Select Page

The Deepfake FAQ: What Every Organization Should Know Before the First Scam Lands

August 19, 2026 | Technology

From “what is a deepfake” to “what do we do if we’ve already been hit,” here’s a plain-language guide.

Deepfakes have moved from a “future threat” conversation to an “active risk” conversation in roughly two years’ time. We’re getting questions from clients across every industry: finance, healthcare, legal, education, private equity, manufacturing, you name it, about how to think about this, what to put in place here and what to do if it’s already happened.

Here are the questions we hear most.

What is a deepfake, exactly?

A deepfake is AI-generated content (audio, video, image or text) designed to convincingly impersonate a real person. The tech has improved dramatically, and the tools to create one now require almost no technical skill.

For most organizations, the practical concern isn’t the Hollywood version. It’s the boring one: a cloned voice asking AP to wire money, or a synthetic video of an executive showing up on a Teams call (things we see often!). 

How are attackers using deepfakes against organizations today?

Three main ways:

  1. Wire transfer fraud. A cloned executive voice or video requests an urgent payment.
  2. Credential and account takeover. A deepfake impersonates a “manager” asking IT to reset a password or change MFA settings.
  3. Information extraction. A “client,” “vendor” or “investigator” joins a call and pulls out confidential data.

All three exploit the same thing: humans trust familiar voices and faces. Deepfakes weaponize that trust.

Is this only a problem for large enterprises?

No, and that’s part of what’s changed. A couple of years ago, the cost of producing a convincing deepfake limited the attack to high-value targets. Today, with AI tools available for a few dollars a month, attackers can target mid-market and even small businesses profitably.

If your business sends wires, processes payroll or stores sensitive data, you’re in scope.

How do we know if a call or message is real?

Unfortunately, you often can’t tell from the content alone. The defensive shift is to stop relying on content for verification.

Instead, verify through an out-of-band channel. If the “CEO” emails asking for a wire, you call them at a known number—no exceptions. If the “vendor” calls asking to change bank details, you email them at the address you already have on file. 

What about deepfake detection software?

It’s improving, and we use detection tools as part of layered defense, but no detection technology is perfect, and the adversarial landscape changes fast. Tools that flagged 90% of deepfakes a year ago may catch significantly less today as generators get better. We recommend treating detection as one layer, not the whole strategy. Process, verification and training do more of the protective work than any single tool.

What’s the role of security awareness training in all this?

A big one! The technical side of deepfake defense matters, but humans are still the decision point on most of these attacks. Awareness training that specifically covers synthetic voice, video and AI-driven social engineering helps your team recognize the patterns and pause before acting.

FYI: Our Security Awareness Training is built for this and not the old “spot the phishing email” approach.

What if our executives are particularly exposed?

You’re asking the right questions.

That’s a real risk and worth treating as its own category. Executives appear publicly on LinkedIn, earnings calls, conferences and podcasts. All of those give attackers training material for voice and video clones.

Executive Risk Management helps reduce exposure by monitoring digital footprint, tightening access and adding verification protocols around the people most likely to be impersonated.

What do we do if we think we’ve already been hit?

Move fast, because the wire transfer window is usually hours. Here’s exactly what we recommend doing:

  1. Engage incident response immediately.
  2. Contact your bank. Wire recalls are possible but time-sensitive.
  3. Preserve evidence: voicemails, recordings, chat logs, email headers.
  4. Notify legal and, depending on the situation, law enforcement.
  5. Debrief your team to close the process gap.

What’s the single most important thing we can do this month?

Pressure-test your verification protocols. Pick a few high-stakes scenarios (a wire request, a payroll change, a password reset for an executive) and run them as a tabletop exercise. The gaps will become obvious.

If you’d like help running that exercise or building out a defense plan, we’re ready when you are!