Deepfake (Cybersecurity)
AI-generated synthetic media (such as fake audio or video of a person) used by attackers to impersonate executives or employees and authorize fraudulent actions.
Deepfakes use AI (typically deep neural networks) to generate realistic synthetic audio, video, or images of real people. In cybersecurity, deepfakes are used for social engineering: an attacker might clone a CEO’s voice to authorize a wire transfer or create a fake video call to impersonate an executive.
Several high-profile cases have involved deepfake audio calls resulting in millions of dollars in fraudulent transfers. As the technology becomes cheaper and more accessible, the threat grows.
Defenses include establishing out-of-band verification procedures for sensitive requests (e.g., always confirming wire transfers via a separate channel), training employees to recognize deepfake indicators, and using multi-factor authorization for financial transactions.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide