Learn It. Grow It. Own It.

What is real?

Aug 18, 2026
Collage of faces

Excuse Me… Are You Actually You? Fraud in the Age of Synthetic Everything

There was a time when fraudsters had to work a little harder.

They needed stolen letterhead. A forged signature. Maybe a fake ID and a reasonably convincing story. The really ambitious ones might even buy a nice suit.

How quaint.

Welcome to fraud in 2026, where the person on your video call may not be the person you think they are, the voice on the telephone may never have spoken those words, the résumé may belong to someone who doesn't exist, and the supporting documentation may have been created approximately 37 seconds before it landed in your inbox.

And here's the uncomfortable part.

It can all look perfectly legitimate.

We Have Entered the Age of Synthetic Fraud

Synthetic fraud isn't entirely new. Fraudsters have been combining real and fictitious information to create identities for years.

Artificial intelligence has changed the economics of it.

Generative AI can help create photographs, documents, voices, correspondence and entire digital personas at a speed and quality that would once have required considerable skill and effort. Fraudsters can potentially combine genuine stolen information with invented details to create identities convincing enough to slip through traditional verification processes.

Industry observers are already identifying synthetic identity fraud as one of the significant fraud concerns of 2026.

But synthetic identity is only part of the story.

We're moving toward synthetic everything.

Synthetic employees.

Synthetic vendors.

Synthetic customers.

Synthetic invoices.

Synthetic photographs.

Synthetic receipts.

Synthetic voices.

Synthetic executives.

Perhaps even synthetic evidence.

Suddenly, the fraud question isn't simply:

"Is this transaction legitimate?"

It's:

"Is any of this real?"

"But Denise, I Saw Him on Teams!"

Wonderful.

Did you?

Deepfake technology is making visual confirmation increasingly unreliable. Voice cloning creates another wrinkle. A familiar voice asking an employee to urgently make a payment no longer provides the comfort it once did.

We've spent years teaching employees to look for the traditional warning signs of phishing and social engineering.

Bad grammar.

Strange wording.

Odd formatting.

Suspicious email addresses.

But generative AI can produce polished, professional, contextually appropriate communications in seconds.

The badly written scam email from the mysterious prince promising you $14 million may eventually become a nostalgic memory.

Today's fraudster can sound like your CEO.

Tomorrow's may look like your CEO too.

The Employee Who Doesn't Exist

Here's where things become particularly interesting for auditors, fraud professionals and HR teams.

What happens when the fraudster doesn't break into your organization?

You hire them.

Remote hiring has created tremendous opportunities for organizations and employees. It has also changed how we establish identity and trust.

Interviews happen through screens. Documents are uploaded electronically. Background information is verified digitally. Employees may work for companies for years without ever physically meeting many of their colleagues.

That environment creates an intriguing fraud opportunity.

Instead of stealing an employee's credentials, create the employee.

A synthetic applicant could potentially use fabricated documents, manipulated images, stolen personal information and AI-assisted interviews to establish credibility.

Once hired, this isn't merely payroll fraud.

You've potentially handed an unknown individual legitimate credentials, legitimate system access and legitimate knowledge of your organization.

No hacking required.

We opened the front door.

And Then There Are the Receipts

Here's another development that should make fraud investigators reach for the coffee.

Generative image technology can create remarkably convincing photographs and documents.

Imagine someone submitting a photograph showing damaged merchandise as evidence supporting a refund claim.

Except the merchandise was never damaged.

Or submitting an altered receipt.

Or photographs supporting an insurance claim.

Or documentation supposedly proving that work was completed.

For years, investigators have treated photographs and supporting documentation as evidence.

Now we need to ask another question:

Evidence of what?

The existence of a file doesn't necessarily establish the existence of the event it supposedly depicts.

That distinction is becoming enormously important.

Fraud Hasn't Changed as Much as We Think

Now for the slightly reassuring part.

Fraudsters have new toys, but human beings haven't received a software update.

Fraud still feeds on familiar ingredients:

Urgency.

Authority.

Trust.

Fear.

Greed.

Opportunity.

And our reluctance to challenge someone who appears to outrank us.

AI doesn't need to invent an entirely new fraud scheme. Sometimes it merely needs to make an old one significantly more believable.

CEO fraud existed before deepfakes.

Fake invoices existed before generative AI.

Identity theft existed before synthetic identities.

Expense fraud existed before AI-generated photographs.

Social engineering certainly existed before ChatGPT.

The technology changes the speed, scale and credibility of the deception.

And that means our controls need to catch up.

Stop Asking People to "Spot the Fake"

One of my concerns with fraud awareness training is our tendency to place enormous responsibility on employees.

Look carefully at the video.

Listen for strange pauses.

Check whether the person's lips move naturally.

Look at their eyes.

Study the shadows.

Listen for robotic speech.

Really?

We're turning Accounts Payable into CSI: Deepfake Division.

Technology will continue improving. Telling employees to become amateur deepfake analysts isn't a sustainable control environment.

Instead, organizations should build processes where authenticity isn't dependent upon appearance.

A request to change bank details should require independent verification through an established channel.

High-risk payments should require appropriate authorization regardless of who appears to request them.

Vendor onboarding should involve verification beyond submitted documents.

Employee identity shouldn't be established solely during recruitment and then assumed forever.

Evidence supporting claims, refunds and expenses should be considered alongside transaction patterns, metadata and other corroborating information.

In other words:

Don't make your controls depend upon your ability to recognize a fake.

Design controls that still work even when the fake is excellent.

The New Fraud Question

For years, fraud professionals have asked:

"Does this make sense?"

That's still a fantastic question.

But perhaps we need to add another:

"How do we know this is real?"

Not because we should become suspicious of absolutely everything.

That way madness lies.

But because many of the shortcuts we've historically used to establish trust are becoming less reliable.

We recognized the person's voice.

We saw them on video.

They sent identification.

They provided a photograph.

The document looked legitimate.

The email sounded exactly like them.

In 2026, none of those statements necessarily proves what it once did.

Maybe memos need to be signed with a drop of blood and a DNA analysis should be performed....

Welcome to the Trust Audit

Maybe that's where auditors and fraud professionals have our greatest opportunity.

We don't need to become deepfake engineers.

We need to become very good at examining how organizations establish trust.

Where do we assume identity?

Where do we independently verify it?

Which transactions rely upon a single source of evidence?

Where can urgency override controls?

Can someone change critical information and immediately transact?

Do employees have a safe way to challenge unusual instructions from senior executives?

And perhaps my favorite:

Which of our controls were designed for a world that no longer exists?

That question could uncover far more than fraud.

Technology is moving quickly. Fraudsters will continue experimenting with it.

So should we.

Not by chasing every shiny new fraud detection tool, and certainly not by assuming AI will magically solve AI-enabled fraud.

Start with something much simpler.

Take one important process in your organization.

Payroll. Vendor onboarding. Expenses. Payments. Customer refunds. Recruitment.

Then ask:

If someone could convincingly fake the person, the voice, the photograph and the document…would our controls still work?

If the answer is yes, excellent.

If the answer is no?

Well…

I think we just found your next audit.

LG3 helps professionals understand emerging risks without drowning them in jargon. Because the world of risk may be getting more complicated, but learning how to manage it doesn't have to be.

Stay connected with news and updates!

Join our mailing list to receive the latest news and updates from our team.
Don't worry, your information will not be shared.

We hate SPAM. We will never sell your information, for any reason.