8/27/26

Unspoken Security Ep 62: How Do We Know What's Real in the Age of AI?

AJ Nash sat down with Shai Gabay, co-founder and CEO of Trustmi, to talk about financial fraud in the age of AI. Gabay opened with the size of the problem: global fraud losses hit $450 billion last year. He explained why business-to-business payment fraud keeps growing. Attackers do not invent new relationships. They study the ones a company already has, then step into an existing conversation between a business and its vendor. Most of that conversation happens over email, and most companies still rely on people, not systems, to catch when something is wrong.

The two traced how far that exploitation has evolved. Generative AI has erased the old tells: bad grammar, wrong context, unfamiliar phrasing. Gabay described attackers who forge invoices, bank letters, and void checks in minutes, and a rising pattern where criminals open fully legitimate bank accounts, complete with real KYC verification, under a stolen supplier identity. He walked through a real case where an attacker built a lookalike domain, cloned a supplier's website, and updated the fake site to appear first in search results, all to defeat a callback verification procedure before it ever started.

Nash and Gabay closed on the harder question: what happens when video and voice can be faked too. They discussed a $25 million loss out of Hong Kong, where an employee was pulled into a Zoom call with deepfaked company leadership and instructed to wire funds. Gabay argued that no single tool fixes this. Organizations need to connect fragmented controls into one process and, above all, give the person who actually approves a payment the standing to ask questions and slow down. Asked the show's closing question, Gabay admitted that even as a CEO, he still gets pulled into incident response himself, just to understand exactly how an attack worked.
Next

Unspoken Security Ep 61: Should We Be Afraid of Artificial Intelligence (AI)?