Deepfakes have moved from novelty to fraud tool. Cloned voices, real-time video impersonation and AI-generated identity documents are now cheap enough that criminals use them against ordinary businesses, not just celebrities and heads of state. The result is that seeing or hearing someone is no longer proof that you are dealing with them.
Most security programs were not designed for that. Payment approvals rely on a familiar voice, help desks reset passwords after a convincing phone call, and onboarding checks compare a selfie to an ID photo. Each of those controls assumes the media is genuine. This article looks at the three forms of deepfake fraud that matter most to organizations and how to rebuild verification so it holds up when the media cannot be trusted.
Deepfake audio: the cloned executive
Voice cloning is the most mature and most common form of deepfake fraud. A few seconds of clean audio from a conference talk, podcast, earnings call or social media video can be enough to produce a convincing imitation. Attackers use it in the classic CEO fraud pattern: an urgent call or voicemail from a senior executive asking finance to move money, or asking IT to reset an account.
Public examples are growing. In 2024, criminals used a cloned voice of WPP’s chief executive in an attempted scam against the advertising group’s staff, and a Ferrari executive stopped an impersonation of the company’s CEO by asking a question only the real CEO could answer. In May 2025 the FBI warned that criminals were sending AI-generated voice messages impersonating senior US officials to gain the trust of their targets. The attempts that fail make the news; the ones that succeed usually do not.
Deepfake video: when a video call is not proof
Video was long treated as the stronger check: if you can see the person, it must be them. That assumption broke in early 2024, when an employee at the engineering firm Arup in Hong Kong transferred about $25 million after a video conference in which the chief financial officer and other colleagues were all deepfakes. The employee had initially been suspicious of the email request; the video call is what convinced them.
Real-time face-swapping tools now run on consumer hardware, and they are being used in job interviews as well as payment fraud. US authorities have repeatedly warned about North Korean IT workers using stolen or synthetic identities, sometimes with altered video, to get hired remotely at Western companies. For hiring managers and help desks, a camera-on call is no longer a reliable identity check on its own.
Synthetic identities: fake people that pass KYC
The third category targets onboarding rather than employees. A synthetic identity blends real data, such as a stolen Social Security number, with invented details and an AI-generated face. Generative tools can produce a matching driver’s license image and a selfie that passes a basic photo comparison. Criminals use these identities to open bank accounts, apply for credit, launder money or pass vendor and employee background checks.
In November 2024 the US Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an alert warning banks about fraud schemes that use deepfake media to get around identity verification. Its red flags include identity photos that look inconsistent or show signs of manipulation, customers who avoid live verification or multifactor checks, and images that match galleries of AI-generated faces. Any business that verifies customers or suppliers remotely should treat those signals as relevant, not just banks.
Rebuilding verification for the deepfake era
Detection tools help, but they are in an arms race with the generators and should not be your primary control. The more durable approach is to design processes where a perfect fake still cannot complete a high-risk action on its own:
- Verify out of band. Any request to move money, change bank details, reset credentials or share sensitive data is confirmed through a separate channel using contact details already on file, never the phone number or meeting link in the request.
- Require two people for high-value actions. Dual approval for payments above a threshold means one deceived employee cannot complete the fraud alone.
- Make MFA phishing-resistant. Multifactor authentication is table stakes, but codes read over the phone can be socially engineered. Passkeys and FIDO2 security keys cannot be handed to a caller.
- Harden the help desk. Password and MFA resets should require identity proofing that does not depend on a voice or video call, such as a manager’s confirmation or a verified in-person or document check.
- Use biometrics with liveness and injection detection. For onboarding and high-risk workflows, biometric checks are useful only if they confirm a live person is present and detect camera feeds replaced with synthetic video. Voice alone should not authenticate anyone.
- Agree on challenge questions or code words. Executives and finance staff can use pre-agreed verification phrases for unusual requests, as the Ferrari case showed.
- Monitor for identity anomalies. Watch for new accounts, logins or payee changes that do not fit normal patterns, and for your executives’ likenesses appearing in scams or fake profiles.
The trade-off is friction. Callbacks and dual approvals slow things down, and staff will push back when the “CEO” is impatient. Leadership has to state clearly that following the procedure is always acceptable, even for them. For how deepfakes fit into the wider pattern of AI-enabled attacks, see AI-Powered Threats: Cyberattacks Are Getting Smarter, and for the human side of these scams, Social Engineering Has Evolved. Our cybersecurity and compliance services help put these verification controls in writing and test them.
Frequently asked questions
Can deepfake detection software solve the problem?
It can help, particularly for identity verification during onboarding, but detection accuracy varies and improves only until the next generation of tools. Treat it as one layer. Process controls such as callbacks and dual approval work regardless of how good the fake is.
How much audio does someone need to clone a voice?
Modern tools can produce a usable imitation from a short sample, often seconds rather than minutes. Any executive with public talks, interviews or videos online should assume their voice can be cloned.
Are small businesses really targeted with deepfakes?
Yes. Voice cloning is inexpensive, and smaller firms often have fewer approval steps, so a single convincing call to the right person can move money. The same controls, callbacks and dual approval, are cheap to implement at any size.
Making verification deepfake-resistant
Delana Technologies helps organizations redesign payment, help desk and onboarding verification so a convincing fake cannot complete a high-risk action, and trains staff to follow those procedures under pressure. To review where your processes still rely on a voice or face, call 239.414.5126 or contact us.
Sources: FinCEN Alert on fraud schemes involving deepfake media targeting financial institutions (November 2024); FBI public service announcement on AI-generated impersonation of senior US officials (May 2025); CNN reporting on the Arup deepfake fraud (May 2024); The Guardian reporting on the WPP voice-clone attempt (May 2024); Bloomberg reporting on the Ferrari CEO impersonation attempt (July 2024); FBI and US government advisories on North Korean IT workers.
