Your success is at the forefront of our minds.

AI Deepfake Fraud Is Now the Fastest-Growing SA Cyber Claim. Is Your Business Covered?

Home / Blog / AI Deepfake Fraud Is Now the Fastest-Growing SA Cyber Claim. Is Your Business Covered?

In February 2024, an employee at the global engineering firm Arup transferred the equivalent of approximately R450 million to fraudsters after participating in a video call with people who looked and sounded exactly like the company’s UK Chief Financial Officer. The CFO was not on the call. Nobody on the call was real. Every participant except the Arup employee was an AI-generated deepfake. The R450 million was gone before anyone realised.

That case became the template for what has followed. Since 2024, published cybersecurity research and incident-response data have documented rapid growth in AI-generated impersonation attacks against businesses, both globally and increasingly in South African incident patterns reported through SABRIC and industry channels. SA businesses have not been spared. By June 2026, SA banks, listed companies, and SMEs alike are reporting deepfake voice fraud, deepfake video fraud, and AI-generated impersonation incidents at a rate that was inconceivable two years ago. The cyber insurance market is scrambling to keep pace, and most existing SA cyber policies have meaningful gaps when it comes to AI-driven fraud. All cover discussed here is subject to underwriting and final policy wording.

TL;DR

  • The 2024 Arup Hong Kong deepfake CEO fraud (approximately HK$200 million / USD 25.6 million) is the most widely-cited case globally. Similar attack patterns have been reported across multiple jurisdictions including South Africa, though verified case-level SA data is limited because most incidents are not publicly disclosed.
  • Standard cyber insurance policies were drafted before deepfake fraud was a real category. Whether your policy responds depends heavily on how “social engineering” and “fraudulent funds transfer” are defined.
  • Many SA cyber policies cover the technical breach side (someone hacks your systems) but not the psychological breach side (someone tricks your employee into a transfer). Deepfake fraud is the second category.
  • Cover that responds to deepfake fraud typically lives in a “social engineering fraud” extension or a “funds transfer fraud” endorsement, not the core cyber wording. These extensions are not automatic and need to be negotiated at placement or renewal.
  • SA businesses can also reduce exposure through verification protocols (callback procedures, multi-signature authorisation, voice and video authentication tests) that most insurers now expect as a condition of cover.

Table of Contents

Biometric facial scan technology used to verify identity and detect ai deepfake impersonation

What deepfake business fraud actually looks like in 2026

Deepfake business fraud is a category of social engineering attack that uses AI-generated audio, video, or both to impersonate a senior figure in the target organisation. The attacker uses the impersonation to direct an employee, customer, or supplier to transfer money, share credentials, or take action that benefits the attacker. The technology has progressed to the point where real-time voice and video deepfakes are convincing enough to fool experienced employees during live calls.

The 2024 Arup case became the template for what has spread since. Four broad attack patterns are now common:

Pattern 1: Deepfake video call

The attacker arranges what appears to be a multi-party video conference featuring senior executives. The employee on the call sees and hears people who look and sound like real colleagues. The “executives” instruct an urgent transfer to a new bank account, framed as commercially sensitive or time-critical. The Arup case followed this pattern.

Pattern 2: Deepfake voice call

The attacker calls an employee using an AI-generated voice clone of a senior executive. The voice clone may be based on as little as 3-5 seconds of source audio scraped from a public conference appearance or earnings call. The clone calls the employee, often during a stressful or distracting moment, and instructs an urgent action.

Pattern 3: Deepfake video message

The attacker sends a pre-recorded deepfake video to the target employee via WhatsApp, Teams, or email. The video shows an executive giving instructions. The employee follows the apparent instructions before the impersonation is detected.

Pattern 4: Hybrid deepfake + compromised email

The attacker first compromises a senior executive’s email account through phishing or credential reuse. They then use email to set up what appears to be a follow-up video call, in which a deepfake of the executive participates. The legitimate email account adds credibility to the deepfake call. This hybrid is particularly difficult to detect.

What SA businesses are seeing

SA-specific deepfake fraud reporting is fragmented because most incidents do not become public, the affected businesses settle quietly, the bank investigates internally, and details remain confidential. From visible cases and broker industry reporting, several themes are emerging:

South African businesses have been targeted with deepfake CFO impersonation attacks. The pattern mirrors the Arup case: a video call with apparent senior executives directing an urgent fund transfer to a new beneficiary, often framed as an acquisition deposit or vendor payment. Individual case values vary widely by industry, controls in place and transaction limits. Verified public reporting of specific South African case values is limited because most incidents are not publicly disclosed.

SA-based subsidiaries of multinational companies have been targeted as proxy entry points to the parent group. Attackers exploit the time zone gap to instruct the SA office to make a payment that would be questioned in the parent’s home market.

SA SME owners have reported deepfake voice calls impersonating their primary banker, auditor, or supplier, instructing changes to bank account details for outgoing payments. The losses tend to be smaller per incident but more frequent.

SA financial services firms (FSPs, FSCA-regulated) have reported attempts to use deepfake video to authorise large transfers through normal authorisation protocols. The FSCA has issued multiple notifications encouraging FSPs to upgrade verification procedures.

SA banks have been on the receiving end of deepfake-impersonation attempts targeting business banking clients. The fraud pattern often involves a deepfake of a corporate finance director instructing a bank manager to update beneficiary details on outgoing payment runs.

Why standard SA cyber insurance often does not respond

Cyber insurance was designed around technical compromise, someone hacks your network, steals data, encrypts files, or disrupts operations. Deepfake business fraud is a different category of attack. The systems are not breached; the employee is. The attacker uses persuasion, not malware. The money leaves through normal channels following an apparently legitimate instruction.

Three reasons standard SA cyber policies often do not respond to deepfake fraud:

Reason 1: The trigger is “network security event,” not “social engineering”

Most cyber policies define the cover trigger as a “network security event,” “computer security breach,” or similar phrasing focused on technical compromise. A deepfake call does not breach the insured’s systems. The trigger may not be satisfied.

Reason 2: Fraudulent funds transfer is often excluded or sub-limited

Many cyber wordings exclude “voluntary transfers” or “funds transferred at the direction of the insured.” A transfer authorised by an employee deceived by a deepfake is, technically, a voluntary transfer, the employee chose to authorise it. The exclusion can apply even when the deception was the cause.

Reason 3: Social engineering extensions exist but are not automatic

Most major SA cyber insurers offer a “social engineering fraud” or “funds transfer fraud” extension that specifically addresses this category. The extension is not automatic, it has to be requested, negotiated, and added at placement or renewal. Many existing SA cyber policies do not have it. See related analysis on third-party cyber breach liability for adjacent gaps in standard policies.

Cybersecurity defences protecting south african businesses from deepfake and ai fraud attacks

The social engineering fraud extension explained

The social engineering fraud (SEF) extension is the cover that specifically responds to deepfake-driven and voice-/video-impersonation fraud. The mechanics of the extension matter for SA businesses negotiating renewal:

Trigger: The extension typically triggers when the insured’s employee is deceived into making a funds transfer based on fraudulent instruction. The instruction may come via email, phone, video call, message, or other communication.

Cover scope: The extension typically covers the financial loss arising from the fraudulent transfer, up to the sub-limit. Sub-limits are typically R5-50 million, lower than the main cyber policy limit. Higher sub-limits are negotiable for businesses with high transfer volumes.

Verification condition: Most SEF extensions now require the insured to have specific verification protocols in place before the cover responds. These typically include callback procedures (phoning back the apparent instructor on a known number), multi-party authorisation for transfers above defined thresholds, and segregation of duties between instruction and payment execution.

Waiting period or deductible: SEF cover typically carries a higher deductible than the main cyber policy, reflecting the discretionary nature of the loss. Deductible levels vary significantly by insurer, business size and the strength of the insured’s verification controls. A specialist broker can advise on the range applicable to your specific situation.

Aggregate limit: The extension is typically capped at an annual aggregate that may be lower than the main cyber policy limit. Businesses with high fraud exposure should negotiate higher aggregates.

For SA businesses, the question to ask at renewal is not “do I have cyber cover?” but “does my cyber programme include social engineering fraud and funds transfer fraud cover at limits that match my realistic exposure?” The answer is often “no” by default, and negotiating the addition takes broker engagement before the renewal is finalised. See our specialised cyber insurance service for placement support.

What insurers now require as a condition of cover

By mid-2026, most SA cyber insurers offering SEF cover now require the insured to demonstrate specific anti-fraud controls before the cover will respond. These conditions are evolving quickly, but the common requirements include:

  1. Documented callback procedure. Before any unusual fund transfer or beneficiary change request is actioned, the employee must call back the apparent instructor using a known and pre-verified phone number, not the number from which the instruction came. The procedure must be documented in writing and applied consistently.
  2. Multi-party authorisation above threshold. Transfers above a defined value (typically R500,000 to R5 million depending on business size) require independent authorisation by at least one additional person, ideally from a different department.
  3. Segregation of duties. The employee who can initiate a transfer should not be the same employee who can authorise it. This separation prevents a single deception from completing the fraud cycle.
  4. Out-of-band verification for new beneficiaries. Adding a new payee or changing existing payee details requires verification through a channel different from the one used for the change request, phone if the request came via email, video call if the request came via phone.
  5. Training and awareness programme. Employees handling payments must receive periodic training on deepfake and social engineering threats, with documented attendance.
  6. Voice and video authentication protocols. For very high-value transactions, insurers increasingly require pre-agreed verification questions, code words, or other authentication tests that a deepfake cannot answer.

For SA businesses, implementing these conditions is increasingly the price of entry for meaningful SEF cover. Implementation also reduces the actual probability of successful deepfake fraud, which is the larger benefit.

Verification protocols that satisfy insurers

The specific verification protocols that SA insurers now look for at placement include:

Time-delayed transfers: All transfers above the threshold are subject to a 24-hour hold during which the apparent instructor can be re-verified through multiple channels. This delays legitimate payments slightly but interrupts the urgency that deepfake attackers rely on.

Channel diversity for verification: If a transfer instruction came via email, verification happens by phone or in person. If by phone, verification by video or in person. Attackers typically have access to only one or two channels; requiring verification through a different channel breaks the attack.

Pre-agreed code phrases: Senior executives and key signatories agree in advance on phrases that must be present in any urgent payment instruction. Deepfakes can replicate voice and image but cannot know an unpublished code phrase.

Independent identity verification questions: The receiving employee asks questions only the real person would know, drawn from a continually updated bank of options. “What did we discuss in last Thursday’s team meeting?”, questions a deepfake cannot answer convincingly.

Authentication tests during the call: Specific physical movements requested in real time (turn your head left, hold up three fingers, look up and to the right) catch most current-generation deepfakes that struggle with complex real-time motion.

None of these protocols are foolproof against future deepfake capability, but in mid-2026 they materially reduce the success rate of current-generation attacks. They are also the actions that insurers will look for at claim time when assessing whether the insured took reasonable precautions.

Face recognition and identity verification layers used to spot deepfake impersonation attempts

What to do this quarter

For SA business owners and finance leaders concerned about deepfake fraud exposure, three specific actions are appropriate this quarter:

  1. Review your cyber insurance for SEF cover. Pull your existing cyber policy and look specifically for “social engineering fraud,” “fraudulent funds transfer,” or “deception fraud” extensions. If none exists, request a quote for the extension at next renewal or sooner. If one exists, check the sub-limit, deductible, and verification conditions.
  2. Implement the verification protocols above. Even before the insurance is in place, these protocols reduce actual fraud probability. Document them in writing, train your team, and audit compliance quarterly. The protocols are also a precondition for SEF cover to respond at claim time.
  3. Run a deepfake awareness session. Most SA businesses have not had a formal conversation with their finance and procurement teams about deepfake fraud. A 30-minute briefing with examples, attack patterns, and verification procedures dramatically improves the chance that an employee will recognise the attack in progress and stop it.

For businesses with significant payment volumes or high-value transfer exposure, our specialised cyber insurance service can structure a cyber programme that includes SEF cover at appropriate limits. See also our related analysis on AI disclosure and professional indemnity for SA firms for the broader AI risk picture.

Frequently asked questions

Does my SA cyber insurance cover deepfake CEO fraud?

Most standard SA cyber policies do not respond to deepfake CEO fraud or similar social engineering attacks unless they include a specific “social engineering fraud” or “fraudulent funds transfer” extension. The core cyber wording typically focuses on technical compromise, not employee deception. Check your policy or have a broker review the wording specifically against this exposure.

What is the maximum loss SA businesses have suffered from deepfake fraud?

The most-cited global benchmark is the February 2024 Arup case in Hong Kong, in which fraudsters used AI-generated video of senior executives to authorise a transfer of approximately HK$200 million (roughly USD 25.6 million at the time). Similar attack patterns have been reported across multiple jurisdictions. Verified South African case data is limited because most incidents are not publicly disclosed.

What is the social engineering fraud extension?

The social engineering fraud (SEF) extension is a cyber insurance add-on that specifically responds when an insured’s employee is deceived into making a fraudulent funds transfer. It typically covers the financial loss up to a sub-limit, requires specific verification protocols to be in place, carries a higher deductible than the main cyber policy, and has annual aggregate caps that may be lower than the core cyber limit.

What verification procedures do SA cyber insurers require?

Insurers offering SEF cover typically require documented callback procedures, multi-party authorisation above defined thresholds, segregation of duties between instruction and execution, out-of-band verification for new beneficiaries, employee training, and increasingly voice and video authentication protocols. The specific requirements vary by insurer but the principles are consistent across the market.

Can deepfake fraud be detected during a live video call?

Current-generation deepfakes have detectable artefacts including unnatural eye movements, inconsistent lighting on the face, lag between voice and lip movement during complex words, and difficulty with complex real-time facial expressions. However, the technology is improving rapidly. The most reliable detection in 2026 remains verification through different channels and pre-agreed authentication tests rather than visual or audio inspection of the call itself.

What is the difference between deepfake fraud and business email compromise (BEC)?

Both are social engineering attacks targeting payments, but BEC typically uses email impersonation while deepfake fraud uses AI-generated voice or video. Many incidents now combine both, a compromised or spoofed email account introduces a deepfake video call. Insurance cover for the two often falls under the same extension (SEF or fraudulent funds transfer) but with different attack vectors and detection signatures.

Is the FSCA tracking deepfake fraud in SA financial services?

The FSCA has issued multiple guidance notices to FSPs and financial institutions about deepfake and AI-driven fraud risks. The regulator has not yet introduced mandatory reporting of specific incidents, but FSPs are generally expected to incorporate deepfake risk into their fraud risk frameworks and broader operational risk programmes. Specific regulatory guidance is evolving.

Get your cyber programme reviewed before the next attack

Deepfake business fraud is the fastest-growing cyber claim category in SA in 2026, and most existing cyber policies have meaningful gaps. A focused programme review identifies whether your current cover responds to the new attack patterns, what extensions you need, and what verification protocols would satisfy your insurer at claim time. Contact Berkley Risk or call 011-702-8250 to arrange a cyber programme review structured around current SA deepfake exposure, subject to underwriting and insurer appetite.

Berkley Risk (Pty) Ltd arranges/places/co-ordinates insurance with licensed insurers. FSP #54407. This article is general information only and does not constitute legal, financial, or regulatory advice. All cover is subject to underwriting acceptance and final policy wording.

This article is general information only and does not constitute financial product advice. Rate movements, cover options and case scenarios described are general market observations. Cover requirements and structuring for your specific business should be discussed with a licensed FSP. Berkley Risk is an authorised financial services provider. FSP #54407.