CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
digital-forensicsBy Cara Candelario

Deepfake Phishing: Compromised Libraries, Breached 2FA, Video Fraud Playbook

Deepfakes Will Drive Most ID Fraud by 2026 — Most Fraud Teams Aren't Ready
A video call illustrating deepfake phishing, where AI-generated faces and voices deceive victims into bypassing security safeguards.

Quick answer

What is deepfake phishing and how does it get past security?

Deepfake phishing is a scam that uses fake AI-generated video or voice, rather than a forged email address, to impersonate someone the victim trusts. Because it targets a person's judgment instead of a link or a password, email filters and two-factor authentication often do not stop it. Checking requests through a separate channel helps.

A software developer didn't click a suspicious link. He didn't fall for a phishing email with a typo in the domain. He sat down for a virtual meeting with people he recognized, faces he knew, voices that sounded right, and got completely owned. The result? A JavaScript library downloaded 100 million times per week was compromised. The attackers were North Korean operatives. The method was an AI deepfake convincing enough to pass real-time human judgment, even with two-factor authentication enabled on the account.

TL;DR

Deepfake-driven social engineering already works at a professional level, fraud teams are almost entirely unprepared for it, and by 2026 every serious investigator who hasn't built deepfake-aware workflows will be systematically outmaneuvered.

That incident, reported by PCMag via Yahoo Finance and now being studied by security teams across the industry, is the clearest possible signal that we have crossed a threshold. The question is no longer whether deepfakes can fool people. They already do, routinely, at scale. The question is whether investigators, fraud analysts, and verification professionals are willing to accept that their current process is broken before a $25 million wire transfer makes the point for them.

My prediction: by the end of Q2 2026, deepfake-driven cases won't be an edge category in fraud investigation, they'll be the dominant starting point. And the teams that haven't formally rebuilt their verification workflows around synthetic identity detection will be the ones writing incident reports they can't explain.


The Numbers Are Not Subtle

Deepfake Phishing and the Phishing Attacks Hiding Behind Video

Deepfake phishing is now a distinct category of phishing attacks, separate from the old email-with-a-bad-link model. A deepfake phishing attempt uses synthetic video or synthetic voice instead of a forged sender address, which is exactly why deepfake phishing slips past filters built to catch traditional phishing. Security teams that still measure phishing risk by counting suspicious email volume are missing the deepfake phishing cases entirely.

Let's start with where we actually are, because a lot of people are still treating this as a theoretical problem. This article is part of a series, start with Deepfakes Investigators Workflow Classmates Elections Fraud.

7%
of anti-fraud professionals say their organizations are firmly prepared to detect AI-fueled fraud, even as deepfake social engineering cases surged 77%
Source: ACFE/SAS 2026 Anti-Fraud Technology Benchmarking Report via PRNewswire

The volume tells a similar story. Fortune's AI research forecast puts the number of deepfakes online at roughly 8 million in 2025, up from approximately 500,000 in 2023. That's not growth, that's detonation. Voice cloning, according to the same research, has "crossed the indistinguishable threshold," meaning a few seconds of audio now generates convincing synthetic speech complete with natural intonation, rhythm, and even breathing patterns. The BBB has already issued warnings about scammers using voice clones to impersonate family members in distress calls. Deepfake health ads are targeting people mid-Google-search for medical conditions. These aren't isolated incidents. This is an industrial production pipeline being aimed at human trust.

Financial damage? Keepnet Labs' 2026 deepfake statistics analysis puts US deepfake fraud losses at $1.1 billion in 2025, triple the $360 million recorded the prior year. Globally, losses from deepfake-enabled fraud topped $200 million in Q1 2025 alone. And the human detection rate for high-quality video deepfakes? A humbling 24.5%. You're essentially flipping a coin, then flipping it again, and still getting it wrong.


Deepfake Phishing Attacks: The Axios Case and Beyond

Voice Cloning, Deepfake Detection, and Why Phishing Voice Scams Work

A voice-phishing scam built on voice cloning does not need a long call to succeed, a few seconds of real audio is enough to build a convincing phishing voice. Deepfake detection tools exist, but most organizations have not deployed them at the point where a call actually happens, which means the deepfake threat lands before any detection layer even gets a chance to look at it. Voice phishing and deepfake phishing now overlap so much that treating them as separate training topics leaves employees only half prepared.

Here's what makes the Axios/npm developer case so instructive: the attacker didn't compromise a system. They compromised a person. The developer saw familiar faces on a video call. He heard familiar voices. Nothing in the interaction triggered suspicion because the AI generation was high-fidelity, real-time, and sustained throughout a live conversation. Two-factor authentication was enabled. It didn't matter. Both factors were rendered irrelevant the moment the human decision point was corrupted.

"The attackers targeted the top 50 npm packages, understanding how modern supply chains work; gatekeepers like Axios maintainers have no security team, corporate backing, or deepfake detection tools." WebProNews, technical analysis of the npm deepfake campaign

Swap "npm maintainer" for "solo PI" or "small fraud unit" and you have an exact description of most investigators right now: capable professionals operating without any institutional support for detecting synthetic identity attacks. The attacker's strategy was to find the undefended gatekeepers, people with real authority and real access, but no detection infrastructure. Sound familiar? Previously in this series: Synthetic Identity Fraud Now Drives Most Id Scams Why Facial.

The Institute for Financial Integrity's case study on the Arup fraud adds a grimmer dimension. In that incident, a $25 million loss, the target joined what appeared to be a routine video conference with colleagues. Every person on that call was an AI-generated deepfake. The attacker had pre-downloaded videos of real Arup employees and used them to generate synthetic personas with matching voices. The target recognized every face on the screen. That recognition itself became the attack surface.

This is the core problem. Traditional fraud defense is built around testing whether something is wrong. Deepfake social engineering inverts that, it's built around looking right. Visual familiarity, voice cadence, contextual plausibility. None of our existing instincts are calibrated for this.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Deepfake Fraud Defense: Building Awareness in Practice

Phishing Attacks, Human Risk, and the Platform Gap

Most phishing attacks still get budgeted like an email problem, but a malicious actor leverages deep learning technology the same way a large-scale social engineering campaign leverages a phone tree, at volume, and aimed at the weakest human link. Deepfakes aid cyber criminals precisely because they turn a highly deceptive cyberattack into something that feels like an ordinary meeting. Reducing human risk means giving every employee a documented request-verification step, plus a platform that logs how a request came in, not just what the request said.

Let's get concrete, because the solution isn't just "be more suspicious." Suspicion doesn't scale, and it burns out investigators who apply it uniformly. What actually changes the equation is workflow, documented, repeatable process that doesn't rely on gut feel.

Three Shifts Investigators Need to Make Right Now

  • ⚡ Treat video and voice as evidence, not verificationA face on a video call or a voice message is no longer a confirmation of identity. It's a data point that needs corroboration from a known-good source image or separate out-of-band channel before it can carry evidentiary weight.
  • 📊 Build facial comparison into baseline intakeWhen a case involves any visual identity claim, photos, video, profile images, comparison against verified source images needs to become standard, not optional. The question isn't "does this look like the person?" It's "does this mathematically match a known-good reference?"
  • 🔮 Document your deepfake posture before the incident, not afterAccording to 2026 social engineering research from ECCU, 80% of companies have no established protocols or response plans for deepfake-based attacks. If you're in that 80%, the liability exposure in a missed synthetic-identity case is significant, and it's coming.

The practical implication for investigators doing facial comparison work is straightforward: source image verification has to be part of the chain of custody. If you're working from a provided photo of a subject and can't establish that image as unmanipulated and current, you're potentially comparing against a synthetic generation. That's not paranoia, that's just accounting for where AI image generation has landed technically in 2025. Up next: 347 Deepfakes Of 60 Classmates Got 60 Hours Of Community Ser.

Platforms built for facial comparison in investigative contexts already operate on this principle. The math either matches or it doesn't, independent of how convincing the face looks to a human reviewer. That gap, between what looks right to a person and what is verifiably right against a reference, is exactly the gap deepfakes exploit, and exactly where documented verification workflows close it.

"55% of fraud professionals expect deepfake social engineering to increase significantly over the next 24 months, yet 80% of companies have no established protocols or response plans for handling deepfake-based attacks." ACFE/SAS 2026 Anti-Fraud Technology Benchmarking Report, via PRNewswire

The FOMO Is Justified

Here's the professional reality: the investigators and fraud teams who build deepfake-aware workflows first don't just protect themselves from liability. They become the most credible experts in the room when enforcement finally catches up to the problem, and it will. Regulators move slowly, but the Arup fraud, the Axios compromise, and the wave of AI voice scams hitting elderly targets (reported by Korean outlet Chosun as a specific demographic pattern) are creating political pressure for mandatory standards. When those standards arrive, the teams already operating with documented synthetic-identity protocols will be positioned as the qualified practitioners. Everyone else will be scrambling to retrofit.

That's not speculation. That's exactly how biometric verification standards evolved after the first wave of identity document fraud, the shops with documented chain of custody ended up setting the industry benchmark by default, because they were the only ones who could demonstrate process.

Key Takeaway

By 2026, the central vulnerability in most fraud cases won't be a stolen password or a forged document, it'll be a face or a voice that looked and sounded right. Investigators without a documented process for testing that assumption against verified source images won't be behind for long; they'll be the ones explaining to clients, regulators, and courts why they trusted appearances in a world where appearances are the easiest thing to fake.

Deepfake phishing training now needs to sit alongside standard security awareness training, not replace it. A short training module that shows employees a real deepfake phishing video, then walks through the request-verification step, does more for human risk reduction than a long slide deck about email hygiene. Security leaders should treat this training as recurring, since deepfake phishing techniques change every few months as the underlying video generation tools improve.

Practically, every request for money, credentials, or access that arrives by video or voice should trigger a second, separate confirmation request through a channel the requester did not initiate. This single habit closes most of the deepfake phishing gap without requiring new software, because it forces the request back into a channel a deepfake cannot yet hijack in real time. Email remains a useful backstop here: an out-of-band email confirmation to a known address is still one of the fastest ways to catch a deepfake phishing attempt before money moves.

Security teams evaluating platform options for deepfake detection should ask vendors directly whether the platform screens video and voice in real time or only after the fact. A platform that only flags deepfake phishing content after a meeting has ended provides forensic value but no protection at the moment the employee is actually being asked to act. Both capabilities matter, but they solve different problems, and budget conversations should separate them clearly.

The threat landscape around deepfake phishing is shifting faster than most internal risk registers get updated. A threat that was theoretical a year ago, a fully synthetic video meeting used to authorize a wire transfer, is now a documented cause of a nine-figure loss. Any organization still listing "phishing" as a single line item on its risk register is underestimating how much of that risk now comes specifically from deepfake phishing rather than email.

Signals that a video or voice interaction might be a deepfake phishing attempt tend to cluster around behavior rather than appearance: unusual urgency, a refusal to switch channels, or a request that conveniently avoids any step that would require live, unscripted interaction. Training employees to notice these behavior patterns, rather than staring at pixels for visual glitches, tends to catch more real cases, since detection software already outperforms the human eye at spotting rendering artifacts. Human judgment is still valuable, but it should be aimed at behavior and process gaps, not at trying to eyeball whether a face is real.

None of this requires a large security budget to start. A written policy that names deepfake phishing specifically, a short training session, and one mandatory out-of-band confirmation step for financial and credential requests covers most of the practical ground. Organizations that treat this as a security policy update rather than a technology purchase tend to move faster, because the human risk reduction comes from the process change, not from any single piece of software.

Frequently asked questions

What is deepfake phishing?

Deepfake phishing is a distinct category of phishing attack that uses synthetic video or synthetic voice instead of a forged sender address, allowing it to slip past filters built to catch traditional email-based phishing. It works by corrupting human judgment directly, using AI-generated faces and voices that appear familiar, rather than tricking someone into clicking a malicious link.

Can two-factor authentication stop deepfake phishing?

No. In the npm developer case described, two-factor authentication was enabled on the account, but it made no difference because the attack corrupted the human decision point during a live video call using real-time AI-generated faces and voices. Both authentication factors became irrelevant once the person believed they were talking to colleagues they recognized.

How good are people at detecting deepfakes in phishing scams?

Not good. The human detection rate for high-quality video deepfakes is only 24.5 percent, roughly worse than a coin flip. This is why deepfake phishing succeeds even against experienced professionals, as seen in cases like the Arup fraud, where the target recognized every face on a video call, yet every person on it was an AI-generated synthetic persona.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search