Why AI Isn't the Real Problem in Identity Fraud,Yet
While artificial intelligence dominates cybersecurity conversations, the real fraud crisis isn't driven by cutting-edge AI attacks,it's driven by criminals using AI to industrialize old-fashioned deception at unprecedented speed and scale. According to a new report from identity verification firm Signicat, 35% of UK identity fraud attempts occur during the transaction phase, with logins accounting for another 29%. The troubling part: these aren't novel AI-powered attacks. They're stolen credentials, phishing emails, smishing (SMS phishing), and account takeovers, now executed faster and against more targets than ever before.
Why Are Traditional Fraud Methods Still Winning?
The cybersecurity industry has spent the last two years warning about deepfakes and AI-generated voice clones. Those threats are real. But they're not the primary threat.
"We must not forget that classic forms of identity fraud are still growing," stated Thomas Osinga, Head of Identity Proofing at Signicat. "Fraudsters are not changing their approach. They use AI to industrialise the classic art of deception at scale."
Thomas Osinga, Head of Identity Proofing at Signicat
The shift is structural, not technological. Criminals have discovered that AI tools can automate the labor-intensive parts of traditional fraud: sending thousands of phishing emails, testing stolen credentials against multiple services, and orchestrating account takeovers across entire customer bases. The barrier to entry has collapsed. What required a criminal operation with resources now requires a laptop and a subscription service.
The financial impact is staggering. Businesses estimate that 19% of the transactions they process and customers they onboard are fraudulent. Smishing now accounts for 35% of all mobile phishing attempts, according to security firm SentinelOne. Meanwhile, AI-generated spear-phishing campaigns achieve a 54% click-through rate, more than four times higher than traditional emails, according to Harvard Business Review.
How Are Small Businesses Becoming the Easiest Targets?
Small businesses face a particular vulnerability: they lack the formal controls that large enterprises take for granted. At a Fortune 500 company, moving $50,000 requires multiple approval layers and dedicated treasury teams. At a 20-person professional services firm, the CEO can call the office manager directly and ask her to move money. That's how the business operates. Attackers know this, and they engineer their attacks to fit existing workflows rather than disrupt them.
Voice cloning fraud illustrates the problem. In 2025, criminals harvested CEO voices from public sources like YouTube interviews, LinkedIn videos, and podcasts, then called employees handling payments and requested urgent wire transfers to unfamiliar accounts. The phone call, which served as a verification step for decades, is no longer reliable. Caller ID is trivially spoofed, and the voice itself is now replicable with high fidelity. A cloned voice combined with a spoofed caller ID removes both signals employees instinctively use to trust a call.
The urgency framing is calibrated to small business culture. "I'm in a client meeting, I need this handled before 3 PM, do not email me back" lands plausibly in a fast-moving small business because it fits how the CEO has actually behaved in the past. The employee is not suspicious. The request is indistinguishable from a real one.
Steps to Protect Against AI-Weaponized Fraud
- Formalize Financial Authorization: Write down which channels can initiate a transfer, what dollar thresholds require additional approvals, and explicitly state that voice-only authorization is never sufficient to move money above a defined threshold. Leadership must sign the policy and review it annually.
- Implement Independent Verification: For any wire transfer or unusual payment request, verify through a second, independent channel using a pre-established code word or phrase. Independent means not a reply to the same phone call or email thread, but a separate channel the CEO controls, using a phrase agreed upon in advance and never shared publicly.
- Train Employees on Deepfake Voice Scams: General phishing training is insufficient. Employees need to know that voice cloning tools are accessible to criminals today, and that they are empowered to slow down and verify any urgent financial request, even from someone who sounds exactly like the CEO.
- Strengthen Supporting Security Controls: Attackers often combine voice fraud with email threads, fake invoice attachments, or account takeover of the CEO's actual email to add credibility. A well-managed security environment with monitored endpoints, email filtering, and identity protection closes these supporting attack vectors.
What Does Continuous Verification Look Like?
The solution isn't adding more visible friction or passwords. Instead, businesses must apply invisible security with continuous background checks throughout the entire customer journey. Companies can use real-time data like geolocation, IP analysis, and device metrics to spot anomalies without making the process harder for genuine customers.
This shift becomes more urgent as autonomous AI agents begin performing actions for humans. European Digital Identity (EUDI) Wallets will be available to European consumers by December 2027. At the same time, autonomous AI agents will increasingly execute tasks on behalf of users. As this transition accelerates, the fraud landscape will shift from human-to-human deception to AI-to-AI battles. Fraudsters will weaponize AI. Defenders will use AI technology to protect everything in the middle.
The healthcare and medical device sectors face an even sharper version of this problem. In January 2025, the FDA and Cybersecurity and Infrastructure Security Agency (CISA) jointly warned that Contec CMS8000 patient monitors contained an embedded backdoor with a hard-coded IP address that could allow remote code execution and patient data theft. No patch was available. The monitor was in clinical use worldwide, carrying a hidden function that bypassed every network security control around it.
AI-powered vulnerability discovery tools now compress the time to find such flaws from months to minutes, and they work for attackers as readily as for defenders. In April 2026, Anthropic released Claude Mythos Preview, a frontier model built for autonomous cybersecurity work. The model identified thousands of high-severity vulnerabilities across major operating systems and browsers, including a 16-year-old FFmpeg flaw that had survived extensive human review and 5 million automated tests. Within days, the White House and US Treasury convened major banks to assess systemic risk.
The deeper issue is that 60% of deployed medical devices are end-of-life with no security patches available. An infusion pump running firmware written in 2012 was engineered for an era when physical access was the primary security concern. The same pump now lives on a hospital network, reachable through remote maintenance tools. An AI-powered analysis of its firmware can enumerate its weaknesses in minutes. The attacker's cost of discovery has collapsed while the defender's cost of remediation, spread across thousands of deployed units with no patch path, has stayed flat or risen.
The real danger isn't rogue AI. It's that the builders of frontier AI models cannot fully predict what they will find or how model behavior will evolve as capabilities compound. Risk frameworks built on cataloged threats have no line item for unknown-unknowns. On August 7, 2026, OpenAI stated that preliminary evaluations left it unable to rule out that Astra, an upcoming model, has crossed the critical cyber capability threshold, defined by the ability to develop working zero-day exploits against hardened real-world systems without human intervention. The company paused internal work on the model.
The convergence of these trends means that cybersecurity itself must evolve. The old playbook of detecting known threats no longer works when AI can discover unknown vulnerabilities faster than humans can patch them. The new playbook requires continuous verification, formal processes, and the acceptance that no single control,not a phone call, not a password, not a firewall,is sufficient on its own. Fraud prevention must move toward continuous verified trust, with checks running silently in the background throughout the entire customer journey.