Why this page exists

Hong Kong organisations face a surge of deepfake-enabled fraud: cloned voices on WhatsApp and phone calls, synthetic video in video conferences, and AI-written invoices that match a known supplier’s style. Boards hear the headlines; operators need a decision path that separates theatre from controls.

This wiki is a practical reference for CISOs, finance controllers, and SME owners. It is not a police report and not a CERT advisory. For active fraud involving bank transfers, contact your bank’s fraud desk and, where appropriate, the Police and HKCERT. See also HKCERT and HKISG.

What “deepfake fraud” means here

In HKISG usage, deepfake fraud covers social-engineering attacks that use synthetic media or AI-generated content to impersonate a trusted person or organisation — typically to authorise payments, reset access, or disclose credentials.

Related glossary: Deepfake, Phishing, Social engineering, LLM.

Common Hong Kong patterns:

  1. Voice clone + urgency — “CEO” asks for an urgent wire outside normal hours.
  2. Fake video conference — a synthetic face joins a Teams/Zoom call while a human accomplice handles chat.
  3. Supplier invoice rewrite — AI regenerates a legitimate PDF with new bank details.
  4. Recruitment / HR bait — synthetic interviewers or candidates to harvest data or install malware.

Why it matters in Hong Kong

  • Cross-border payment rails and dense SME supply chains create high-value, low-friction targets.
  • WhatsApp and WeChat-style channels are hard to monitor with classical email DLP alone.
  • Personal data captured in voice notes may engage PDPO duties if retained or misused.
  • GenAI assistants that process untrusted audio/video can amplify risk — see Prompt Injection and AI Security and Governance.

HKISG scores related AI and fraud-resistance evidence under Methodology v2026.2. Reading this page does not change any public TrustScore.

What good looks like

Control
Weak signal
Strong signal
Payment out-of-band
“Confirm on the same chat thread”
Second channel to a pre-registered number; dual control above a threshold
Vendor bank changes
Accept PDF + email alone
Callback to known contact; hold period; finance dual approval
Executive impersonation
Staff told to “just obey urgency”
Published exception path; no payment on voice/video alone
Staff drills
Annual phishing email only
Voice/video tabletop with finance + IT + HR

Hong Kong operator checklist

  1. Set a payment dual-control threshold and ban voice/video-only authorisations above it.
  2. Publish a one-page CEO/CFO impersonation rule for all staff who can move money.
  3. Require out-of-band verification for any supplier bank-detail change.
  4. Train reception, EA, and finance on deepfake audio — not only email phishing.
  5. Inventory GenAI tools that process customer or staff media; assign owners (Evidence quality domain).
  6. Brief the board with dated scenarios using the Board Briefing Pack.
  7. If fraud is in progress: freeze transfers, preserve chat/call evidence, escalate via bank + Police; coordinate technical compromise with HKCERT when systems are involved.

Editorial note

Published by the Hong Kong Information Security Group (HKISG) for educational purposes. Not legal advice, not a substitute for bank fraud procedures or national CERT coordination. Corrections are dated under our editorial standards.