Skip to content
FortaRisks
Back to blogAI

AI security (5/8): offensive AI, and the one control that still holds

October 1, 2026 · 5 min read

The first four episodes looked at the AI you use: the inventory of uses, who answers for it, the risks specific to language models, your vendors' AI.

This episode switches sides of the table. It is about the AI other people use against you, and one simple question: if your CFO called you tomorrow with their voice, their face and a good reason, what would stop the wire transfer?

What has really changed

The text no longer gives anything away

For years, phishing awareness came down to one tip: look for the mistakes. That tip is obsolete. As we wrote in June, more than 80% of phishing emails now contain AI-generated content. The message reads as if your vendor wrote it, in your language, with your industry's vocabulary, and it took minutes to produce.

A voice and a face no longer prove anything

In February 2024, an employee in the Hong Kong office of Arup, the British engineering firm, joined a video call with the group's CFO and several colleagues he knew. He had doubted the email about a confidential transaction at first. The meeting removed his doubts. Every other participant was a deepfake. He made fifteen transfers, about 25 million US dollars. Arup later confirmed that none of its systems had been compromised.

That is the point to keep: nothing was hacked. No firewall, no EDR, no email filter had anything to detect. The attack went through a business process, not through infrastructure.

The pretext disables the check

The third change is the subtlest. In September, our weekly review covered the Phantom Deal campaign documented by Gen Digital: a WhatsApp message in the name of a known executive, then a fake adviser who sends a non-disclosure agreement branded with a major firm's logo, for a secret acquisition. The document requires everything to go through WhatsApp and personal email, and colleagues to be kept out. The target: 626,735 euros to Hong Kong.

The NDA is not decoration. It justifies the secrecy in writing, and so forbids the one move that really protects you: asking a colleague. The attempt failed because the employee noticed that a voice did not match. In other words, by luck, and the next voice will be better.

What has not changed

AI has made the cheap version of social engineering as convincing as the expensive version used to be. It has not changed how the story ends. Every attack in this family ends with one of four requests:

  1. Pay: an urgent, confidential transfer, outside the usual process.
  2. Change bank details: a vendor's, or an employee's direct deposit.
  3. Give back access: reset a password or an authentication factor, often an executive's, by phone at the service desk. That is exactly what happened to Abbott.
  4. Send data: payroll files, tax slips, a customer list.

That is excellent news. You cannot win the race to detect fakes; the fakes get better every month. You can, however, control four requests.

The one control that still holds

It fits in one sentence: none of these four requests is carried out without verification through an independent channel, chosen by the person who executes, never by the person who asks.

Every word matters.

  • An independent channel. Not a reply to the email, not a call back to the number in the signature, not the video call in which the request was made. A number taken from the internal directory or the vendor file, established before the request.
  • Chosen by the person who executes. The person in accounts payable, payroll or the service desk decides how they verify. If the requester offers a way to verify, that is a signal, not help.
  • No exceptions. Not for urgency, not for confidentiality, not for seniority. Urgency and secrecy are precisely the two levers of the attack. A rule with an exception for the CEO protects everyone except the CEO.

Two additions make the rule workable. A second approver for any new bank details, with a waiting period before the first payment. And phishing-resistant authentication (FIDO2, passkeys) for finance, leadership and administrators, because a code received by text message can be relayed in real time.

This control looks old-fashioned. That is the whole point: a synthetic voice cannot get past a control it never touches.

The test: fifteen minutes, one table, four rows

Do it this week, with the person who runs payments and the person who runs the service desk.

Draw a table with one row per request and three questions as columns:

| Request | Through which channel do we verify, concretely? | Who chooses the number? | What if the requester invokes urgency or secrecy? | | ------------------- | ----------------------------------------------- | ----------------------- | ------------------------------------------------- | | Pay | | | | | Change bank details | | | | | Give back access | | | | | Send data | | | |

Fill it in with what actually happens, not with what the policy says.

Three answers should worry you. "We call the person back", with no word on which number. "It depends on who is asking." And, in the last column, any answer containing the word "exception".

Then ask the question that matters to the person in accounts payable: "If our CEO calls you from their cell phone, on video, for a confidential transfer linked to an acquisition, what do you do?" If they hesitate, they are not the problem. The problem is that nobody ever gave them the written right to say no to the CEO.

What you should have by Friday

The table filled in, with the empty or vague cells highlighted. A half-page verification rule, signed by leadership, that explicitly forbids exceptions for urgency and confidentiality, and gives the person executing the right to refuse. And the named list of people who must move to phishing-resistant authentication by the end of the quarter.

If you want to place this risk among the others, the free cyber risk score gives you a reading of your data, third-party and resilience domains in ten minutes.

Episode 6, on 8 October: ISO 42001 and the NIST AI RMF, where to start. Two frameworks to structure everything the first five episodes put in place, and how to avoid turning it into one more compliance project.

Sources: CNN, Arup revealed as victim of a $25 million deepfake scam · Dark Reading, fake merger and acquisition scams

Governing AI

AI now has its frameworks: ISO 42001, NIST AI RMF

Governing AI does not mean starting from scratch. These frameworks are assessed on the same control backbone as your ISO 27001, so the work already done counts.