Skip to main content

We use Google Analytics on Knowledge Center pages to understand aggregate readership. No account, session, or security-tool data is included. See our Privacy Policy.

CyberBlink AIEvidence. Clarity. Confidence.
Verified Incident

Deepfake Detection Tips: How to Check If a Call or Video Is Real

AI can now copy a person's face and voice convincingly enough to fool trained staff. A well-documented Hong Kong case shows the deception didn't even require a live, interactive fake — and visual glitches are no longer a reliable test. This guide explains how deepfake scams work and the verification habits that protect you even when the fake looks perfect.

Your manager joins a video call. Their face, voice and mannerisms all look right. Not long after, you get a message asking you to move money quickly and quietly. Would you question it?

A deepfake is audio, video or an image that has been created or altered with artificial intelligence to make a real person appear to say or do something they never did. The FBI uses the term for a broad range of AI-generated or manipulated media, including voice clones and synthetic video.

Making synthetic media is not illegal by itself, and the technology has legitimate uses. The problem is misuse. Criminals use deepfakes to impersonate executives, government officials and family members so that a fraudulent request feels trustworthy.

The good news: you do not need special software to protect yourself. You need to know the warning signs, and more importantly, you need a habit of checking before you act.

EVIDENCEThe fraud began with a phishing email. A finance employee at the Hong Kong office of Arup, a UK-headquartered engineering firm, received a message that appeared to come from the company's UK-based chief financial officer. Following up on the email, the employee joined a video conference with people who appeared to be the CFO and other colleagues. Hong Kong police later stated that this conference was not a live, interactive exchange — the other participants were pre-recorded video footage of real colleagues, manipulated with deepfake technology, rather than synthetic figures responding to him in real time. After the video conference, further instructions — including the specific payment details — were given separately, through instant messaging. Acting on those messages, the employee sent HK$200 million (about US$25.6 million) across 15 transactions to accounts controlled by criminals. Reports indicate the employee was initially suspicious of the request but set those doubts aside after the video conference; the fraud was identified when he later checked with the company's UK head office. Arup confirmed that fake voices and images were used, and stated — specifically about its own network and business operations — that its internal systems were not compromised and its operations were not affected. Hong Kong police reported the case publicly in February 2024; Arup was named as the affected company in May 2024. The sequence above — phishing email, pre-recorded video conference, follow-up instructions by messaging — was set out by Hong Kong police in a reply to the Legislative Council. Arup's own statement concerns its internal systems only — it is not a finding about every part of how the attack was carried out. What the reported sequence shows is that the deception did not require a live, responsive deepfake at all: pre-recorded footage of familiar colleagues, followed by ordinary text-based instructions, was enough to make an urgent payment request feel routine.
Illustrative reconstruction of a person viewed from behind, looking at a laptop screen during a six-person video conference call, captioned 'Illustrative reconstruction — not the actual meeting.'
A reconstruction of the kind of video meeting used in the Arup case — the other participants were later found to be pre-recorded, manipulated footage, not live interactive deepfakes.
01What Happened (and How Deepfake Scams Work)

Most deepfake scams follow a familiar social-engineering pattern, with AI added to make the impersonation more believable.

  • Collecting material. Criminals gather photos, video and voice recordings of the person they want to imitate. Public interviews, social media posts and recorded meetings can all provide source material. The FBI advises limiting publicly available images and audio of yourself for this reason.
  • Creating the fake. AI tools generate a synthetic voice, face, or manipulated video from that material — including, as in the Arup case, pre-recorded footage rather than a real-time synthetic performance. The FTC notes that voice-cloning tools may need only a short audio clip to produce a convincing imitation.
  • Making contact. The fake arrives through a phone call, voice note, messaging app, or video meeting — often followed by further instructions through a separate channel, as happened in the Arup case.
  • Applying pressure. The request usually involves money, credentials, or confidential information, combined with urgency or secrecy. The FBI highlights fear, urgency and caller-ID spoofing as common supporting tactics.

Deepfakes appear in several recognized fraud patterns documented by the FBI, including video calls or conferences with supposed executives or officials, cloned voices of relatives claiming to be in crisis, and fake videos of public figures promoting investment schemes.

Four-step illustration titled 'How a Deepfake Scam Works': Collect, Create, Contact, Pressure, each with its own icon, captioned 'Look familiar? Verify through a separate, trusted channel.'
02Why It Matters

Deepfakes remove a check that people have relied on for decades: recognizing a familiar face or voice. When a request appears to come from someone you trust, you are more likely to act without questioning it.

  • Financial loss — fraudulent payments, which can be difficult or impossible to reverse once sent.
  • Account takeover — the FBI reports criminals using AI-generated audio of individuals in attempts to access bank accounts.
  • Reputational harm — fake statements attributed to leaders or organizations.
  • Re-victimization — in 2026 the FBI warned of deepfake videos of a senior FBI official being used to promote a spoofed complaint website aimed at people who had already lost money to scams.

It is important to keep this in perspective. Most calls and videos you receive are genuine. The aim is not to distrust everyone — it is to add a quick, reliable check whenever a request involves money, access, or secrecy.

03How You Can Protect Yourself

Look and listen — but do not rely on it alone. The FBI lists signs that may reveal synthetic media:

  • Distorted hands, unrealistic teeth or eyes, or indistinct facial features
  • Glasses or jewelry that look unnatural, or inaccurate shadows
  • Movements that seem unnatural, or delays and lag in the voice
  • A voice whose tone or word choice does not quite match the person you know

The FBI also cautions that AI-generated content has advanced to the point that it is often difficult to identify. Treat these signs as reasons to check further — never treat their absence as proof that something is real. As the Arup case shows, the video itself doesn't have to look live or interactive to work — it just has to look plausible enough that you don't check.

Verify through a separate channel — this is the single most effective step. End the call and contact the person using a phone number or channel you already know is theirs — one you looked up yourself or already had saved, never one supplied in the suspicious message, call, or follow-up chat. If you cannot reach them, contact another family member, a colleague, or their manager, through a channel you already trust.

For any request to send money or change payment details:

  • Never authorize a payment or a change to who receives it based on a call, video, or chat message alone, however convincing it looks or sounds.
  • Call back on an established number before authorizing, not to confirm after the fact — this applies even more strictly to any request to add or change a payment beneficiary or bank account.
  • Keep payment initiation and payment approval separate. The person who starts a payment request should never also be the sole person who approves it — a second, independent person checking the request on its own merits is what actually stops this style of scam.

Agree on a verification phrase — as one extra layer, not your main defense. The FBI recommends creating a secret word or phrase with your family to help confirm identity in an emergency. Teams can adopt a similar habit for sensitive requests. A shared phrase is a supplement to calling back on a known number — it does not replace it, and it is not a substitute for an organization's own payment-approval controls.

Slow down when emotions run high. Be cautious of any content designed to make you angry, frightened, or rushed. Pause and verify surprising videos or images through reputable news sources or official channels before reacting or sharing.

Reduce what can be copied. Where practical, make social media accounts private and limit followers to people you know.

For organizations: require independent, out-of-band verification for any payment or payment-beneficiary change — never one that depends solely on recognizing a face or voice — and keep the person who requests or initiates a payment separate from the person who approves it. Plan and rehearse your response to impersonation attempts before one happens. The NSA, FBI and CISA also recommend staff training and exploring technologies that verify media provenance.

Three-panel illustration featuring Locky, the CyberBlink mascot, titled 'Pause · Lock · Verify: Three Simple Steps to Protect Yourself.' Pause: stop and think, watch for unexpected requests, urgent or secret instructions, and pressure to skip checks. Lock: use your verification process -- company procedure, a known contact number, or a second approver. Verify: confirm through a separate channel -- call back on a trusted number, verify with another person, confirm details independently.
Pause, lock in your verification process, and verify through a separate channel — calling back on a trusted number, never one supplied during the suspicious contact.
Protection

Practical Solutions

  1. Call back on a number you already trust before acting on any urgent request for money, passwords, or a changed payment beneficiary — even if it arrived by video, call, or chat, and even if it looks and sounds right.

  2. Set up a family or team verification phrase today — and agree it is a supplement to calling back on a known number, never a substitute for it.

  3. Adopt a "pause rule" for pressure: if a message demands secrecy or immediate payment, stop and verify independently before doing anything.

A necessary caveat

Treat these signs as reasons to check further — never treat their absence as proof that something is real.

Summary

The Takeaways

  1. Deepfakes can convincingly copy real faces and voices — and, as documented in a real case, don't even need to be live or interactive to work.

  2. Visual and audio glitches can help reveal a fake, but their absence does not mean a call or video is genuine.

  3. Verifying through a separate, trusted channel — and keeping payment requests and approvals separate — is the most dependable way to stop a deepfake scam.

Companion Video

If you would like a visual explanation, continue with the accompanying CyberBlink video.

Illustrative reconstruction of a person viewed from behind, looking at a laptop screen during a six-person video conference call, captioned 'Illustrative reconstruction — not the actual meeting.'

Your Boss Is on Video. It's Not Your Boss. (Deepfake Scam)

A fictional employee faces a deepfake video-call payment scam, with lessons from the separate, documented 2024 Hong Kong case.