Skip to content
Vigil

Deepfakes, 2025 to 2026

The fake you were trained to spot is gone.

Most awareness training still teaches people to catch a robotic voice or a glitchy face. The research published since the start of 2025 says those are no longer the fakes that matter, and that what now stops deepfake fraud is a rehearsed step, not a sharper eye.

61 to 66%

of the time, listeners correctly identified voice clones from current commercial systems, in a study of 1,768 people. Guessing scores 50%.1

€95M

was sent in eleven transfers at an Italian private bank in February 2026, after a fake chief executive on WhatsApp and a cloned voice of a trusted lawyer.10,11

54%

of people clicked fully AI-written spear phishing, exactly the same rate as messages written by human experts.22

In February 2026, the chairman of Fideuram, the private bank of Italy's Intesa Sanpaolo group, received a WhatsApp message from what appeared to be the group's chief executive. It described an urgent, highly confidential acquisition. Then came a phone call from the managing partner of a law firm he knew, confirming the instruction. The partner's voice had been cloned. Eleven transfers followed, totalling about €95 million. When Milano Finanza reported the case in September, about €36 million was still missing, after being converted to cryptocurrency.10,11

Look closely at what the cloned voice was for. It did not open the attack. A text message did that. The voice arrived at the exact moment a careful person would want reassurance, and it supplied it. The deepfake was not the lure. It was the check.

That is the shift this piece is about. The security awareness most organisations run today was designed for an earlier generation of fakes: emails with odd spelling, voices that sounded slightly robotic, video that stuttered. The research published since January 2025 shows those tells have largely gone, that neither people nor detection software can reliably close the gap, and that the losses which are falling are falling because of procedure, not perception.

Then and nowThe tells we trained people to notice have disappeared

The clearest evidence comes from two listening studies published in 2026.

The largest study yet. Müller and Choong collected 35,532 judgements from 1,768 people across 138 speech synthesis systems.1Clips from older system designs were identified correctly about 75% to 77% of the time. Clips from current commercial and language-model-based systems were identified only 61% to 66% of the time, not far above guessing. Compared with a 2021 baseline, people were no better at catching fakes (72.9% then, 71.2% now). What changed was their trust in real voices: accuracy on genuine recordings fell from 72.7% to 64.1%. The authors conclude that the main threat "may not be mere deception, but the erosion of trust in genuine audio".

Even IT professionals. Šalko and colleagues tested 82 IT professionals, a group that should do better than the public.2Against older open-source synthesisers, their F1 score (a combined measure of catching fakes and not flagging real speech) was about 90%. Against ElevenLabs, a widely available commercial tool, it fell to 48%. When a single synthetic sentence was spliced into otherwise real speech, strict accuracy fell to 9%, and the fake sentence was judged genuine 77% of the time. Their conclusion: "human perception alone is unreliable" for modern and partial-spoof conditions.

Figure 1

Older voice fakes were catchable. Current ones are not.

82 IT professionals listening for synthetic speech. F1 score combines catching fakes and not flagging real speech; 100% is perfect.

0%25%50%75%100%RTVC (older, open source)about 90%YourTTS (older, open source)about 90%ElevenLabs (current, commercial)48%One fake sentence spliced instrict accuracy9%

Source: Šalko, Firc, Malinka et al., "Tracking the Trend in How Speech Synthesizers Deceive People", arXiv, August 2026.2 The bottom bar is a different measure (strict accuracy), shown on the same 0 to 100% scale.

Figure 2

People are no worse at catching fakes. They are worse at trusting real voices.

Share of clips judged correctly, 1,768 listeners. The axis starts at 50%, which is what guessing would score.

By type of system

50%60%70%80%75 to 77%Older designs61 to 66%Current commercial

Each block spans the reported range for that family of systems.

2021 baseline against now

50%60%70%80%2021 baseline2026 study71.2%fakes64.1%real voicesabout 73%

Both lines began at about 73% (72.9% and 72.7%).

Source: Müller and Choong, "Eroding Trust in Real Speech: A Large-Scale Study of Human Audio Deepfake Perception", arXiv, May 2026; 35,532 judgements across 138 systems.1

The tools that make these voices are now ordinary. In a peer-reviewed study published in PLOS One in September 2025, clones made with a consumer product from about four minutes of recordings were judged human 58% of the time; real voices in the same experiment were judged human only 62% of the time.3When Consumer Reports tested six voice-cloning products in March 2025, four required only that the user "check a box" confirming they had the right to clone the voice.4

Can training close the gap? Not reliably. A 2025 systematic review of 40 studies found interventions to improve deepfake detection "yielded mixed results".5In one of the better results, five minutes of training raised typical people's accuracy at spotting AI-generated faces from 31% to 51%, still close to a coin flip, and that was for still images rather than live video.6

For your programmeRetire any training that teaches people to listen for a robotic voice or watch for a glitch. The current evidence says those cues are unreliable, and teaching them gives false confidence.

The machinesDetection software cannot carry the decision either

If people cannot hear the difference, perhaps software can. In the lab, it often does: the detector baseline in the Müller and Choong study scored above 94.5% on that study's own clips.1 In the wild, the picture is very different.

Deepfake-Eval-2024, a benchmark built from deepfakes actually circulating online in 2024 (45 hours of video, 56.5 hours of audio and 1,975 images from 88 websites in 52 languages), found that the performance of leading open-source detectors "drops precipitously" on real-world material.7Commercial models did better, but "do not yet reach the accuracy of deepfake forensic analysts". A March 2026 study of 200 people against 95 detectors found that on everyday phone-recorded video, the detectors' accuracy "collapses to near chance (0.537) while humans maintain robust performance (0.784)", but that people missed the high-quality fakes.8A third team found that every detector they tested struggled with real political deepfakes and was "vulnerable to simple manipulations".9

Detectors built for live calls are an active research area; one 2025 system that tracks where a speaker is looking reached 82% accuracy on its authors' own test set.34 That is promising, and not yet a field result.

Figure 3

Detectors lose about half their accuracy on real-world fakes

Fall in AUC, a standard accuracy measure, for leading open-source detectors when tested on deepfakes collected from the internet instead of earlier academic benchmarks.

0%25%50%75%100%Video detectors50% lowerAudio detectors48% lowerImage detectors45% lower

Source: Chandra et al., "Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024", arXiv, March 2025 (revised May 2026).7 Open-source models; commercial and fine-tuned models performed better.

For your programmeTreat detection tools as one useful layer. Never let a payment decision rest on whether a voice or face "passed" a check.

The attacksWhat a 2026 deepfake attack actually looks like

The incidents reported since January 2025 share a shape that earlier cases did not. The deepfake rarely works alone. It is one step in a sequence across several channels, and its job is usually to confirm a story that started somewhere else.

Figure 4

Three reported attacks, one pattern

Each attack moved across channels. The deepfake (gold) supplied the reassurance a careful person would look for.

Singapore, March 2025Multinational, finance directorWhatsApp, fake CFODeepfake ZoomCall, fake lawyerUS$499k sentstopped, funds recoveredSingapore, May 2026Business professionalWhatsAppDeepfake Zoom: the Prime Minister and officialsAt least S$4.9M lostItaly, February 2026Private bank, chairmanWhatsApp, fake CEOCloned voice of a known lawyer, on a callAbout €95M, 11 transfersabout €36M still missingOpens the storySupplies the reassuranceThe money moves

Sources: Singapore Police Force, 7 April 2025;12 Mothership and The Star, 14 May 2026, citing police;13 Milano Finanza, 25 September 2026, and TechRadar, 29 September 2026.10,11

Other reported cases follow the same logic. In July 2026, Indian software company Capillary Technologies told the stock exchange that a recently acquired subsidiary had lost about €3 million to "advanced deepfake methods including cloning, signature forging, social engineering to impersonate the company's senior management". 14Throughout 2025, the FBI warned twice that senior US officials were being impersonated with AI-generated voice messages that "closely match the cadence, tone, and accent of real officials", followed by a request to move to an encrypted messaging app.15,16The voices of Italy's defence minister and the US Secretary of State were both imitated in 2025.17,18And in July 2026, eleven governments warned that North Korean IT workers applying for remote jobs present "video feeds that appear to be manipulated or artificially generated".19

Inside organisations, this is no longer rare. In a Gartner survey of 302 security leaders published in September 2025, 62% said their organisation had faced a deepfake attack in the previous twelve months, 44% on an audio call and 36% on a video call.20

Regional data points the same way. Singapore's police recorded 3,363 cases of government-official impersonation in 2025, with losses of S$242.9 million, and noted that impersonation of senior executives sometimes uses "digital manipulation techniques ... including via Zoom meetings". 30And in the World Economic Forum's 2026 survey of 804 leaders, chief executives ranked cyber-enabled fraud as their top concern, ahead of ransomware.32

Singapore, March 2025US$499,000 traced and recovered

A finance director joined a Zoom call where the chief executive and other executives were deepfakes, then took a call from a fake lawyer and sent US$499,000.12

What saved the company was not spotting the fake. It was a second, larger request, for US$1.4 million, that did not sit right. The director alerted the company's bank, and police in Singapore and Hong Kong traced and withheld the money. The check that worked was a channel the attacker did not control.

For your programmeTeach the pattern, not the pixel: a message app opens the story, a familiar face or voice confirms it, and the request is urgent and confidential. That combination is the cue.

The numbersWhat the official figures can see, and what they cannot

Here the honest picture is more interesting than the headlines. The FBI's 2025 Internet Crime Report is the first to count complaints that mention AI: 22,364 of them, with losses above $893 million.21 Yet of $3.05 billion lost to business email compromise in 2025, only about $30 million came from cases where the victim reported AI involvement. That is about 1%.

Two things are true at once. First, these figures depend on victims realising AI was involved; the FBI itself says "many victims do not realize the extent AI may be involved in scams", and it warned in December 2025 that "AI-generated content has advanced to the point that it is often difficult to identify".16,21 The counted share is a floor, not a measure. Second, no reliable dataset yet shows deepfakes driving a measured surge in business payment losses. Anyone who tells you otherwise with a precise percentage is guessing.

Figure 5

Losses the FBI could tie to AI in 2025, as a share of each category

Gold shows losses in complaints where victims reported AI involvement. Each bar is the whole category.

All reported cybercrime$20.877B4%Investment fraud$8.65B7%Business email compromise$3.05B1%Shares calculated by Vigil from the report's figures: $893M, $632M and $30.3M.

Source: FBI IC3 Internet Crime Report 2025, published April 2026.21"AI-related" means the complaint referenced AI; 2025 is the first year this was captured.

The economicsAI makes attacks cheaper, not cleverer

The most rigorous work on AI-written attacks points to the same conclusion. In a peer-reviewed study published in June 2026, spear phishing written entirely by an AI model drew a 54% click rate, identical to emails written by human experts and far above the 12% control.22AI did not out-persuade the experts. It matched them, at what the authors estimate is up to 50 times the profitability for large campaigns. A companion study of AI voice phishing with 4,100 participants found that the main risk lies in "the economics of automation rather than novel or 'superhuman' persuasive techniques". 23

Figure 6

AI-written spear phishing performs like a human expert

Share of participants who clicked, by who wrote the message. 101 participants.

0%25%50%75%100%Control email12%Written by human experts54%Fully written by AI54%AI with a human in the loop56%

Source: Heiding, Lermen, Kao, Verdun, Schneier, Vishwanath, "Evaluating Large Language Models' Ability to Automate Spear Phishing", Expert Systems with Applications, June 2026.22 A small, single study; read it as a signal, not a benchmark.

Official forecasts agree. The UK's National Cyber Security Centre expects AI to raise "the volume and impact of cyber intrusions through evolution and enhancement of existing TTPs, rather than creating novel threat vectors", and judges fully automated end-to-end attacks "unlikely to 2027". 24Europol's 2026 assessment warns that criminal use of agentic AI "is set to raise the threat from OFS [online fraud schemes] to unprecedented levels", while describing it today as "a developing driver for crime". 25Verizon's 2026 report adds a useful check: in its incident data, the share of breaches starting with phishing "has barely moved", though it notes it cannot measure fraud against individuals.26

The deepfake is rarely the lure. It is the reassurance, and it arrives at exactly the moment a careful person checks.
Vigil Security

What worksWhere losses are falling, procedure is doing the work

There is good news in the 2025 data, and it points in one direction. UK Finance reported that CEO fraud fell 53% in 2025 to £5.6 million, its lowest case count ever, and that invoice and mandate fraud fell to its lowest loss total on record.27UK Finance credits "continued industry investment in fraud prevention and customer education and awareness", and notes that checks such as confirmation of payee may help catch these payments earlier. This happened while cloning tools spread. It is correlation, not proof, but it is the strongest real-world signal we have, and it is a signal about process.

The FBI's data tells the same story about speed. Through its Financial Fraud Kill Chain in 2025, quick reporting froze $679 million of $1.16 billion in attempted theft, 58%.21And the most specific official guidance anywhere, published by the Monetary Authority of Singapore in September 2025, is almost entirely procedural: verify through "a separate and trusted communication channel", use "code words" for high-risk requests, enforce dual control so no single person can move money "the minute he or she falls prey to a deepfake impersonation attack", and "conduct regular video and voice deepfake simulation exercises on employees".28

Figure 7

UK CEO and invoice fraud fell sharply in 2025

Losses reported by UK Finance members, £ millions. Separate scales; both series start at zero.

CEO fraud

£0£7.5M£15M202020212022202320242025£13.4M£5.6M

Down 53% in 2025; lowest number of cases ever reported, though 2020 losses were lower.

Invoice and mandate fraud

£0£40M£80M202020212022202320242025£68.8M£41.3M

Lowest loss total ever reported; 68% fell on business accounts.

Source: UK Finance, Annual Fraud Report 2026 (2025 data), June 2026.27 UK bank-reported authorised push payment fraud only; total authorised fraud still rose 19%, driven by investment, purchase and romance scams.

For your programmePut your effort where the falling numbers are: a callback on a number you already hold, a second approver, a code word for high-risk requests, and a habit of reporting fast.

2026 to 2028What the evidence supports about the next two years

Forecasting is where most writing on deepfakes goes wrong, so we have kept to claims the 2025 and 2026 evidence can carry.

1

Spotting fakes will get harder, not easier

Listener accuracy on current commercial voices already sits near 61% to 66%, and trust in real voices is falling.1,2 Any control that depends on someone recognising a fake will fail more often.

2

More attempts, against more people

AI matches human experts at a fraction of the cost.22,23 Expect more, cheaper, better-localised impersonation aimed at finance, HR and helpdesk staff, not only executives. The NCSC and Europol both describe the change as scale and speed.24,25

3

Fully automated fraud is coming, but it is not here yet

Europol calls agentic AI "a developing driver"; the NCSC judges fully automated end-to-end attacks "unlikely to 2027".24,25 Plan for it, but do not let it distract from the human-run attacks working today.

4

Businesses will carry the loss

New protections mostly cover consumers. The UK's reimbursement scheme applies to personal, micro-enterprise and charity accounts up to £85,000, and returned 88% of claimed losses in its first year.29The EU AI Act's deepfake labelling duties, in force since 2 August 2026, bind legitimate providers and deployers, not fraudsters.33 A mid-sized or large firm that authorises a deepfake-induced payment will generally bear it.

Figures circulating that we could not verify

  • "Three seconds of audio is enough." The peer-reviewed and penetration-testing work we found used about four to five minutes of audio for convincing clones.3,35 Short-sample claims come mainly from vendor material and have not been tested in field studies.
  • Large percentage rises in "deepfake BEC" attributed to the FBI. The FBI's 2025 report contains no such figure; it ties about $30 million of business email compromise losses to AI.21
  • "Detectors are 95% accurate." True in some laboratories, not on real-world material.7,8
  • "Deepfake CEO fraud is exploding." UK CEO fraud fell 53% in 2025, to its lowest number of cases on record.27 The threat is real and growing in capability; the measured losses do not yet show a surge.

The modelFive shifts for a programme built for 2026

1
From"Spot the fake"
To"Verify regardless": a rule that holds even when the voice is perfectListener accuracy near 61% to 66% on current clones
2
FromEmail-only testing
ToRehearsal across the chain: message app, voice, live video, then the "trusted" confirmerSingapore 2025 and 2026; Fideuram 2026
3
FromIndividual judgement
ToDesigned controls: callback on a held number, dual control, code wordsMAS, September 2025
4
FromAnnual awareness modules
ToRegular, realistic deepfake simulation of the people your staff trustMAS suggests "regular video and voice deepfake simulation exercises"
5
FromCounting completions
ToMeasuring what people did: who called back, who escalated, how fastQuick reporting froze 58% of attempted theft

The authoritiesWhat regulators and law enforcement now say

MASInformation Paper on deepfakes, Sep 2025 · Singapore
verifying the authenticity of caller through a separate and trusted communication channelSource 28
MASInformation Paper on deepfakes, Sep 2025 · Singapore
FIs could conduct regular video and voice deepfake simulation exercises on employeesSource 28
FBIPublic service announcement, 19 Dec 2025 · United States
AI-generated content has advanced to the point that it is often difficult to identifySource 16
NCSCImpact of AI on cyber threat to 2027, May 2025 · United Kingdom
evolution and enhancement of existing TTPs, rather than creating novel threat vectorsSource 24
EuropolIOCTA, April 2026 · European Union
social engineering and human error will remain the weakest links for fraudsters to exploitSource 25
ASDAnnual Cyber Threat Report 2024-25 · Australia
Cybercriminals also use GenAI to create high-quality videos, fake voices, websitesSource 31

For the boardFive questions to ask this quarter

MeasureWhat it tells you
Does any payment depend on someone recognising a voice or face?Current clones are identified correctly only 61% to 66% of the time, and detectors fail on real-world material.
Is there a callback rule that holds even for the chief executive?The 2025 and 2026 cases used executives and trusted advisers as the confirming voice.
Can one person move a large sum alone?MAS asks for dual control precisely so one deceived person cannot move money.
Have our people rehearsed a deepfake call, not just read about one?Training to spot fakes shows mixed results; MAS encourages regular simulation.
How fast would we report a suspicious transfer?Fast reporting froze 58% of attempted theft in the FBI's 2025 data.

Where Vigil fitsRehearse the moment the fake supplies the reassurance

We built Vigil for regulated firms that need their people to follow the verification rule when the voice on the line sounds exactly right, and to prove they did.

Shift 2 and 4

Rehearse the whole chain

Simulations by email, SMS, QR code, phone call and video, including calls in a cloned executive's voice and deepfake video, used only after you record that executive's consent.

Shift 1

Teach the rule, not the glitch

Short, story-driven training films that show the pattern of a real attack and the step that defeats it, instead of tips for spotting artefacts.

Shift 5

Measure what people did

A dated record for every person of what they were tested on and what they did, and a risk score for each employee with trends across the organisation.

For your regulator

Evidence for your auditors

A one-click compliance report for auditors and cyber insurers, which shows "Not available" rather than a false zero, and a tamper-evident audit trail.

A note on evidence: the research above shows why "spot the fake" is failing and why rehearsed procedure is where losses are falling. It does not test any vendor's product, including ours. We would rather show you than claim it.

Book a 30-minute programme reviewWe read your current programme against your regulator's own words and send you a one-page list of gaps, whether or not you work with us.

Sources

Sources published between January 2025 and October 2026, opened on 2 October 2026. Figures are quoted as published. Secondary reporting and vendor material are marked.

  1. Müller, Choong. Eroding Trust in Real Speech: A Large-Scale Study of Human Audio Deepfake Perception. arXiv, May 2026. arxiv.org/abs/2605.26136
  2. Šalko, Firc, Malinka et al. Tracking the Trend in How Speech Synthesizers Deceive People. arXiv, August 2026. arxiv.org/abs/2608.19959
  3. Lavan, Irvine, Rosi, McGettigan. Voice clones sound realistic but not (yet) hyperrealistic. PLOS One, September 2025. journals.plos.org
  4. Consumer Reports. AI Voice Cloning assessment, March 2025. consumerreports.org
  5. Somoray, Miller, Holmes. Human Performance in Deepfake Detection: A Systematic Review. Human Behavior and Emerging Technologies, 2025. onlinelibrary.wiley.com
  6. University of Reading. Five minutes of training could help you spot fake AI faces (study in Royal Society Open Science), November 2025. reading.ac.uk
  7. Chandra et al. Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024. arXiv, March 2025, revised May 2026. arxiv.org/abs/2503.02857
  8. Postiglione, Gortner, Subrahmanian. Human and AI deepfake detection ensembles. arXiv, March 2026. arxiv.org/abs/2603.14658
  9. Lin et al. Fit for Purpose? Deepfake Detection in the Real World. arXiv, October 2025. arxiv.org/abs/2510.16556
  10. Milano Finanza, 25 September 2026, Fideuram case (secondary, in Italian). milanofinanza.it
  11. TechRadar, 29 September 2026, syndicated (secondary). finance.yahoo.com
  12. Singapore Police Force. Singapore and Hong Kong police recover over $670,000 in a scam, 7 April 2025. police.gov.sg
  13. Mothership, May 2026, citing Singapore Police Force (secondary). mothership.sg; The Star, 14 May 2026. thestar.com.my
  14. Inc42, July 2026, Capillary Technologies stock exchange disclosure (secondary). inc42.com
  15. FBI. I-051525-PSA, Senior US Officials Impersonated in Malicious Messaging Campaign, 15 May 2025. ic3.gov
  16. FBI. Public service announcement, 19 December 2025, as reported by Biometric Update. ic3.gov; biometricupdate.com
  17. Euronews, 10 February 2025, cloned voice of Italy's defence minister (secondary). euronews.com
  18. ABC News (Australia), 9 July 2025, Rubio impostor (secondary). abc.net.au
  19. US Department of State. Alert regarding North Korean IT workers, 31 July 2026. state.gov
  20. Gartner survey of 302 security leaders, 22 September 2025, as reported by Infosecurity Magazine and The Register (secondary). infosecurity-magazine.com; theregister.com
  21. FBI IC3. 2025 Internet Crime Report, April 2026. ic3.gov
  22. Heiding, Lermen, Kao, Verdun, Schneier, Vishwanath. Evaluating Large Language Models' Ability to Automate Spear Phishing. Expert Systems with Applications, June 2026. sciencedirect.com
  23. Heiding, Verdun, Lermen, Kao et al. Evaluating AI Models' Capability to Automate Voice Phishing Attacks. arXiv, July 2026. arxiv.org/abs/2607.09970
  24. NCSC. Impact of AI on cyber threat from now to 2027, May 2025. ncsc.gov.uk
  25. Europol. Internet Organised Crime Threat Assessment (IOCTA) 2026, April 2026. europol.europa.eu
  26. Verizon. 2026 Data Breach Investigations Report, May 2026. verizon.com
  27. UK Finance. Annual Fraud Report 2026, June 2026. ukfinance.org.uk
  28. Monetary Authority of Singapore. Information Paper: Cyber Risks Associated with Deepfakes, September 2025. mas.gov.sg
  29. Payment Systems Regulator. One year on: impact of APP reimbursement on victims, 8 October 2025. psr.org.uk
  30. Singapore Police Force. Annual Scam and Cybercrime Brief 2025. police.gov.sg
  31. Australian Signals Directorate. Annual Cyber Threat Report 2024-25, October 2025. cyber.gov.au
  32. World Economic Forum. Global Cybersecurity Outlook 2026, January 2026. weforum.org
  33. European Commission. Transparency obligations under Article 50 of the AI Act, FAQ, July 2026. digital-strategy.ec.europa.eu
  34. Kohler et al. DeepFake Detection in Dyadic Video Calls using Point of Gaze Tracking. arXiv, September 2025. arxiv.org/abs/2509.25503
  35. NCC Group. Voice impersonation and deepfake vishing in real time, 2025 (vendor). nccgroup.com