Reporting describes AI-powered business email compromise driving $2.77 billion in losses across 21,442 incidents in one recent year, with deepfake components moving from anecdotal in 2022 to around 40% of BEC incidents by early 2026.
The trajectory is steep. The starting point is what makes it consequential.
A Mature, Profitable Category Got An Upgrade
BEC was already the single most financially damaging category of cybercrime before synthesis was involved, and it worked with plain text email and patience.
Adding voice or video to that operation does not create a new crime. It removes the last verification step that used to catch the sophisticated attempts: the call to check. This desk filed what that looks like in 26-0421.
The Economics Changed More Than The Technique
Previously, a convincing impersonation required research, patience and language skill, which limited how many targets one operator could work. Synthesis removes the language barrier and much of the preparation cost.
That converts a technique with a natural ceiling into one bounded mainly by target lists — the same industrialisation this desk described for consent phishing in 26-0429.
The Defence Is A Process, Not A Detector
Deepfake detection tooling exists and will improve. It is the wrong place to put the weight, because it puts a human in the position of adjudicating authenticity in real time under social pressure from someone appearing to be their boss.
Controls that never ask that question work regardless of how convincing the impersonation is: no payment change on verbal instruction, callback to a directory number, dual authorisation through separate channels. Boring, and indifferent to how good the fake becomes.
This is an analysis file built on published research, listed below. Percentages and loss figures come from vendor and agency datasets with differing scopes and years, and we give them as reported. Corrections: corrections@forensicpost.com.
- AI deepfake BEC: $4.1M losses, 40% attack surge in 2026Cyber Technology Insights
- AI deepfake attacks surge: 40% of email compromiseDigital Applied