A deepfake video call is a forged real-time or recorded video interaction that imitates a known person, usually an executive or manager, to influence decisions or extract information. In security terms, it weaponises visual trust and can bypass casual verification unless a separate confirmation step is used.
What Makes a Deepfake Video Call Dangerous?
A deepfake video call is most effective when the target already expects the person on screen to be real. The risk is not the technology alone, but the way it can collapse normal doubt during urgent, high-trust conversations about payments, approvals, access, or confidential information.
These calls are usually persuasive because they combine live conversation, facial realism, and social pressure. Even when the video is imperfect, a familiar voice, a known name, or a busy meeting context can be enough to override careful scrutiny.
How Deepfake Video Calls Work in Practice
Deepfake video calls can be generated from recorded footage, synthetic voice, or real-time face swapping and lip-syncing. The attacker’s goal is usually to imitate an executive, manager, vendor, recruiter, or colleague well enough to steer the conversation toward a requested action.
The call often succeeds by exploiting familiar work patterns. A request to “handle this now,” “keep it discreet,” or “avoid extra steps” can make the interaction feel routine, especially when the impersonated person is someone who normally has authority.
What makes this class of fraud different from a simple spoofed email is the added visual and conversational layer. That combination can reduce hesitation, especially when the target is multitasking, under time pressure, or unable to verify the caller through a separate channel.
Why Verification Has to Happen Outside the Call
Deepfake video calls are best understood as trust attacks, not just media forgery. The practical defense is to treat the video call as untrusted until the person’s identity is confirmed through a separate confirmation step, such as a known callback path or an established internal approval process.
Verification matters most when the request involves money movement, credential changes, sensitive documents, or unusual account activity. In those moments, the call is not the control, it is the thing being challenged, and the control must sit outside the conversation itself.
For a useful cautionary example, NHIMG’s Arup deepfake fraud 2024 shows how a fabricated executive video call can be used to trigger a major transfer decision.
Where Deepfake Video Calls Fit in Social Engineering
Deepfake video calls sit at the intersection of impersonation, urgency, and trust abuse. They are especially effective when the attacker can combine multiple signals at once, such as a recognisable face, a plausible voice, a familiar title, and context that feels operationally believable.
That is why these attacks are often stronger than older “single-channel” impersonation tactics. A target may distrust an email alone, but still accept a video call that appears to come from a senior leader or trusted partner.
As the threat becomes more common, teams need to understand the pattern as part of broader impersonation resilience. NHIMG’s Deepfakes, Social Engineering and AI Impersonation Guide covers the recurring controls that matter most, including out-of-band verification and payment validation.
Risk and Threat Considerations
Deepfake video calls create a direct fraud and impersonation risk because they can convert a familiar human interaction into a high-confidence deception channel. The main danger is not merely that the media is fake, but that the call can bypass the casual verification people normally rely on in fast-moving business conversations.
Failure mechanism: The attacker exploits authority, urgency, and visual trust to push the target toward a decision before separate verification can occur. Once the impersonation is accepted, the call can be used to authorise payments, reveal sensitive information, reset access, or confirm further fraudulent steps.
Impact: The result can be financial loss, unauthorised disclosure, account compromise, or a broader breakdown in internal trust and approval processes. If the organisation lacks a consistent second-check habit, one convincing call can create a high-value compromise path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Deepfake calls target user identity assurance and trust in authenticated interactions. |
| AC-6 — Least Privilege | Reduces damage when an impersonated user or executive request is abused. | |
| AU-6 — Audit Review, Analysis, and Reporting | Supports detection and review of suspicious approvals, changes, and transaction flows. | |
| Recommendation — Require separate verification for high-impact requests before acting on claimed identity. Limit approval and payment authority to the minimum needed for each role. Review unusual requests and approvals for signs of impersonation abuse. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant identity proofing and authentication strengthen confidence in remote verification. |
| Recommendation — Use phishing-resistant verification methods for high-risk remote approvals. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Helps govern who can approve, change, or request sensitive actions after impersonation attempts. |
| Recommendation — Restrict approval paths and revoke excessive access quickly when abuse is suspected. | ||
| MITRE ATT&CK | T1656 — Impersonation | Deepfake calls are a direct impersonation technique used to manipulate targets. |
| Recommendation — Map impersonation attempts to detection rules and response playbooks. | ||
Practitioner Guidance
Why practitioners should care: The key governance problem is that a video call can feel more authentic than it is, so the organisation must define what counts as valid identity confirmation for urgent requests. Teams should not rely on “it looked real” as evidence of trust.
Common misunderstanding: Many people assume that seeing the person on screen is enough to approve an exception, payment, or sensitive change. In practice, the safer assumption is that the call itself may be the attack surface, so the verification step must be independent of the medium.
Practitioner takeaway: Build a normal habit of separate confirmation for high-impact requests, because the best defence against deepfake video calls is to make visual trust insufficient on its own.
Related resources from NHI Mgmt Group
- What breaks when a deepfake video call is used to authorize a payment?
- What breaks when video verification is trusted without deepfake detection?
- How should organisations verify participants in high-risk video calls to reduce impersonation and deepfake fraud?
- What are the signs that a video interview may be using a deepfake?