Blog

Zoom Deepfake Scams: How to Spot a Fake Executive Before You Approve the Wire

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: July 27, 2026

Zoom Deepfake Scams: How to Spot a Fake Executive | Image
TL;DR

A Zoom deepfake scam puts an AI-cloned executive on a live call to pressure finance staff into approving a fraudulent wire. One such scam cost engineering firm Arup $25 million.

On the call, watch for lip-sync drift, glassy eyes and odd reflections, mismatched lighting, warping around the hairline, filtered or camera-off video, and studio-clean audio.

The biggest tell is behavioral: an urgent, confidential wire request that pressures you to skip normal approval steps.

Never approve a wire from a Zoom call alone. Verify the requester on a known channel, require dual approval, and use a pre-agreed code word.

Zoom's own controls (SSO, waiting room, meeting lock) help but do not verify the human behind the face. Real-time detection like Netarx closes that gap.

What is a Zoom deepfake scam?

A Zoom deepfake scam is a live video call in which an attacker uses AI to impersonate a trusted person, usually a senior executive, to authorize a fraudulent transaction. Attackers harvest public footage and audio from earnings calls, conference talks, webinars, and social media, generate a real-time face-and-voice clone, and drive it on camera to apply pressure in the moment.

It is the video evolution of business email compromises. The same social engineering that powers vishing, smishing, and phishing now arrive wearing your CFO's face, because a familiar face on Zoom disarms the skepticism people would apply to a suspicious email.

Key Takeaways

  • checkmark

    A Zoom deepfake scam puts an AI-cloned executive on a live call to pressure finance staff into approving a fraudulent wire the Arup case cost $25 million across 15 transfers.

  • checkmark

    Visual and audio tells include lip-sync drift, glassy eyes with mismatched reflections, lighting that doesn't match the room, warping around the hairline, filtered or low-resolution video, and studio-clean audio over a busy scene.

  • checkmark

    The loudest alarm is behavioral: an urgent, confidential wire request with new payment details and pressure to skip callbacks, dual approval, or normal channels.

  • checkmark

    Zoom's controls SSO sign-in, waiting room, meeting lock, roster checks gate who joins, but none of them verify that the human behind a familiar face is real.

  • checkmark

    Process beats detection: never approve a wire from a call alone. Call back on a known number, use a pre-agreed code word, and require dual approval plus out-of-band callback for new beneficiaries.

  • checkmark

    Training the eye is a losing race against real-time cloning high-stakes calls need automated detection like Netarx layered inside Zoom itself.

In This Article

Are Zoom deepfake scams real?

A Zoom deepfake is an AI-generated impersonation of a real person on a Zoom call, most often an executive, used to trick employees into wiring money or sharing access. Spot one by watching for lip-sync lag, unnatural eyes and lighting, edge warping around the face, and camera or audio quirks, but treat the urgent wire request itself as the loudest alarm. Never approve a payment from a video call alone: verify the requester through a second trusted channel and require dual authorization first.

The message lands during a Zoom call that looks completely normal. Your CFO is on camera, a couple of colleagues are there too, and the ask is urgent and confidential: push through a wire before end of day for a deal that cannot wait. Everything you see and hear says it is real. In the Arup case, none of it was. Every participant was an AI deepfake, and a finance employee authorized 15 transfers totaling roughly $25 million (CNN; Fortune).

Zoom's ubiquity in finance and executive workflows makes it a prime stage for this attack. This guide shows you how to spot a fake executive on Zoom, the platform controls that actually help, and the wire-approval playbook that stops the fraud even if the deepfake is flawless.

How to spot a fake executive on a Zoom call

No single clue is proof, but several together should stop you cold. Scan three categories: visual, audio, and behavioral.

Visual tells on camera

  • Lip-sync drift. The mouth moves slightly ahead of or behind the words. Mismatched lips and audio are one of the most reliable giveaways.

  • Unnatural eyes. Glassy or fixed gaze, and reflections that differ between the two eyes. Real irises mirror the same light sources; AI faces often do not.

  • Mismatched lighting. The face is lit from one direction while the room behind is lit from another, or shadows do not match the environment.

  • Edge warping. Flicker, blur, or a faint halo where the face meets hair, glasses, or ears, especially when the person turns their head.

  • Filters and low resolution. A deliberately soft image, heavy "Touch Up My Appearance," or a busy virtual background can hide artifacts. Ask the person to switch them off.

Audio tells

  • Flat cadence. Synthetic speech often lacks natural rhythm, breathing, and filler words, or stresses the wrong syllables.

  • Acoustic mismatch. Studio-clean voice over a video that shows a noisy office, or audio with no ambient sound at all.

  • Interaction lag. The "executive" is slow to handle interruptions or cross-talk, because the fake cannot improvise like a human.

Behavioral tells (the loudest alarm)

  • Urgency plus secrecy. A confidential, time-critical wire that must skip normal channels is the single biggest red flag, deepfake or not.

  • New or changed payment details. A never-before-seen beneficiary account, an overseas bank, or last-minute changes to wire instructions.

  • Pressure to bypass controls. Discouraging you from calling back, looping in a colleague, or following dual-approval policy is a tell in itself.

Zoom-specific controls that reduce the risk

Zoom gives hosts and admins several settings that make these attacks harder. Use them, but remember they gate who joins, not whether a face is genuine:

  • Require SSO or authenticated sign-in so only verified company accounts can join sensitive meetings.

  • Enable the Waiting Room and admit people deliberately, and use Lock Meeting once expected attendees have arrived.

  • Confirm the participant roster and be suspicious of external accounts, unfamiliar names, or executives dialed in with camera off.

  • Ask for a live liveness check. Request the person turn their head fully sideways or wave a hand across their face; many real-time fakes break down at extreme angles.

The honest limitation: none of these verifies that the human behind a familiar face is real. That gap is why Netarx built deepfake detection directly into Zoom (as well as Teams, Meet, and Webex), analyzing each interaction in real time instead of relying on meeting settings alone.

The wire-approval playbook: stop the fraud even if the deepfake is perfect

Detection can fail. Process should not. These controls stop the payment regardless of how convincing the call is:

  1. Never approve from the call alone. Treat any wire, vendor change, or credential request made on Zoom as unverified until confirmed elsewhere.

  2. Call back on a known number. Reach the executive on a number you already have, not one supplied during the meeting, and confirm the request.

  3. Use a pre-agreed code word. Finance and executive teams should set a verbal passphrase in advance, a practice the U.S. Federal Trade Commission recommends for instantly verifying urgent callers.

  4. Enforce dual approval and callback for wires. Require a second authorized approver and an out-of-band callback for any payment over a set threshold or to a new beneficiary.

  5. Preserve evidence and report. Screenshot the call and save metadata, alert your security team, notify the real executive on a verified channel, and report fraud to the FBI Internet Crime Complaint Center (IC3).

Why training your eye is not enough

Classic advice like "watch for bad blinking" is already obsolete; modern models handle it. Real-time deepfakes are improving faster than employees can be trained, and a convincing fake takes only minutes of public footage. Awareness helps, but it cannot be the last line of defense on a wire that moves millions.

That is why manual vigilance needs a technical backstop. Netarx analyzes over 75 metadata signals per interaction, including frame-level forensics, temporal inconsistencies, and audio-visual correlation between lip movement and voice, and it works across voice, video, email, and messaging on one platform because these attacks rarely stay in a single channel. Employees get a simple traffic-light indicator inside Zoom telling them whether the person is real, before the wire is approved. See how it maps to financial services fraud prevention and fraud prevention teams.

Test your team in 2 minutes. Spin up a deepfake of your own CEO with Defrag and see if your finance staff can spot it, no card required. Then book a Netarx demo to add real-time Zoom deepfake detection before the next wire goes out.

SOURCES & REFERENCES

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

Yes. Real-time face and voice cloning lets attackers drive a convincing executive likeness during a live Zoom meeting. The Arup fraud involved multiple deepfaked participants on a single video call.