What to Do if Someone Deepfakes Your Business

The instinct is to get it taken down immediately. Do the opposite for the first twenty minutes: capture everything, because a successful takedown destroys the evidence you will need later.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
8 August 20261 min read

If someone deepfakes your business, capture the evidence before you report it. A takedown removes the page, the video and the account, and with them everything you would need for a bank dispute, a police report or a platform appeal. Twenty minutes of screenshotting and archiving first will save you weeks later. Then report it, then tell your own customers directly, and expect the whole thing to take days rather than hours.

This is an incident, not a PR problem, and it runs on the same logic as any other incident: preserve, contain, communicate, review. It also sits squarely inside the category of AI risks a small business can actually plan for, rather than the speculative kind.

The first hour after someone deepfakes your business

Minutes 0 to 20: capture everything

Before you click report anywhere, collect:

  • Full-page screenshots including the URL bar, the account handle, follower count and the post timestamp.

  • The direct URL of the content, the profile URL, and any account ID visible in the page source.

  • A download of the media itself if the platform allows it, saved with the date in the filename.

  • An archive snapshot via a public web archiving service, which gives you a third-party timestamped copy.

  • Where it was surfaced to you: the message, the email, the ad, the customer who reported it. That chain matters more than people expect.

Save it all in one folder with a plain text note recording who captured what and when. If money moves later, that folder is the difference between a bank reversing a payment and a bank asking you for proof you no longer have.

Minutes 20 to 60: work out the blast radius

Three questions, in order. Is anyone being asked for money or credentials? Is the impersonation targeting your customers, your staff, or the public? And is it live and spreading, or a static page that has been sitting there for weeks?

A fake video ad running paid distribution to your customer base is a different emergency from a cloned executive on a dormant profile. The first needs a customer warning within the hour. The second can follow the normal reporting path.

Reporting, and picking the right category

Platform reports are triaged by category, and the wrong category is the single most common reason a legitimate report gets closed with no action. Reporting a scam video as "I do not like this" puts it in a queue that will never look at it.

Where it is

File under

Also do

Social platform

Impersonation of a business, or fraud, not misinformation

Report from the brand's own verified account if you have one

Paid ad

Ad policy violation, deceptive practices

Ad libraries are public, capture the advertiser identity

Website

Registrar and host abuse contacts, plus trademark if the name is used

Check the domain registration date, new domains move faster

Video platform

Impersonation, then a separate trademark complaint if the logo appears

Two routes, they are handled by different teams

Search results

Report to the search engine after the source is removed

Cached results linger, this is a follow-up not a first step

Trademark complaints are worth understanding even if you feel small for it. A registered mark gives you a legal route with a defined response time, which the generic impersonation queue does not. If your business name is registered, use that route in parallel.

Tell your customers before someone else does

The instinct is to stay quiet until it is resolved. That is the wrong call almost every time. Your customers may already be seeing it, and silence looks like either ignorance or complicity.

Post something short and factual on the channels you actually control, within a few hours. Name the thing, say what you will never do, and give one verification route:

There is a video circulating that uses our name and appears to show our founder offering an investment scheme. It is not us and it is not real. We have reported it. We will never ask you to send money to a personal account, and we will never contact you about investments. If you are unsure whether a message is from us, call the number on our website.

No apology, since you did nothing. No detail about the fake that helps it spread. One concrete rule your customers can check any future message against. That last sentence is the part that keeps working after this incident is over.

The days after

  1. Chase the report. Most platforms have an appeal route for a rejected report, and a rejected first report is common rather than final.

  2. File with the police or the national fraud reporting body if money was solicited, even when you expect nothing to happen. The reference number is what insurers and banks ask for.

  3. Warn suppliers and partners, not just customers. Business email compromise frequently follows a public impersonation, using the same cloned voice or face against your finance contacts.

  4. Check whether staff were targeted. A convincing clone of you asking an employee to move money is the version of this that costs real money.

  5. Watch for the reupload. Take down one copy and two more often appear within a week from the same operator. Set a search alert on your business name plus the terms used in the fake.

Where the law now sits

The regulatory position improved in 2026, slowly. The European Commission began enforcing the AI Act's transparency rules on 2 August 2026, which require deepfakes to be labelled and AI-generated or altered content to carry machine-readable marks that make it automatically detectable, with penalties up to 15 million euros or 3 percent of worldwide annual turnover.

Be realistic about what that does for you. It obliges the people generating content to label it, which the honest ones already do and the fraudsters will not. Its practical value to a small business is indirect: it gives platforms a clearer basis for removal and gives detection tooling something standardised to look for. It is not a route to getting a specific video taken down this afternoon. The full picture of the transparency rules covers what applies to whom.

Making the next one cheaper

You cannot prevent impersonation. You can make it fail.

  • Publish a canonical contact list and refer to it in every warning you ever post. Verification only works if there is one place to verify against.

  • Agree a callback rule internally. Any payment or credential request arriving by voice or video gets confirmed on a known number, no exceptions, including from you. Say out loud that you will never be annoyed by someone applying it.

  • Claim your handles on platforms you do not use. An unused account you own cannot be registered by someone else.

  • Keep a monitoring alert on your business name and your own name. Most impersonation is discovered by a customer, which means it has already been working for a while.

  • Write the response down now. A one-page plan with the folder location, who captures evidence and who posts the statement turns a bad afternoon into a process.

The voice-cloning version of this attack has its own well-worn playbook worth reading separately in protecting your business from AI voice cloning scams, and the general pattern-recognition skills in how to spot an AI scam are what your team needs before an incident rather than during one. For images specifically, the tells that a photo is AI generated still apply to stills pulled from a fake video.

Common questions

Should I engage with the fake account publicly?

No. Replying to it amplifies it into feeds that had not seen it and gives the operator engagement to work with. Post on your own channels instead.

How long does a takedown usually take?

Anywhere from hours to weeks, and it depends far more on which report category you filed under and whether you have a verified presence than on how obviously fake the content is.

Is it worth paying a takedown service?

For a single incident, rarely. They mostly file the same reports you can file. It becomes reasonable when impersonation is persistent and organised, or when reuploads are appearing faster than you can track them. If you do sign up with one, it is worth knowing what happens to your data when an AI company shuts down before you hand your evidence archive to a vendor that might not be around next year.

What if a customer already lost money?

Tell them to contact their bank immediately, because reversal windows are short, and give them your evidence folder reference. Then be careful with your wording publicly: you can express that the customer was defrauded by a third party without accepting liability. If the amounts are meaningful, that is a conversation for a lawyer, and who is responsible when AI causes harm is genuinely unsettled ground.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.