MFA protects system access, not human trust inside a live conversation. A fraudster can pass the login boundary and still impersonate a colleague on a call or video meeting. That is why organisations need a second assurance layer for communication-time identity, especially where approvals or transfers can happen outside applications.
Why MFA does not stop deepfake fraud in a live conversation
MFA is designed to raise the cost of account login, not to verify the person speaking after the session begins. In a voice call, video meeting, or message thread, the attacker can exploit trust directly, using a convincing synthetic persona to request urgency, secrecy, or a payment action. That makes the control gap one of communication-time identity, not only sign-in identity.
The practical problem is that many fraud workflows happen outside the application boundary. Once the attacker has access to the right channel, the victim often relies on recognition, tone, job title, or apparent familiarity rather than a second cryptographic proof. Deepfakes are effective precisely because they imitate the social evidence humans use to grant confidence.
Where the fraud path opens after login succeeds
Deepfakes matter because they can be paired with other access methods and then used to turn routine business communication into an approval channel. A fraudster may not need to defeat MFA if they can persuade someone to disclose information, alter bank details, approve an invoice, or bypass a normal verification step. The weakness is not the login alone, it is the assumption that authenticated access implies trustworthy intent.
This is why payment, payroll, treasury, and help-desk style workflows are common targets. The attacker only needs one person to treat an identity claim as sufficient evidence. When that happens, MFA has done its job at the door, but the organisation has no equivalent control at the moment of decision.
What organisations need in the second assurance layer
The answer is to separate sign-in assurance from communication assurance. Use out-of-band verification for material requests, require callback or codeword checks for sensitive changes, and add policy friction where a single conversation can trigger financial or privileged action. For broad workforce identity controls, NHIMG’s Workforce Identity Security Guide is useful because it connects phishing-resistant sign-in with the recovery and session risks that remain after authentication.
Where the concern is specifically impersonation and fraud during calls or video, the right control set is closer to human verification than access management. NHIMG’s Deepfakes, Social Engineering and AI Impersonation Guide and Arup deepfake fraud 2024 both show why a live voice or video presence cannot be treated as proof of legitimacy. The control objective is to force confirmation through an independent channel before value moves.
Risk and Threat Considerations
Deepfakes create fraud risk because they let an attacker borrow authority from a familiar face or voice while avoiding the friction of a normal login attack. The danger is highest where staff are trained to respond quickly, defer to senior people, or approve exceptions under time pressure.
Failure mechanism: The attacker exploits human trust in real-time conversation, then converts that trust into a financial transfer, credential reset, data disclosure, or policy exception. MFA does not interrupt that path once the target is already engaged in the call or meeting.
Impact: Organisations can suffer unauthorised payments, business email compromise style losses, account recovery abuse, and downstream access expansion if the victim helps the attacker reset or rebind controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | AAL — Authenticator Assurance Levels | Deepfakes exploit the gap between login assurance and live conversation trust. |
| Recommendation — Use phishing-resistant assurance for sign-in, then add independent verification for material requests. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Fraud risk rises when users can approve high-impact actions without strong verification. |
| Recommendation — Restrict approval paths and require separate verification for sensitive changes. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Synthetic impersonation abuses human trust in identity claims during interaction. |
| Recommendation — Design workflows so humans do not rely on a conversational identity claim alone. | ||
| OWASP Agentic AI Top 10 | ASI09 — Human-Agent Trust Exploitation | The same trust-exploitation pattern applies when synthetic personas influence decisions. |
| Recommendation — Add verification barriers before any high-impact action follows an interaction. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Second-factor style trust checks must extend beyond the initial login boundary. |
| Recommendation — Apply stronger identity proofing for external-facing recovery and approval workflows. | ||
Practitioner Guidance
What to prioritise: Treat any request that changes money movement, beneficiary details, login recovery, or privileged access as a high-risk event, even when the requester sounds familiar. The control should be strongest at the point of action, not only at sign-in.
What to verify: Require a verification step that is independent of the current call, meeting, or message thread. If a request can be executed with only conversational trust, it is under-controlled.
Decision rule: If the action would create irreversible loss or expose a privileged path, stop and re-verify through a known-good channel before proceeding.
Practitioner takeaway: MFA reduces one class of impersonation, but deepfake fraud succeeds when organisations fail to authenticate the conversation itself.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org