Back to Learning Hub

Quick Guide: Deepfake Phishing

Last updated: 2026-08-133 min read

Deepfake phishing uses AI-cloned voices and video to impersonate executives. Learn how it works and the verification habits that stop it.

Deepfake phishing is social engineering carried out with AI-generated voice or video that impersonates someone the target knows — usually a senior figure. The attacker uses a cloned voice on a phone call, or a synthesised face in a video meeting, to issue an instruction the target would normally trust. For full incident analysis and program guidance, see the deep-dive on deepfake phishing and employee training.

The reference case remains Arup in 2024: a finance employee transferred roughly 25 million US dollars after a video meeting in which every other senior participant was a deepfake. It is still the highest-value documented example, but the pattern is mature enough now to treat as an operational risk, not a future one.


How it works

Voice cloning targets finance, accounts payable, and executive support staff with an urgent transfer or credential request by phone. A credible clone now needs under a minute of public audio — a podcast, a conference talk, a testimonial — so source material exists for almost any senior figure with a public presence.

Video deepfakes impersonate face and voice inside a live meeting. The Arup pattern used several deepfaked participants reinforcing one another. The instinct that says "I would never authorize this from an email" never engages, because it is not an email.

Why red-flag training does not stop it

Training built on inspecting sender domains, hovering over URLs, and spotting typos has nothing to work with on a call. The visual tells earlier deepfakes produced — unnatural eye movement, audio-video drift — have largely been engineered out. Teaching employees to spot the deepfake itself teaches a defense that expires with the next quality improvement.

The deeper problem is psychological. A familiar voice or face activates trust that text does not. The same employee who would scrutinise a suspicious email complies reflexively with someone who sounds like their boss.

The habits that do work

The durable defense is not better detection but verification independent of audio and video.

  • Out-of-band callbacks. Verify any high-stakes request through a channel known in advance, never by responding on the one it arrived on. The deepfake cannot answer a callback to the real person's phone.
  • Code-word challenges. A pre-arranged phrase for executive and finance teams, rotated periodically. The attacker who cloned the voice does not know it.
  • Cooling-off on unscheduled high-value actions. Large transfers, privileged credential resets, and off-cycle vendor changes get a documented confirmation step that urgency cannot compress. Real-time pressure is the deepfake's main weapon; a mandatory pause removes it.

These are policy decisions as much as training topics: training teaches the habits, policy is what makes them defensible when someone pushes back. The full training program guidance covers role-specific scenarios.

Who is most at risk

Three groups carry most of the exposure. Finance and accounts payable, because they move money. Executive assistants and chiefs of staff, because they act on senior figures' behalf. Anyone with privileged access, because their credentials unlock more. Role-specific scenarios beat uniform deepfake awareness.


Related Learning

Related PhishSkill Capabilities

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.