Blog

August 16, 2026 · SafeInstinct Team

Deepfake Video Conferences: When AI Impersonates Your Boss

Sophisticated criminals are leveraging artificial intelligence to clone the voices and faces of executives. In a notable case last year, a finance worker wired millions of dollars after attending a video call with convincing deepfakes of her colleagues. This article explores how deepfake video scams work, why they’re so persuasive, and how organizations can protect themselves.

Deepfake Video Conferences: When AI Impersonates Your Boss

A shocking example

The most dramatic deepfake fraud to make headlines recently occurred in Hong Kong. A finance department employee of a multinational firm received an email from a colleague directing her to join a video conference to discuss a confidential transaction. On the call were several familiar faces—senior executives and the company’s finance director—who all requested that she transfer a large sum of money to a supposed vendor. Over the course of the meeting, the employee made 15 wire transfers totaling more than HK$200 million (roughly US$25 million) to bank accounts provided during the call.

Afterwards, she learned that none of the people she spoke to were real. Investigators discovered that criminals had downloaded publicly available videos of the executives and used generative AI tools to create lifelike avatars complete with matching voices. The scammers even manipulated the video feed to simulate natural gestures and lip movements. Because the meeting seemed so authentic and involved multiple “participants,” the victim did not question the unusual payment request until it was too late.

Deepfake technology is improving—and proliferating

Creating deepfakes no longer requires advanced technical skills or expensive equipment. Open‑source tools and commercial AI services can generate believable synthetic voices and faces with only a few minutes of source footage. Criminals can scrape videos from social media, webinars, investor calls or media interviews to build a training set for their AI model.

Security researchers have reported a surge in deepfake fraud attempts over the past few years. One industry analysis observed a 3,000 percent increase in deepfake incidents from 2022 to 2023. Meanwhile, surveys show that many employees overestimate their ability to spot fakes: in one study, 43 percent of respondents said they couldn’t tell the difference between real and fabricated videos, and only 29 percent had heard of deepfakes before.

Why deepfake scams work

Deepfake scams succeed by exploiting trust in live communication and leveraging organizational power dynamics:

  1. Assumption of authenticity: People generally assume that a live video conference is genuine. Seeing a familiar face and hearing a recognizable voice triggers a sense of legitimacy. Attackers exploit that trust to bypass normal skepticism.
  2. Authority bias: Deepfake scammers often impersonate high‑ranking executives who can approve large transactions. Employees may feel pressure to comply quickly, especially if the request appears urgent and comes from someone in a position of power.
  3. Group reinforcement: As in the Hong Kong case, scammers sometimes populate the call with several AI‑generated participants to create the impression of consensus. Seeing multiple “colleagues” agreeing with the request reduces the likelihood that a victim will challenge it.
  4. Nonexistent awareness: Many security training programs have not yet incorporated deepfake scenarios. Employees are taught to be wary of phishing emails but may not realize that video and audio can be fabricated with equal ease.

Warning signs and verification strategies

Organizations can reduce the risk of deepfake fraud by training employees to look for subtle inconsistencies and by strengthening verification protocols:

  • Inconsistent lip‑sync or unnatural pauses: AI tools have improved dramatically, but they sometimes produce video that doesn’t quite match the audio or shows jerky head movements and unnatural blinking. Encourage employees to speak up if something looks off.
  • Unusual channel changes: If an executive who normally communicates via email or Slack suddenly requests a large transfer over a video call, that’s a red flag. Employees should question unusual communication methods or abrupt changes in procedure.
  • Urgency and secrecy: Requests that require immediate, confidential action without documentation should be scrutinized. Attackers use urgency to short‑circuit standard approval processes.
  • No camera policies: Be wary of calls where some participants refuse to turn on their cameras or where video freezes conveniently when sensitive questions are asked. Scammers may claim technical difficulties to hide poor deepfake quality.

Best practices to mitigate risk

  1. Multi‑factor verification for financial transactions: Require secondary approval for large payments or changes to payment details. At least two authorized individuals should sign off on wire transfers or account updates. A simple call to confirm on a known, trusted number can stop a fraud in its tracks.
  2. Use established workflows: Ensure that requests to move money follow documented processes. Disallow one‑off approvals via informal channels like Zoom or Teams calls. Legitimate changes should be documented in internal systems and reviewed by finance leadership.
  3. Train for deepfakes: Incorporate deepfake awareness into security training. Provide examples of fabricated audio and video and educate employees about the ease with which media can be altered. Emphasize that it’s acceptable—and necessary—to question unexpected requests, even from senior leaders.
  4. Limit publicly available footage: While executives may need a public presence, they should avoid posting unnecessary video content. Consider using still images or slides for presentations that will be publicly archived, and be mindful of how much facial footage is available online.
  5. Leverage technical safeguards: Some video conferencing platforms are beginning to integrate AI‑based deepfake detection. Although these tools are still maturing, they can provide additional cues when something is amiss.

Building a culture of verification

Deepfake scams represent a sophisticated evolution of traditional social engineering. They remind us that seeing—and hearing—is no longer believing. Organizations must foster a culture where employees feel empowered to verify requests, regardless of who appears to be asking. By combining robust financial controls, updated security awareness training, and healthy skepticism of unusual communication, companies can blunt the impact of this emerging threat.

Protect your employees before small mistakes become expensive incidents.

SafeInstinct helps teams build security habits that stick with practical employee training, repeatable awareness programs, and a rollout that is simple to manage.