Back to all articles
How Can RIAs Prepare for AI-Driven Scams and Deepfakes?
How Can RIAs Prepare for AI-Driven Scams and Deepfakes?
By Stan Vick

How Can RIAs Prepare for AI-Driven Scams and Deepfakes?

AI-driven scams are becoming a practical cybersecurity issue for RIAs. Voice cloning, deepfake video, and AI-generated phishing can be combined with a compromised email account to make a fraudulent wire request look legitimate.

The scale of the problem is growing. The FBI’s Internet Crime Complaint Center recorded more than 22,000 AI-related complaints in 2025, with nearly $893 million in reported losses. At the same time, the SEC has included Regulation S-P and cybersecurity on its 2026 examination priorities, while FINRA has warned that generative AI can make cyber fraud more convincing.

What Verification Procedures Should RIAs Use?

A money-movement request should never be approved based on one communication channel alone. If an attacker has access to a client’s email, they may already know the client’s account details, recent conversations, and the way they normally communicate.

A safer process starts with an independent callback using a phone number already on file. Large or unusual transfers can also require a second employee to approve the request. Firms can establish verbal passphrases or other verification methods with clients before there is a reason to use them.

Video calls should not automatically be treated as proof of identity either. Deepfake video has been used to impersonate executives and authorize payments. FinCEN has identified several warning signs associated with deepfake media, including changes in camera setup during a call and problems responding to multifactor authentication requests.

How Can RIAs Educate Clients About AI Scams?

Clients should know in advance what the firm will and will not ask them to do. RIAs can make a few basic rules part of the onboarding process and review them with clients regularly.

Clients should know that the firm will not change wiring instructions based only on an email, ask for a one-time passcode during an inbound call, or rely on an urgent message without additional verification. If something feels unusual, the client should know to end the conversation and contact the firm using a number already on file.

This is particularly important for older clients. Americans aged 60 and older reported $352 million in AI-related scam losses to the FBI in 2025. A short annual security review and a one-page guide can give clients a simple reference when a suspicious call or message arrives.

What Should RIA Staff Learn About Deepfakes?

Employees need to practice these situations rather than simply read a cybersecurity policy. Training can include simulated voice-cloning calls, fake regulator emails, compromised client accounts, and fraudulent transfer requests that start over email and continue by phone.

FINRA has also warned about phishing campaigns impersonating its employees to obtain credentials. That means training should not be limited to advisors. Operations, client service, IT, and other employees who can access client information or initiate transactions need to know the same verification rules.

Firms should also record who completed the training and make the stop-the-wire procedure clear. Reviewing the process after another firm experiences an incident can help employees recognize similar patterns before they become a real problem.

What Other Areas Can Help RIAs Deliver More Client Value?

Strong operational controls are useful beyond cybersecurity. RIAs also need processes that help clients capture financial value that might otherwise be missed.

Securities class action recovery is one example. Settlements totaled approximately $8 billion in 2025, creating another potential source of value for eligible investors. Platforms such as 11th.com automate settlement monitoring, holdings matching, claim filing, and payout delivery, allowing RIAs to identify and collect recoveries without adding another manual process for their teams. 

This also gives advisors more time to focus on the work clients directly experience, including security, communication, and planning.

What Will RIA Cybersecurity Look Like in 2026 and Beyond?

AI-driven fraud is likely to become harder to recognize by appearance or voice alone. That makes the process around a transaction more important than whether a caller or video looks convincing.

RIAs that build independent verification into money movement, educate clients before an incident happens, train employees with realistic examples, and limit which channels can authorize transactions will be better prepared for increasingly sophisticated impersonation attempts.

FAQ

Are deepfake calls a real risk for RIA clients?

Yes. Attackers can combine stolen email information with cloned voices or video to make fraudulent transfer requests appear legitimate.

What verification step stops most of these scams?

Calling the client back using a number already on file and requiring a second internal approval for unusual money movement.

What should clients be told in advance?

That the firm will never change wiring instructions by email only and that they should contact the firm directly if a request seems unusual or urgent.

Do regulators expect firms to address this?

Yes. SEC examination priorities include Regulation S-P and cybersecurity, while FINRA has highlighted generative AI as a tool that can increase cyber fraud risks.

Is a video call enough to confirm identity?

Not by itself. Deepfake video can make an impersonation look convincing, so firms should use an independent callback, passphrase, or another verification method.

How Can RIAs Build Portfolios for Uncertain Markets in 2026?

How Can RIAs Build Portfolios for Uncertain Markets in 2026?

How Can RIAs Prepare for AI-Driven Scams and Deepfakes?

How Can RIAs Prepare for AI-Driven Scams and Deepfakes?

How Can RIAs Help Families Create a Framework for Managing Multigenerational Wealth?

How Can RIAs Help Families Create a Framework for Managing Multigenerational Wealth?