When the Video Call Lies: Professor Kai London on Deepfakes and the New Face of Payment Fraud

 By the Swiss Times Business Desk

Professor Kai London, board advisor and interim/fractional CISO, CIO and CTO
Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com

A finance employee joins a video call with colleagues they recognise, receives an urgent instruction, and authorises a large payment. Every face on the call was fabricated. The money is gone. Once a hypothetical, this scenario has already cost organisations tens of millions — and it represents, says Professor Kai London, a senior CISO and board advisor, a fundamental shift in the nature of fraud. “AI has industrialised deception,” he says. “The controls that assume you can trust a familiar face or voice are now obsolete.”

“For centuries, fraud prevention rested on recognising people and processes we trust. Generative AI has broken that assumption. In finance, that is not a curiosity — it is a live threat to the payment process itself.”

Why finance is the target

London explains that deepfake-enabled fraud gravitates to where the money moves fastest and the authorisation chains are human. Finance functions, treasury teams and payment approvers are natural targets because a single deceived decision can release large sums. “The attacker no longer needs to breach your systems,” he says. “They need to convince a person with authority that a fake instruction is real. AI has made that dramatically easier.”

The failure is a process failure

Crucially, London reframes the problem away from the technology and toward controls. “The deepfake is the weapon, but the vulnerability is a payment process that can be triggered by a convincing request,” he says. “If a single video call or voice message can move money, the process is the weakness — and the process is what you can fix.” That reframing is empowering, he argues, because it points to controllable defences.

Defences that do not depend on trusting a face

London's prescription centres on removing reliance on human recognition for high-value actions. Payments above thresholds should require verification through independent, pre-agreed channels — not the channel the request arrived on. Approvals should be separated so no single person, deceived or not, can release large sums alone. And staff should be trained to treat urgency itself as a red flag, since manufactured time pressure is the fraudster's oldest tool. “Verify out of band, separate the duties, and slow the urgent request down,” he says. “None of that depends on being able to tell a real face from a fake one.”

Decide before the crisis

London stresses rehearsing these scenarios in advance. “The moment to decide how you verify a large, urgent payment instruction is not when a panicked employee is on a call with what looks like the CEO,” he says. Tabletop exercises that walk executives and finance teams through a deepfake attempt, he argues, build the reflexes and the permission to pause that stop the fraud in the moment. “You are training people to feel comfortable saying ‘I will verify this and call you back’ — even to someone who appears to be the boss.”

A board-level risk

Because the losses are large, immediate and reputational, London places deepfake fraud firmly on the board agenda. “This is not an IT issue to delegate,” he says. “It sits at the intersection of security, finance and operations, and it can hit the balance sheet in a single afternoon. Boards should ask directly: could a convincing fake instruction move our money today, and what stops it?”

The wider lesson

For London, deepfake fraud is an early, vivid example of a broader truth: as AI grows more capable, the controls that assumed a human could reliably tell real from fake will keep failing. “The organisations that adapt will be the ones that built verification into their processes rather than into their people's intuition,” he says. “Trust, in the AI era, has to be engineered — not assumed.”

For a financial community whose business is moving money safely, the warning is timely and the remedy is within reach: assume the face on the screen might lie, and build a payment process that does not need to trust it.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Combating the CISO Exodus: New ‘90-Day Command Framework’ Stabilizes Cyber Risk During Executive Transitions

From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience

Why Governance Wins Deals: Professor Kai London on Turning Cyber Evidence Into Revenue