1 in 4 financial institutions report deepfake incidents: report

U.S. survey shows low confidence in employees' ability to identify AI-generated scams

1 in 4 financial institutions report deepfake incidents: report

A new survey of financial professionals in the United States has found that 1 in 4 financial institutions has experienced a suspected or confirmed deepfake incident.

The survey, conducted by US-based governance, risk and compliance software provider Tandem, gathered responses from 85 financial professionals working at banks, credit unions and other financial institutions of varying asset sizes.

It found that 25 per cent of respondents reported a known deepfake, voice cloning or AI impersonation incident, while 21 per cent said they were unsure whether their organization had been targeted.

Respondents pointed most often to fraud and impersonation scenarios, including AI-generated phishing, social engineering and voice cloning, rather than manipulated public-facing media, as their leading concerns, Tandem found.

These attempts increasingly surface inside everyday HR and administrative workflows, the survey noted, including payment requests, account access requests, customer interactions and help desk communications — all processes where employee judgment plays a direct role in detection.

That places the issue within existing responsibilities around cybersecurity awareness training for employees, rather than treating it solely as an IT concern.

Training confidence remains low despite the threat

Confidence in employees' ability to spot these scams is low. Only eight per cent of respondents expressed high confidence in their employees' ability to identify AI-generated scams, Tandem's survey found.

Most organizations surveyed reported they had not yet run deepfake-focused tabletop exercises to test their response under realistic conditions. Tandem's report recommends institutions strengthen verification and escalation procedures, improve detection of what it calls "human-layer" attacks, and test response capabilities through real-world scenarios rather than relying on awareness training alone.

The pattern echoes concerns already raised in HR-focused reporting on how recruitment scams are targeting HR teams, where AI-enhanced identities and forged documents have been used to bypass hiring safeguards.

Canadian regulators and fraud agencies flag similar risks

Canadian regulators have raised comparable concerns. The Office of the Superintendent of Financial Institutions (OSFI), the federal prudential regulator for banks and insurers, published a 2026 report on artificial intelligence risks facing Canadian financial institutions.

That report cited Michael Barr of the US Federal Reserve Board of Governors, who said in April 2025 that "deepfake attacks have seen a twentyfold increase over the last three years."

Closer to home, the Canadian Anti-Fraud Centre (CAFC) has reported Canadians lost more than $49 million to job and employment scams in 2024, a figure that has roughly quadrupled since 2022, according to reporting on employment scams putting HR on the front lines. The CAFC has said the rise of artificial intelligence has made it easier for fraudsters to identify targets and produce convincing scams at scale. Together, the two data points suggest AI-enabled impersonation is no longer a hypothetical risk for Canadian financial institutions, even though country-specific incident data remains limited.

For HR teams, the findings underscore that employees handling payroll changes, benefits inquiries and help desk requests are often the first point of contact for these attempts, making verification procedures and realistic training a shared priority across the sector.

Building a deepfake training program: five action items for HR

Drawing on recommendations from Canada's financial-sector AI risk forum and current national fraud data, HR teams can use the following steps as a starting point for building a deepfake-awareness training program.

#

Action item

Description

Source

1

Build role-based training scenarios around real incidents

Ground training in documented cases rather than generic warnings — for example, senior executives are frequent deepfake targets because so much of their voice and image data is publicly available online. Tailor scenarios by role (executive, payroll, customer-facing) rather than using one-size-fits-all modules.

Office of the Superintendent of Financial Institutions (OSFI), FIFAI II: AI Risks and Opportunities, March 23, 2026

2

Teach staff to verify identity-sensitive requests through a second channel

Train employees to question unexpected or unverified requests — especially those involving sensitive data, password resets, or financial transactions — even when the request appears to come from a trusted authority figure. Reinforce that pausing to confirm through an independent channel is expected behaviour, not a delay to be avoided.

OSFI, FIFAI II: AI Risks and Opportunities, March 23, 2026

3

Extend deepfake awareness to recruitment and onboarding

Hiring processes are a documented entry point for fraud: synthetic identities generated with AI have already been used to secure remote employment at North American firms and gain access to internal systems. HR and talent-acquisition teams should be trained to scrutinize identity verification during hiring, not only during established employment.

OSFI, FIFAI II: AI Risks and Opportunities, March 23, 2026 (citing US Department of Justice indictment, footnote 7)

4

Add voice-cloning scenarios given eroding trust in voice verification

Train staff, particularly those in call centres, help desks, and any role handling password resets or device requests, to treat voice alone as insufficient proof of identity. Industry survey data cited by OSFI found a large majority of financial institutions globally are already reconsidering their voice-verification systems because of AI voice-cloning capabilities.

OSFI, FIFAI II: AI Risks and Opportunities, March 23, 2026 (citing BioCatch 2024 AI, Fraud, and Financial Crime Survey, footnote 8)

5

Use national fraud data to set training frequency and urgency

Anchor the business case for ongoing (not one-time) training in current numbers: Canadians reported 15,107 fraud cases and $351 million in losses in the first half of 2026 alone. Even with a year-over-year decline from 2025's $704 million, the scale of loss supports treating deepfake and impersonation training as a recurring program rather than an annual checkbox.

Canadian Anti-Fraud Centre (CAFC), fraud impact statistics as of June 30, 2026

Latest stories