TL;DR: AI voice cloning can be produced from three seconds of audio, and deepfake fraud now hits 1 in 127 retail contact-center calls, according to Trusona’s analysis. The core failure is not user awareness but help desk verification designed around human judgment, which collapses when callers can perfectly spoof voice and face.
NHIMG editorial — based on content published by Trusona: Deepfake help desk fraud and why human verification is failing
By the numbers:
- Deepfake fraud attempts now hit 1 in 127 retail contact center calls.
- Deepfake voice activity rose 680% year-over-year in 2024.
Questions worth separating out
Q: How should security teams stop deepfake attacks on help desk resets?
A: Make reset approval dependent on a separate trust path that the caller cannot control, such as an enrolled device, phishing-resistant MFA, or verified identity proofing workflow.
Q: Why do deepfakes create more risk than ordinary identity fraud?
A: Deepfakes compress the time needed to impersonate a real person and make the attack look legitimate at the exact moment trust is granted.
Q: What breaks when help desk teams rely on phone numbers to confirm identity?
A: Phone-based confirmation breaks when attackers perform SIM swaps or control the caller’s number through a compromised carrier relationship.
Practitioner guidance
- Remove human judgment from high-risk resets Require out-of-band verification through an enrolled device before any password reset, MFA re-enrolment, or executive account recovery is completed.
- Classify support resets as privileged workflows Apply privileged access controls, ticket approval, and stronger logging to all account recovery paths that can change access state or bypass MFA.
- Harden executive and finance recovery paths Add separate verification rules for accounts that can authorize payments, approve transactions, or access sensitive internal systems, and do not let caller confidence shorten the process.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The article breaks down the help desk reset flow where voice, face, and urgency are currently used as verification signals.
- It explains the specific out-of-band device challenge model used to block caller-controlled impersonation.
- It outlines how phishing-resistant MFA and zero-trust recovery workflows change the account reset path for support teams.
- It provides the Arup scenario and the Scattered Spider pattern as examples of how support abuse becomes financial or account takeover risk.
👉 Read Trusona's analysis of deepfake help desk fraud and identity verification →
Deepfake help desk fraud: are your reset controls keeping up?
Explore further
Help desk verification is now a brittle identity control, not a trustworthy gate. The article demonstrates that voice, face, and conversational confidence have become spoofable at scale. That means the control assumption behind many support workflows is no longer reliable: a human agent cannot be the final arbiter of identity when the attacker can synthesize the same cues the agent is trained to trust. The practitioner conclusion is simple: verification must move out of the caller-controlled channel.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, according to The State of Secrets in AppSec.
A question worth separating out:
Q: Who is accountable when a deepfake scam succeeds through a support workflow?
A: Accountability usually sits with the business owner of the workflow, the identity team that defined the controls, and the operations manager who allowed exceptions to become normal. Frameworks such as NIST CSF and NIST 800-53 expect clear ownership of access and authentication controls. If the process can alter identity state, someone must own the risk end to end.
👉 Read our full editorial: Deepfake help desk fraud is breaking human identity verification