How to Verify a Video Call Is Not a Deepfake

A finance worker sent $25.6 million after a video call with an AI-generated CFO. Real-time checks and the second-channel policy that actually prevents it.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
2 September 20261 min read

In 2024, a finance worker at the engineering firm Arup joined a video call with people who looked and sounded exactly like his colleagues, including the company's CFO, and sent 200 million Hong Kong dollars, about 25.6 million dollars, across 15 transactions before anyone realized everyone else on the call was an AI-generated deepfake, according to CNN's reporting. This guide covers a live video call specifically, not a pre-recorded clip or a cloned voice message, which is a distinct scenario from those already covered on this blog and needs its own verification steps.

Why a live call is a different problem

Detecting a recorded deepfake video means looking for artifacts, lighting mismatches, unnatural blinking, frame-to-frame flicker, at your own pace, with the ability to pause and zoom. A live call gives you none of that. The other person is responding in real time, which is convincing on its own, and the pressure of an actual conversation makes careful visual scrutiny hard to sustain. The countermeasures that work here are interactive, not observational, because you cannot pause a live call to study a frame.

Real-time interactive checks

  1. Ask them to turn their head fully to the side, then back. Most real-time deepfake generation still struggles with extreme profile angles and occlusion, and a live deepfake will often glitch, blur, or freeze briefly during this motion in a way a genuine camera feed will not.

  2. Ask an unexpected, specific question only the real person would answer naturally, referencing something from a recent in-person interaction, not something guessable from a LinkedIn profile or a public earnings call. Deepfake operators build their impersonation from public material, so anything outside that material is a genuine test.

  3. Watch for a lag between mouth movement and audio, or audio that sounds slightly too clean and consistent for someone speaking naturally, since even good voice cloning tends to lose the small imperfections (breathing, pacing, background noise) that a real live call has.

  4. If the request involves money or credentials, end the call and call the person back on a number you already have on file, not a number given to you during the call. This single step defeats the Arup scenario entirely, since the fraud only worked because the request came through the call itself with no independent channel to verify against.

The policy that actually prevents this

Individually clever verification tricks are useful in the moment, but the reliable fix is a standing rule: any request for a wire transfer, credential change, or unusual payment, no matter how convincing the video call requesting it, requires confirmation through a second, pre-established channel before action. A phone call to a known number, a message in an existing internal channel, an in-person check for anything above a set dollar threshold.

This works because it does not depend on your ability to spot a fake in the moment, which is exactly the ability real-time deepfakes are designed to defeat. It substitutes a process requirement for a detection skill, and processes hold up under pressure in a way that in-the-moment judgment often does not, especially when the request comes from someone who appears to be a senior colleague creating time pressure.

What to tell your team, concretely

  • Any payment or credential request made on a video call gets confirmed through a second channel before action, without exception, regardless of who appears to be asking or how urgent it seems.

  • "I need to verify this separately" is not insubordination and should never be treated as such internally. Make this explicit, since the biggest reason the Arup employee proceeded despite doubts was social pressure not to seem like he distrusted his own CFO.

  • Report a suspected deepfake attempt immediately, even if you are not certain, rather than staying quiet out of uncertainty. A near-miss report helps the next person on the team recognize the same attempt.

FAQ

Can I ask someone to prove they are real on a call?

Yes, directly. Asking someone to turn their head, or asking a specific verifying question, is a reasonable and increasingly normal request given how common these scams have become. A genuine colleague will not be offended by a quick check, especially if the request involves money.

Are these attacks only aimed at large companies?

No. Real-time deepfake tools have gotten cheaper and easier to use, and small businesses are targeted specifically because they are less likely to have a formal second-channel verification policy in place. The defense here does not require enterprise security tooling, just a written rule everyone actually follows.

How is this different from a voice cloning phone scam?

A voice-only scam relies purely on audio, often over a phone call rather than video, and generally involves less setup than fabricating a convincing live video feed. Live video deepfakes require more sophistication but are correspondingly more convincing, which is why the Arup case succeeded even though the employee had initial doubts.

For the pre-recorded and photo cases, see how to tell if an AI video is a deepfake and how to protect your business from AI voice cloning scams, which cover the two related but distinct scenarios this guide deliberately does not repeat. For the aftermath if a deepfake attempt against your business succeeds, what to do if someone deepfakes your business covers the response sequence. Source: CNN, "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'".

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.

How to Verify a Video Call Is Not a Deepfake | swarmz.net