
Chief Executive Officer
Published: August 17, 2026

A deepfake attack is a social engineering scam in which criminals use AI-generated video, audio, or images to impersonate a real person, usually an executive, colleague, or vendor, so they can steal money, credentials, or sensitive data. These attacks now happen live on video calls, phone calls, and messaging apps, and they routinely bypass traditional security tools because they target the human behind the login, not the login itself. One attack on engineering firm Arup cost $25 million in a single incident. The defense is not "spotting the fake" with the naked eye, it is verifying every sensitive request through a trusted, out-of-band channel and using real-time deepfake detection built for video, voice, and email.
A deepfake attack is a type of AI-powered social engineering in which an attacker uses synthetic media, realistic fake video, cloned voices, or fabricated images, to impersonate someone the target trusts. The goal is almost always the same: pressure a person into moving money, handing over credentials, or approving a transaction they otherwise would have questioned.
What makes a deepfake attack different from a normal phishing email is realism. Instead of a suspicious message from a stranger, the victim sees their CFO's face on a Zoom call or hears their manager's voice on the phone. Because the impersonation targets the human rather than a password or a mailbox, it slips past the security tools most organizations already run. Attackers build these fakes from publicly available material: earnings-call footage, conference talks, podcast audio, and social media clips.
According to the U.S. Federal Trade Commission, scammers increasingly use AI to make impersonation schemes more convincing, and the FBI has warned that criminals use generative AI to create content for large-scale fraud and social engineering. The threat is no longer theoretical.
In This Article
Deepfake attacks show up across every communication channel a business uses. These are the four main categories.
Video call deepfakes. Attackers place an AI-generated face on a live meeting in Zoom, Microsoft Teams, Google Meet, or Webex, often impersonating a senior executive to pressure staff into approving a wire. Our breakdown of how to spot a deepfake on a video call explains why visual detection alone is not enough.
Voice cloning and vishing. With as little as a few seconds of audio, criminals clone a person's voice and place a phone call, a "vishing" attack, to confirm fake payment instructions or request urgent transfers. See our explainer on smishing, vishing, and phishing for how these channels are exploited.
Synthetic images and documents. Deepfakes are not limited to faces and voices. Attackers generate fake ID documents, invoices, and images to pass identity verification checks or lend credibility to a fraudulent request. Deepfakes have been linked to roughly 1 in 20 identity-verification failures.
Deepfake phishing across email and messaging. AI-generated media is increasingly embedded in email and messaging-app scams to make phishing far more convincing. Our post on defending email from deepfake phishing covers this fast-growing vector, which often blends with classic social engineering attacks.
Arup, $25 million (Hong Kong, 2024). An employee at global engineering firm Arup joined a video call where every other participant, including the company's CFO and other senior staff, was an AI-generated deepfake. Convinced the meeting was real; the worker made 15 transfers totaling about $25.6 million before the fraud was discovered. Hong Kong police described it as the first deepfake conference-call scam of that scale in the city, as reported by CNN.
WPP, attempted CEO scam (2024). Fraudsters targeted the world's largest advertising group by setting up a Microsoft Teams meeting that appeared to feature CEO Mark Read. They used a voice clone and YouTube footage of an executive and impersonated Read through the meeting chat, attempting to solicit money and personal details. The scam failed, and Read warned staff about it directly.
Ferrari, attempted CEO scam (2024). A Ferrari executive received WhatsApp messages impersonating CEO Benedetto Vigna, complete with his photo and a deepfaked voice, asking for help with a confidential acquisition. The executive grew suspicious and asked a personal question only the real CEO could answer, and the scam collapsed. It is a textbook example of out-of-band verification working.
The common thread: in each case the attackers relied on urgency, authority, and confidentiality to short-circuit normal approval steps.
Detection with the naked eye is getting harder, but these red flags still matter. Watch for a combination of behavioral and technical tells.
Behavioral red flags (the most reliable):
An urgent, confidential request to move money, change payment details, or share credentials.
Pressure to bypass normal approval or verification steps.
A request that arrives through an unusual channel or from a slightly different number or account.
Refusal to switch to a known, trusted channel to confirm.
Technical red flags on video and audio:
Lip-sync drift, where the mouth does not quite match the words.
Glassy or unfocused eyes, unnatural blinking, or odd reflections.
Mismatched lighting or shadows, and warping around the hairline, ears, or glasses.
The person keeps their camera off, uses a filter, or has suspiciously "studio-clean" audio.
Delays or glitches when you ask them to turn, wave a hand in front of their face, or answer an unexpected question.
Keep in mind that as models improve, these visual cues disappear, especially after a video is compressed by a messaging app. That is why visual detection alone is no longer enough.
There is no single fix, but a layered approach dramatically reduces risk:
Verify out of band. For any sensitive request, confirm through a separate, known channel, call the person back on a saved number, before money, data, or access moves. This one habit would have stopped the Arup loss.
Set a verification policy. Require dual approval for wire transfers and payment-detail changes, and give employees explicit permission to pause and verify without fear of "annoying the boss."
Train for the new threat. Traditional security awareness training was built for text-based phishing. Update it to include live video and voice deepfakes, and test your team with realistic simulations.
Deploy real-time detection. Point tools that watch only one channel miss cross-media attacks. Netarx detects AI-generated impersonation across video, voice, messaging, and email in real time, using multiple inference models plus metadata analysis and giving employees a simple traffic-light signal inside the tools they already use.
Prepare for compliance. Regulations are catching up. See what the EU AI Act Article 50 now requires around deepfake disclosure and transparency.
Want to see whether your team would fall for it? You can book a Netarx demo or run a free simulation that spins up a deepfake of your own executive.
SOURCES & REFERENCES
FBI IC3 Public Service Announcement: Criminals Use Generative AI to Facilitate Fraud (PSA241203)
FBI IC3 2024 Internet Crime Report — $16.6 billion in reported losses
Fighting Back Against Harmful Voice Cloning — FTC Consumer Advice
British engineering firm Arup revealed as victim of $25 million deepfake scam — CNN
WPP CEO Mark Read targeted by deepfake AI scam — Marketing-Interactive
Ferrari narrowly dodges deepfake scam simulating CEO's voice — The Spokesman-Review
Real-time deepfake fraud: 1 in 20 identity verification failures linked to deepfakes — Veriff

Chief Executive Officer
CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.
A deepfake attack is when a criminal uses AI to fake someone's face or voice, then uses that fake to trick a victim into sending money, sharing data, or granting access. It is a modern, far more convincing form of impersonation fraud.