Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

How AI-Driven Fraud Works and How to Stop It

AI-driven fraud reuses the routes to money your organization already has. See the four paths a fraudulent request takes and the controls that close each.

Evolution of AI-driven threats

A caller using an executive's cloned voice (opens in new tab) asks finance to change bank details, while another asks the help desk to move MFA to a new device. AI-driven fraud runs the schemes your organization already faced, with one change that matters more than the technology behind it: generative AI has reduced production costs (opens in new tab) and the time to produce a convincing, personalized approach, which turns fraud from a craft into a volume business.

However good the impersonation, a fraudulent request still has to reach a business process that hands something over, one that releases money or grants access through approval or enrollment. This article explains what AI changed about the economics, the paths a fraudulent request takes to a payout, why reported losses understate the exposure, and the controls that close each path.

Key takeaways

  • Generating a personalized fraudulent approach now costs very little, which makes campaigns profitable that used to run at a loss.
  • The impersonation is disposable, while the paths a fraudulent request travels to reach money are few and already familiar to you.
  • Two of those paths report to teams outside security, so reported AI fraud losses set a floor under the real exposure.

AI-driven fraud runs the same schemes at a fraction of the cost

AI-driven fraud (opens in new tab) is a form of social engineering fraud (opens in new tab) in which generative AI produces the impersonation that makes a fraudulent request or counterparty look legitimate.

A convincing impersonation now costs very little per target

A personalized, convincing approach now costs almost nothing to produce. In controlled testing, a fully automated AI pipeline (opens in new tab) handled target research (opens in new tab) and message generation at minimal per-target cost and far faster than skilled manual work, turning outreach from a scarce task into a repeatable step.

Cheap attempts make campaigns profitable that used to run at a loss

AI automation can increase phishing profitability by as much as 50 times (opens in new tab) by scaling highly targeted attacks to large audiences at minimal cost. When the cost per attempt approaches zero, an attacker no longer has to choose targets carefully.

Mid-value employees who were not worth a skilled operator's half hour become worth approaching, and the same economics reach smaller suppliers and ordinary customers.

The impersonation changes faster than the path to the money

AI made the stages before the payout cheap: building the infrastructure, reaching the target, and sustaining the conversation (opens in new tab) across the Setup, Launch, Contact, Engagement, and Compromise stages of the social engineering attack chain (opens in new tab).

The Compromise stage, where value actually moves, still runs through business processes your organization built for legitimate reasons and still needs.

Where AI-driven fraud reaches your money and your systems

Four such processes recur across enterprises. Two release money directly: a payment your organization approves and a payment your customer makes to someone posing as you. Two are gates that hand the attacker a position to convert later: an access grant (opens in new tab), and an enrollment that admits a fabricated counterparty.

A single operator may work more than one of these against the same organization in the same week. Financial services carries two more on the same logic, contact-center account takeover and account origination under a fabricated identity, set aside here.

1. A fraudulent payment request exits through finance

A fraudulent payment leaves through the process built to approve one. Criminals use generative AI to impersonate an executive (opens in new tab) or other trusted employee, then instruct staff to transfer funds to accounts under their control.

US businesses reported substantial 2025 losses (opens in new tab) to BEC scams (opens in new tab), and that figure counts only victims who recognized an AI element. When a fraudulent payment clears, your response plan (opens in new tab) governs the hours that follow.

2. An impersonated employee talks the help desk into an access grant

The attacker defers the payout for a position that converts to money later. Posing as employees, they convince IT and help desk staff (opens in new tab) to hand over sensitive information or reset a password, and can move that employee's MFA to a device they control. That mechanic predates generative AI and requires no AI at all.

Criminals also use AI-generated audio clips (opens in new tab) of real people to impersonate them in social engineering and financial fraud.

With 62% (opens in new tab) of organizations reporting a deepfake attack involving social engineering or automated-process abuse in the year to mid-2025, the pressure on password reset fraud (opens in new tab) keeps rising.

3. An impersonated brand takes payment from your customers

Security programs have the least line of sight into this path. Attackers use your name and your executives' likenesses to take customer payments (opens in new tab), so the customer sends money to the attacker and your organization receives nothing.

The same federal report logs substantial losses to investment fraud with an AI element, in schemes that use generated videos and voices (opens in new tab) of CEOs, celebrities, and other trusted figures to manufacture credibility.

The customer absorbs the loss, the brand absorbs the damage, and your own ledger records nothing.

4. A fabricated identity gets onboarded as an employee or supplier

This gate inverts the pattern: the organization invites the attacker across the boundary. The inflow is large. Fake candidate profiles (opens in new tab) will account for a growing share of worldwide submissions, and some job candidates already admit to interview fraud, either posing as someone else or having someone else pose as them.

A fraudulent applicant who passes screening receives employee credentials and network access.

A June 2025 Department of Justice action found North Korean IT workers had used the stolen identities (opens in new tab) of dozens of US persons to obtain remote roles at many US companies. The goal in these employment cases generally appears to be access to company networks (opens in new tab), which is what makes this a gate and produces no immediate loss to report.

The supplier side runs the same gate on a different process, where a fabricated vendor is onboarded and later paid through vendor impersonation fraud (opens in new tab); learning to spot fake job applicants (opens in new tab) closes the employee side.

Why your reported AI fraud losses are a floor

The number a security leader reports understates the exposure in three ways at once, and they compound.

  • Organizational routing. Payment approval sits with finance, access provisioning with IT and identity, customer complaints with support and trust and safety, and enrollment with HR and procurement. Typically only the first two reach a security incident queue, so half the exposure rarely rolls up through the cross-functional reporting (opens in new tab) leadership reviews.
  • Definitional undercount. A cloned voice is counted only when the victim realized it was cloned. Overall investment losses ran far higher than the AI-flagged share in the same federal report, which notes that many victims do not realize the extent AI may be involved in scams.
  • Fragmentation. Operators reuse infrastructure and personas (opens in new tab), so one operator can approach finance for payment, call the help desk, and stand up a counterfeit seller page for customers in the same week. Each team resolves its own item at its own severity and closes it, so one campaign is recorded three times as three small things, with no line anywhere that totals it.

Each mechanism leaves part of the same campaign outside the numbers leadership sees.

How to stop AI-driven fraud at the payout and the gate

Two of the four paths release money directly, and two hand the attacker a position first: the gates. The controls below reduce how many fraudulent requests reach a payout by protecting the payment, access, enrollment, and customer-reporting workflows, and dismantling the impersonation infrastructure (opens in new tab) behind these attempts shortens several paths at once.

Put the verification step on the payout action itself

The durable control sits on the action that moves value (the payment release, the access grant, the enrollment approval) because a check placed there must be satisfied whatever the request looked like on arrival.

A requirement attached to an inbound message can be sidestepped by switching channel, which AI has made cheap.

For payments, require an independent account-ownership check against banking data outside the requester's control before finance pays any new vendor account or bank-detail change. For access, let the reset workflow (opens in new tab) issue new credentials and take that discretion away from the agent, with identity proofing comparable to NIST IAL2 (opens in new tab) before the help desk changes credentials or MFA.

Give the customer-facing path an internal owner

The path with no owner is the one that stays open. Assign support or trust and safety to own customer-facing impersonation, which means a route for customers to report impersonation (opens in new tab) that reaches an accountable team, abuse reports treated as threat data, and one team owning the time between a fake going live and coming down.

That owner routes confirmed domains, profiles, ads, and seller pages to whoever can file removals with registrars, platforms, ad networks, and telcos, and keeps one shared case from first report to takedown.

Treat hiring and vendor onboarding as security controls

Identity proofing (opens in new tab) at hiring and supplier onboarding closes the fourth path, and it usually sits with teams that have no security tooling. Security should own the identity-verification step in both processes and brief interviewers and onboarding staff on the tactics in use, including real-time deepfake interviews (opens in new tab) and fabricated vendor portals.

HR and procurement should require independent identity and account checks before activating an employee or supplier record, while security defines the proofing standard, reviews exceptions, and gives staff a route to escalate mismatched identities, altered payment details, or suspicious portals.

How Doppel defends against AI-driven fraud

Doppel is the AI-native Social Engineering Defense (SED) (opens in new tab) platform that unifies Doppel Digital Risk Protection and Doppel Human Risk Management. Its AI agents use the Doppel Threat Graph (opens in new tab) to correlate the scattered artifacts behind these paths into a single campaign, so a payment approach at finance and a help desk call in the same week resolve as one operator with one infrastructure set.

Within Digital Risk Protection (opens in new tab), AI agents detect spoofed domains, fake profiles, counterfeit sellers (opens in new tab), and fraudulent support portals and run provider takedowns across registrars, social platforms, telcos, and ad networks, dismantling the infrastructure behind the customer-facing path.

Executive Protection (opens in new tab) removes leaked executive PII, credentials, and deepfake content (opens in new tab) from data broker and dark web (opens in new tab) venues, cutting the raw material for those pretexts.

Within Human Risk Management (opens in new tab), adaptive AI voice agents (opens in new tab) rehearse help desk identity-verification and MFA-reset workflows under fraud and scam prevention (opens in new tab), navigate IVR trees and hold times, and pivot to email or SMS the way real attackers do.

Make the routes to your money expensive to reach

AI will keep driving impersonation costs down, so the defensible position is built around the paths, which are few and already familiar. Put verification on the action, give the customer-facing path an owner, and keep attacker infrastructure from staying up, so each attempt costs more even as the impersonation gets cheaper.

Request a demo (opens in new tab) to get started with Doppel.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.