Deepfake technology has made it significantly easier for scammers to impersonate business professionals. A scammer can now join a call on camera and respond to questions in real time convincingly as another person. 

This is the third channel of AI-enabled impersonation, after email and voice, and it’s the one businesses are least prepared for: A face on a video call feels completely human and impossible to fake.

We’ve covered how AI phishing campaigns are faster and easier to launch, and how voice cloning is increasing vishing attempts. In this article, we’ll explore what happens when a person’s identity is co-opted with deepfake videos and how to prevent team members from falling for deepfake scams. 

What makes deepfake video fraud different

Email deception relies on written detail: the right tone, the right context, and a reasonable-sounding but urgent request. Voice cloning relies on the ear: a familiar voice saying something urgent enough to bypass a moment of doubt. Deepfake video fraud goes a step further and compromises the one verification instinct most people never think to question: seeing someone’s face and hearing them speak, in real time, on a call that looks exactly like every other video meeting on the calendar.

Employees are trained to be skeptical of an email and to double-check an unexpected phone call. Almost nobody is trained to question a face-to-face video call, because video has always been as trustworthy as a physical meeting. 

This new frontier of fraud requires a re-evaluation of what can be trusted at work, as well as how easily processes can be overridden by urgency. 

How deepfake scams work in practice

Deepfake video fraud can take a few different forms. The simplest is a pre-recorded deepfake video played into a live call, sometimes with the attacker muting their own camera and claiming connectivity issues to explain why the “executive” doesn’t respond naturally to follow-up questions. 

More sophisticated attacks use real-time face-swapping tools during an actual live call, letting the attacker respond, nod, and react in the moment, which is far harder to detect. 

A third pattern has emerged, which relies on onboarding and compliance meetings specifically. A synthetic video persona posing as an auditor, a new starter, or an HR contact can sit through an entire meeting designed to extract system access, security answers, or credentials, precisely because those meetings are built around the assumption that a video call with a real person is inherently trustworthy.

A real-world deepfake fraud example 

In 2024, a finance employee at the Hong Kong office of Arup(ventana nueva), a UK-headquartered engineering firm, joined a video call with people who appeared to be the company’s CFO and several colleagues. Every person on that call was an AI-generated deepfake, built from publicly available footage of real executives.

Believing the request was genuine, the employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered, and only then because he happened to follow up with the company’s actual head office about the “confidential transaction” he’d just completed.

The Arup case remains the clearest illustration of what this attack looks like at scale, but it’s not a unique incident. UK Finance’s Fraud Report 2026(ventana nueva) found that overall payment fraud losses reached £1.28 billion in 2025, and specifically flagged organized criminal groups increasingly using deepfakes, cloned voices, and synthetic identities to impersonate trusted individuals and bypass identity checks.

Separate industry research from Sumsub(ventana nueva) recorded a 94% year-on-year rise in UK deepfake attempts, and a Gartner survey of security leaders(ventana nueva) found that 62% of organizations had experienced some form of deepfake attack in the prior twelve months. Any business that still treats this as a future problem is behind where the data already is.

The Arup incident is particularly instructive of what to watch out for. The employee’s initial instinct was sound: he treated the original email as a probable phishing attempt and asked for a video call specifically to confirm it, which is exactly the verification step most security training would recommend.

The failure happened at the next step, when the video call itself was treated as sufficient proof, because nobody had told him that a convincing face on screen is no longer reliable. At that moment, the failure was caused by insufficient business training, not by the employee.

What are some potential deepfake fraud scenarios?

The mechanics described above manifest in a handful of recurring scenarios, each aimed at a different point of leverage inside a business. They share the same underlying trick; a convincing face and voice on a call that looks entirely normal, but the target and the payoff can differ.

A CFO’s face authorizing a wire transfer

A deepfake of a senior finance executive appears on a call and instructs a subordinate to process an urgent, confidential payment. The presence of a familiar, apparently live face overrides doubts that an email alone would have triggered.

A fake auditor extracting system credentials

A synthetic persona posing as an external auditor or compliance reviewer conducts a video interview with IT or finance staff, framed as a routine review, and asks questions specifically designed to surface system access details, security question answers, or login information.

A synthetic HR manager onboarding a new employee

A deepfake HR contact hosts an onboarding call with a genuinely new starter, or with an existing employee under the guise of a policy update, and uses the session to capture details about internal systems, access permissions, or credential recovery information.

Board member impersonation to a financial officer

A deepfake of a board member or senior non-executive joins a call with a financial officer to authorize a transaction or request sensitive financial information, leaning on the authority of a role that a finance team is culturally trained not to question.

Why deepfake fraud is harder to catch 

Most anti-phishing and anti-vishing training programs work by teaching people to add friction to a process that someone’s trying to rush through: an email can be forwarded to IT for double-checking, a phone call can be ended in order to verify a phone number.

Video calls don’t get the same instinctive scrutiny, because for years a video call has been the closest digital substitute for being in a room with someone. Employees are rarely told to be suspicious of a colleague’s face, because the cultural assumption behind video conferencing is that it’s totally reliable.

This assumption is what deepfake video fraud exploits. An attacker doesn’t need to defeat an employee’s skepticism about the request itself. They need only supply the one thing that has always ended skepticism in the past; a familiar face responding naturally in real time.

That’s a much higher bar for an employee to meet, which is why the verification protocols for this channel need to be procedural rather than relying on someone simply noticing something is off.

There’s also a social dynamic that has to be challenged. Questioning a written request feels like ordinary diligence. Questioning a phone call feels reasonable, since impersonating a voice has been a known risk for years.

But questioning a face on a video call, particularly a senior colleague’s, can feel closer to an accusation, which is precisely why employees hesitate to do it even when something about the interaction feels slightly off. Removing that social cost, making the question routine and expected rather than awkward, is as much a part of deepfake prevention and defense as any technical control.

Verification protocols that work specifically for video

Create a code

Pre-agreed code words or gestures, established in advance through a separate channel, are one of the few things a deepfake genuinely can’t produce, because they don’t exist in any public footage an attacker could train a model on.

A simple, changeable phrase or physical signal, confirmed periodically among senior staff and finance teams, gives employees something concrete to ask for rather than relying on a subjective sense that a call feels wrong.

Set authorization rules in stone

No financial authorization or credential disclosure should ever take place via video call alone. This has to be a concrete policy, not a judgement call left to whoever is on the call at the time: any request of that kind, regardless of who appears to be asking, requires a second confirmation through a genuinely separate channel, using contact details already on file rather than anything supplied during the call itself.

Employees need explicit, repeated permission to ask “is this really you?” on any call, regardless of who appears to be on screen. They should also feel comfortable to ask for proof via another channel that the person is who they say they are.

The instinct that stops people from questioning a senior figure is precisely what this attack relies on, and that instinct only goes away when leadership makes it unambiguous that the question is always acceptable.

Keep records

Recording and logging sensitive video meetings, particularly anything involving financial authorization, credential access, or onboarding, gives a business something to review after the fact if a request turns out to have been fraudulent, and the knowledge that a meeting is logged is itself a mild deterrent against attackers who prefer to operate without a trail.

Treat video calls the same as you treat an email

Deepfake video fraud succeeds because it exploits the one channel businesses have never trained employees to question. Email deception is covered by phishing awareness, and voice deception is covered by callback verification and the training we’ve written about for social engineering more broadly

Being aware of deepfake video calls doesn’t require employees to become forensic analysts capable of spotting a synthetic video frame by frame. It requires a business to accept that a convincing face and voice are no longer proof of anything on their own, and to build verification habits that don’t depend on anyone becoming suspicious in the moment.

Reinforcing that culture alongside the wider practices covered in our guide to building a strong workplace security culture gives a team the same instinct for video that good training already builds for email and phone calls.

The credential connection: limiting what a failed verification can reach

Whatever form a deepfake video attack takes, CFO fraud, a fake auditor, a synthetic HR contact, it’s ultimately aiming at one of two things: a financial transaction or a set of credentials. The video is simply the delivery mechanism for a request that, if it succeeds, either moves money directly or gives the attacker a login that lets them cause damage on their own terms.

This is why credential hygiene is important, even when the attack itself has nothing to do with a stolen password at first. If a deepfake call tricks someone into handing over a credential, unique passwords and multi-factor authentication limit what that single credential can actually reach. 

The same containment principle we’ve covered in relation to business email compromise applies here: The goal isn’t to make every employee individually unbeatable against a sophisticated attack, it’s to make sure that when verification fails once, the damage stays contained.

A business password manager like Proton Pass for Business makes containment realistic to maintain: It removes the pressure to reuse familiar passwords across accounts and makes it easy for employees to adhere to your password policies. Paired with a secure platform for video conferencing and a workplace culture that treats pausing to verify as normal rather than suspicious, that combination is what actually limits the damage when video calls themselves can no longer be fully trusted.

Reduce your team’s exposure to impersonation fraud with a business password manager.