AI Deepfakes Have Broken Trust: Why an Old-Fashioned Security Trick May Be Your Best Defense + Video

Listen to this Post

Featured Image

The Moment Seeing Is No Longer Believing

For decades, corporate security depended on a deceptively simple assumption: if you could see and hear someone, you could reasonably trust that the person was who they claimed to be.

That assumption is now collapsing.

Generative AI has transformed voice cloning, video manipulation, and digital impersonation from experimental technologies into practical weapons. Attackers can reproduce a person’s appearance, voice, mannerisms, and communication style well enough to deceive employees who may have worked with that person for years.

The frightening part is not simply that deepfakes are becoming better. It is that human perception itself is becoming an unreliable security control.

A corporate employee receiving an urgent request from a familiar executive can no longer safely depend on a recognizable face or familiar voice. The question is no longer, “Does this person look real?” It is, “What independent evidence proves that this person is real?”

That distinction could determine whether a company protects millions of dollars or transfers them directly into an attacker’s account.

The $25 Million Warning

One of the most striking examples occurred in January 2024, when an employee at professional services company Arup was reportedly deceived during a video conference.

The employee believed they were speaking with the company’s chief financial officer and other colleagues. In reality, the people appearing on the call had been recreated using AI-generated digital identities.

The result was devastating: 15 transfers totaling approximately $25 million were sent to third-party accounts.

The incident illustrates a fundamental change in cybercrime.

The attacker did not necessarily need to break through a firewall. They did not have to exploit a software vulnerability. They attacked something much older and more difficult to patch: human trust.

The Face and Voice Are No Longer Credentials

Traditionally, video calls provided a sense of authentication.

An employee could recognize a

That model worked when reproducing

AI has changed the economics.

Today, publicly available interviews, conference appearances, podcasts, earnings calls, social-media videos, photographs, and recorded presentations can provide attackers with enormous amounts of material from which to construct convincing impersonations.

A person may unknowingly provide the raw material for their own digital clone simply by doing their job publicly.

The Old Deepfake Tells Are Disappearing

Early deepfakes often contained obvious imperfections.

A voice might sound robotic. Lip movements could appear slightly disconnected. Facial expressions could be unnatural. Background sounds might behave strangely.

Those signals were useful because they gave people something tangible to look for.

But technology has moved quickly.

Modern synthetic media can eliminate many of those obvious imperfections, while real-time generation makes the attack much more dangerous. The attacker no longer needs to send a suspicious video file. They can potentially participate in a live conversation and respond dynamically.

That makes traditional employee training based around “spot the fake” increasingly fragile.

Human Detection Is Not a Security System

Research cited in the original report reinforces the problem.

A University College London study found that people correctly identified deepfake audio only around 73% of the time, with training producing only a modest improvement. Other research aggregating dozens of studies suggested that human performance can approach chance under certain conditions.

The exact percentages matter less than the broader lesson.

A security system that depends on employees consistently winning a psychological guessing game against increasingly sophisticated AI is not a reliable security system.

Employees can still use suspicious behavior as a warning signal. They should absolutely question unusual requests.

But suspicion should trigger another authentication process, not become the authentication process itself.

Detection Technology Has Its Own Limits

It is tempting to assume that AI can simply fight AI.

If artificial intelligence creates a deepfake, perhaps another AI system can analyze the video or audio and identify the manipulation.

Unfortunately, this is not a guaranteed solution.

Detection systems generally look for statistical or technical characteristics associated with manipulated content. As generation techniques improve, however, those characteristics can become less obvious or disappear altogether.

This creates an uncomfortable technological race.

One side generates increasingly realistic synthetic media.

The other side attempts to identify it.

There is no guarantee that the detector will remain ahead.

The Bigger Threat Is Longer-Term Infiltration

Financial fraud is only one part of the problem.

Deepfake-enabled social engineering can also become an entry point for prolonged intrusion.

An attacker could impersonate an executive, employee, contractor, supplier, or job candidate. Once trusted, that identity could be used to obtain credentials, convince another employee to disclose information, authorize a payment, or establish access to internal systems.

That makes deepfakes particularly dangerous because the attack does not necessarily end after the first successful interaction.

The impersonation can become the beginning of an intrusion.

The Fake Employee Problem

The KnowBe4 incident demonstrates another dimension of identity fraud.

The company reportedly hired an individual who passed interviews and screening processes. After receiving a corporate workstation, the individual used it in suspicious activity before the company discovered the underlying identity problem.

The irony was especially uncomfortable: KnowBe4 is itself a security-awareness company.

The broader lesson is more important than the irony.

Traditional recruitment and identity-verification processes can be manipulated when organizations assume that a convincing identity presentation is equivalent to a verified identity.

North Korean IT-worker campaigns have further demonstrated how identity fraud can operate at scale, with attackers attempting to obtain legitimate employment and use trusted access for malicious purposes.

Why Low-Tech Security Is Suddenly Powerful

This is where the argument becomes surprisingly simple.

If attackers can copy everything employees can observe remotely, then authentication should depend on something the attacker cannot observe or reproduce remotely.

That could mean a physical security key.

It could mean a secret passphrase.

It could mean a telephone number or communication channel that is independently verified.

It could mean requiring two authorized employees to approve a transaction.

None of these technologies sounds futuristic.

That is precisely why they can work.

The Power of a Secret That Was Never Public

Consider a verbal passphrase.

An executive calls an accounts-payable employee and instructs them to transfer $5 million.

The voice sounds perfect.

The video looks convincing.

The background looks correct.

The attacker knows the

But the employee asks for a secret phrase that was never publicly recorded.

The attacker does not know it.

The deepfake suddenly becomes irrelevant.

This is the fundamental advantage of an offline secret: AI cannot infer information that was never exposed to the attacker.

Hardware Keys Go Even Further

For sensitive systems, hardware-backed authentication is considerably stronger than simply asking someone to provide a secret phrase.

FIDO2 security keys and PIV credentials can provide cryptographic authentication that is difficult to replicate through a video or voice impersonation.

The important distinction is that the employee does not simply “say” they are authenticated.

The physical credential performs a cryptographic operation.

That changes the security model from:

I recognize you.

to:

“A trusted credential has cryptographically authenticated this action.”

That is a much stronger foundation.

The Most Important Rule: No Exceptions

Even the best security control fails if employees are permitted to bypass it whenever a senior executive becomes impatient.

Attackers understand hierarchy.

They know that employees may hesitate to challenge a CEO, CFO, director, or senior manager.

They create urgency.

They invoke confidentiality.

They threaten consequences.

They say the transaction must happen immediately.

They tell the employee that nobody else can know.

This is exactly where security procedures must become stronger rather than weaker.

A good policy should effectively say:

If the authentication requirement is not satisfied, the transaction does not happen.

Not because the employee is being difficult.

Because the process is doing its job.

Security Should Become Automatic

Employees should not have to make a personal judgment about whether a security policy is important enough to follow.

The system should enforce it.

For example, a financial platform could require a separate authentication mechanism whenever a transaction exceeds a predefined threshold.

A high-value transfer could require:

A hardware-backed credential.

A secret transaction-specific verification mechanism.

An independent callback.

A second authorized employee.

A verified destination account.

A cooling-off period for unusual transactions.

The objective is not to make every ordinary task miserable.

The objective is to make extraordinary actions difficult to perform accidentally.

Building Better Verbal Passphrases

Verbal passphrases can be useful, but they should not become another weak password system.

The phrase should be randomly generated rather than personally invented.

Avoid names, birthdays, company slogans, favorite sports teams, locations, or phrases connected to the organization.

A stronger structure could use several unrelated words combined with random characters.

The important property is not whether the phrase sounds clever.

It is whether the selection was unpredictable.

Human creativity is surprisingly predictable.

Randomness is much harder to guess.

Never Use One Universal Passphrase

A company-wide master phrase creates an obvious single point of failure.

If one employee accidentally reveals it, the entire authentication system may become compromised.

Instead, organizations can divide authentication secrets according to role, transaction type, department, or risk level.

For example, accounts payable could use one authentication mechanism for ordinary transactions, while transactions above a defined threshold require additional independent verification.

This creates compartments.

One compromised secret does not automatically compromise everything else.

Passphrases Need Lifecycle Management

A passphrase should not remain valid forever.

However, blindly changing every secret every 90 days can also create problems.

Employees may choose weaker replacement secrets, write them down, reuse them, or develop predictable patterns.

A better approach is event-driven rotation.

Change the secret when:

Someone leaves the organization.

An employee changes roles.

A secret may have been exposed.

A vendor relationship changes.

A privileged account is transferred.

A security incident occurs.

A transaction workflow is redesigned.

Security should respond to risk rather than an arbitrary calendar.

Out-of-Band Verification Is Critical

For extremely sensitive transactions, a verbal passphrase should be only one layer.

Suppose an employee receives a request to transfer $10 million.

Instead of replying directly to the person who made the request, the employee independently contacts the executive through a trusted number already stored in the corporate directory.

The employee does not use a phone number provided during the suspicious call.

That distinction matters.

If the attacker controls the original communication channel, asking the attacker to confirm the request through that same channel proves almost nothing.

Two-Person Authorization Changes the Equation

Dual authorization provides another powerful barrier.

One employee prepares the transaction.

Another independently reviews and approves it.

This prevents a single compromised identity from automatically controlling the entire workflow.

It also reduces the effectiveness of deepfake attacks because the attacker must defeat multiple independent verification processes instead of convincing one person.

For high-value financial operations, that additional layer can be enormously valuable.

Deep Analysis: Building a Deepfake-Resistant Security Architecture

Start With a Zero-Trust Assumption

Organizations should assume that identity presented through a single communication channel can be compromised.

A familiar voice should not automatically authorize an action.

A recognizable face should not automatically authorize an action.

An email address should not automatically authorize an action.

Authentication should be based on independent evidence.

Verify the Transaction, Not Just the Person

The most important question is not always “Is this really the CFO?”

The more useful question is:

Is this exact transaction legitimate?

An attacker could compromise a legitimate employee account and still issue an unauthorized request.

Transaction verification therefore needs its own controls.

Use Hardware-Backed Credentials

For privileged users, FIDO2 security keys can provide strong phishing-resistant authentication.

On Linux, administrators can inspect available security-key and smart-card devices with commands such as:

lsusb

For systems using the Linux Pluggable Authentication Modules framework, administrators can inspect authentication configuration with:

grep -R "pam_u2f|pam_fido2" /etc/pam.d/

The exact configuration should be tested carefully before deployment because authentication mistakes can lock administrators out.

Audit Privileged Access

Organizations should regularly identify accounts with elevated permissions.

For Linux systems, a basic review can begin with:

getent group sudo

and:

getent group wheel

Depending on the distribution, administrators may also inspect:

sudo -l

These commands can reveal who has administrative privileges and help identify accounts that should no longer have them.

Monitor High-Risk Transactions

Security teams should treat unusual financial activity as a separate detection problem.

For example, organizations can monitor:

journalctl --since "24 hours ago"

and search authentication activity with:

journalctl | grep -Ei "authentication|sudo|login|failed"

For centralized environments, those logs should ideally feed into a SIEM rather than remain exclusively on individual machines.

Test the Human Layer

Security teams should periodically conduct controlled simulations.

A simulated executive voice-phishing call can test whether employees follow the required authentication process.

The objective should not be to embarrass employees.

The objective is to discover where the workflow breaks.

If employees bypass a control during a harmless simulation, the organization has found a vulnerability before a criminal discovers it.

Protect Secrets Like Passwords

Verbal authentication secrets should be treated as credentials.

Do not put them in ordinary chat messages.

Do not store them in shared documents.

Do not print them on desks.

Do not send them through the same communication channel used to authenticate the person.

Where practical, secrets should be managed through approved enterprise credential-management systems.

Reduce the Blast Radius

No authentication method is perfect.

The goal should therefore be to ensure that one compromised identity cannot destroy the organization.

Separate privileges.

Separate transaction limits.

Separate approval chains.

Separate credentials.

Separate communication channels.

This turns one successful attack into a contained incident rather than a catastrophic breach.

Make Urgency a Warning Signal

Urgency should never be treated as proof of legitimacy.

In fact, urgency should increase scrutiny.

An attacker wants an employee to think:

There’s no time to verify this.

A mature security culture should teach employees to think:

“Because this is urgent, I need to verify it.”

That psychological reversal could prevent enormous losses.

The Real Battle Is Against Trust Manipulation

Deepfakes are impressive technology, but the underlying attack remains remarkably traditional.

The criminal is exploiting authority.

They are exploiting urgency.

They are exploiting familiarity.

They are exploiting fear of challenging a superior.

AI simply makes the impersonation more convincing.

The strongest defense is therefore not necessarily another AI model.

It is a security architecture that refuses to trust appearances.

What Undercode Say:

Trust Has Become a Technical Vulnerability

The biggest lesson from deepfake attacks is that trust itself can now be manipulated as easily as software.

Organizations spent decades teaching employees to recognize faces, voices, signatures, email addresses, and familiar communication patterns.

AI is weakening every one of those signals.

Perception Should Trigger Verification

Human judgment still matters, but it should function as an alarm rather than a final authorization mechanism.

If something looks unusual, verify it.

If something looks completely normal, verify it anyway when the transaction is high risk.

The Simplest Controls Can Be the Strongest

There is a strange irony in modern cybersecurity.

As attackers become technologically sophisticated, effective defenses sometimes become more physical and procedural.

A security key cannot be deepfaked through a video call.

A secret stored only in a trusted system cannot be extracted from a public interview.

A second independent approver cannot simply be replaced by an AI-generated face.

AI Changes the Economics of Social Engineering

Previously, impersonating a senior executive convincingly could require significant preparation.

Generative AI lowers that barrier.

One attacker can potentially produce highly convincing audio, video, text, and images at scale.

That means organizations should assume social-engineering attacks will become cheaper and more frequent.

Executive Identities Need Extra Protection

Executives are particularly attractive targets because their identities carry authority.

Companies should therefore protect executive voice recordings, public video appearances, organizational information, travel schedules, and internal communication patterns where practical.

The less useful material attackers have for cloning and contextual preparation, the harder the attack becomes.

Financial Teams Need Different Security

A receptionist answering a routine call and an employee approving a multimillion-dollar transfer should not operate under identical authentication requirements.

Risk-based controls make more sense.

Low-risk actions can remain convenient.

High-risk actions should require stronger verification.

Security Friction Should Be Strategic

Too much friction encourages employees to bypass controls.

Too little friction creates opportunities for attackers.

The solution is not maximum security everywhere.

It is maximum security where the consequences of failure are highest.

Secret Information Must Stay Outside Public Channels

A passphrase only works when the attacker does not know it.

This sounds obvious, but organizations frequently expose sensitive information through documents, chat systems, email threads, shared drives, and recordings.

A secret is not a secret if everyone can eventually search for it.

Independent Channels Matter

Calling back through a known corporate number is fundamentally different from replying to a number provided by the person making the request.

Security teams should explicitly train employees to understand this distinction.

The verification channel must be independently trusted.

AI Detection Will Remain Useful

Deepfake detection should not be dismissed.

Detection systems can still provide valuable supporting evidence.

The problem begins when an organization treats a detection score as absolute proof of authenticity.

Detection should be one signal among several.

The Future Is Multi-Signal Authentication

The most resilient systems will combine multiple independent signals.

Identity.

Device.

Credential.

Transaction.

Location.

Behavior.

Approval.

Communication channel.

The more independent evidence an attacker must defeat, the harder the attack becomes.

Zero Trust Becomes More Relevant

Zero Trust is often discussed in the context of networks and applications.

Deepfakes demonstrate why the same philosophy applies to people.

Never automatically trust an identity simply because the communication looks familiar.

Continuously verify important actions.

Job Recruitment Needs Stronger Identity Controls

The KnowBe4 incident demonstrates that identity fraud can begin before an employee receives access to corporate systems.

Organizations should consider stronger identity verification for sensitive positions, particularly remote roles involving privileged access.

The challenge is balancing privacy and security without creating discriminatory or excessive screening practices.

Remote Work Increases the Challenge

Distributed teams rarely share the same physical environment.

That creates more opportunities for attackers to exploit digital communication.

Organizations should compensate by making authentication workflows stronger rather than assuming video meetings provide identity assurance.

Voice Authentication Is Becoming Dangerous

Voice biometrics and voice recognition may remain useful in some applications, but voice alone should not be treated as an unbreakable identity credential.

If an

The Executive Impersonation Problem Will Grow

CFO fraud is already a familiar concept.

AI makes it more convincing.

Attackers can impersonate CEOs, finance directors, lawyers, suppliers, customers, and security personnel.

Every trusted relationship can potentially become an attack surface.

Attackers Want You to Break Your Own Rules

This is perhaps the most important behavioral observation.

Attackers do not always need to defeat security controls technically.

Sometimes they simply need to convince an employee that the rules should not apply this time.

That is why no exceptions policies matter.

Security Culture Must Reward Verification

Employees should never fear punishment for verifying a suspicious executive request.

If someone says, “I called the CFO back because the transaction was unusual,” the organization should recognize that as good security behavior.

Not insubordination.

Authentication Should Be Transaction-Aware

A user logging into an internal dashboard and a user approving a $20 million payment should face different authentication requirements.

Authentication should understand the risk associated with the action.

Hardware Is Having a Security Renaissance

For years, cybersecurity moved toward software-only solutions.

Deepfakes are helping reverse that trend.

Physical security keys, smart cards, secure devices, and independently verified communication channels are becoming increasingly valuable because they exist outside the attacker’s synthetic-media environment.

The Best Secret May Be Boring

Cybersecurity often celebrates complicated technology.

But a random passphrase known only by two authorized people can sometimes stop an attack that defeats expensive AI detection technology.

Boring security can be exceptionally powerful.

Companies Should Practice Failure

Organizations should not wait for a real incident.

They should conduct controlled simulations involving deepfake video, cloned voices, fake executives, suspicious invoices, and urgent transfer requests.

The objective is to discover whether employees follow the process under pressure.

Attackers Will Learn the Procedures Too

Once companies establish verification protocols, attackers will attempt to learn them.

That means organizations should avoid relying on publicly documented secrets or predictable authentication challenges.

Secrets need to remain genuinely secret.

Segmentation Limits Damage

If one authentication secret is compromised, segmentation should prevent attackers from moving directly into every sensitive operation.

Different roles should have different permissions.

Different transaction levels should have different approval requirements.

Password Managers Can Help, But Carefully

Centralized credential management can make complex authentication systems easier to operate.

But the credential-management platform itself becomes critical infrastructure.

It therefore needs strong access controls, auditing, MFA, recovery procedures, and careful administrator management.

Compliance Is Not Enough

A company can technically comply with security regulations and still be vulnerable to a deepfake.

Compliance establishes a baseline.

Resilience requires understanding how attackers actually manipulate people.

Deepfakes Are a Social Problem as Much as a Technical Problem

The technology is only half the story.

The other half is human behavior.

People trust authority.

People respond to urgency.

People recognize familiar faces.

People hesitate to challenge superiors.

Cybersecurity training must address those psychological realities.

The End of I Saw It Myself

Perhaps the most profound change is cultural.

“I saw the person on video” can no longer carry the same evidentiary weight.

The digital world has reached a point where visual evidence can be manufactured in real time.

Organizations must adapt their definition of proof.

Physical Reality Becomes More Valuable

As digital representations become easier to fabricate, independently controlled physical objects become more valuable.

A hardware key.

A known phone number.

A secure device.

A separate approval process.

The future of authentication may involve more physical-world verification precisely because the digital world is becoming easier to fake.

Security Should Assume Compromise

The mature organization does not ask whether an attacker can fool one employee.

It asks what happens if they do.

Can the attacker transfer money?

Can they access customer data?

Can they create accounts?

Can they modify payment instructions?

Can they move laterally?

Can another employee stop them?

These questions reveal the real resilience of the system.

The Human Firewall Needs Better Tools

Employees are still an important security layer.

But they should not be expected to identify synthetic media with their eyes and ears.

Give them procedures.

Give them technical controls.

Give them permission to challenge authority.

Give them independent verification channels.

Then make the secure behavior the easiest behavior.

The Most Dangerous Deepfake Is the One Nobody Questions

A spectacularly fake video may be detected quickly.

A nearly perfect impersonation of a trusted executive asking for a completely plausible action is much more dangerous.

That is why authentication must not depend on plausibility.

The Security Lesson Is Surprisingly Old

Before digital communication dominated business, organizations relied on signatures, physical credentials, personal verification, dual authorization, and controlled procedures.

Many of those ideas still work.

Technology did not make them obsolete.

Technology simply made us forget why they existed.

The Future Will Be Hybrid

The strongest security architecture will probably combine AI detection with old-fashioned controls.

AI can identify suspicious behavior.

Hardware can provide cryptographic proof.

Human employees can challenge unusual requests.

Independent channels can confirm transactions.

Multiple approvers can prevent unilateral fraud.

No single layer has to be perfect.

Trust Must Be Earned at the Transaction Level

In the deepfake era, knowing

The organization must verify that the person is authorized to perform the specific action being requested.

That is a much stronger concept of trust.

The Real Defense Is Process

Deepfake technology will continue improving.

Detection will improve too.

But the most durable defense is a process that remains safe even when detection fails.

That is why a simple secret, a hardware key, and a second human approver can sometimes defeat an attack built with millions of dollars of AI technology.

✅ Deepfakes Can Convincingly Mimic Real People

The central claim is supported by documented incidents involving synthetic video and voice impersonation. Modern generative AI has made visual and audio identity increasingly unreliable as a standalone security signal.

✅ Human Detection Is Not Perfect

Research cited in the article supports the broader conclusion that people cannot consistently distinguish sophisticated synthetic media. Training can help, but it does not turn human perception into a foolproof authentication system.

✅ Hardware-Based Authentication Is Stronger Than Face or Voice Alone

FIDO2 and other phishing-resistant hardware-backed credentials provide cryptographic evidence rather than relying solely on what someone looks or sounds like. They are therefore much harder to defeat through a deepfake video call.

⚠️ Verbal Passphrases Are Not a Complete Security Solution

A secret phrase can stop an attacker who has cloned a person’s public identity, but it becomes useless if the secret itself is exposed. High-value transactions should therefore combine passphrases with independent authentication and authorization mechanisms.

Prediction

(+1) Physical Authentication Will Become More Important

As synthetic voices and faces become increasingly convincing, organizations will place greater value on physical security keys, smart cards, trusted devices, and other credentials that cannot simply be copied through publicly available media.

(+1) High-Value Payments Will Require Multiple Independent Approvals

Financial institutions and large companies are likely to expand transaction-level authentication, independent callbacks, dual authorization, and risk-based approval systems for unusually large or suspicious transfers.

(+1) Deepfake Training Will Become Standard Corporate Security Training

Employees will increasingly participate in simulated AI-generated voice calls, video meetings, fake executives, and synthetic supplier requests as organizations learn that traditional phishing exercises are no longer enough.

(-1) Face and Voice Alone Will Lose Their Authority

A familiar face or voice will increasingly become evidence rather than proof. Organizations that continue treating video calls as automatic identity verification will face growing exposure to impersonation fraud.

(-1) AI-Generated Social Engineering Will Become More Scalable

Attackers will be able to personalize scams using public information and synthetic media at a scale that would previously have required large criminal teams. The result will likely be more frequent attempts against finance departments, executives, recruiters, contractors, and privileged employees.

(+1) The Best Defense May Look Surprisingly Boring

The cybersecurity industry will continue producing sophisticated AI detection tools, but some of the most effective controls against deepfake fraud will remain remarkably simple: a secret that nobody outside the organization knows, a physical credential an attacker cannot remotely possess, an independently verified phone call, and a second person who refuses to approve a transaction without evidence.

The age of convincing digital identities is forcing companies to rediscover an old security principle: never confuse familiarity with authentication.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.zdnet.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube