Deepfakes Updated June 24, 2026

Deepfake Fraud at Work: The $25M Video-Call Scam and How to Stop It

An employee joined a video call with the CFO and colleagues, and authorized roughly US $25 million in transfers. Every person on the call was a deepfake. Here's how AI impersonation attacks work — and the single habit that defeats them.

An employee of a multinational firm joins a video call with the company’s CFO and several colleagues. Familiar faces. Familiar voices. The CFO authorizes a series of urgent transfers. Every participant on the call was a deepfake. The employee transferred roughly US $25 million to the attackers. (Reported 2024.)

The lesson is not that the employee was careless. It’s that eyes and ears are no longer adequate verification for high-stakes requests.

What is a deepfake attack?

A deepfake attack uses AI-generated audio or video to impersonate someone the target trusts — an executive, a colleague, a vendor. Seconds of public audio or video is enough to clone a voice or a face. The attacker then uses that synthetic identity to authorize a payment, request credentials, or extract sensitive data.

What makes it so effective is that it hijacks a reliable human instinct: we trust people we recognize. When the face and voice are familiar, our guard drops.

Why the old warning signs are gone

For years, security training taught people to spot fraud by its rough edges: bad grammar, generic greetings, a slightly-wrong email address. AI erased those tells.

BeforeNow
PhishingGeneric, error-ridden, mass-mailedFlawless, personalized to your role and projects, thousands at a time
ImpersonationA spoofed email claiming to be an executiveA cloned voice on the phone, or a live deepfake on video
ReconnaissanceManual research on a few targetsAutomated profiling of staff, org charts, and writing styles

The takeaway: judge requests by what they ask you to do — not how well they’re written, or how familiar they look.

The one habit that stops it: verify out-of-band

Any request involving money, credentials, sensitive data, or unusual urgency should be verified through a separate channel you already trust, before you act.

Do:

  • Call back on the number in the company directory — not the one the requester provided.
  • Confirm in the official chat or ticketing system.
  • Let verification add a few minutes. Real executives respect it.

Never:

  • Verify using contact details the requester gave you (attackers happily “confirm” their own scam).
  • Let urgency or authority pressure you into skipping the step. Manufactured urgency is the whole play.
  • Trust a voice or a face alone — both can be cloned.

This single habit — out-of-band verification — would have stopped the $25 million transfer. It costs minutes. It saves millions.

Build it into the culture, not just the individual

Individual vigilance fades under pressure, so make verification a norm, not a judgment call:

  • Set a standing rule that payment and credential changes require out-of-band confirmation, regardless of who asks.
  • Make it explicitly okay to slow down a request from a senior leader to verify. Remove the social cost.
  • Pair this with reporting that’s protected, not punished, so a near-miss becomes a lesson instead of a secret.

Where this fits

Deepfakes are one front in a broader shift: attackers now have the same AI tools your team does. Recognizing AI-powered attacks — and drilling the habits that beat them — is a core module of our AI Security & Awareness Training course.

Keep going: read what AI security awareness training covers or the seven golden rules of safe workplace AI use.

Save this to your AI assistant

Published June 24, 2026.

Frequently asked questions

What is a deepfake scam?

A deepfake scam uses AI-generated audio or video to impersonate a real, trusted person — an executive, colleague, or vendor — to authorize fraudulent payments or extract sensitive information. Because it can clone a familiar voice or face, it defeats the instinct to trust people you recognize.

How did the $25 million deepfake scam work?

An employee at a multinational firm joined a video call with what appeared to be the company CFO and several colleagues. The faces and voices were familiar, and the CFO authorized a series of urgent transfers totaling roughly US $25 million. Every participant on the call was an AI-generated deepfake. The attack succeeded because eyes and ears were treated as sufficient verification.

How can you protect against deepfake fraud?

Verify any high-stakes request out-of-band: call the person back on a number from the company directory, or confirm through an official channel you already trust, before acting. Never verify using contact details the requester provides, and never let urgency or authority pressure you into skipping the step. A voice or face alone is no longer proof of identity.

Can you tell a deepfake from a real video call?

Increasingly, no — not reliably, and not in the moment. The defense is not better eyesight; it's a process. Judge a request by what it asks you to do, and verify sensitive or financial requests through a separate, trusted channel every time, regardless of how convincing the call looks.

Make these habits automatic

Turn every employee into a careful, confident AI user — and your first line of defense against AI-powered attacks.

Explore AI Security & Awareness Training