Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

Deepfake Scams: When the Video Call Is Fake

Abstract digital human face dissolving into pixels, representing deepfake video call fraud targeting small businesses

The newest business scam doesn't arrive as a typo-ridden email. It arrives as a video call where your CFO's face and voice ask the finance team to move money — and every person on that call is an AI fake. Deepfake fraud has moved from novelty to a real threat to small and mid-sized businesses, and the defenses that stop phishing don't automatically stop a convincing fake face on a screen.

By Karla Gilvergara, The NetSys Group. NetSys has delivered managed IT, cybersecurity, and AI services since 1998; our engineers are certified Microsoft and Cisco instructors serving businesses across NY, NJ, CT, PA, and Southwest Florida.

What is a deepfake scam?

A deepfake scam uses AI-generated video or audio to impersonate a real person — usually an executive, vendor, or colleague — to trick an employee into sending money, sharing credentials, or approving a request. Instead of faking an email address, the attacker fakes a face and voice on a live call, which feels far harder to doubt.

How bad is the problem, really?

Bad enough to have already cost real companies real money. In one widely reported case, an employee at the engineering firm Arup joined a video conference with what appeared to be the company CFO and several colleagues, then authorized 15 transactions totaling about $25.6 million — before learning that everyone on the call had been an AI deepfake. That figure comes from CrowdStrike's threat reporting, and it's not an outlier so much as a preview.

The trajectory is steep. Deloitte's Center for Financial Services has projected that generative-AI-enabled fraud losses in the U.S. could reach $40 billion by 2027, up from $12.3 billion in 2023. Small businesses are attractive targets precisely because they rarely have a fraud team, and a single employee often has the authority to move money quickly.

Why do deepfakes get past normal defenses?

Because they attack trust, not technology. Your spam filter never sees the call. Your firewall isn't involved. The employee is looking at a familiar face, hearing a familiar voice, and feeling the ordinary pressure to help the boss fast. Deepfakes are simply the high-production-value version of the same social engineering behind business email compromise and AI voice-cloning fraud — the con is old, the mask is new.

What are the warning signs of a deepfake?

Real-time fakes still slip up, especially on cheaper tooling. Watch for faces that don't quite track head movement, lip-sync that drifts, odd blinking or lighting, and audio that sounds slightly flat or robotic. But don't rely on spotting artifacts — the technology improves every month. The reliable red flag is behavioral: any urgent, unusual request to move money or change payment details, no matter who appears to be asking.

How can a small business defend against deepfake fraud?

The fix is process, not just tools. A few controls stop the overwhelming majority of these attacks:

  • Verify out of band. For any payment or credential request, hang up and confirm through a known phone number or in person — never the contact info provided on the call.
  • Require dual approval. No single person should be able to move funds or change vendor bank details alone.
  • Use a code word. Agree on a private verification phrase for finance approvals that no deepfake would know.
  • Slow the urgency down. Train staff that "urgent and secret" is itself the warning sign, and that pausing to verify is always acceptable.
  • Train for it specifically. Update security awareness training to include deepfake video and voice scenarios, not just email.

Underneath those habits, keep the fundamentals strong: phishing-resistant multi-factor authentication, tight controls on who can authorize payments, and clear finance procedures. Deepfakes are one more reason the human layer of your defenses matters as much as the technical one.

Frequently asked questions

Can deepfakes really be done in real time on a live call?

Yes. Real-time face and voice swapping is now possible with consumer and criminal tools, which is why live video is no longer proof of identity. Treat a face on a screen as a claim to verify, not as confirmation — especially when money or access is involved.

Are small businesses actually targeted, or just big companies?

Small and mid-sized businesses are frequently targeted because they have fewer fraud controls and faster payment approvals. Attackers don't need a huge payout; several mid-five-figure wires from smaller firms are easier to pull off and often go unreported.

What should an employee do if they suspect a deepfake?

Stop and verify before acting. End the call, contact the person through a known number or channel, and confirm the request independently. There should never be a penalty for pausing a payment to verify — make that explicit so employees feel safe slowing down.

Does multi-factor authentication stop deepfake fraud?

MFA helps protect accounts but doesn't stop a social-engineering wire fraud where the employee is tricked into acting. Phishing-resistant MFA plus payment verification procedures and dual approval together close the gap that deepfakes exploit.

How do we train staff without scaring them off video calls?

Frame it as a simple habit, not paranoia: verify money and access requests out of band, every time. Regular, realistic training keeps the reflex sharp while keeping day-to-day collaboration normal.

Want to pressure-test your team against modern social engineering? Contact The NetSys Group for a complimentary risk assessment, or explore our cybersecurity services to build deepfake-aware defenses into your business.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.