Deepfakes and Social Engineering: The New Enterprise Threat
CEO fraud worth $25M, deepfake detection, team training: how enterprises must protect themselves.
In February 2024, a Hong Kong company lost $25 million after an employee participated in a video conference with what they thought was their CFO and several colleagues. All were real-time deepfakes. The era where "seeing is believing" protected businesses is over.
Deepfakes: Threat Landscape in 2026
Deepfake technology has accelerated dramatically. What required hours of GPU processing in 2023 now runs in real-time on consumer hardware:
-
Real-time video deepfakes: face swapping during video calls with lip sync and facial expressions
-
Voice cloning: 3 seconds of audio is enough to convincingly clone a voice
-
Document generation: fake IDs, fake wire transfer orders, fake emails mimicking writing style
-
Accessibility: tools are freely available on GitHub, the technical barrier is nearly zero
Attack Scenarios
Enhanced CEO Fraud
Traditional CEO fraud (email from the CEO requesting an urgent wire transfer) was already effective. With a voice or video deepfake of the CEO, the success rate skyrockets. The employee sees and hears their supervisor: why doubt?
Job Interview Compromise
Attackers use deepfakes to pass remote job interviews, gaining access to internal systems once hired. The FBI issued a specific alert about this vector.
Market Manipulation
Fake videos of executives announcing financial results or acquisitions can manipulate stock prices while the disinformation spreads.
Multi-Channel Social Engineering
The attacker combines a phishing email (AI-generated content mimicking writing style), voice call (cloned voice), and potentially a video conference (video deepfake) for an attack with overwhelming credibility.
Deepfake Detection
Detection is an arms race, but techniques exist:
-
Visual artifact analysis: inconsistencies in blinking, reflections, face edges, skin texture
-
Audio analysis: micro-frequency variations absent in synthetic voices, compression artifacts
-
AI-based detection: models trained to spot generated content. ThreatClaw integrates this capability into its detection platform
-
Watermarking and provenance: C2PA standards for multimedia content provenance
Protection: Beyond Technology
Verification Procedures
Technology alone is not enough. Companies must implement multi-channel verification procedures:
-
Any transfer above a threshold requires confirmation through a different channel (call to a known number, not the one provided)
-
Verbal password or rotating code to validate identity during sensitive calls
-
Four-eyes principle: two people to validate critical operations
Team Training
Specifically train teams on deepfakes. Exposed employees (finance, executive assistants, HR) must know the threat and verification reflexes.
Monitoring and Detection
Integrate deepfake detection into your security chain. Our experts can assess your exposure and implement appropriate countermeasures. Check our plans.
FAQ
Can a deepfake really fool someone on a video call?
Yes. Current technologies enable real-time face swapping with quality sufficient to deceive an unsuspecting participant, especially at standard video conferencing quality.
How do you verify a call is legitimate?
Hang up and call back on a number you know (not the one provided in the call). Use a pre-agreed verbal password. When in doubt, require written confirmation through a separate channel.
Are detection tools reliable?
They are improving but none are 100% reliable. AI detection is an arms race. This is why organizational procedures (multi-channel verification) remain essential.
Is our company a target for deepfakes?
Any company is a potential target. Priority targets are companies with large financial transfers, publicly visible executives (videos, conferences), and weak validation processes.
Related articles
We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.
Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.
Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.
Dosia malware targets SMBs with obfuscation and tool transfer tactics. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this threat effectively.