Why this page exists
Hong Kong organisations face a surge of deepfake-enabled fraud: cloned voices on WhatsApp and phone calls, synthetic video in video conferences, and AI-written invoices that match a known supplier’s style. Boards hear the headlines; operators need a decision path that separates theatre from controls.
This wiki is a practical reference for CISOs, finance controllers, and SME owners. It is not a police report and not a CERT advisory. For active fraud involving bank transfers, contact your bank’s fraud desk and, where appropriate, the Police and HKCERT. See also HKCERT and HKISG.
What “deepfake fraud” means here
In HKISG usage, deepfake fraud covers social-engineering attacks that use synthetic media or AI-generated content to impersonate a trusted person or organisation — typically to authorise payments, reset access, or disclose credentials.
Related glossary: Deepfake, Phishing, Social engineering, LLM.
Common Hong Kong patterns:
- Voice clone + urgency — “CEO” asks for an urgent wire outside normal hours.
- Fake video conference — a synthetic face joins a Teams/Zoom call while a human accomplice handles chat.
- Supplier invoice rewrite — AI regenerates a legitimate PDF with new bank details.
- Recruitment / HR bait — synthetic interviewers or candidates to harvest data or install malware.
Why it matters in Hong Kong
- Cross-border payment rails and dense SME supply chains create high-value, low-friction targets.
- WhatsApp and WeChat-style channels are hard to monitor with classical email DLP alone.
- Personal data captured in voice notes may engage PDPO duties if retained or misused.
- GenAI assistants that process untrusted audio/video can amplify risk — see Prompt Injection and AI Security and Governance.
HKISG scores related AI and fraud-resistance evidence under Methodology v2026.2. Reading this page does not change any public TrustScore.
What good looks like
Hong Kong operator checklist
- Set a payment dual-control threshold and ban voice/video-only authorisations above it.
- Publish a one-page CEO/CFO impersonation rule for all staff who can move money.
- Require out-of-band verification for any supplier bank-detail change.
- Train reception, EA, and finance on deepfake audio — not only email phishing.
- Inventory GenAI tools that process customer or staff media; assign owners (Evidence quality domain).
- Brief the board with dated scenarios using the Board Briefing Pack.
- If fraud is in progress: freeze transfers, preserve chat/call evidence, escalate via bank + Police; coordinate technical compromise with HKCERT when systems are involved.
Related HKISG materials
- AI Security and Governance
- Ransomware for Hong Kong SMEs
- CISO AI Security Briefing
- Security News · Bulletins · Trust Reviews
Editorial note
Published by the Hong Kong Information Security Group (HKISG) for educational purposes. Not legal advice, not a substitute for bank fraud procedures or national CERT coordination. Corrections are dated under our editorial standards.