AI & AUTOMATION MASTER CLASS WORKSHOP
 SEP 10 | SEP 24 | OCT 8
That Video Call From Your CEO? It Might Be a Deepfake

That Video Call From Your CEO? It Might Be a Deepfake

Lorenzo Ciambotti

A finance employee joins a routine video call. The CFO is there. So are a few familiar colleagues. Everyone looks right. Everyone sounds right. By the end of the call, $25 million has been wired to a criminal's bank account, and not a single person on that screen was real. 

This isn't a thought experiment. It happened to Arup, a global engineering firm, when attackers used AI-generated deepfakes to impersonate the company's CFO and staff in a live video conference. The employee followed every normal procedure. The fraud still worked, because the technology used to fake human identity has gotten good enough to fool the people who trust it most. 

What Exactly Counts as Deepfake CEO Fraud? 

Deepfake CEO fraud is a scam where attackers use AI-generated video or voice to impersonate a company executive, tricking an employee into wiring money, sharing credentials, or approving a transaction they would never approve otherwise. It's the next evolution of business email compromise. Instead of a suspicious email with bad grammar and an odd sender address, attackers now show up on a live video call or phone line with a synthetic version of someone the employee already knows and trusts, making the request feel completely legitimate in the moment. 

The old advice, that a strange request from the boss would "sound a little off," no longer holds. Modern voice and video generation tools have removed those seams. Synchronized facial movement, matched speech patterns, and natural pacing make these calls indistinguishable from the real thing in the moment. 

How Do Attackers Pull This Off? 

Attackers build a deepfake almost entirely from information the target company already published itself, including LinkedIn profiles, press releases, earnings calls, webinar recordings, and old interview footage that provide enough audio and video to train a convincing likeness. None of it requires hacking into anything. The preparation can take weeks, but the AI tools themselves cost only a few hundred dollars and require moderate technical skill at most, putting this kind of fraud well within reach of ordinary organized crime groups, not just sophisticated nation-state actors with major resources behind them. 

Once the identity is built, the attackers pick their pretext. A confidential acquisition. An urgent vendor payment. A time-sensitive deal that "can't wait for the usual approval chain." The urgency is the point. It's designed to short-circuit the questions someone would normally ask. 

Why Do These Attacks Keep Working? 

Deepfake CEO fraud keeps working because it exploits human trust rather than a technology gap, and trust is much harder to patch than software. A cloned voice can't answer a callback placed to the real person's known number, but by the time someone thinks to make that call, the transfer is often already gone. In smaller companies especially, the person approving a wire often knows the CEO personally and wants to move fast when the boss calls directly, and that familiarity is exactly what attackers are counting on when they build the pretext. 

Some attackers have even gotten ahead of the skepticism. In one case, a finance director was targeted by fraudsters who proactively suggested a video call to "prove" their identity, since they knew finance teams had started verifying suspicious requests by phone. The video call was fake too. The director authorized nearly half a million dollars before anyone realized what had happened. 

What Can a Small or Mid-Sized Business Actually Do About It? 

The fix for deepfake CEO fraud isn't more suspicion on every call. It's a verification process that doesn't depend on how convincing a voice or face seems in the moment, since that judgment call is exactly what attackers have learned to defeat. No wire transfer, payment redirect, or account change should ever be approved based on a single video call or voicemail alone, no matter how familiar or urgent the person asking sounds. 

Verification Controls Worth Putting in Place 

  • Require a second, independent verification channel for any unusual payment request, ideally one that isn't video or voice, like a callback to a number already on file or an in-person confirmation. 

  • Build a "no exceptions" rule around urgency. Real acquisitions and real deals can survive a 20-minute delay for verification. Attackers count on urgency overriding process. 

  • Limit what's publicly available about your executives' voices and faces. Not eliminate it, since that's often unrealistic for leadership, but be aware that every earnings call, webinar recording, and interview is training data for someone. 

Awareness and Technical Defenses to Pair With Them 

  • Pair identity controls with strong email security. Deepfake fraud frequently starts with a compromised inbox or leaked internal information, which makes layered email protection part of the same defense. 

Where Does This Fit Into a Broader Security Strategy? 

Deepfake CEO fraud isn't a standalone threat. It's a symptom of the same identity and access gaps that show up in ransomware, business email compromise, and credential theft, which means the fix belongs inside a broader security strategy rather than treated as its own separate problem. A business with strong identity verification, monitored access, and a real incident response plan is far better positioned to catch a deepfake attempt before it turns into a wire transfer. That's the kind of layered oversight a managed security operations center is built to provide, watching for the unusual patterns that a single employee on a single call can't be expected to catch alone.