# Deepfake Fraud Statistics 2026: What the Numbers Show | RankShield Financial

> Deepfake fraud statistics, read honestly: what the FBI actually measured, what Deloitte projected, the $25M Arup case, and why none of it changes the defense.
>
> Source: https://rankshieldfinancial.com/resources/deepfake-fraud-statistics-2026/ · RankShield Financial (verifiable pre-settlement payment security)

RankShield Network · Financial · Payment Fraud
# Deepfake Fraud Statistics 2026: Reading the Numbers Honestly

The deepfake-fraud numbers people quote are three different kinds of evidence: one measured, one projected, one a single case. Read for what each actually is, none of them changes the defense, because the loss is still an authorized payment to a switched payee.
   By  Jamie Kloncz  Founder, RankShield Financial    August 18, 2026 · 11 min read               Key takeaways
- The headline deepfake-fraud numbers are three different kinds of evidence. The FBI figure is a measured count of reported losses; the Deloitte figure is a projection from a model; the Arup figure is one confirmed case. They answer different questions and should not be quoted interchangeably.
- Measured: the FBI recorded more than $893 million in losses across AI-nexus complaints in 2025, on top of $3.046 billion in total business email compromise losses, with 86 percent of BEC money moving by wire or ACH. Because it counts only reported crime, it is a floor, not a ceiling.
- Projected: Deloitte projects US gen-AI fraud losses reaching $40 billion by 2027 from $12.3 billion in 2023, a 32 percent compound annual growth rate. That is a scenario model of a direction, not a count of what has already been lost.
- One case: Arup lost $25 million in 15 transfers after an employee joined a video call where every other participant was a deepfake. It proves the attack is real and can scale per incident; it does not prove it is yet common.
- None of these numbers changes the defense. Detection of a live deepfake is unreliable and lags the generators, so the durable control is to verify the payee and the approval before the payment settles, which is what RankShield Financial is built to do.

Deepfake fraud statistics are quoted constantly, and most of the time they are read as if they were the same kind of fact, when they are not. The three numbers you see most often are three different kinds of evidence: a measured count of reported losses, a modelled projection of where losses are heading, and a single confirmed case. Each is useful, but only if you read it for what it actually is, because a projection is not a count and one dramatic case is not a rate. The FBI measured more than $893 million in losses across complaints with an AI nexus in 2025 1 ; Deloitte's Center for Financial Services projects US generative-AI fraud losses reaching $40 billion by 2027, from $12.3 billion in 2023 2 ; and one firm, Arup, lost $25 million in a single deepfake-video case. This guide reads each number honestly, explains what it does and does not prove, and makes the point that matters for a finance team: whichever number you believe, the defense does not change, because the loss underneath all of them is an authorized payment to a switched payee.

## The measured number: what the FBI actually counted

The most solid figure is also the most conservative, because it counts only crime that was reported. In its 2025 Internet Crime Report, the FBI recorded more than $893 million in losses across complaints that had an artificial-intelligence nexus 1 , including more than $30 million tied specifically to business email compromise with an AI component. That sits on top of the broader BEC total, which the same report put at $3.046 billion, with 86 percent of the stolen money moving by wire or ACH. These are the numbers to trust the most and to overclaim the least: they describe losses that were actually reported to one agency, in one country, in one year.

The honest reading is that this is a floor, not a ceiling. Payment fraud is heavily underreported, because businesses that lose money to a spoofed vendor or a cloned executive rarely file a public complaint, and many losses are absorbed quietly or handled through insurance. So the measured number tells you the problem is large and AI is now a named factor in it, but it undercounts the real total by an unknown margin. When you see a much larger figure quoted, the first question to ask is whether it is a count like this one or a projection, because the two are not comparable.

## The projected number: what a $40 billion forecast is and is not

The figure people reach for when they want to convey scale is Deloitte's. Its Center for Financial Services projects that generative AI could push US fraud losses to $40 billion by 2027, from $12.3 billion in 2023 2 , a compound annual growth rate of about 32 percent. It is a striking number and a reasonable one, but it is important to be precise about what kind of number it is: a projection built on adoption scenarios, not a count of money already lost. Deloitte itself frames it across conservative, base, and aggressive scenarios, which is the tell that this is a model of a direction rather than a measurement of an outcome.

That does not make it worthless; it makes it a different tool. A projection is useful for planning and for understanding trajectory, and the trajectory here is clearly steep. But it should never be quoted as if $40 billion had already been stolen, and it should not be stacked on top of the measured FBI figure as though they were additive. The disciplined way to use it is as a statement about where the curve points, paired with the measured number as the current floor. If a vendor cites the $40 billion figure without noting that it is a 2027 projection, that is a small sign to read the rest of their claims carefully too.

## The case that made it real: Arup's $25 million

Statistics move people less than a single vivid case, and the case that anchors this whole topic is Arup. In early 2024 an employee in the engineering firm's Hong Kong office was persuaded to make 15 transfers totaling about $25 million 3 after joining a video call in which every other participant, including a figure who looked and sounded like the company's chief financial officer, was an AI-generated deepfake. Arup's chief information officer later confirmed the incident publicly, noting that no internal systems were breached; this was social engineering enhanced by technology, not a network intrusion.

What the Arup case proves is real and important: a video call with familiar faces is no longer proof of anything, and a single deepfake-enabled fraud can scale to eight figures. What it does not prove is a rate. One catastrophic, widely reported case is evidence that the attack works and is worth an attacker's effort, not evidence that it happens to the average business every week. Holding both of those truths at once is the honest posture: take the attack seriously because it is real and can be large, without inflating a landmark case into an implied frequency it does not support.

## What the numbers agree on, even where they differ

Read together, these three numbers disagree about magnitude and timing but agree completely about mechanism, and the mechanism is the part that should drive your decisions. In every one of them, the loss is an authorized payment to a switched or fraudulent payee. The deepfake, whether a cloned voice on a call or a fabricated CFO on video, is not the thing that moves the money; it is the thing that convinces a real, authorized employee to move the money themselves. That is why AI-enabled fraud clears the controls built to stop intruders: there is no intruder to catch, only a legitimate user acting on a convincing lie.

This is the same shape as ordinary business email compromise, which is why the FBI counts much of it under BEC. Artificial intelligence is an accelerant on an existing crime, making it cheaper, faster, and more convincing, rather than a new category that needs a new defense. As the companion guide on [deepfake CEO fraud](https://rankshieldfinancial.com/resources/deepfake-ceo-fraud-voice-cloned-wire/) explains, the delivery method has changed but the ending has not: an authorized person releases money to an account the attacker controls. Once you see that every one of these statistics describes the same underlying event, the right response stops depending on which number you find most alarming.

## Why a bigger number does not change the defense

The instinct when the numbers rise is to look for better detection, a tool that can spot the deepfake on the call or in the video. That instinct is understandable and, for the payment decision, misplaced. Detection of synthetic media is unreliable and structurally behind: the models that generate fakes improve faster than the models that detect them, so any detector is chasing last season's forgeries. Betting a wire on a system catching the fake in real time is a bet against the direction of the technology. This is exactly why the measured, projected, and single-case numbers can all keep climbing without changing what you should do.

The defense that does not depend on the size of the number is process, applied to the payment rather than the media. Verify any new or changed payee, and any urgent or unusual request, through a channel the attacker does not control, on a contact you already had. Hold the first payment to new details until that verification is complete. Record a named approval so the decision is attributable, and keep a verifiable record of it. That control works identically whether the true annual loss is $893 million or $40 billion, because it acts on the one step every version of the attack must pass through: the authorized release of the money. The [payee verification](https://rankshieldfinancial.com/resources/payee-verification/) discipline and the [buyer's guide](https://rankshieldfinancial.com/resources/wire-fraud-prevention-software/) to choosing a tool both come back to this same standard.

## Where RankShield Financial fits, and where it does not

Given all of that, here is the honest framing of what RankShield Financial does. It is a verification and attestation layer in the payment authorization path, not a deepfake detector, a bank, or a custodian of funds. It does not claim to tell you whether the voice on your call or the face on your screen is real, because that is the detection race no one reliably wins. What it does is verify the payee and a named approval and seal a checkable record before a payment settles, so that a convincing deepfake still cannot turn into a completed transfer without passing a verification the attacker cannot forge. It never touches the money, and it complements the controls you already run rather than replacing your bank or your accounting system.

The boundaries stay explicit, because a reader who has just been taught to distinguish a projection from a count will rightly hold a vendor to the same standard. RankShield verifies the payee and the approval and proves the decision; it does not vet your vendors for you, does not catch every scam, and is a design-partner-stage product that claims no network it has not built. Its value is precisely that it does not depend on winning the deepfake-detection arms race: it acts on the payment, which is the one place the outcome can still change. If you want that layer in front of your payments, you can [see how it works](https://rankshieldfinancial.com/how-it-works/) or [request access](https://rankshieldfinancial.com/contact/).

## The statistic to remember

If you keep one thing from the deepfake-fraud numbers, make it this: the useful statistic is not the biggest one, it is the shared one. Measured at $893 million, projected at $40 billion, or realized as a single $25 million loss, every version of the story ends with an authorized payment to a payee the business was deceived into trusting. That is the number the defense actually addresses. You cannot control how convincing the fakes become, and you should assume they will only get better; you can control whether a payment leaves for a new or changed payee that a person verified out of band and approved on the record. Build for that, and the trajectory of the deepfake statistics becomes something you can watch with concern rather than fear.
        Operate it
## Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.
      Pay to     Amount (USD)     Conditions around this payment      Bank details changed by email       First-time payee       Amount over approval policy       Approver signature verifies       PRE-SETTLEMENT VERDICT  RANKSHIELD NETWORK
Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call
        Downloadable · SVG
The headline deepfake-fraud figures are three different kinds of evidence: the FBI measured more than $893 million in AI-nexus losses in 2025, Deloitte projected US gen-AI fraud reaching $40 billion by 2027 (a model, not a count), and Arup lost $25 million in one confirmed deepfake-video case. None of them changes the defense, because the loss is still an authorized payment to a switched payee.
      FAQ
## Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →           Self-check
## How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

- 01 Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
- 02 Can one person both change a vendor’s bank details and approve the payment?
- 03 Do you always confirm a bank-detail change on a number from your own files, not the request?
- 04 Is the first payment to a new or changed payee held for verification before it goes out?
- 05 Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5
        References
- [FBI IC3, 2025 Internet Crime Report (more than $893M in AI-nexus losses; BEC $3.046B; 86% via wire or ACH)](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- [Deloitte Center for Financial Services, Generative AI and fraud in banking (US gen-AI fraud losses projected to reach $40B by 2027, from $12.3B in 2023; 32% CAGR)](https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html)
- [CFO Dive, Scammers siphon $25M from engineering firm Arup via AI deepfake CFO (15 transfers; confirmed by Arup CIO)](https://www.cfodive.com/news/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai/716501/)

         About the author
## [Jamie Kloncz](https://rankshieldfinancial.com/about/) Founder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

- Primary sources only: each figure links to the original filing
- Honest boundaries: what verification can and cannot do is stated plainly
- Last verified August 18, 2026

  How RankShield Financial verifies →  Request access →            Verify, then settle
## See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.
  Request access  How it works

## Frequently asked questions

### What are the most reliable deepfake fraud statistics?

The most reliable figure is a measured count of reported crime: the FBI recorded more than $893 million in losses across complaints with an AI nexus in 2025, on top of $3.046 billion in total business email compromise losses, with 86 percent of BEC money moving by wire or ACH. That is trustworthy precisely because it counts only losses reported to one agency in one year, which also makes it a floor rather than a ceiling, since most payment fraud is underreported. Larger figures you see quoted, such as Deloitte's $40 billion, are projections from a model rather than counts, and the two should not be treated as the same kind of number.

### Is the $40 billion deepfake fraud figure real?

It is a real and reasonable projection, but it is a projection, not a count. Deloitte's Center for Financial Services projects that generative AI could push US fraud losses to about $40 billion by 2027, from $12.3 billion in 2023, a compound annual growth rate near 32 percent, and it frames that across conservative, base, and aggressive scenarios. That makes it a useful statement about trajectory and planning, not a measurement of money already stolen. The disciplined way to use it is as a direction paired with the measured FBI figure as the current floor, and never to stack the two as if they were additive or to quote $40 billion as though it had already been lost.

### What happened in the Arup deepfake fraud case?

In early 2024, an employee in Arup's Hong Kong office made 15 transfers totaling about $25 million after joining a video call in which every other participant, including someone who appeared to be the company's chief financial officer, was an AI-generated deepfake. Arup's chief information officer confirmed the incident publicly and said no internal systems were breached, describing it as technology-enhanced social engineering rather than a network intrusion. The case proves the attack is real and can reach eight figures in a single incident. It does not prove the attack is yet common; one landmark case is evidence that it works, not a measure of how often it happens.

### Can software detect a deepfake on a live call?

Not reliably, and betting a payment on it is a mistake. Detection of synthetic audio and video is structurally behind the tools that generate it, because the generators improve faster than the detectors, so any detection model is effectively chasing older forgeries. For a payment decision, this means you should not assume a tool will flag the fake in real time. The defense that works does not depend on detecting the deepfake at all: it acts on the payment instead, verifying the payee and a named approval through a channel the attacker does not control, and holding the payment until that verification is complete. That control works the same whether or not anyone spots that the call was fake.

### Does the rising number change what a business should do?

No, and that is the practical point of reading the statistics honestly. Whether the true annual loss is the measured $893 million, the projected $40 billion, or a single $25 million case, every version describes the same underlying event: an authorized payment to a payee the business was deceived into trusting. The defense addresses that event directly, so it does not need to be re-chosen each time the headline number rises. Verify any new or changed payee and any urgent request out of band, hold the first payment until confirmed, record a named approver, and keep a verifiable record. A control that acts on the authorized release of money is durable against a threat whose statistics will keep climbing.
