An employee of a multinational firm joins a video call with the company’s CFO and several colleagues. Familiar faces. Familiar voices. The CFO authorizes a series of urgent transfers. Every participant on the call was a deepfake. The employee transferred roughly US $25 million to the attackers. (Reported 2024.)
The lesson is not that the employee was careless. It’s that eyes and ears are no longer adequate verification for high-stakes requests.
What is a deepfake attack?
A deepfake attack uses AI-generated audio or video to impersonate someone the target trusts — an executive, a colleague, a vendor. Seconds of public audio or video is enough to clone a voice or a face. The attacker then uses that synthetic identity to authorize a payment, request credentials, or extract sensitive data.
What makes it so effective is that it hijacks a reliable human instinct: we trust people we recognize. When the face and voice are familiar, our guard drops.
Why the old warning signs are gone
For years, security training taught people to spot fraud by its rough edges: bad grammar, generic greetings, a slightly-wrong email address. AI erased those tells.
| Before | Now | |
|---|---|---|
| Phishing | Generic, error-ridden, mass-mailed | Flawless, personalized to your role and projects, thousands at a time |
| Impersonation | A spoofed email claiming to be an executive | A cloned voice on the phone, or a live deepfake on video |
| Reconnaissance | Manual research on a few targets | Automated profiling of staff, org charts, and writing styles |
The takeaway: judge requests by what they ask you to do — not how well they’re written, or how familiar they look.
The one habit that stops it: verify out-of-band
Any request involving money, credentials, sensitive data, or unusual urgency should be verified through a separate channel you already trust, before you act.
Do:
- Call back on the number in the company directory — not the one the requester provided.
- Confirm in the official chat or ticketing system.
- Let verification add a few minutes. Real executives respect it.
Never:
- Verify using contact details the requester gave you (attackers happily “confirm” their own scam).
- Let urgency or authority pressure you into skipping the step. Manufactured urgency is the whole play.
- Trust a voice or a face alone — both can be cloned.
This single habit — out-of-band verification — would have stopped the $25 million transfer. It costs minutes. It saves millions.
Build it into the culture, not just the individual
Individual vigilance fades under pressure, so make verification a norm, not a judgment call:
- Set a standing rule that payment and credential changes require out-of-band confirmation, regardless of who asks.
- Make it explicitly okay to slow down a request from a senior leader to verify. Remove the social cost.
- Pair this with reporting that’s protected, not punished, so a near-miss becomes a lesson instead of a secret.
Where this fits
Deepfakes are one front in a broader shift: attackers now have the same AI tools your team does. Recognizing AI-powered attacks — and drilling the habits that beat them — is a core module of our AI Security & Awareness Training course.
Keep going: read what AI security awareness training covers or the seven golden rules of safe workplace AI use.