Deepfakes and Advanced Identity Deception
Originally reported viaFBI Internet Crime Report / KrebsOnSecurityBusiness email compromise has been the highest-volume financial cybercrime for five consecutive years. In 2026, it has evolved: threat actors supplement email fraud with AI-generated voice calls and real-time video deepfakes to impersonate executives during finance team interactions.
How synthetic identity attacks are deployed
The most common pattern involves three stages: a phishing email establishing urgency around a confidential payment, a follow-up voice call from a cloned version of an executive's voice, and fraudulent wire instructions. In the most sophisticated cases, a real-time video deepfake replaces the voice call entirely.
Three detection engineering patterns
Pattern one: alert when an email uses a C-suite display name but originates from a non-DMARC-authorised domain. Pattern two: flag high-value wire requests initiated within 48 hours of an email thread containing executive names and urgency language. Pattern three: mandatory dual-authorisation via a pre-registered out-of-band number for transfers above a defined threshold.
- Build an executive display-name watchlist in your SIEM and alert on any external email using those names from non-authorised domains.
- Establish a pre-registered out-of-band verification channel for finance wire authorisation.
- Conduct a finance team tabletop exercise simulating a deepfake CEO call.
- Audit executives' publicly available voice and video content — earnings calls are training data for voice clones.
- Implement a one-time verbal codeword system for high-value transfer authorisation calls.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.