What Is Deepfake Fraud?

Also called: Deepfake scam

Related problems: Worried someone could fake our CEO's voice to request a wire transfer; Staff can't tell a real video call from a fake one; Fake job candidates or vendors on video interviews; Payment approval process relies on recognizing a voice

Deepfake fraud is a form of social engineering in which criminals use AI-generated or AI-altered audio, video or images of real people, such as an executive, colleague, vendor or job candidate, to deceive employees. The goal is usually to get someone to send money, change bank details, share sensitive data or grant access. Because the fake looks or sounds like someone the target knows, it can defeat the instinct to trust a familiar voice or face.

At a glance

  • It is impersonation fraud powered by generative AI: cloned voices, face-swapped video or fabricated images.
  • Common targets are finance staff, help desks, HR and recruiting teams, and executive assistants.
  • Creating a convincing voice clone can take only a short audio sample, such as a recorded talk or video.
  • Detection tools help but are not reliable on their own; verification processes are the main defense.
  • It often combines with email, text or chat messages that set up the call, much like business email compromise (BEC).

What problem it solves

Deepfake fraud is a threat, not a solution, but naming it helps buyers decide what controls to put in place. Many payment and access processes still rely on a human recognizing a voice or face: “the CFO called and approved it” or “I saw them on video.” Generative AI tools have made it far easier and cheaper to fake those signals convincingly.

The risk is not limited to large wire transfers. Help desks can be talked into resetting passwords and multi-factor authentication (MFA) for an impersonated employee. Recruiters can unknowingly hire a fake candidate who then gets network access. Vendors can be impersonated to redirect invoice payments. Each of these targets a process, so the defense is mainly about fixing the process.

How it works

Research. Attackers gather public material on the person they will impersonate: earnings calls, conference talks, podcasts, social media videos and voicemail greetings. They also learn the organization chart, vendor relationships and payment routines, often from phishing or a compromised mailbox.

Generation. Using voice cloning and face or video synthesis tools, they create audio or video of the target saying what they need. Some tools work in real time, letting the attacker speak or appear as the impersonated person during a live call.

Pretext and pressure. The fake is delivered with a reason to act quickly and quietly: a confidential acquisition, an overdue supplier, a locked-out executive traveling abroad. Urgency and authority discourage the target from checking.

Cash-out. Money goes to accounts controlled by the attackers and is moved on quickly, or the stolen access is used for further attacks such as data theft or ransomware.

When it matters for buyers

  • When reviewing payment controls. Any approval that relies on recognizing a voice or face over a call should get an out-of-band check.
  • When a peer is hit. Incidents at similar companies are a good prompt to test how your finance team and help desk would respond.
  • When choosing security awareness training. Look for content and simulations that cover voice and video impersonation, not only email phishing.
  • When hardening the help desk. Identity verification for password and MFA resets is a frequent weak point.
  • When renewing cyber insurance. Check whether social engineering losses are covered and what controls the insurer expects.

Questions to ask vendors

  • For training providers: do your courses and simulations include voice cloning and video impersonation scenarios?
  • Can you run simulated vishing (voice phishing) calls against our finance team and help desk?
  • For meeting, contact center or identity verification platforms: what deepfake detection do you offer, and how do you measure its accuracy?
  • How does your help desk or identity verification process confirm a caller is who they say they are?
  • What logging do you keep that would help us investigate a suspected deepfake call?

How it differs from business email compromise

Business email compromise (BEC) uses email from a compromised or look-alike account to impersonate an executive or vendor, usually to redirect payments. Deepfake fraud uses synthetic voice or video to make the impersonation more convincing, often over phone or video calls, and is frequently combined with BEC: the email sets up the request and the deepfake call “confirms” it. The same core defense applies to both: verify through a separate, trusted channel. Security awareness training (SAT) is one of the main ways to build that habit; see our security awareness training overview.

Frequently Asked Questions

How do deepfake scams usually target businesses?
Common patterns include a phone call or voicemail in an executive's cloned voice asking for an urgent payment, a video meeting with faked participants, fake job candidates on video interviews, and calls to the help desk impersonating an employee to reset a password or multi-factor authentication.
Can software detect deepfakes?
Detection tools exist and some are built into meeting, call center and identity verification products, but none catches every fake, and generation tools keep improving. Treat detection as one layer; verification procedures that do not depend on recognizing a face or voice matter more.
What is the best defense against deepfake fraud?
Process. Require out-of-band verification for payments, bank detail changes and access resets, using contact details you already have on file rather than ones given in the request. Use approval workflows with more than one person for large transfers, and train staff that a familiar voice or face is not proof of identity.
Is deepfake fraud covered by cyber insurance?
It depends on the policy. Losses from tricked payments are often treated as social engineering or funds transfer fraud, which some policies cover only with a separate endorsement or a lower sub-limit. Check the wording with your broker.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.