Artificial intelligence has given criminals a powerful new toolkit. "Dark AI" — generative models used for fraud — now lets attackers clone a familiar voice from seconds of audio, fabricate convincing video, and write flawless phishing in perfect Thai. For organisations in Thailand, deepfake-enabled fraud has moved from a future risk to a present one, and traditional "trust your eyes and ears" instincts no longer protect us.
How deepfake scams work
The mechanics are straightforward and cheap. An attacker harvests a short sample of someone's voice or face — from social media, a webinar, or a voicemail — and uses an AI model to generate new speech or video saying whatever they choose. They then place an urgent call or video request: a "CEO" instructing finance to make a payment, a "family member" in distress, or a "supplier" updating bank details. The emotional urgency is designed to bypass scrutiny.
The threat in Thailand
Thai authorities, including the Anti Online Scam Operation Centre (AOC 1441), have warned that AI voice cloning and deepfakes are a defining scam tactic for 2026, with working-age adults increasingly targeted. In late 2025, groups were arrested for using AI to defeat banks' biometric verification. Globally, losses from deepfake-enabled fraud ran into hundreds of millions of dollars in early 2025 alone — and Southeast Asia's scam centres are a major source.
Why technology alone is not enough
Deepfakes attack the human layer, so defence must combine controls and culture. Detection tools are improving, but the most reliable safeguards are process-based — verification steps that an attacker cannot fake even with a perfect voice. The lesson from real incidents is that organisations are compromised not because the deepfake was flawless, but because no one was required to verify through a second channel.
How to defend your organisation
- Mandate out-of-band verification for any payment or sensitive request — call back on a known number, never the one provided in the request.
- Use agreed verbal pass-phrases or callback procedures for high-value transactions.
- Apply DNS and email security to block the phishing and malicious infrastructure that often accompanies these scams.
- Harden identity with phishing-resistant MFA so a cloned voice cannot also unlock an account.
- Train staff specifically on AI-cloned voice and video — show real examples so urgency triggers verification, not compliance.
- Limit public exposure of executives' voice and video where practical, and monitor for impersonation.
Build a verify-by-default culture
The single most effective control is cultural: make it normal — even expected — to pause and verify an unusual request, regardless of who appears to be asking. Empower junior staff to challenge a "CEO" instruction without fear. When verification is the default rather than the exception, deepfakes lose their power because authenticity is confirmed by process, not by perception.
How iconnet helps
iconnet helps Thai organisations build resilience against AI-enabled fraud — combining DNS-layer protection, email security, phishing-resistant access, threat intelligence (via KELA) and security-awareness guidance. Talk to our team about hardening both your technology and your processes against deepfake and dark-AI threats.