Request access
RankShield Network · Financial · Payment Fraud

Deepfake Fraud Statistics 2026: Reading the Numbers Honestly

The deepfake-fraud numbers people quote are three different kinds of evidence: one measured, one projected, one a single case. Read for what each actually is, none of them changes the defense, because the loss is still an authorized payment to a switched payee.

A brushed-steel featureless mask dissolving on one side into a grid of gold metallic pixels with a small teal indicator light, representing a synthetic or deepfake identity.
Key takeaways
  • The headline deepfake-fraud numbers are three different kinds of evidence. The FBI figure is a measured count of reported losses; the Deloitte figure is a projection from a model; the Arup figure is one confirmed case. They answer different questions and should not be quoted interchangeably.
  • Measured: the FBI recorded more than $893 million in losses across AI-nexus complaints in 2025, on top of $3.046 billion in total business email compromise losses, with 86 percent of BEC money moving by wire or ACH. Because it counts only reported crime, it is a floor, not a ceiling.
  • Projected: Deloitte projects US gen-AI fraud losses reaching $40 billion by 2027 from $12.3 billion in 2023, a 32 percent compound annual growth rate. That is a scenario model of a direction, not a count of what has already been lost.
  • One case: Arup lost $25 million in 15 transfers after an employee joined a video call where every other participant was a deepfake. It proves the attack is real and can scale per incident; it does not prove it is yet common.
  • None of these numbers changes the defense. Detection of a live deepfake is unreliable and lags the generators, so the durable control is to verify the payee and the approval before the payment settles, which is what RankShield Financial is built to do.

Deepfake fraud statistics are quoted constantly, and most of the time they are read as if they were the same kind of fact, when they are not. The three numbers you see most often are three different kinds of evidence: a measured count of reported losses, a modelled projection of where losses are heading, and a single confirmed case. Each is useful, but only if you read it for what it actually is, because a projection is not a count and one dramatic case is not a rate. The FBI measured more than $893 million in losses across complaints with an AI nexus in 20251; Deloitte's Center for Financial Services projects US generative-AI fraud losses reaching $40 billion by 2027, from $12.3 billion in 20232; and one firm, Arup, lost $25 million in a single deepfake-video case. This guide reads each number honestly, explains what it does and does not prove, and makes the point that matters for a finance team: whichever number you believe, the defense does not change, because the loss underneath all of them is an authorized payment to a switched payee.

The measured number: what the FBI actually counted

The most solid figure is also the most conservative, because it counts only crime that was reported. In its 2025 Internet Crime Report, the FBI recorded more than $893 million in losses across complaints that had an artificial-intelligence nexus1, including more than $30 million tied specifically to business email compromise with an AI component. That sits on top of the broader BEC total, which the same report put at $3.046 billion, with 86 percent of the stolen money moving by wire or ACH. These are the numbers to trust the most and to overclaim the least: they describe losses that were actually reported to one agency, in one country, in one year.

The honest reading is that this is a floor, not a ceiling. Payment fraud is heavily underreported, because businesses that lose money to a spoofed vendor or a cloned executive rarely file a public complaint, and many losses are absorbed quietly or handled through insurance. So the measured number tells you the problem is large and AI is now a named factor in it, but it undercounts the real total by an unknown margin. When you see a much larger figure quoted, the first question to ask is whether it is a count like this one or a projection, because the two are not comparable.

The projected number: what a $40 billion forecast is and is not

The figure people reach for when they want to convey scale is Deloitte's. Its Center for Financial Services projects that generative AI could push US fraud losses to $40 billion by 2027, from $12.3 billion in 20232, a compound annual growth rate of about 32 percent. It is a striking number and a reasonable one, but it is important to be precise about what kind of number it is: a projection built on adoption scenarios, not a count of money already lost. Deloitte itself frames it across conservative, base, and aggressive scenarios, which is the tell that this is a model of a direction rather than a measurement of an outcome.

That does not make it worthless; it makes it a different tool. A projection is useful for planning and for understanding trajectory, and the trajectory here is clearly steep. But it should never be quoted as if $40 billion had already been stolen, and it should not be stacked on top of the measured FBI figure as though they were additive. The disciplined way to use it is as a statement about where the curve points, paired with the measured number as the current floor. If a vendor cites the $40 billion figure without noting that it is a 2027 projection, that is a small sign to read the rest of their claims carefully too.

The case that made it real: Arup's $25 million

Statistics move people less than a single vivid case, and the case that anchors this whole topic is Arup. In early 2024 an employee in the engineering firm's Hong Kong office was persuaded to make 15 transfers totaling about $25 million3 after joining a video call in which every other participant, including a figure who looked and sounded like the company's chief financial officer, was an AI-generated deepfake. Arup's chief information officer later confirmed the incident publicly, noting that no internal systems were breached; this was social engineering enhanced by technology, not a network intrusion.

What the Arup case proves is real and important: a video call with familiar faces is no longer proof of anything, and a single deepfake-enabled fraud can scale to eight figures. What it does not prove is a rate. One catastrophic, widely reported case is evidence that the attack works and is worth an attacker's effort, not evidence that it happens to the average business every week. Holding both of those truths at once is the honest posture: take the attack seriously because it is real and can be large, without inflating a landmark case into an implied frequency it does not support.

What the numbers agree on, even where they differ

Read together, these three numbers disagree about magnitude and timing but agree completely about mechanism, and the mechanism is the part that should drive your decisions. In every one of them, the loss is an authorized payment to a switched or fraudulent payee. The deepfake, whether a cloned voice on a call or a fabricated CFO on video, is not the thing that moves the money; it is the thing that convinces a real, authorized employee to move the money themselves. That is why AI-enabled fraud clears the controls built to stop intruders: there is no intruder to catch, only a legitimate user acting on a convincing lie.

This is the same shape as ordinary business email compromise, which is why the FBI counts much of it under BEC. Artificial intelligence is an accelerant on an existing crime, making it cheaper, faster, and more convincing, rather than a new category that needs a new defense. As the companion guide on deepfake CEO fraud explains, the delivery method has changed but the ending has not: an authorized person releases money to an account the attacker controls. Once you see that every one of these statistics describes the same underlying event, the right response stops depending on which number you find most alarming.

Why a bigger number does not change the defense

The instinct when the numbers rise is to look for better detection, a tool that can spot the deepfake on the call or in the video. That instinct is understandable and, for the payment decision, misplaced. Detection of synthetic media is unreliable and structurally behind: the models that generate fakes improve faster than the models that detect them, so any detector is chasing last season's forgeries. Betting a wire on a system catching the fake in real time is a bet against the direction of the technology. This is exactly why the measured, projected, and single-case numbers can all keep climbing without changing what you should do.

The defense that does not depend on the size of the number is process, applied to the payment rather than the media. Verify any new or changed payee, and any urgent or unusual request, through a channel the attacker does not control, on a contact you already had. Hold the first payment to new details until that verification is complete. Record a named approval so the decision is attributable, and keep a verifiable record of it. That control works identically whether the true annual loss is $893 million or $40 billion, because it acts on the one step every version of the attack must pass through: the authorized release of the money. The payee verification discipline and the buyer's guide to choosing a tool both come back to this same standard.

Where RankShield Financial fits, and where it does not

Given all of that, here is the honest framing of what RankShield Financial does. It is a verification and attestation layer in the payment authorization path, not a deepfake detector, a bank, or a custodian of funds. It does not claim to tell you whether the voice on your call or the face on your screen is real, because that is the detection race no one reliably wins. What it does is verify the payee and a named approval and seal a checkable record before a payment settles, so that a convincing deepfake still cannot turn into a completed transfer without passing a verification the attacker cannot forge. It never touches the money, and it complements the controls you already run rather than replacing your bank or your accounting system.

The boundaries stay explicit, because a reader who has just been taught to distinguish a projection from a count will rightly hold a vendor to the same standard. RankShield verifies the payee and the approval and proves the decision; it does not vet your vendors for you, does not catch every scam, and is a design-partner-stage product that claims no network it has not built. Its value is precisely that it does not depend on winning the deepfake-detection arms race: it acts on the payment, which is the one place the outcome can still change. If you want that layer in front of your payments, you can see how it works or request access.

The statistic to remember

If you keep one thing from the deepfake-fraud numbers, make it this: the useful statistic is not the biggest one, it is the shared one. Measured at $893 million, projected at $40 billion, or realized as a single $25 million loss, every version of the story ends with an authorized payment to a payee the business was deceived into trusting. That is the number the defense actually addresses. You cannot control how convincing the fakes become, and you should assume they will only get better; you can control whether a payment leaves for a new or changed payee that a person verified out of band and approved on the record. Build for that, and the trajectory of the deepfake statistics becomes something you can watch with concern rather than fear.

Operate it

Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.

Conditions around this payment
PRE-SETTLEMENT VERDICTRANKSHIELD NETWORK

Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call

Downloadable · SVG
RANKSHIELD FINANCIAL // DEEPFAKE FRAUD, BY THE NUMBERS Three numbers, three different kinds of evidence MEASURED · US · REPORTED $893M+ FBI-recorded losses acrosscomplaints with an AI nexus,reported in 2025. FBI IC3, 2025 Internet Crime Report PROJECTED · MODEL $40B A 2027 projection for USgen-AI fraud, up from $12.3Bin 2023. A forecast, not a count. Deloitte Center for Financial Services ONE CASE · CONFIRMED $25M A single firm, Arup, lost thisin 15 transfers after a deepfakevideo call. One case, not a rate. Arup, confirmed by its CIO (2024) None of these changes the defense. The loss is still an authorized payment to a switched payee, so verify the payee before it settles. rankshieldfinancial.com A PROJECTION IS NOT A COUNT

The headline deepfake-fraud figures are three different kinds of evidence: the FBI measured more than $893 million in AI-nexus losses in 2025, Deloitte projected US gen-AI fraud reaching $40 billion by 2027 (a model, not a count), and Arup lost $25 million in one confirmed deepfake-video case. None of them changes the defense, because the loss is still an authorized payment to a switched payee.

FAQ

Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Self-check

How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

  1. 01Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
  2. 02Can one person both change a vendor’s bank details and approve the payment?
  3. 03Do you always confirm a bank-detail change on a number from your own files, not the request?
  4. 04Is the first payment to a new or changed payee held for verification before it goes out?
  5. 05Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5

Jamie Kloncz
About the author

Jamie KlonczFounder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

  • Primary sources only: each figure links to the original filing
  • Honest boundaries: what verification can and cannot do is stated plainly
  • Last verified August 18, 2026
Verify, then settle

See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.

Request accessHow it works