The scale of the threat, by the numbers
The deepfake threat is no longer emerging — it has arrived. The data from 2025 is unambiguous about both scale and acceleration.
verified deepfake incidents in Q3 2025 alone — the highest ever recorded in a single quarter.
Resemble AIin deepfake-related fraud losses in 2025, roughly tripling from ~$360M in 2024.
Surfshark Researchyear-on-year increase in deepfake incidents, Q2 2024 to Q2 2025.
Surfshark ResearchIn Australia, ASD's ACSC confirms AI is supercharging attacks: phishing laced with deepfakes featured in a majority of cyber incidents responded to in 2025, and large Australian businesses saw average cyber costs rise sharply, with AI-driven impersonation topping the list of new threats. These threats extend beyond financial loss — they erode trust in digital communication and can manipulate markets or sabotage supply chains through fake executive announcements or vendor impersonation.
Real-world case studies — what has already happened
These are not hypothetical scenarios. The incident below is one of the most thoroughly documented cases of 2024–2025, illustrating the tangible impact of deepfake impersonation on an organisation that believed its controls were sufficient.
Arup — $25.6 million, January 2024
A finance employee at the UK engineering and design firm Arup authorised 15 wire transfers — around HK$200 million — after joining a video call populated entirely by AI-generated colleagues, including a deepfake of the CFO. The voice and likeness were indistinguishable from the real executives. Standard verification procedures were bypassed through urgency and authority cues. Hong Kong Police confirmed the attack; the funds were never recovered.
This is not an isolated pattern. Gartner's 2025 AI Risk Management Survey found that 62% of organisations reported a deepfake incident in the prior 12 months, and separate executive-protection research puts the share of organisations reporting deepfake incidents specifically targeting executives at 41% — up from 34% just two years earlier. Common tactics include impersonation of a trusted contact with an urgent demand for payment or information.
In Australia, while individual corporate cases are less publicised, the ACSC reports rising AI-enhanced phishing in finance and government sectors, where deepfakes have increasingly facilitated credential theft and payment fraud.
The regulatory landscape — Australia and global
Regulatory responses to deepfake misuse are accelerating, but enforcement still lags the threat. Organisations should align with these frameworks now, rather than waiting for mandatory requirements to crystallise.
Laws effective November 2025 criminalise AI-generated violent or sexually degrading deepfakes, with penalties up to $20,000 or four years' imprisonment.
Introduced by Senator David Pocock in November 2025, proposing amendments to the Online Safety Act and Privacy Act requiring consent for using a person's face or voice in AI content, with new powers for the eSafety Commissioner.
The Criminal Code Amendment (Deepfake Sexual Material) Act 2024 already criminalises sharing non-consensual sexually explicit deepfakes, with penalties up to six years' imprisonment.
Both address non-consensual deepfakes at a regulatory level, though enforcement currently lags. Organisations with EU exposure or global operations should build these into their compliance strategy now.
Regulatory alignment is a floor, not a ceiling. Organisations that treat compliance as the target are already behind the threat — the evidence calls for a proactive, people-first approach that goes well beyond minimum obligations.
Building a robust culture — the four pillars
The foundation of deepfake defence lies in people. Technology helps, but organisations with proactive, people-first programs cut successful breaches significantly more than those relying on tools alone. Effective defence rests on four interlocking pillars.
Interactive simulations
Fake executive calls, glitched deepfake video, voice-cloned vishing. Employees learn to spot lip-sync drift and audio mismatch through live drills, not slides.
Monitoring & detection
AI-based anomaly detection, liveness checks that verify real-time human presence, and behavioural biometrics that flag mismatched typing or voice patterns.
Human-centric zero trust
No one is trusted by default for unusual requests — even from senior leadership. Code phrases for high-stakes communications, plus biometric MFA.
Incident response, phased
Assess, train, test, review. A dedicated response plan for detection, communication, and legal action — prepared before it's needed, not during.
What good deepfake awareness training looks like
Generic cybersecurity training does not prepare people for deepfake threats. Programs that actually work share specific traits: deepfake-specific indicators (unnatural facial movement, audio glitches, lip-sync drift), scenario-based simulations across email, calls, and video, executive-focused content for the people disproportionately targeted, clear second-channel verification protocols, and ongoing reinforcement — quarterly, not annual.
Effective defence turns employees into a human firewall — not through fear, but through genuine competence built over time.
That competence only develops through repeated, realistic practice — the same principle that runs through every Mono course.
Looking ahead — the deepfake threat, 2025 to 2028
Forecasts from research firms are unambiguous: deepfake-related threats will keep accelerating over the next two years. Organisations that build their defences now will be substantially better positioned than those who wait.
Deepfake fraud losses reach roughly $1.1 billion — tripling from 2024. Executive impersonation via voice and video becomes a standard attack vector, and cheap AI tools lower the skill barrier for attackers.
Detection spending projected to surge as deepfakes go mainstream across industries (Forrester). Deepfake-driven employment fraud escalates, with AI-generated interviews and résumés.
Generative AI fraud losses in the US alone projected to reach $40 billion, up from $12.3 billion in 2023 — a 32% compound annual growth rate (Deloitte Center for Financial Services).
Up to 80% of social engineering attacks could feature deepfakes without global standards on AI misuse (WEF). Organisations with people-first programs will be measurably more resilient than those without.
The threat is accelerating. But so is the shield — if you build it now.
What this means for your organisation
The threat is real and accelerating
2,031 verified incidents in Q3 2025 alone, $1.1 billion in losses, 62% of organisations already affected. This is a present risk, not a future one.
Technology alone is insufficient
Deepfakes exploit human trust, not software vulnerabilities. Detection tools help — but trained, vigilant people are the primary defence.
Verification protocols are essential
Code phrases, second-channel verification, and zero-trust habits need to become embedded behaviour — not procedures only remembered under pressure.
Proactive programs outperform reactive ones
Organisations that build people-first simulation programs now will be measurably more resilient than those waiting for a breach to act.
Build the human firewall before the attack arrives.
Click or Flick Corporate delivers deepfake-aware training, realistic simulations, and the behavioural reinforcement that turns awareness into instinct. If the evidence here concerns you, the program page is the right next step.