How the Age of AI Scams Is Reshaping Digital Trust

Generative artificial intelligence (AI) is rapidly proliferating and is simultaneously changing both the methods of fraud and approaches to fraud prevention. Fraudsters can now create highly realistic fake content at lower cost and greater speed, impersonating relatives, friends, supervisors, investment experts, or even government agencies to trick targets into transferring funds, disclosing sensitive information, or approving high-risk transactions.


Professor Maurice Tse and Mr Clive Ho

26 August 2026

Generative artificial intelligence (AI) is rapidly proliferating and is simultaneously changing both the methods of fraud and approaches to fraud prevention. Fraudsters can now create highly realistic fake content at lower cost and greater speed, impersonating relatives, friends, supervisors, investment experts, or even government agencies to trick targets into transferring funds, disclosing sensitive information, or approving high-risk transactions.

Trust mechanisms traditionally based on voice, images, or single-factor identity authentication are now facing unprecedented challenges. As a highly digitalized and international financial centre, Hong Kong is not immune to the impact of the sharp rise in AI scam risks.

The onslaught of AI scams

According to the 2024 crime figures released by the Hong Kong Police Force, there were 44,480 fraud cases involving approximately HK$9.2 billion, accounting for about 47% of recorded crimes, of which approximately 62% were online fraud cases. In recent years, the persistently high incidence of fraud cases has been the main driver of the rise in Hong Kong’s overall crime figures. In the same year, nearly 34,000 technology crime cases were also registered. It is evident that AI-driven cyberattacks and scams will become a major source of risk in the future.

Generative AI can quickly generate images and text, audiovisual materials, and automated interactive content. Among these technologies, voice cloning can imitate the voice of a specific individual, while deepfake technology can synthesize a person’s facial expressions and voice. Together, these technologies can be used to impersonate celebrities or a target’s relatives and friends.  Some deepfake software is even sold at low prices in underground markets, thereby expanding the scale of scam activities.

Fraud through fabrication: difficult to guard against

In early 2024, a deepfake video-conferencing fraud case in Hong Kong involving approximately HK$200 million attracted worldwide attention. According to reports, an employee in the finance department first received an email that seemed to come from the company’s chief financial officer, followed by an invitation to join an online meeting. Given that several participants’ appearances closely resembled those of the company’s senior executives and the employee’s colleagues, the employee mistakenly believed that the instructions were genuinely authorized and ultimately completed a substantial transfer of funds.

This incident clearly demonstrates that, under the impact of deepfake technology, “seeing with one’s own eyes and hearing with one’s own ears” is no longer a reliable basis for identity authentication. The loss did not result from a corporate system being hacked, but from fraudsters using deepfake technology to strengthen traditional social engineering attacks, successfully breaching the target’s trust-based defences.

In fact, it is not difficult for fraudsters to obtain voice samples from short videos on social media or recordings of public events and use AI to generate voice content that is almost indistinguishable from the real thing. In some cases, parents have received distress calls imitating their children’s voices, with the caller claiming to have been involved in an accident and demanding an immediate money transfer. In a state of emotional distress, family members often have no time to verify the authenticity of the call and simply comply.

In the age of AI, fraud has gradually penetrated key domains such as investment decision-making, corporate management, and financial activities. New high-risk fraud scenarios also include e-commerce and recruitment platforms. In e-commerce, criminals use generative AI to quickly create counterfeit websites and leverage social media advertisements to attract traffic. Consumers mistakenly believe these sites to be trustworthy, only to discover after payment that the goods are not as described; their credit card information may even be stolen. In the context of job seeking, fraudsters impersonate well-known companies offering employment, use AI to simulate preliminary interviews, and then demand that applicants pay training fees in advance or provide bank account details for so-called “salary tests”.

The AI offence–defence battle in the financial sector

As real-time payment tools such as the Faster Payment System (FPS) become more popular, the speed of fund transfers has greatly increased, while the time window for financial institutions to identify and intercept suspicious transactions has narrowed. In recent years, highly realistic synthetic-identity fraud techniques have posed unprecedented challenges to traditional identity authentication mechanisms. The Deloitte Centre for Financial Services predicts that, driven by generative AI, losses caused by fraudulent activities in the US may surge from US$12.3 billion in 2023 to US$40 billion by 2027.

In addition to direct financial losses, payment fraud gives rise to a series of knock-on effects, including investigation costs, customer compensation liabilities, regulatory pressure, and damage to brand reputation. For merchants, a large number of fraudulent transactions, chargebacks, and identity-theft incidents may further weaken consumers’ confidence in digital payment systems. Financial institutions must therefore strive to strike a balance between enhancing payment efficiency and ensuring transaction security.

Using AI to combat AI-enabled fraud

As generative AI is seeing wider use in the automation, precision targeting, and cross-border spread of scam activities, the financial industry is working to introduce AI technologies to upgrade its fraud-prevention capabilities. For example, large volumes of transaction data, login records, geolocation data, and user behaviour patterns can be analysed to identify abnormal activities. When such data clearly deviate from a user’s habits, the system can immediately raise the risk rating and require additional authentication or suspend the transaction.

In 2025, a global survey conducted by Mastercard and Longitude―part of the Financial Times Group―classified institutions with stronger fraud-prevention performance as “leaders”, which represented approximately 17% of the survey sample. These institutions continued to generate returns on investment in areas such as real-time transaction monitoring, cross-channel fraud detection, and predictive modelling.

It is important to note that, for AI models to perform an effective fraud-prevention function, data quality, continuous monitoring, and sound governance mechanisms are indispensable. Institutions must also ensure the protection of personal data, maintain channels for human review, and implement effective complaint and redress mechanisms.

Multiple lines of defence to stamp out fraud

As AI-driven fraudulent activities continue to emerge in ever-changing forms, technology alone is insufficient to ensure security. When deepfakes, voice imitation, data analysis, and social engineering techniques are combined, fraud evolves from simple information deception into a systemic risk that precisely manipulates human emotions and decision-making. Therefore, countermeasures can no longer rely solely on individual vigilance; they must instead be a comprehensive undertaking encompassing technology, institutions, education, and cross-institutional cooperation.

From the perspective of the general public, any request involving fund transfers, personal data, login credentials, or confidential documents should be verified through other trusted channels even if it comes from a familiar voice or realistic image. The habit of “verifying before taking action” is undoubtedly an indispensable digital survival skill.

For enterprises, payment approval, multi-factor identity authentication, and staff training must be institutionalized so that risks are not managed solely by relying on the experience and vigilance of individual employees. Platform operators should strengthen the detection and removal of fake accounts, fraudulent advertisements, and AI-generated content, while financial institutions must continue to integrate account security, identity authentication, transaction monitoring, and customer education. Finally, the government, educational institutions, and community organizations should actively promote digital literacy education to help elderly people, students, job seekers, and small and medium-sized enterprises understand how AI scams operate and recognize common warning signs.

Ultimately, the crux of AI-enabled fraud lies in the breakdown of trust mechanisms. In the past, people were accustomed to judging authenticity through voices, images, documents, and identity markers. However, when all these signals can be replicated and generated at low cost, the traditional authentication model of “seeing and hearing is believing” is no longer reliable. Future fraud-prevention efforts must focus on building a new framework of trust. Only through institutionalized authentication, multilayered protection, and continuous education can a robust protective barrier be built to safeguard digital trust and financial security.

Translation

AI詐騙時代如何重塑數碼信任

生成式人工智能(AI)迅速普及,正在同時改變詐騙犯罪的手法與防騙工作的模式。騙徒如今能以更低成本、更快速度製作極為逼真的虛假內容,假冒親友上司、投資專家甚至政府機構,誘使目標對象轉帳、披露敏感資料或批准高風險交易。

過往建立於聲音、影像或單一身份驗證基礎的信任機制,正備受前所未有的挑戰。作為高度數碼化及國際化的金融中心,香港亦難以避免AI詐騙風險急升所造成的衝擊。

AI詐騙   來勢洶洶

根據香港警務處公布的2024年罪案數字,詐騙案涉及金額約92億元,為數44,480宗,佔整體罪案約47%,其中約62%屬網上詐騙。近年詐騙案持續高企,是推高全港罪案數字的主因。同年亦錄得接近3.4萬宗科技罪案。顯而易見,AI驅動的網絡攻擊及詐騙活動將成為未來的重要風險來源。

生成式AI能快速製作圖文、影音,以及自動化互動內容,其中語音模仿(voice cloning)技術能仿造特定人士的聲音,而深度偽造(deepfake)則可合成人物的面部表情、聲線,結合起來,就能冒充名人或目標對象的親友。部分深偽軟件甚至在地下市場低價販售,詐騙活動的規模效應也因此擴大。

為非作假   防不勝防

2024年初,香港發生一宗涉款約2億元的深偽視像會議詐騙案,引起國際廣泛關注。據報,一名財務職員先收到看似公司財務總監的電郵,其後被邀參與網上會議,其中多名與公司高層及同事外貌極為相似的人士出席,令該名員工誤信指示屬真實授權,最終完成巨額轉帳。

該事件充分反映,在深偽技術的衝擊下,「親眼所見、親耳所聞」已不再足以作為身份認證的可靠依據。有關損失並不因企業系統遭黑客入侵,而是騙徒利用深偽技術加強傳統社交工程攻擊,成功突破目標對象的信任防線。

事實上,騙徒不難從社交媒體短片或公開活動錄像取得聲音樣本,透過AI生成幾可亂真的聲音內容。有家長就曾接到模仿子女聲音的求助電話,對方藉口遭遇意外而要求立即匯款,家人在情緒波動下往往來不及查證真偽,只好照辦。

踏入AI時代,詐騙已逐步滲透至投資決策、企業管理及金融活動等關鍵領域。新一代高危詐騙場景更包括電子商務和求職平台。在電子商務方面,不法之徒利用生成式AI快速建立仿冒網站、利用社交媒體廣告吸引流量,消費者誤以為可信,在付款後才發現貨不對辦,其信用卡資料甚至被盜用。至於求職方面,騙徒會假扮知名企業招聘,使用AI模擬初步面試,進一步要求應徵者預繳培訓費用,或提供銀行帳戶以作所謂「薪資測試」。

金融業的AI攻防戰

隨着轉數快等即時支付工具日益普及,資金轉移速度大幅提升之餘,亦收窄了金融機構識別和攔截可疑交易的時間窗口。近年擬真度高的合成身份詐騙手法,導致傳統身份驗證機制面臨前所未有的挑戰。Deloitte金融服務研究中心預測,在生成式AI推動下,美國因欺詐活動造成的損失可能由2023年的123億美元,上升至2027年的400億美元。

除了直接財務損失外,支付欺詐亦帶來調查成本、客戶補償責任、監管壓力及品牌聲譽受損等連鎖影響。對商戶而言,大量偽冒交易、退單與身份盜用事件更可能削弱消費者對數碼支付系統的信心。因此,金融機構必須在提高支付效率與確保交易安全之間謀求平衡。

以子之矛 攻子之盾

有鑑於生成式AI日益被應用於詐騙活動的自動化、精準化和跨境擴散,金融業亦致力引入AI技術以升級其防詐能力,例如分析大量交易數據、登入紀錄、地理位置及用戶行為模式,從中識別異常活動。當有關資料與用戶日常習慣明顯不符,系統能即時提高風險評級,要求額外驗證或暫停交易。

2025年,Mastercard與《金融時報》旗下Longitude的全球調查,將防詐表現較佳的機構歸類為「領先群組」(leaders),約佔受訪樣本的17%。這類機構在即時交易監測、跨渠道詐騙偵測、預測模型等範疇持續取得投資回報。

不可不察的是,要AI模型發揮防騙功能,必須依賴數據品質、持續監察及完善治理機制。機構亦需確保個人資料保障、保留人工覆核渠道,以及實施有效的申訴和補救機制。

多重防線  杜絕詐騙

由AI驅動的詐騙活動層出不窮,單靠科技不足以保障安全。當深度偽造、語音模仿、資料分析與社交工程手法互相結合,詐騙已由簡單的資訊欺騙演變為精準操控人類情緒與決策的系統性風險。因此,應對之策不能只依賴個人警覺,而必須為涵蓋科技、制度、教育與跨機構合作的綜合工程。

從市民角度出發,凡涉及金錢轉移、個人資料、登入憑證或機密文件的要求,即使來自熟悉聲音或逼真影像,也應透過其他可信渠道加以核實。「先查證、後行動」的習慣,無疑是不可或缺的數碼生存技能。

對企業而言,則必須把付款審批、多重身份驗證及員工培訓制度化,避免單靠個別員工的經驗與警覺管理風險。平台營運商應加強偵測及移除偽冒帳戶、詐騙廣告和AI生成內容,而金融機構則須持續整合帳戶安全、身份驗證、交易監控與客戶教育。

最後,政府、教育機構及社區組織應積極推動數碼素養教育,協助長者、學生、求職者及中小企了解AI詐騙的運作模式和常見警號。

歸根究柢,應用AI進行詐騙的癥結,在於信任機制失靈。過去人們習慣透過聲音、影像、文件及身份標誌判斷真偽,但當這些訊號都可透過低成本方式複製和生成,傳統上「耳聞目睹才算真」的驗證模式便不再可靠。未來防詐工作必須聚焦於建構新型信任框架。唯有制度化驗證、多層防護和持續教育,才能全面築起保衛數碼信任與金融安全的保護屏障。

謝國生教授
港大經管學院金融學教學副教授、新界鄉議局當然執行委員

何敏淙先生
香港大學附屬學院經濟及商學學部助理學部主任、香港大學附屬學院講師

(本文同時於二零二六年八月二十六日載於《信報》「龍虎山下」專欄)