How it is used against companies
The most damaging use is executive impersonation. In 2024, an employee of the engineering firm Arup in Hong Kong transferred around 25 million US dollars after a video call in which the other participants, including the CFO, were deepfakes. Cloned voices are also used in vishing calls, to get past voice verification and by fake candidates in remote job interviews.
Why it works
A few seconds of public audio or video, from a podcast, a conference talk or social media, can be enough to clone a voice. Combined with pressure and secrecy, a familiar face or voice lowers people's guard more than an email would.
How to reduce the risk
Detection tools help but are not reliable on their own. The most effective measures are procedural: verify payment and access requests through a second, known channel, require more than one approver for large or unusual transfers, agree verification questions for sensitive requests and include deepfake scenarios in security awareness training. These controls also stop BEC fraud.
Regulation
The EU AI Act requires deepfake content to be disclosed as artificially generated or manipulated, with limited exceptions. This helps with legitimate content, but criminals will not label their fakes.




