Voice and deepfake

How do you spot a deepfake?

The reliable way to spot a deepfake is not to examine the video, but to verify the request through a channel the caller did not choose. Visual tells are unreliable and getting worse every year, while an out-of-band callback works regardless of how good the fake is.

This is the opposite of the usual advice. Guidance about blinking, lighting and lip-sync described a 2019 problem. The cases in this library show finance staff facing video calls good enough that spotting the fake was never realistic.

Documented cases

  • At Arup, a Hong Kong finance employee wired HK$200 million (about US$25.6 million) after a video conference in which the CFO and every colleague present were AI-generated.
  • WPP saw a staged Teams call built from an AI voice clone and repurposed YouTube footage of its chief executive.
  • LastPass is the case that worked: an employee received a cloned voice of the CEO over WhatsApp, judged the channel and urgency to be wrong, and simply did not act.

The control that breaks it

  • Verify out of band. Hang up and call back on a number you already hold.
  • Treat the channel as the signal. Executives do not issue payment instructions over WhatsApp, and that fact does not require any visual judgement.
  • Agree a challenge phrase for high-value verbal approvals.
  • Do not train staff to hunt for visual artefacts. It builds false confidence in a test that keeps getting easier to pass.

Related: how to spot a deepfake call · how to prevent deepfake fraud · Deepfake & synthetic media