OpenTreasury · 2025-07-11 · 26 min
Key moments - from our scoring
Substance score
29 / 100
Five dimensions, 20 points each
Craig Jeffrey, managing partner at Strategic Treasurer, joins Pushpendra Mehta to unpack deepfakes as an existential threat to treasury operations. The discussion centers on Strategic Treasurer's newly released white paper, which exposes why treasury teams are uniquely vulnerable: they control large fund movements, handle confidential transactions, and enjoy operational trust that criminals increasingly exploit through AI-generated audio and video. Craig explains that deepfakes leverage accessible AI tools and massive criminal payouts to fuel rapid adoption - making it economically rational for fraudsters to target treasury over accounts payable. The episode reveals a sobering reality: iProves research shows only 0.1% of people can reliably detect deepfakes. Rather than chase detection (which is becoming impossible), the conversation pivots to validation, dual controls, banking services, modern account structures, and multi-layered security. Craig emphasizes that defense must begin with people, processes, and policies, supplemented by AI-infused automation, regular staff training, improved workflows, and well-rehearsed incident response plans. For treasury leaders, CFOs, and payments professionals, this is essential listening on preparing organizational defenses before deepfake fraud strikes.
Treasury controls large fund movements, handles confidential transactions like acquisitions and settlements, and operates with high internal trust. Criminals logically target treasury because they can access more money with fewer transactions and less scrutiny than accounts payable, making deepfake attacks on treasury officers highly profitable.
According to iProves February 2025 research cited in the white paper, only 0.1% of individuals can consistently and accurately detect AI-generated deepfakes, meaning 99.9% of people - including sharp finance professionals - risk being fooled by synthetic content that looks, sounds, and feels real.
Look for unnatural eye activity, mismatched facial expressions or overlay errors where the face doesn't align with the head and body, awkward body positioning and movement, unrealistic teeth (overly white or uniform like Barney the Dinosaur), perfectly styled hair without natural wisps, and audio anomalies or distortions in the voice.
Rather than trying to detect deepfakes visually, validate the source through secondary confirmation methods: callback verification using different communication channels, AI-infused validation services, permission lists, network analysis showing payment pattern anomalies, modern banking structures with isolated accounts, and regular bank security services and data reconciliation (weekly or daily rather than monthly).
A rehearsed response plan is essential - without it, your posture is unacceptable. Speed matters in fraud situations to stem losses and recover funds. Plans should be tested regularly (every 3-6 months, not annually) and include procedures for contacting law enforcement, notifying banks immediately so they can freeze accounts or issue alerts to other institutions, and preventing further exploitation.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of actionable tactical points buried in significant padding - validation callback procedures, layered security logic, and network-based payment flagging are mildly useful - but the episode repeatedly restates the same general warning across 26 minutes and could have been compressed to 10 without losing substance.
how can we detect what's becoming undetectable? We can't by itself, straight on by looking at things. But how can we confirm things?
six other companies have now moved to change payments to Acme company, to this other address, to this other account at this different bank
The episode relies almost entirely on recycled frameworks - the war escalation metaphor, the classic 'outrun the bear not the bear' cliché, and the misattributed Willie Sutton bank-robber anecdote - with no contrarian or first-principles thinking about deepfake risk that a treasury professional couldn't find in a vendor blog post.
if you're being chased by a bear, you don't have to outrun the bear, you have to outrun your friends
I think it was Willie Horton who was a famous bank robber
Craig Jeffrey is a legitimate managing partner of a treasury consultancy with genuine domain expertise, but the episode is explicitly promotional for his own firm's white paper, and he presents as an advisor-commentator rather than an operator who has personally navigated a deepfake attack or loss at scale.
I'm joined by Craig Jeffrey, managing partner and strategic treasurer, to discuss their newly released white paper on deepfakes
I recommend that our audience download the deepfake white paper by visiting strategictreasurer.com deepfakes
The episode rests almost entirely on a single third-party statistic, offers no named company case studies, no dollar figures for actual losses, and no specific tools or vendors beyond vague references to 'AI-infused validation service' - most examples are hypothetical constructs.
Only 0.1% of individuals can consistently and accurately detect AI generated deepfakes
I know there's some systems that when they're checking for secure, it'll even check flow of blood and it'll look at pressure points
The host and guest work for the same consulting firm and are jointly promoting a white paper they co-produced, resulting in entirely scripted, mutually congratulatory exchanges with zero pushback, no probing follow-ups, and questions that function purely as extended set-ups for the guest's talking points.
Well, uh, that was a deeply informative response. Thank you, Craig.
That's a good setup to the question
Computed from the transcript - who did the talking, and the words that came up most.
Pushpendra Mehta meets with Craig Jeffery , Managing Partner at Strategic Treasurer , to discuss the firm's newly released white paper on deepfakes. Listen in to learn more. You can download the white paper Deepfakes & Payments Fraud: Is Treasury Prepared? by visiting:
Transcribed and scored by The B2B Podcast Index.
Pushpendra Mehta: Hello and a warm welcome to the open treasury podcast. Your go to source for the latest news and analysis in corporate cash and treasury management. This show is brought to you by ctmfile.com and the Treasury News Network where Treasury professionals learn and share the information that matters most. Welcome to today's episode where we explore one of the most pressing and fast evolving threats facing the treasury finance and payment security landscape. Deepfake enabled fraud. I'm Pushpendra Mehta, your host, and I'm joined by Craig Jeffrey, managing partner and strategic treasurer, to discuss their newly released white paper on deepfakes titled Deepfakes and Payments Fraud. Is Treasury Prepared? Produced by Strategic Treasurer, a uh, leading name in treasury consulting that both Craig and I work for, this white paper sheds light on what deepfakes are, how they're being used in financial fraud, and why treasury is particularly at risk. Before outlining the practical steps organizations can take to mitigate these threats. To my mind, this white paper is a, ah, wake up call for treasury leaders and their teams, CFOs and payments professionals. It exposes an uncomfortable truth. Deepfakes are no longer a distant concern. They're a veneered threat already embedded in these shadows and seeping into overlooked corners of treasury and finance operations. I recommend that our audience download the deepfake white paper by visiting strategictreasurer.com deepfakes and now let's welcome the managing partner at Strategic Treasurer, Craig Jeffrey. It's a pleasure to have you with us. Your insights on the deepfake white paper will help bring this topic to life and we are excited to hear your perspectives.
Craig Jeffrey: Well, it's a really important, uh, topic. I think it's been in the news a lot. People are certainly clued in. And whether it's a wake up call or a warning or a combination of those two is very much the case. So thank you, Push.
Pushpendra Mehta: Thank you, Craig. Let's start our discussion with a question where if you can briefly explain what deepfakes are and what's fueling the rapid surge in deepfake incidents across business and finance.
Craig Jeffrey: When someone uses artificial intelligence to generate content that, uh, mimics or replicates what people do very realistically, that could be their voice. Video, you know, so the appearance and behavior. This is what we mean by something that's been deep faked. And the term comes from deep learning and fake. And so deep learning is part of artificial intelligence. It's a way of, you know, learning how something works. It could be text, could be video, could be voice. So it's A uh, way of deep learning combined with this fake or artificial way of making you say something that you're not saying, but it looks and appears like you're saying this, you're communicating this in a particular way. That's the, the deep fake aspect, a way of spoofing or fooling people. It's like the next generation of uh, business email compromise. Instead of just a cleverly worded email, now it's voice and facial, uh, activities and audio and video. Why is a surge? I think that's a really key question. And uh, I think most of our audience is probably familiar with how uh, technology becoming much more available, you can call it democratization of technology, happens more frequently and this is certainly occurring in increasing measure with artificial intelligence tools. And so this makes it very available for people to use it for free or for very low cost to create very good deep fakes. And the second part of that, uh, not only is the technology available, the success that the criminals have had in terms of huge payouts is really driving that behavior. I have a huge payout and it's cheaper for me to do this. Those two things combined are huge drivers for why deep fakes are becoming far more popular, more prevalent and are a greater risk.
Pushpendra Mehta: Let's build on that. Craig. Deepfakes, often considered a, ah, subset of synthetic media, are now being weaponized to perpetuate various crimes against corporations and financial institutions. Craig, why are treasury teams believed to be especially vulnerable to the growing threat of deepfake fraud?
Craig Jeffrey: I'd love to answer that. And when you use the term weaponized that was, it was funny. I mean it's a war and it's a, the weapons are becoming increasingly sophisticated. So that's clearly the case. And I think it was Willie Horton who was a famous bank robber when he finally got caught. This was, you know, I think back in Stagecoach days and he'd go rob banks or maybe his post Stagecoach. I guess I should know some of the more specifics about that. But why are you robbing banks? You know, thinking it's more of a general question, he answered it very simplistically. It's like that's where the money is. And so someone's saying why are you doing that generally? And he says well I need to rob something. That's where the money is. And the humor of that type of response aside, who has the control and the ability to move large sums of money? Treasury groups do. Where has a lot of fraud been propagated? Where has a lot of money come out of organizations? It's heavily come out of accounts payable areas, less so in payroll. But also treasury groups have been targeted and so they have more control the builder move large sums of funds and they're used to handling confidential matters, acquisitions, legal, uh, settlements, and so they're moving that type of activity. They're used to it, and so there's a little more confidence, confidentiality around their transaction. So those couple things combined make it particularly needful for treasury groups to say we're going to be targeted. They may not have lost as many, had, uh, as many fraud situations as AP for, you know, getting emails in to change your payee information and then when the payment goes out, it goes to an account controlled by criminal. You know, AP may have suffered far more losses there. But if you're a criminal and you're logical, where's more money? Where is it likely to be more contained? If I can spoof, fool or deep fake someone in treasury to enact a transfer, I'm going to come away with more money and have success in doing that.
Pushpendra Mehta: Thank you for the insightful response, Craig. Uh, the deepfake white paper cites iProves February 2025 research which reveals a troubling reality. Only 0.1% of individuals can consistently and accurately detect AI generated deepfakes. If just a tiny fraction of people can repeatedly and reliably spot these fakes, that means 99.9% of us are essentially navigating in the dark. When it comes to a digital deception, even the sharpest finance, treasury and payment security professionals are at risk of being fooled by synthetic content that looks, sounds and feels real. Does this concern you, Craig? And in light of this, could you share a couple of telltale signs treasury employees should be aware of to help spot a deep fake or digitally altered content?
Craig Jeffrey: Let me take it in a slightly different direction than answering it head on. I'll answer it from the side. What's the real question is how can we detect things that are becoming undetectable? How can we detect something that's fraudulent? I'm saying it that way because, you know, once you get over 50% of people can't do it. Okay, if you're humble, you're like, okay, that's we're at risk. When you get over 75%, you'd almost have to be proud to say, I can tell all these deep fakes. Well, we're well past the point where we can reliably trust what we see. We may not be able to detect it. We may have some suspicion, but I don't Think anybody's confident now that everything they're getting is real. And if you've been doom scrolling, you look at different videos, you're like, okay, there's two babies talking and it's like a president and you know, Elon Musk or whatever, it's like, oh this is cute but you know it's fake. You know, it's intuitive. Like that looks really quite good in terms of how the video comes across. And then you see more and more and then there's people that come up and you're like that person is fake. Like that's not a real person. Why is that? And you can't necessarily put it through your filter quickly to know that that's fake. But I guess the key thing is how can we detect what's becoming undetectable? We can't by itself, straight on by looking at things. But how can we confirm things? The things that we see, the things that we hear are what we expect them to be. How can we trust the source? How can we validate the source? I think that becomes more important, especially as things come to us outside of an approved system with dual controls, you know, triple controls or some additional valid methods. I think that's a component of what your question is as well. And so some of those things are, which is vanishing. Like we're not going to be able to do it for long. It's, you know, it's eye activity. Like we can have, we're recording over zoom. You can set it so your eyes follow the screen. It looks like they're looking at the person even if you're reading from something somewhere else. And so we have the ability to do that to show responsiveness. Well, that's an aspect of eye activity can seem unnatural or odd. And so that's an area where not all the systems are caught up. The other is um, we would refer to as mismatched facial expressions or overlay errors. In other words, you're putting a face over an existing head and body and they're not quite matching. Right? The shading, the coloring, when things turn, it's not sitting within the, the face. Right. And so that can be a situation. Um, a third one is weird or unusual or awkward body positioning and movement. Like something's not right about the movement, like it's trying to mimic it, but it's still not natural for the most part. The other thing is the teeth and hair. Very unrealistic teeth. And that's been, you know, since we've had whitening agents. There's always something about, wow, that's extraordinarily white. But everything's perfectly sized. Maybe there's no gradation between it. It looks more like the Barney, uh, teeth, the Barney the Dinosaur, where it's a straight white flow instead of individual teeth. Hair. You know, usually there's some hairs that are out of alignment, wisps are floating around, but it's always, you know, perfect. It's like watching Neo in the Matrix from 1999. It's like all their hair slicked back. It's not natural, it's not quite there yet. And audio and noise anomalies tend to play out as well. Sometimes people, experts refer to that as they're focused more on the video than the audio. And so it's creating some distortions, some unnaturalness to that. But we're at the point where it's. Many things are rapidly becoming undetectable. And at what point will they be undetectable? I mean, 90% is too much like you can't now rely on just some short conversation where it's going to, you know, you would be fooled by it. So this idea of we have to confirm and test the sources with what we're saying. Whether you do that by, hey, we have a code list that you can share a code at a certain point when a message is being delivered, uh, you can do that by confirming with a text message back to the person who's supposed to be talking to you. Are we talking right now on this topic? Say this word or whatever, some way of providing validation that who you're talking to is fine. When messages that are changing payment instructions or providing you some type of activity that could be fraudulent or could result in a fraudulent transfer if you're not checking it. And so I think that's the key thing there is not to say how can we become really good at the, well, the hair is not right. The person smoothed out all that stuff. We do those things right? There's auto tune on voices, there's the smooth out your image when you're on teams or zoom, there's like all those things are done naturally. And so whatever the points that are failing right now will disappear very, very soon. I know there's some systems that when they're checking for secure, it'll even check flow of blood and it'll look at pressure points and heat on the face and it'll become a different and a better image. And so that's going to be a way to provide an advantage for a time. But why wouldn't that, uh, be captured uh, up front. So this idea of secondary sources and validation for instructions certainly matters.
Pushpendra Mehta: Now, moving on to strengthening Treasury's defenses against deepfakes. Craig, one quote by you in the Deepfake white paper really stood out. You said when fake started with the roughly worded language and misspelled words, we all laughed at these attempts. As they became progressively advanced, we stopped laughing and paid attention to the losses that were piling up. Now, every treasurer is highly concerned about the hyper sophistication and the level of automation being used for deepfakes. Increasing our defensive posture through AI infused automation, staff training and improved workflows, uh, is of existential importance. Importance for asset protection. Can you please expand on that? And could you also elaborate on another key point from the white paper that aligns with your quote, namely that defense must begin with people, policies and processes.
Craig Jeffrey: Yeah. So push. The gist of that quote is that criminal proficiency in this war is escalating rapidly. You know, you talk about war over time. You see, okay, someone has something that can. A better club and then a spear and then arrows that you can shoot from afar, and then, you know, shields and, you know, like, there's always this increase in offense and defense and how that changes the tide of war over time. I think this idea of how we look at the threat from cyber criminals who are stealing money, trying to convince you to send money or stealing data, this war is escalating rapidly. And so it's funny when it starts, because it's not a problem. It's like, nobody is going to be fooled in a business setting. And then it gets better and better. And now you're like, is that right? No, that's not right. And then you think you're fine, and then you make up stories in your head that they're not after our company, they're. It's all right. And so we're at the point where we've seen enough losses. This idea of the sophistication has become extremely good. I think you use the term hyper sophistication, right? And supremely easy to do. The tools are readily available. And so now it's how can I spoof you? I have a massive tool set to do that. And I don't have to be a nation state or a huge crime syndicate to do something that can fool you. And I may, I may not have to convince you to send all the money immediately, but maybe I can convince you to do certain things, which allows me to better interrogate, probe your defenses, your points of exposure, the surface area of attacks. So that's one aspect of it. The proficiency is growing rapidly. And like in any type of, you know, war and defensive posture, it's like the defense must match the pace of the offense and uh, what the criminals are doing. I think the last part of the question, as you said, defense must begin with people, processes and policies or those three things matter, right? People are the ones that are going to get spoofed, so they have to be mindful. They're the ones who manage the controls. They're the ones who identify where a need is to protect maybe a newly revealed weakness. And they're the ones who have to make sure that the policies, the systems, the tools and the processes support that. So policies and processes, a process to make sure there's validation has to occur. I think everybody who's listening knows and understand that. So I won't go into too much detail on that other than to say validation processes, whether it's the form of you're doing a callback for every change request that comes in using a different source, or you're using an AI infused validation service, you're using list of permission people, you're using, I'll call it, uh, network, you know, power of network functionality there where it's like, okay, six other companies have now moved to change payments to Acme company, to this other address, to this other account at this different bank. And so when we think about processes, that would include that. I think the other aspect too is it's people, processes, technology, policies. But it also would include modern structures, modern banking structures for their bank accounts to isolate activity, to be able to call it out more readily and to see how it moves. So a modern concentration structure, whether you use header accounts or concentration accounts or isolated accounts for a particular activity, that'd be one thing. Another one would be services. So banking services, for example, there's significant number of information services, security services, validation services that you can turn on with your banks. And you should make the proof that we don't need something like these security services. The default position should be we're going to use the security services that the banks provide. We're also going to get data on a more regular basis. And if we're not reconciling monthly, we're reconciling monthly. We're reconciling monthly. Maybe we move it to weekly or daily because speed matters. Structure, systems, services, data and processes that will detect and deter are really vital. So I would have added to the quote, modern structures and services. But how long can you make a quote? Right?
Pushpendra Mehta: Well, uh, that was a deeply informative response. Thank you, Craig. Your emphasis on the role of people, policies and processes alongside AI driven defenses really reinforces the idea that Treasury's best protection against deep fakes begins with a strong internal foundation or structure. Craig, my last question for today builds on our conversation so far. Even with robust prevention, detection and controls in place, some deepfake attacks may still succeed. In such cases, how vital, uh, is it to have a well rehearsed response plan that can be activated the moment a deep fake is identified?
Craig Jeffrey: That's a good setup to the question, right? It's like in light of all the scary stuff and the risk and the great loss, it's fairly obvious that things are going to get through. And so if something happens, how do you respond quickly? So I think that's, I think that's a great question. What's necessary for a well rehearsed response plan? I guess my background on this is, you know, your layers of security matter. You don't want one layer of security to be compromised and you lose. You have to have multiple layers. That way if one layer is compromised, you still have another. So security layers matter. Make sure they're the right ones and make sure every layer is protected so that if one layer is removed, you're finding out that somebody has removed a security layer. They've removed an electronic pre authorization off of an account so someone can debit your account. Oh, now uh, we know that that's occurred. Now we're watching and figuring out what occurred. One of the, this is, uh, you've probably heard this is if you're being chased by a bear, you don't have to outrun the bear, you have to outrun your friends. But you want to make yourself hard enough to deep fake or to commit fraud that it's not worth it for the criminals and it's not worth it to them because they're going to try to find softer targets. And I mean they'll try to roll up as many as they can, but make it so it's sufficiently hard that they will go after other companies first. And that doesn't mean pointing them in the direction, but making your defense is sure. And so you need to outrun, you need to have this mindset. I'm going to be at the forefront, maybe not the top 1%, but maybe I'm going to shoot for the top 20%. So you're well above half of the companies that are, what their posture is, you know, which is below the midpoint and there'll be plenty of Opportunities for criminals to steal from them have multiple security layers. Every security layer matters. Make sure you're staying at the front of the broader pack. Maybe not number one, but stay well clear of, I would say 75, 80%, stay in the top quartile, top, you know, two deciles. And then finally, because you said having a well rehearsed response plan, the answer could be yes. Or, you know, I would just maybe expand on that. It's like, yes, prepare for a loss or issue. Speed matters. And because speed matters in these fraud situations, I have to respond quickly to stem the loss or to recover funds. Because speed matters, a rehearse plan matters. And because a rehearse plan matters, that assumes that you have a good and updated response plan, that you have it in place, that you test it and you test it regularly. Now, regularly might be defined as three months or six months once a year. I don't think is enough to do that. And that's something where we find ourselves adapting, uh, too as well. But that's essential for cybersecurity, for protecting payments. It's very crucial that you have a rehearsed plan. Who do we call? Who do we notify? We notify criminal law enforcement that will help, uh, pursue the criminals. We want to make sure we can contact our banks immediately so they can use what their functionality is to stop it if it's still within the banking system, or they can put out other alerts to stop it from criminals exploiting other companies. So if someone has gained control of account and they're moving funds to a particular account, once that's discovered what's happening, they can pass out alerts to flag that account because it's going to a, uh, compromised account, which is used to exfiltrate money out of the banking system or out of the country, wherever it came from. So your question is, how vital is it? I think it's essential if you don't have that, a plan, that's not acceptable. If you don't rehearse it at all, that's still in there of not acceptable. What would be ideal is to have it, to rehearse it, to make people aware that they have it. Don't get tied up into the, uh, oh, this is embarrassing. The money's gone. I'm done. No, the money. If the money's gone, do what you can to stop it from happening to others and see if you can catch it before it has left the banking system. Your bankers will be a big help. Whatever government crime agency you have can, can help you in that area as well.
Pushpendra Mehta: Those are great points, Craig. Your insights on the importance of a well rehearsed response plan truly underscore the need for readiness, not just resilience. Is there anything else you'd like to add or share before we wrap up this discussion?
Craig Jeffrey: Well, a couple of points. As a uh, as a wrap up or summary, I guess I would pull out and say that what we've seen with deep fakes should be considered both a warning and a threat. I think you called it a wake up call or you called it a uh, warning or it's all of those. It's a wake up call, it's a warning, it's a threat that has to be addressed. And if you haven't had the wake up call, like you haven't seen that and recognize that as a wake up call, you know, you've listened this far in the podcast and so take this as a wake up call to the fraud war that is going on. Make sure others in your organizations know that too. You can't just pretend it doesn't exist. It's not a threat for us now because let's say you're protected today and if you don't change, it won't be long before you're exposed. And if you're not treating the threat seriously, if you're not viewing it seriously enough, or you parts of your company or not help change their perspective or your perspective and the level of activity you're doing to defend yourself, if you still don't like that, that doesn't seem right. And you're over responsible for payments, you're in treasury, you're the superintendent of payments or you're an AP and you're, you're doing things. If that's not something that you think makes sense, I would encourage you to move to another area of finance because the protection has to be there and you need to do that. And if that's not something that gets you engage to defend that, you probably need to move to another area. That's, that would be the right thing for your company. And you know, you could be worn out uh, in this area, do something else but make sure people in your company are doing that. And there's no question that your organization needs to be hyper vigilant with payment security. Train your people on payment security, set up the reaction plans and test those. Make sure you're looking at people, processes, structure, services, technology to provide that support. I don't want people to listen to this, just say, oh, I just need to protect against deepfake criminals will use any means necessary. Deep fakes are a very good tool to get you to give up information or to get you to act in a way you shouldn't, leaving your company vulnerable to a loss or creating the situation where funds leave the organization.
Pushpendra Mehta: Well, those are wise words. And before we close out this episode, I, uh, encourage all our listeners to head over to strict strategic treasurer.com deepfakes and download their must read white paper on deepfakes. That brings us to the end of this episode. Craig, thank you for sharing your valuable perspectives and to our audience, thank you for joining us. Stay sharp, stay deepfake aware and trained and stay one step ahead because anticipation is the key to outsmarting digital fabrications or intelligent forgeries. If you found this discussion helpful, please subscribe and share this episode with your network. We'll be back soon with more meaningful conversations on the evolving world of corporate, treasury and payments. Thank you and have a wonderful week. This podcast is provided for information purposes only and statement statements made by CTM File or guests on this podcast are not intended as legal, business, or consulting advice. For more information, visit ctmfile.com.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.