In a KPMG in Canada research survey of 300 Canadian organizations that had been previously victimized by fraud, 95% of leaders said that they are very concerned that the threat of deepfakes has increased the risk of fraud at their companies. 91% are worried that generative AI will give criminals more opportunities to launch corporate misinformation and disinformation campaigns using deepfakes.
“Because fraud is rarely reported to the police, we wanted to speak to business owners and C-suite leaders across Canada to get a deeper understanding of how the evolving fraud landscape of new technology, a shifting economy, geopolitical tensions and remote work was giving perpetrators the opportunity, motivation and rationalization to commit fraud,” said Enzo Carlucci, National Forensic Leader at KPMG in Canada.
“Respondents overwhelmingly told us the fraud landscape is becoming more complex, with 95% saying generative AI and social engineering scams make it easier for fraudsters to deceive, manipulate, misrepresent and conceal their crime. As fraudsters are becoming increasingly sophisticated in their attack methods, it’s more and more challenging to deter criminals,” Mr. Carlucci continued. “Organizations need to find new ways to strengthen their anti-fraud programs and stay one step ahead of scammers, or else they could be facing increased financial, legal, regulatory and reputational risks.”
Other key points from the survey:
- 84% worry that current economic conditions could potentially drive their employees or their customers to commit fraud out of desperation.
- 87% say the shift to remote work increased the risk of fraud occurring within their company, due to a reduced ability to monitor and control for fraudulent behaviour.
- 89% admit they had to ‘scramble or react quickly’ to implement a robust fraud detection and prevention program due to a fraud incident.
- 43% victimized by fraud disclosed that they are currently experiencing a form of internal fraud, such as embezzlement, data or personally identifiable information (PII) theft, environmental, social and governance (ESG) fraud, or procurement fraud.
- 33% victimized by fraud say they are currently dealing with an external fraud, such as payment fraud, synthetic identity (ID) fraud, a cyber attack, or social engineering campaigns (from intentional online deception to manipulating visual media and fabricating content or deepfakes)
- 53% say that their company lost between 1-to-5% of their profits to fraud in the past 12 months, 35% lost up to 1%, and 7% suffered losses over 5%. Only 4% that were impacted by fraud didn’t suffer any loss.
The top causes of business fraud impacts
The most common types of external fraud schemes involve the use of manufactured or falsified information, often created or aided using technology. The top three scams reported by respondents include:
- Payment fraud, where criminals use false or stolen payment information to make a purchase.
- Misinformation or disinformation campaigns, such as malvertising or malicious advertising and deceptive editing (deepfakes) or missing content.
- Account takeover or synthetic identity (ID) fraud, where fraudsters use fake personas to gain access to accounts.
The most common types of internal fraud that respondents reported were:
- Embezzlement.
- Exaggerating, distorting, or embellishing environmental, social and governance (ESG) data.
- Theft of personally identifiable information (PII) or using PII to commit fraud.
The respondents said their company learned of the fraud primarily through internal audits, management reviews, whistleblowers and proactive monitoring.
The research finds that 77% of companies have a fraud detection program. However, only 39% call it ‘extremely effective’. When it comes to prevention, just over half (54%) say they have a fraud prevention program in place. Yet only 37% describe their anti-fraud policies and 38% describe their financial controls as ‘extremely effective’. Further, only 42% call their fraud risk assessment programs ‘extremely effective’.
Almost half (47%) say that they are actively using emerging technologies, such as AI, advanced data analytics, generative AI, automation and biometric verification to mitigate the risk of fraud.
“It’s encouraging to see organizations starting to use technology to deter fraud, but not enough of them are,” says Marilyn Abate, a partner in KPMG’s Forensic and Financial Crimes practice. “Companies need to use AI to fight AI. These tools are fast-becoming essentials in the fraud toolkit to prevent fraudsters from gaining the upper hand. But if you don’t perform regular fraud risk assessments to identify external and internal risks and vulnerabilities, you will always be at a disadvantage.”






