
Boards now ask a question most security teams could not have imagined five years ago: what happens if a fraudulent instruction arrives in the CEO’s own voice? Deepfake social engineering incidents have moved from novelty to boardroom risk, using synthetic audio and video files convincing enough to defeat executive judgment. Traditional controls such as firewalls and email filters were never designed to question whether a familiar voice on a call is genuine.
For chief executives, security officers, and finance leaders, this is no longer a future scenario. It is an active line in enterprise risk registers, demanding a verification standard built for synthetic media.
Generative AI has removed the cost and skill barriers that once limited synthetic media fraud. A few seconds of publicly available audio, pulled from an earnings call or a conference keynote, is enough to clone an executive’s voice. Video generation models on the other hand can now place a fabricated likeness onto a live call.
Fraud losses tied to these techniques have jumped from millions to billions worldwide over the past two years. This trend extends well beyond mature markets. AI-powered cyberattacks in Indonesia have accelerated alongside the country’s rapid shift to digital banking and cloud services, with national cyber authorities reporting anomaly volumes far above prior-year averages.
For enterprises operating or expanding across Southeast Asia, this growth signals that synthetic media fraud is no longer a distant risk confined to global headlines.
Most enterprise defences focus on technical layers such as network monitoring and endpoint protection. Deepfakes bypass this entirely by targeting a different layer: the trust an employee places in a familiar voice or face. When a request appears to come from a senior leader, staff are conditioned to comply quickly rather than question its authenticity, and attackers design their approach around exactly that instinct.
Strengthening threat intelligence in Indonesia and across any region requires more than just watching network traffic for anomalies. It means understanding how attackers assemble a synthetic profile from public interviews, earnings calls and social media, then time an impersonation to a moment of genuine pressure, such as a closing deadline or a live negotiation, when an executive or their team is least likely to pause and verify.
Of all synthetic media formats, voice cloning is the most operationally efficient for attackers to deploy. A short clip from a podcast, webinar, or public interview can train a convincing clone, and the resulting call can reach a finance team, a vendor, or an assistant within minutes. Video impersonation raises the stakes further, with fabricated executives appearing on live conference calls to authorise payments or approve access changes in front of colleagues with no visible reason to doubt.
Email often sets the stage beforehand, building context so the later voice or video request feels consistent with an ongoing conversation. A mature approach to information security in Indonesia and other high-growth digital markets treat these channels as coordinated, and thus design verification accordingly.
A resilient framework begins with a governing principle: no high-value instruction, no matter how convincing, should be actioned without confirmation through a second, independent channel. This applies directly to payment approvals, credential resets, and changes to banking details — the transactions attackers target most. Security leaders should mandate call-back verifications using pre-approved contact records rather than numbers provided during the interaction.
Deepfake social engineering defences are strongest when the ‘human process’ is paired with technical signals, including anomalous login locations and requests that bypass standard approval hierarchies. Executive awareness training should also evolve beyond email phishing to cover the pressure tactics common in synthetic media fraud, namely urgency, secrecy, and requests to override normal procedure. These controls require governance discipline, not new technology investment.
Security leaders do not need a complete architectural overhaul to reduce exposure within a single quarter. A focused set of governance actions can materially lower risk while a broader strategy takes shape, which are as stated:
These actions close the gap between what policy assumes and what an executive actually faces when a convincing, fraudulent request reaches their desk or their phone.
These risks are not merely theoretical for organisations operating in Southeast Asia’s fastest-growing digital economy. AI-powered cyberattacks in Indonesia continue to rise alongside record digital banking adoption, placing new pressure on executives to modernise governance and verification practices.
The third edition of digitalCIO Indonesia, scheduled to take place on 11 November 2026 at The Ritz-Carlton Jakarta, Pacific Place, brings together technology, security, and data leaders to confront these systemic vulnerabilities — bridging the gap between board-level governance frameworks and deployable defenses against advanced synthetic media fraud.
Attending provides direct access to a peer network navigating identical pressures, critical foresight into how regional authorities are updating Indonesian information security mandates, and actionable frameworks to fortify your existing risk and compliance structures.
What is deepfake social engineering?
AI-generated audio or video used to impersonate a trusted person, manipulating staff into approving fraudulent payments or system access.
How can executives verify a suspicious call?
Hang up and call back using a pre-verified number from an internal directory, never a number given during the call.
Why is Indonesia becoming a growing target for these attacks?
Rapid digital and financial adoption, combined with a large internet base, gives attackers more targets and public audio samples.
What is the most effective enterprise defence?
Mandatory second-channel verification for every high-value request, paired with executive training on urgency, secrecy, and override pressure tactics.
Should mid-sized enterprises take this threat seriously?
Yes, attackers frequently target finance and vendor teams at mid-sized firms, where verification controls are often weaker than larger enterprises.