Deepfakes and AI: New Security Threats for Businesses
IA & Machine Learning

Deepfakes and AI: New Security Threats for Businesses

March 7, 202610 min readDeepfakeIASécurité

AI-powered audio and video deepfakes are becoming a real attack vector against companies: CEO fraud, identity theft, internal disinformation. How to protect against them.

An Attack Vector Leaving the Lab

For a long time, deepfakes were mainly a technological curiosity or a concern for celebrities. In 2025–2026, they have become a concrete attack vector against enterprises. The FBI reported a 300% increase in fraud involving audio deepfakes between 2023 and 2025. Several large companies have suffered wire transfer fraud attempts based on AI voice impersonation of executives.

Documented Attacks

AI-Enhanced CEO Fraud

Business Email Compromise (BEC) has existed for years. AI makes it far more dangerous. In 2024, a Hong Kong company lost $25 million following a deepfake video call — a finance employee thought they were speaking to their CFO in a video conference — all participants were real-time AI-generated deepfakes.

Voice Cloning

With 10–30 seconds of audio (a voicemail, an interview excerpt), tools like ElevenLabs or open-source models can clone a voice with unsettling accuracy. Attackers call an employee pretending to be the CEO or CTO to request an urgent wire transfer, system access, or confidential information.

Organisational Protection Measures

Out-of-Band Verification Protocols

The most effective countermeasure is simple: establish a callback protocol for any financial or sensitive access request, even from an executive. If the CFO requests a wire transfer by phone, call back on a known, registered number — not the one displayed during the incoming call.

Code Words and Challenge Questions

Some teams use pre-established code words to authenticate urgent requests. A deepfake cannot know a pre-arranged code word shared only within the team.

Training and Awareness

Finance, HR, and IT teams are priority targets. Training must cover: recognising deepfake signals (visual artefacts, lip-audio asynchrony, artificial audio quality), the most common attack scenarios (urgency, confidentiality, time pressure), and verification procedures to follow systematically.

Technical Detection Solutions

Solution Type Effectiveness
Intel FakeCatcherPPG (blood flow) analysis~96% (lab)
Microsoft Azure AI Content SafetyDeepfake detection API~90% video
Reality DefenderMulti-modal analysis~92% audio+video
PindropVoice detectionVery good (voice)

Important: no solution is foolproof. Deepfakes and detectors evolve in parallel in a permanent arms race. Technical solutions complement organisational procedures — they do not replace them.

Action Plan for CISOs

  1. Identify critical exposed processes (wire transfers, system access, HR decisions)
  2. Implement out-of-band verification protocols for these processes
  3. Train targeted teams with deepfake attack simulations
  4. Evaluate detection solutions for critical video streams
  5. Update security policy and incident response procedures

Conclusion

Deepfakes are no longer a theoretical threat to enterprises. The most effective defence combines robust organisational procedures (out-of-band verification, code words) with continuous team awareness. Technical detection solutions complement the defence but cannot be the only barrier.

← Back to blog