Why organisations must rethink AI fraud training
Ivan Shkvarun, CEO at Social Links, discusses how employees have become the main entry point for data breaches as AI-powered fraud grows.

50 of the world’s largest companies across telecom, banking & finance, mobility & delivery, e-commerce, and transportation suffered over 880,000 data leaks only in Q2 2025. The weak link is people – employees are often targeted, and what’s interesting is that attacks now mostly go through personal communication channels: emails, messengers, mobile phones. At the same time, artificial intelligence (AI) has massively increased the scale of these attacks and made them way more tailored. And all of this for very little money.
In 2024, a British engineering company lost around £20m because of an AI scam. An employee was contacted by senior officers of the company. First they got an email, and then a video call from someone who looked like the company’s CFO. During the call, the leadership convinced the employee to carry out a series of urgent confidential transfers – in the end they made around 15 transactions to accounts belonging to scammers in Hong Kong.
There are also stories with better endings. The same year, a Ferrari executive received urgent messages and a phone call from someone claiming to be the CEO. The request was, of course, an urgent money transfer. But this time the fraud didn’t work.
Instead of reacting immediately, the executive asked a personal verification question about a book the real CEO had recently recommended. The caller couldn’t answer properly and the attempt fell apart.
From these examples, one conclusion is pretty obvious – some companies are simply better trained for AI-related security than others.
Today, many companies run AI training for employees, but most of these sessions are focused on optimising processes. Meanwhile, skills around spotting fraud are still overlooked. In 2024, Gartner estimated that by 2027, 17% of all cyberattacks and data leaks will involve generative AI. I think the number could be even higher. After all, it’s incredibly cheap and simple. AI can fake your voice – or your CEO’s voice – with just a 5-second recording.
The main problem in today’s business world is the wrong focus. Companies are still investing heavily in infrastructure defense – updating security systems, adding corporate email protection tools, controlling access to internal services, and strengthening network security. And they definitely shouldn’t stop doing that. But part of those resources should already be going into training employees to recognise AI scams, and building internal rules around how sensitive information is shared in high-pressure situations.
Today there are several types of AI-powered scams that are especially common and convincing: deepfake calls (including video), highly customised phishing messages. And when I say highly, I mean messages that can include specific information about you and the person you’re talking to, even fragments of your communication history – because now AI can analyse massive amounts of data about you and your colleagues, everything you’ve ever posted online, and use it against you.











