Deepfake Detection Tips: How to Check If a Call or Video Is Real
AI can now copy a person's face and voice convincingly enough to fool trained staff. A well-documented Hong Kong case shows the deception didn't even require a live, interactive fake — and visual glitches are no longer a reliable test. This guide explains how deepfake scams work and the verification habits that protect you even when the fake looks perfect.
Your manager joins a video call. Their face, voice and mannerisms all look right. Not long after, you get a message asking you to move money quickly and quietly. Would you question it?
A deepfake is audio, video or an image that has been created or altered with artificial intelligence to make a real person appear to say or do something they never did. The FBI uses the term for a broad range of AI-generated or manipulated media, including voice clones and synthetic video.
Making synthetic media is not illegal by itself, and the technology has legitimate uses. The problem is misuse. Criminals use deepfakes to impersonate executives, government officials and family members so that a fraudulent request feels trustworthy.
The good news: you do not need special software to protect yourself. You need to know the warning signs, and more importantly, you need a habit of checking before you act.

Most deepfake scams follow a familiar social-engineering pattern, with AI added to make the impersonation more believable.
- Collecting material. Criminals gather photos, video and voice recordings of the person they want to imitate. Public interviews, social media posts and recorded meetings can all provide source material. The FBI advises limiting publicly available images and audio of yourself for this reason.
- Creating the fake. AI tools generate a synthetic voice, face, or manipulated video from that material — including, as in the Arup case, pre-recorded footage rather than a real-time synthetic performance. The FTC notes that voice-cloning tools may need only a short audio clip to produce a convincing imitation.
- Making contact. The fake arrives through a phone call, voice note, messaging app, or video meeting — often followed by further instructions through a separate channel, as happened in the Arup case.
- Applying pressure. The request usually involves money, credentials, or confidential information, combined with urgency or secrecy. The FBI highlights fear, urgency and caller-ID spoofing as common supporting tactics.
Deepfakes appear in several recognized fraud patterns documented by the FBI, including video calls or conferences with supposed executives or officials, cloned voices of relatives claiming to be in crisis, and fake videos of public figures promoting investment schemes.

Deepfakes remove a check that people have relied on for decades: recognizing a familiar face or voice. When a request appears to come from someone you trust, you are more likely to act without questioning it.
- Financial loss — fraudulent payments, which can be difficult or impossible to reverse once sent.
- Account takeover — the FBI reports criminals using AI-generated audio of individuals in attempts to access bank accounts.
- Reputational harm — fake statements attributed to leaders or organizations.
- Re-victimization — in 2026 the FBI warned of deepfake videos of a senior FBI official being used to promote a spoofed complaint website aimed at people who had already lost money to scams.
It is important to keep this in perspective. Most calls and videos you receive are genuine. The aim is not to distrust everyone — it is to add a quick, reliable check whenever a request involves money, access, or secrecy.
Look and listen — but do not rely on it alone. The FBI lists signs that may reveal synthetic media:
- Distorted hands, unrealistic teeth or eyes, or indistinct facial features
- Glasses or jewelry that look unnatural, or inaccurate shadows
- Movements that seem unnatural, or delays and lag in the voice
- A voice whose tone or word choice does not quite match the person you know
The FBI also cautions that AI-generated content has advanced to the point that it is often difficult to identify. Treat these signs as reasons to check further — never treat their absence as proof that something is real. As the Arup case shows, the video itself doesn't have to look live or interactive to work — it just has to look plausible enough that you don't check.
Verify through a separate channel — this is the single most effective step. End the call and contact the person using a phone number or channel you already know is theirs — one you looked up yourself or already had saved, never one supplied in the suspicious message, call, or follow-up chat. If you cannot reach them, contact another family member, a colleague, or their manager, through a channel you already trust.
For any request to send money or change payment details:
- Never authorize a payment or a change to who receives it based on a call, video, or chat message alone, however convincing it looks or sounds.
- Call back on an established number before authorizing, not to confirm after the fact — this applies even more strictly to any request to add or change a payment beneficiary or bank account.
- Keep payment initiation and payment approval separate. The person who starts a payment request should never also be the sole person who approves it — a second, independent person checking the request on its own merits is what actually stops this style of scam.
Agree on a verification phrase — as one extra layer, not your main defense. The FBI recommends creating a secret word or phrase with your family to help confirm identity in an emergency. Teams can adopt a similar habit for sensitive requests. A shared phrase is a supplement to calling back on a known number — it does not replace it, and it is not a substitute for an organization's own payment-approval controls.
Slow down when emotions run high. Be cautious of any content designed to make you angry, frightened, or rushed. Pause and verify surprising videos or images through reputable news sources or official channels before reacting or sharing.
Reduce what can be copied. Where practical, make social media accounts private and limit followers to people you know.
For organizations: require independent, out-of-band verification for any payment or payment-beneficiary change — never one that depends solely on recognizing a face or voice — and keep the person who requests or initiates a payment separate from the person who approves it. Plan and rehearse your response to impersonation attempts before one happens. The NSA, FBI and CISA also recommend staff training and exploring technologies that verify media provenance.

Practical Solutions
Call back on a number you already trust before acting on any urgent request for money, passwords, or a changed payment beneficiary — even if it arrived by video, call, or chat, and even if it looks and sounds right.
Set up a family or team verification phrase today — and agree it is a supplement to calling back on a known number, never a substitute for it.
Adopt a "pause rule" for pressure: if a message demands secrecy or immediate payment, stop and verify independently before doing anything.
A necessary caveat
Treat these signs as reasons to check further — never treat their absence as proof that something is real.
The Takeaways
Deepfakes can convincingly copy real faces and voices — and, as documented in a real case, don't even need to be live or interactive to work.
Visual and audio glitches can help reveal a fake, but their absence does not mean a call or video is genuine.
Verifying through a separate, trusted channel — and keeping payment requests and approvals separate — is the most dependable way to stop a deepfake scam.
Companion Video
If you would like a visual explanation, continue with the accompanying CyberBlink video.

Your Boss Is on Video. It's Not Your Boss. (Deepfake Scam)
A fictional employee faces a deepfake video-call payment scam, with lessons from the separate, documented 2024 Hong Kong case.
Related investigations
References
FBI Internet Crime Complaint Center (IC3), Alert I-072026-PSA — 2026-07-20
FBI Internet Crime Complaint Center (IC3), Alert I-120324-PSA — 2024-12-03
NSA, FBI and CISA — Contextualizing Deepfake Threats to Organizations — 2023-09-12
CNN Business — 2024-05-16
Fortune — 2024-05-17
Federal Trade Commission — 2023-11-01
Federal Trade Commission — 2024-04-01
Federal Trade Commission — 2023-03-20
Hong Kong Government — LCQ9: Combating frauds involving deepfake — 2024-06-26