Skip to main content

IT security

What is a deepfake?

Deepfakes are AI-generated videos and voices that imitate real people and are used for executive fraud. See how to detect and prevent them.

In short

A deepfake is video, audio or imagery in which artificial intelligence imitates a real person's face or voice so convincingly that the forgery is hard to expose.

The technology is built on AI models trained on recordings of the person, and since executives and managers often appear in videos, podcasts and presentations, they are easy to clone. For companies the threat is concrete: deepfake voices are used in calls where 'the CEO' asks for an urgent transfer, and there are documented cases where employees have transferred millions after video meetings with deepfaked participants.

Deepfakes are thus the next generation of CEO fraud, where even the old advice to 'call and confirm' is no longer enough if the call itself can be faked. The defence is procedures that do not depend on sight and hearing: verification through known channels, fixed payment limits and four eyes on unusual payments. MI Support IT trains Danish businesses in handling exactly this type of attack.

Back to the glossary

What is a deepfake?

A deepfake is media content (video, audio or imagery) in which artificial intelligence has placed a real person's face or voice into something the person never said or did. The name comes from "deep learning" + "fake". What required a film studio a few years ago can today be produced with a few minutes of audio and publicly available tools, and the quality improves month by month.

How deepfakes are made

The AI model is trained on existing recordings of the person: the more material, the better the imitation. A voice clone can today be created from just a few minutes of audio: a talk, a podcast, a video on LinkedIn. The attacker can then make the clone say anything, in real time or as pre-recorded messages. Video is harder, but video-meeting deepfakes, where a face is overlaid on the attacker's in real time, have already been seen in real fraud cases. The point for you: any public figure in the company can be cloned, and that includes every manager with videos online.

Deepfake executive fraud: real cases

Deepfakes have lifted classic CEO fraud to a new level. In one of the most widely reported cases, a finance employee in Hong Kong transferred around 25 million dollars after a video meeting in which both "the CFO" and several "colleagues" turned out to be deepfakes. Other cases are more mundane: a phone call with the CEO's cloned voice asking for an urgent transfer or a mobile-payment purchase of gift cards. The pattern is the same as all other executive fraud (authority, urgency, confidentiality), but the evidence the employee used to rely on ("I could hear it was him") no longer holds.

How to spot a deepfake

Technical tell-tales can help, but they quickly become outdated as the technology improves:

  • Video: unnatural transitions at the edges of the face, odd blinking, lighting that does not match, lips out of sync, especially when the person turns their head or moves a hand past the face.
  • Audio: flat intonation, strange rhythm, missing background noise or breathing.
  • Behaviour: The participant will not answer unexpected questions, avoids spontaneous interaction or has a "bad connection" exactly when questions are asked.

The most important advice: do not rely on being able to see the difference. Build processes that do not need to.

Policies: verifying unusual requests

  • Verification through another channel: Any unusual payment request is confirmed by you calling back on a number you already know. Never by answering the incoming call or meeting.
  • Fixed payment limits and four eyes: No single person can complete large transfers alone, no matter who asks.
  • A crisis code word: An agreed verification word within management that a deepfake does not know.
  • Culture: Make it explicitly legitimate to say "let me just verify this", even to the CEO. See also spoofing, which is often part of the same attack.

How MI Support IT helps

MI Support IT trains employees and management teams in deepfake and fraud scenarios through security awareness training and advises on safe use of AI in the business through AI consulting. Contact us if your verification procedures still rely on recognising the boss's voice.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.