Deepfake fraud is stopped at the payment process, not at the point of detection. If a transfer cannot complete without a callback and a second approver, it does not matter how convincing the synthetic executive on the call was.
Detection tooling helps, but it is a probabilistic check on a fast-improving technology. Process controls are deterministic: they fail closed.
Documented cases
- Arup lost about US$25.6 million because a video call was treated as authorisation.
- A UK energy firm wired about EUR 220,000 in March 2019 after a call using cloned audio of its parent-company chief.
- A Singaporean businessman transferred at least S$4.9 million after lures citing a geopolitical crisis drew him into a deepfake call.
The control that breaks it
- Callback verification on a stored number before any transfer, with no exception for video or voice approval.
- Dual authorisation that seniority cannot override.
- A standing rule that no payment is ever authorised by call alone, communicated by the executives themselves.
- Limit the public footage and audio of finance-authority executives where practical, since that material is the raw input.
Related: how to spot a deepfake · deepfake vs voice cloning · Deepfake & synthetic media
Related