Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
General

Deepfake Phishing: How to Detect and Prevent AI-Powered Impersonation Attacks

Deepfake phishing uses AI voice and video to impersonate trusted people. Learn how the attack works, why conventional controls miss it, and how to detect and prevent it.

Doppel TeamSecurity Experts
August 1, 2026
5 min read

Attackers can now turn human trust, security's oldest weakness, into an AI-generated attack that scales. They can clone an executive's voice from short audio samples and use synthetic video to impersonate a colleague, and AI-generated content is now often difficult to identify. A convincing deepfake call can lead an employee to authorize a fraudulent wire transfer or share credentials despite MFA controls.

Security leaders already report broad exposure, with 62% of organizations reporting a deepfake attack that involved social engineering or exploited automated processes in the 12 months prior to mid-2025. These attacks reach employees through phone calls and the collaboration tools used for meetings, channels that many phishing defenses do not inspect.

This guide explains how deepfake phishing works, why conventional controls miss it, and how to detect and prevent it.

Key takeaways

  • Deepfake phishing uses synthetic media to impersonate trusted people and push victims into high-risk actions such as transfers, credential sharing, or access changes.
  • Traditional email gateways and typo-focused awareness training miss attacks that move through live calls and collaboration tools. MFA can also fail when attackers manipulate the victim into approving the step.
  • Prevention depends on approval controls and out-of-band verification. AI-native detection and realistic simulations reinforce those controls across the channels attackers use.

What is deepfake phishing?

Deepfake phishing is a social engineering attack that uses AI-generated synthetic voice or video, sometimes paired with AI-generated text, to impersonate a trusted person. The technique amplifies well-understood manipulation through a medium that removes the human's reason to doubt.

Deepfake phishing fuses synthetic media with social engineering

AI supplies the realism, and the social engineering supplies the manipulation. Deepfake deceptions use synthetic media to simulate a specific person's appearance or voice and deceive victims into divulging information or performing an action. AI enables hyper-personalization at scale and adapts during live interactions.

It exploits psychological triggers such as urgency and authority, and familiarity makes the request feel safer than it is.

Voice, video, and text are the three forms of deepfake phishing

Security teams group deepfake phishing into three forms based on the channel the synthetic media travels. Each operates on a different trust signal and demands a different defense.

  1. Voice ( vishing): AI clones an executive's voice to instruct an employee to transfer funds or share information. Employees often treat voice as a reliable identity signal, which gives this tactic its force. Malicious actors used AI-generated voice messages in a documented impersonation campaign claiming to come from senior US officials, active since at least 2023.
  2. Video: Real-time deepfake technology lets attackers impersonate a trusted person in a video call. Business communication now defaults to conferencing, so video impersonation reaches employees in a familiar setting.
  3. Text: AI-generated phishing crafts messages with proper grammar and spelling and recipient-specific details. That removes the errors that training taught employees to catch.

These three forms can combine in a single campaign. Each step reinforces the last.

Deepfake phishing exploits trust in a familiar voice or face

The attack succeeds because it impersonates people employees already trust. Malicious actors increasingly use AI-powered voice and video cloning to impersonate trusted individuals, including co-workers and business partners. Skepticism fails to activate because the person on the other end appears to be someone the target knows.

How deepfake phishing attacks work

A deepfake phishing attack moves through the same five-stage social engineering lifecycle as any campaign. AI compresses the early stages and makes the persuasion stage harder to evaluate in real time.

1. Reconnaissance: Attackers harvest voice and video samples from public sources

Reconnaissance starts with the content that many organizations publish freely. Attackers use public executive media and visible LinkedIn profiles to build convincing pretexts. A short clip from an investor call becomes material for a voice clone, and an org chart becomes a pretext.

2. Weaponization: AI models generate the synthetic media or message

The harvested audio and video become the raw material for weaponization. Voice cloning can produce a convincing replica from short audio samples, and attackers can use live synthetic-media workflows to support interactive impersonation during a call. Video deepfakes follow a similar path.

Attackers use public images and video, then replace their own webcam feed with the target's likeness. Synthetic video techniques can manipulate a speaker's likeness so the target appears to deliver a different message. Alongside the media, attackers register supporting infrastructure, such as typosquatting domains, to make the pretext feel legitimate.

3. Delivery: The deepfake reaches the target through a live channel or inbox

Sophisticated campaigns sequence delivery across email and live channels. A phishing email establishes the pretext first, then a follow-up call from the cloned voice reinforces the instruction. A voice or video impersonation falls outside email-layer controls because the attack reaches the human channel, where those tools have limited visibility.

4. Persuasion: A familiar voice or face manufactures authority and urgency

The psychological cues that make social engineering work, perceived authority and familiarity, become far more convincing when a near-flawless impersonation carries them. In a 2025 video-call scam, attackers populated a Zoom meeting with deepfakes of a company's CEO and other executives to manufacture authority and defuse a finance director's suspicion.

5. Execution: The target transfers funds or grants access

The final stage converts manipulation into loss. Victims transfer funds, share credentials, or approve access. The same scam shows the risk. The finance director authorized a US$499,000 transfer during that fabricated call, and the money reached a mule account before he realized the executives on screen were synthetic.

Some threat actors pursue privileged access instead of a financial transfer, including documented Scattered Spider activity where attackers pressured help desk personnel into resetting passwords and MFA tokens.

Why conventional controls miss deepfake attacks

Email gateways and awareness training are strongest against text-based lures and known-bad indicators. MFA can also fail when attackers manipulate the human decision around approval. Those controls miss audio and video manipulation that carries no malicious link and impersonates a real, trusted person.

Voice and video calls travel channels email gateways never inspect

The decisive instruction in a deepfake attack often arrives by phone or video, on channels email gateways never inspect. Email security gateways are built to scan inbound mail, so a voice call or video conference travels right past them. An organization can have strong email security and still lose money to an executive deepfake call.

The same blind spot extends to messaging apps and collaboration platforms, where messages and meeting invites may bypass the controls that defend the inbox.

Deepfakes defeat MFA by manipulating the person who approves the prompt

A deepfake voice or video call provides the cover story that explains and legitimizes an MFA prompt, turning a moment of push fatigue into account takeover. The employee requests confirmation, as trained, and the attacker supplies it through a cloned voice or video presence. Phishing-resistant MFA secures the authentication event.

Approval workflows govern the downstream human decision to authorize a wire transfer or reset a credential.

Awareness training drills the visual tells that deepfakes eliminate

Traditional security awareness training taught employees to spot spelling errors, suspicious links, and odd phrasing. AI-generated messages remove many of those signs by producing proper grammar and recipient-specific detail. Deepfakes go further by shifting the attack surface to audio and video, where text-recognition skills offer little help.

A program that drills typos gives employees little preparation for questioning the familiar voice or face of a CFO on a live call.

How to detect a deepfake phishing attempt

Because generation quality keeps improving, detecting deepfake phishing depends on behavioral red flags and a verification step that does not rely on the channel the request arrived on. Rapid advances in generative AI realism force detection programs to evolve continuously.

1. Watch for audio and visual artifacts that survive generation

Some artifacts still survive generations, though attackers are reducing them quickly. Visual signs include unnatural blinking, lip movements that lag or mismatch speech, texture mismatches around the jawline and hairline, inconsistent lighting, or a floating-head effect. Audio signs include flat or robotic prosody, awkward pauses, suspiciously clean background audio, or verbal habits that differ from the real person.

Treat suspiciously poor video or audio quality as a red flag rather than a reason to trust more, since poor connectivity can mask artifacts.

2. Treat off-process requests as behavioral red flags

Behavioral red flags hold up better than technical tells because the story attackers build around a deepfake exposes it even when the media does not. An active attack commonly involves emotional manipulation through fear or urgency, unexpected requests for money or credentials, requests for secrecy, and uncharacteristic communication from a known person.

Those signals match the FBI behavioral profile. The pretext and off-process request are the durable signals.

3. Verify a suspect request through a separately initiated channel

Verify suspicious requests through a separately initiated channel before acting. The safer response to a suspicious call is to hang up and call the person back using a number you already trust instead of one the caller supplied.

Pre-agreed code words offer a fast identity check, and in one documented case, the targeted executive ended a deepfake call by asking a challenge question the caller could not answer.

How to prevent deepfake phishing attacks

Preventing deepfake phishing requires layered controls that assume the lure will be convincing. Approval controls protect high-risk transactions, training drawn from real attacks gives employees a verification habit, and AI-native detection covers the channels a campaign can use.

1. Put payments and credential changes behind dual-approval controls

Wire transfers and significant payments belong behind dual-approval workflows that require sign-off from at least two authorized people, so a single instruction from a cloned voice cannot move money on its own.

These multiple layers of control matter most for high-risk transactions. Any change to vendor bank details or contact information should trigger a mandatory callback to a number from the organization's own directory.

Pre-shared, rotating code words exchanged in advance give executives and key finance staff a fast way to verify identity during sensitive requests.

2. Train employees against the deepfake lures attackers are actually running

Training has to shift from detection to verification discipline. Because employees struggle to reliably spot deepfakes by inspection, the program should drill the verification protocol regardless of how convincing the communication appears. That means running simulations using realistic AI voice and video scenarios that mirror the tactics targeting the organization.

Doppel, the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management, builds simulations from the live attacks it observes.

Its Dynamic Simulation runs adaptive voice and Microsoft Teams scenarios using AI-generated voices, so finance teams hear a synthetic CFO before an attacker calls with one. The Teams scenarios mirror real attacker staging.

The platform sends targets a calendar invite ahead of the meeting, and the agent can pivot mid-call to a follow-up SMS or email.

3. Deploy AI-native detection across every channel a campaign can use

AI-native detection has to cover every channel a campaign can use, from the inbox to voice, social, and messaging. Because modern campaigns channel-hop deliberately, any defense that guards a single surface misses most of the campaign.

By April 2026, email had emerged as a leading source of attacker activity against financial services and fintech brands alongside social and messaging platforms. Detection has to follow the attack across domains, social, ads, voice, and messaging, rather than guarding one door.

How Doppel defends against deepfake phishing

Doppel detects deepfake impersonation across voice, video, and social channels, correlates and dismantles the attacker infrastructure behind each campaign, then converts the real attacks it observes into employee simulations that build resistance before the next call lands. Four capabilities do the work:

  • Map the whole campaign with the Threat Graph. The Doppel Threat Graph ingests signals across domains, social, paid ads, messaging, telco, and crypto and stitches them into a single view of an attacker's full infrastructure. When it surfaces an impersonation domain, it maps the connected pieces: phone numbers, messaging accounts, social profiles, and ads running off the same registrar.
  • Shrink the executive attack surface. Executive Protection treats each named executive as a digital asset and tracks their exposure across data broker sites, dark web channels, and social platforms. It thins out the leaked PII, family member data, and dormant impersonation accounts attackers use to assemble a deepfake pretext, before a campaign reaches weaponization.
  • Dismantle infrastructure at machine speed. The platform's agentic AI correlates, prioritizes, and executes takedowns across registrars, social platforms, telcos, and ad networks in a single action, so analysts focus on the escalations that need human judgment. Legacy takedown workflows often miss telco infrastructure, leaving the SMS and messaging legs of a campaign live.
  • Turn real attacks into training. When Brand Protection or Executive Protection detects a deepfake campaign externally, security teams convert it to an internal simulation with a single click, so employees rehearse against the exact tactics aimed at them.

Public customer references include Coinbase, where enterprise teams use the platform to dismantle social impersonation and map the connected infrastructure behind active campaigns.

Outpace deepfake phishing with ai-native defense

As synthetic voice and video become harder to distinguish from the real thing, the security teams that stay ahead build verification into every high-risk workflow and meet AI-generated attacks with defense that moves at machine speed. Every takedown raises the cost of running campaigns against your brand, and every detection sharpens the simulations that prepare your people for the next call.

Request a demo to see how Doppel detects and dismantles deepfake impersonation across every channel.

Frequently asked questions about deepfake phishing

What is deepfake phishing?

Deepfake phishing is a social engineering attack that uses AI-generated voice, video, or images to impersonate someone the target trusts, such as an executive, colleague, or business partner. The synthetic media makes a fraudulent request feel routine and pressures the victim to wire money, share credentials, or grant access. Because it can play out live on a phone or video call, the familiar voice or face removes the usual reasons to doubt. The most reliable defense is to verify any sensitive request through a separate, trusted channel rather than trusting the call itself.

How is deepfake phishing different from traditional phishing?

Traditional phishing relies on written lures like a fake email or login page, and it often carries tells such as spelling errors or mismatched links. Deepfake phishing replaces those text cues with a convincing synthetic voice or face, so the attack can land on a live call that email filters never inspect. It also tends to be highly targeted, using publicly available audio and video of real people to build the impersonation. The practical result is that employees cannot catch it by hunting for typos. They have to confirm the person through a trusted channel.

What is an example of a deepfake phishing attack?

A common example is a finance employee who joins a video call with people who look and sound like company executives, then approves a large transfer at their request. In a 2025 Singapore case, a finance director joined a Zoom meeting where the CEO and other executives were all deepfakes and transferred about US$499,000 before realizing the meeting was fabricated. Voice-only versions also occur, where a cloned executive calls an employee with an urgent payment demand. The shared pattern is a trusted-looking identity making an off-process, time-pressured request.

Last updated: August 1, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.