← Back to glossary Threats and attacks

Deepfake

What is a deepfake?

A deepfake is synthetic audio, video or imagery generated with AI that realistically impersonates a real person's voice or appearance. A few seconds of public audio are enough to clone a voice, and the material any executive has on LinkedIn, press releases or webinars is enough to fabricate a convincing video within hours. It is the technological evolution of social engineering: classic schemes such as Business Email Compromise or vishing now arrive with the voice and face of someone the victim trusts.

Why does it matter?

Because it breaks the verification mechanism everyone relied on without noticing: recognising the other person. The Arup case (Hong Kong, 2024) made it plain: a finance employee wired around 25 million dollars after a video call in which the "CFO" and several "colleagues" were real-time deepfakes. Voice-cloning tools are public, cheap and need very little source material, which attackers harvest through OSINT. The impact goes beyond payment fraud: deepfakes are used to defeat KYC identity verification in banking, to run spoofing schemes with fake candidates in remote hiring, and to mount disinformation campaigns against executives and brands. Regulators have reacted: the EU AI Act imposes transparency obligations in Article 50 — whoever generates or shares deepfakes must disclose that the content is artificial — and NIS2 requires cyber-hygiene training that can no longer ignore this threat.

Key points

Three operational flavours: cloned audio for calls and voice notes (the most common in fraud, given its low cost), real-time face-swap video for video calls, and static imagery to forge identity documents or pass KYC checks.

CEO fraud 2.0: classic BEC requested the transfer by email; now the email is reinforced with a deepfake call or video call that disarms suspicion. Urgency and secrecy remain the warning signs, even when the voice is flawless.

Attacks on identity verification: deepfakes are fed into digital onboarding either through virtual cameras (injection attacks) or by showing imagery to the camera (presentation attacks). Identity providers respond with active and passive liveness detection, with uneven results.

Technical detection helps but is not enough: artefact-based detectors lose accuracy with every model generation, and nobody runs forensic analysis in the middle of a live call. Provenance standards like C2PA (Content Credentials) mark legitimate content, but adoption is still partial.

The controls that work are process controls, not perception: out-of-band verification (hang up and call a known number), dual approval for payments and bank-detail changes, and thresholds no verbal order can override, whoever it comes from.

Legal framework in Europe: Article 50 of the EU AI Act requires labelling AI-generated or manipulated content, and using a deepfake to defraud or impersonate is a crime regardless of the tool. Transparency is the generator's duty; verification remains the payer's responsibility.

Example: CEO fraud over a deepfake video call

A treasury manager receives an email from the CFO announcing a confidential corporate transaction and inviting him to a video call with the leadership team. On the call he sees and hears the CFO and two other executives, who ask him to execute several transfers to new accounts before close of business. Everything fits: the faces, the voices, the context of the deal (built from public information and a previously compromised mailbox). He executes the transfers. None of the participants was real: they were real-time deepfakes operated by the attackers, mirroring the Arup case.

What would have stopped the fraud is not a deepfake detector but process: a policy requiring out-of-band verification (calling the CFO's known mobile) for any urgent payment or account change, mandatory dual approval above a threshold with no "confidentiality" exceptions, and awareness training that teaches that seeing and hearing someone no longer verifies their identity. If the fraud does get executed, every minute counts: triggering the incident response protocol and contacting the bank immediately can freeze the funds before they scatter.

Common mistakes

  • Trusting voice or face recognition as verification. That is exactly what a deepfake forges; identity is verified through an independent channel or a factor the attacker cannot clone.
  • Training staff against email phishing while ignoring voice and video. If awareness programmes skip fake calls, voice notes and video meetings, employees drop their guard precisely on the channels where the attack is most convincing.
  • Keeping payment processes with urgency exceptions: if a verbal order from the CEO can bypass dual approval, so can a deepfake of the CEO. Controls are only as strong as their worst exception.
  • Outsourcing the problem to automated detection tools. Their error rates grow with every model generation and they do not operate inside a live conversation; they are a complement, not a primary control.
  • Having no plan for the reverse scenario: a deepfake of your own CEO announcing something false to employees, customers or the market. Without a prepared communication and rebuttal protocol, the reaction comes too late.

Related services

This concept may be related to services such as:

Frequently asked questions

I run the finance team: how do I avoid approving a transfer ordered by a deepfake of my CEO?

With process controls that do not depend on recognising anyone. First, mandatory out-of-band verification: for any urgent payment or bank-detail change, hang up and call the requester's known number — never a number provided in the message itself. Second, dual approval above a threshold, with no exception for urgency or confidentiality: those two words are precisely the signature of social engineering. Third, culture: the employee who pauses a payment to verify should be congratulated, not penalised. The Arup case proves that a video call with several executives "present" no longer proves anything.

Can attackers clone our executives' voices from the videos we publish on LinkedIn or YouTube?

Yes, and with very little material: current cloning tools produce a convincing voice from a few seconds of clean audio, and one webinar or interview is more than enough. Removing all public content is unrealistic for any executive with a commercial presence, so the answer is not hiding but assuming voice and image are cloneable. That means shifting trust to non-cloneable factors: channels you initiate yourself, agreed code words for family or corporate emergencies, and payment processes that reject verbal orders. Running an OSINT exercise against your own executives shows exactly what raw material an attacker has to work with.

What does the EU AI Act require regarding deepfakes?

Article 50 imposes transparency obligations: providers of systems that generate synthetic content must make it technically detectable (for instance through watermarking), and anyone deploying a deepfake must disclose that the content has been artificially generated or manipulated, with narrow exceptions (evident creative use, satire). These obligations are fully applicable from August 2026, with significant penalties for non-compliance. For a business this cuts both ways: if you use generative AI in marketing or communications, you have labelling duties; and if you are targeted by a deepfake, the regulation reinforces the illegality of the content. Our EU AI Act compliance service covers both fronts.

How do I verify someone's identity on a video call if I suspect a deepfake?

Visual tricks (asking them to turn their head or pass a hand over their face) work increasingly poorly against real-time models, so do not rely on them as your only barrier. What is reliable is leaving the channel: propose continuing through a route you initiate — calling their usual number yourself, writing on the internal corporate channel — or validate a fact only the real person knows that is neither published nor sitting in a compromisable mailbox. In high-risk contexts (payments, access grants, remote hiring) the protocol must be written in advance: improvising how to verify mid-call, under pressure, is exactly the scenario the attacker has rehearsed and you have not.