Deepfake fraud is a form of social engineering in which criminals use AI-generated or AI-altered audio, video or images of real people, such as an executive, colleague, vendor or job candidate, to deceive employees. The goal is usually to get someone to send money, change bank details, share sensitive data or grant access. Because the fake looks or sounds like someone the target knows, it can defeat the instinct to trust a familiar voice or face.
At a glance
- It is impersonation fraud powered by generative AI: cloned voices, face-swapped video or fabricated images.
- Common targets are finance staff, help desks, HR and recruiting teams, and executive assistants.
- Creating a convincing voice clone can take only a short audio sample, such as a recorded talk or video.
- Detection tools help but are not reliable on their own; verification processes are the main defense.
- It often combines with email, text or chat messages that set up the call, much like business email compromise (BEC).
What problem it solves
Deepfake fraud is a threat, not a solution, but naming it helps buyers decide what controls to put in place. Many payment and access processes still rely on a human recognizing a voice or face: “the CFO called and approved it” or “I saw them on video.” Generative AI tools have made it far easier and cheaper to fake those signals convincingly.
The risk is not limited to large wire transfers. Help desks can be talked into resetting passwords and multi-factor authentication (MFA) for an impersonated employee. Recruiters can unknowingly hire a fake candidate who then gets network access. Vendors can be impersonated to redirect invoice payments. Each of these targets a process, so the defense is mainly about fixing the process.
How it works
Research. Attackers gather public material on the person they will impersonate: earnings calls, conference talks, podcasts, social media videos and voicemail greetings. They also learn the organization chart, vendor relationships and payment routines, often from phishing or a compromised mailbox.
Generation. Using voice cloning and face or video synthesis tools, they create audio or video of the target saying what they need. Some tools work in real time, letting the attacker speak or appear as the impersonated person during a live call.
Pretext and pressure. The fake is delivered with a reason to act quickly and quietly: a confidential acquisition, an overdue supplier, a locked-out executive traveling abroad. Urgency and authority discourage the target from checking.
Cash-out. Money goes to accounts controlled by the attackers and is moved on quickly, or the stolen access is used for further attacks such as data theft or ransomware.
When it matters for buyers
- When reviewing payment controls. Any approval that relies on recognizing a voice or face over a call should get an out-of-band check.
- When a peer is hit. Incidents at similar companies are a good prompt to test how your finance team and help desk would respond.
- When choosing security awareness training. Look for content and simulations that cover voice and video impersonation, not only email phishing.
- When hardening the help desk. Identity verification for password and MFA resets is a frequent weak point.
- When renewing cyber insurance. Check whether social engineering losses are covered and what controls the insurer expects.
Questions to ask vendors
- For training providers: do your courses and simulations include voice cloning and video impersonation scenarios?
- Can you run simulated vishing (voice phishing) calls against our finance team and help desk?
- For meeting, contact center or identity verification platforms: what deepfake detection do you offer, and how do you measure its accuracy?
- How does your help desk or identity verification process confirm a caller is who they say they are?
- What logging do you keep that would help us investigate a suspected deepfake call?
How it differs from business email compromise
Business email compromise (BEC) uses email from a compromised or look-alike account to impersonate an executive or vendor, usually to redirect payments. Deepfake fraud uses synthetic voice or video to make the impersonation more convincing, often over phone or video calls, and is frequently combined with BEC: the email sets up the request and the deepfake call “confirms” it. The same core defense applies to both: verify through a separate, trusted channel. Security awareness training (SAT) is one of the main ways to build that habit; see our security awareness training overview.
