The Threat Landscape
How AI is turned against financial institutions
This module sets out the evidence. It describes how generative and agentic AI have changed the economics of financial crime: deepfake voice and video fraud, AI-synthesised identity documents, fraud-as-a-service marketplaces, and multi-step schemes run by AI systems that plan and act with limited human input. Each attack type is anchored in published figures and named cases, including the South African evidence. By the end you can describe the principal attack types, cite the leading sources when you make the internal case for AI-risk competency, and map where your own institution is exposed.
- Describe the principal AI-enabled attack types now facing financial institutions, and the direction in which the published trends are moving.
- Cite the leading evidence, including the South African fraud data, to make the internal case for AI-risk competency.
- Recognise where the institution is exposed to these attacks across onboarding, payments, advice and lending.
- Threat-model literacy
- Reading fraud and identity-verification reports critically
- Translating threat intelligence into desk-level vigilance
- Making the evidence-based internal case
Lessons in this module
How it lands across the four desks
Every attack type in this module arrives at your desk: synthetic documents at onboarding, deepfake-authorised payments, and AI-automated schemes designed to move faster than a rules engine can respond. You leave with the full attack taxonomy and the trend data behind it.
You are usually the person who maintains the exposure map. This module gives you the evidence base, meaning regulator alerts, threat-intelligence data and the named cases, to brief a board, support a case for control spending, and record that the institution understood its threat environment.
Your clients and your own recorded likeness are both targets: deepfake investment scams using synthetic video of trusted figures, impersonation of advisers, and social engineering built from scraped client data. You learn the patterns your clients are most likely to meet.
Manipulated and fabricated application inputs are the main risk on your desk: AI-polished payslips, invented income histories, and identities assembled specifically to pass onboarding and default later. This module shows you the industrialised supply chain behind them.
Key literature · 6 sources
Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.
- Europol (2024) 'Internet Organised Crime Threat Assessment (IOCTA) 2024': the fraud-as-a-service supply chain, including AI-generated identity documents sold to defeat onboarding.
- FinCEN (2024) 'Alert FIN-2024-Alert004: Fraud Schemes Involving Deepfake Media Targeting Financial Institutions': the operational alert and red-flag indicators.
- FATF (2025) 'Horizon Scan: AI and Deepfakes — Impacts on ML/TF/PF': the detection-lags-generation finding that frames the defensive posture.
- SABRIC (2024) 'Annual Crime Statistics 2023': the South African loss and trend anchor, with generative AI named among drivers.
- SARB Prudential Authority & FSCA (2025) 'Artificial Intelligence in the South African Financial Sector': adoption, risk rankings, the skills-shortage finding, and the announced discussion paper.
- U.S. Federal Reserve (2019) 'Synthetic Identity Fraud' payments-fraud insights: the definitional treatment of synthetic identities and bust-out patterns.