Guide for Preparing & Responding to Deepfake Events
DEEP
FAKES
It now takes seconds to fake anyone's face or voice - a boss, a family member, a celebrity. That doesn't mean you can't protect yourself. It means you need a few good habits, not better eyes.
This guide explains the four ways deepfakes are used, why no one can reliably spot them - and what actually works instead.
Four Ways Reality Gets Faked
Every deepfake attack is, at bottom, one of four objectives. Each requires a different preparation, a different detection, and a different response.
The Forged Voice of Power
Attackers clone a CEO or CFO - the one voice with absolute authority to command a transfer - and direct a mid-level employee to wire funds under a veil of urgency and secrecy.
A finance worker paid out $25,000,000 after a video call with a deepfake "chief financial officer." A UK firm lost $243,000 to a single cloned voice.
The Hire Who Was Never Human
Threat actors use deepfaked faces and voices to secure remote jobs - gaining insider access to your network, your code, and your secrets under a legitimate employee badge.
Campaigns attributed to the DPRK used synthetic personas to land remote developer roles, then deployed malware and exfiltrated data from within.
The Helpdesk That Opened the Gate
A cloned voice or face passes human authentication - the helpdesk resets a password, enrolls a new device, or grants access - and the attacker walks through the front door as someone trusted.
A journalist broke into his own bank account with an AI-generated voice. Deepfakes bypass the very biometrics meant to keep intruders out.
The Lie That Moved Markets
A fabricated video of a leader saying the unthinkable - defaming a company, moving a stock price, destabilizing a public. Google DeepMind found mis/disinformation is the leading way malicious actors abuse generative AI.
A fake image of an explosion at the Pentagon briefly erased $500,000,000,000 from the S&P 500 before it was debunked.
The Fake Never Had to Be Perfect
Deepfakes are not defeated by sharper eyes. They are defeated by process. Scammers rarely win because their forgery was flawless - they win because they trigger fear and urgency, hijacking the brain's alarm system before logic can catch up. This is the amygdala hack: override normal reasoning and force a rash action.
Studies show that even with training, people cannot reliably detect deepfakes - and tend to overestimate their own ability to spot them. Detection technology is a cat-and-mouse game that is already losing. So the answer is not "look harder." It is: follow the procedure, no matter how perfect the face looks.
Trust the Process, Not Your Eyes
The guide's core counsel is defense-in-depth through process adherence - because your eyes and ears cannot be trusted, the procedure must be unbreakable.
Separation of Duties & Dual Authorization
No single person authorizes and executes a transfer. Require two independent approvers for significant transactions, with non-overlapping justification chains.
The Code of the Day
A rotating code, accessed through a separate MFA-protected channel, that must be stated for any authorization. It rotates several times a day and can be revoked on demand.
Call Back on a Known Number
Verify any unusual request through a different, pre-registered channel - call the number on file, never the one in the suspicious message.
Empower Challenge, Always
Give employees explicit latitude to challenge senior leadership requests, and reinforce that moving to an off-channel platform is itself a red flag.
Interview Verification
Camera on, no filters or background blur, screen shared, at least one in-person touchpoint - and gradual, probationary access for every new hire.
Plan for the Event
Write a deepfake incident response plan: who monitors, who owns takedown, crisis communication templates, forensic retainers - and tabletop it before you need it.