GoFirm
Back to Blog
Threat Landscape·4 min read

The FBI recorded $893 million in AI-related scams in 2025. The primary method was executive impersonation to approve payments.

By GoFirm

The FBI's Internet Crime Complaint Center recorded at least $893 million in AI-related scams against Americans in 2025. The primary method was voice-cloning attacks impersonating executives to approve payments.

That is a precise description of what the execution boundary control exists to prevent. The attacker does not need to breach the network. They do not need to compromise credentials. They need to convince someone that the executive has authorised the transfer. AI has made that convincing trivially achievable at scale.

The attack works because authorisation and authority are treated as the same thing.

In most organisations, a payment is approved when the right person appears to have said so. An email from the CFO. A voicemail from the CEO. A message that looks, sounds, and reads like the instruction came from the right authority. The system processes the instruction. The payment executes.

The problem is not that the identity controls failed. It is that identity and authority are different things, and most organisations have conflated them. Identity asks: who is this? Authority asks: did this specific named person confirm this specific action, right now, on a channel that cannot be impersonated?

A deepfake voice answers the identity question convincingly. It cannot answer the authority question. A biometric confirmation on a registered personal device through an out-of-band channel cannot be faked by a voice clone, a deepfake video, or a phishing email. The attacker can impersonate the executive to every system in the organisation. They cannot produce the executive's biometric on the executive's registered device.

The same attack at machine speed, against multiple targets simultaneously.

The Soufan Center also references Anthropic's disclosure of the first known large-scale AI-orchestrated cyberattack, attributed to a Chinese state-sponsored group, in which an AI agent executed an estimated 80 to 90 percent of the operation independently against technology companies, financial institutions, and government agencies, with some successful intrusions.

That attack executed at machine speed across multiple targets simultaneously. The article frames this as a capability and detection problem. The attackers had capabilities the defenders could not immediately match, and the intrusions succeeded before defenders could respond.

The execution boundary control does not compete with attacker capability. It does not try to detect the attack or match it in speed. It holds one condition at the point where the attack must complete to cause damage: confirmed human authority before the action executes. An AI agent executing 80 percent of an operation autonomously still has to execute the high-consequence action at the end of the chain. That action has an execution moment. GoFirm holds that moment.

Whether attackers or defenders benefit more from AI remains uncertain. The execution boundary is not uncertain.

The Soufan Center cites the 2026 AI Safety Report conclusion that whether attackers or defenders will benefit more from AI assistance remains uncertain. That uncertainty is real and the debate is legitimate across the broad threat landscape.

At the execution boundary of a high-consequence irreversible action, the uncertainty disappears. The attacker may have superior capability. They may have compromised the network, the credentials, the agent, and the upstream workflow. They still cannot execute the action without confirmed human authority from a named person on a registered personal device through a channel that exists outside the compromised environment.

The threat landscape changes. New models, new attack vectors, new capabilities. The consequence landscape does not change: unauthorised financial transfer; data exfiltration; infrastructure compromise. The execution boundary holds against all of them for the same reason: it does not care how the attacker got there. It holds one condition before the action completes.

$893 million in 2025. Executive impersonation to approve payments as the primary method. The attack is not novel. The defence is not complex. A named human authority confirms on a registered personal device before the payment executes. The impersonator cannot produce that confirmation. The payment does not execute.

Stop catastrophic loss instead of having to explain and recover from it.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai , the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Tejeda, Gaby. Assessing the Malicious Use of Advanced AI Models. The Soufan Center IntelBrief, 17 June 2026. https://thesoufancenter.org/intelbrief-2026-june-17/

2. FBI Internet Crime Complaint Center. Cryptocurrency and AI Scams Bilk Americans of Billions. 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions

3. International AI Safety Report 2026. https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026

4. Anthropic. Disrupting AI Espionage. November 2025. https://www.anthropic.com/news/disrupting-AI-espionage

Share this article