Deepfake
A deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.
A deepfake is synthetic media generated by artificial intelligence that convincingly replicates a real person's face, voice, or mannerisms. In the context of social engineering, deepfakes are used to impersonate executives, colleagues, or trusted contacts in ways that traditional spoofing cannot achieve. Deloitte's Center for Financial Services projects that generative AI-enabled fraud — including deepfakes — could reach $40 billion in US losses by 2027.
How it works
Deepfake attacks in a social engineering context typically take three forms:
- Voice cloning. With as little as three seconds of sample audio — easily obtained from earnings calls, conference talks, or social media videos — an attacker can generate a real-time voice clone. This is used in vishing calls where the "CEO" phones the CFO to authorize a wire transfer.
- Video deepfakes. Real-time face-swapping technology allows an attacker to appear as a known executive on a video call. Several publicized cases in 2024-2025 involved deepfake video calls authorizing multi-million-dollar transfers.
- Synthetic images. AI-generated profile photos and ID documents are used to create fake identities for social engineering, recruiting scams, synthetic identity fraud, or bypassing identity verification.
The barrier to creating convincing deepfakes has dropped dramatically. Consumer-grade tools can produce usable voice clones in minutes, and real-time video deepfakes are available as commercial services.
How to defend against it
- Establish out-of-band verification for any high-value request received via voice or video — call back on a known number, use a pre-agreed code word, or require written confirmation through a separate channel.
- Train employees to recognize deepfake indicators — audio artifacts, lip-sync mismatches, unusual latency, refusal to go off-script. But recognize that detection by ear and eye is becoming unreliable as the technology improves.
- Simulate deepfake scenarios. NOUSEC supports deepfake voice simulations to test whether employees follow verification procedures when they hear a familiar voice making an unusual request.
- Adopt process-based controls that do not depend on voice or video identity alone — dual authorization, mandatory cooling-off periods for large transactions, and separation of duties.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo