A familiar voice or face can make a fraudulent request feel legitimate. Protecting your business starts with clear verification steps, secure brand accounts and a response plan your team can use under pressure.

Video call showing facial tracking points over a participant’s face

A familiar face is no longer enough

A deepfake is synthetic or manipulated media that can imitate a real person’s face or voice. Used in a scam, it can make an ordinary request for money, access or confidential information feel credible.

The FBI’s warning on AI-enabled fraud describes cloned voices, fabricated executive video calls and false endorsements. It also notes that identifying AI-generated content can be difficult. For a business, the useful response is to verify sensitive requests independently.

The consequences are real. In 2024, Arup confirmed that criminals used fake voices and images in a Hong Kong video-call scam involving HK$200 million. The company told the Guardian that its internal systems had not been compromised. An attacker can exploit trust without first breaking into your network.

Verify the instruction. A convincing face or voice should never replace the checks required to release money, change account details or share sensitive information.

Where an SMB is exposed

Small teams often rely on familiar relationships and quick decisions. That makes it worth checking where personal recognition has become an informal approval system. Review these scenarios with finance, HR, customer support and leadership.

Requests that deserve an independent check
ScenarioWhat is at risk
An executive requests an urgent transferCompany funds and the normal approval process.
A supplier changes bank detailsA legitimate invoice being paid to the wrong account.
An employee requests a payroll changeSalary payments and personal information.
A fake spokesperson promotes an offerCustomers’ money and confidence in your brand.
A caller asks for a password resetBusiness accounts, customer records and administrative access.

The damage can extend beyond the initial loss. Staff must investigate, customers need answers and normal work gets delayed. Where information is exposed, the response may also require privacy or legal advice.

Face recognition grid over a person shown on a screen

Put a pause in the payment process

The Digital ID & Authentication Council of Canada’s 2026 guide recommends callbacks to established numbers and dual authorization for high-value transactions. Build these into everyday payment handling so employees do not need to improvise under pressure.

  • Confirm new payees and bank-detail changes using a contact already held in your approved records.
  • Require a second authorized person for payments above a documented threshold.
  • Record the verification and approval before releasing funds.
  • Escalate requests that bypass the process, including requests apparently made by senior leaders.

Choose thresholds and escalation routes that fit your business. Test a realistic scenario: the owner is travelling, a payment is urgent and the usual approver is unavailable. Staff should know exactly who can approve the next step.

A second message in the same conversation is weak confirmation. The number, meeting link or alternate contact supplied by the requester may also belong to the attacker.

Protect the identity customers see

Make your genuine contact routes easy to find. Keep your website, social profiles and customer-facing payment instructions consistent. Tell customers how to check an unexpected request, especially if your business handles deposits or large transfers.

Secure the accounts behind your brand

Review who can access your website, social accounts and email administration. Remove access that is no longer needed and use phishing-resistant authentication where supported. See our guide to passkeys for businesses for planning considerations.

Watch for impersonation

Assign someone to review reports of fake accounts, copied websites or false promotions. Keep a record of official profiles and an owner for takedown requests. A customer reporting a suspicious advertisement should have a clear route to a real person.

Review domain protection

Ask your IT provider to check your email authentication setup. SPF, DKIM and DMARC can help address direct domain spoofing. They do not stop lookalike domains, fake social profiles or a criminal using a cloned voice.

Train for verification, not guesswork

Distorted faces, unusual pauses or mismatched lip movements can be warning signs. Their absence is not proof that a call is genuine. Train staff to respond to the request’s risk, even when the caller looks and sounds familiar.

Use short exercises based on actual roles: a finance employee receives a bank-change request, HR is asked to redirect payroll, or support is pressured to reset an executive’s account. Measure whether the employee followed the verification route and reported the attempt.

Detection tools can support investigation, but evaluate them in the context where they will be used. Ask about supported media, false positives, privacy, integrations and what staff should do when a result is uncertain. Avoid making an automated score the sole approval for a sensitive action.

Leadership needs to support the pause. Employees should be able to say, “I need to complete our verification process,” without worrying that checking an urgent request will be treated as poor service.

Act quickly when something is wrong

Prepare a short response checklist before an incident. Keep current bank, IT, platform-support and internal escalation contacts somewhere staff can reach if their usual account is unavailable.

  1. Stop the action. Pause pending payments or changes. If money has moved, contact the financial institution immediately and ask about recovery options.
  2. Preserve evidence. Save messages, profile URLs, timestamps and transaction references. Avoid circulating sensitive material more widely than necessary.
  3. Contain affected access. Involve IT if credentials, accounts or devices may be compromised.
  4. Coordinate communication. Assign one incident lead and give affected customers a verified contact route.
  5. Report and review. Follow applicable reporting requirements and insurer notification terms, then identify which process needs to change.

For an active fake promotion, publish a clear correction through your established channels and report the impersonating content to the platform. State what customers should do without repeating fraudulent payment links.

Deepfake warning graphic with a wireframe face above a phone

Check coverage and build a realistic plan

Insurance can be part of recovery planning, but do not assume a policy covers a payment authorized after a convincing impersonation. DIACC’s guide recommends reviewing social-engineering, funds-transfer and AI-impersonation wording with your insurer or broker.

Ask about exclusions, sublimits, deductibles, required controls and reporting deadlines. Confirm the actual policy wording rather than relying on a headline coverage amount. Our article on cyber insurance and resilience explains why prevention and response still matter.

Start with a focused review of payment approvals, account recovery and customer verification. Then decide where monitoring, staff exercises or additional technology will address a specific gap. Talk to us about your cybersecurity priorities and confirm the scope of any proposed service or insurance arrangement before relying on it.

Frequently asked questions

01Can a deepfake scam happen without a hacked account?

Yes. A criminal can impersonate a person using synthetic media and a separate account or phone number. Secure accounts are important, but sensitive requests still need verification.

02Is a video call enough to approve a payment?

No. Apply your established payment checks even when you recognize everyone on screen. Confirm changes through a trusted contact route and obtain the required approvals.

03Should staff try to spot visual glitches?

They can report anything unusual, but a realistic-looking call is not proof of identity. Training should emphasize verification procedures rather than confidence in recognizing a fake.

04What should we do about a fake brand profile?

Preserve the profile URL and relevant evidence, report it through the platform’s impersonation process and direct customers to your official channels. Escalate quickly if it is collecting payments or personal information.

05Does cyber insurance cover deepfake fraud?

Coverage depends on the policy and the facts of the claim. Ask your broker or insurer to confirm how social engineering, funds transfers and impersonation are treated, including exclusions and notification requirements.

Make trust harder to exploit.

Talk to us about the verification processes and security controls that support your team and protect your customers.

Talk it through
ThinkSwift Cybersecurity Team