Every story tagged Fraud Prevention, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
12 stories · open in the command center
Scammers are increasingly exploiting FaceTime's video calling feature to impersonate financial institutions and conduct social engineering attacks, exploiting the psychological trust that live video communication generates. This emerging threat poses significant risk to enterprise security, as employees may inadvertently expose sensitive corporate data or credentials through seemingly legitimate video interactions. IT organizations must implement employee awareness training and leverage Apple-specific security controls to detect and prevent such impersonation attempts across managed device fleets.
Research demonstrates that AI chatbots outperform human scammers at building trust during fraud schemes, with nearly half of test subjects complying with AI requests versus fewer than one-fifth for humans, creating a significant cybersecurity threat that could scale fraudulent operations and bypass existing LLM safeguards. This evolution in fraud tactics represents a critical business risk for organizations, as scammers can now automate the trust-building phase at scale before handing off to humans only for final exploitation, potentially increasing fraud losses across financial services, investment platforms, and customer-facing businesses. IT and security leaders must recognize that traditional content filters and vendor safeguards are increasingly ineffective against hybrid human-AI fraud operations, requiring new detection strategies that focus on relationship patterns and behavioral anomalies rather than language-based safeguards alone.
AI-enabled voice fraud has become a mainstream financial crime threat, with reported losses exceeding $893 million in 2025—and actual losses likely far higher—with older adults as the primary targets; the technology requires only 3 seconds of publicly available audio to create indistinguishable synthetic voices, while detection and prevention capabilities remain critically underdeveloped across financial institutions and telecom providers. For IT leaders, this represents a convergence of technical sophistication and organizational unpreparedness: existing security frameworks were not designed to defend against fraud that bypasses traditional authentication and exploits the emotional vulnerability of callers, requiring urgent investment in voice authentication, fraud detection systems, and employee training. The industrialization of fraud by transnational criminal organizations—coupled with agentic AI systems that can autonomously execute campaigns—signals that legacy defenses are obsolete and that IT organizations must fundamentally rearchitect identity verification and transaction authorization workflows.
AI-powered voice cloning and generative tools have dramatically lowered barriers for consumer-targeted scams, with losses from imposter scams tripling to $3.5 billion in 2025, creating an urgent new threat vector that IT leaders must address beyond traditional enterprise security. Savi Security's new app provides real-time AI-based detection and live-call monitoring to protect consumers, signaling that organizations need to extend security awareness and defensive capabilities to employees' families and the broader consumer ecosystem. This emerging threat landscape requires IT leaders to reevaluate their security posture, implement user education programs around AI-generated scams, and potentially integrate consumer-grade protective tools into corporate risk management strategies.
Australia's mandatory SMS/MMS Sender ID registration requirement will significantly impact how organizations communicate with customers and employees, requiring IT and compliance teams to update messaging infrastructure and maintain sender registries. This regulatory change affects telecommunications operations, customer engagement platforms, and internal communications systems, necessitating coordination between IT, compliance, and business units to ensure organizational messaging remains operational and compliant. Technology leaders must prepare for potential service disruptions during the transition period and budget for updates to communication systems and process changes.
Elderly fraud has evolved into a $64 billion/year industrialized criminal enterprise using sophisticated technologies (voice cloning, deepfakes, remote access tools) that exploit cognitive vulnerabilities in aging populations, creating a critical cybersecurity and organizational risk that extends beyond traditional IT security boundaries. The article argues that technology professionals have a responsibility to develop protective solutions and assist law enforcement in gathering admissible evidence, as loneliness drives seniors toward digital platforms where they become vulnerable, presenting both a humanitarian imperative and a legal/compliance opportunity for IT organizations. Technology leaders should recognize this as a systemic business continuity and reputation risk affecting customers, employees' families, and organizational liability.
Google is expanding deepfake call detection across Android devices to combat a $3 billion annual scam threat, requiring users to adopt Google's Phone, Contacts, and Messages apps—creating both a security opportunity and ecosystem lock-in concern for IT leaders. While this addresses a critical emerging threat to organizational users, the feature's effectiveness depends on widespread adoption of specific Google applications and requires IT teams to evaluate compatibility with Samsung, OnePlus, and enterprise communication preferences. Additionally, Google is expanding AirDrop support and AI features across Android, signaling continued platform fragmentation challenges that require IT policy updates.
Google's new fake call detection feature uses device verification signals to combat AI-powered voice impersonation scams, automatically alerting users when calls from trusted contacts fail authentication checks. This capability, built on RCS technology and rolling out to Android 12+ devices globally, represents a critical security advancement as scammers increasingly leverage deepfake audio to impersonate family members and authority figures. IT leaders should recognize this as both a consumer protection benchmark and a signal that enterprise communications security strategies must evolve to address similar AI-driven impersonation threats to organizational infrastructure and employee safety.
Google is deploying AI-powered call authentication in its Phone app to detect and flag impersonation scams that exploit contact spoofing and AI voice synthesis, addressing a critical security vulnerability that cost Americans $893 million in 2025. The feature leverages end-to-end encrypted RCS technology to verify caller identity through device-level confirmation signals, setting a new standard for telecom security that IT leaders should monitor for enterprise implications and potential adoption across corporate communication systems. This represents a significant shift in how enterprises must approach mobile security strategy and user authentication, requiring alignment between device manufacturers, telecom providers, and security frameworks.
Payment processors like Stripe have significant blind spots in fraud prevention, particularly with 'friendly fraud' where legitimate cardholders dispute valid transactions after receiving goods—a gap that undermines merchant trust and exposes the limitation of machine learning systems that lack cross-merchant signal sharing. While card networks and banks make final chargeback decisions, sophisticated payment platforms could do more to leverage accumulated fraud evidence to protect ecosystems, yet currently leave individual merchants vulnerable with limited recourse and require additional paid tools to address known bad actors. This represents both a technology architecture challenge and a business risk for organizations dependent on payment platforms, as the cost of fraud tolerance is ultimately passed to legitimate merchants through losses and increased operational burden.
Apple's App Store blocked $2.2B in fraudulent transactions and rejected over 2M problematic app submissions in 2025, demonstrating the significant security and trust infrastructure required to operate a large-scale digital platform. For IT leaders, this highlights the substantial investment and complexity involved in maintaining platform security, fraud prevention, and compliance at enterprise scale—underscoring the business risk of inadequate security controls in digital ecosystems. Organizations should evaluate whether their own application governance, fraud detection, and security review processes match the rigor Apple has established as an industry baseline.
Google is implementing AI-powered security features in Android that will automatically block spoofed banking scam calls by verifying with banks whether incoming calls are legitimate, addressing a problem that costs victims nearly $1 billion annually worldwide. The update also enhances device theft protection through biometric locks and connection restrictions, plus introduces dynamic app monitoring to detect and prevent data-stealing malware. For IT leaders, this represents a significant shift in how mobile security is managed—moving from user-dependent vigilance to proactive, OS-level threat prevention that reduces both user risk and potential organizational liability from compromised employee devices.