Deepfakes and AI Scams: How to Spot Them
A deepfake is AI-generated audio, video, or images that convincingly imitate a real person. Criminals now use deepfakes to clone a CEO’s voice to approve a fake transfer, or to impersonate a family member in an emergency call.
The technology is improving fast, so the defense is less about spotting flaws and more about verifying identity a different way.
How deepfake scams work
Deepfakes power a few common scams:
- Voice cloning: a short clip of someone’s voice is enough to generate a fake "urgent" phone call.
- CEO or executive fraud: a faked voice or video call pressures staff to move money or share data.
- The "family emergency" call: a cloned voice of a relative claims to be in trouble and needs money now.
- Fake video meetings: an impersonated colleague on a video call requests a sensitive action.
Warning signs
Deepfakes are getting harder to spot by eye or ear, but these still help:
- Unexpected urgency around money, gift cards, or credentials.
- A request to keep it secret or to bypass the normal process.
- Odd pauses, robotic tone, or mismatched lip-sync on video.
- Pressure not to hang up or not to verify.
How to protect yourself
Verification beats detection:
- Hang up and call the person back on a number you already trust.
- Agree on a family or team "safe word" for high-stakes requests.
- Never approve payments or share data based on a call or video alone, confirm through a second channel.
- Slow down: urgency is the scammer’s main tool.
How it plays out in the real world
Based on real, widely reported incident patterns; names and details are illustrative.
The $25 million video call
In a widely reported 2024 case, a finance employee at a multinational's Hong Kong office joined a video call with the company's CFO and several colleagues. The faces were right, the voices were right. Following instructions from the call, the employee sent about $25 million across 15 transfers.
Every other participant on that call was a deepfake, generated from publicly available footage. The employee had actually been suspicious of the initial email, but the video call dissolved the doubt, which was exactly its job.
- Seeing and hearing is no longer verifying. If video and voice can be synthesized, "I saw them say it" cannot authorize money. Treat unusual payment instructions as unverified regardless of the medium.
- Verify out-of-band, every time. Call the requester back on a number you already have, or confirm in person. A pre-agreed code word for payment approvals defeats a perfect deepfake.
- Process beats perception. Dual approval and payment thresholds exist precisely because humans can be fooled. The controls only work if urgency is never allowed to bypass them.
Test yourself
Test your ability to spot AI scams, free.
Frequently asked questions
Can you really fake someone’s voice from a short clip?
Yes. Modern tools can clone a convincing voice from just a few seconds of audio, often taken from social media or a voicemail greeting. That is why you should verify the person through a trusted channel, not the incoming call.
How can I tell if a video call is a deepfake?
Look for unnatural blinking, lip-sync that is slightly off, strange lighting, or a refusal to do something spontaneous. But because quality is improving, the safest move is to verify the request separately rather than trust the video.
What is a "safe word" and why does it help?
It is a private phrase agreed in advance among family members or a finance team. If someone calls with an urgent money request, you ask for the safe word. A deepfake of their voice will not know it.