Appearance
How to Spot Deepfake Audio and Video Scams
Applies to: General Security, Phone Calls, Zoom/Teams
Article Type: Informational
Last Updated: 2026-07-10
Summary
In the past, scammers relied on misspelled emails to steal money. Today, they use Artificial Intelligence (AI) to perfectly mimic the voice of your CEO or the video feed of your manager on a Zoom call. These "deepfakes" are used to authorize fraudulent wire transfers or steal passwords. This guide explains how to identify synthetic audio/video and the number one rule for verifying identity.
Prerequisites
- No prerequisites — this is an informational reference guide.
Instructions: Spotting the Fake
1. Identifying Audio Deepfakes (The Fake CEO Call)
Voice cloning software only requires a 3-second clip of someone talking (often scraped from a public YouTube video or company webinar) to create a perfect replica of their voice.
Red Flags:
- Urgency and Secrecy: The caller will insist that this is a highly confidential, urgent matter (e.g., "We are acquiring a company today, do not tell anyone in finance, wire the money").
- Lack of emotion: The voice sounds like the person, but it is entirely monotone, lacking the natural inflections, pauses, and breaths of a human.
- Delay in response: Because a scammer is typing out responses for the AI to read, there is often a distinct 2-3 second delay before the "CEO" answers your question.
2. Identifying Video Deepfakes (The Fake Zoom Call)
Scammers can now apply a "digital mask" over their face on a live video call to look exactly like a coworker.
Red Flags:
- Unnatural blinking or eye movement: The eyes may look dead, or the blinking may seem disjointed from the rest of the face.
- Blurring around the edges: Look closely at the edges of the person's face, their hair, and their jawline. If they turn their head quickly, or put their hand in front of their face, the "mask" will glitch and blur.
- The Lighting doesn't match: The shadows on the person's face do not match the lighting of the room behind them.
3. The Ultimate Defense: The "Hang Up and Verify" Rule
You cannot rely purely on your eyes and ears to defeat modern AI. If you receive any request for money, passwords, or sensitive data—even if it looks and sounds exactly like your boss—you must verify it using a different communication channel.
- Tell the person on the phone, "I'm losing connection, I'm going to call you right back."
- Hang up.
- Call the person back using the internal company directory number (or their known, verified cell phone number). Do not press "redial."
- If they do not answer, send them a message on Slack or Teams: "Did you call me asking for a wire transfer?"
- Never authorize a transaction based solely on an inbound phone call.
Troubleshooting
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| I already sent the wire transfer | Successful Phish | Immediately call the IT Helpdesk and the Finance Department. Time is critical to freeze the transaction |
| I gave the caller my password | Compromised Account | Go to your company's password reset portal and change your password instantly. Then notify IT |
| I'm not sure if the voicemail is real | Suspicious Audio | Delete it. If the CEO actually needs you for an urgent financial matter, they will reach out through multiple official channels |