In recent months, the use of deepfakes—videos and audio falsified byartificial intelligence—has become a serious threat to the corporate environment, including in Brazil. In a landmark case in 2024, an employee made a multimillion-dollar transfer after taking part in a video conference in which every other participant was a realistic AI-generated recreation. The episode marked a new era in cyber scams, increasing the alert among corporate security teams to sophisticated fraud that can now occur through email, text messages, phone calls, or virtual meetings.
The Escalation of Deepfake Scams
The reproduction of voices and simulation of senior executives are keeping digital security departments constantly alert. These attacks, known as deepfakes, are already circulating in the corporate world and are reaching ever higher levels of sophistication.
With this technology, criminals assume the identities of senior leaders and deceive employees with access to sensitive data. According to Adaptive Security, deepfake attacks grew 822% in Brazil and are five times more common here than in the United States, which recorded more than 105,000 cases. The figure shows how traditional defenses are rapidly being outpaced.
Experts emphasize the speed of this escalation. One year ago, only one in ten security executives said they had witnessed this type of attack. Today, that proportion has already reached five in ten. The combination of convincing voices and faces gives scammers the confidence to request seemingly legitimate actions, such as sending credentials or authorizing transfers, making the fraud increasingly difficult to identify.
Attack Models and Prevention
One of the most striking cases occurred in the United Kingdom, when engineering company Arup transferred US$25 million after a fraudulent virtual meeting with AI-created “executives.” The scam followed a common pattern: a supposed CEO or director contacts an employee with privileged access, usually with a sense of urgency. A video conference is then arranged in which the impostor uses a deepfake to give instructions that lead to the loss of data or money.
To reduce the risk, experts recommend strict verification protocols and caution when handling urgent requests through digital channels. Ideally, the request should be confirmed directly with the sender through official means, never using the same channel as the initial approach. It is also essential to avoid suspicious links and attachments, protect personal data on social media, and keep software updated—measures that help prevent losses caused by deepfakes.