Deepfakes and identity deception
Back to Blog
Detection Engineering

Deepfakes and Advanced Identity Deception

PublishedJune 2, 2026
Read time8 min read
Share
Originally reported viaFBI Internet Crime Report / KrebsOnSecurity

Business email compromise has been the highest-volume financial cybercrime for five consecutive years. In 2026, it has evolved: threat actors supplement email fraud with AI-generated voice calls and real-time video deepfakes to impersonate executives during finance team interactions.

How synthetic identity attacks are deployed

The most common pattern involves three stages: a phishing email establishing urgency around a confidential payment, a follow-up voice call from a cloned version of an executive's voice, and fraudulent wire instructions. In the most sophisticated cases, a real-time video deepfake replaces the voice call entirely.

Verification call won't save you
Finance teams trained to 'call back the executive' are not protected against voice cloning. If the attacker has a high-quality voice clone, the verification call is the attack. Verification must use a pre-established out-of-band channel.

Three detection engineering patterns

Pattern one: alert when an email uses a C-suite display name but originates from a non-DMARC-authorised domain. Pattern two: flag high-value wire requests initiated within 48 hours of an email thread containing executive names and urgency language. Pattern three: mandatory dual-authorisation via a pre-registered out-of-band number for transfers above a defined threshold.

  • Build an executive display-name watchlist in your SIEM and alert on any external email using those names from non-authorised domains.
  • Establish a pre-registered out-of-band verification channel for finance wire authorisation.
  • Conduct a finance team tabletop exercise simulating a deepfake CEO call.
  • Audit executives' publicly available voice and video content — earnings calls are training data for voice clones.
  • Implement a one-time verbal codeword system for high-value transfer authorisation calls.
Furix's Detection Library includes pre-built Sigma rules for executive impersonation email detection and finance-system correlation queries.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.