)
Yeah, you’re absolutely right and I love the way you described that. think a new type of fraud requires a new type of training, doesn’t it? I mean, it’s sort of as simple as that really. And I think that how do businesses then go about sort of building that kind of culture, if you like, that will sort of minimize exposure to any kind of deep fake fraud?
Aarti Samani (33:26.535)
So I always say right now with the way deep fake fraud is going, business culture and risk exposure are almost directly correlated. And why I say this is because going back to that human manipulation, the human exploitation, right? If we’re under pressure, if we’re under an emergency environment, if our fight or flight sort of instincts are kicking in.
if we are exhausted, we don’t feel psychologically safe, if there is not enough trust and transparency in the organization, all of these contribute to a higher risk exposure. Because when a deepfake fraud attacks you, they are creating a sense of urgency and they’re asking you to do something, right? If you feel the urgency, you give in to that, you’ve committed or you’ve played into the hands of the victims.
If there isn’t enough transparency in the organization of what is happening commercially, what is happening financially, and in other parts of the business, you do not have the context. And therefore, you cannot deploy your contextual awareness to work out whether this request from the CFO makes sense or not. If there is a very high distance between the executive and the employees, they have no idea.
What sense of humor does my CEO have? What is their level of sarcasm? They are not able to deploy critical thinking to pick out some of these anomalies which only humans can. so risk and culture are very, very intertwined at the moment. And again, it comes down to HR to lead some of this. HR have been talking about culture for a long time. Now they can tie
bad culture to high risk exposure and therefore loss of finance and reputation.
Chris Hooper (35:26.99)
Yeah, absolutely. I think that’s a very good summary. I think we’ve sort of got into a number of different subjects today. But I think one of the things I always like to ask people on these types of calls and conversations is their predictions and what we want to see. it’s crystal ball time for you, I’m afraid, Artie. what are some of the, we’ve covered some of the things that you sort of saw in 2025, sorry 2024. Do you think that 2025 is going to be much the same in terms of the types of fraud that we’re seeing and the types of applications of deep fake fraud?
or do you think that there is sort some new stuff that’s on the horizon that we should be aware of? Is there anything that you would sort of identify there?
Aarti Samani (36:01.775)
Yeah, so agentic AI, right? Like everybody is talking about agentic AI, it’s being like people are cheering it on, et cetera. But with agentic AI comes agentic AI fraud as well. So and deep fake again is a very good, good technology to be utilizing for that. So I expect to see a lot of agentic AI type fraud where two agents are talking to each other.
creating a conversation to then deceive the victim and instructing them into doing certain things. I’m also seeing a trend in terms of localized fraud. So for example, in India, we are seeing a lot of digital arrest type fraud. And now they have perfected that.
in that region, in that country, it is gradually starting to permeate west into Europe, into United States. On the other side, the fake remote workers started in North America, in United States. They’ve been perfected over there. There is a lot of awareness. It’s now permeating into Europe. that, you know, very sort of localized, very customized fraud vectors in different parts of the world launched and then sort of
coming into other parts, into other regions once the techniques have been perfected. As I mentioned earlier, we’re seeing a lot of sandbox environments in forms of SMBs where techniques are utilized, perfected, and then launched in other parts, in large enterprises, in other sectors, et cetera.
as tech is getting better, as there are more more co-pilots, as there is more kind of wider cyber social terrain in which our information is floating around, it’s becoming really, yeah, we’re going to see more of the same, but also leveraging any new tech that comes on the market.
Chris Hooper (38:03.906)
Yeah, so how, I mean, from a practical point of view, then, how would a business kind of prepare for that? If the future is potentially unknown or there are sort of known threats and unknown unknowns, I think is the phrase I’ve heard once before, but how would a business go about kind of bolstering its defenses against those sort emerging AI fraud risks, would you say?
Aarti Samani (38:25.635)
Yeah, it’s a very tricky one, isn’t it? That’s a million dollar question, right? And as always, it has to be sort of tech process and people. And until now, people have not formed a big part of the security defense focus and it has to now. So.
We are not going to be able to predict what will come next reliably, but what we can do is shift the mindset with which we operate, right? So we are now, what we’re saying is don’t trust digital interactions, even if it is with the individual that you know very, very well, because you trust the person, but the digital interaction with that person may not be genuine, may not be authentic. So treat every digital action with curiosity, with caution, and let’s…
Let’s give that information to everyone that we can through media, through government, as employers. The other pieces that make sure that your tech is as best as you can get, right? A lot of the times when I speak with CISOs, they tell me, and I really feel for them, I empathize because they tell me, we have so much legacy security debt that we are busy.
filling those gaps, we don’t have the mindshare or the bandwidth to think about these deep fake attacks which are emerging and forthcoming, right? Now this is where AI, so AI enforces the breakdown of silos. And so it is the case here. We have to break down silos. So it’s not just the security officers, security teams, responsibility for protection.
HR can be a partner to the CISO, right? Through running some of these awareness programs, et cetera. CMOs can be a partner to the CISOs, right? Like, are we protecting our executive brand? Are we following the breadcrumb trails on social media? What information are they giving out? What is our social media policy so we are not inadvertently giving pieces of information that can be utilized against us? So every vertical function in an organization
Aarti Samani (40:38.871)
is as responsible for defense as is the CSOS office, right? This chief revenue officer, I’m running a sales kickoff. I have an opportunity here to include a session on awareness around various types of emerging fraud. And their teams are at the front line, right? So they are faced with this day in, day out. in terms of, apart from the technology and the process, which we should always have the best that we can get,
The human defense has to elevate, the human defense has to strengthen and here each executive, every vertical owner has to play their part and has to take a responsibility and partner with the CISO’s office.
Chris Hooper (41:24.258)
Yeah, I fully agree with that. think it’s, know, security of the business is, it has to be a shared responsibility as we move into this sort of this world of AI powered fraud. It’s one of those things that, you know, in previous history, I know certainly, you know,
roles I’ve had in the past and things like that. was almost a box checking exercise where you had to go through a certain level of awareness around email fraud and things like that, for example, as well, where once you’d done the course, you’d satisfied the requirement. There was no need for recall or anything like that. You just kind of went on with your work life, I suppose. But I think that that has changed, it feels like. And what would be, if we were to give one takeaway from this conversation here, is it…
Is it around that kind of level of urgency? Is that sort of what you’d point to, I think, for businesses here?
Aarti Samani (42:07.535)
Yeah, absolutely. It is here. It’s not a hypothetical threat anymore. It’s urgent. It’s imminent. Unfortunately, for most businesses, I will say it’s a matter of when rather than if. So let’s not be complacent. Let’s do everything we can to get our sort of
our tentacles on high alert, let’s get these emerging fraud vectors on the radars of our employees, of our partners, of our customers, of our board directors. Like that’s a demographic we did not talk about, but actually they are probably some of the least aware when it comes to this. And just recently, I was speaking to someone who was targeted by the deep fake video of one of their board directors asking them to…
do something. And it was only because this individual had received an awareness training on deep fake fraud, he went and cross-checked with the board director and it turned out that those weren’t authentic instructions, they were fabricated. And so, like every human who is involved with our organization needs to be aware of this, needs to be informed, and it is our responsibility as employers to do this job.
We can’t just rely on governments and regulations. Like a lot of times I hear people say, well, know, regulators should do this and we should have global regulations. I agree, we should. We should absolutely do everything we can to push the government, to push the regulators. But there’s a limit. We can’t execute it ourselves, right? Unless you are in that role, you are not in a position to execute it. You’re in a position to lobby for it. You can respond to calls for comments.
But what can you practically do? And that is take responsibility as an employer to empower your teams.
Chris Hooper (44:02.83)
Absolutely, I fully agree with that. think it’s something we’ve seen in a number of fields actually where regulation by its nature is always two or three steps behind. It sort of gets there after the horse has bolted to a certain extent, doesn’t it? And I think with the speed with which this type of fraud is moving as well.
any regulation you put in place now would almost be sort rendered redundant within a year, maybe less than that, and then you have to start the whole process over again. So I think the burden of responsibility does sit with businesses, does sit with the owners and the leaders of those businesses, but does also sit with everybody else within that business too. Well, just one last point there, just to finish off. I know we’re sort of close to time, but what is the of the one action you would point to then for businesses to improve their defences against deepfake fraud? What’s the one takeaway they can sort of…
know, having this conversation to sort of really make a practical difference to what they do.
Aarti Samani (44:53.253)
Yeah, make human defense part of your cybersecurity strategy. Like, I can put it very succinctly, that’s what I would say. And human defenses include awareness and training, but they also include ethical simulations mirroring real life scenarios. So we’re thinking from an attacker’s mindset and executing those simulations. Because if you don’t think like an attacker, then you can’t really, you can’t really.
predict what’s going to happen and therefore you are always a few steps behind that.
Chris Hooper (45:25.102)
Yeah, yeah, I fully agree with that. that’s a good point to end on, I think. We’ve covered an awful lot of ground today. So there’s a lot in here and hopefully your folks will appreciate that level of information. But Artie, it just remains for me to say thank you to you for joining us today. It was a very, very informative conversation. And as I say, we covered an awful lot of stuff, but I think there’s some great things and there’s some great takeaways as well. So thank you very much for your time. I appreciate it.
Aarti Samani (45:47.057)
Thank you for inviting me and giving me this platform to really drive this message forward, something that I feel very passionately about.
Chris Hooper (45:54.318)
Thank you everybody for listening and we’ll catch you next time.