CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
digital-forensics

Deepfake Scam Losses Hit $410M: What Video Scam Calls Reveal

Deepfakes Just Stole $410M. Your "Media Literacy" Training Won't Save You.
A video call showing a fake CFO illustrates how a deepfake scam tricked an engineering firm into wiring $25 million.

An engineering firm wires $25 million to a fraudster after a video call. The "CFO" on screen looks right, sounds right, answers questions in real time. Every visual and audio signal that humans have evolved to trust, eye contact, vocal cadence, facial expression, is there. It's all fake. That's not a thought experiment. That's Arup, 2024, and it's the clearest possible signal that we've been having the wrong conversation about deepfakes for years.

TL;DR

Deepfakes have crossed from the misinformation beat into financial fraud, and the institutions still treating this as a media-literacy problem are leaving their authentication infrastructure wide open to attacks that are scaling fast.

The public narrative around deepfakes has been dominated, understandably, by non-consensual imagery, election interference, and celebrity exploitation. Real harms, all of them. But while policymakers were drafting content moderation guidelines, a separate and arguably more dangerous use case was quietly maturing: using synthetic media to defeat the identity verification systems that guard money, accounts, and executive decision-making. The fraud angle isn't a subplot. It's becoming the main event.


Deepfake Video Call Scams: How $410M Got Stolen

Here's a figure that deserves a moment of silence: deepfake-related fraud losses exceeded $410 million in the first half of 2025 alone, according to data compiled by Fourthline. Projections place annual losses at $40 billion by 2027. For context, that's roughly the GDP of Paraguay, evaporating into synthetic faces and cloned voices, year after year, if the trajectory holds.

CaraComp DailyEP.22
3 stories · 2:57
Starts at 00:21 — this story
2:57

Watch this story, in under a minute

Plays right here · jumps to 00:21
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube
700%
increase in deepfake incidents targeting the fintech sector in 2023 versus 2022, and the acceleration since then has outpaced detection capabilities
Source: Fourthline, Deepfakes in Financial Services 2026

Seven hundred percent. In a single year. And that's the 2023 figure, the 2024-to-2026 acceleration is moving faster than detection infrastructure can respond. The fintech sector didn't have a deepfake problem in 2021. Now it has an existential authentication problem, and most institutions are still running identity verification processes designed for a world where a face on a video call meant something.

Deepfake Phishing: The New Front Door for Fraud

Deepfake phishing is what happens when the old email scam gets a face and a voice. Instead of a suspicious link, the victim gets a video call or a voicemail that sounds exactly like a boss, a bank rep, or a family member asking for money or login details. Because the request arrives through a channel people have always trusted, a live voice, a live face, the usual "check the sender address" advice doesn't help, which is exactly why this variant of deepfake phishing is spreading faster than traditional email fraud.

Voice Cloning: Three Seconds Is All It Takes

Voice cloning tools no longer need a long recording to work. As the reporting above notes, three seconds of audio pulled from a podcast, a voicemail greeting, or a company all-hands meeting is enough to build a convincing clone. That means voice cloning has quietly become a background risk for anyone whose voice has ever been recorded and posted publicly, executives included.

Video Deepfakes on Live Calls

Video deepfakes used to mean an edited clip posted online after the fact. Now they run live, in real time, on ordinary video call software, answering questions and reacting to what's said, which is precisely what made the Arup video call scam work. Treating video deepfakes as a future problem rather than a live-call problem is the mistake that keeps costing companies money today.

Deepfake Schemes Are Getting More Organized

These aren't one-off pranks pulled by a lone hacker. The deepfake schemes behind the biggest losses involve planning, reconnaissance on a target company's org chart, and a script built to sound like a real urgent business request. Recognizing that these deepfake schemes are run like small operations, not stunts, changes how seriously a finance team should treat an unexpected urgent call.

Video Scam Calls: Why the Format Itself Is the Weapon

A video scam call works because it borrows the credibility of a format people already trust for high-stakes conversations. Nobody questions a scheduled video scam call the way they'd question an unexpected text asking for a wire transfer, and that gap in scrutiny is exactly what attackers are counting on. Treating any urgent, money-related video scam call as unverified by default, no matter how senior the face on screen appears, closes that gap without slowing down legitimate business.

Deepfake Scams: A Shared Anatomy Worth Learning

Across industries, deepfake scams follow a recognizable shape: a familiar face or voice, a request that can't wait, and a channel picked because it skips normal checks. Staff who learn to spot that shared anatomy in deepfake scams are better prepared than staff who only memorize the latest headline example, since the underlying playbook barely changes between incidents.

Voice fraud is accelerating on its own separate track. CybelAngel's analysis of CEO deepfake fraud draws on FBI data showing $893 million in losses tied to voice-cloning and business email compromise variants in 2025. The FBI has been warning about this for months. Meanwhile, Group-IB's breakdown of voice phishing attacks makes the operational reality painfully clear: a convincing voice clone requires as little as three seconds of source audio. Three seconds. Every earnings call, podcast appearance, conference keynote, and LinkedIn video your executives have ever recorded is raw training material for attackers who are paying attention. This article is part of a series, start with That 95 Face Match Scammers Built The Other 3 Layers To Fool.


How Deepfake Fraud Exploits Trust in Authority

The Arup case isn't just a story about sophisticated technology. It's a story about human psychology, specifically, the near-impossible position that finance staff are put in when the "CFO" calls with an urgent request.

"All requests involving fund transfers, sensitive data, or account access should be validated through at least two separate communication channels, for example, confirming a phone call via email or secure internal messaging." PwC, The Era of Deepfakes and Synthetic Identities

That's sensible advice. It's also, if you've ever worked inside a real organization, advice that collides head-on with corporate culture. The reluctance to delay or question a request from someone presenting as the CEO isn't irrationality, it's career risk calculation. Attackers know this. They specifically impersonate the highest-authority figures in the org chart because the power differential suppresses exactly the skepticism that would protect the target. The technology enables the deception; the org chart does the rest of the work.

January 2026 brought another instructive case: a deepfake executive impersonation scheme targeting a company connected to the Bombay Stock Exchange, detailed by CSO Online. This isn't a Silicon Valley problem or an American problem. It's a global authentication problem, and it will reach every institution that has executives with a public profile and staff conditioned to defer to authority.

Why This Matters Right Now

  • Detection is always reactiveAI-based deepfake detection achieves up to 90% accuracy in controlled lab conditions, but drops 40-50% when real-world compression and background noise enter the picture. By the time a flag triggers, the wire has often cleared.
  • 📊 Onboarding is now a fraud surfaceSynthetic identities created with deepfake photo and video generation are defeating KYC flows at scale, meaning fraudsters aren't just impersonating real people, they're creating entirely fictional ones that pass verification.
  • 🎙️ Voice is the least protected channelMost organizations have no liveness detection or voice-clone screening on phone-based authorization flows, which is exactly why attackers have migrated there from more protected email and document channels.
  • 🔮 The regulatory gap is closing, but slowlyThe American Bankers Association published a 20-point action plan for fighting AI identity attacks in early 2026, per Help Net Security. Twenty points is a lot of points. Fraudsters are not waiting for point twenty.

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The Epistemological Problem Nobody Wants to Admit

Here's the shift that keeps security professionals up at night, and should keep the rest of us a little unsettled too. This isn't fundamentally a technology problem, it's an epistemological one. The question "how do we know this is real?" has been answered, for most of human history, through a combination of sensory experience and institutional trust. You saw the person. You heard the voice. You read the document with the letterhead.

All three of those signals are now forgeable at scale, at low cost, with tools that require no advanced technical knowledge to operate. Keepnet Labs' 2026 deepfake statistics report is blunt about the operational implication: approval workflows must now be designed around the assumption that a convincing face or voice can be faked. Not "might be faked in rare circumstances." Can be faked, routinely, by motivated attackers operating at commercial scale. Previously in this series: Flagged By A Face Innocent Shoppers Banned With No Way To Fi.

That's a genuinely destabilizing premise for institutions built on the idea that identity is something you can verify by looking at someone. And it creates a real opening, not just for fraud, but for investigators, compliance professionals, and security teams who understand how to cross-reference behavioral patterns, metadata, and contextual signals across fragmented data sources when the primary identity signal can no longer be trusted alone. Facial comparison tools, behavioral analysis, and cross-platform verification aren't optional add-ons for high-stakes cases anymore. They're the infrastructure that fills the gap left by the collapse of surface-level identity signals. That's the role CaraComp was built for, and it's a role that's becoming more critical every quarter.

The investigators and security teams who will actually matter in this environment are not the ones asking "does this face look real?" They're the ones asking: does this behavioral pattern match? Does the metadata corroborate the claim? Is there a second-channel confirmation that exists independently of the channel being spoofed? Those are forensic questions, not media-literacy questions.


Stop Treating This as a Comms Problem

The framing that frustrates me most is the one where deepfakes remain primarily a "misinformation" issue, something for trust-and-safety teams, fact-checkers, and media-literacy educators to handle. That framing made sense in 2020. In 2026, it's a liability.

When your authentication infrastructure assumes that a live video is evidence of a live person, and your wire transfer authorization process assumes that a voice on a call is who it claims to be, you don't have a misinformation problem. You have an open door. Calling it a media-literacy issue is like responding to a bank robbery by recommending that tellers attend a seminar on spotting counterfeit bills, technically related, completely insufficient.

The institutions moving fastest on this are reframing it correctly: as an authentication failure risk, a payments security risk, and an identity infrastructure risk. That means new verification protocols, multi-channel confirmation requirements, continuous behavioral monitoring rather than point-in-time identity checks, and, critically, shorter incident response timelines so that fraudulent transactions can be flagged before settlement rather than after. Up next: Retail Facial Recognition Watchlists No Appeals Process.

Key Takeaway

The institutions still framing deepfakes as a content moderation problem are already behind. This is an authentication infrastructure failure, and the financial losses are the proof. Every verification workflow that treats a face, voice, or video as primary evidence needs to be rebuilt around the assumption that all three can be faked convincingly, on demand, by attackers with modest resources and clear financial motivation.

Look, nobody's saying this is simple. Rebuilding organizational trust in identity verification when the underlying signals are compromised is genuinely hard, and there's no single technology that solves it. Detection systems help but lag. Behavioral analytics add friction. Multi-channel confirmation creates bottlenecks that real executives resent. These are real tradeoffs, and the people managing them deserve more than a 20-point action plan and a media-literacy course.

But the conversation has to start in the right place. And right now, in too many boardrooms and compliance departments, it doesn't.

So here's the question worth sitting with: if a Arup-level firm, global, sophisticated, well-resourced, can lose $25 million to a deepfake video call, and the people on that call were not stupid or careless, just human, what exactly does "proof of identity" mean in a high-stakes financial decision? And more pressingly: what does your organization's answer to that question actually look like in practice, right now, today? Not in the roadmap. Not in the policy document. In the next wire transfer authorization that hits your finance team's inbox at 4:45 on a Friday afternoon.

A deepfake scam rarely announces itself as a scam. It arrives dressed as routine business: a video call, a voicemail, a chat message from someone who already has your trust. That disguise is precisely why a deepfake scam succeeds where a clumsier fraud attempt would get flagged in seconds, and it's why awareness of the pattern matters more than awareness of any single technology.

Every deepfake scam shares a common structure once you strip away the specific technology used. There's a trusted identity being impersonated, a request that requires urgency to work, and a channel chosen because it short-circuits the normal verification steps. Understanding that structure is more useful than trying to memorize every new deepfake scam variant as it appears, because the underlying scam logic barely changes even as the tools improve.

Financial institutions are starting to build fraud controls specifically around the deepfake scam pattern rather than treating each incident as a one-off. That includes flagging unusual urgency in a payment request, requiring a second channel of confirmation for anything above a set dollar threshold, and training staff to recognize that a scam video call can look flawless and still be fake. None of these controls require exotic technology, they require treating a video or voice request the same way a suspicious email has been treated for the past decade.

A scam deepfake used against a company rarely targets the CEO directly. It targets whoever has the authority to move money or grant access but is junior enough to feel unable to question a senior-sounding request. That's why training has to reach beyond the executive suite and into finance, HR, and IT support desks, where a scam deepfake call is more likely to land and less likely to be challenged.

Fraud deepfake incidents are increasingly bundled with other social engineering steps rather than used alone. An attacker might first send a phishing email to gather context, then follow up with a fraud deepfake voice call that references details from that email to sound credible. Layering the attack this way makes each individual step look more plausible, which is exactly why single-channel verification keeps failing against it.

Deepfake technology itself is not the villain of this story; it's a tool with legitimate uses in film, accessibility, and entertainment. The problem is that deepfake technology has become cheap and accessible enough that the same tools used for legitimate dubbing or animation can be repurposed for fraud with almost no technical barrier to entry.

Every organization now faces some version of a deepfake threat, whether or not it has been targeted yet. The size of a company doesn't determine whether it faces a deepfake threat, its visibility does, since attackers need public audio and video of an executive to build a convincing fake in the first place.

Basic awareness training remains one of the cheapest defenses available, even against a threat this sophisticated. Awareness alone won't stop every attempt, but a staff member who has simply heard that a video call can be faked is far more likely to pause and verify than one who assumes seeing is still believing.

Security teams that used to focus on network intrusion and malware are now being asked to own identity-based fraud as well, and that shift in scope is still catching up in a lot of budgets. Building security around the assumption that a face or voice can be faked means investing in second-channel verification tools, not just better detection software, since detection alone will always lag the newest fraud technique.

None of this means every video call should be treated with suspicion. It means the highest-stakes requests, the ones involving money, credentials, or access, deserve a verification step that doesn't rely solely on how convincing the person on screen sounds.

Security teams that treat customer-facing channels as a single unit miss how differently fraud moves through each one. Account takeover attempts, image-based verification checks, and social engineering calls all exploit trust in slightly different ways, so security controls built for one rarely transfer cleanly to another. A customer support line and a customer onboarding flow face different flavors of the same underlying problem, and both need protection that accounts for a convincing fake face or voice.

Phishing remains the quiet workhorse behind many of these schemes, even when a deepfake gets the headline. A phishing message that harvests a password or a security answer often supplies the exact detail a fraudster needs to make a later deepfake scams call sound credible, which is why phishing defenses and deepfake defenses can't be built as separate projects.

Social engineering tactics that predate deepfakes, urgency, authority, and isolation from a second opinion, still do most of the work in a deepfake scams incident. The synthetic video or voice removes the one signal, a mismatched face or voice, that used to give social engineering away, but it doesn't replace the pressure tactics underneath it.

Protection against this category of fraud has to start with process, not software. A verification protection step as simple as calling a known number back, rather than trusting the number or face that just appeared on screen, blocks a large share of deepfake scam attempts before they reach a decision point.

Fraudsters running deepfakes fraudsters schemes rely on speed as much as they rely on the fake itself. Slowing a request down by even a few minutes, long enough to confirm it through a second channel, often breaks the attack, because deepfakes fraudsters count on nobody pausing to check.

Voice spoofing deserves its own line item in a company's fraud training, separate from video. A voice spoofing attempt over a phone call can be even harder to catch than a video scam, since there's no face to compare and no visual artifact to notice, only a voice that sounds exactly like someone the listener already trusts.

Frequently asked questions

What is a deepfake scam?

A deepfake scam uses synthetic video or audio to impersonate a real person, such as a company executive, convincingly enough to trick someone into acting on false instructions. In one case, an engineering firm wired $25 million after a video call with a fake CFO whose face, voice, and real-time responses appeared completely genuine, despite being entirely fabricated.

How much money has been lost to deepfake scams?

Deepfake-related fraud losses exceeded $410 million in just the first half of 2025, according to data compiled by Fourthline. Projections suggest annual losses could reach $40 billion by 2027, an amount comparable to the entire GDP of Paraguay, disappearing into fraudulent synthetic identities each year if current trends continue.

Why are deepfake scams hard to stop?

Deepfake scams exploit the exact signals humans and systems rely on to verify identity, like eye contact, vocal cadence, and facial expression, all of which can now be convincingly faked in real time. Treating this purely as a media-literacy or communications issue leaves authentication infrastructure exposed, since the real vulnerability lies in identity verification systems, not public awareness alone.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search