Deepfake phishing uses AI-cloned voices and video to impersonate executives. Learn how it works and the verification habits that stop it.
Deepfake phishing is social engineering carried out with AI-generated voice or video that impersonates someone the target knows — usually a senior figure. The attacker uses a cloned voice on a phone call, or a synthesised face in a video meeting, to issue an instruction the target would normally trust. For full incident analysis and program guidance, see the deep-dive on deepfake phishing and employee training.
The reference case remains Arup in 2024: a finance employee transferred roughly 25 million US dollars after a video meeting in which every other senior participant was a deepfake. It is still the highest-value documented example, but the pattern is mature enough now to treat as an operational risk, not a future one.
How it works
Voice cloning targets finance, accounts payable, and executive support staff with an urgent transfer or credential request by phone. A credible clone now needs under a minute of public audio — a podcast, a conference talk, a testimonial — so source material exists for almost any senior figure with a public presence.
Video deepfakes impersonate face and voice inside a live meeting. The Arup pattern used several deepfaked participants reinforcing one another. The instinct that says "I would never authorize this from an email" never engages, because it is not an email.
Why red-flag training does not stop it
Training built on inspecting sender domains, hovering over URLs, and spotting typos has nothing to work with on a call. The visual tells earlier deepfakes produced — unnatural eye movement, audio-video drift — have largely been engineered out. Teaching employees to spot the deepfake itself teaches a defense that expires with the next quality improvement.
The deeper problem is psychological. A familiar voice or face activates trust that text does not. The same employee who would scrutinise a suspicious email complies reflexively with someone who sounds like their boss.
The habits that do work
The durable defense is not better detection but verification independent of audio and video.
- Out-of-band callbacks. Verify any high-stakes request through a channel known in advance, never by responding on the one it arrived on. The deepfake cannot answer a callback to the real person's phone.
- Code-word challenges. A pre-arranged phrase for executive and finance teams, rotated periodically. The attacker who cloned the voice does not know it.
- Cooling-off on unscheduled high-value actions. Large transfers, privileged credential resets, and off-cycle vendor changes get a documented confirmation step that urgency cannot compress. Real-time pressure is the deepfake's main weapon; a mandatory pause removes it.
These are policy decisions as much as training topics: training teaches the habits, policy is what makes them defensible when someone pushes back. The full training program guidance covers role-specific scenarios.
Who is most at risk
Three groups carry most of the exposure. Finance and accounts payable, because they move money. Executive assistants and chiefs of staff, because they act on senior figures' behalf. Anyone with privileged access, because their credentials unlock more. Role-specific scenarios beat uniform deepfake awareness.
Related Learning
- What Is Phishing Awareness Training?
- What Is Spear Phishing?
- What Is Social Engineering?
- What Is Smishing?
Related PhishSkill Capabilities
- AI-Powered Phishing Awareness Training — train employees on AI-augmented attack patterns including voice and video impersonation
- WhatsApp Phishing Awareness Training — extend awareness coverage to the mobile channel attackers use alongside voice clones
- Phishing Simulation Software — the simulation engine that measures the behavior training builds
More Learning Resources
View all learning resourcesHow to Run a Phishing Simulation
A practical guide to running a phishing simulation — scoping it, choosing a fair pretext, teaching at the click, and reading the numbers after.
What Is Smishing? SMS, WhatsApp, and Mobile Phishing Explained
Smishing is phishing delivered through text messages. Learn how SMS attacks work, why they bypass email defences, and how to train employees to spot them.
Phishing Email Examples
Seven phishing emails your team will actually receive, what makes each one work, and the two habits that catch them all.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.