For years, the advice for spotting a scam call was "listen for the voice." Then it became "video calls are safer, because you can see them." Both of those checks are now unreliable. Real-time deepfake tools can convincingly reproduce a specific person's face and voice live on a video call, reacting and speaking in the moment — not just in a pre-recorded clip.

The attack that's actually working against businesses isn't a movie-style face swap of a celebrity. It's smaller and more targeted: an employee joins what looks like a normal video call with someone who appears to be their CFO, a vendor, or a senior executive — often with a few other "attendees" whose cameras stay off — and is instructed to approve a wire transfer, change a payment account, or share credentials, under time pressure.

Why this works even on cautious people

The scam borrows credibility from three things at once: a face and voice that look and sound right, the social pressure of a live meeting rather than an email, and urgency that discourages the "let me check on that" response. Each one individually is resistible. Together, in the moment, they're designed to overwhelm normal skepticism.

The tell isn't visual anymore. Current deepfake video is good enough that lag, lighting, or a slightly-off blink rate can't be relied on. The tell has to be procedural, not visual.

The one step that actually stops it

Verify any request involving money, credentials, or account changes through a second channel you initiate yourself — never one offered to you during the call. If "the CFO" asks for an urgent transfer on a video call, hang up and call them back on the phone number you already had on file, or message them on an internal tool where their identity is already established. A deepfake can join a video call convincingly. It's much harder for an attacker to also intercept a phone call you place yourself to a number you already had.

Build this into how your team operates

The takeaway

Seeing and hearing a familiar face on a call used to be reasonable proof of identity. It no longer is. The fix isn't learning to spot better fakes — it's moving verification to a channel the attacker doesn't control, every time money or access is on the line.

GOOGLE AD SLOT — IN-ARTICLE (responsive)
GOOGLE AD SLOT — END-OF-ARTICLE (responsive)