Join our Newsletter — 33% off our NHI Course
Home› Guides› Deepfakes, Social Engineering and AI Impersonation Guide
Guide Identity & Access Management (IAM)

Deepfakes, Social Engineering and AI Impersonation Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 6 min read
On this page

Seeing and hearing someone is no longer proof that they are there. Generative AI can clone a voice from a short recording and put a convincing live face on a video call, and criminals use both to impersonate executives, suppliers, colleagues and IT staff. In early 2024 a finance employee at Arup made 15 transfers totalling about HK$200 million after a video call in which every other participant was a deepfake. Most successful impersonation still relies on older tricks too: urgent phone calls to the help desk, spoofed email and pressure to bypass process. This guide explains how deepfake and impersonation attacks work, and the identity, process and technical controls that stop them.

Key takeaways

  • Treat voice, video and email as unauthenticated channels. Recognition is not verification.
  • The strongest defence is process: out-of-band verification through known channels and dual approval for payments and access changes.
  • Replace "does this sound like them?" with cryptographic proof where possible, such as a sign-in or approval on the person's registered device.
  • Help desks and finance teams are the main targets. Give them explicit permission to slow down.
  • Detection tools help, but do not rely on spotting fakes. Quality is improving faster than detection.

How impersonation attacks work

AttackTargetTypical goal
Executive impersonation (CEO or CFO fraud) by email, voice or videoFinance staffUrgent payment to an attacker account
Supplier impersonationAccounts payableChange of bank details on invoices
IT or help desk impersonation (vishing)EmployeesApprove an MFA prompt, install remote access tools, reveal a code
Employee impersonation to the help deskHelp desk agentsPassword or MFA reset, new device enrolment
Deepfake identity verificationOnboarding and recovery flowsOpen or take over an account
Fake job candidatesRecruiters and hiring managersGet hired and gain insider access

Recent examples

  • Arup (2024): a video call with deepfaked senior colleagues led to HK$200 million in transfers.
  • Cisco (2022): vishing calls impersonating support organisations persuaded an employee to accept MFA pushes.
  • Marks and Spencer (2025): impersonation of a third-party user was the route in.
  • ShinyHunters Salesforce campaign (2025): callers posing as IT talked staff into authorising malicious connected apps.
  • Storm-2949 (2026): IT support impersonation and self-service password reset abuse led to a cloud-wide data theft.

Controls that work

Verify through a separate, known channel

  • For any request to pay, change bank details, grant access or reset credentials, confirm through a channel the requester did not supply: a call-back to a number from the HR or supplier master file, a message in a verified internal chat, or an approval in a workflow system.
  • Agree code words or challenge questions for senior staff where process allows, but do not rely on information an attacker can research.

Use identity, not recognition

  • Ask the person to prove themselves with something bound to their identity: a push or passkey approval on their registered device, or a signed request in a workflow tool.
  • For help desk resets, follow the verification methods in the Account Recovery and Help Desk Security Guide.
  • Move high-risk approvals into systems with strong authentication, rather than accepting them by phone, video or email.

Build friction into high-risk actions

  • Dual approval for payments above a threshold and for new or changed payees.
  • Cooling-off periods for bank detail changes.
  • Written policy that no executive will ever ask for a secret, urgent payment outside the normal process, so staff know a request like that is a red flag.
  • Explicit permission for staff to pause, verify and escalate without penalty.

Protect identity verification flows

  • Remote onboarding and recovery need presentation attack detection and injection attack detection, plus document chip reading where possible. See the Biometrics Guide and the Identity Proofing and KYC Guide.
  • Retire voice-only caller authentication for sensitive actions.

Protect hiring

  • Verify identity during recruitment, and again at onboarding, with the same assurance you would use for a new customer.
  • Check that the person who joins is the person who interviewed.
  • Limit new starters' access until verification is complete, and watch for remote access from unexpected locations. See the Insider Threat and Identity Guide.

Email controls

Many impersonation attacks start or finish with email. Enforce DMARC on your own domains, flag external senders and look-alike domains, and watch for mailbox rules that hide replies. See the Email Identity and BEC Guide.

Detection and provenance technology

  • Deepfake detection tools analyse audio and video for artefacts. They are useful as one signal but produce false negatives as generation improves, so they should not be the only control.
  • Content provenance: the C2PA standard lets cameras, tools and platforms attach signed information about how media was created and edited. It helps prove that genuine content is genuine; it cannot prove that unsigned content is fake.
  • Meeting controls: restrict external participants, show verified identity labels and alert on unusual joins.

Training that helps

  • Focus on process ("we always call back on the known number") rather than on spotting visual glitches.
  • Run realistic exercises for finance, help desk, executive assistants and recruiters.
  • Share real examples, including the ones in this guide, so the threat feels concrete.
  • Reward reporting, including false alarms.

AI agents and impersonation

AI agents can both be impersonated and be used to impersonate. An attacker can pose as a trusted agent to another agent, or trick a support agent into acting for the wrong person. Give agents verifiable identities, sign agent-to-agent messages and require human approval for sensitive actions. See the Multi-Agent and A2A Security Guide.

Practitioner checklist

  • Publish a rule that payments, bank detail changes and access resets are verified out of band through known channels.
  • Require dual approval and cooling-off periods for high-value payments and payee changes.
  • Move approvals into systems with strong authentication instead of phone, video or email.
  • Harden help desk verification and retire voice-only authentication.
  • Use PAD, injection detection and chip reading in remote identity verification.
  • Verify identity during hiring and at onboarding.
  • Enforce DMARC and flag look-alike domains.
  • Train finance, help desk and executive support staff on process, with realistic exercises.

Standards and references

Related NHI Mgmt Group resources: Account Recovery and Help Desk Security Guide · Email Identity and BEC Guide · Biometrics Guide · Workforce Identity Security Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org