Key Takeaways
Making a deepfake now takes no skill, so any public-facing executive is a target.
Detection tools weaken under compression, so a second verification channel provides stronger control.
Group-IB Fraud Protection detects device and session signals associated with deepfakes, including virtual camera injection, emulator use, and anti-detection browsers, so fraud teams can flag a synthetic identity attempt during verification rather than after the account is open.

What is a deepfake?

What is a Deepfake?

Deepfakes are created using deep learning techniques and Artificial Intelligence (AI) to manipulate existing media by swapping one person with another, creating the illusion that someone is present when they were never actually there. Deepfakes can also be entirely new and fabricated content, showing people doing or saying things that they never did or said.

Although they were initially popular in the entertainment industry and on social media, deepfakes have now become a significant cybersecurity concern. Fraudsters use deepfakes to manipulate public opinion and influence elections, deceive biometric facial recognition systems, and register fake accounts on various commercial resources and government systems.

Deepfakes are difficult to recognize. In this article, we explore how deepfakes threaten cybersecurity, present ways to detect them (elaborated by Group-IB Digital Risk Protection experts), and share strategies to mitigate the associated risks.

CYBERSECURITY X AI: Building capabilities to defend assets and defeat attackers
CYBERSECURITY X AI

Test your AI readiness and implement essential
upgrades to your cybersecurity

How Are Deepfakes Made?

Deepfakes are made by training a model on real recordings of a person until it can reproduce that face or voice on demand. An autoencoder learns to strip a face down to its core features and rebuild it on someone else’s body, while a generative adversarial network runs a forger against a critic until the fake passes. Diffusion models refine visual noise into a finished frame.

Voice cloning follows a different process, since speech models learn a target’s pitch, accent, and rhythm before generating new sentences in that voice. Group-IB research on deepfake voice phishing found that current models require only a few seconds of clean audio, harvested from webinars, social media clips, or short calls. The clone is then played from a prewritten script or used to transform the attacker’s speech in real time.

None of this requires technical skill anymore, because consumer apps handle face swaps in a browser, and the methods described work with footage the target has already posted online. 

Group-IB has tracked underground vendors selling deepfake generation-as-a-service, alongside forum posts recruiting “AI video actors” for hire. Cost and skill no longer separate amateurs from organized fraud groups, which is why deepfake attacks have scaled so quickly.

Why Are Deepfakes Dangerous?

Digital cloning poses a serious threat, especially when used in cyberattacks. AI-powered text-to-voice services can make scam calls sound incredibly natural, leading to more effective vishing (voice phishing) campaigns. The demand for deepfake apps like HeyGen and the discussions around them point to growing interest among threat actors in bypassing the security measures in such apps, as noted by Group-IB experts in the 2023/2024 Hi-Tech Crimes Report.

Gartner has drawn attention to the fact that AI-driven cyber and fraud attacks, including those involving deepfake technology, are on the rise: “Enterprises must prepare for malicious actors’ use of generative AI systems for cyber and fraud attacks, such as those that use deepfakes for social engineering of personnel, and ensure mitigating controls are put in place.”

Scams and phishing are among the most common challenges, and they are only expected to become even more dangerous as AI continues to evolve. Threat actors will continue to use realistic, convincing deepfakes to manipulate individuals and businesses, making it even harder to distinguish genuine from fraudulent communications. These risks mean that organizations must adapt their cybersecurity strategies accordingly.

Typical Deepfake Attack Schemes

Deepfakes are used in various malicious ways:

  • Blackmail: Victims’ faces are placed in compromising videos, for example, in pornography.
  • Impersonation scams: Executives and employees have their identities forged and used in phishing attacks to steal money and sensitive information.
  • Brand damage: False videos or audio clips are often created to imitate brands, mislead customers into visiting phishing or scam websites, or spread false information. These attacks can damage a company’s reputation, affecting stock prices and consumer trust.
  • Cyberbullying: Deepfake videos or images are used to harass, defame, or humiliate individuals online, often with devastating effects on their mental health and reputation.
  • Fraud schemes: Criminals use the faces of public figures (such as Elon Musk) to convince victims to use new crypto exchange platforms as part of crypto scams. Cybercriminals can also steal facial recognition data to create deepfakes, replacing their own faces with victims’ faces to gain unauthorized access to banking apps. Group-IB recently uncovered the first-ever Trojan with such capabilities, called GoldPickaxe.iOS.

Cybercriminals can also steal facial recognition data to create deepfakes that replace their own faces with victims’ faces, enabling unauthorized access to banking apps. Group-IB uncovered the first-ever Trojan with these capabilities, called GoldPickaxe.iOS.

How to Identify a Deepfake Voice?

It is possible to recognize a deepfake audio by listening for the following:

  • Digital artifacts: Robotic sounds or digital noise
  • Unnatural speech tempo: Odd slowdowns or speed-ups
  • Inconsistent tone: The expression or articulation may not match the person’s typical speech or the context (e.g., overly emotional during a calm segment or vice versa)
  • Monotone delivery: A lack of variation in intonation, which makes speech sound unnatural
  • Uncharacteristic vocabulary: Use of words or phrases that the individual doesn’t normally use

Unlike fake videos, where various artifacts created by neural networks can be seen with the naked eye (such as the “uncanny valley” effect), detecting fake audio by ear is much harder. Scammers can easily mask the audio’s digital origins with slight alterations and noise. To make detection even harder, deepfakes may be based on well-established, highly developed sound analysis and modulation technologies widely used in the music industry and smart voice assistants like Siri. Group-IB Digital Risk Protection experts therefore recommend calling the person back to verify their identity if you have any doubts.

Important note: In many fraud schemes, instead of using deepfakes, cybercriminals often rely on real fragments of archival videos featuring famous people. For instance, celebrities who have taken part in advertising or marketing campaigns risk having their videos edited and re-dubbed. These manipulated videos, which don’t involve complex face-swapping techniques, can be just as misleading as deepfakes.

Deepfake Examples

Documented incidents show how quickly these techniques moved from novelty to active abuse. The deepfake examples below are grouped by the format attackers reach for, since each one fails in a different way and calls for a different check.

1. Celebrity and political deepfakes

Public figures make the easiest targets because hours of their footage already sit online. In March 2022, a fabricated video of Volodymyr Zelensky telling Ukrainian troops to surrender appeared on a hacked news site and spread across social platforms before being debunked. Group-IB has separately documented crypto investment scams built around the face of Elon Musk, which push victims toward fraudulent exchange platforms.

2. Deepfake videos

Video remains the most convincing format because it carries a face, a voice, and body language at once. Attackers now run face swaps live inside video calls rather than producing clips in advance, which defeats the instinct to trust a familiar face on screen. Quality still varies widely, and the Zelensky clip was debunked within hours, but poor quality no longer stops a fake from spreading.

3. Deepfake images

Still images are the cheapest deepfakes to produce and the fastest to spread. In May 2023, an AI-generated photo appearing to show an explosion near the Pentagon circulated widely and briefly unsettled US stock markets before officials confirmed nothing had happened. The same techniques produce non-consensual intimate imagery and forged identity documents, which is where most financial institutions first encounter the problem.

4. Deepfake voice cloning

Cloned audio needs the least source material and works over channels people rarely question. Group-IB’s research points to a 2019 case in which a cloned executive’s voice moved 243,000 dollars from a UK energy company, and a Canadian case in which a grandmother sent 6,500 dollars after a call that sounded like her grandson. Neither attack required anything beyond a short voice sample.

5. Deepfake scams targeting businesses

Corporate fraud causes the largest single losses, since a single successful call can move seven figures. Group-IB reports that a deepfake video conference cost engineering firm Arup around $ 25 million, after an employee joined a call populated entirely by synthetic colleagues and approved the transfers. Group-IB’s vishing research separately recorded a 194 percent rise in AI-related fraud attempts across Asia-Pacific during 2024.

Deepfake Detection

Manual inspection is used less often as technology improves, and deepfake detection has largely moved into software. AI-based deepfake detection models are trained on large sets of real and synthetic media until they learn the statistical traces a generator leaves behind. 

Some analyze frequency patterns invisible to the eye, while others track subtle physiological signals, such as facial blood flow or head movement between frames. Accuracy remains high against generators the model has seen but drops sharply against new ones.

Manipulated images

Images carry the least data, so detection relies as much on context as on pixels. A reverse image search will often surface the original photograph the fake was built from, and Content Credentials embedded at creation can confirm provenance when they survive re-upload. 

Forensic analysis of compression and noise patterns adds a second layer, though heavy editing and platform recompression degrade both signals.

Deepfake videos

Video gives detectors more to work with, because a forgery has to stay consistent across thousands of frames. Automated checks compare lip movement against the audio track and look for flicker where an overlaid face meets the original footage. 

On live calls, asking the person to turn their head fully or pass a hand across their face still breaks many real-time systems.

Synthetic audio

Audio detection reads the spectrum of a recording, which carries evidence a listener’s ear never registers. Acoustic fingerprinting looks for the absence of things a real recording contains, such as room reverberation, breathing, and the small irregularities of a human larynx. 

Telephone compression strips much of that evidence, so a callback on a known number remains the more dependable control.

Deepfake detection tools

Available deepfake detection tools fall into a few groups: standalone services that score an uploaded file, platform screening that runs at the point of upload, provenance systems that attach signed metadata at creation, and fraud platforms that watch behavior rather than pixels. 

Group-IB Fraud Protection sits in the last group and flags device and session anomalies associated with synthetic media, so the verdict never depends on the file itself.

How to Prevent Deepfake Scams and Attacks

Preventing deepfake scams depends on process controls that hold even when the face and voice on the call are convincing.

1. Verify identities through multiple channels

Confirm requests received through one channel on another before anyone acts. 

Validate any request involving funds, sensitive data, or account access across at least two separate communication channels, so a phone call gets confirmed by internal messaging or email. 

The second channel has to be one the requester did not choose, since attackers control the first.

2. Establish strong authentication controls

Voice and face should never be the only credentials, because both can now be reproduced from publicly available material. Phishing-resistant multi-factor authentication anchored to a hardware key or a registered device leaves attackers with nothing to clone. 

For customer onboarding, pair liveness checks with device and behavioral signals, since a synthetic face presented through a virtual camera will pass a visual test on its own.

3. Train employees to recognize deepfakes

Awareness training works better when it uses real deepfake examples than when it describes the threat in the abstract. 

Finance and executive assistant teams need it most, since they hold the authority attackers are trying to borrow. The lesson worth drilling is procedural: staff should feel able to pause a call from a senior figure and verify it without fearing the consequences.

4. Implement payment verification procedures

Payment controls stop a loss even after the deception succeeds. Require dual approval above a set threshold, with the second approver contacting the beneficiary independently rather than through details supplied in the request. 

New bank accounts and changed payment details deserve a mandatory hold, because urgency is the pressure every deepfake operator applies and a delay costs a legitimate supplier very little.

5. Monitor for impersonation and brand abuse

Most deepfake attacks begin outside your perimeter, on the platforms where your executives and brand appear. Continuous monitoring catches cloned executive profiles and the scam domains behind them while they are still being set up. 

Group-IB Digital Risk Protection tracks unauthorized use of logos, trademarks, and executive likenesses across the open web, which shortens the window between a campaign launching and someone noticing it.

How to Defend Against Deepfakes with Group-IB

Group-IB Fraud Protection treats a deepfake as a session problem, not an image problem. The platform builds a unique profile for every device that touches your systems, so surrounding signals expose a synthetic face presented through a virtual camera, even when the video itself looks clean. The engine runs at a 96 percent real-time detection rate across protected merchants.

Here is how the solution works against deepfake-driven fraud:

  • Injection and liveness bypass detection: Flags attempts to feed a pre-recorded or synthetic face into an identity check through a virtual camera. 
  • Device fingerprinting: Creates a unique profile for every device accessing your systems, exposing the emulators and virtual cameras that synthetic media must pass through.
  • Behavioral analysis: Identifies the session anomalies that accompany an assisted or scripted interaction, including timing and input patterns no cloned face or voice can reproduce.
  • Account takeover prevention: Detects unauthorized access and blocks attempts to change account details after an impersonation succeeds elsewhere.
  • Underground visibility: Group-IB Threat Intelligence monitors vendors that sell deepfake generation as a service, giving security teams warning before a campaign reaches their customers.

Explore how Group-IB Fraud Protection works in practice and why it stands out against other offerings. Or talk to our experts today to build a defense against deepfake-enabled fraud.

FAQs

What is the difference between a deepfake and AI-generated content?

arrow_drop_down

All deepfakes are AI-generated content, but most AI-generated content is not a deepfake. AI can write text, compose music, or produce an image of a person who does not exist. A deepfake specifically imitates a real, identifiable person by swapping a face or cloning a voice. 

 

Are deepfakes illegal?

arrow_drop_down

Creating a deepfake is not illegal everywhere, but using one to defraud, defame, or produce non-consensual intimate imagery breaks the law in most countries. In the United States, the TAKE IT DOWN Act made non-consensual intimate deepfakes a federal offense, and the FTC began enforcing its 48-hour platform takedown rule in May 2026. China and the EU now require AI-generated content to be labeled.

 

How accurate are deepfake detection tools?

arrow_drop_down

Less accurate outside the lab than benchmark scores suggest. Academic testing found one detector’s accuracy fell from 98 percent to roughly 61 percent once video was compressed with a standard codec, and performance drops again against generators the model has never seen. 

 

Can deepfake detection tools detect AI-generated voices?

arrow_drop_down

Yes, though less reliably than for video. Audio detectors look for traces of synthesis, such as unnatural pitch transitions, missing breath sounds, and background noise that stays too consistent. Phone audio is already compressed, which strips much of the detail a detector needs. Group-IB research notes that current models can clone a voice from only a few seconds of recording, so callback verification remains the stronger check.

 

Can deepfakes be detected on social media?

arrow_drop_down

Sometimes. Platforms run automated screening and label AI-generated media, and provenance standards such as C2PA attach signed metadata when a file is created. Both have gaps: metadata is stripped when a video is downloaded and re-uploaded, and compression removes the artifacts detectors rely on. 

 

How can businesses protect themselves from deepfake scams?

arrow_drop_down

Build verification into the process rather than relying on staff to spot a fake. Group-IB recommends validating any request involving funds, sensitive data, or account access through at least two separate communication channels. 

 

 

Can deepfakes be used for identity theft?

arrow_drop_down

Yes, and financial services see it most often. Fraudsters use a stolen photo or a leaked video to bypass facial recognition and liveness checks during onboarding, then open accounts in someone else’s name. Group-IB uncovered GoldPickaxe, the first known iOS Trojan built to harvest facial recognition data for exactly this purpose. 

 

 

What are the most common deepfake attacks?

arrow_drop_down

Executive impersonation leads. An attacker joins a video call posing as a CFO or supplier and pushes through an urgent transfer, as in the Arup case, where Group-IB reports that a single deepfake Zoom meeting cost the firm $ 25 million.

Group-IB: Fight
against cybercrime