RESOURCES · SECURITY & EMAIL

Deepfake voice & video scams,
explained

Artificial intelligence can now copy a person's voice from a few seconds of audio, and even put a convincing fake face on a live video call. Criminals are using this to impersonate CEOs and colleagues — usually to authorise a payment. Here's what deepfake scams look like, and how to keep your business a step ahead.

Applies to: Leaders & finance teams Read: ~4 min Level: Non-technical
Quick answer

Attackers use AI to fake a familiar voice (a phone call from the "CEO") or even a live video call, to pressure staff into paying or sharing data. Seeing or hearing someone is no longer proof it's really them. The defence hasn't changed and is simple: verify any money or sensitive request through a separate, trusted channel — a deepfake can't fake that.

HOW IT WORKS

When your eyes and ears can be faked.

AI can clone a voice from short audio — a voicemail, a webinar recording or a social-media clip — and newer tools can swap a face onto a live video call. Combined with urgency, secrecy and real details scraped from online, it can be very convincing. The person on the other end sounds exactly like your boss, references a real project, and needs your help right now. Nothing about the moment feels off — and that's precisely what makes it dangerous.

REAL-WORLD PLAYS

How the scam is used.

The technology changes, but the goal is almost always the same — get money moved or information shared. A few of the plays we see:

WHY IT'S SO CONVINCING

It hijacks our instincts.

Deepfakes work because they exploit the shortcuts our brains rely on every day:

HOW TO PROTECT YOUR BUSINESS

Verify the human, not the medium.

  1. Verify out-of-bandCall the person back on a number you already have — not one they gave you on the call. A quick, independent check on a known number defeats the whole scam.
  2. Use a strict payment / bank-change processAny payment or change of bank details should always need an independent second check, no matter who appears to be asking or how urgent it feels.
  3. Agree a private "safe word" or challenge questionFor unusual or high-pressure requests, have a private phrase or question only the real people would know — something a deepfake can't answer.
  4. Brief your executives and finance teamMake sure the people most likely to be targeted know how these scams work — and be mindful of how much of your voice and video is public, since that's the raw material attackers use.
The reassuring part. None of this beats a simple call-back. A scammer can fake a voice or a face, but they can't answer your call on the real person's known number.
AI-ERA SCAMS

Would a fake call from the "CEO" get a payment approved?

Deepfakes are exactly the kind of attack that slips past gut instinct. Our free IT Health Check reviews your payment-verification habits and how aware your staff are of AI-driven scams — and shows you the simple, practical steps that stop a faked voice or face from ever getting a payment over the line.

KEEP READING

Related resources