To kick us off, can you tell us a bit about your role at AXA XL and your focus within investigations and fraud control?
My name is Hamza Zarrouk, and I am the Head of Investigations at AXA XL. I have dedicated my career to uncovering and mitigating various forms of financial and organizational misconduct as well as improving fraud prevention and detection capabilities within AXA.
In my role, I lead a global team responsible for investigating high-risk issues including asset misappropriation, and impersonation attacks. These threats are increasingly sophisticated and can undermine trust and integrity within organizations. My team works in conjunction with Information security to develop strategies to detect and prevent such frauds, implement standardized processes, and promote a security culture labelled “Care, Protect, Alert”
At the event, I will be discussing impersonation attacks — an insidious form of fraud that often involves impersonating trusted individuals or entities. I look forward to sharing insights on how organizations can better recognize, prevent, and respond to these cyber-enabled threats to safeguard their assets and reputation.
Compromised advisor emails and fraudulent instructions from legitimate accounts are increasingly common – what patterns are you seeing in how these attacks unfold?
In today’s landscape of cyber threats, our focus must go beyond the traditional phishing scenarios of generic email scams or CEO impersonations that most organizations have learned to defend against. These are well-understood, and while evolving with deepfake technology, they are not the core of the current wave of sophisticated attacks we’re witnessing.
What’s more insidious is how fraudsters have shifted their attention. They’ve discovered that it’s far easier and more lucrative to target the very arteries of our business ecosystem—our clients, beneficiaries, claimants, intermediaries, brokers, and legal professionals. These actors often serve as the bridge between the insurance company and the ultimate recipient of funds, making them an attractive target for impersonation and manipulation.
The simplest scenario involves impersonating the insurance company itself. Fraudsters craft convincing communications instructing clients to transfer funds to bank accounts controlled by the criminals. To the client, it seems legitimate—an official request from their insurer, leading to financial losses that are often difficult to recover.
A more complex scenario emerges when we consider the recent surge in data breaches. The leakage of passwords and sensitive information has made access to emails and resources of individuals and small-to-medium enterprises (SMEs) readily available. AI tools enable these criminals to sift through vast volumes of stolen data, quickly identifying upcoming transactions or vulnerable accounts. They don’t even need to contact the insurance company directly; instead, they hijack the communication channels of trusted intermediaries.
Once they gain control of a beneficiary’s account, the fraudsters impersonate the individual’s identity and instruct the solicitor, broker, or accountant to redirect payments—often to offshore accounts. Here, the insurance company’s controls might still validate the solicitor’s identity, making the deception even more convincing, because the communication appears legitimate and compliant with existing protocols.
The third scenario involves a strategic wait. After the funds are transferred to the intermediary—be it a solicitor, broker, or accountant—the fraudsters impersonate the beneficiary again, instructing the intermediary to deposit the funds into offshore or shell accounts. This layered approach complicates detection and increases the potential for significant financial loss.
Despite our extensive efforts—hundreds of training sessions, awareness campaigns, and technological controls—our weakest link remains the individual beneficiary or SME. Human nature and organizational complacency often open the door for these intrusions. That’s why our defense must be multi-layered, combining technological safeguards, ongoing education, and rigorous verification processes—not only within our organization but across the entire broader ecosystem in which we operate.
In essence, today’s fraud landscape isn’t just about technical vulnerabilities; it’s about understanding the behavioral and systemic weaknesses that fraudsters exploit. As experts, our role is to stay one step ahead – anticipating these evolving tactics and reinforcing our defenses at every level, including the wider ecosystem, to effectively mitigate these risks.
How has the rise of AI-generated content and deepfakes changed the landscape for impersonation fraud?
Traditionally, impersonation fraud required significant time and effort for fraudsters to prepare and execute, involving manual reconnaissance, impersonation, and communication. However, with the advent of AI-generated content, these campaigns can now be launched rapidly and at scale. Attackers can produce highly tailored messages by leveraging data from breached accounts, social media profiles, or other sources to craft convincing narratives that resonate with targeted individuals. This level of personalization dramatically increases the likelihood of success, as recipients perceive these communications as authentic.
The integration of AI and deepfake technology further complicates detection efforts. Conventional controls—such as verifying email addresses, cross-checking phone numbers, or employing basic identity checks—are often insufficient against AI-crafted content, which can be seamlessly embedded into legitimate communication channels, making fraudulent messages appear highly credible.
Personally, I have not yet encountered a case involving high-quality deepfakes, but I am aware that criminals have found ways to circumvent traditional verification methods. For instance, some have used free to bypass selfie verification when opening bank accounts in victims’ names. There is even a publicly available video tutorial detailing how to carry out such attacks, which adds to the challenge of detection.
In the past, we recommended verbal verification for large transactions as an additional safeguard. However, with AI-generated voice synthesis and deepfake audio, this approach can also be circumvented. Similarly, SMS-based verification codes—once considered a robust control—are increasingly vulnerable to techniques like SIM swapping or well-executed social engineering attacks.
Overall, these technological advancements mean that our defenses must evolve. Relying solely on traditional controls is no longer sufficient; we need to implement multi-layered, behavior-based detection methods and continuously educate all stakeholders about these emerging threats.
Looking forward, what kinds of controls or collaboration are needed to stay ahead of increasingly sophisticated impersonation attacks?
Real-Time Alerts:
Given that a primary goal of many impersonation scams is to divert funds, the banking sector has a crucial role to play by implementing smarter, more reactive controls to detect and prevent these fraudulent transactions.
I dream of a real-time alerting system (embedded within the bank offer) that flag suspicious transactions based on fraud/impersonation red flags. For example, banks could introduce alerts when the actual beneficiary of a transfer does not match the name recorded by the payer. Some solutions in the market already provide such services, but it would be highly beneficial to everyone to embed this functionality into the standard banking offerings.
Layered Authentication and Customer Education:
Another key control is educating all participants within the ecosystem on layered authentication, especially for high-risk transactions. This could include requiring multi-channel confirmation—such as secondary verification through a different communication channel—before executing large or unusual transfers. This approach helps ensure that requests are genuine at every stage of the process. (sharing a concrete example of failure because one participant missed to get a verbal confirmation).
Leveraging Advanced Identity Verification:
At an early stage, we should also promote the widespread use of advanced identity verification tools that cross-reference customer information against multiple trusted data sources. This can help detect anomalies or inconsistencies early on. Incorporating AI-driven analytics further enhances this process by identifying irregular transaction patterns, such as recently created email accounts, phone numbers, or bank accounts linked to profile changes, which may indicate fraudulent activity.
Industry Collaboration for Enhanced Security:
Finally, collaboration across the industry is essential. Sharing threat intelligence with other institutions helps create a unified front against emerging impersonation tactics. Industry-wide initiatives for data sharing and best practice exchange enable us to stay ahead of evolving threats and strengthen our collective defenses.
