Overview: Deepfake detection advice expires with every model release, so the training that lasts builds verification habits and a workplace culture where double-checking a request from the boss is normal, not insubordinate.
Summarise this page with your favorite AI assistant

When Any Voice Or Face Can Be Faked: The Phishing Playbook Has A Blind Spot

Most companies have finally gotten decent at email security training. Employees hover over links, squint at sender addresses, and forward anything odd to IT. Years of phishing simulations did their job. The trouble is that the playbook stops at the inbox.

In early 2024, a finance employee at a multinational engineering firm in Hong Kong received a suspicious email about a confidential transaction. He did what training taught him to do: he doubted it. Then he joined a video call with the company's CFO and several colleagues, who confirmed the request, and he approved transfers worth about $25 million. Every other person on that call was a deepfake. Notice the order of events. The fake meeting did not start the fraud; it was the step that dissolved the doubts his training had correctly raised.

That case gets cited a lot in security circles, and for good reason. It shows the attack moving to the exact channels employees are trained to treat as proof: a familiar face and a live conversation. Corporate training has not caught up. We teach people to distrust text and then leave voice and video as unquestioned tiebreakers.

Why "Spot The Fake" Training Expires So Fast

The instinctive response is to teach detection: odd blinking, hands with too many fingers, lighting that does not quite match the room. Plenty of awareness decks from two or three years ago did exactly this, and nearly every tell they listed has since disappeared. Each visual glitch is a bug report, and the next model version fixes it. Detection training gives employees confidence with a shelf life of months, which is worse than no confidence at all, because it teaches that a convincing call has earned trust.

There is a second problem, and it is less obvious. Synthetic media is no longer only a fraud tool. Marketing teams now put out synthetic influencers and deepfake spokespeople as ordinary brand assets, with disclosure labels and compliance reviews attached. Your employees will encounter polished, legitimate synthetic video at work regularly. When generated faces are part of normal business communication, "it looked real" stops carrying information. Realism became the baseline, so it can no longer be the test.

Teach Verification, Not Detection

What holds up is procedure. A deepfake literacy program should spend a small fraction of its time on how the technology works and most of it on what employees do when a request arrives by voice or video. The skills worth drilling are boring, which is exactly why they survive model upgrades.

Confirm On A Second Channel

Any request involving money, credentials, or data access gets verified on a channel different from the one it arrived on. If the CFO asks during a video call, the employee calls back using the number in the company directory, not the number in the meeting invite. The rule matters more than the tool. Attackers control the channel they contacted you on; they rarely control the one you choose yourself.

Put Authority In Writing

Half of these scams work because nobody is sure who can approve what. Publish the actual approval chain for payments, vendor changes, and access grants, and state plainly that no phone call or video call can override it. An employee who knows the CEO cannot authorize a wire by voice alone has a script for the scariest moment of the con.

Treat Urgency As The Alarm

Manufactured time pressure is the one element the attacker cannot remove, because verification takes minutes and minutes are what kill the scheme. "This has to happen before end of day and you cannot tell anyone" should register as the red flag itself, whatever face is saying it.

Give High-Exposure Teams A Shared Phrase

Finance, executive assistants, and IT support pick up the phone for a living. Families now use code words to defeat voice-clone scams aimed at relatives, and the same low-tech fix works for a leadership team. It costs nothing and no model can generate it.

Drill It Like You Drill Phishing

Phishing simulations became standard because one experience of being fooled teaches more than an hour of video content. The same logic applies here, and the raw material is uncomfortably easy to produce. A short clip of clean audio from a town hall recording or a webinar is enough to clone a voice with a consumer tool. Executives are public speakers; their voices are already training data.

So use that, with consent. Clone a leader's voice and run a controlled voice-phishing drill against the finance team. (Get sign-off from the executive first. This is not a place for surprises.) Stage a tabletop exercise around the fake CFO call and let people argue about what they would have done. Debrief without shaming anyone, the way mature phishing programs already do. The aim is for the first deepfake call your employees experience to be one you sent.

Let Peers Carry The Message

A mandated module tells employees the company is worried. A teammate who plays a clone of their own voice in a Monday meeting and says "this took me four minutes and a free trial" changes what people believe. That demonstration lands because of who is giving it, which is the same reason internal learning champions outperform top-down rollouts in AI adoption generally: people weigh who is talking before they weigh what is being said.

Champions serve another purpose here. In practice, the first thing a suspicious employee does is not file a ticket. It is turning to a colleague and asking, "does this look off to you?" Give that instinct somewhere to go. A named champion on each team, plus an informal second-opinion channel, catches the cases where someone feels uneasy but cannot justify escalating. Verification culture lives in those small exchanges, not in the policy document.

Measure Behavior, Then Protect It

Completion rates tell you nothing about any of this. Track what people do. In drills, measure the share of targeted employees who actually made the callback, and how long reporting took. Outside drills, count near-miss reports, and treat a rising count as the program working rather than the sky falling. People reporting weird calls means people noticing weird calls.

Then protect the behavior. The employee who double-checks a genuine request from the CEO must come out of that exchange feeling smart, not insubordinate. One executive who snaps "why are you wasting my time" undoes a year of training, because everyone hears about it. Leadership has to say, out loud and more than once, that verification is never a career risk.

The technology side of this arms race is already lost, in the sense that screens and speakers have stopped being reliable witnesses. Training that promises employees sharper eyes is selling them a detection skill the next model release will delete. Training that gives them a procedure they can follow without permission, and a culture where following it is expected, holds up no matter how good the fakes get.

About the author

Related articles

Change your privacy settings to see the content.
In order write or read comments you need to have functional cookies enabled.
You can adjust your cookie preferences here.
Share