You Can't Believe Your Eyes
When what you see and hear can no longer be trusted, it’s time to implement new security protocols.
The cost of creating video and audio deepfakes has fallen to practically nothing. Bill Sparks looks at how companies are evolving to operate in a world where remotely communicated executive orders can no longer be trusted.
In early 2024, a finance worker at the British engineering firm Arup joined a video call with his chief financial officer and several colleagues. The CFO wanted some money moved. By the time the call ended, the employee had approved fifteen separate wire transfers worth roughly $25.6 million. He later learned that everyone on that call was a deepfake. The CFO was fake. The colleagues were fake. The entire meeting was a piece of theater generated by criminals.
Here is the part that should worry everyone reading this. The employee did not fall for a clumsy trick. He saw his boss. He heard his boss. He did exactly what his boss requested, as employees have all been trained to do their entire working lives. The criminals did not defeat a security system. They revealed there was no security system.
This is not a rare event
It would be comforting to file the Arup story under freak occurrence. The numbers say otherwise. Deepfake-related fraud has cost roughly $2.19 billion worldwide since 2019, and the pace is accelerating, with $1.65 billion of that total lost in 2025 alone. The United States is the hardest-hit country, accounting for about $712 million of the global figure. A Gartner survey found that 62 percent of organizations had been hit by a deepfake attack in the previous twelve months. More than half of the organizations that were targeted reported real financial losses, averaging about $280,000 per incident.
What changed is that the cost of faking a person collapsed. A few years ago, a convincing voice clone required a studio and a budget. Today it requires three to ten seconds of clear audio, which is roughly the length of a voicemail greeting or a clip lifted from a conference panel on YouTube. Security people have started calling this the new business email compromise, and the comparison is apt. The old scam was a spoofed email from the boss asking for a transfer. The new one is the boss's actual face and voice asking for it. A decade was spent teaching employees to distrust suspicious emails. Now, not even the face and the voice of the boss can be trusted.
Established companies are, if anything, more exposed than the digital natives. Decades spent building a business on personal relationships, on the handshake and the trusted phone call and the senior manager whose word is good, produced exactly the informal, high-trust culture these attacks feed on. The very thing that made these firms resilient for fifty years, that people know each other and act quickly on one another's say-so, is now the attack vector.
Advanced and readily available deepfake technology has rendered the human instinct of trusting a known face obsolete.
Recognition is not verification
The instinct here is to treat this as a technology problem, and to think it must have a technology solution. This is a dangerous reflex. The real exposure is not a software flaw. It is a roughly hundred-year-old assumption baked into how organizations operate, which is that recognizing someone is the same as verifying them. For most of business history that assumption was fine. Faces and voices were genuinely hard to counterfeit, so we let them stand in for proof. Recognition quietly became our authentication layer, and we never wrote it down because we never had to.
Deepfakes do not so much break that system as walk through the door it left open. Which raises an uncomfortable question. If you can no longer trust your own eyes and ears on a video call, what exactly were your financial controls resting on the entire time? For a lot of companies, the honest answer is that they were resting on instinct, and instinct is now compromised.
The market will happily sell you detection software, and some of it is genuinely useful. But betting your defense on it is a mistake. Independent research has found that deepfake detectors fall below 50 percent accuracy under real-world conditions. A coin flip is not a control. Worse, detection is an arms race in which the defender is structurally behind. Every improvement in detection becomes training data for the next generation of fakes.
Designing a zero-trust system
The firms handling this well have reached a counterintuitive conclusion. The durable fix is not more sophisticated technology. It is less reliance on individual human judgment. They are deliberately designing trust out of the moment and into the process.
In practice that means a few specific things. They set a zero-trust rule for voice and video, so no money and no sensitive data ever moves on the strength of a call alone, no matter whose face is on the screen. They require out-of-band verification, so an employee who receives an urgent request hangs up and calls back on a known internal number rather than trusting the channel the request arrived on. Some adopt challenge-response phrases, simple agreed-upon safe words known only to specific people, where no correct phrase means no transaction. And they require multi-party authorization for high-risk actions, wire transfers and payroll changes and credential resets, so that no single person can be talked into acting alone.
None of this is expensive. None of it requires a vendor. The hard part is cultural, not technical. These attacks work by weaponizing urgency and authority, the fake boss who needs it done right now and does not want questions. A junior employee who has never been given explicit permission to say no to the CEO is precisely the vulnerability the attacker is counting on. The control only works if the organization decides, in advance, that verification is mandatory and that slowing down to confirm is a sign of competence rather than insubordination.
If that sounds like a lot to stand up at once, it is not. The sensible place to start is the short list of actions that actually move money or hand over access, and to write down a single firm rule for each one. Most organizations discover they have only a handful of these choke points, and that protecting them well covers the great majority of the risk. The goal is not to verify everything that moves. It is to make the few transactions worth faking impossible to complete on the strength of a face and a familiar voice.
What leadership needs to do
This is where senior leaders have a part to play that cannot be handed off to IT. The shift underway is that trust has to migrate from people to processes, and that migration is uncomfortable because it feels like replacing relationships with bureaucracy. The reframe worth internalizing is that verification is a form of respect, not suspicion. The CEO who insists on being called back, who treats the safe word as ordinary, who thanks the employee that paused a transfer to double-check, is the one setting a culture that holds up under attack.
In an era where AI can wear human skin, executive faces have become the raw material for sophisticated fraud.
Executives' faces are now raw material for stealing a company's money. It is no surprise that 72 percent of business leaders now rank AI-enabled fraud and deepfakes among their top operational challenges for the year.
What makes this dangerous is the gap between how fast the threat is moving and how slowly most companies are responding. Anti-fraud teams openly admit they are not yet equipped to detect or respond to these attacks, and the majority of organizations still have no formal protocol for handling a suspicious audio or video request. The criminals, meanwhile, have turned their craft into subscription services that anyone can rent. The attackers have industrialized. Most of their targets are still relying on the same instincts that failed the employee at Arup.
Developing a new discipline
"I'd recognize them anywhere" was a perfectly good security model for the era in which faces and voices were hard to fake. That era is over, and it is not coming back. The companies that come through this well will not be the ones with the cleverest detection software. They will be the ones with the discipline to retire a comfortable old instinct and put something verifiable in its place.
The technology that fakes a CEO or CFO is only going to get better. The good news, and there is some, is that the defense does not depend on out-teching the criminals. It depends on deciding, today, that voice and video requests will not be executed without some form of zero-trust verification.
Pfanner Advantage works with clients to turn change into advantage at the intersection of mobility, motorsport, media, technology, and marketing. Learn more or start a conversation: contact us today.
The Advantage Journal arrives every week. What matters in sport, mobility, media, and technology — curated and contextualized by Bill Sparks, Bill Long, and Paul Pfanner. No hedging. No filler. Subscribe — It’s Free
