Effective AI-enhanced executive impersonation doesn’t require a deepfake.
After years of deepfake headlines, executives and employees are wary of the strange, urgent phone call and the last-minute video meeting. The deepfake threat gets the headlines and the attention, even if the numbers behind it are still messy and hard to pin down. But those aren’t the only way this works, and they may not be the way money actually leaves an enterprise.
Consider the patient attacker. Over two years, this one quietly drained a company of nearly a million dollars, and no one noticed until it was gone. It’s one of two real, anonymized campaigns in Trustmi’s 2026 Payment Security & Risk Benchmark Report, and there wasn’t a deepfake in sight. Just AI used more quietly, to generate look-alike domains, write emails, and mass-produce paperwork at a scale one person could never manage by hand.
What made it work wasn’t a single clever trick. It ran like a marketing campaign, tested, refined, and relaunched until it converted, made cheap and repeatable by AI.

How a $1M Executive Impersonation Campaign Hid Inside Normal Payments
To understand how a campaign like this actually operates, we went to someone who sees them constantly: our CTO, Eli Ben Nun, who tracks these attacks across the organizations Trustmi protects.
“For two years this attacker just kept showing up, quiet, patient, and more precise every time. They never forced their way in. They embedded into real payment conversations until a fraudulent request looked like part of the job.”
— Eli Ben Nun, CTO and Co-founder at Trustmi
You can see the repetition in the numbers. In 2024 alone, the attacker made eighteen separate attempts, each one typically between $50,000 and $70,000. That range is no accident. Amounts that size clear routine approval thresholds and disappear into normal accounts payable activity, so the attacker never asked for a number big enough to make anyone stop and look. Small asks, made often, adding up to nearly a million dollars over the life of the campaign.
Each attempt ran the same two-part play. First, the attacker set up a fake vendor, real-looking paperwork, W-9 and all, and let it clear the normal onboarding checks until the company’s own system treated it as a legitimate payee. Then came the ask: a payment request sent from a look-alike domain in a company leader’s name, dropped into an email thread built to look like an ongoing conversation. That two-step is the whole trick. The fake vendor got the payee on the books. The fake executive got the invoice approved. Neither half looked alarming on its own.
Then the attacker did it again, the way a marketing team relaunches a campaign that’s working. New domain, new mailbox, same routine, twenty-five look-alike domains over two years.

When Context Creates Credibility
The thread was a quiet linchpin. Dropping the request into a conversation that already looked real meant the actual ask, an invoice paired with an ACH or card request, never arrived cold. And that instinct to trust a familiar thread is measurable: in Trustmi’s Employee Payment Fraud Awareness Report 81% of a thousand employees handling comms, vendors, and payments said they would assume a request was legitimate if it showed up in an existing email thread.
An urgent phone call from your boss is the kind of thing you remember. An email like these? Not so much. It slides in among a hundred others, references a project you recognize, and asks for something that looks like what you do every day. That’s why it stays under the radar. It doesn’t feel like an attack. It feels like a normal Tuesday.
The AI Was in the Assembly Line, Not the Face
This is where the AI executive impersonation actually lived. Not in a synthetic face, but in the assembly line behind it. The documents weren’t painstaking forgeries, they were mass-produced. PDF generators, AI-written emails, and reusable templates churned out W-9s and official-looking invoices fast enough to feed attempt after attempt. In practice, the attacker ran it like a marketing team runs a campaign, reusable templates, small tweaks between sends, and each attempt a little more refined than the last. The sophistication wasn’t in any single message. It was in how cheaply the whole operation could be run and repeated.
The tells were there, just not where anyone was looking. The fake documents carried metadata anomalies, script-generated PDF producers and timestamps no genuine business document would have. On the surface, an invoice looked fine. The proof it was fake lived in places a human reviewer never opens.

The Fraud Your Controls Won’t Flag
On its own, any single request looked ordinary. The fraud only became visible by connecting each request to the payment behind it. That’s the whole idea behind stopping executive impersonation before it turns into a fraudulent payment.
The deepfake calls will keep making headlines. This AI-enhanced executive impersonation won’t, and most companies have no real measure of how much of it is already moving through their payment workflows. You can’t fix what you can’t see, so the place to start is finding out what your own exposure looks like.
Take Trustmi’s free fraud risk assessment to see where payment fraud could be slipping through, and read the Payment Security & Risk Benchmark Report for the full picture of how these campaigns operate.

Behavioral AI-powered security
Protection on day one
10-15x ROI