Logo SealfieSealfie
Figures

55 billion dollars over ten years

Banner from the FBI IC3 public service announcement on business email compromise

In September 2024 the FBI published the cumulative reported losses for business email compromise across ten years, from October 2013 to December 2023: 55 billion dollars. That averages 5.5 billion a year, and counts only the incidents reported to IC3.

The figure grows with the tools available. Deepfakes, the manipulations that produce convincing voice and video, have become the weapon of choice for this kind of attack. Picture a call from your chief executive: the voice, the intonation, the pacing, all of it right. They ask for an urgent transfer for a confidential operation.

Traditional recommendations have reached their limit

Agencies advise treating unusual requests with suspicion and verifying through another channel. Those practices remain useful and should be applied.

They rest, however, on an ability that does not exist. Faced with a well-made deepfake, no human, whatever their training and level of vigilance, tells it apart from the real thing. The documented incidents are therefore not human error in the usual sense: the person did what they had been taught to do.

Two recent cases

In 2024 the engineering group Arup lost 25 million dollars in Hong Kong. An employee joined a video call in which the other participants were deepfakes. Hong Kong police summed the case up in one phrase: everyone was fake. No carelessness was found.

At Ferrari, the attempt failed narrowly. The criminals mimicked the voice, the accent and the Sicilian expressions of the chief executive. An employee asked a question only the real executive could answer. The defence held on one individual’s reflex, not on a control.

Detectors do not close the gap

Deepfake detectors, meant to take over from the eye and the ear, hold up poorly in real conditions, particularly on voice. Their reliability depends on the corpus they were trained on, and attackers work constantly to get around them. We covered this in detail using the CSIRO evaluation of sixteen detectors.

Rebuilding validation around the requester

If the message can no longer be authenticated, the person remains. That is the shift Sealfie carries: a mobile application that requires no training, and that prompts the real requester on their own phone before a sensitive order is carried out. Validation then stops resting on a spoken exchange and on one person’s judgement.

Test your procedure

The 30-minute Challenge simulates an executive fraud attack against your validation procedure, with your consent. You keep the written report either way.