Certos Survey Finds Deepfake Fraud Hitting Finance Teams
Certos, part of Early Warning Services, found 81% of 230 senior finance leaders faced AI-linked fraud attempts in the past year.
81% of 230 senior finance executives surveyed by Certos, the fraud prevention unit of Early Warning Services, said their company faced an attempted fraud involving AI-generated or AI-enhanced content in the past year, the company said on October 8, 2026.
The result makes deepfake fraud finance teams must plan for a routine exposure rather than a rare event. Only half the respondents said they were very or extremely confident they could identify an AI fraud attempt before money left their institution.
The survey is vendor research. Certos sells payment validation and fraud tools to banks, and its conclusions point towards those products. The figures show what finance leaders reported, not confirmed losses, and the release publishes no loss amounts.
Independent data from the FBI and the Association for Financial Professionals (AFP) show the underlying problem is real and growing, though neither isolates deepfakes as the main cause.
What the Certos survey found on deepfake fraud
Accelerant Research conducted the survey for Early Warning online from August 7 to 21, 2026. Respondents were CFOs, treasurers, controllers and heads of finance with responsibility for treasury operations, payment execution or banking relationships. They came from Fortune 500 companies, venture-backed growth companies and large non-profits.
Banks and credit unions were excluded, and participants were compensated. The release does not give the split between the three groups.
Of those surveyed, 84% said AI-enabled fraud is harder to detect than traditional fraud and scams. Ninety-three per cent said the risk has changed how they view their commercial banking relationships, and 92% rated fraud prevention and scam-risk capabilities as very or extremely important when choosing a bank. Among Fortune 500 respondents that figure was 96%.
The respondents named the following as their main threats:
- Business email compromise: 57% overall, 62% at Fortune 500 companies
- Vendor impersonation: 53% overall, 59% at Fortune 500 companies
- Executive and client impersonation: 47% overall, 61% at Fortune 500 companies
Large companies report more exposure to impersonation of their own executives. That fits their structure: 77% of all respondents manage several banking relationships, rising to 81% in the Fortune 500, where 49% work with five or more banks.
Controls finance teams have changed
The survey asked what companies had done in response. Fifty-eight per cent increased multi-factor authentication, 51% expanded employee training and 37% added manual review holds for higher-risk payments.
The release does not break results down by payment type. It names wire and ACH transfers as the rails where real-time checks on the payee could help. It adds that crypto wallet-to-wallet transfers may bypass such controls and need separate safeguards.
That leaves a gap for finance teams. Vendor bank detail changes, the usual route for impersonation fraud, are not reported as a separate category. Teams reviewing their payment fraud prevention routines will need their own data on where attempts arrive, and an internal controls register is a practical place to record which approvals sit on ACH payments, wires and supplier master-data changes.
No controller or CFO is quoted by name in the release describing which controls they changed.
What Certos says banks should do
Ben Chance, general manager of Certos, argued that detection at the point of the call or message is not enough. “The solution isn’t just trying to spot the fake voice,” he said, in the release.
His case is for inter-bank network intelligence: banks sharing signals to confirm that a receiving account belongs to the intended payee before funds leave. Certos is the fraud and identity brand of Early Warning, the company behind Zelle. The release says Certos products have helped financial institutions stop about $16.4 billion in potential fraud over four years, and it gives no method for that figure.
The argument has a commercial logic. A payee check at the bank works regardless of how convincing the fake request was. It also requires the bank to hold the data, which is the service Certos sells.
The survey supports the demand side. Ninety-three per cent of respondents said cross-industry collaboration among companies, banks, payment networks and technology providers is vital.
FBI and AFP data on payment fraud
The FBI’s Internet Crime Complaint Center recorded business email compromise losses of $3.05 billion in 2025, from 24,768 complaints, according to its 2025 annual report. The 2024 figures were $2.77 billion and 21,442 complaints. Only investment fraud caused larger losses.
The report includes an AI section for the first time. It lists 22,364 complaints and nearly $893 million in losses with an AI link. Total reported cybercrime losses for all victims reached nearly $21 billion, up 26% from 2024, the FBI said.
The AFP’s 2026 Payments Fraud and Control Survey, underwritten by Truist and published on April 14, found that 76% of organisations experienced attempted or actual payments fraud in 2025. That was a slight fall from 2024. Business email compromise affected 74%, and 58% reported check fraud.
Only 17% of organisations in the AFP survey use AI to fight payments fraud. Among those that do, 45% reported better detection of deepfakes.
The AFP and FBI figures measure different things from the Certos survey. They count fraud against payments, while Certos counts attempts involving AI content. The overlap is business email compromise, where AI-written messages and cloned voices make requests harder to refuse.
The Arup case shows how deepfake fraud works
The clearest documented case remains the one at Arup, the British engineering group. In early 2024 a finance employee in Hong Kong sent about $25 million to criminals after a video call in which senior colleagues were AI-generated impersonations.
Rob Greig, Arup’s global chief information officer, has described the incident as “technology-enhanced social engineering” rather than a cyberattack. The criminals did not breach Arup’s systems or disrupt its operations, according to the World Economic Forum’s account. They persuaded a person to make payments.
That is the exposure for finance teams. The payments were authorised by a real employee, and a control that relies on recognising a face or a voice failed. Controls that do not depend on recognition, such as callbacks to numbers held on file, dual approval and payee validation, are the ones that apply.
Governance of automated tools matters too, since the same techniques are spreading into agent-driven workflows. Finance leaders deciding who and what may initiate a payment can start with AI agent governance for finance teams.
What deepfake fraud means for finance teams next
The Certos survey measures concern and attempted fraud, not losses, and it draws on a compensated sample of 230. Treated as directional evidence alongside the FBI and AFP figures, it points one way: impersonation of executives and vendors is the attack finance teams most expect.
The next data points are due from the FBI, whose IC3 report for 2026 will show whether the AI-linked complaint count of 22,364 grows, and from the AFP, whose 2027 survey will show whether the 17% using AI against fraud rises.
Accountio.
The go-to weekly newsletter for accounting professionals. Trusted by 10,000+ industry leaders to deliver the tech trends and insights that matter most. Join them today.
