Sign up for our Newsletter
Keep up to date with the latest IT news, tips and guides from Dragon IS and sign up here:
Trusted and Proactive IT Support and Managed IT Services
Whether it’s celebrities endorsing crypto platforms, an investment scheme, or a ‘free giveaway’, you don’t have to look far to find a deepfake scam online.
And they’re becoming a very real problem for businesses of all sizes too.
In early 2024, one finance worker in Hong Kong joined what looked like a routine video call with senior colleagues. Everyone on the call appeared familiar and the conversation felt normal. He was then instructed to transfer the equivalent of £20 million via 15 transactions to five local bank accounts, only afterwards discovering that every person on the call had been digitally faked.
While an extreme case it highlights just how sophisticated – and ambitious – these types of scams are becoming.
In its annual Future of Fraud Forecast, Experian cites deepfakes as amongst the top five fraud trends expected to impact businesses and consumers in 2026.
A deepfake is essentially an image, or a piece of audio or video, that has been digitally altered using artificial intelligence to make a person appear to say or do something they never actually did.
Modern deepfake tools can clone a voice, face or mannerisms with high levels of accuracy, with the result being content that looks and sounds convincing.
Deepfakes are used in a number of ways, including to impersonate individuals, spread misinformation, or for fraudulent activities. Advances in technology and the increasing availability of such tools means it is now easier than ever to create a deep fake, with minimal effort and at a low cost.
A quick Google search reveals multiple tools are now available offering to help create a cloned voice using as little as 30 seconds of audio. That could come from a podcast clip, a YouTube video, or a scam phone call. These tools are inexpensive and simple to use, requiring no specialist skills. They can generate a fake video or voice in minutes, or even impersonate someone live on a call.
In one scam example, National Trading Standards has warned that criminals are now recording scam calls and then cloning voices to set up direct debits.
While a little more complicated, it is the same story for deepfake video, which has been taken to new heights with recent advances made in AI.
Far from being a threat that only large organisations face, the use of deep fakes is a form of cyberattack that SMEs and their teams are also under threat from. For scammers, smaller organisations can make a very appealing target, due to their more limited resources and how they operate.
In many SMEs, it’s normal for a director to call or message the finance team with an urgent request. That familiarity can be capitalised on by criminals.
A single person within an SME team might handle finance, payroll and supplier payments. With fewer layers of approval and oversight, it’s easier for potential scams to slip through.
LinkedIn profiles, company websites, interviews and online events can all provide material that can be used to clone a voice or face, along with information about individuals and the company that can be used for carrying out a scam.
Impersonation scams have been around for a long time and deepfakes are simply the latest evolution of this tactic. Deepfakes can be incredibly convincing, are easily scalable, and can be harder to challenge in the moment. These types of scams don’t rely on hacking, they rely on trust and familiarity.
Here are some examples of how the tactics are being used to target businesses:
The CEO voice note
A finance manager receives a voice message from the managing director asking for an urgent payment. The voice sounds identical and the request feels believable.
The fake video call
A supplier appears on a Teams call to confirm new bank details. The face looks right and the voice matches. The payment goes to a criminal account.
The cloned customer
A scammer impersonates a customer to request refunds, credit changes or gain access to an account.
The fake job applicant
Deepfake candidates attending video interviews can result in employers unknowingly onboarding remote employees who aren’t who they say they are, potentially giving bad actors access to sensitive systems.
The good news is there are steps you can take to protect your business against the growing threat of deepfakes. Small process changes can make a huge difference against this and other types of cyberattack.
One of the most important steps you can take is to implement regular staff training to raise awareness around issues of cybersecurity and keep them front of mind. Find out more here about creating a cybersecure culture and take a look at some of the top cyber defence strategies, such as zero trust architecture (ZTA), which is based on the principle of ‘never trust, always verify’.
Any request involving payments, bank detail changes or sensitive information should always be confirmed through different communication channels. If the request comes by email or voice message, confirm it through a call or video meeting. If it comes through a video meeting, confirm it by phone and email.
Make it a rule that no single employee is able to set up a new payee, change bank details or release a payment over a set threshold. Make it mandatory that at least two people must sign off on this, even if working in a small team.
For high-value and high‑risk approvals, agree a phrase internally that only the relevant team members know. A cloned voice may sound real but it won’t know the phrase.
Most deepfake scams – and indeed many other types of scams – rely on pushing a sense of urgency. Typically, ‘act now or something bad will happen’! If something feels rushed or out of character, staff should feel confident to slow things down and pause before acting.
Avoid approving payments through WhatsApp, SMS or personal email accounts. Make it mandatory for employees to only operate through approved secure channels. This is good practice for any business, not just when it is related to payments.
Many insurers now expect businesses to have verification processes in place. It’s worth reviewing your policy to check what is covered and to make sure you meet all the requirements. Deepfakes typically fall under the category of ‘impersonation fraud’, ‘synthetic media attacks’, or ‘social engineering losses’. They’re treated as a human‑layer cyber risk, meaning insurers expect businesses to have strong internal processes, not just firewalls.
Check what information about your team is online. Try and reduce the amount of audio and video content available, especially for senior leaders. This will make it far harder to clone. Deepfake scammers may seeks to gather material from sources including LinkedIn, company websites, YouTube and podcasts.
The strongest security defence will always be a layered approach – one that combines technology and people – with intelligent security measures and system design backed by ongoing employee education and training.
At Dragon IS, we work with small and medium-sized businesses, assisting them with IT infrastructure and cybersecurity. For an informal discussion about your needs, please email info@dragon-is.com or call us on 0330 363 005.
You may also be interested in: