A deepfake is an AI-generated or AI-altered video, image or voice recording that realistically shows a person saying or doing something they never did.
How deepfakes are made
Deepfakes are produced with deep learning models – originally autoencoders and generative adversarial networks (GANs), today mostly diffusion models and neural voice synthesis. A face-swap model learns from photos and videos of a person and maps their face onto another video. Voice cloning can imitate a voice from just a few seconds of audio. Real-time tools now allow live deepfakes in video calls.
Why deepfakes matter for security
Deepfakes have turned social engineering into a much stronger weapon:
- CEO and CFO fraud – in 2024 an employee of the engineering company Arup in Hong Kong transferred about 25 million US dollars after a video call in which all other “colleagues” were deepfakes;
- voice phishing – calls from a cloned voice of a relative or manager asking for money or passwords;
- bypassing identity checks based on selfies or video (KYC);
- fake job candidates in remote interviews and disinformation campaigns;
- non-consensual intimate images and harassment.
How to protect yourself
- Verify unusual requests for money or data through a second, known channel – call back on a saved number.
- Agree on code words for urgent requests in families and finance teams.
- Require multi-person approval for large payments.
- Look for content credentials (C2PA) and use detection tools, but do not rely on spotting visual errors – quality improves fast.