How criminals use AI
Generative AI has lowered the cost and raised the quality of fraud. Tasks that once needed skill, time or a team can now be done quickly by one person. Law enforcement and financial regulators have warned about several uses:
- Voice cloning: a short recording of someone's voice, for example from a video posted online, can be enough to produce a convincing imitation. Criminals use cloned voices to pose as relatives in distress, or as executives authorising urgent payments.
- Deepfake video: realistic fake video of a real person, used in video calls, in fake endorsements for investment scams, or to defeat remote identity checks.
- Generated documents and images: fake identity documents, bank statements, payslips and invoices produced with image-generation and editing tools.
- Synthetic identities: invented people, built from a mix of real and fake details and supported by generated photos and documents, used to open accounts and take out loans.
- Scam messages at scale: well-written, personalised phishing and scam messages in any language, without the spelling mistakes people were once taught to look for.
One widely reported case shows the scale of the risk. In early 2024, a finance employee in the Hong Kong office of a multinational engineering firm joined a video call with what looked like the company's chief financial officer and other colleagues. All of them were deepfakes. The employee then made 15 transfers totalling about HK$200 million (roughly US$25.6 million).
Africa is not spared. INTERPOL's African Cyberthreat Assessment Report 2026, based on survey data from 36 African countries, found that AI was enabling 55 per cent of reported cybercrimes across Africa, and described East Africa as a hub of mobile money fraud. It also reported that AI-generated synthetic identities have been used to open bank accounts, take mobile loans and register SIM cards under false names.
None of these techniques is entirely new. What AI changes is cost, speed and realism: more attacks, more convincing, reaching more people.
How defenders use AI
AI is also a powerful tool against fraud. Organisations use it to:
- Score transactions and events in real time, weighing many signals at once to estimate the risk of fraud.
- Detect anomalies: activity that departs from a customer's normal behaviour or from the behaviour of similar customers.
- Find networks: analyse links between accounts, devices, phone numbers and payments to uncover mule rings and organised fraud that look innocent one account at a time.
- Check identity evidence: detect signs of forged or generated documents during remote identity checks, and spot presentation attacks (holding a photo, mask or screen up to the camera) and injection attacks (feeding fake video straight into the app so it never passes through the camera).
- Analyse behaviour: behavioural signals can help show when the way someone uses an app suggests a fraudster, or a genuine customer who may be being coached by a scammer on the phone.
- Support investigators: language models can help summarise cases, draft reports and search records. But they can produce confident errors, so a person must check every output. Customer data should only be used with tools the organisation has approved for it.
AI works best alongside rules and people: rules for known patterns and hard limits, models for subtle risks, and trained people for uncertain cases and decisions that affect customers significantly.
Detecting deepfakes and synthetic content
Detecting AI-generated content is an arms race. Detection tools can spot artefacts left by generators, such as inconsistencies in lighting, skin texture, lip movement, audio frequencies or file metadata. But generators improve quickly, and a detector that works today may fail tomorrow. Detection is a useful layer, not a guarantee.
More robust defences do not depend on spotting the fake at all:
- Verify the request, not the voice or face. If a call or video asks for money, a change of bank details or secret information, confirm it through a separate channel you already trust, such as calling back on a known number.
- Check the process, not the person. Payments above a limit, or changes to supplier details, should require a second approver and a documented check, whoever appears to be asking.
- Liveness and integrity checks in remote identity verification. A liveness check tests that a real, live person is in front of the camera, not a photo or replayed video. Integrity checks look at the device and the video stream, not only the face.
- Consistency across sources: does the document, the data in official registers and the applicant's history fit together?
- Provenance: some cameras, platforms and editing tools can attach cryptographically signed information about how content was created and edited, following open standards such as the C2PA specification (known as Content Credentials). Where present and valid, this helps confirm that genuine content is genuine. Its absence proves nothing, because many tools do not add it and it can be removed, so it cannot be used to prove that something is fake.
Train staff with realistic examples. The goal is not for everyone to become a deepfake expert, but for everyone to know that a convincing voice or face is no longer proof of who someone is.
The limits and risks of AI in fraud decisions
AI fraud tools make mistakes, and their mistakes affect real people.
- False positives: genuine customers blocked, accounts frozen or applications rejected. At scale, even a small error rate harms many people.
- Bias: a model trained on past data can treat some groups of customers unfairly, for example by associating a neighbourhood, device type or name pattern with fraud.
- Explainability: it can be hard to explain why a complex model flagged a customer, yet customers, auditors and regulators may ask.
- Adaptation: fraudsters study defences and change tactics; a model trained on last year's fraud may miss this year's.
- Attacks on the model: criminals may probe a system with small transactions to learn its limits, or try to shape the data it learns from, for example by making fraudulent accounts behave normally for a while before striking.
Responsible use calls for:
- Human review of decisions that significantly affect people. Section 35 of Kenya's Data Protection Act, 2019 gives people a right not to be subject to a decision based solely on automated processing, including profiling, that has legal effects on them or significantly affects them. There are limited exceptions: where the decision is necessary for a contract, authorised by a law with safeguards, or based on the person's consent. Where such a decision is made, the organisation must tell the person in writing. The person can then ask for the decision to be reconsidered, or for a new decision not based solely on automated processing.
- Testing for fairness across customer groups, not only overall accuracy.
- Clear routes to challenge a decision, and quick correction when the model is wrong.
- Documentation and monitoring of each model: what it does, the data it uses, how it performs and how that changes over time.
Practical controls against AI-enabled scams
Most defences against AI-enabled fraud are not high-tech. They are good processes that do not trust appearances.
For organisations - Call-back verification on known numbers for any request to pay, change bank details or share sensitive data. - Two-person approval for payments above a limit and for changes to supplier or customer payment details. - No exceptions for seniority or urgency. Fraudsters impersonate the most senior people and invent emergencies precisely to skip controls. - Code words or pre-agreed questions for high-risk requests between executives and finance teams. - Layered identity checks in onboarding: documents, liveness, device checks and authoritative data, not a single selfie. - Staff training with real examples, and a culture where questioning an unusual request from a senior person is praised, not punished.
For individuals - Be suspicious of urgent requests for money, even from a familiar voice or face. Hang up and call back on a number you know. - Agree a family code word for emergencies. - Never share PINs, passwords or one-time codes with anyone, including someone who says they are from your bank, mobile money provider or employer. - If you have sent money to a scammer, contact your bank or mobile money provider immediately on its official number; fast reporting gives the best chance of stopping or recovering the funds. Then report to the police or the Directorate of Criminal Investigations. - Limit how much of your voice and video you share publicly where it is not needed.
AI makes fraud more convincing, but the fundamentals still hold: verify independently, slow down, and require more than one person for anything irreversible.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004) · US Financial Crimes Enforcement Network
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (Public Service Announcement I-120324-PSA, 3 December 2024) · US Federal Bureau of Investigation, Internet Crime Complaint Center
- C2PA specifications (Content Credentials) · Coalition for Content Provenance and Authenticity
- Scammers use AI to enhance their family emergency schemes (2023) · US Federal Trade Commission
- INTERPOL report finds AI linked to more than half of cybercrime in Africa (2026) · INTERPOL
- Finance worker pays out $25 million after video call with deepfake 'chief financial officer' (2024) · CNN
- Data Protection Act, 2019 (No. 24 of 2019) · Kenya Law