The reliable way to spot a deepfake is not to examine the video, but to verify the request through a channel the caller did not choose. Visual tells are unreliable and getting worse every year, while an out-of-band callback works regardless of how good the fake is.
This is the opposite of the usual advice. Guidance about blinking, lighting and lip-sync described a 2019 problem. The cases in this library show finance staff facing video calls good enough that spotting the fake was never realistic.
Documented cases
- At Arup, a Hong Kong finance employee wired HK$200 million (about US$25.6 million) after a video conference in which the CFO and every colleague present were AI-generated.
- WPP saw a staged Teams call built from an AI voice clone and repurposed YouTube footage of its chief executive.
- LastPass is the case that worked: an employee received a cloned voice of the CEO over WhatsApp, judged the channel and urgency to be wrong, and simply did not act.
The control that breaks it
- Verify out of band. Hang up and call back on a number you already hold.
- Treat the channel as the signal. Executives do not issue payment instructions over WhatsApp, and that fact does not require any visual judgement.
- Agree a challenge phrase for high-value verbal approvals.
- Do not train staff to hunt for visual artefacts. It builds false confidence in a test that keeps getting easier to pass.
Related: how to spot a deepfake call · how to prevent deepfake fraud · Deepfake & synthetic media
Related