Blog

Deepfake Attack: Types, Real Examples, and Warning Signs

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: August 17, 2026

a deepfake attack
TL;DR

A deepfake attack is a social engineering scam in which criminals use AI-generated video, audio, or images to impersonate a real person, usually an executive, colleague, or vendor, so they can steal money, credentials, or sensitive data. These attacks now happen live on video calls, phone calls, and messaging apps, and they routinely bypass traditional security tools because they target the human behind the login, not the login itself. One attack on engineering firm Arup cost $25 million in a single incident. The defense is not "spotting the fake" with the naked eye, it is verifying every sensitive request through a trusted, out-of-band channel and using real-time deepfake detection built for video, voice, and email.

What Is a Deepfake Attack?

A deepfake attack is a type of AI-powered social engineering in which an attacker uses synthetic media, realistic fake video, cloned voices, or fabricated images, to impersonate someone the target trusts. The goal is almost always the same: pressure a person into moving money, handing over credentials, or approving a transaction they otherwise would have questioned.

What makes a deepfake attack different from a normal phishing email is realism. Instead of a suspicious message from a stranger, the victim sees their CFO's face on a Zoom call or hears their manager's voice on the phone. Because the impersonation targets the human rather than a password or a mailbox, it slips past the security tools most organizations already run. Attackers build these fakes from publicly available material: earnings-call footage, conference talks, podcast audio, and social media clips.

According to the U.S. Federal Trade Commission, scammers increasingly use AI to make impersonation schemes more convincing, and the FBI has warned that criminals use generative AI to create content for large-scale fraud and social engineering. The threat is no longer theoretical.

Key Takeaways

  • checkmark

    What it is: A deepfake attack uses generative AI to clone a trusted person's face or voice and trick a target into approving a payment, sharing data, or granting access.

  • checkmark

    Why it works: Deepfakes impersonate the human, so identity and email security tools that verify credentials never get triggered. Learn more in our guide to impersonation attacks in cybersecurity.

  • checkmark

    Main types: Video call deepfakes, voice cloning (vishing), synthetic images and documents, and deepfake phishing across email and messaging apps.

  • checkmark

    Real examples: Arup lost $25 million to a deepfake video call; WPP and Ferrari both dodged deepfake CEO scams in 2024.

  • checkmark

    The cost is rising fast: Deepfake fraud attempts jumped roughly 3,000% in 2023, and the average reported loss per attack is about $500,000.

  • checkmark

    Warning signs: Urgent and confidential money requests, lip-sync drift, glassy eyes, mismatched lighting, camera-off video, and studio-clean audio.

  • checkmark

    The fix: Verify sensitive requests out of band, train employees on the new threat, and deploy multi-channel deepfake detection that flags fakes the moment they happen.

In This Article

Types of Deepfake Attacks

Deepfake attacks show up across every communication channel a business uses. These are the four main categories.

Video call deepfakes. Attackers place an AI-generated face on a live meeting in Zoom, Microsoft Teams, Google Meet, or Webex, often impersonating a senior executive to pressure staff into approving a wire. Our breakdown of how to spot a deepfake on a video call explains why visual detection alone is not enough.

Voice cloning and vishing. With as little as a few seconds of audio, criminals clone a person's voice and place a phone call, a "vishing" attack, to confirm fake payment instructions or request urgent transfers. See our explainer on smishing, vishing, and phishing for how these channels are exploited.

Synthetic images and documents. Deepfakes are not limited to faces and voices. Attackers generate fake ID documents, invoices, and images to pass identity verification checks or lend credibility to a fraudulent request. Deepfakes have been linked to roughly 1 in 20 identity-verification failures.

Deepfake phishing across email and messaging. AI-generated media is increasingly embedded in email and messaging-app scams to make phishing far more convincing. Our post on defending email from deepfake phishing covers this fast-growing vector, which often blends with classic social engineering attacks.

Real Deepfake Attack Examples

Arup, $25 million (Hong Kong, 2024). An employee at global engineering firm Arup joined a video call where every other participant, including the company's CFO and other senior staff, was an AI-generated deepfake. Convinced the meeting was real; the worker made 15 transfers totaling about $25.6 million before the fraud was discovered. Hong Kong police described it as the first deepfake conference-call scam of that scale in the city, as reported by CNN.

WPP, attempted CEO scam (2024). Fraudsters targeted the world's largest advertising group by setting up a Microsoft Teams meeting that appeared to feature CEO Mark Read. They used a voice clone and YouTube footage of an executive and impersonated Read through the meeting chat, attempting to solicit money and personal details. The scam failed, and Read warned staff about it directly.

Ferrari, attempted CEO scam (2024). A Ferrari executive received WhatsApp messages impersonating CEO Benedetto Vigna, complete with his photo and a deepfaked voice, asking for help with a confidential acquisition. The executive grew suspicious and asked a personal question only the real CEO could answer, and the scam collapsed. It is a textbook example of out-of-band verification working.

The common thread: in each case the attackers relied on urgency, authority, and confidentiality to short-circuit normal approval steps.

Deepfake Attack Warning Signs

Detection with the naked eye is getting harder, but these red flags still matter. Watch for a combination of behavioral and technical tells.

Behavioral red flags (the most reliable):

  • An urgent, confidential request to move money, change payment details, or share credentials.

  • Pressure to bypass normal approval or verification steps.

  • A request that arrives through an unusual channel or from a slightly different number or account.

  • Refusal to switch to a known, trusted channel to confirm.

Technical red flags on video and audio:

  • Lip-sync drift, where the mouth does not quite match the words.

  • Glassy or unfocused eyes, unnatural blinking, or odd reflections.

  • Mismatched lighting or shadows, and warping around the hairline, ears, or glasses.

  • The person keeps their camera off, uses a filter, or has suspiciously "studio-clean" audio.

  • Delays or glitches when you ask them to turn, wave a hand in front of their face, or answer an unexpected question.

Keep in mind that as models improve, these visual cues disappear, especially after a video is compressed by a messaging app. That is why visual detection alone is no longer enough.

How to Defend Against Deepfake Attacks

There is no single fix, but a layered approach dramatically reduces risk:

  • Verify out of band. For any sensitive request, confirm through a separate, known channel, call the person back on a saved number, before money, data, or access moves. This one habit would have stopped the Arup loss.

  • Set a verification policy. Require dual approval for wire transfers and payment-detail changes, and give employees explicit permission to pause and verify without fear of "annoying the boss."

  • Train for the new threat. Traditional security awareness training was built for text-based phishing. Update it to include live video and voice deepfakes, and test your team with realistic simulations.

  • Deploy real-time detection. Point tools that watch only one channel miss cross-media attacks. Netarx detects AI-generated impersonation across video, voice, messaging, and email in real time, using multiple inference models plus metadata analysis and giving employees a simple traffic-light signal inside the tools they already use.

  • Prepare for compliance. Regulations are catching up. See what the EU AI Act Article 50 now requires around deepfake disclosure and transparency.

Want to see whether your team would fall for it? You can book a Netarx demo or run a free simulation that spins up a deepfake of your own executive.

SOURCES & REFERENCES

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

A deepfake attack is when a criminal uses AI to fake someone's face or voice, then uses that fake to trick a victim into sending money, sharing data, or granting access. It is a modern, far more convincing form of impersonation fraud.

Related Reading

GDPR-Compliant Deepfake Detection: Biometric Data Rules Explained

blog

GDPR-Compliant Deepfake Detection: Biometric Data Rules Explained

GDPR-compliant deepfake detection is the practice of screening communications for AI-generated impersonation in a way that satisfies the GDPR's rules on lawfulness, purpose limitation, data minimization, and special category data.

2026-08-14
Zoom Deepfake Scams 1

blog

Zoom Deepfake Scams: How to Spot a Fake Executive Before You Approve the Wire

A Zoom deepfake scam puts an AI-cloned executive on a live call to pressure finance staff into approving a fraudulent wire. One such scam cost engineering firm Arup $25 million.

On the call, watch for lip-sync drift, glassy eyes and odd reflections, mismatched lighting, warping around the hairline, filtered or camera-off video, and studio-clean audio.

The biggest tell is behavioral: an urgent, confidential wire request that pressures you to skip normal approval steps.

Never approve a wire from a Zoom call alone. Verify the requester on a known channel, require dual approval, and use a pre-agreed code word.

Zoom's own controls (SSO, waiting room, meeting lock) help but do not verify the human behind the face. Real-time detection like Netarx closes that gap.

2026-07-27
Can You Detect Deepfakes on WhatsApp, Signal & Telegram?

blog

Can You Detect Deepfakes on WhatsApp, Signal & Telegram?

End-to-end encryption protects a message in transit. It does nothing to prove the sender is real or that a voice note, photo, or video is not a deepfake.

Deepfakes reach these apps as cloned voice notes, live voice and video calls, forwarded AI images and videos, and impersonated or hijacked accounts.

2026-07-24