By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SlashIDPublished March 30, 2026

TL;DR: Deepfake-enabled fraud is exploiting the gap between system authentication and human-to-human trust, with Arup’s Hong Kong office losing about $25 million in one incident and forecasts putting annual losses at $40 billion by 2027, according to SlashID. Perception-based verification is no longer enough; identity programmes must account for cryptographic proof in live communication as well as login events.


At a glance

What this is: This analysis shows that deepfake impersonation attacks bypass conventional login controls by abusing human trust in live calls and meetings.

Why it matters: It matters because IAM, fraud, and security teams need a way to verify identity during conversations, not just at system authentication points.

By the numbers:

👉 Read SlashID's analysis of deepfake impersonation and Mutual TOTP


Context

Deepfake impersonation is a human identity problem, not a login problem. Attackers are using synthetic voice and video to enter trusted communication channels, where existing IAM controls like passwords and MFA are not designed to validate who is speaking in real time. That makes perception-based trust a governance weakness, especially for finance, executive approval flows, and other high-risk interactions.

The practical issue for identity teams is that a person can be authenticated to a system and still be convincingly impersonated in a call or meeting. That breaks the assumption that secure access ends at login. For programmes that span human IAM, fraud prevention, and privileged workflow approval, the control gap is now at the point of conversation, not just account access.


Key questions

Q: How should security teams handle identity verification in high-risk video calls?

A: Security teams should treat high-risk video calls as identity checkpoints, not just collaboration sessions. Use participant verification before approving hiring, account recovery, payments, or privileged changes. The goal is to confirm the human behind the screen and the integrity of the camera source before any trust-sensitive decision is made.

Q: Why do deepfake attacks bypass normal MFA and SSO controls?

A: Because MFA and SSO authenticate a person to a system, not necessarily a person to another person in a live conversation. Deepfakes exploit trust in speech, appearance, and timing after login has already succeeded. The control gap is in interaction trust, not account access.

Q: What do organisations get wrong about human identity fraud?

A: They often assume that strong login controls are enough to protect downstream decisions. In reality, attackers can impersonate trusted colleagues in calls, meetings, and chats even when accounts are secured. That means the fraud risk sits in approval workflows and communication channels, not only in authentication events.

Q: Who is accountable when a deepfake impersonation bypasses identity controls?

A: Accountability sits with the organisation that allowed one trust signal to carry too much decision weight. Identity, fraud, and application owners all share responsibility when verification design permits synthetic presence to reach high-risk actions. Governance frameworks should map that responsibility before incidents occur.


Technical breakdown

Why deepfake impersonation evades normal authentication controls

Deepfake fraud works because it targets the trust layer around communication, not the authentication layer around system access. A user can pass MFA, use a passkey, or be fully enrolled in SSO and still be socially engineered in a live call if the attacker can imitate voice, face, context, and timing. The attack surface is the conversation itself, where employees often rely on familiarity rather than cryptographic proof. This is why email security, endpoint tools, and network monitoring are insufficient on their own.

Practical implication: teams need identity verification methods that operate during live human interaction, not only at login.

How mutual TOTP changes identity proof in real-time conversations

Mutual TOTP extends one-time password logic into a bidirectional human verification flow. Each participant generates a time-based code from a device-bound secret, then confirms the other party during the call or meeting. Because the codes are short-lived and derived from shared cryptographic material, they cannot be replayed by a deepfake system that only imitates voice or video. The model shifts trust from perception to possession of a registered device, which is materially harder for impersonators to fake.

Practical implication: high-risk conversations should use a verification step that proves device possession before sensitive information is shared.

Why time-limited codes matter for human identity assurance

The security value of TOTP in this context comes from expiry and synchronisation. A code that changes every 30 seconds reduces replay risk, while the short verification window limits the attacker’s chance to exploit prolonged conversation. Mutual verification also creates an auditable event, which is useful in investigations and control testing. In practice, this is closer to step-up verification for communication than to conventional MFA for applications.

Practical implication: organisations should treat live-call verification as a separate control family from application authentication.


Threat narrative

Attacker objective: The attacker wants to convert human trust into fraudulent approval, data disclosure, or financial transfer without needing to compromise the underlying system.

  1. Entry begins with phishing or pretexting into a trusted communication channel, often a call or video meeting that appears legitimate to the target.
  2. Escalation occurs when the attacker uses synthetic voice or video to gain social authority, causing the victim to share information or approve actions they would otherwise question.
  3. Impact follows when the victim executes privileged transfers, discloses sensitive data, or authorises access based on perception rather than cryptographic proof.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Human identity assurance no longer ends at successful login. The core failure exposed by deepfake fraud is that many identity programmes still assume authentication of a user to a system is enough to trust that person in a conversation. That assumption breaks when the attacker can convincingly impersonate voice and video in real time. The implication is that human IAM must now distinguish between session access and interaction trust.

Perception-based trust is now a control liability, not a convenience feature. Voice recognition, visual recognition, and contextual familiarity were always soft signals, but deepfakes turn them into exploitable control points. Security teams should treat any approval flow that depends on “this sounds like the right person” as a governance gap. The practitioner conclusion is that identity proof must be cryptographic when the action is high impact.

Real-time verification creates a new boundary for privileged human actions. The article’s central concept is a communication-layer identity check that sits before sensitive disclosure or approval. That is a useful pattern for finance, executive operations, and incident response, where an attacker benefits from urgency and familiarity. The practitioner takeaway is that approval workflows need a trust check at the moment of interaction, not only at the moment of access.

Mutual verification is the right framing for high-risk human interactions. One-way authentication tells a system who a user is; it does not establish that both humans in a call are genuine. That difference matters in fraud scenarios because attackers often need only one compromised participant to trigger loss. Identity governance must therefore expand its control model from single-party authentication to bilateral assurance when the decision is irreversible.

From our research:

  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how often identity control depends on partial inventory and incomplete governance.
  • If you are building lifecycle or access review improvements, Ultimate Guide to NHIs , Key Challenges and Risks is the right next reference for understanding exposure patterns.

What this signals

Human identity programmes now need a communication-layer control plane. The next phase of identity governance is not only about stronger authentication at login, but about proving identity during live interaction when the business is making irreversible decisions. That matters most in finance, executive approvals, and support workflows where urgency lowers scrutiny.

Interaction trust should become a named control objective. Organisations should explicitly classify which conversations require cryptographic proof, out-of-band confirmation, or bilateral verification before action can proceed. Deepfake risk is not a fringe threat anymore, and programmes that leave conversation trust undocumented will keep relying on human judgment where it is least reliable.

With 90% of IT leaders saying properly managing NHIs is essential for a successful zero-trust implementation, the broader lesson is that trust boundaries are widening across both machine and human identity. Identity teams should align human approval paths with the same discipline now used for non-human access.


For practitioners

  • Map high-risk human interactions Identify call, video, and chat workflows that can trigger money movement, credential resets, vendor approval, or privileged disclosure. Rank them by fraud impact and require stronger verification for the highest-risk interactions.
  • Separate login trust from conversation trust Document where MFA, SSO, and passkeys end and where live interaction trust begins. Use different control requirements for system access and for communication-based approvals.
  • Add cryptographic verification to sensitive approvals Introduce mutual proof steps before any transfer, reset, or escalation that relies on identity confirmation in a live call. Make the verification step mandatory for actions that cannot be easily reversed.
  • Train staff on deepfake-aware escalation paths Update fraud and incident playbooks so employees know how to pause a request, verify through an out-of-band channel, and escalate suspicious interaction patterns without delaying legitimate work.

Key takeaways

  • Deepfake impersonation attacks exploit the gap between system authentication and human trust in live communication.
  • The scale is rising quickly, with one cited fraud costing about $25 million and forecasts reaching $40 billion in annual losses by 2027.
  • Cryptographic verification during the conversation is the control shift that can limit fraud when voice and video can no longer be trusted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BThe article is about human identity proof and authentication assurance.
NIST CSF 2.0PR.AC-1Identity assurance and access control underpin the response to impersonation risk.
NIST Zero Trust (SP 800-207)3.2Zero trust principles apply when trust must be verified during interaction, not assumed after login.
MITRE ATT&CKTA0001 , Initial Access; TA0009 , CollectionThe fraud begins with social engineering and ends with data or payment collection.

Map impersonation workflows to Initial Access and Collection to improve detection and escalation playbooks.


Key terms

  • Deepfake-based impersonation: A fraud technique that uses synthetic audio, video, or both to make an attacker appear to be a trusted person during a live interaction. The tactic exploits human trust in familiar cues and often aims to trigger urgent actions such as payments, resets, or access changes before verification is challenged.
  • Mutual TOTP: A bidirectional verification method where both participants in a conversation prove possession of a registered device by exchanging time-based one-time passwords. It shifts identity proof from human perception to cryptographic confirmation, creating a stronger control for high-risk calls and meetings.
  • Conversation Trust: The level of confidence an organisation places in a live human interaction, such as a phone call, video meeting, or chat. Unlike account authentication, conversation trust must withstand impersonation, urgency, and social pressure, so it often needs separate verification controls.
  • Passive Trust: Trust based on voice, face, familiarity, or context rather than on cryptographic evidence. It is easy for attackers to exploit because people tend to accept familiar cues during live interactions, especially when the request appears urgent or routine.

What's in the full article

SlashID's full article covers the technical detail this post intentionally leaves for the source:

  • How Mutual TOTP is provisioned on devices and how the shared secret is delivered and protected
  • The precise session flow for bidirectional verification during a live conversation
  • The TOTP timing model, including the 30-second code rotation and the 2-minute session timeout
  • How the approach maps to real-world deepfake impersonation scenarios in calls and video meetings

👉 SlashID's full post covers the Mutual TOTP workflow, timing model, and deepfake resistance details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org