Artificial intelligence can now copy a person's voice from a few seconds of audio, and even put a convincing fake face on a live video call. Criminals are using this to impersonate CEOs and colleagues — usually to authorise a payment. Here's what deepfake scams look like, and how to keep your business a step ahead.
Attackers use AI to fake a familiar voice (a phone call from the "CEO") or even a live video call, to pressure staff into paying or sharing data. Seeing or hearing someone is no longer proof it's really them. The defence hasn't changed and is simple: verify any money or sensitive request through a separate, trusted channel — a deepfake can't fake that.
AI can clone a voice from short audio — a voicemail, a webinar recording or a social-media clip — and newer tools can swap a face onto a live video call. Combined with urgency, secrecy and real details scraped from online, it can be very convincing. The person on the other end sounds exactly like your boss, references a real project, and needs your help right now. Nothing about the moment feels off — and that's precisely what makes it dangerous.
The technology changes, but the goal is almost always the same — get money moved or information shared. A few of the plays we see:
Deepfakes work because they exploit the shortcuts our brains rely on every day:
Deepfakes are exactly the kind of attack that slips past gut instinct. Our free IT Health Check reviews your payment-verification habits and how aware your staff are of AI-driven scams — and shows you the simple, practical steps that stop a faked voice or face from ever getting a payment over the line.