An Attack Vector Leaving the Lab
For a long time, deepfakes were mainly a technological curiosity or a concern for celebrities. In 2025–2026, they have become a concrete attack vector against enterprises. The FBI reported a 300% increase in fraud involving audio deepfakes between 2023 and 2025. Several large companies have suffered wire transfer fraud attempts based on AI voice impersonation of executives.
Documented Attacks
AI-Enhanced CEO Fraud
Business Email Compromise (BEC) has existed for years. AI makes it far more dangerous. In 2024, a Hong Kong company lost $25 million following a deepfake video call — a finance employee thought they were speaking to their CFO in a video conference — all participants were real-time AI-generated deepfakes.
Voice Cloning
With 10–30 seconds of audio (a voicemail, an interview excerpt), tools like ElevenLabs or open-source models can clone a voice with unsettling accuracy. Attackers call an employee pretending to be the CEO or CTO to request an urgent wire transfer, system access, or confidential information.
Organisational Protection Measures
Out-of-Band Verification Protocols
The most effective countermeasure is simple: establish a callback protocol for any financial or sensitive access request, even from an executive. If the CFO requests a wire transfer by phone, call back on a known, registered number — not the one displayed during the incoming call.
Code Words and Challenge Questions
Some teams use pre-established code words to authenticate urgent requests. A deepfake cannot know a pre-arranged code word shared only within the team.
Training and Awareness
Finance, HR, and IT teams are priority targets. Training must cover: recognising deepfake signals (visual artefacts, lip-audio asynchrony, artificial audio quality), the most common attack scenarios (urgency, confidentiality, time pressure), and verification procedures to follow systematically.
Technical Detection Solutions
| Solution | Type | Effectiveness |
|---|---|---|
| Intel FakeCatcher | PPG (blood flow) analysis | ~96% (lab) |
| Microsoft Azure AI Content Safety | Deepfake detection API | ~90% video |
| Reality Defender | Multi-modal analysis | ~92% audio+video |
| Pindrop | Voice detection | Very good (voice) |
Important: no solution is foolproof. Deepfakes and detectors evolve in parallel in a permanent arms race. Technical solutions complement organisational procedures — they do not replace them.
Action Plan for CISOs
- Identify critical exposed processes (wire transfers, system access, HR decisions)
- Implement out-of-band verification protocols for these processes
- Train targeted teams with deepfake attack simulations
- Evaluate detection solutions for critical video streams
- Update security policy and incident response procedures
Conclusion
Deepfakes are no longer a theoretical threat to enterprises. The most effective defence combines robust organisational procedures (out-of-band verification, code words) with continuous team awareness. Technical detection solutions complement the defence but cannot be the only barrier.
