← Glossary

Deepfake

Synthetic media, video, voice or images, generated by AI to convincingly imitate a real person, increasingly used to "confirm" fraudulent payment instructions in corporate fraud.

Updated

Key facts

  • Seconds of public audio (earnings calls, interviews, webinars) suffice to clone an executive's voice.
  • The documented corporate pattern is a fraudulent email or meeting invite first, then a deepfake voice or video call as "verification". Reputable reporting on the widely covered 2024 Arup case describes an employee paying out roughly USD 25 million after a deepfaked video meeting (CNN, 2024).
  • Detection by eye and ear is unreliable and getting worse; procedural defense beats perceptual defense.

The corporate deepfake playbook

Deepfakes rarely start the fraud; they close it. The chain: pretexting via email establishes the scenario (confidential deal, urgent payment), the target hesitates, and the deepfake, a voice call, voicemail or video meeting, supplies the human confirmation that policy said to ask for. This is why "call to verify" has weakened as a control: the caller may also be synthetic. Verification must run through channels and numbers you initiate, not channels the requester provides. Related patterns: whaling, business email compromise, social engineering and phishing.

How to defend

Payment procedures with out-of-band verification on known numbers, code words for high-value approvals, executive awareness that their public audio is cloning material, and behavioral email security that flags the fraudulent instruction before the deepfake ever gets to "confirm" it. The email is still the weakest, most detectable link in the chain.

How Sentaro helps

Sentaro cannot inspect a phone call, and does not claim to. It attacks the chain where the fraud starts: the impersonation email, the lookalike domain, the hijacked thread, the anomalous payment instruction. Stop the setup and the deepfake has nothing to confirm.

Questions we get asked.

What does deepfake mean?

AI-generated media that convincingly imitates a real person's face, voice or both. The name combines "deep learning" and "fake".

How are deepfakes used against companies?

Mainly to confirm fraud initiated by email: a cloned executive voice or video presence "verifies" a payment or data request, defeating callback-style controls.

Can you detect a deepfake?

Sometimes (unnatural blinking, audio artifacts), but quality improves constantly and real-time detection is unreliable. Procedural verification through channels you initiate is the dependable defense.

Are deepfakes illegal?

Using them for fraud or impersonation is criminal in most jurisdictions, and regulations increasingly target malicious synthetic media specifically. The technology itself also has legitimate uses.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.