Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
General

What Are AI Deepfakes? How They Work and How to Stop Them

AI deepfakes clone faces and voices to authorize fraud and bypass identity checks. See how they work, the forms they take, and how enterprises defend.

Doppel TeamSecurity Experts
August 3, 2026
5 min read

A finance director joins a scheduled video call. The CFO is on screen, along with two colleagues she recognizes and a company lawyer she doesn't. They discuss a confidential restructuring, then ask her to authorize a series of transfers before the bank's cutoff. The faces are familiar, and the voices sound right, but none of the people on the call are real.

That scenario is not hypothetical. In one documented engineering firm case, a finance employee wired millions after joining a video conference where attackers had generated every other participant as an AI deepfake.

One believable fake can authorize a fraudulent wire, expose the credentials multi-factor authentication (MFA) was built to protect, or damage a brand before teams can respond. AI deepfakes turn familiar faces, voices, and documents into attack channels standard identity checks aren't built to verify.

That shift now shows up at scale: 62% of organizations experienced a deepfake attack involving social engineering in the year before mid-2025.

Key takeaways

  • AI deepfakes synthesize faces, voices, images, or documents that impersonate real people or fabricate events.
  • Attackers use them to pressure employees and bypass identity checks across the channels customers trust.
  • Durable defense starts before the call lands: reduce exposed executive media, dismantle impersonation infrastructure, verify sensitive requests out of band, and rehearse employees against live synthetic attacks.

An AI deepfake is generated media that impersonates a real person

An AI deepfake is video, audio, or imagery a generative model produces to pass as a specific real person or to fabricate an event that never happened. A neural network learns a target's appearance or voice from sample data, then synthesizes new content matching those patterns. Because it carries the target's own statistical patterns, it survives scrutiny that catches ordinary forgeries.

A cloned voice on a phone line and a swapped face on a Teams call draw on the same underlying technology, and fabricated ID documents bring it into know-your-customer (KYC) flows. Attackers use these tools to run impersonation attacks against executives, finance staff, and vendors whose authority moves money or grants access.

Business Identity Compromise extends Business Email Compromise into synthetic voice and video, a BEC evolution at serious financial and reputational cost.

How are AI deepfakes made?

Every deepfake starts with a generative model that learns a target from sample data, then synthesizes new media in their likeness. A face swap renders the target's face onto the attacker's movements; a voice clone reproduces tone, pitch, cadence, and accent from typed text or a live feed.

The data threshold has collapsed: tools clone a convincing voice from seconds of audio, and any executive who appears in an earnings call or keynote has already supplied usable video.

Dark web marketplaces even sell synthetic identity kits cheaply, each bundling a generated face, cloned voice, and fabricated employment history, so building the fake no longer takes skill or budget.

The main types of AI deepfakes

Deepfakes take four main forms against enterprises, and each exploits a different channel of trust:

1. Recorded video deepfakes swap or reanimate a face

Attackers pre-render recorded video deepfakes to spread disinformation, impersonate executives, or reinforce a phishing campaign.

They train the model on headshots and public footage, then distribute the swapped or reanimated clip over email, messaging apps, or social platforms, powering fake product announcements and executive statements that spread before any correction reaches customers.

2. Real-time deepfakes run live on video calls

Real-time deepfakes replace the attacker's live webcam feed with the target's likeness during a call, tracking head movements and speech live.

Victims have believed they were on a Teams or Zoom call with an executive or CFO while attackers used deepfake masking on calls, on platforms that assume trust and rarely check identity.

3. Voice clones reproduce how someone sounds

Voice clones reproduce a target's speech from harvested audio, running from typed text or live, changing the attacker's voice to the target's. A common sequence pairs the clone with an email from a "CEO" warning that an urgent call will follow, overriding an employee's caution.

Attackers often pair AI voice scams with spoofed caller ID.

4. Synthetic images and documents fabricate proof

Generative tools also fabricate evidence. They produce counterfeit government IDs, utility bills, and bank statements that pass a first glance, while large language models fabricate the employment records and financial histories traditional KYC checks expect.

These synthetic identities open fraudulent accounts, enable money laundering, and can even clear background checks to plant a fake employee inside the company.

How AI deepfakes are used against people and enterprises

Deepfakes put a trusted face or voice on frauds enterprises already recognize, across both internal and customer-facing channels.

Executive impersonation drives wire fraud and business email compromise

Attackers get the highest returns by impersonating a leader to authorize a transfer. They build the fake from video and audio online, then deploy it on a call to request an urgent, confidential payment.

In the engineering firm case above, they stacked several senior figures on one call and added a fake lawyer before the finance executive released the funds.

Cloned voices bypass identity checks for account access

Deepfakes also target the front door of identity. A fraudster can clone a customer's voice, call a bank contact center, pass the automated voice biometrics check, and steer an agent into authorizing a transaction.

The IT helpdesk is the other primary target, because MFA and password resets fall within agents' authority: attackers pose as a locked-out employee, clear checks with leaked details, and trigger an MFA reset that hands over the account.

At Wiz, an attacker cloned the CEO's voice from a public talk and messaged dozens of employees trying to steal credentials.

Fake executives and brand assets deceive customers

Customer-facing fraud is the other lane. Threat actors clone an executive's face and voice from legitimate media appearances, then deploy the result in scam investment ads alongside lookalike domains and spoofed social profiles.

Fraudsters have repeatedly impersonated UK consumer-finance figure Martin Lewis this way, with documented victims reporting major losses to fake-crypto adverts. A convincing fake spreads faster than any correction, and the reputational and legal fallout can exceed a direct fraud loss.

Why AI deepfakes are so hard to stop

Deepfakes defeat standard defenses on three fronts: the tells fade with each model release, lures arrive on channels email security never inspects, and people still treat seeing and hearing as proof.

Detection is losing an arms race by design. As detectors improve, generation advances in parallel, and operational deployment pushes accuracy below academic benchmarks, because detectors learn one generator's fingerprint rather than fakeness itself and struggle against unseen tools.

Email gateways inspect one channel; deepfake attacks deliberately arrive on others. Phone calls, video meetings, SMS, WhatsApp, Teams, and Slack sit largely outside gateway filters, domain authentication, and URL previews. Deepfake phishing carries no malicious code, so endpoint and email defenses miss it: the vector is a trusted channel and the payload is a human request.

Attackers sequence across them: an AI-written email sets up urgency, a cloned call reinforces it, and a video deepfake on a scheduled meeting seals it.

Employees are the last line, and they still treat familiar faces and voices as proof of identity. In the engineering firm case, the attack worked because the employee sought visual confirmation, long considered reliable. Multi-channel sequencing compounds this, satisfying several verification instincts at once until the deception feels like proof.

What it takes to defend against AI deepfakes

Defending against deepfakes takes four moves working as one system: shrink the executive media attackers mine, dismantle impersonation infrastructure before the clone performs, route high-stakes requests through verification a clone cannot follow, and rehearse employees against live synthetic voice and video.

Public audio and video of an executive become training data for an adversarial model. Security teams should audit old webinars, panels, and interviews, remove what serves no purpose, and restrict all-hands recordings to verified employees. Thinning that digital footprint limits the media an attacker can produce.

Detecting the deepfake on the call comes too late. Attackers build lookalike domains, spoofed profiles, and burner accounts to stage it, so defenders can see them first. Dismantle that attacker infrastructure across every channel it lives on, and the campaign loses its staging ground.

Out-of-band verification gives teams a control a deepfake cannot satisfy. For a wire instruction issued on a video call, finance should call the executive back on a known, pre-registered number. Mandatory time delays and a pre-agreed code word for sensitive meetings add friction an attacker struggles to script around.

Annual video training rarely changes how a person reacts with an attacker on the phone. Employees need practice with live synthetic voice and video, a core recommendation in federal deepfake guidance.

That practice should build one reflex: asking a question only the real person could answer. It stopped an attempt when an executive asked about a book the real CEO had recently recommended and the impostor could not.

How Doppel defends enterprises against AI deepfakes

Doppel is the AI-native Social Engineering Defense platform that unifies Digital Risk Protection and Human Risk Management around these requirements. Executive Protection shrinks the footprint attackers mine, auditing public exposure and removing personal data from data-broker sites. Coverage extends to family members, because reconnaissance often starts with the people around a target.

Detection then starts with the infrastructure, before the finished fake appears. Brand Protection detects synthetic impersonations and the domains, profiles, and phone numbers that stage them, and the Doppel Threat Graph correlates those signals into campaign-level views.

When an impersonation domain surfaces, the Graph maps the connected phone numbers, messaging accounts, and social profiles, so enforcement reaches the whole campaign, not one asset at a time. Agentic AI correlates, prioritizes, and executes takedowns at scale, freeing analysts for escalations that need human judgment.

The loop closes on the workforce. One-click threat-to-simulation conversion turns attacks Doppel detects into voice and video simulations that drill employees on the lures in play. Live AI agents can join scheduled Microsoft Teams meetings using a voice clone of an executive, then pivot mid-call to email or SMS like real attackers.

It also tests helpdesks with agents that work through IVR trees, hold times, and transfers, so teams rehearse verification reflexes against real attacker scenarios.

Treat seeing and hearing as untrusted inputs

Security leaders need to stop treating a familiar face or voice as proof of identity. Defend the executive footprint and the workforce's response as one system, and keep dismantling the infrastructure between them until cloning the enterprise costs more than it pays.

Every real attack then becomes training that hardens the people it targets. Attackers already treat seeing and hearing as inputs they can synthesize. The defense has to follow. Request a demo to get started.

Last updated: August 3, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.