Treat the request as unverified until confirmed through another trusted channel. Deepfake voice and video can copy familiar speech patterns, so urgency alone is not evidence of authenticity. Use a separate messenger, known phone number, or direct in person confirmation before sending money or sharing sensitive information. If the request involves danger, move quickly, but still verify first.
How to Respond Before Money Leaves the Account
Requests that arrive by voice or video should be treated as unverified until the person is confirmed through a separate channel. The key decision is not whether the voice sounds right, but whether the request can be independently validated before any transfer, password reset, or disclosure of sensitive information.
A practical response is to pause, switch channels, and confirm using contact details you already trust, not the ones embedded in the message. If the caller claims an emergency, keep the conversation calm and move verification forward quickly rather than letting urgency become the reason to skip it.
Why Familiar Audio and Video Are Not Enough
Deepfake voice and video can imitate speech patterns, facial movement, and style well enough to make a request feel authentic. That means the usual human shortcut, recognising a familiar tone, is no longer a safe authenticity test on its own.
The important distinction is between resemblance and verified identity. A convincing call can still be false if the message is routed through an account, number, or device that was spoofed, hijacked, or simply used to create social pressure. Confirmation must therefore happen outside the channel that delivered the request.
What Verification Should Look Like in Practice
Use a second path that is independent of the suspected message. That may be a known phone number saved before the incident, a separate chat service, an email address you already trust, or an in-person check. If the person cannot be reached immediately, stop the payment and wait for confirmation.
For money requests, add a simple challenge that a copied voice or video would not reliably answer, such as referencing a prior event only the real person would know. Do not rely on one question alone if the stakes are high, because a determined impersonator may have gathered enough context to pass a superficial test.
Risk and Threat Considerations
This type of scam works because it combines impersonation with urgency. The attacker does not need perfect realism, only enough credibility to push the victim into acting before verification happens.
Failure mechanism: A familiar voice or face, plus time pressure, suppresses normal caution and causes the target to send money or reveal information through the same channel that may have been fabricated or compromised.
Impact: The result can be immediate financial loss, account compromise, or wider fraud if the same conversation is used to request passwords, one-time codes, or additional sensitive details.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1656 — Impersonation | Covers fraudulent impersonation used to elicit money or secrets. |
| Recommendation — Map suspicious calls to impersonation and verify the requester through an independent channel. | ||
| NIST CSF 2.0 | PR.AT-01 — Individuals are provided cybersecurity awareness and training | Supports user training against synthetic voice and video fraud. |
| PR.AA-05 — Identities and credentials are issued, managed, verified, revoked, and audited | Identity verification is central when requests arrive through possibly spoofed channels. | |
| Recommendation — Train users to verify high-risk requests before sending money or data. Require independent verification before acting on money or sensitive requests. | ||
| NIST SP 800-53 Rev 5 | SI-4 — System Monitoring | Monitoring and detection help identify impersonation, spoofing, and related abuse patterns. |
| AT-2 — Awareness Training | Awareness training is directly relevant to social-engineering and deepfake fraud resistance. | |
| Recommendation — Monitor for suspicious identity-compromise indicators around high-risk requests. Train staff to pause and verify before responding to urgent money requests. | ||
Practitioner Guidance
What to verify: Verify the request through a channel that was established before the incident, and verify the person, not just the story. If the request changes from “send money” to “help me recover access,” treat that as an escalation signal and confirm again before doing anything else.
Common mistake: People often trust the message because the voice sounds like a relative or the video looks plausible. In practice, emotional urgency is part of the attack pattern, so a fast response should still include a separate confirmation step.
Practitioner takeaway: The safest default is to assume the call may be synthetic until an independent channel proves otherwise, because authenticity has to be confirmed outside the medium that delivered the request.
Related resources from NHI Mgmt Group
- How should people verify a virtual money request before sending funds through a chat app or QR code?
- What is the difference between video verification and cryptographic people verification?
- Who is accountable when a malicious message arrives through a vendor account?
- Who is accountable when an MCP tool call is authorised through a gateway and fails downstream?