What is deepfake fraud?
By Identra · Updated
Deepfake fraud is the use of AI-generated or altered voices, images or video to impersonate a trusted person and trick someone into handing over money, access or sensitive information. The familiar face or voice stands in as proof that the request is real.
How does deepfake fraud work?
An attacker uses a synthetic voice, altered video or a fake image to pose as someone the target trusts. A CEO. A supplier's account manager. An IT technician. It might be a voicemail or a live Teams or Zoom call. Urgency, secrecy and a few real details about the business do the rest.
The attacker doesn't need the real person's account. The employee who gets fooled already has the access, and they make the transfer or reset the password themselves.
Deepfakes give AI-powered phishing a face and a voice. The failure happens when recognition stands in for verification. Knowing the voice tells you nothing about who controls the call.
What does a deepfake attack on a company look like?
Say a finance analyst gets an email about a confidential acquisition. A video call follows with someone who looks and sounds like the CFO. The caller wants an urgent wire to a new beneficiary and says the usual approvals would leak the deal.
The analyst recognizes the face and starts the payment. What should stop it is an approval tied to the exact beneficiary and payment details, plus a check through a number already in the company directory. Calling back the number in the email just reaches the attacker again.
The help desk version is quieter. A caller sounds like an employee and says they lost their phone. If support enrolls a new MFA factor on the strength of that conversation, the attacker gets account takeover through the recovery process.
How is deepfake fraud different from other impersonation attacks?
The deepfake is only the media. The fraud usually has other parts, like a spoofed email, a stolen account or details pulled from LinkedIn. Investigate the message and the action that followed it.
Deepfake impersonation
- What makes it convincing
- A familiar voice, face or recording
- What to verify
- The request, through a channel you already trust
Email spoofing
- What makes it convincing
- A familiar display name or look-alike address
- What to verify
- The sender and the business action requested
Compromised account
- What makes it convincing
- A message from a real account or thread
- What to verify
- The specific action, through a separate route
Ordinary social engineering
- What makes it convincing
- Authority, urgency, inside knowledge
- What to verify
- Identity and permission under the normal workflow
How do you stop deepfake fraud?
Treat identity and authorization as two separate checks. A verified CFO still goes through payment approval. The approval covers the exact recipient and account, and any change to those details starts it over.
Phishing-resistant MFA protects sign-in. It does nothing when a signed-in employee follows a fake instruction. Recovery is the soft spot, so decide who can replace a security key or authenticator app and on what evidence.
Rehearse it. AI security awareness training should have people practice pausing a request from a senior leader and escalating it.
- List the actions that always need independent verification. New beneficiaries, bank detail changes, MFA resets, sensitive file transfers.
- Call back on numbers from the HR directory or the vendor master record. Never the number in the request.
- A second approver for sensitive payments and access changes, shown the exact details.
- Documented identity checks before any authenticator is replaced. Escalate when they can't be completed.
- Log the request, the verification, the approval and the outcome where the control owner can see exceptions.
Can employees or detection tools reliably spot a deepfake?
No. Odd lip sync, a voice that shifts or lighting that doesn't match are reasons to look closer. A bad connection produces the same glitches, and a good fake may have none.
Employees should be able to stop a request without first proving the media is fake. A detector's verdict shouldn't authorize a payment or a credential reset. Neither should asking the caller to turn their head on camera.
The real question is whether the workflow stays safe when the impersonation is convincing. Exercises should check that staff use known contact routes and keep the approvals in place under pressure.
What should you do after a suspected deepfake?
Stop the action. Reach the real person through a trusted route. Tell security and the owner of the affected workflow. Keep the original messages, call details, approvals and any recordings.
If a payment went out, call your bank's fraud line right away and ask for a hold or recall. If access changed, check newly enrolled factors, credentials, sessions and permissions, then look at what the account did afterward.
Add these scenarios to the AI incident response plan. Work out what was asked, who acted and which check failed. Containment doesn't wait for anyone to confirm it was a deepfake.
How Identra thinks about it
Identra gives security teams one timeline across browser, endpoint and identity, SaaS and cloud activity, which helps when a suspected impersonation ends in account access. Sign-in sessions can be revoked with approval, and the result is recorded. In the browser, Identra also helps protect against look-alike sign-in pages and corporate credentials typed on risky sites.
Go deeper: AI security, built on identity
Frequently asked questions
Is voice cloning a type of deepfake fraud?
It becomes deepfake fraud when the cloned voice is used to impersonate someone for a fraudulent purpose. Authorized voice synthesis isn't fraud.
Does the attacker need to hack the executive's account?
No. A separate phone call, message or meeting invite is enough. A compromised account adds credibility but isn't required.
Can a live video call prove who someone is?
Not for a sensitive action. Use a verification route set up in advance and keep the normal approvals.
Does calling back a known number solve it?
It removes reliance on the suspicious call. It doesn't replace authorization checks, and a contact route that may be compromised needs extra verification.
Who should own deepfake fraud prevention?
Security coordinates with finance, the help desk, HR and any team that approves sensitive actions. Each workflow owner sets the verification steps and an escalation path staff can use under pressure.
