Knowledge and Insights
AI, Deepfakes, Fraud & Scams: A Perspective for Bankers and the Customers They Serve
By: IsabelDominic Hulick, CAMS, Director
Artificial intelligence is enabling criminals to proliferate fraud at a rate higher than ever. Banks and financial institutions must rethink how they approach identity verification, fraud prevention, and risk management. Consumers must remain more vigilant than ever with the wherewithal to recognize increasingly deceptive schemes.
Criminals are using AI software to impersonate people, generate convincing phishing schemes, and circumvent financial institutions’ identity verification controls. Addressing this requires two concurrent approaches: (1) making a concerted effort to raise customer’s awareness to better protect themselves, and (2) helping institutions modernize their fraud control and governance frameworks to combat AI-enabled fraud that is escalating at scale.
UNDERSTANDING THE THREAT: WHAT AI-ENABLED FRAUD LOOKS LIKE
More than ever, criminals are using artificial intelligence to create deepfakes, which are fake media creations, engineered to gain your trust and then swindle you out of money. A deepfake can be an image, a video, or audio. It can depict people you know, your friends and family, or public figures such as celebrities, government officials, or law enforcement.
Criminals scour the web and social media to source the images, video clips, and audio they need to fabricate convincing impersonations. The underlying tactics used once the impersonation is created remain the same: imitate a person, fabricate a situation, deceive you to make you believe a falsehood, and trick you into sending money. What is changing is the scale that these impersonations can be executed on – and the believability of the impersonation.
The ability to distinguish legitimate communication from a scam has become significantly harder since the widespread introduction of personal and commercial AI software in 2022. Federal government agencies issued multiple public advisories on this topic in 2025 and 2026.
The proliferation and success of AI-enabled fraud have increased tenfold since the widespread introduction of commercial AI software in 2022.
HOW CONSUMERS ARE TARGETED: THE GRANDPARENT SCAM
One of the most emotionally devastating and rapidly growing scams, the Grandparent Scam, illustrates exactly how this technology is weaponized against ordinary people.
THE SCENARIO — THE GRANDPARENT SCAM
A criminal obtains your personal information by mining social media or purchasing it from data brokers. They fabricate a believable story and contact a family member; typically a parent or grandparent. Posing as a child or grandchild that is in distress using voice cloning technology, paired with phone number spoofing, it is increasingly easier for criminals to imitate the family member’s voice and caller ID.
The call is engineered to incite emotion, panic, and urgency, falsely claiming the family member is in danger and that the parent must act immediately. This deliberate pressure is designed to lower the target’s ability to think critically by allowing panic to override judgment.
YOU RECEIVED A CALL LIKE THIS… NOW WHAT?
Do not trust the voice on the phone. Write down the details, hang up, and call the relative who is allegedly in danger using the number saved in your own phone book. If you cannot reach them directly, contact other family members or friends. Consider setting up a family safe word — a code only known to your household. If the person on the other end cannot provide it, treat the call as a scam.
HOW TO PROTECT YOURSELF: ADVICE EVERYONE SHOULD HEED
CONSUMER PROTECTION GUIDANCE
If any situation pressures you to act quickly – to share personal information or send money – stop and think before doing anything.
- Verify the legitimacy of people and companies by hanging up and redialing using independently sourced, trusted contact information.
- Limit your digital footprint: ensure photos, voice clips, and videos of yourself are not freely available online.
- Be wary of emotional manipulation that relies on fear and urgency to drive action.
- Be suspicious of any unexpected contact that requires payment or sharing of personal information.
- Watch for uncharacteristic communication from someone you know, especially over text, call, or video.
- Monitor federal government agency official webpages for announcements and bulletins of emerging fraud trends.
Before sending money or personal information, confirm the recipient is legitimate, that you expected the request, and that you are not being pressured to act in isolation or right away.
If you believe you were a victim of a fraud, report it to your local police department and your financial institution right away.
THE BANKER’S PERSPECTIVE: WHY THIS CHALLENGE IS DIFFERENT
The challenge institutions face is not new in its nature — but it is escalating in scale and sophistication in ways that demand a strategic response. This is not a purely technological problem. Institutions must balance fraud mitigation with customer experience, regulatory expectations, and operational efficiency.
The path forward starts with understanding your current risks, identifying the gaps, and implementing practical, prioritized action. This should be done dynamically and on an ongoing basis as risks evolve. The objective is to maximize you and your team’s efforts toward mitigating the highest risks, which inevitably will change over time. That period of time, in the day and age of AI-enabled fraud, is shorter than ever.
WHY AI FRAUD RISK MATTERS NOW
Artificial intelligence enables machines and software to simulate aspects of human learning, problem-solving, and decision-making. The machine learning technologies underlying today’s AI allow software to produce highly realistic text, audio, images, and video at scale — and at low cost.
This technology developed in parallel with a post-pandemic shift in banking toward speed, convenience, and digital access is a combination that has created significant openings for criminal exploitation.
Banks are exposed to a range of fraud risks: organic and synthetic identity theft, online account takeover, and unauthorized transactions. Institutions must ensure that the person on the other end of a phone call or digital transaction is who they claim to be.
Existing operational controls – callback procedures, identity verification, and credit history checks no longer have sufficient power to detect AI-enabled fraud schemes. Multi-factor authentication, liveness checks, and biometric authentication will increasingly become industry-standard CIP and identity verification protocols. Fraud and scams are proliferating at a rate faster than ever, and Banks are incurring significant financial and reputational losses when prompt action is not taken.
HOW MERCADIEN CAN HELP
Addressing AI-enabled fraud requires more than awareness. It demands a fast, practical, and agile framework — one that accounts for your products, channels, customer base, fraud exposure, existing technologies, and regulatory obligations.
As financial crime threats continue to evolve, institutions need advisors who understand not only the law, but also how compliance and operations intersect in practice. Mercadien brings a perspective that helps your institution build resilience in a rapidly changing environment.
Visit Mercadien.com
DISCLAIMER: This advisory resource is for general information purposes only. It does not constitute business or tax advice and may not be used or relied upon as a substitute for business or tax advice regarding a specific issue or problem. Advice should be obtained from a qualified accountant, tax practitioner or attorney licensed to practice in the jurisdiction where that advice is sought.


