Blog

Why ITDR Fails to Protect Against Deepfake Threats—and What You Can Do About It

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: August 5, 2025

shutterstock 2428990573
TL;DR
  • ITDR catches misuse of compromised accounts, but deepfakes bypass identity systems entirely, impersonating the human before any login, so ITDR never sees them.

  • Pair ITDR with real-time, AI-based deepfake detection (voice, video, metadata) as your first line of defense, with ITDR as the last line of audit and response.

What Is ITDR?

Identity Threat Detection and Response (ITDR) is a category of security tools and practices that monitor identity systems, such as Active Directory or Entra ID, to detect and respond to identity-based attacks like credential theft, privilege escalation, suspicious logins, and lateral movement.

The catch: ITDR assumes an attacker is using a compromised account. A deepfake impersonating an executive on a call or video never touches those systems, no credential is entered, no policy is violated, and no log is generated, so ITDR alone can’t see it.

Key Takeaways

  • checkmark

    ITDR has a blind spot. It watches accounts, not the humans deepfakes impersonate.

  • checkmark

    Deepfakes target perception. They bypass identity systems before any login occurs.

  • checkmark

    Detection goes first. Real-time voice, video, and metadata analysis belongs in front of identity tools.

  • checkmark

    Layer, don’t replace. Deepfake detection is the first line; ITDR is the last line of audit.

  • checkmark

    Government agrees. NIST, CISA, FinCEN, and the FBI all flagged deepfake and identity fraud in 2024.

In This Article

In 2024, deepfake fraud cost organizations an average of $500,000 per attack. That figure alone should give pause to any security leader relying solely on Identity Threat Detection and Response (ITDR) to protect their enterprise. While ITDR plays a crucial role in monitoring internal identity misuse, it wasn’t built to recognize, much less stop, synthetic media-based threats.

As AI-generated voice, video, and images grow more realistic, cybercriminals are no longer just breaching systems—they’re bypassing them entirely through manipulation and deception.

Deepfakes: The New Front Line in Identity Exploitation

Deepfakes—synthetic media created with artificial intelligence—are now sophisticated enough to convincingly impersonate executive voices, forge video messages, and fake facial expressions in real time. These aren’t science fiction scenarios anymore. Attackers are using deepfakes to:

  • Trick finance teams with fake CEO voicemails authorizing urgent payments

  • Infiltrate secure communications by spoofing trusted internal sources

  • Manipulate recorded evidence for legal, compliance, or reputational gain

These attacks target perception, not infrastructure—making traditional tools like ITDR ineffective as first-line defenses.

Why ITDR Alone Isn’t Enough

ITDR solutions are designed to monitor and respond to misuse of legitimate digital identities. They excel at detecting things like:

  • Credential theft

  • Privilege escalation

  • Suspicious login patterns

  • Lateral movement inside identity systems like Active Directory or Entra ID

But ITDR assumes the threat actor is using a compromised account. Deepfakes, on the other hand, allow attackers to bypass identity systems completely by impersonating the human behind the identity before credentials are ever entered.

Example: A deepfake video of a CEO doesn’t trigger any red flags in ITDR—because no account was accessed, no policy was violated, and no authentication logs exist to review.

Deepfake Detection Requires a New Layer of Defense

To combat deepfakes, organizations must extend their security stack beyond internal monitoring to include real-time, AI-based detection of synthetic media. This includes:

  • Voice authentication analysis for impersonation in calls or voicemails

  • Facial integrity analysis in video conferencing tools

  • Cross-channel consistency checking between email, audio, and video signals

  • Metadata and blockchain verification to identify tampered content

These detection methods must sit in front of identity systems—not behind them—stopping deception before it becomes an exploit.

Augmenting ITDR with Deepfake Defense

Think of deepfake detection as the first line of defense, while ITDR acts as the last line of audit and response if an identity is compromised. Together, they offer a more complete picture of digital trust.

A combined strategy:

  • Blocks impersonation attempts before they reach critical business systems

  • Enhances ITDR with context about synthetic threats

  • Protects brand, reputation, and decision-makers from targeted AI-powered attacks

What Security Leaders Should Do Now

  • Acknowledge the blind spot:

    If your ITDR system can’t detect synthetic voices, video, or spoofed communications, your attack surface is exposed.

  • Deploy a deepfake detection platform:

    Look for solutions that analyze voice, video, and email in real time—ideally integrated with your current communication stack.

  • Update incident response playbooks:

    Include AI impersonation scenarios alongside traditional credential-based threats.

  • Educate executives and staff:

    Make them aware of what deepfakes look and sound like, and how to verify unusual requests.

  • Evaluate vendors that augment ITDR:

    Platforms like Netarx use metadata signals, blockchain validation, and inference models to stop deepfakes before they’re believed.

Conclusion

ITDR is vital—but it was never designed to detect synthetic deception. As deepfakes become weaponized by attackers, enterprises must evolve. AI-powered identity forgery needs an AI-powered defense.

Don’t wait until a deepfake hits your inbox. Build detection into your first layer of digital trust—before the damage is done.

SOURCES & REFERENCES

  1. Science & Tech Spotlight: Combating Deepfakes (GAO-24-107292), U.S. Government Accountability Office (March 11, 2024). Finds that existing detection methods may not accurately identify deepfakes in real-world conditions.

  2. Reducing Risks Posed by Synthetic Content (NIST AI 100-4), National Institute of Standards and Technology (NIST) / U.S. AI Safety Institute (November 2024). Reviews the technical limits of synthetic-content detection and authentication.

  3. Digital Identity Guidelines (NIST SP 800-63-4), Second Public Draft, NIST (August 2024). Expands identity-proofing, authentication, and fraud requirements for digital identity systems.

  4. Use Secure Cloud Identity and Access Management Practices, NSA & CISA Cybersecurity Information Sheet (March 7, 2024). Recommends phishing-resistant MFA and stronger identity and access management.

  5. Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004), U.S. Treasury Financial Crimes Enforcement Network (FinCEN) (November 13, 2024). Reports rising deepfake media used to bypass identity verification.

  6. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, FBI Internet Crime Complaint Center (IC3), Public Service Announcement (December 3, 2024).

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

No. ITDR monitors identity systems for misuse of legitimate accounts, credential theft, privilege escalation, abnormal logins. A deepfake impersonates the human before any credential is used, so it generates no account activity, policy violation, or log for ITDR to catch.