For years, the advice for spotting a scam call was "listen for the voice." Then it became "video calls are safer, because you can see them." Both of those checks are now unreliable. Real-time deepfake tools can convincingly reproduce a specific person's face and voice live on a video call, reacting and speaking in the moment — not just in a pre-recorded clip.
The attack that's actually working against businesses isn't a movie-style face swap of a celebrity. It's smaller and more targeted: an employee joins what looks like a normal video call with someone who appears to be their CFO, a vendor, or a senior executive — often with a few other "attendees" whose cameras stay off — and is instructed to approve a wire transfer, change a payment account, or share credentials, under time pressure.
Why this works even on cautious people
The scam borrows credibility from three things at once: a face and voice that look and sound right, the social pressure of a live meeting rather than an email, and urgency that discourages the "let me check on that" response. Each one individually is resistible. Together, in the moment, they're designed to overwhelm normal skepticism.
The one step that actually stops it
Verify any request involving money, credentials, or account changes through a second channel you initiate yourself — never one offered to you during the call. If "the CFO" asks for an urgent transfer on a video call, hang up and call them back on the phone number you already had on file, or message them on an internal tool where their identity is already established. A deepfake can join a video call convincingly. It's much harder for an attacker to also intercept a phone call you place yourself to a number you already had.
Build this into how your team operates
- Put a callback rule in writing. Any payment or account-change request that arrives over video or by message requires a callback to a known number before action — no exceptions for seniority or urgency. Make this policy, not a personal judgment call, so employees have something to point to under pressure.
- Separate the approver from the requester. Require a second person to confirm significant transfers, especially ones requested outside normal process. A scammer impersonating one executive can't easily also impersonate the second approval step.
- Agree on a family or team verification phrase. For personal use — a call claiming to be a relative in an emergency — a pre-agreed word or question works the same way a callback does for a business: it doesn't rely on recognizing a voice or face at all.
- Slow down on purpose when a call feels urgent. "This needs to happen in the next ten minutes" is doing the same job it does in phishing email — removing your time to verify. Treat urgency itself as a signal to check, not a reason to skip checking.
The takeaway
Seeing and hearing a familiar face on a call used to be reasonable proof of identity. It no longer is. The fix isn't learning to spot better fakes — it's moving verification to a channel the attacker doesn't control, every time money or access is on the line.