Threat Overview
Hong Kong’s Commercial Crime Bureau has warned of a surge in deepfake scams using AI-generated voice and video to impersonate company executives and trick employees into authorising fraudulent wire transfers.
Attack Method
Attackers typically:
- Research target companies and identify key decision-makers through public sources
- Generate convincing deepfake audio or video using AI tools, often impersonating CEOs or CFOs
- Contact finance department staff via video call or voice message
- Urgently request wire transfers to attacker-controlled accounts, often citing time-sensitive business deals
Reported Losses
In the first quarter of 2026 alone, Hong Kong businesses reported losses exceeding HK$280 million from deepfake-related fraud, representing a 340% increase compared to the same period in 2025.
Protective Measures
- Implement a verification protocol for all wire transfer requests (e.g., secondary confirmation through a different communication channel)
- Establish a “challenge question” system for urgent financial requests
- Train finance and administrative staff to recognise potential deepfake indicators
- Require in-person or multi-channel verification for transactions above a certain threshold
- Consider implementing AI detection tools for video and audio communications
Hong Kong operator checklist
- Confirm whether the systems, vendors, or practices described apply to your estate.
- Assign an owner and a review date — do not leave findings as unread newsletter content.
- Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
- Brief leadership with a dated one-page note when residual risk remains high.
What “good” looks like
- Controls are operated, not only documented
- Privileged access uses phishing-resistant MFA where feasible
- Detection and response paths are exercised at least annually
- Third-party dependencies have an owner and an exit plan
Sources and further reading
- HKISG Security Bulletins
- Assessment Methodology
- Governance & Integrity
- Online Education
- External: HKCERT · PCPD
Editorial note
This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.
Frequently asked questions
Who should read this?
Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.
Does this change any public HKISG rating?
No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.
How often is this content reviewed?
HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.