James McGachie: AI deepfakes expose Scottish businesses to new fraud threat
James McGachie
AI-powered fraud is exposing Scottish businesses to increasingly sophisticated deepfake scams that can bypass traditional cybersecurity defences, writes James McGachie.
A director joins a video call with the chief financial officer and several senior colleagues. An urgent series of transfers is requested and complied with, wiring multi-millions in payments across multiple transactions. Other than the director, every face on the screen is fake, every voice generated by artificial intelligence. This isn’t hypothetical. It happened to Arup, one of the world’s largest engineering firms, after an employee in its Hong Kong office joined a call populated entirely by deepfake executives.
This is the new front line of cybercrime. The World Economic Forum’s 2026 Global Cybersecurity Outlook marks a turning point: cyber-enabled fraud has overtaken ransomware as the number one concern for businesses worldwide. Seventy-three per cent of respondents said they or someone in their professional network had been personally affected by fraud in 2025.
In the UK, the picture is stark. UK Finance reported nearly £1.3 billion in fraud losses in 2025, up 11 per cent from the previous year, with investment scams soaring 40 per cent to record highs.
What makes this a step change, not an evolution, is the technology behind it. Deception has been industrialised through the use of AI. IBM’s 2026 data shows 37 per cent of phishing attacks use AI-generated content, while 35 per cent of breaches involve deepfakes as an attack method.
AI can strip away spelling errors, clumsy formatting, and implausible scenarios that once helped employees spot a fake. It can produce flawless emails in seconds, clone a voice from a few seconds of audio, and create convincing video that fools a trained professional on a live call.
Traditional defences – spam filters, firewalls, antivirus software – were not built for this. These attacks target human judgment, not technical infrastructure.
Scotland is not immune. In December 2025, the Scottish Parliament’s Criminal Justice Committee reported that cyber-enabled fraud now accounts for roughly half of all recorded fraud in Scotland.
For Scottish businesses, particularly mid-sized ones and professional services practices that handle significant transactions without dedicated fraud teams, the threat is acute and growing.
Threat extends beyond deepfake calls. In its 2025 Annual Review, the National Cyber Security Centre warned UK firms are “almost certainly” being targeted by North Korean state operatives posing as freelance IT workers, using AI-generated identities and deepfake video interviews to secure remote employment, including privileged access to corporate systems. When the very people you hire may not be who they claim to be, the attack surface is not your firewall but your entire hiring and payment approval process.
The practical response starts with process, not technology: multi-person approval for payments above a defined threshold; identity verification for remote hires that goes beyond a video call; staff training that includes AI-specific scenarios and threats, such as deepfake calls, cloned voices, and synthetic documents; board-level ownership of fraud risk, not delegation to IT.
The regulatory direction is clear. The UK’s Cyber Security and Resilience Bill will strengthen obligations on businesses to manage cyber risk, including new supply chain due diligence duties requiring regulated entities to understand and manage the cybersecurity risks posed by their suppliers and service providers. That obligation could not be more timely. But regulation follows the threat – it does not prevent it.
Criminals have moved on from locking your systems and demanding bitcoin. They now sit in your video calls, wearing your CEO’s face, and asking for money directly.
The question for every Scottish business leader is simple: would your workforce spot the difference?

James McGachie is a partner at DLA Piper. This article first appeared in The Scotsman.



