All topicsAI-enabled fraud and cyber awareness
Deepfake fraud: when a familiar voice is no longer proof
Imitated voices and faces make an old fraud more persuasive. The weakness is often not a failure to spot the fake, but a process that lets familiarity replace approval.

Suppose a finance employee receives a call from someone who sounds like the managing director. There is an urgent acquisition payment, the usual approver is unavailable and the matter is confidential. The voice is familiar. The request is not.
A deepfake can make that situation more convincing. It is synthetic or manipulated audio, video or imagery that makes a person appear to say or do something they did not. In fraud, its value is the credibility it lends to the request.
The underlying scam is older than the technology: impersonate someone trusted and persuade another person to move money, reveal information or bypass a control. AI-generated media can strengthen the impersonation without changing the business weakness it exploits.
What has changed about trust?
A voice used to feel like a stronger identity signal than an email address. Seeing a face on a call could seem stronger still. Neither signal was ever the same as authority to approve a payment, but everyday familiarity often blurred the distinction.
The UAE Cyber Security Council's deepfake awareness material describes manipulated media and its risks. The practical implication is not that every call is fraudulent. It is that a high-impact decision should not depend entirely on recognising the caller.
Even a genuine director can request something outside the approved process. Verifying identity and confirming authority are separate checks. A successful defence needs both.
Why “look for glitches” is an incomplete answer
Unnatural movements or odd audio may raise suspicion, but their absence does not establish authenticity. Poor connections also affect genuine calls, and the quality of synthetic media varies.
A hurried employee is poorly placed to perform a reliable technical assessment while being pressured to act. Training that depends on spotting a particular visual defect can give false confidence when that defect is absent.
The more dependable question is what the request changes. A new payee, different bank details, unusual secrecy or an instruction to skip approval creates a reason for independent confirmation regardless of the image quality.
What counts as independent confirmation?
In the hypothetical director call, the employee can pause and use an established company contact route. A phone number supplied by the caller is not independent. Nor is a message sent from the same account used to make the original request.
For a supplier's bank change, confirmation through an already verified supplier contact helps test the instruction. The company's approval process still matters afterwards: recognising the supplier does not remove the need to authorise the change.
The UAE guidance on business email compromise addresses a related form of identity abuse. Both risks point towards the same distinction between a persuasive conversation and a properly authorised transaction.
A process must allow people to interrupt it
A written rule is weak if employees believe they will be criticised for delaying a senior manager. The organisation needs to make “I will confirm this through the usual channel” an acceptable response.
A supposed secret deal should not require one employee to invent an alternative payment system. Where genuine exceptions are necessary, they need an established approval route rather than an improvised waiver during the call.
This is also why an agreed password or secret phrase should not become the only defence. A phrase can be exposed, and pressure can persuade someone to overlook its absence. It is an additional check, not a substitute for authority and separation of duties.
The response need not wait for a technical verdict
If money has been sent, the bank and finance team need prompt notice. If access credentials or confidential files were shared, IT or security needs the relevant facts. The original messages, payment instructions and timing help establish what happened.
Waiting to prove that the recording was a deepfake can delay useful action. The immediate issue is an unauthorised request and its consequences, whatever technology produced it.
AI security awareness can help employees practise that reasoning. The lasting protection is a process that still works when the caller is convincing, not a promise that people will always recognise a fake.
Questions we are asked
Short answers on the points readers raise most about this topic.
- Can a deepfake detector confirm that a call is genuine?
- A tool's result should not be treated as a guarantee. Detection has limitations, and a business still needs to verify the request and apply its approval controls. A negative detection result is not payment authorisation.
- Does this mean businesses should stop publishing all videos of their leaders?
- Public recordings can contribute to impersonation risk, but removing every recording is not a complete defence and may not be practical. The business should assess its exposure while strengthening the controls around payments, account changes and sensitive information.
Related articles
Train your people, and keep records an inspector can read.
