Insights — Scams

Deepfake and AI impersonation scams using executive likeness

This moved from a theoretical risk to a documented, multimillion-dollar problem in Singapore inside two years.


Deepfake impersonation of executives moved from an edge-case warning to a documented Singapore problem faster than most corporate security policies have adapted. The cases on record are specific enough to be worth knowing in detail.

What's actually happened

In one documented case, a company finance director was tricked into transferring over S$499,000 after joining a fake Zoom conference featuring deepfake impersonation of the company's CEO and colleagues. In a separate, more striking incident, a fabricated video conference purported to include Singapore's President, Prime Minister, a government minister and MAS representatives, alongside international figures — a fabrication sophisticated enough to warrant a formal police statement.

MAS has separately flagged deepfake risk directly to financial institutions, and the joint advisory from MAS, the Singapore Police Force and the Cyber Security Agency addresses this category of scam specifically, not as a hypothetical.

The regulatory response, current as of this writing

  • Enhanced banking safeguards took effect from October 2025, contributing to a measurable reduction in impersonation scam losses since introduction.
  • The Online Safety (Relief and Accountability) Bill, passed by Parliament in November 2025, established an Online Safety Commission with powers to direct takedowns, restrict perpetrator accounts, and assist victims identifying anonymous actors.
  • A "multi-layered approach" has been the explicit government framing — government agencies, banks, platforms and individuals all carrying part of the defence, not any single safeguard being treated as sufficient alone.

Why detection tools aren't the full answer

Deepfake detection technology exists and continues to improve, but documented losses have occurred despite its availability — sophisticated fabrications, delivered under time pressure in a live call, don't always trigger the doubt a viewer would apply with time to scrutinise. The more reliable defence is procedural rather than technical.

The defence that actually holds up isn't spotting the fake in the moment. It's a verification step that doesn't depend on trusting what's seen or heard at all.

What actually works procedurally

Out-of-band verification for any high-value or unusual request, even one that appears to come from a live video call with a recognisable executive — a callback to a known number, not a number provided on the call itself.

A standing rule that no financial transfer is authorised solely through a video or voice call, regardless of how convincing it appears, without a separate confirmation channel.

Executive-level awareness that their own likeness is a target, independent of whether they've personally been impersonated yet — the exposure exists the moment enough public video and audio of someone exists to train a convincing model, which for most senior executives is already true.

If it happens to you

The response sequence — platform reporting, police report, a clear public statement, direct notification to likely targets — is covered in full in our guide to investment-scam impersonation, which applies directly to deepfake-specific incidents as well.

Common questions

Straight answers

How real is the deepfake scam risk for Singapore executives?

Very real and documented — cases include a company finance director transferring over S$499,000 after a fake Zoom call impersonating the CEO, and a separate fabricated video conference impersonating senior government officials and MAS representatives.

What has Singapore done in response?

MAS, the Singapore Police Force and the Cyber Security Agency issued a joint advisory on digital manipulation scams, enhanced banking safeguards took effect from October 2025, and the Online Safety (Relief and Accountability) Bill passed in November 2025 established an Online Safety Commission with takedown powers.

Can deepfake video be reliably detected?

Detection tools exist and are improving, but they're not foolproof, and financial institutions have reported material losses despite them — the more reliable defence is procedural, not technical: verification steps that don't depend on trusting what's seen or heard on a call.

Related

When scammers use your name to run an investment scam

Impersonation scams move fast and the response has to move faster — the first 24 hours determine how far it sp

Read more

Brand protection monitoring: what to actually track

A Google Alert catches a fraction of what's actually out there. Here's what a real monitoring programme covers

Read more

What to say in the first hour of a crisis

The first statement doesn't need to have every answer. It needs to not create new problems while the real answ

Read more

Private enquiry

Send us what you are dealing with.

We will tell you which route applies before you spend anything.