
Chief Executive Officer
Published: July 22, 2026

Deepfake video calls are live meetings where an executive's face and voice are AI-generated. One tricked an Arup employee into wiring $25 million.
Watch for lip-sync drift, odd eye reflections, mismatched lighting, blurred facial edges, flat audio, and urgent, secret payment requests.
The signs apply Zoom, Teams, Meet, and Webex alike; none of these platforms verify that the person behind a familiar face is real.
If suspicious, do not act. Verify on a second channel, use a pre-agreed code word, then preserve evidence and report it.
The human eye is no longer reliable against modern fakes. Real-time detection like Netarx catches what people miss across every channel.
A deepfake video call is a live video meeting in which one or more participants are AI-generated impersonations rather than real people. Attackers use publicly available footage, photos, and audio, often scraped from earnings calls, webinars, or social media, to clone an executive's face and voice, then drive that synthetic likeness in real time to pressure a target into wiring money, sharing credentials, or approving a transaction.
These attacks work because they hijack trust. Seeing a familiar face and hearing a familiar voice short-circuits the skepticism of people apply to a suspicious email. That is the same trust that vishing, smishing, and phishing campaigns exploit, now escalated to live video.
In This Article
To spot a deepfake on a video call, watch for lip-sync drift, unnatural blinking or eye reflections, mismatched lighting, blurred edges where the face meets hair or background, and audio that lags the mouth. If anything feels off, stop and verify the person through a second channel you already trust, such as calling a known number or asking for a pre-agreed code word. Because modern deepfakes increasingly defeat the human eye, real-time detection tools are the only dependable safeguard for high-stakes calls.
A finance employee at engineering firm Arup joined what looked like a routine video conference with the company's CFO and several colleagues. Every face and voice on that call was an AI-generated fake. By the end of it, the worker had authorized 15 transfers totaling roughly $25 million to accounts controlled by fraudsters (CNN reported the case in February 2024; Fortune covered the details).
A deepfake video call is no longer hypothetical. It is one of the fastest-growing social engineering threats facing finance, HR, and executive teams. This guide explains exactly what to look for on Zoom, Teams, Google Meet, and Webex, what to do the moment you get suspicious, and why the human eye alone is no longer enough.
No single tell is proof on its own but stacked together these signals should raise your suspicion. Watch for them across three categories: visual, audio, and behavioral.
Visual red flags
Lip-sync drift. The mouth moves a fraction of a second before or after the sound. Mismatched lips and audio remain one of the most reliable giveaways.
Unnatural eyes. Look at the reflections in both eyes. Real irises reflect the same light sources with consistent shape and intensity; AI faces often break this. Blinking that is too regular, too rare, or absent is another clue.
Mismatched lighting. The face is lit from one direction while the background light comes from another. Shadows that do not match the environment are hard for generators to get right.
Blurred or shifting edges. Watch where the face meets hair, glasses, ears, or the background. Warping, flicker, or a faint halo when the person turns their head suggests a synthetic overlay.
Skin and texture oddities. Waxy or overly smooth skin, teeth that blur when the mouth moves, or jewelry and earrings that morph frame to frame.
Audio red flags
Flat or robotic cadence. Synthetic speech often lacks natural rhythm, breathing, and filler words, or places emphasis in slightly wrong places.
Mismatched room acoustics. The voice sounds studio-clean while the video shows a busy office, or the audio has no background noise at all.
Latency on interaction. The person is slow to respond to interruptions or overlapping speech, because the fake cannot improvise as fluidly as a human.
Behavioral and context red flags
Urgency and secrecy. A sudden, confidential, time-critical payment or credential request is the single biggest warning sign, deepfake or not.
Camera-shy participants. Someone keeps their video low-resolution, poorly lit, or briefly on then off to hide artifacts.
Reluctance to do a liveness check. Ask the person to turn their head fully sideways, wave a hand in front of their face, or stand up. Many real-time deepfakes degrade badly at extreme angles or occlusions.
The detection signs above apply everywhere, but each platform has quirks worth knowing. On Zoom, beware of "touch up my appearance" and virtual backgrounds that can mask edge artifacts; ask participants to disable filters. On Microsoft Teams, external guests joining from unrecognized tenants deserve extra scrutiny, and you can require verified sign-in. On Google Meet, dial-in-only or camera-off participants claiming to be executives should be verified before any action. On Cisco Webex, use host controls to lock the meeting and confirm the roster once everyone has joined.
The uncomfortable reality is that none of these platforms verify that the human behind a familiar face is genuine. That gap is exactly why Netarx built detection directly into Zoom, Teams, Meet, and Webex, analyzing each interaction rather than relying on the meeting software's own controls.
If your instincts fire mid-call, do not act on any request from that meeting. Follow this playbook:
Pause the transaction. Never approve payment, wire, credential reset, or data transfer while the call is live. Legitimate colleagues will understand a short delay.
Verify on a second channel. Hang up and call the person back on a number you already know, not one provided during the call. Confirm through a trusted channel before doing anything.
Use a pre-agreed code word. Teams that handle money or sensitive access should set a verbal passphrase in advance, a practice the U.S. Federal Trade Commission recommends for verifying urgent callers instantly.
Preserve evidence and report. Screenshot the call and save metadata, notify the impersonated executive through a verified channel, alert your security team, and report the incident to the FBI Internet Crime Complaint Center (IC3).
Much of the classic advice, "watch the blinking," is already outdated. Generators fixed the blinking problem years ago, and real-time models are improving faster than most people can keep up with. Training employees to spot artifacts helps, but it is a losing race when a convincing fake can be produced from a few minutes of public footage.
That is why manual detection has to be backed by technology. Netarx is purpose-built to catch what people miss, analyzing over 75 metadata signals around each interaction rather than surface-level pixels: frame-level forensics, temporal inconsistencies, audio-visual correlation between lip movement and voice, biometric cues like pulse from skin micro-texture, and device and source verification. Crucially, it works across voice, video, email, and messaging in a single platform, because real attacks rarely stay in one channel.
For finance, banking, and other high-risk teams, Netarx delivers a simple traffic-light indicator inside the tools employees already use, so the answer to "is this person real?" arrives in real time instead of after the money is gone. See how it maps to financial services fraud prevention and the tiers of identity model that underpins it.
Test your team in 2 minutes. Spin up a deepfake of your own CEO with Defrag and see if your staff can spot it, no card required. Then book a Netarx demo to add real-time deepfake detection to every Zoom, Teams, Meet, and Webex call.
SOURCES & REFERENCES
CNN — "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'" (Feb 2024): https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk
Fortune — "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee" (May 2024): https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo/
FBI IC3 — Public Service Announcement: "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud" (PSA241203): https://www.ic3.gov/PSA/2024/PSA241203
U.S. Federal Trade Commission — consumer alert on AI voice-cloning scams and verifying urgent callers with a code word: https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes
FBI Internet Crime Complaint Center (IC3) — official fraud reporting portal: https://www.ic3.gov/

Chief Executive Officer
CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.
Sometimes, if you know what to look for: lip-sync drift, odd eye reflections, mismatched lighting, blurred facial edges, and flat audio. But modern real-time deepfakes increasingly pass a casual look, so visual inspection should be paired with second-channel verification and automated detection for anything high-stakes.