Fraud is no longer what it used to be. Once seen as a marginal risk, it is now evolving into something far more scalable and sophisticated. The rise of artificial intelligence and widespread access to advanced technologies have made attacks more credible, faster, and above all, easier to execute.
The shift is not just about sophistication; it is about accessibility. Exploiting identity data no longer requires advanced technical skills. Large-scale data breaches provide abundant raw material: names, addresses, credentials and personal records. Once aggregated and enriched, this data can be used to reconstruct credible identities at scale and fuel fraud scenarios that are increasingly difficult to distinguish from reality. Technology is not just professionalizing fraud; it is industrializing it.
For insurers, this evolution is particularly critical. The industry is built on trust, the reliability of declared information, and efficient processes. Yet compromised data now allows these mechanisms to be bypassed at scale. Underwriting based on reconstructed identities, claims supported by plausible but manipulated evidence, and interactions shaped through social engineering are no longer exceptions. Fraud is no longer isolated, it is becoming a systemic risk, at the intersection of cyber and business operations.
Fraud is no longer an isolated phenomenon; it is becoming a systemic risk, at the crossroads of cyber and business.

Fraud in the age of AI: the blind spot for insurers (Source: FBI’s figures, 2025)
The chart, based on FBI’s figures, clearly illustrates a strong and accelerating increase in AI-driven insurance fraud in the United States, confirming both the scale and the sophistication of emerging threats. Given the historical pattern where innovation in fraud techniques typically originates or scales first in the U.S. market before spreading internationally, it is highly likely that a similar trajectory will be observed across Europe. As digitalization and AI adoption continue to expand within the EU financial and insurance sectors, Luxembourg, given its highly interconnected and cross-border ecosystem, will not remain immune. It is necessary to anticipate this evolution proactively and adapt detection, prevention, and awareness mechanisms accordingly.
But what risks are insurers exposed to with the rise of generative AI? The first risk lies in the growing ability of fraudsters to produce evidence that is indistinguishable from reality. Generated images, manipulated videos, altered documents and synthetic voices are making traditional controls obsolete. Verification is no longer sufficient. Insurers must develop advanced detection capabilities that combine technical analysis, behavioral patterns and business context to identify inconsistencies invisible to the human eye.
The second risk is more fundamental. It stems from the large-scale reuse of identity data compromised during cyber incidents. Fraud is no longer based solely on fabrication, but on the exploitation of real data, making it increasingly difficult to distinguish legitimate customers from well-informed fraudsters. The challenge is to detect subtle deviations, correlate weak signals, and integrate cyber intelligence into business risk analysis.
In this context, insurers must rethink both priorities and posture. Identity becomes central, and investment in detection capabilities must be seen as a business imperative, not a cost.
The second priority concerns resources. Despite the rise in threats, investments in advanced detection capabilities often remain insufficient. These measures, although critical, are still perceived as costs rather than as levers for controlling risk. Boards of directors need to adopt new perspectives: these investments directly protect the business model. They are becoming a key element of resilience, just like traditional financial mechanisms.
Faced with AI-boosted fraud, capable of imitating reality with precision, the challenge is no longer just technical: it is becoming strategic.
“We often continue to secure systems, while fraudsters are mostly learning how to manipulate identities and decisions.”
Insurance has always been able to model risk. But with AI‑driven fraud now capable of replicating reality with unprecedented precision, the challenge is no longer purely statistical, it has become strategic.
This evolution calls for a profound transformation of the CISO role. Far beyond its traditional scope, it is now emerging as a strategic partner, capable of linking cyber challenges to business priorities. In a context where fraud, data, and operations are increasingly intertwined, the challenge goes beyond protecting systems: it is about securing decisions and preserving what ultimately defines a company’s value; trust.
This shift paves the way for a more central and influential role. By developing a deep understanding of value chains, strengthening collaboration with business teams, and actively contributing to strategic decisions, CISOs are becoming key drivers of resilience and performance. More than just a function, it is now a lever for sustainable transformation within the organization.

