By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Diving into the Deep: How Deepfakes Will Change Cybercrime” (June 26, 2026)

TL;DR: Deepfake technology is increasing the credibility of phishing, disinformation, and social engineering by making manipulated audio and video harder to distinguish from authentic content, according to Abnormal AI’s on-demand webinar with Mike Britton and Tyler Cohen Wood. The trust problem now extends beyond fraud response into identity verification, executive protection, and approval workflows.


At a glance

What this is: This on-demand webinar examines how deepfakes are changing cybercrime by making manipulated audio and video more credible and harder to distinguish from authentic content.

Why it matters: It matters because IAM, fraud, and security teams now need controls that account for synthetic content in verification, approvals, and executive-trust workflows.


Context

Deepfakes are synthetic audio, video, or images designed to look or sound authentic. In identity and security terms, they matter because they attack trust at the moment a human decides whether to approve, verify, or disclose.

This webinar frames deepfakes as more than a media problem. The risk now touches phishing, social engineering, executive impersonation, and disinformation, which means identity programmes have to think about trust as an operational control, not just a user-experience concern.

The article is a webinar promotion, but the underlying issue is real and broad: organisations are being asked to trust content that may be convincingly fabricated at machine speed.


Key questions

Q: How should security teams defend against deepfake fraud in executive approval workflows?

A: They should require out-of-band verification, role separation, and documented approval steps for any high-risk request. Deepfake fraud succeeds when a familiar voice or face can trigger action without a second trust check, so the control objective is to make impersonation insufficient on its own.

Q: Why do deepfakes create more risk than ordinary phishing emails?

A: Deepfakes add credible audio or video to the social engineering attack, which removes many of the visual and linguistic cues people use to detect fraud. That makes the victim more likely to act quickly, especially when the request appears to come from a senior leader or known colleague.

Q: What should organisations do when a request uses synthetic voice or video?

A: Pause the transaction, verify through a separate channel, and require a control that does not depend on the same media path. If the request concerns credentials, payments, or access, escalate it through a predefined approval route instead of relying on the apparent authenticity of the message.

Q: How should IAM teams respond when AI makes identity impersonation easier to scale?

A: They should reassess every process that relies on human judgement alone and add independent checks where a false identity can trigger access or payment changes. The right response is not only more authentication friction, but better assurance at the workflow level and consistent lifecycle coverage across people and systems.


Background and context

How deepfakes undermine identity verification

Deepfakes exploit the fact that many verification flows still rely on human recognition of voice, face, or tone. When audio and video can be synthesised convincingly, the control weakness is not the medium itself but the assumption that sensory confirmation is inherently trustworthy. That creates failure conditions for help desks, executive approvals, vendor callbacks, and incident escalation paths that were never designed to authenticate against adversarial media. In practice, the attacker does not need to defeat cryptography if they can defeat the person deciding whether the content is real.

Practical implication: treat voice and video as weak proof on their own in high-risk workflows.

Why deepfake phishing is different from ordinary impersonation

Traditional phishing often depends on writing quality, domain spoofing, or rushed behaviour. Deepfake-enabled phishing adds believable audio and video, which increases the social pressure to comply and reduces the chance that a target will pause. That shifts the threat from obvious deception to identity-layer manipulation, where the attacker can impersonate an executive, a colleague, or a known partner with far more fidelity. The result is not just more convincing lures, but more credible authority signals inside approval chains.

Practical implication: pair human verification with out-of-band confirmation for any request involving money, credentials, or access.

How AI detection helps, and where it still falls short

AI-driven detection can help identify synthetic patterns, manipulation artefacts, and media anomalies, but it is not a complete trust model. Detection is probabilistic, and attackers adapt quickly as generation techniques improve. That means the operational answer is layered defence: detection to reduce exposure, workflow controls to limit what a fake can accomplish, and identity governance to slow or block high-risk actions when trust is uncertain. The goal is not perfect detection, but reduced blast radius when synthetic content reaches a decision point.

Practical implication: design verification workflows so one failed detection does not automatically become one successful compromise.


NHI Mgmt Group analysis

Deepfakes turn trust itself into an attack surface: the security problem is no longer limited to suspicious links or malicious files. When audio and video can be fabricated convincingly, identity assurance has to extend to the content people rely on to make decisions. That shifts the control question from content authenticity alone to whether the workflow can withstand synthetic authority.

Identity verification built on human perception is now structurally weaker: many approval and escalation paths still assume that a familiar voice or face is a meaningful trust signal. Deepfakes invalidate that premise by making familiar identity cues reproducible at scale. The implication is that verification programmes need to treat perception-based trust as provisional, not authoritative.

Digital impersonation is now a governance issue, not just a fraud issue: the article’s emphasis on businesses, governments, and disinformation shows that synthetic media can distort both operational and reputational decision-making. That widens the scope from account takeover to executive protection, incident response, and policy enforcement. Practitioners need to govern the trust channel, not just the endpoint.

Deepfake risk exposes a named concept: synthetic trust debt: organisations have accumulated workflows that assume voice, image, and video are reliable enough for rapid decisions. That assumption fails when adversaries can manufacture credible identity signals on demand. The practical consequence is that teams must re-evaluate which approvals are allowed to depend on human recognition at all.

From our research library:

What this signals

Synthetic trust is the real control gap: the problem deepfakes create is not only deception, but decision quality under deception. IAM and fraud teams should assume that any workflow relying on face, voice, or video can be attacked at the point of approval, not just at the point of delivery.

Executives and service desks are both high-value targets: the same synthetic persona can be used to pressure a leader into action or a support desk into reset activity. That means organisations need verification rules that are consistent across privilege levels, not exception-based when the requester sounds credible.


For practitioners

  • Tighten approval workflows Require out-of-band validation for payment, password reset, and access requests that arrive through voice or video, especially when urgency is part of the message.
  • Harden executive verification paths Use pre-agreed callback procedures, known contact methods, and step-up checks before any instruction attributed to senior leadership is acted on.
  • Add deepfake-aware training Train staff to question synthetic authority cues, especially when a request combines urgency, secrecy, and a familiar persona.
  • Review fraud and incident playbooks Make sure response procedures cover synthetic media, disinformation, and impersonation attempts as distinct escalation scenarios.

Key takeaways

  • Deepfakes expand cybercrime by making identity cues such as voice and video unreliable in high-trust workflows.
  • The most exposed processes are approvals, resets, payments, and escalation paths that depend on human judgment.
  • Organisations should pair deepfake awareness with out-of-band verification and workflow controls that synthetic media cannot satisfy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationDeepfakes exploit trust in human-readable identity signals and decision paths.
Recommendation — Limit high-risk approvals to channels that synthetic media cannot convincingly imitate.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsDeepfake-driven impersonation often targets approval and access decisions.
DE.CM-09 — Monitoring for Anomalous BehaviorsSynthetic media attacks benefit from monitoring that spots abnormal request patterns.
Recommendation — Require step-up verification before privileged authorisations proceed. Watch for unusually urgent, repetitive, or inconsistent approval requests.
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessDeepfake impersonation is a route to initial trust and credential harvesting.
Recommendation — Map synthetic impersonation attempts to initial access and credential access detections.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIThe article’s core issue is humans making trust decisions based on manipulated signals.
Recommendation — Reduce reliance on human judgment where identity evidence can be fabricated.

Key terms

  • Deepfake: Synthetic or altered media created with AI or machine learning so that a person appears to say or do something they never did. In security terms, deepfakes are trust attacks that can distort identity verification, approval workflows, and fraud detection.
  • Synthetic Trust Debt: The gap between what AI-generated output appears to prove and what identity teams can actually verify. It grows when organisations let generated content influence access, authentication, or decisions without enough provenance, review, or control validation. The debt becomes operational risk as trust scales faster than assurance.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
  • Human-in-the-loop trust failure: A breakdown where a person, rather than a system, becomes the weak point in a verification or approval process. Deepfake campaigns exploit this by using realistic media to trigger fast human decisions before technical controls can intervene.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org