How Deepfake Fraud Manufactures Institutional Trust

The Governance Illusion Series
The Meeting That Never Happened: When AI Learns to Manufacture Trust
In May 2026, a business professional in Singapore attended what appeared to be an extraordinary virtual meeting. The invitation had supposedly come from the Secretary to the Cabinet. Prime Minister Lawrence Wong appeared to participate. President Tharman Shanmugaratnam was apparently present. So was Minister Indranee Rajah. The meeting appeared to include representatives of the Monetary Authority of Singapore, foreign government officials and private-sector participants including BlackRock and the Dubai International Financial Centre. The discussion concerned the situation in the Straits of Hormuz, and the participant had previously received what appeared to be an official letter of guarantee bearing the Prime Minister's signature, together with a non-disclosure agreement. The setting was authoritative, confidential, international and apparently legitimate. There was only one fundamental problem: the meeting had never happened.
Singapore Police subsequently revealed that the virtual conference had been fabricated, with portions manipulated using deepfake AI technology. The victim had initially been contacted through WhatsApp by somebody impersonating the Secretary to the Cabinet and was subsequently drawn into the fabricated meeting. After it concluded, a supposed lawyer continued the engagement, and the victim ultimately transferred at least $4.9 million through a series of transactions to a corporate bank account controlled by the scammers. Only afterwards did the victim contact the real Secretary to the Cabinet and discover that the elaborate institutional world presented to him had been manufactured.
It would be easy to dismiss this as another example of an individual being deceived online. That would be a serious mistake.
The Singapore case is interesting precisely because the deception was not based on one obviously suspicious email, an improbable investment opportunity or a badly constructed video of a celebrity promising extraordinary returns. The criminals manufactured an entire environment of credibility.
Authority was layered upon authority: government, senior officials, confidentiality, legal documentation, international institutions, recognised corporations and a geopolitical emergency.
The victim was not simply asked to believe a fake person. He was placed inside a fake institutional reality.
That distinction should concern every board, Compliance Officer, Risk Officer, MLRO, CFO and (re)insurer.
We have spent decades designing corporate controls around a relatively stable assumption: people, documents and institutions can ultimately be authenticated. Artificial intelligence is beginning to attack all three simultaneously.

The Risk Is Not the Deepfake. The Risk Is Trust.
The most important lesson from Singapore is not that AI can generate convincing video. We have known that for years. The more uncomfortable lesson is that sophisticated fraud no longer needs to falsify a single element of a transaction.
AI allows criminals to manufacture the entire context in which a decision is made.
The Singapore fraud was psychologically sophisticated. The victim was not simply shown a fake Prime Minister and immediately asked for money. According to the Police, the process included communications supposedly originating from the Secretary to the Cabinet, an NDA, a purported government letter of guarantee and a virtual conference populated by figures whose positions carried enormous institutional authority.
The supposed purpose of the funding was linked to the geopolitical situation in the Straits of Hormuz. The individual was therefore being asked to process not one signal of authenticity but many mutually reinforcing signals.
This is important because conventional fraud controls frequently operate in exactly the same way. Employees are trained to look for inconsistencies. Does the email address look correct? Does the person sound familiar? Is the request consistent with the individual's position? Is documentation available? Can the request be independently confirmed? If necessary, arrange a video call.
But what happens when the fraudster can manufacture every element?
What happens when the email is supported by a letter, the letter is supported by a signature, the signature is supported by a video call, the video call contains several apparently legitimate participants and the participants discuss a real geopolitical event?
At some point, the volume of apparently independent evidence stops triggering suspicion and starts manufacturing certainty.
This is why deepfake fraud should not be treated merely as another category of cyber fraud. They challenge the architecture through which organisations establish trust.
Would Your Employees Have Detected It?
There is an uncomfortable tendency after sophisticated frauds to focus on the person who authorised the payment. Why did the employee believe it? Why did he not verify the instruction? Why did he transfer the money? Why did he not notice that something was wrong?
These questions are legitimate, but they can also become an easy way for organisations to avoid examining their own vulnerabilities.
The more useful question for a board is much harder: Would our people have detected it?
Singapore Police identified several defects in the fabricated conference. Lip movements did not always synchronise with speech. Audio appeared to be transmitted through a single account rather than through the individual participants. There were distorted backgrounds and inconsistencies involving the Zoom interface. More recent analysis of the footage found additional weaknesses, including apparently passive participants whose video feeds were looping and a single account effectively transmitting different speakers.
Looking at those clues after the fraud has been exposed is easy. Detecting them while participating in what appears to be a confidential government meeting concerning a geopolitical crisis is something entirely different.
This distinction matters enormously for employee training. Organisations frequently respond to emerging fraud threats by issuing another circular, adding another slide to annual compliance training or telling employees to “remain vigilant.” But vigilance is not a control framework. Employees cannot reasonably be expected to become forensic specialists capable of detecting every synthetic voice, manipulated image, cloned executive or AI-generated document they encounter.
Training remains essential, but the objective must change. We should stop trying to train employees to become human deepfake detectors and start training them to recognise situations in which identity itself can no longer be accepted as sufficient evidence of authority.
The employee should not need to determine whether the Prime Minister on the screen is real. The control environment should determine whether the transaction can proceed regardless.
That is a fundamental change.
The Four-Eyes Principle Has a New Problem
The four-eyes principle is deeply embedded in financial services and corporate governance. Material decisions require independent approval because two humans are assumed to provide greater protection than one.
AI complicates that assumption. What happens to four-eyes approval when two of the four eyes can be manufactured?
A CFO receives an unusual payment instruction from the CEO and correctly refuses to rely on email. He requests a video call. The CEO appears on screen, together with another director. Both confirm the instruction. The CFO therefore follows precisely the escalation process the organisation designed.
Has the CFO failed? Or has the control failed?
This distinction will become increasingly important. A governance framework that relies upon visual or vocal confirmation may already be weaker than its designers believe. A video callback is not necessarily independent verification if the person answering can be synthetically recreated. Voice recognition is not necessarily authentication when voices can be cloned. A document signed by a senior executive provides diminishing comfort when documents and signatures can be generated at scale.
The question for boards is therefore no longer simply whether adequate controls exist. It is whether those controls remain valid in the technological environment in which the organisation now operates.
A control can exist, be properly documented, consistently followed and still become obsolete. That may be one of AI's least appreciated governance risks.
AI Is an Unknown Risk Because We Do Not Control Both Sides of It
Much of the corporate discussion about AI governance focuses on how organisations themselves use artificial intelligence. Companies establish acceptable-use policies, approve particular tools, restrict confidential information, create model inventories and establish governance committees. These measures are necessary, but they address only half of the exposure.
The organisation may govern its own AI. It cannot govern the AI being used against it.
This creates an unusual asymmetry. A regulated financial institution may spend millions ensuring that its AI systems satisfy internal standards while a criminal organisation operating anonymously from another jurisdiction uses unrestricted models specifically designed to circumvent those controls. Legitimate developers may impose safeguards, identity requirements and restrictions on harmful uses, while illegal developers, modified open-source models or criminal services have no reason to observe equivalent standards.
The emerging AI ecosystem therefore contains actors operating under radically different governance conditions. Some developers are publicly listed technology companies subject to regulation, litigation, reputational pressure and contractual obligations. Others may be small developers. Some models are open source. Some can be modified. Others may be deliberately engineered for fraud, impersonation, malware or circumvention of safeguards.
Criminal groups do not need their models to be ethical, explainable, unbiased or compliant. They need them to work.
This makes AI risk fundamentally different from many conventional corporate technology risks.
The organisation is not simply managing the risks arising from technology it chooses to deploy. It is defending itself against technological capabilities whose developers, users, location, standards and intentions may be completely unknown.
How does a board establish a risk appetite for that? How does an insurer price it? How does a regulator write rules for it? And who is accountable when the technology that causes the loss was created specifically to operate outside every rule?
We Are Regulating the Legitimate Side of the Market
This creates an uncomfortable regulatory paradox. Governments around the world are developing frameworks intended to make legitimate AI safer, more transparent and more accountable. Yet many of the most dangerous AI applications may originate from actors who have no intention of complying with those frameworks.
A licensed financial institution can be required to establish AI governance. A major technology company can be subject to transparency requirements. A regulated insurer can be required to assess model risk.
A criminal developer operating anonymously cannot.
This does not make regulation pointless. It does, however, mean that regulation alone cannot solve the problem. Indeed, there is a danger that the regulated economy becomes increasingly sophisticated in governing its own use of AI while underestimating the capabilities of an unregulated AI economy developing alongside it.
Singapore itself illustrates how rapidly authorities are having to adapt. In August 2026, the Government explained that measures under the Online Criminal Harms Act require designated online services to detect and remove deepfakes used for scams, including user-verification measures and facial-recognition technology. Singapore is also considering stronger methods for identifying genuine government communications. New Codes of Practice issued on 17 August introduce additional anti-scam requirements for designated messaging, conferencing, social-media and e-commerce services, with specific measures addressing government impersonation.
Yet another official response reveals how difficult the problem is to measure. In July 2026, Singapore's Ministry of Home Affairs stated that the Police do not separately track the requested number of AI-generated deepfake impersonation reports because establishing whether content was AI-generated can require detailed forensic examination and may not always be conclusive.
That statement deserves attention from risk professionals.
We are trying to calculate an emerging risk that we may not yet even be able to reliably classify after it occurs. Let’s repeat it and perhaps we will comprehend it.
The Training Problem Is Bigger Than Compliance Training
Employee training must consequently evolve much faster. A thirty-minute annual e-learning module explaining deepfakes will not be enough. Neither will an email from Compliance warning employees that AI scams are becoming more sophisticated.
The training needs to challenge human instincts.
Authority creates compliance. Urgency suppresses scepticism. Confidentiality discourages consultation. Familiar faces create trust. Seniority makes junior employees reluctant to challenge instructions. Multiple participants create social proof. Technical sophistication creates credibility.
The Singapore fraud appears to have exploited several of these mechanisms simultaneously.
That is why training should increasingly be behavioural rather than purely informational. Employees need permission to challenge seniority. They need to understand that an urgent instruction from a CEO deserves more verification, not less, when it involves an unusual transaction. Confidentiality should never eliminate independent authentication. No employee should fear delaying a multimillion-dollar payment because he or she wants to verify an instruction through a separately established channel.
Boards also need to understand something uncomfortable: if an employee follows an apparently authoritative instruction because the organisation's culture discourages questioning senior people, the resulting AI fraud is partly a culture risk.
Technology may have delivered the attack. Governance may have created the vulnerability.
Who Pays the $4.9 Million?
Then comes the insurance question.
Suppose the same scenario occurs inside a corporation. An employee attends a deepfake meeting with the supposed CEO and CFO and transfers millions of dollars in accordance with the instructions received.
Which policy responds?
Crime insurance may become relevant, but the insurer may examine whether verification procedures were followed. Cyber insurance may be disputed if no corporate system was technically breached. Professional indemnity may be irrelevant. D&O insurance could enter the picture later if shareholders allege that directors failed to establish appropriate controls despite known deepfake risks. Banks may face questions regarding transaction monitoring. Technology providers may face claims concerning authentication or detection capabilities.
Should the insurer pay?
If the insurer argues that the company should have implemented deepfake-resistant authentication, when did that expectation become an accepted standard of reasonable governance? Was it written into the policy? Was it required by regulation? Would an ordinary board reasonably have known that its existing verification procedures were obsolete?
AI is moving faster than the standards against which negligence is normally judged. That gap between technological capability and established standards of reasonable control may become one of the most difficult insurance disputes of the next decade.
The Board's Deepfake Problem
Ultimately, this returns to the boardroom.
Boards should not respond to the Singapore case by asking management whether the organisation has deepfake-detection software. That would reduce a governance problem to a technology procurement exercise.
They should ask much harder questions.
Which transactions within our organisation still depend primarily upon recognising a person's face or voice?
Which critical instructions can be authorised remotely?
How would we authenticate an emergency instruction supposedly coming from the CEO?
Can employees challenge instructions from directors without fear?
What happens if a criminal simultaneously impersonates several executives?
Could our current payment controls survive that attack?
Do our incident-response procedures distinguish between compromised credentials and compromised identity? Do our insurers understand the exposure?
Have we tested the scenario?
And perhaps the most uncomfortable question:
If tomorrow morning our CFO receives a convincing video call from three members of this Board instructing an urgent $20 million payment, what exactly prevents the money from leaving?
If nobody around the table can answer that question confidently, the organisation has discovered a governance risk.
Not an AI problem. Not an IT problem. A governance risk.
The Governance Illusion Has Acquired a Face
The Singapore case should change the way we think about AI risk because it demonstrates that AI does not merely automate decisions, generate content or improve productivity. It can manufacture the evidence upon which humans make decisions.
That is a fundamentally different threat.
The old fraudster had to convince an employee that he was trustworthy.
The AI-enabled fraudster can manufacture the person the employee already trusts.
He can manufacture the CEO, the minister, the lawyer, the colleague, the customer, the regulator and potentially an entire meeting of people whose combined presence makes the request appear beyond reasonable doubt.
This is why the response cannot simply be better deepfake detection. Detection technology will improve, and generation technology will improve with it. The contest will continue.
The more durable response is to redesign governance around a world in which seeing is no longer verification, hearing is no longer authentication and familiarity is no longer proof of identity.
Singapore's $4.9 million loss is therefore not interesting because somebody was fooled by artificial intelligence. Humans have been fooled since commerce began. It is interesting because the fraudsters demonstrated how cheaply and convincingly institutional trust can now be manufactured.
And that should leave boards with a much more disturbing question than whether their employees know what a deepfake looks like.
How much of our control environment still depends on believing what we see?
The factual backbone here is unusually strong because the Singapore Police released both the case details and footage analysis, and Singapore has subsequently introduced additional anti-scam measures addressing messaging, conferencing and impersonation risks.
Perhaps the greatest irony of the AI revolution is that, after years of engineering the human out of business interactions, the most sophisticated defence against a deepfake may turn out to be the least sophisticated technology of all: a handshake.
Is Your Governance Framework Ready for Deepfake Fraud?
Pnyx Hill works with boards and regulated organisations to assess whether their governance frameworks, internal controls and decision-making protocols remain effective as AI-enabled risks evolve.
Our Governance, Risk and Compliance advisory team supports institutions in strengthening board oversight, control design, risk management and executive training against emerging threats. We assess where deepfake fraud could expose weaknesses in your organisation.
