Skip to content
ADVERTISEMENT

Why organisations must rethink AI fraud training

Ivan Shkvarun, CEO at Social Links, discusses how employees have become the main entry point for data breaches as AI-powered fraud grows.

Img 0093 768x1089 1
ADVERTISEMENT

50 of the world’s largest companies across telecom, banking & finance, mobility & delivery, e-commerce, and transportation suffered over 880,000 data leaks only in Q2 2025. The weak link is people – employees are often targeted, and what’s interesting is that attacks now mostly go through personal communication channels: emails, messengers, mobile phones. At the same time, artificial intelligence (AI) has massively increased the scale of these attacks and made them way more tailored. And all of this for very little money.

In 2024, a British engineering company lost around £20m because of an AI scam. An employee was contacted by senior officers of the company. First they got an email, and then a video call from someone who looked like the company’s CFO. During the call, the leadership convinced the employee to carry out a series of urgent confidential transfers – in the end they made around 15 transactions to accounts belonging to scammers in Hong Kong.

There are also stories with better endings. The same year, a Ferrari executive received urgent messages and a phone call from someone claiming to be the CEO. The request was, of course, an urgent money transfer. But this time the fraud didn’t work.

Instead of reacting immediately, the executive asked a personal verification question about a book the real CEO had recently recommended. The caller couldn’t answer properly and the attempt fell apart.

From these examples, one conclusion is pretty obvious – some companies are simply better trained for AI-related security than others.  

ADVERTISEMENT

Today, many companies run AI training for employees, but most of these sessions are focused on optimising processes. Meanwhile, skills around spotting fraud are still overlooked. In 2024, Gartner estimated that by 2027, 17% of all cyberattacks and data leaks will involve generative AI. I think the number could be even higher. After all, it’s incredibly cheap and simple. AI can fake your voice – or your CEO’s voice – with just a 5-second recording. 

The main problem in today’s business world is the wrong focus. Companies are still investing heavily in infrastructure defense – updating security systems, adding corporate email protection tools, controlling access to internal services, and strengthening network security. And they definitely shouldn’t stop doing that. But part of those resources should already be going into training employees to recognise AI scams, and building internal rules around how sensitive information is shared in high-pressure situations.

Today there are several types of AI-powered scams that are especially common and convincing: deepfake calls (including video), highly customised phishing messages. And when I say highly, I mean messages that can include specific information about you and the person you’re talking to, even fragments of your communication history – because now AI can analyse massive amounts of data about you and your colleagues, everything you’ve ever posted online, and use it against you.

ADVERTISEMENT

Naturally, fraudsters want to target businesses – that’s where the big money is. And AI makes it possible to identify the most vulnerable and valuable groups inside a company.

What should companies actually do at the employee level?

ADVERTISEMENT

Our research revealed a significant issue: many leaders still believe their organizations are well protected against AI-enabled fraud. That confidence is often misplaced which creates a dangerous gap between perceived and actual preparedness.

ADVERTISEMENT

Companies need to rethink who security training is primarily designed for. In the AI era, a significant share of risk management depends on leaders. HR teams should place a much stronger focus on educating managers and executives about emerging threats, how they affect the business, and how to respond to them. At the same time, organizations should not neglect broader employee education.

General training isn’t enough. Many people don’t even know what channels AI fraud can come through. Employees need to understand the different types of AI scams: from deepfakes, phishing, smishing (SMS-based attacks), voice cloning, youtube video streaming to fake conference setups.

We grew up with the idea that we can trust what we see. But in the AI era, that’s no longer true. The problem is that many people still operate with that assumption, and employees may unknowingly bypass basic security principles. That’s why for sensitive data and financial operations there need to be clear, mandatory verification requirements – confirming requests through multiple channels. Some companies are now explicitly separating “decision channels” from “chat channels”, so that real approvals can only happen in controlled systems, not in informal threads.

Theory needs to be followed by practice. Unfortunately or fortunately, we already have a solid library of cases showing how AI fraud has entered companies and stolen thousands or millions. One way to train employees is to break down these cases. Studying examples helps people understand the scale and real risks. But to prepare employees even better, companies can also run targeted simulations – where the internal cybersecurity team launches personalised attack scenarios against employees and analyses their reactions: did the human layer of defense hold or break?

ADVERTISEMENT

These kinds of exercises show how people actually respond when the scam is real and happening now – not just in slides or training decks.

Ivan Shkvarun is CEO of Social Links