
How to protect your business from AI-driven fraud: Q&A
Learn how AI, social engineering and payment scams are changing the fraud landscape
4 min read
KEY POINTS
- AI is making fraud more convincing through voice cloning, deepfakes, phishing emails and highly personalized social engineering attacks.
- Businesses can reduce risk by implementing multi-factor authentication, dual approvals, Positive Pay services and independent payment verification procedures.
- Combining employee education with layered fraud prevention controls is one of the most effective ways to defend against modern payment and account takeover scams.
Decades ago, AI being used to maliciously impersonate a person’s voice was the subject of sci-fi scripts, but certainly not real life. Today, it’s the foundation of a dangerous form of attack on businesses, in which fraudsters use AI to impersonate a representative at a financial institution to try to convince a business’s employees to change payment information.
This type of fraud, called voice cloning or deepfakes, is one of the many sophisticated types of attack that BOK Financial® Treasury Management Officer Joseph Rangel teaches businesses how to recognize and prevent. In this Q&A, he explains how he discusses fraud with clients, the concerns he’s hearing most and the steps that businesses can take today to mitigate the risk.
Can you describe your role at BOK Financial?
I’m based in Houston and work with clients across corporate banking, commercial real estate and energy. Because I support a variety of industries, I see a wide range of payment challenges and fraud threats facing businesses today.
My role is to help clients strengthen their treasury management processes and reduce risk. That includes evaluating payment workflows, recommending fraud prevention tools and working with organizations to educate employees about emerging fraud trends. I regularly meet with client teams to share practical strategies that can help them identify suspicious activity and protect their businesses from financial loss.
What fraud concerns are you hearing from clients and how do you typically respond to those concerns?
We're hearing concerns about wire fraud, account takeover, check fraud and social engineering attacks. When addressing those concerns, I emphasize a layered approach to fraud prevention. It starts with fostering a culture of healthy skepticism around requests involving money movement or sensitive information.
From there, businesses should pair employee awareness with controls such as Positive Pay for ACH and checks, dual approvals, account alerts and multi-factor authentication. Fraud prevention is most effective when organizations combine informed employees with multiple layers of security.
What is the biggest fraud threat keeping business leaders up at night?
The biggest threat I'm hearing about today is social engineering because it targets people rather than systems. Fraudsters have become increasingly sophisticated in the way they create trust and urgency, often impersonating executives, vendors, customers and even bankers. What makes this especially concerning is that it can bypass otherwise strong security controls. If an employee is manipulated into taking action, a simple phone call or email can lead to compromised credentials or an attempted fraudulent wire transfer. This combination of human trust and increasingly sophisticated tactics makes social engineering one of the most difficult risks for organizations to defend against.
What are some ways that AI is changing the fraud landscape, both in terms of the types of threats and the prevention measures that are available?
AI is changing both sides of the equation.
On the threat side, fraudsters are using AI to create more convincing phishing emails, voice cloning, deepfakes and highly personalized scams at a scale we've never seen before. Messages that once contained obvious warning signs now appear polished, professional and tailored to specific recipients. AI also allows fraudsters to mimic a person's communication style. If they gain access to email conversations, they can study how someone writes and continue those conversations in a way that appears authentic and trustworthy.
At the same time, AI is helping strengthen fraud prevention efforts. AI-powered tools can identify anomalies, detect suspicious activity more quickly and recognize patterns that humans might overlook. As these capabilities evolve, organizations will need to combine advanced technology with strong employee education and verification procedures to stay ahead of emerging threats.
What are some practical steps that organizations can take today to reduce the risk of fraud?
One of the most effective steps organizations can take is to establish verification procedures for payment-related requests. For example, businesses should independently verify changes to payment instructions using a trusted phone number already on file rather than relying on contact information included in an email or message.
Organizations should also implement multi-factor authentication, maintain strong password practices and require dual approvals for payment initiation and release. Segregating duties within the payment process can help reduce both internal fraud risks and account takeover attempts.
Finally, businesses should take advantage of fraud prevention tools such as Positive Pay for ACH and checks, along with account alerts that can help identify suspicious activity before money leaves the account. Combined with ongoing employee awareness efforts, these measures can significantly reduce an organization's fraud risk.
For more on how your business can reduce the risk of fraud, visit our Fraud Protection page.