"Deepfake video conference fraud" refers to a scam in which a fake executive—often a CFO or CEO—appears in a video conference to get a wire transfer approved. The risk is no longer theoretical: verified cases have already cost tens of millions. For an SME, the best defense isn’t a miracle tool, but a simple procedure: an independent follow-up call, double verification, and payment limits.
Deepfake Video Conference Fraud: What Has Changed
CEO fraud has been around for a long time. As early as 2019, INTERPOL described it as a form of social engineering—that is, psychological manipulation aimed at tricking an employee into transferring money. What’s new is that the fraudulent email no longer comes alone: it can be reinforced by a cloned voice, a synthetic face, and a credible video conference.
The most frequently cited case remains the one uncovered by the Hong Kong police in February 2024. An employee of a multinational corporation participated in a video conference that included a fake chief financial officer and other fake participants. The result: 15 wire transfers to five local bank accounts, totaling 200 million Hong Kong dollars, or approximately 25.6 million U.S. dollars.
In May 2024, Arup confirmed that it was the company involved in this fraud, while noting that the incident had not affected its financial stability or operations. That detail matters. Large companies can sometimes weather the blow. An SME, on the other hand, can lose its cash reserves, miss a payroll, or put an investment on hold in a matter of hours.
The FBI classifies this type of attack as Business Email Compromise, or BEC: scams in which the identity of a company or executive is impersonated to request a wire transfer. In September 2024, the IC3, the FBI’s reporting center, reported more than $55.4 billion in reported losses related to BEC worldwide. Video, therefore, does not replace the classic scam; it simply makes it more convincing.
Why Videoconferencing Makes the Scam Seem More Credible
A video call instills a sense of trust. We see a face, hear a voice, recognize a decision, and sometimes even a particular intonation. Many executives have learned to be wary of a suspicious email; far fewer are wary of an order given via video call by someone who looks like the group’s CEO.
Generative artificial intelligence tools now make it possible to create or alter images, voices, and computations. The CNIL refers to this as “hyper-faking”: the reproduction of a face, a voice, or a mannerism to impersonate someone. The danger is not merely technical. It stems primarily from the context: urgency, confidentiality, and hierarchical authority.
A typical scenario can be summarized in just a few lines. A finance executive receives a preliminary message, often from an address similar to the original one or from a compromised account. They are asked to join a Zoom, Microsoft Teams, or Google Meet meeting. An impostor posing as a company executive explains that an acquisition, a legal dispute, or a sensitive transaction requires an immediate wire transfer.
In the projects we manage, we often see the same perspective from SMEs: security is viewed as a technical issue, while CEO fraud is generally considered an organizational issue. Even with a well-secured website, protected email, and strong authentication, an employee may give in if the payment process depends on a single person under pressure. For similar application-related risks, the same control logic applies on the technical side, particularly in the Securing Exposed APIs.
How can you spot a deepfake during a video call?
Let’s be honest: asking an employee to “spot” a deepfake with the naked eye isn’t enough. Visual flaws do exist, but they vary depending on connection quality, video compression, and lighting. A face that barely blinks doesn’t prove anything. Neither does a frozen image.
However, certain red flags should raise concerns. An unusual request for a wire transfer, a refusal to use the usual methods, an insistence on secrecy, or a sudden inability to reach the person at their known number are more reliable indicators than facial recognition. The best indicator is often a deviation from standard procedure.
- The meeting is organized from an unknown account or via a link received through the usual channel.
- The executive refuses to return a call to the number already listed in the internal directory.
- The request porte refers to an unusual amount, beneficiary, or country.
- Validation must be done “right away,” and you are not allowed to discuss it with the team.
- The voice or the responses seem slightly out of sync, especially when answering specific questions.
In 2026, La Banque Postale cited a case described by the DGSI: the manager of a French industrial site reportedly received a video call from someone posing as the group’s CEO, an attempt that was later identified as a deepfake CEO fraud. This type of case shows that the target is not limited to the finance department. A site manager, office manager, or executive assistant can become the point of entry.
How can you protect yourself from CEO fraud?
The most effective rule is simple: any unusual request for money or sensitive information should be verified through another channel. The CNIL recommends making a direct call or sending a separate message in 2026. The FBI also advises confirming transfer requests by phone, using a number you already know—never the number provided in the request.
This detail may seem like a mere formality, but it’s crucial. If the scammer gives you a number to call back, they’re also in control of the verification process. Given this budget, it’s better to invest in a written procedure and a brief training session than in expensive software that no one will use when an emergency arises.
An SME can implement a defense strategy in just a few weeks. There’s no need to turn the company into a fortress. The key is to make it impossible for a single person to authorize a transfer after a single interaction through a single channel.
| Measurement | Realistic timeline | Indicative cost in France | Main profit |
|---|---|---|---|
| Procedure for Calling Back a Known Number | 1 to 3 days | Internal time | Blocks the priority status of urgent fraudulent requests |
| Double Verification of Sensitive Transfers | 1 to 2 weeks | Internal time, sometimes bank settings | Reduces the risk of unilateral decision-making |
| Short-term training in finance, management, and administrative support | 2 to 4 weeks | Approximately €800 to €3,000, depending on the service provider and the number of employees | Build the right habits for dealing with pressure |
| forte Authentication for Email and Tools | 1 to 3 weeks | Includes Microsoft 365/Google Workspace or a project costing around 1,000 to 5,000 € | Minimizes the risk of internal accounts being compromised |
| Stress Test or BEC Simulation | 3 to 6 weeks | Around €2,000 to €8,000 for an SME | Verify that the procedure works in a real-world scenario |
Passwords remain a weak point, especially when email is used to set up a scam. The passkeys, or passwordless access keys, are becoming relevant for certain types of sensitive access; they replace a memorized secret with cryptographic proof. To understand the trade-offs, you can read this guide on Passkeys for a website, because the logic is the same: to reduce the amount of items that can be stolen or reused.
Honestly, an automated deepfake detection tool is only justified if your risk exposure is high: highly visible executives, frequent international wire transfers, geographically dispersed teams, or confidential operations. For a typical small or medium-sized business, the priority lies elsewhere: banking rights, two-factor authentication, decision logging, and targeted awareness campaigns.
Budget, timelines, and trade-offs for an SMB
The first decision is not to treat all employees the same way. Training 120 people using the same generic module is costly and dilutes the message. It’s better to start with the people who can initiate, approve, or influence a payment: management, finance, purchasing, administrative staff, and site managers.
A thorough assessment often takes anywhere from half a day to two days: mapping payment flows, identifying the bank accounts used, listing recurring exceptions, and verifying who can approve what. After that, the rules should be concise. Three pages that no one reads. An operational checklist—displayed and integrated into the banking process—works better.
From the agency’s perspective, the natural instinct is to integrate this process with existing tools rather than adding another layer of abstraction. Internal directory, Microsoft 365 or Google Workspace email, SSO (single sign-on), access rights management, and audit trail retention: all of these must tell the same story. In a mobile application profession, for example, the Pre-publication security checklist already helps in planning for validation and sensitive access.
The trap that non-technical people often fall into: the attack doesn’t necessarily start with the video. It sometimes begins weeks earlier, with surveillance. LinkedIn provides organizational charts, press releases reveal acquisitions, email signatures reveal direct phone numbers, and a compromised email account reveals the exact tone of internal communications.
Useful technology, but cumbersome procedures
Technical solutions have their place. Cloudflare can reduce certain risks associated with web access; Microsoft Entra ID and Google Workspace allow for the enforcement of multi-factor authentication; and banks offer work validation workflows. But no technology should autorize a verbal exception dictated during a video conference.
A robust security architecture supports the process; it does not replace it. Login logs, alerts for unusual logins, geographic restrictions, and FIDO2 security keys provide early warning signs of fraud. If your digital project includes extranets, customer portals, or internal applications, strong authentication must be considered from the design phase—not added after an incident occurs.
Visit RGPD This issue also remains relevant. A deepfake can be used to obtain personal data: employee lists, bank account information, copies of identification documents, and customer files. As soon as a data breach involves personal data, the company must assess the risk and, depending on the circumstances, notify the CNIL within the timeframes set forth in the European regulation that has been in effect since 2018.
Finally, keep track of any rejections. If an employee stops a suspicious transfer, it’s not an excess of caution—it’s an achievement worth recognizing. Organizations that penalize delays unwittingly create the perfect conditions for rapid fraud.
What should you do after a fraudulent attempt or transfer?
You must act immediately. Notify the bank, request that the funds be frozen or recalled, and keep all available evidence: meeting invitations, emails, screenshots, caller IDs, dates and times, and IP addresses if available. Every hour counts.
Next, avoid cleaning up too quickly. Deleting messages or resetting all accounts haphazardly can destroy useful evidence. A cybersecurity provider or your IT team should first isolate the suspicious accounts, check the automatic forwarding rules in your email system, and look for other unauthorized connections.
A complaint must be filed, and the matter must be reported to the appropriate authorities. Companies working with international partners must also notify the beneficiaries and corresponding banks. At the same time, they should communicate internally without causing undue alarm: remind staff of the procedure, explain the situation, and make it clear that a deliberate slowdown is expected in cases of doubt.
Identifying this type of risk early on helps avoid most unpleasant surprises. An outside perspective often helps translate a vague concern into concrete guidelines that are compatible with your payment terms, your tools, and your decision-making culture.
FAQ on Deepfakes in Videoconferencing and Fraud
Can a deepfake during a video conference happen in real time?
Yes. Current technology already makes it possible to alter a person’s voice or appearance during a video call, though the quality varies depending on the tools and the connection. It is therefore important to verify the person’s identity, not just the image.
What is the first step in combating fraud against the president?
Verifying a number you already know is the simplest and most effective measure. This should be required for any unusual transfer, even if the request appears to come from a senior executive.
Should you buy deepfake detection software?
Not as a first step. For most small and medium-sized businesses, two-factor authentication, banking limits, and targeted forte and formation authentication offer a better cost-benefit ratio.
Which services are most at risk?
Finance, management, procurement, administrative staff, and operational managers with the authority to approve expenses are the primary targets. Attackers are looking for someone who can act quickly, not necessarily the person in the highest position.