Versatile AI Risk Assessment

AI threat catalogueMalicious Use for Attacks, Fraud and DisinformationProduction

Fraud

Criminals use AI to commit fraud at greater scale and with greater credibility: through fake reviews, invented identities, forged documents, and cloned voices and videos.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 6 verified sources

Description

Generative AI gives fraudsters the building blocks of a credible deception. Language models write convincing scam messages and fake product reviews; image generators create profile photos, identity documents and entire invented identities used to set up fictitious accounts and social media profiles in bulk. Voice clones and deepfakes (AI-generated image, audio or video content that convincingly resembles real people) impersonate relatives, business partners or well-known figures to trigger payments. Points of attack include payment and ordering processes, customer channels, and identity checks such as video identification, whose biometric controls can be defeated with deepfakes.

Possible impact

Companies face direct financial losses from fraudulently obtained payments and accounts opened under false identities. Fake reviews and fraudulent appearances in the company’s name damage the brand and customer trust. Where identity checks are defeated, legal and regulatory risks follow, for example around anti-money-laundering and customer identification duties (know your customer).

Example

Fraudsters open accounts with a financial services provider using AI-generated ID photos and pass the video identification with a deepfake face injected in real time. They then route fraudulent payments through the accounts opened this way.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

NIST AI RMF Section 2.8MITRE ATLAS AML.T0048.002EU AI Act Article 5(1)(a) · Article 55(1)(b)BSI R10 · R11

Verified references (6)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Malicious Use for Attacks, Fraud and Disinformation.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Fraud”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/fraud/

← Back to the full catalogue