GlossarySecurity awareness

Deepfake

Short answer

A deepfake is audio, video or an image generated or altered with AI to make it look as if a real person said or did something they did not. In business, deepfakes are increasingly used for fraud, for example a fake video call or voice message from an executive requesting an urgent payment.

How it is used against companies

The most damaging use is executive impersonation. In 2024, an employee of the engineering firm Arup in Hong Kong transferred around 25 million US dollars after a video call in which the other participants, including the CFO, were deepfakes. Cloned voices are also used in vishing calls, to get past voice verification and by fake candidates in remote job interviews.

Why it works

A few seconds of public audio or video, from a podcast, a conference talk or social media, can be enough to clone a voice. Combined with pressure and secrecy, a familiar face or voice lowers people's guard more than an email would.

How to reduce the risk

Detection tools help but are not reliable on their own. The most effective measures are procedural: verify payment and access requests through a second, known channel, require more than one approver for large or unusual transfers, agree verification questions for sensitive requests and include deepfake scenarios in security awareness training. These controls also stop BEC fraud.

Regulation

The EU AI Act requires deepfake content to be disclosed as artificially generated or manipulated, with limited exceptions. This helps with legitimate content, but criminals will not label their fakes.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub