In early 2024, an employee at the Hong Kong office of engineering company Arup joined what appeared to be a normal video meeting. The call included the company’s chief financial officer and several colleagues.
There was just one problem: none of them were real.
The faces and voices on the call had been created using artificial intelligence. Convinced that he was speaking with people he knew and trusted, the employee went ahead with 15 wire transfers totaling about $25.6 million. The money was never recovered.
The Arup case showed just how convincing deepfake scams can be. You might think you would immediately recognize a fake video or cloned voice, but that is becoming much harder. AI tools can now create realistic faces, voices, and even live video interactions that can fool people during an ordinary conversation.
And scammers do not need a Hollywood production team to do it. Many of the tools required to create convincing fake audio and video are increasingly accessible and inexpensive.
That means deepfake scams are no longer just a problem for large companies or high-profile people. They can target families, employees, small businesses, and anyone who has photos, videos or voice recordings available online.
The good news is that protecting yourself does not require becoming an expert in artificial intelligence. The most effective defense is knowing when to stop, question what you are seeing and verify the person through a different channel.
What Exactly Is a Deepfake Scam?

A deepfake scam uses AI-generated or manipulated video, audio or images to impersonate a real person.
The scammer might pretend to be your boss asking for an urgent payment, a family member who needs money, a business partner requesting confidential information, or even a bank or government representative.
Traditional phishing often depends on suspicious emails, strange links or obvious mistakes. Deepfake scams take a different approach. They use something much more convincing: a familiar face and a familiar voice.
A scammer may collect someone’s photographs, videos and voice recordings from social media or other public websites and use them to create an imitation. In more sophisticated attacks, that fake identity can be used during a live video call.
That is what makes these scams particularly dangerous. People naturally trust what they can see and hear.
But a video call is no longer absolute proof that the person on the other side is genuine.
How a Fake Video Call Scam Usually Happens
Although individual scams vary, many follow the same basic pattern.
1. The scammer gathers information
The attacker first collects information about the person they want to impersonate. Social media accounts, company websites, YouTube videos, interviews and other public sources can provide photographs, videos and voice samples.
The more information available, the easier it can be to make the impersonation convincing.
2. An urgent request arrives
The target receives a message, email or phone call from someone they recognize.
It might sound like:
“I need you to make this payment right away.”
Or:
“I’m stuck somewhere and need money urgently.”
The story is designed to create pressure before the victim has time to think.
3. The scammer uses a call to build trust
If the target becomes suspicious, the scammer may suggest a video call.
This is where the deepfake becomes particularly useful. Seeing the supposed boss, friend or family member on screen can make the request feel legitimate.
4. Pressure and secrecy take over
The scammer may insist that the request is confidential or that there is only a short amount of time to complete it.
That combination is important.
Urgency makes people act quickly. Secrecy prevents them from asking someone else for help.
5. The victim takes the action
By the time the victim realizes something is wrong, money may already have been transferred, passwords shared or access granted.

Don’t Rely on Your Eyes and Ears Alone
There are certain clues that can sometimes indicate a deepfake, but none of them should be treated as a foolproof detection method.
You might notice unusual lip movements, strange facial expressions, inconsistent lighting, unnatural blinking or a voice that sounds slightly different from normal.
The person may also respond slowly or awkwardly when you ask an unexpected question.
But technology is improving quickly. A poor internet connection can also create many of the same visual and audio problems.
So instead of asking, “Can I spot the deepfake?”, ask a more useful question:
“How can I verify that this person is really who they claim to be?”
That change in mindset can make a big difference.
8 Practical Ways to Protect Yourself
1. Verify Through Another Channel
This is probably the most important rule.
If someone unexpectedly asks you for money, passwords, confidential documents or access to an account, end the conversation and contact them separately.
Call their normal phone number. Send them a message through an account you already know belongs to them. Speak to them in person if possible.
Most importantly, do not use the contact information provided by the suspicious caller to verify the request.
If the video call came from a scammer, they control the information they are giving you.
2. Create a Family Safe Word
Families can prepare for voice and video impersonation scams before they happen.
Choose a private word or phrase that only close family members know. It should not be something publicly visible on social media.
If a relative suddenly calls asking for money, ask them for the phrase.
It is not a perfect security system, but it gives you another way to verify someone’s identity when a voice or video alone cannot be trusted.
3. Stop When Someone Creates Urgency
A genuine emergency can happen, but urgency should never automatically override your normal security checks.
Be especially suspicious when someone says:
- “Do it right now.”
- “Don’t tell anyone.”
- “You only have a few minutes.”
- “I can’t explain this.”
- “Don’t call me back.”
When urgency and secrecy appear together, slow down rather than speed up.
A few minutes spent verifying a request is far better than trying to recover money after it has been transferred.
4. Ask an Unexpected Question
If you are on a suspicious call, ask something that is not publicly available and was not part of the earlier conversation.
You could ask a family member about a private shared memory or ask a colleague about a detail that only the genuine person would reasonably know.
You can also ask them to perform a simple action that was not previously requested.
This should not be your only verification method, because sophisticated systems can sometimes respond convincingly. Think of it as another warning signal, not definitive proof.
5. Protect the Information AI Can Copy
The less material scammers have, the harder impersonation can become.
Review what you make publicly available on social media. Consider limiting access to personal videos, voice recordings and photographs where appropriate.
You do not have to stop using social media altogether. The goal is simply to avoid unnecessarily giving scammers a large library of material they can use to imitate you.
6. Secure Your Accounts
Deepfake scams can be combined with traditional phishing and account theft.
Use strong, unique passwords and turn on multi-factor authentication wherever possible.
An authenticator app or security key can provide stronger protection than relying only on SMS codes, particularly for important accounts.
Even if a scammer manages to convince you to click a malicious link or reveal part of your information, additional account security can make it harder for them to take control.
7. Businesses Need a Verification Policy
Companies should never depend on an employee’s ability to recognize a deepfake.
Instead, build verification into the payment process.
For example, an employee receiving an unusual payment request from a senior executive should be required to independently confirm it using an established company procedure.
The same rule should apply when someone asks for passwords, sensitive documents, changes to banking information or access to important systems.
The more senior the person making the request appears to be, the more important independent verification becomes — not less.
8. Teach Your Family and Employees
Security awareness is one of the simplest defenses against deepfake scams.
Talk to parents, children, older relatives and employees about the possibility of cloned voices and fake video calls.
Make sure they understand one important rule:
A familiar voice or face is not enough to prove someone’s identity anymore.
Knowing this before a scam happens can prevent someone from deciding on pressure.
What Should You Do If You Suspect a Deepfake Scam?
If something about a call does not feel right, you do not need to prove that it is a deepfake before taking action.
Simply stop.
End the call, do not send money, and do not share passwords, verification codes or sensitive documents.
Then contact the person through a trusted channel and ask whether they really made the request.
If money has already been sent, contact your bank or payment provider immediately. The sooner a financial institution knows about a fraudulent transaction, the better the chance of taking action.
You should also preserve evidence, including screenshots, messages, phone numbers, usernames, email addresses and transaction information, and report the incident to the appropriate platform, organization or cybercrime authority.
What If the Person Looks Completely Real?
This is where deepfake scams become particularly difficult.
You may see a familiar face looking directly at you. You may hear a voice that sounds exactly like someone you know. The person may even answer your questions.
That does not necessarily mean the call is genuine.
Instead of trying to become an expert at spotting tiny imperfections in AI-generated video, build a habit of independent verification.
This is the same principle used in good cybersecurity practices generally: don’t trust a single signal when the consequences of being wrong are serious.
Deepfake Scams Are Also a Family Problem
Businesses are not the only targets.
Imagine receiving a late-night call from someone who looks and sounds like your child, sibling or parent. They tell you they are in trouble and urgently need money.
In that moment, most people are not thinking about artificial intelligence. They are thinking about helping someone they love.
That is exactly what scammers exploit.
Families can reduce this risk by agreeing in advance on simple verification procedures. A safe word, a second phone number or a rule that large emergency payments must always be confirmed by another family member can make a major difference.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The important thing is to establish these habits before an emergency happens.
The Biggest Defense Is Simply to Slow Down
Deepfake technology will continue to improve. The fake video you can easily identify today may be much harder to distinguish tomorrow.
That means relying entirely on visual clues is not a long-term security strategy.
The better strategy is behavioral.
When an unexpected video call involves money, passwords, confidential information or urgent action, stop and verify the request independently.
Don’t be embarrassed to hang up. Don’t worry about appearing rude. And don’t let someone else’s urgency become your emergency.
If a face and voice can be copied, trust needs to be verified another way.
The safest response to a suspicious video call is often the simplest one: pause, disconnect and call back using a number you already trust.



