Identifying and Responding to Deepfake Scams
Deepfakes refer to sophisticated forgeries of images, videos or audio recordings. They have been around for years; you can even find versions of them on social media applications. For example, with Snapchat, face-changing filters take real-time data and feed it through an algorithm to produce a synthetic image.
However, as technology has evolved, deepfakes can now alter media so well that it’s often difficult to detect any manipulation. Using artificial intelligence (AI) tools, deepfakes leverage existing audio and video of an individual and continuously learn to produce increasingly convincing forgeries. As a result, deepfakes have become so advanced that they can deceive people into thinking trusted individuals have said or done something they normally wouldn’t.
In today’s workplace, cybercriminals have begun using deepfake scams to sway public opinion on business leadership and trick employees into divulging sensitive information or wiring corporate funds. These scams can lead to numerous consequences for both you and your employer, including stolen data and lasting financial and reputational hardship. As such, it’s crucial to understand deepfake scams and how to mitigate them. This article outlines common deepfake tactics, highlights red flags to watch for and explains what to do when you come across a suspected scam.
Common Deepfake Tactics
While deepfakes were historically used to impersonate political figures in “fake president scams,” cybercriminals are now using them to pose as key stakeholders (e.g., CEOs, board members, managers, IT or HR professionals, vendors and business partners) and target companies across industry lines in damaging attacks. Using these forgeries, malicious parties can fool even the most perceptive individuals.
Some common deepfake tactics leveraged against businesses and their staff include:
- Social engineering plots—Social engineering is a broader cyberattack method that preys on human behaviors (e.g., trust in authority, fear of conflict and the promise of rewards) to obtain unwarranted access to corporate systems, funds or data. Because AI-powered deepfakes have become less expensive and more accessible over the years, the prospect of tricking an employee into performing compromising actions through social engineering plots, whether it’s a deceptive video conference or fraudulent voicemail, has grown that much easier.
- Public manipulation—By deepfaking a company’s CEO or other figureheads, cybercriminals can quickly spread false or potentially damaging information. These forgeries can make key stakeholders say or do just about anything. They could have a board member share false business plans, say or do socially unacceptable things or attempt to influence consumer behavior. All of these actions can harm a company’s reputation, sometimes irreparably.
Red Flags to Watch For
Although deepfake scams can be convincing, there are some red flags you can watch for:
- Visual cues—The people portrayed on deepfaked video conferences may blink or move their heads awkwardly, appear somewhat blurry, have inconsistent background lighting, or speak out of sync with their audio.
- Audio cues—During both deepfaked video conferences and phone calls, voices may sound robotic, have odd pacing or be interrupted by suspicious background noise.
- Behavioral cues—The conversations that take place amid deepfaked interactions may feel unnatural or lack certain social cues. They also often include a heightened sense of urgency, requests that bypass company protocols and pressure to keep specific details of the conversation secret.
In addition to these red flags, your employer may have tools or systems in place to help detect potential deepfakes, such as using company-issued code words when discussing sensitive matters or advanced detection technology that alerts you to suspected forgeries. Be sure to familiarize yourself with any available resources.
Handling a Suspected Deepfake Scam
If you attend an unusual video conference or receive an unexpected phone call and suspect a deepfake scam, take these steps:
- Pause and reflect. Take a moment to evaluate the interaction and trust your instinct if anything feels off. Refrain from immediately fulfilling any requests made during the conversation, even if they are deemed urgent.
- Verify all requests. Never, under any circumstance, bypass your employer’s verification requirements for sharing sensitive data or wiring corporate funds. These requests should be carefully analyzed and discussed with multiple parties—such as management, HR and accounting professionals, and the supposed sender—through trusted channels (preferably in person) to confirm their validity, especially if they involve alternative payment procedures.
- Report the conversation. If you are unable to verify an interaction or related request, report it right away. This may entail discussing the origin and details of the conversation with designated IT staff or using a built-in alert system on your laptop or mobile device to flag the interaction for further review.
For More Information
Deepfakes are a growing threat, but staying informed is your best defense. By recognizing common tactics, watching for red flags and following response measures, you can help protect yourself and your employer against potential scams. When in doubt, verify before you act, and always report suspicious interactions promptly.
Cybersecurity can be challenging, but you don’t have to navigate this topic alone. Reach out to your employer for more information on cybersecurity best practices.
Provided by Alera Group.
This Cybersecurity Essentials document is not intended to be exhaustive nor should any discussion or opinions be construed as legal advice. Readers should contact legal counsel or an insurance professional for appropriate advice. © 2026 Zywave, Inc. All rights reserved.
