Is a deepfake video call from a company executive telling employees to transfer funds a scam?
This is an emerging, high-impact scam. Deepfake video calls impersonating executives have been used to authorise large fraudulent bank transfers. Always verify payment requests through a separate, confirmed channel.
Last reviewed: 1 August 2026
Explanation
Business email compromise (BEC) has evolved into deepfake video compromise. Employees in finance or payments roles receive a video call that appears to show their CEO, CFO, or a trusted external partner instructing an urgent wire transfer or change of banking details. The video may look convincing because it is generated in real time using deepfake tools or is a pre-recorded manipulation of genuine footage, and multiple companies have reported significant financial losses from this fraud.
Senior executives are the easiest people in a company to deepfake, because hours of their speech and video exist publicly in interviews, earnings calls, and conference talks. The scripts also exploit hierarchy: an employee asked directly by an apparent CEO to handle something 'confidential' and 'time-critical' is being pushed to skip the very controls that would catch the fraud. Some attacks stage entire multi-person meetings in which every other participant is fake, so the presence of colleagues on screen is not reassurance.
The defence is procedural, not perceptual. Any financial instruction received by video call — especially if unexpected, high-value, urgent, or framed as secret — should be verified by calling the executive back on a known direct number and confirmed through your company's standard payment authorisation process. No genuine executive is harmed by a verification step, and organisations should say so explicitly in policy so that junior staff never feel that checking is insubordination.
Common red flags
- Unexpected video call from a senior figure requesting an urgent transfer
- Audio or lip-sync is slightly off
- Call uses a different communication platform than usual
- Request bypasses normal approval processes due to 'urgency' or 'confidentiality'
What to do now
- Do not authorise any transfer during or immediately after such a call
- Call the executive on their known direct number to verify the instruction
- Follow your company's standard payment authorisation procedures regardless of apparent urgency
- Report any suspected deepfake attempt to your IT security team and fraud authorities
Frequently asked questions
Can technical tools detect a deepfake video call in real time?
Detection tools exist but are not yet reliable enough to be your primary defence. Process controls — always verifying payment instructions through a separate channel — are more robust.
There were several colleagues on the call who agreed with the instruction. Does that make it safe?
No. Attacks have staged meetings where every participant other than the victim was a deepfake. Numbers on a screen are not verification — only an out-of-band call-back and your standard authorisation process are.
What should companies change to defend against this?
Make out-of-band verification mandatory for payment instructions and bank detail changes regardless of who requests them, and state in policy that urgency or confidentiality never waives the check. The control must not depend on an employee's courage to question a boss.