Jeyki SecurityCybersecurity consulting
AI scams

Deepfake Video Call Scams: Protecting Executives and Finance Teams

How AI-generated deepfake video and voice are being used to impersonate executives on calls to authorize fraudulent payments, and the verification habits that stop it.

← Back to guidesPublished 2026-08-20 · Updated 2026-08-20

This is not a hypothetical risk anymore

Deepfake video and voice fraud moved from novelty to real financial loss once generative AI tools made convincing impersonation cheap and fast to produce. High-profile cases have involved fraudsters using deepfake video on a live call to impersonate a company's executives well enough to convince finance staff to authorize a large transfer. The Canadian Anti-Fraud Centre has specifically warned Canadians about fraud using deepfakes.

How the scam typically works

The mechanics build on classic CEO fraud, with AI raising the production quality of the impersonation.

  • The attacker gathers public video and audio of the executive being impersonated, often from earnings calls, interviews, or social media
  • A deepfake video or cloned voice is used on a live or recorded call, sometimes with a plausible excuse for poor video quality or a 'bad connection'
  • The 'executive' instructs finance staff to make an urgent, confidential wire transfer, often citing a sensitive deal that cannot be discussed with others yet
  • Secrecy and urgency are used deliberately to prevent the target from verifying through a second channel

Verification habits that defeat this, even against a good deepfake

The defence does not depend on visually detecting a fake. It depends on a verification process the scam cannot route around.

  • Require a callback to a known phone number on file for any unusual payment instruction, regardless of how the request arrived or how convincing it looked
  • Establish a pre-agreed verification phrase or process for high-value or unusual requests from executives, known to relevant staff in advance
  • Treat 'this is confidential, do not discuss with anyone' as a red flag rather than a legitimate business reason to skip verification
  • Apply dual-approval requirements for wire transfers above a set threshold with no exceptions for 'the CEO said so'
  • Train finance and executive-assistant staff specifically, since they are the most likely targets of this exact scam

What to tell your team without causing paranoia

The goal is a calm, consistent process, not fear of every video call.

  • Normal internal calls and meetings do not need extra verification; this applies specifically to unusual, urgent, secretive payment requests
  • Frame the callback verification step as standard company policy applying to everyone, including real executives, so it never feels like an accusation
  • Encourage staff to trust their instinct if something feels off, and give them a clear, low-friction way to pause and verify without fear of seeming distrustful

If a deepfake attempt happens

Respond the same way as any attempted wire fraud, with immediate reporting.

  • Do not proceed with the payment; end the call and verify independently
  • Preserve any recording, screenshots, or call logs from the attempt
  • Report the incident to the Canadian Anti-Fraud Centre, since deepfake fraud reports help authorities track emerging patterns
  • Alert other executives and finance staff immediately in case the same attacker targets multiple people at your organization

Frequently asked questions

Can people reliably spot a deepfake video on a live call?

Not reliably, and the technology is improving quickly. Relying on visually detecting a fake is not a safe long-term strategy. A verification process that does not depend on judging the video's authenticity is far more reliable.

Are small businesses actually targeted by this, or just large corporations?

Deepfake fraud has so far concentrated on larger, high-value targets because of the production effort involved, but the tools are becoming cheaper and easier to use, and the underlying scam pattern, urgent secretive payment requests, already targets small businesses constantly through simpler email and voice methods. The same verification habits protect against both.

Should we ban video calls for payment approvals?

Not necessary. The fix is procedural, not technological: require independent verification through a known channel for any unusual payment instruction, regardless of what medium the request arrived through.

Official resources