Professor Maurice Tse and Mr Clive Ho
26 August 2026
Generative artificial intelligence (AI) is rapidly proliferating and is simultaneously changing both the methods of fraud and approaches to fraud prevention. Fraudsters can now create highly realistic fake content at lower cost and greater speed, impersonating relatives, friends, supervisors, investment experts, or even government agencies to trick targets into transferring funds, disclosing sensitive information, or approving high-risk transactions.
Trust mechanisms traditionally based on voice, images, or single-factor identity authentication are now facing unprecedented challenges. As a highly digitalized and international financial centre, Hong Kong is not immune to the impact of the sharp rise in AI scam risks.
The onslaught of AI scams
According to the 2024 crime figures released by the Hong Kong Police Force, there were 44,480 fraud cases involving approximately HK$9.2 billion, accounting for about 47% of recorded crimes, of which approximately 62% were online fraud cases. In recent years, the persistently high incidence of fraud cases has been the main driver of the rise in Hong Kong’s overall crime figures. In the same year, nearly 34,000 technology crime cases were also registered. It is evident that AI-driven cyberattacks and scams will become a major source of risk in the future.
Generative AI can quickly generate images and text, audiovisual materials, and automated interactive content. Among these technologies, voice cloning can imitate the voice of a specific individual, while deepfake technology can synthesize a person’s facial expressions and voice. Together, these technologies can be used to impersonate celebrities or a target’s relatives and friends. Some deepfake software is even sold at low prices in underground markets, thereby expanding the scale of scam activities.
Fraud through fabrication: difficult to guard against
In early 2024, a deepfake video-conferencing fraud case in Hong Kong involving approximately HK$200 million attracted worldwide attention. According to reports, an employee in the finance department first received an email that seemed to come from the company’s chief financial officer, followed by an invitation to join an online meeting. Given that several participants’ appearances closely resembled those of the company’s senior executives and the employee’s colleagues, the employee mistakenly believed that the instructions were genuinely authorized and ultimately completed a substantial transfer of funds.
This incident clearly demonstrates that, under the impact of deepfake technology, “seeing with one’s own eyes and hearing with one’s own ears” is no longer a reliable basis for identity authentication. The loss did not result from a corporate system being hacked, but from fraudsters using deepfake technology to strengthen traditional social engineering attacks, successfully breaching the target’s trust-based defences.
In fact, it is not difficult for fraudsters to obtain voice samples from short videos on social media or recordings of public events and use AI to generate voice content that is almost indistinguishable from the real thing. In some cases, parents have received distress calls imitating their children’s voices, with the caller claiming to have been involved in an accident and demanding an immediate money transfer. In a state of emotional distress, family members often have no time to verify the authenticity of the call and simply comply.
In the age of AI, fraud has gradually penetrated key domains such as investment decision-making, corporate management, and financial activities. New high-risk fraud scenarios also include e-commerce and recruitment platforms. In e-commerce, criminals use generative AI to quickly create counterfeit websites and leverage social media advertisements to attract traffic. Consumers mistakenly believe these sites to be trustworthy, only to discover after payment that the goods are not as described; their credit card information may even be stolen. In the context of job seeking, fraudsters impersonate well-known companies offering employment, use AI to simulate preliminary interviews, and then demand that applicants pay training fees in advance or provide bank account details for so-called “salary tests”.
The AI offence–defence battle in the financial sector
As real-time payment tools such as the Faster Payment System (FPS) become more popular, the speed of fund transfers has greatly increased, while the time window for financial institutions to identify and intercept suspicious transactions has narrowed. In recent years, highly realistic synthetic-identity fraud techniques have posed unprecedented challenges to traditional identity authentication mechanisms. The Deloitte Centre for Financial Services predicts that, driven by generative AI, losses caused by fraudulent activities in the US may surge from US$12.3 billion in 2023 to US$40 billion by 2027.
In addition to direct financial losses, payment fraud gives rise to a series of knock-on effects, including investigation costs, customer compensation liabilities, regulatory pressure, and damage to brand reputation. For merchants, a large number of fraudulent transactions, chargebacks, and identity-theft incidents may further weaken consumers’ confidence in digital payment systems. Financial institutions must therefore strive to strike a balance between enhancing payment efficiency and ensuring transaction security.
Using AI to combat AI-enabled fraud
As generative AI is seeing wider use in the automation, precision targeting, and cross-border spread of scam activities, the financial industry is working to introduce AI technologies to upgrade its fraud-prevention capabilities. For example, large volumes of transaction data, login records, geolocation data, and user behaviour patterns can be analysed to identify abnormal activities. When such data clearly deviate from a user’s habits, the system can immediately raise the risk rating and require additional authentication or suspend the transaction.
In 2025, a global survey conducted by Mastercard and Longitude―part of the Financial Times Group―classified institutions with stronger fraud-prevention performance as “leaders”, which represented approximately 17% of the survey sample. These institutions continued to generate returns on investment in areas such as real-time transaction monitoring, cross-channel fraud detection, and predictive modelling.
It is important to note that, for AI models to perform an effective fraud-prevention function, data quality, continuous monitoring, and sound governance mechanisms are indispensable. Institutions must also ensure the protection of personal data, maintain channels for human review, and implement effective complaint and redress mechanisms.
Multiple lines of defence to stamp out fraud
As AI-driven fraudulent activities continue to emerge in ever-changing forms, technology alone is insufficient to ensure security. When deepfakes, voice imitation, data analysis, and social engineering techniques are combined, fraud evolves from simple information deception into a systemic risk that precisely manipulates human emotions and decision-making. Therefore, countermeasures can no longer rely solely on individual vigilance; they must instead be a comprehensive undertaking encompassing technology, institutions, education, and cross-institutional cooperation.
From the perspective of the general public, any request involving fund transfers, personal data, login credentials, or confidential documents should be verified through other trusted channels even if it comes from a familiar voice or realistic image. The habit of “verifying before taking action” is undoubtedly an indispensable digital survival skill.
For enterprises, payment approval, multi-factor identity authentication, and staff training must be institutionalized so that risks are not managed solely by relying on the experience and vigilance of individual employees. Platform operators should strengthen the detection and removal of fake accounts, fraudulent advertisements, and AI-generated content, while financial institutions must continue to integrate account security, identity authentication, transaction monitoring, and customer education. Finally, the government, educational institutions, and community organizations should actively promote digital literacy education to help elderly people, students, job seekers, and small and medium-sized enterprises understand how AI scams operate and recognize common warning signs.
Ultimately, the crux of AI-enabled fraud lies in the breakdown of trust mechanisms. In the past, people were accustomed to judging authenticity through voices, images, documents, and identity markers. However, when all these signals can be replicated and generated at low cost, the traditional authentication model of “seeing and hearing is believing” is no longer reliable. Future fraud-prevention efforts must focus on building a new framework of trust. Only through institutionalized authentication, multilayered protection, and continuous education can a robust protective barrier be built to safeguard digital trust and financial security.







