In November 2023, Dubai Police announced the arrests of 43 people accused of running a fraud syndicate that had allegedly stolen US$36 million from two Asian companies. The mechanics described by investigators tell you most of what you need to know about how this category of attack has evolved. Investigators say the group first compromised the email accounts of the companies’ CEOs and sat in their inboxes, reading real correspondence with branch managers and learning the cadence of legitimate deals.
At the right moment, they sent forged wire instructions from the hijacked email and then placed a call to the branch manager in the CEO’s own cloned voice, “confirming” the instructions and removing any lingering doubt. The branch managers complied, and the money moved through Dubai banks before being shuffled across accounts and eventually withdrawn in cash through intermediaries.
That is deepfake phishing: a social engineering attack that uses synthetic voice, video, or images to impersonate a trusted person and trick a target into doing something they would not otherwise do. The arrests in “Operation Monopoly,” as Dubai Police called it, were not the end of the matter; Interpol red notices were issued against the ringleader and twenty other accomplices outside the UAE. The point isn’t the bust but rather the methodology: email compromise married to voice cloning as a coordinated attack.
In this blog you’ll get a clear picture of what deepfake phishing actually is, how the attack chain works, why your existing email security and awareness training don’t catch it, and the practical controls that actually move the needle.
What Is Deepfake Phishing?
TL;DR: Deepfake phishing is a social engineering attack that uses AI-generated voice, video, or images to impersonate someone the target trusts. Unlike traditional email phishing, which exploits what you know, deepfake phishing exploits what you trust.
Deepfake phishing is social engineering with synthetic media in the loop. An attacker uses AI-generated voice, video, or images to impersonate a real person (usually someone the target already trusts) and then uses that impersonation to extract money, credentials, an MFA approval, sensitive data, or anything else they need the target to hand over.
More sophisticated than email phishing, yes, and more complex to execute. But the reason this shift matters has less to do with sophistication and more to do with which part of the target’s judgement is being attacked. Traditional phishing exploits what the target knows: it plays the gap between a real sender domain and a fake one, between a legitimate URL and a near-miss, between an expected attachment and a malicious one.
Over two decades of training have taught people to look for those tells, and the training does its job often enough to matter. Deepfake phishing exploits something different, what the target trusts. When the voice on the call sounds like the CFO and the face on the video matches the one in the company directory, the usual fallback advice (if anything looks off, hang up and call them back) loses most of its value, because the signal it depends on is no longer there.
Three things compound the problem:
- Consumer-grade tools for cloning a voice or generating videos are widely available.
- The source material an attacker needs to train them is sitting in public for any employee with a media footprint.
- AI has lowered the skill barrier enough that parts of the attack which used to require specialist training can now be put together by a determined non-specialist, in much less time than before.
The Types of Deepfakes Used in Deepfake Phishing Attacks
TL;DR: Deepfake phishing attacks rely on four categories of synthetic media: voice clones, video deepfakes, AI-generated images, and hybrid multi-channel campaigns that combine all three. The hybrid version is the one that does real damage.
Four categories of synthetic media show up in real-world attacks, and they aren’t equal in cost, skill, or how convincing they tend to be.
1. Voice (audio)
The quality of voice clones varies, and recording conditions matter more than the raw length of the sample. A couple of minutes of clean audio from a quiet room produces a more convincing result than ten minutes pulled from a video meeting where the speaker was using a laptop microphone, or from a podcast with background noise.
The very short “minimum sample” figures that appear in vendor marketing describe what’s technically sufficient to generate a clone of some kind, not what reliably fools the speaker’s own colleagues on a phone call. Read the same vendors’ own documentation carefully and you’ll find them quietly walking those numbers back. Source audio isn’t usually the bottleneck either. Earnings calls, YouTube interviews, conference keynotes, webinars, and long-form podcast appearances are sitting in public, sometimes recorded with good microphones in treated rooms.
2. Video
The honest read is that you can no longer trust your own eyes on a video clip. Siwei Lyu, a deepfake-detection researcher at the University at Buffalo, summed up the state of the field at the end of 2025 by describing pre-rendered synthetic video as “indistinguishable from authentic recordings for ordinary people and, in some cases, even for institutions.”
The tells that used to give it away (flicker, warping around the eyes and jawline, the wrong number of fingers, an off-kilter blink rate) are largely absent from current tooling. The practical implication for a business is direct: a short clip of your CEO “saying” something inflammatory, a WhatsApp video message from “the CFO” approving a transfer, a Loom-style “quick recording” sent to the finance team, none of these can be reliably authenticated by the person who receives them. Once a clip has been cropped, compressed, and watched on a phone screen, even the residual artefacts disappear. All of which means “I saw it, so I believe it” is no longer a workable standard. Authentication has to come from somewhere other than the clip itself, typically through a channel the sender doesn’t control.
Real-time interactive video is harder to fake, but the gap is narrowing more quickly than most people realise. Current real-time face-swap pipelines run on a single consumer GPU at under 200 milliseconds of latency and produce results that hold together (mostly) under the conditions of a standard Zoom or Teams call: even lighting, head facing the camera, no sudden movements. Where they still break is under deliberate challenge, such as asking the caller to turn fully sideways, to wave a hand in front of their face, to hold up an object the attacker couldn’t have anticipated, or to react to an unscripted prompt. Those still produce visible artefacts in today’s tooling, but the artefacts are getting smaller.
Procedures should be designed on the assumption that the gap will close, and on the assumption that an attacker running a real-time face-swap on a typical video call doesn’t need to fool a forensic examiner, only a employee who has thirty seconds to decide whether to approve something they shouldn’t.
3. Image
This is the easiest category to fake and the one to trust the least. A peer-reviewed 2025 study from Swansea University, the University of Lincoln, and Ariel University ran four experiments on participants across the US, UK, Canada, Australia, and New Zealand: AI-generated face images of both fictional people and real public figures could not be reliably distinguished from genuine photographs, even when the participant was familiar with the person and even when given a real comparison photo side-by-side.
Most popular image-generating models can now render photorealistic IDs, passports, prescriptions, wire confirmation receipts, and bank alerts with legible text from a simple prompt. The kind of artefact that used to require a competent forger with Photoshop and an afternoon can be produced in thirty seconds with no specialist skill involved.
In the deepfake-phishing chain, images tend to be the connective tissue: the polished LinkedIn headshot of a fake recruiter or new colleague, the synthetic ID that clears automated onboarding, the screenshot of a “signed contract,” the doctored invoice that primes the wire. Less attention-grabbing on their own than the video cases, but they’re what makes the larger multi-channel attacks plausible in the first place.
Hybrid, multi-channel
This is what the serious cases actually look like in practice, and it’s the version to plan against. Single-channel attacks (just a voice call, or just a video clip) invite the kind of question that a half-alert employee eventually asks: “Why is the CFO sending me a video message about this instead of just calling me?” The hybrid attack closes off those questions by giving each anomaly an answer that the next channel provides.
A spoofed email or WhatsApp message arrives first to establish pretext and explain why an unusual request is coming through an unusual channel. A cloned voice on a phone call follows shortly afterwards to apply authority and urgency. A short pre-rendered video clip, or in the higher-investment cases a live video call with several “colleagues” present, functions as the final confirmation step. Each channel reinforces the others: the email explains why the call is happening, the call explains why the video is necessary, and the video closes the loop. By the time the target is being asked to do something irreversible, several apparently independent pieces of evidence are corroborating one another, and the cost of pausing to verify has been quietly raised at every stage.
Both the Ferrari and LastPass attempts opened with side-channel messaging before the cloned voice arrived. They failed in different ways: at Ferrari, the targeted executive asked a verification question the attacker hadn’t prepared for; at LastPass, the employee recognised WhatsApp as an off-pattern channel and disengaged before the deepfake could do its work. Either kind of failure widens the margin the procedural defences in the second half of this piece are designed to create.
Overview of a Hybrid Deepfake Attack
TL;DR: A deepfake phishing attack unfolds in four stages: reconnaissance, synthetic media generation, multi-channel delivery with pretext, and the irreversible payoff. The entire chain is engineered to shrink the window between the request and the moment the target thinks to verify.
1. Reconnaissance
The attacker maps the organisation. Open-source intelligence (OSINT) gives them the reporting structure, the names of finance and ops leads, recent role changes, and approval relationships. The target’s public footprint provides source media: a quarterly earnings call yields twenty minutes of clean CFO audio, a YouTube interview yields video. For an executive with a meaningful media footprint, an attacker can assemble a usable training corpus in an afternoon without writing a single line of code.
2. Synthetic media generation
For voice clones (whether pre-rendered or generated live during a call) and for real-time video face-swap, the tooling runs comfortably on consumer-grade hardware: a single GPU of the kind sold for gaming or content creation gets the job done. Pre-rendered talking-head videos tend to be produced differently. Where the attacker wants a polished short clip rather than a live interactive feed, the generation is generally done through consumer subscription platforms, typically priced under a hundred dollars a month for the better-known services. In both cases, the skill barrier has come down with the price; no deep-learning expertise is needed, and the products do the work.
3. Multi-channel delivery
The attacker primes the target through a side channel before the main contact arrives. In the Ferrari attempt, the targeted executive received WhatsApp messages from an unknown number bearing a profile photo of CEO Benedetto Vigna. In the LastPass attempt, the attackers came at an employee with calls, texts, and a voicemail through WhatsApp (a channel the company doesn’t use for business communications and which the employee correctly recognised as off-pattern).
4. The payoff
The endpoint is always some action the target has to take because the attacker can’t take it themselves: a wire transfer, an MFA push approval, a credential reset, a sensitive data hand-off, a contract signature. What these have in common is that they’re hard or impossible to undo once executed. The closing pressure is almost always time-based, framed around a window that’s about to close, and the entire chain is engineered to shrink the gap between the request landing and the employee thinking to call someone for confirmation.
The Business Impact of Deepfake Phishing Attacks
TL;DR: Deepfake phishing attacks drive direct financial loss, regulatory exposure under SEC and NYDFS rules, lasting reputational damage, and weeks of operational drag. With incidents up 1,300% in 2024, the trendline matters more than any single case.
Direct financial loss is the first-order impact, but it isn’t the only one, and there are three more worth understanding before the next budget cycle.
The second is regulatory exposure. A material deepfake-enabled wire fraud against a US public company will, where the attack chain includes a cybersecurity component (typically an email account compromise), trigger the SEC’s cyber disclosure obligations under Item 1.05 of Form 8-K, with a four-business-day reporting clock that begins from the materiality determination. Financial services firms operating in New York are separately bound by NYDFS 23 NYCRR Part 500.17, which requires notification of a cybersecurity incident to the Superintendent within 72 hours of determination. None of those obligations relax because the attack vector was voice or video rather than email.
The third is reputational damage. The Arup story has, in a little over a year, become a case study in business school decks, in World Economic Forum reports, and across cybersecurity vendor pitches. Customers, partners, analysts, and recruits all notice. For public companies, the research on cyber incidents is fairly consistent: share-price reactions are usually temporary but real. For private firms like Arup, the equivalent exposure shows up in sales cycles, in partner due diligence, and in recruiting conversations, where the answer to “what happened in Hong Kong” is now part of doing business.
Operational drag is the fourth. The aftermath of a successful deepfake fraud absorbs the executive team for weeks: forensics, insurance claims, internal investigations, board reporting, regulator briefings, legal posture toward the bank that processed the transfers, and a thorough rewrite of wire approval processes. The opportunity cost is rarely line-itemed but it’s consistently significant.
How to Protect Your Organization Against Deepfake Phishing Attacks
TL;DR: No single product stops deepfake phishing, but a layered set of procedural controls (verbal codewords, out-of-band verification, dual-control wires, simulations, and an updated incident response playbook) significantly raises the cost of a successful attack. These defenses need to be in place before the call lands, not after.
There is no single product on the market that solves this, and any vendor claiming otherwise should be treated with suspicion. What does work is a set of practices that, taken together, raise the cost and complexity of pulling off an attack against your company enough that most attackers will move on to easier targets.
1. Pre-shared verbal codewords for high-risk actions
The FBI’s December 2024 IC3 alert recommends families adopt a secret word for verifying identity in distress-call scams, and the same control transfers cleanly to a business context. For wire transfers above a chosen threshold, for credential resets on privileged accounts, and for MFA approvals on executive accounts, require a verbal codeword that exists nowhere in any system an attacker could have compromised. Rotate it on a sensible cadence, and don’t write it down in a document that anyone could exfiltrate. A convincing deepfake of the CFO has no way of knowing a codeword that lives only in the heads of three people, which is precisely what makes this the matched control against an Arup-style attack.
2. Out-of-band verification through a channel the attacker doesn’t control
Codify the rule that high-risk requests are verified through a different channel than the one they arrived on, and define which channel that is in advance, in writing. If the request came in over WhatsApp, the verification call goes to the desk phone number listed in the corporate directory. Not the number in the requester’s email signature, not the number the requester is calling from, the number in the directory.
3. Mandatory dual control on outbound wires above a threshold
Two independent people, performing two independent verifications, both required before the transfer is released. The threshold should be set well below the loss the business could absorb without serious distress. This is standard accounting hygiene; what the current threat environment does is take it from “recommended” to “non-negotiable.”
4. Treat public exposure as training data
Every podcast appearance, every keynote, and every YouTube interview that an executive does is a sample of clean audio (and often clean video) that can be used to train a clone. You aren’t going to keep the marketing team from putting the founder on stage, and you shouldn’t try. What you can do is be honest with the leadership team about the trade-off being made, and adjust the verification procedures around those individuals accordingly.
5. C2PA and Content Credentials, with measured expectations
The Coalition for Content Provenance and Authenticity (C2PA) maintains an open standard for cryptographically signed media provenance, with backing from Microsoft, Adobe, Google, Meta, OpenAI, the BBC, Sony, and others. It’s the right long-term direction, but it isn’t yet load-bearing infrastructure for incoming calls or video in a typical enterprise environment, and shouldn’t be relied on as one yet.
6. Detection tooling, honestly
Vendors like Reality Defender, Pindrop, and Hive offer deepfake detection across video, audio, and image. The technology works, but it sits on one side of an arms race. Use detection as one layer of a defense rather than the layer. Any vendor making “100% accuracy” claims should be treated with suspicion.
7. Tabletop exercises and live simulations
Run the scenario before the attacker does. Walk the finance team through the Arup chain on paper, then have a third-party run a controlled simulation against a small group, with executive consent and a clear scope. The research on email-phishing simulations is consistent: employees who have failed a controlled simulation are measurably harder to fool the next time. The underlying mechanism (making the pattern familiar before the real attack lands) carries over to the deepfake version.
8. Update the incident response playbook for synthetic media
Who decides that an incident is a deepfake incident? Who calls the bank to attempt a clawback? Who briefs the board, and on what timeline? What does the SEC 8-K clock look like if the incident is material? What does the NYDFS 72-hour clock look like for a regulated entity? These questions are better answered while the building isn’t on fire.
None of this requires a large security team. It requires that a small number of these controls actually exist before they’re needed.
How SafeHill Can Prepare Your Team for Deepfake Phishing Attacks
The summary is straightforward enough. Deepfake phishing is targeted social engineering with synthetic media in the loop. The existing email and awareness controls don’t catch the part of it that does the damage. The defenses that do work are procedural rather than technical, and they need to be in place before the call lands. The most direct way to find out whether your defenses actually work is to run the attack against your own organization, under controlled conditions, before someone else does.
This is what SafeHill does. We run adversary-grade social engineering assessments and deepfake phishing simulations (voice, video, and hybrid) against client teams. The deliverable isn’t a pass/fail score. It’s a clear picture of which people, channels, and approval paths in your organization actually break under a realistic deepfake attack, and which procedural controls would have caught it. All targets are scoped with leadership in advance, consent is documented in writing, and the goal is never to embarrass anyone. The goal is to find out what fails before an attacker does.
If you want to discuss what an assessment for your organization would look like in practice, book a consultation with SafeHill.
About the Author
Anthony Cepero is a Penetration Tester at SafeHill. His primary focus spans internal and external network penetration testing, open-source intelligence (OSINT), and executing high-impact social engineering campaigns. To prepare organizations for highly targeted adversaries, Anthony regularly researches and integrates deepfake technology into standard campaigns to replicate sophisticated, real-world adversary behavior.