7 min read
Deepfake video
Seeing is no longer proof
Most of us grew up treating a face and a voice as proof. If you can see the person on a video call and hear them speak, surely it is them. That assumption is the one attackers are now aiming at.
A deepfake is video or audio that AI has generated or altered to show a real person saying or doing something they never did. Early attempts were easy to laugh off. The quality has moved from "obviously fake" to "hard to tell", and the tools are cheap and require no special skill.
What a deepfake can do on a call
The important shift is that deepfakes are no longer only pre-recorded clips. A face can now be faked in real time during a normal video meeting. The attacker speaks, and software overlays a convincing likeness of someone you know onto their own movements, matching lighting and expressions well enough to pass on a laptop screen.
That means the reassuring parts of a video call, the face, the setting, even several familiar colleagues at once, can all be manufactured. What feels like the strongest possible confirmation ("I saw them, I spoke to them") becomes the trap.
A widely reported case
This one is real and worth naming, so you can check it rather than take our word for it: the engineering firm Arup, whose Hong Kong office lost about HK$200 million across fifteen transfers in early 2024. An employee in a company's finance function was drawn into a video call that appeared to include senior colleagues, including someone presenting as a senior executive. The people on the call looked and sounded familiar. On the strength of that call, the employee carried out a series of large money transfers. Every other participant on the call had been faked; the request was fraudulent.
The detail that matters is not the amount or the country. It is the shape of the attack: a face on a screen was used as proof of identity to authorise moving money, and the face was fake. No spelling mistake, no suspicious link, nothing to proofread. Just a familiar face making an urgent, expensive request.
A face is not identity
The defence does not require you to become an expert at spotting visual glitches. People will tell you to watch for odd blinking, mismatched lighting, or lips that do not quite match the words, and sometimes those tells are there. But the technology keeps improving, and betting your organisation's money on catching a subtle artefact is a weak plan.
The reliable rule is simpler: a video call is not proof of who you are talking to. Treat a face as a claim, not a guarantee.
So when a call, however convincing, leads to a sensitive request, moving money, changing bank details, buying gift cards, sharing credentials or codes, pause and confirm through a separate, trusted channel. Hang up and call the person back on a number you already have, or check with them another way you know is real. A genuine colleague will not mind a quick confirmation. An attacker cannot survive one.
Tip
Before you act on any urgent, sensitive request made over video, verify it on a separate, trusted channel first, for example by calling back on a number you already have. The face on the screen does not settle it.
Check yourself
Where this lesson comes from
Built from
- Workshop 5: AI Security Tools and Defending Against AI-Enabled Threats (V3.0): deepfake video and real cases
- Workshop 7: Social Engineering, Phishing and Deepfakes (V3.0): the deepfake era
- The case described here is the deepfake video-call fraud at the engineering firm Arup, Hong Kong, widely reported from February 2024: 15 transfers totalling about HK$200 million. Verified 2026-08-26.
alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement