The Rising Threat: Protecting SMEs Against Deepfake Fraud

4 min read
Share article

Summary

Your CEO’s voice can be cloned in seconds. In 2024 alone, 56% of Singapore businesses faced deepfake fraud, with one company losing $4.9M from a single fake Zoom call. Since trust is no longer enough and urgency is the trap, discover the three verification habits that protect your business from AI imposters.

Scammers have always found ways to exploit trust. What has changed is how convincingly they can now manufacture it.

Deepfakes are synthethic media, which may include realistic images, audio clips, and videos generated using artificial intelligence, that leverage machine learning to create manipulated media of individuals. Depending on the amount of data used, many deepfakes result in highly convincing impersonations of the individual, making people seem to say or do things they never actually said or did. 

This risk can no longer be considered a distant concern. Business in Singapore are increasingly exposed to deepfake fraud, and the numbers reflect how quickly this threat has grown. In 2024, 56% of businesses in Singapore reported encountering audio deepfake fraud, and 52% faced incidents involving video deepfakes. Both figures sit well above the global average.

Running a business often requires decisions to be made urgently under the pressure of time, which deepfakes are designed to exploit and target.

How the scam typically unfolds

In one high-profile case, a victim lost at least $4.9 million after scammers used a combination of deepfake technology, phishing emails, and WhatsApp messages to draw business professionals into a Zoom call. On that call, fraudsters impersonated senior Singapore government officials in real time, creating enough perceived authority to prompt an urgent fund transfer.

The playbook tends to follow a pattern. First, scammers build a convincing likeness, a realistic audio or video clip of a CEO, a government official, or a known business partner. They use this to manipulate a target into disclosing sensitive information, such as an email address or a copy of an identity document. Once they have what they need, they move to extraction: a transfer of funds to an account you cannot trace back.

What makes deepfakes particularly dangerous is that they do not rely on obvious red flags. The voice sounds right. The face looks right. The urgency feels real.

Three things your business can do now

Defending against deepfake fraud does not necessarily require sophisticated technology. The risk may also be partly mitigated by cultivating a certain set of structured habits, as well as ensuring that teams within your organisation know what to look out for.

1. Verification

For high-urgency demands, particularly those involving a senior figure requesting funds or sensitive data, treat every unexpected request with a zero-trust approach. Any such request must be confirmed through a pre-established, off-channel method such as calling a known phone number or verifying the request face-to-face. If the request cannot be independently verified, it should not be acted upon until verification has been completed.

2. Training and Awareness

Conduct regular cybersecurity training focused on the realities of AI-driven fraud so employees understand what they are up against. Train them to spot common deepfake indicators such as unnatural blinking, robotic audio tones, or lip-sync lag. The Cyber Security Agency of Singapore publishes regular advisories on detection techniques, and ingraining the techniques shared by the CSA with your team’s practices is beneficial to your organisation.

3. Singapore’s National Resources

Encourage management and staff to actively use the ScamShield ecosystem to secure both their corporate and personal devices. The ScamShield app allows employees to report suspicious calls, links, emails, and messages that they received via SMS, WhatsApp, and Telegram. These reports feed into a shared intelligence network that helps authorities identify and block fraudulent numbers across the wider ecosystem. The app also analyses incoming SMS messages directly on-device to protect user privacy, automatically filtering suspicious content into a Junk folder while ensuring legitimate business communications remain unhindered. For immediate verification, the ScamShield Helpline at 1799 is available around the clock to help verify potential scams in real time. 

What This Means for You

Deepfake technology is advancing faster than most organisations realise. Businesses that remain protected are not necessarily those with the most sophisticated systems. They are the ones with a clear verification step before any payment moves, where staff and owners alike feel empowered to pause and question, and where urgency is treated as a reason to slow down, not speed up. 

The statistics of the 2024 suggest that more than half of business in Singapore have already encountered some form of deepfake fraud. Now, this percentage may have already increased. The tactics are sophisticated, the impersonations are convincing, and the sense of urgency created appears genuine. Staying protected goes beyond just being vigilant—it requires proactive systems. You need the right habits and processes in place before you’re ever targeted.

Legitimate business partners and authorities should not ask you to bypass established verification or approval processes. If someone does, treat it as a warning sign and independently verify the request before taking any action.

Share article

More reads