Editor's Note:The author of this article, Ryan Hittner, is the leader of the Audit and Assurance practice at Deloitte & Touche LLP, one of the Big Four accounting firms. This article reflects the personal views of the author.

The rise of generative artificial intelligence (GenAI) has given rise to powerful, accessible, and scalable tools. When exploited by fraudsters, these tools can trigger a range of cybersecurity issues, from data breaches to malware, leading to various forms of theft.

Earlier this year, CNN.com published a report on deepfake fraud that revealed an increasingly serious fraud issue warranting the attention of every corporate executive. In the report, a finance employee was defrauded of $25 million by fraudsters impersonating the company's chief financial officer during an AI-enhanced video conference.

This incident serves as an unsettling preview of how the future threat landscape may evolve.

GenAI's ability to create credible, realistic-sounding deepfakes is just the tip of the iceberg when it comes to malicious use. The technology can also be used to enhance email phishing scams, enabling criminals to draft messages that mimic the writing style and grammar of trusted individuals or sources. Another malicious use involves manipulating data or forging documents to support fraudulent transactions. Combining these methods with GenAI is relatively easy, increasing the difficulty of preventing or detecting fraud.

In May of this year, the Federal Bureau of Investigation (FBI) San Francisco field office issued a warning that cybercriminals using AI for "sophisticated phishing/social engineering attacks and voice/video cloning scams" pose an "escalating threat."

Admittedly, cybersecurity issues existed before GenAI, but the rapid evolution of this technology has undoubtedly intensified potential threats.

The persuasiveness and speed of development of AI-enhanced threats likely mean that many traditional risk management protocols are no longer effective in defending against such attacks. The Deloitte Center for Financial Services predicts that by 2027, GenAI could drive U.S. fraud losses from $12.3 billion in 2023 to $40 billion.

Defensive Measures

Many organizations already place significant emphasis on cyber threats, but the advent of the GenAI fraud era is changing the rules of the game across the business landscape. Here are some defensive measures worth considering:

  • Learn the technology.Familiarize yourself with the fundamentals of GenAI, including algorithms, data sources, trends, and technologies, to better understand its advantages. Staying informed about AI advancements, particularly use cases relevant to your industry, helps deepen understanding of potential risks and vulnerabilities and identify capabilities that need improvement.
  • Understand your GenAI vulnerabilities.Identifying which security protocols are most likely to be breached or misled by GenAI-generated content—whether voice, video, audio, files, or other forms—is critical. Risk identification processes, which can include activities such as risk hackathons and brainstorming sessions, help uncover these vulnerabilities. Organizations can focus on strengthening access and approval processes, such as implementing multi-level approvals and multi-factor authentication to verify identities, as well as enhancing verification procedures for third-party files.
  • Conduct regular employee training.Fraud tactics may continue to evolve, and organizations' awareness should strive to keep pace. Employees and key stakeholders should all understand how to identify potential GenAI threats and how to properly respond to security breaches. Consider updating security processes to incorporate more diverse data when evaluating and verifying files, requests, or transactions.
  • Integrate internal expertise.Cyber threats are now complex enough that effective defense often requires multidisciplinary collaboration. Consider partnering with other departments within the organization, such as IT and human resources, to comprehensively assess AI-driven fraud risks and develop internal knowledge and skills.
  • Share lessons learned.Once malicious actors discover any weak point, other organizations are likely to become targets soon after. Sharing your findings helps protect more businesses.

While no threat can be completely eliminated, proactive defense and continuous improvement can reduce the likelihood of falling victim to GenAI fraud schemes. Organizations should, as always, proactively think about their defense and risk management strategies and regularly reassess and update their security protocols in response to the rapidly evolving GenAI threat landscape.