July 30, 2026
Cybercriminals are using AI to make familiar scams more convincing than ever before. From deepfakes and executive impersonation to increasingly sophisticated social engineering attacks, organizations are facing new risks that extend beyond technology alone. This article explores how these tactics are evolving, what high-profile incidents reveal about the business impact and the practical steps leaders can take to help protect their people, processes and reputation in an AI-enabled world.
Every business decision starts with trust. Whether it’s approving a payment, responding to an email from a colleague, or joining a video call with your leadership team, organizations make hundreds of trust-based decisions every day. Most happen in seconds because we assume we know who’s on the other end, and that’s exactly what cybercriminals are counting on.
While generative AI is helping organizations improve productivity and automate routine work, it’s also giving attackers new ways to imitate trusted people, craft convincing identities, and manipulate everyday business interactions. The technology itself isn’t the biggest concern; it’s how easily trust can now be exploited.
During a recent demonstration, we created an AI-generated persona named Maya using publicly available tools and launched it onto a popular social media platform. Within minutes, she had a believable backstory, personal interests and realistic conversations. When asked who she was spending time with that evening, the AI invented a friend named Sarah, generated an image of the two of them together, and seamlessly wove that fabricated relationship into the conversation. There was nothing to suggest either person didn’t exist.
That ability to create convincing content in seconds is what makes today’s AI tools so powerful and, in the wrong hands, so concerning.
Deepfakes often attract the most attention because they’re highly visible. A familiar face joins a video meeting. A senior executive leaves a voicemail asking for an urgent wire transfer. A supplier emails updated banking information.
These scenarios may sound extraordinary, but they all rely on the same principle that has driven cybercrime for years – convincing someone to trust the wrong person.
Social engineering has always been about influencing people rather than defeating technology.
For decades, attackers have used phishing emails, fraudulent invoices, fake websites, and phone calls to convince employees to click malicious links, share confidential information, or authorize payments. Success has always depended on making those interactions appear legitimate.
Now, generative AI is making that process significantly easier. Instead of spending days or weeks researching a target, attackers can generate polished emails, clone voices, create realistic images, translate conversations into multiple languages, and personalize messages using publicly available information in a matter of minutes. Rather than targeting one individual at a time, they can launch convincing attacks against hundreds of people simultaneously while tailoring each interaction to their intended recipient.
The financial consequences are already being felt around the world. An employee of a Hong Kong-based firm made international headlines when they transferred approximately $25 million to cybercriminals after unknowingly participating in what appeared to be a legitimate video conference with colleagues, including the organization’s chief financial officer. Several participants on the call were AI-generated deepfakes. Believing the meeting was authentic, the employee approved the transfers before realizing they’d been deceived.
Closer to home, a Canadian University lost more than $11 million after attackers redirected payments through a sophisticated phishing scheme. While AI wasn’t part of that incident, it illustrates an important point – successful attacks don’t always begin by exploiting technical vulnerabilities. More often, they begin by exploiting trust.
These incidents may differ in scale and technique, but they share a common lesson. As cybercriminals gain access to more well-engineered tools, organizations can no longer rely on familiar voices, recognizable faces, or trusted email addresses as proof that a request is legitimate.
A successful cyberattack can result in millions of dollars in direct financial losses, but the impact doesn’t end there.
Business operations may be disrupted, customer confidence can be shaken, and employees may lose trust in the systems and processes they rely on every day. Regardless of size, organizations with a strong public profile can be impacted by reputational damage long after the technical issues have been resolved.
AI is also changing who can carry out these attacks. Creating convincing emails, cloned voices or stolen identities once required significant technical expertise. Today, many of these capabilities are inexpensive, publicly available, and very easy to use. As those tools become more prevalent, businesses are facing a broader range of threat actors with extremely sophisticated capabilities.
For executives and business leaders, it’s vital to understand that cyber security isn’t solely an IT issue. It influences financial controls, operational resilience, governance and the confidence customers, employees, and business partners place in your organization.
Every organization should have strong cyber security fundamentals in place, including governance, monitoring, endpoint protection, and incident response planning. But sometimes the best defence is learning to follow your gut.
We’ve seen that firsthand. During a client engagement, we conducted a phishing assessment to evaluate how employees responded to suspicious requests. One employee received what appeared to be a legitimate message from a senior executive. Although the request looked authentic, something didn’t feel right and the employee questioned it, raised their concerns internally, and ultimately escalated the concern to the appropriate authorities.
Rather than viewing that response as extreme, we saw it as a success. That’s the kind of thinking organizations should encourage. When something feels unusual, employees should feel confident slowing down, asking questions, and verifying the request before taking action.
As AI-enabled attacks continue to transform, organizations can revisit the habits and controls that help reduce risk, such as:
None of these practices are new, but they’re becoming critical as AI enables attackers to produce more convincing cyber scams with very little effort.
Organizations shouldn’t respond to these cyber threats by becoming suspicious of every interaction. Business depends on trust, and technology will continue to create new opportunities to work more efficiently and collaborate in different ways.
Whether you’re approving a payment, responding to an urgent request from a senior leader, or sharing sensitive business information, taking a moment to verify the request through an independent channel can prevent a costly mistake.
The Canadian Centre for Cyber Security encourages organizations to think about AI from multiple perspectives: protecting against malicious uses of AI, securing AI systems themselves, and protecting the people and business processes that interact with them.
That broad approach recognizes an important reality: As AI becomes more integrated into everyday operations, cyber security can’t focus solely on technology. It also needs to address how people make decisions, how information is verified, and how trust is established throughout an organization.
Deepfakes and executive impersonation may dominate headlines right now, but they’re only one example of how cyber threats are ever-changing. The good news is that the qualities that make organizations resilient, including informed employees, well-designed processes, and strong governance, remain just as effective today as they’ve always been.
MNP’s Cyber Security Leader, Eugene oversees research and development activities and formulates long-term vision and strategies at the executive management level to help the firm better serve clients. He provides a full range of cyber security services and solutions to medium-sized and large enterprises, delivering strong advice to help clients make business decisions relating to technology.
Drew is MNP’s National Cyber Security Assessment Lead, Digital Services. Based in Edmonton, he leads the Cyber Security practice for Alberta. With close to two decades of experience, Drew helps organizations with critical IT systems or sensitive information that are looking to build or enhance their cyber security programs.
Our team of dedicated professionals can help you determine which options are best for you and how adopting these kinds of solutions could transform the way your organization works. For more information, and for extra support along the way, contact our team.