Desk live·
ForensicPost
AI/Fraud/File 26-0712

Deepfakes Reported in 40% of Business Email Compromise Incidents

Deepfake components are reported in around 40% of business email compromise incidents by early 2026, up from anecdotal three years ago. BEC was already the most lucrative category before any of this.

Constructed geometry · not a chart of case data
TargetCorporate payment processes
ActorMultiple
S. Rosler10 min readConfidence: medium2 sources reviewed

Reporting describes AI-powered business email compromise driving $2.77 billion in losses across 21,442 incidents in one recent year, with deepfake components moving from anecdotal in 2022 to around 40% of BEC incidents by early 2026.

The trajectory is steep. The starting point is what makes it consequential.

A Mature, Profitable Category Got An Upgrade

BEC was already the single most financially damaging category of cybercrime before synthesis was involved, and it worked with plain text email and patience.

Adding voice or video to that operation does not create a new crime. It removes the last verification step that used to catch the sophisticated attempts: the call to check. This desk filed what that looks like in 26-0421.

The Economics Changed More Than The Technique

Previously, a convincing impersonation required research, patience and language skill, which limited how many targets one operator could work. Synthesis removes the language barrier and much of the preparation cost.

That converts a technique with a natural ceiling into one bounded mainly by target lists — the same industrialisation this desk described for consent phishing in 26-0429.

The Defence Is A Process, Not A Detector

Deepfake detection tooling exists and will improve. It is the wrong place to put the weight, because it puts a human in the position of adjudicating authenticity in real time under social pressure from someone appearing to be their boss.

Controls that never ask that question work regardless of how convincing the impersonation is: no payment change on verbal instruction, callback to a directory number, dual authorisation through separate channels. Boring, and indifferent to how good the fake becomes.

How we reported this

This is an analysis file built on published research, listed below. Percentages and loss figures come from vendor and agency datasets with differing scopes and years, and we give them as reported. Corrections: corrections@forensicpost.com.

Sources
  1. AI deepfake BEC: $4.1M losses, 40% attack surge in 2026Cyber Technology Insights
  2. AI deepfake attacks surge: 40% of email compromiseDigital Applied
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary