Cyber fraud is big business. According to research firm Cybersecurity Ventures, global cyber fraud and cybercrime were on track to cost a staggering $10.5 trillion (€9.15 trillion) in 2025 and to grow to $12.2 trillion (€10.6 trillion) by 2031. Meanwhile, the World Economic Forum Global Cybersecurity Outlook 2026 reports that cyber-enabled fraud is among the most prominent cyber risks facing organisations.
“Cyber-enabled fraud has evolved far beyond opportunistic scams,” says Ciara Weldon, senior technical underwriter with specialist commercial and personal insurance solutions firm Hiscox Ireland. “Today it is a highly organised criminal enterprise, increasingly powered by artificial intelligence [AI] and designed to exploit not only technology but also human behaviour. While organisations continue to invest in cybersecurity, fraudsters are adapting just as quickly, using convincing impersonation, social engineering and AI-generated content to target employees, suppliers and customers alike.”
The organisations best placed to withstand these threats are those that treat cyber-enabled fraud as a business risk rather than simply an IT issue, she advises. “This is especially important for SMEs, which may not have large in-house cybersecurity or fraud-prevention teams, but face many of the same sophisticated threats as larger organisations. Strong governance, well-informed employees, clear payment controls and tested incident response plans all play an important role in reducing both the likelihood and the impact of an attack.”
According to PwC Ireland cybersecurity practice director Shomo Das, cyber-enabled fraud is essentially old-fashioned deception supercharged by technology. “Criminals use email, messaging platforms, fake websites, stolen credentials and social engineering to trick people into making payments, handing over data or giving access to systems,” he says.
RM Block

“It can appear as a convincing email from a supplier, a text from a bank, a fake investment opportunity or an urgent request from a senior executive. What makes it dangerous is that it often looks routine and legitimate until the money or data has gone.”
A common example is chief financial officer or chief executive fraud, where a criminal impersonates a senior executive and pressures an employee to approve an urgent payment, Das adds. “Another is invoice fraud, where attackers intercept or imitate supplier communications and change bank details. Business email compromise is also widespread: criminals gain access to a real email account and use it to request payments or sensitive information. These attacks work because they exploit trust, hierarchy and time pressure rather than relying only on technical hacking.”
What makes cyber-enabled fraud particularly challenging is that it often targets people rather than technology. “Criminals look for opportunities to exploit trust, urgency or routine business processes,” Weldon points out. “Whether it is impersonating a senior executive, a trusted supplier or even a customer, the objective is usually to persuade someone to take an action that appears entirely legitimate.”
AI has made an already bad situation even worse. “Artificial intelligence has significantly lowered the barriers for cyber criminals by allowing them to create far more convincing fraudulent communications at speed and scale,” says Weldon.

“Before the emergence of AI, cyber fraud required skilled criminals, time, research, good language skills and convincing impersonation skills. Now, AI allows a relatively unsophisticated criminal to perform attacks which are becoming faster, cheaper, more convincing and scalable. AI can rapidly generate convincing invoices, bank letters, identity documents, contracts and payment instructions which allows fraudsters to automate phishing, scam call scripting and deepfake impersonations.”
The result is more personalised emails and more grammatically accurate phishing attempts. “AI-generated content can imitate the tone and style of trusted colleagues or business partners with remarkable realism,” she adds.
Emerging technologies such as voice cloning and synthetic media are also creating new opportunities for impersonation fraud, making it increasingly difficult for employees to distinguish genuine communications from malicious ones, she says.
“For SMEs without dedicated fraud detection or cybersecurity teams, the increased credibility and volume of these communications can make attempted attacks more difficult to identify and investigate.”
Das notes: “Scams contain fewer obvious warning signs, arrive in greater volumes, and are increasingly difficult for ordinary users to spot.”
He echoes Weldon’s view that fraud prevention needs to be treated as a business issue and not one confined to IT.
“That means strong payment controls, multifactor authentication, independent verification of bank detail changes, and clear escalation processes for unusual or urgent requests,” he says.
“Staff training is vital, especially for finance, customer service and executive teams. Companies should also monitor for fake websites and brand impersonation, strengthen email security, and rehearse their response to incidents. The guiding principle should be simple: verify before you trust.”
There is no single solution that eliminates cyber-enabled fraud, and organisations should adopt a layered approach to resilience, according to Weldon. “Technology remains important, but equally critical are strong governance, robust financial controls, regular employee awareness training and clearly defined approval processes for payments and sensitive transactions.
“For SMEs, the most effective measures are often relatively straightforward, such as independently verifying changes to payment details, requiring more than one person to approve significant transactions, segregating duties, implementing multifactor authentication and ensuring employees know how to report a suspicious request quickly.”
The insurance aspect shouldn’t be overlooked. “Insurance brokers can also play an important role in helping SMEs understand their exposures and consider the level of protection and support appropriate to their circumstances,” Weldon says.
“Often, the response element of a cyber insurance policy provides invaluable support to a business that is suffering from a cyber fraud crisis. The question they will have is ‘Who do we call, and what do we do next?’, so access to expert incident response reduces confusion, accelerates recovery and limits the overall impact of an attack to the business.”



















