top of page

Everyone Sees It Coming and Almost Nobody Is Prepared

Forty four per cent report deepfake social engineering rising sharply, fifty five per cent expect worse, and seven per cent describe themselves as more than moderately ready.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.




There is a particular kind of governance failure that does not involve ignorance. The organisation knows the threat is coming, says so in writing, and does nothing that would meaningfully change the outcome. New global research on artificial intelligence and fraud has produced the clearest example of this pattern I have seen, and South African boards sit squarely inside the sample.


CONTEXT AND BACKGROUND

The Association of Certified Fraud Examiners, working with SAS, surveyed 713 anti-fraud professionals across eight regions including sub-Saharan Africa for the fourth edition of its benchmarking study. Deepfake social engineering was the AI-powered scheme most often reported to have increased significantly over the past two years, at forty four per cent, and fifty five per cent expect it to grow significantly again over the next two, alongside generative document forgery. Against that, only seven per cent believe their organisation is more than moderately prepared to detect or prevent AI-powered fraud. The association’s president put the conclusion plainly, saying “fraud is evolving faster than most organizations can defend against it.”


INSIGHT AND ANALYSIS

The gap between anticipation and preparation exists because the threat has been filed in the wrong drawer. Boards have been briefed on synthetic media as a security matter, which implies a detection product, a procurement cycle and a technology owner. The attack does not work that way. In July 2026 the Federal Bureau of Investigation warned that criminals now generate video for real-time chats with people posing as company executives, law enforcement or other authority figures, and produce video in private communications specifically to prove the contact is a real person. Notice what is absent from that description. There is no intrusion, no malware and no compromised credential. A properly authenticated employee, following an approved process, authorises a legitimate payment for an illegitimate reason. Every system performs exactly as designed. That is why the security budget has not moved the readiness number, and why it will not.


IMPLICATIONS

Two consequences follow for organisations here. The first is that the local trend line is already visible. SABRIC’s 2025 annual banking crime statistics show digital banking crime losses rising to R2.4bn from about R1.9bn the previous year, with banking applications accounting for more than seventy per cent of reported digital losses, and local institutions have been warned that criminals are using artificial intelligence to impersonate bank officials and manipulate digital platforms. The second is a matter of proportion that deserves honesty.


Executive impersonation produces spectacular individual losses rather than the largest aggregate ones. In the American figures, investment fraud accounted for more than 8.6 billion dollars of losses in 2025 while business email compromise accounted for three billion, from over a million complaints. The case for acting does not rest on this being the biggest category. It rests on the loss per incident being catastrophic and the controls being cheap.


CLOSING TAKEAWAY

Almost everything that would move an organisation out of the ninety three per cent costs nothing to purchase. Confirm payment instructions by calling a number the organisation already holds, never one supplied in the instruction itself. Agree a challenge phrase in advance with anyone who can authorise a payment, shared in person and never stored where the payment system stores anything, because a word the caller must produce defeats a cloned voice in a way that recognising the voice never will. Require two people who genuinely report to different executives to release funds above a threshold. Establish that no instruction is ever confirmed through the channel that delivered it. Test the treasury and accounts payable teams against a scenario involving a familiar voice rather than against another generic phishing simulation. None of that requires a vendor, a business case or a project. It requires the audit committee to ask one question at the next meeting and to be dissatisfied with a documented answer rather than a demonstrated one.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net

 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page