Deepfake Scams: What Businesses Need to Know

I was watching the local news when a story caught my attention. A family says they lost about $10,000 to someone they believed was an immigration attorney while trying to help a loved one being held at the Adelanto immigration detention center.

Unfortunately, scams involving fake professionals aren't new.

What caught my attention was how sophisticated and convincing this one appeared to be.

According to FOX 11, the family found the supposed attorney on Facebook. The profile appeared legitimate and featured what the family described as glowing reviews.

They didn't just exchange a few emails with this person. They communicated with her over video calls.

The family had a recording of one of those calls, and watching the footage shown in the news report, it really appeared as though they were speaking with an actual person. There was a face on the screen. There was a conversation taking place. To someone who wasn't specifically looking for signs of AI manipulation, it could be incredibly convincing.

Marena Lin, a software engineer who is now helping the family, reviewed video of the woman communicating with the detainee's mother and became suspicious. Lin told FOX 11 that she believes the woman shown in the video was actually an AI-generated avatar.

Think about that for a moment.

This wasn't just a suspicious email from a stranger.

There was a social media presence.

There were positive reviews.

There were video conversations.

There were legal documents.

There was professional license information.

There were payment instructions.

And each piece reinforced the credibility of the next.

The family was even provided documents that appeared to be legitimate legal filings. One stated that their loved one had been granted release under a $4,355 bond. They later learned that the documents had not actually been filed with the court.

Some of the paperwork contained clues. FOX 11 showed one document where "United States of Americ..." appeared cut off at the top. But other documents reportedly looked much more convincing.

The person presenting herself as the attorney was also allegedly using the license information of a real attorney in another state.

By the time the family realized something was wrong, they say they had lost approximately $10,000.

This story should get the attention of every business leader.

Not because your organization is likely to encounter a fake immigration attorney.

But because the same ingredients can be used to impersonate someone your employees already trust.

Seeing Is No Longer Believing

For years, we've trained employees to recognize social engineering by looking for clues.

Check the sender's email address.

Look for spelling mistakes.

Be suspicious of strange links.

Watch for unusual requests.

All of that advice still matters.

But AI is fundamentally changing what a convincing impersonation can look and sound like.

What happens when the person asking your controller to transfer money doesn't just send an email that looks like it came from the CEO?

What happens when the CEO appears on a video call and asks for it?

What happens when your accounts payable employee receives a video message from what appears to be a longtime vendor explaining that their banking information has changed?

What happens when someone who looks and sounds like your attorney asks an employee to send confidential documents?

Or when your IT team receives a call from an executive who appears to need an urgent password reset?

The old instinct was:

"I recognize that person, so I trust the request."

That assumption is becoming dangerous.

AI Is Giving Social Engineering a New Toolkit

Social engineering has always been about manipulating trust.

AI simply gives attackers more tools to manufacture that trust.

An attacker can potentially combine:

  • AI-generated or manipulated video
  • Voice cloning
  • Professional-looking social media profiles
  • AI-generated emails and messages
  • Convincing documents
  • Public information about executives and employees
  • Stolen credentials or professional information
  • Knowledge gathered from company websites and social media

Individually, one of those elements might raise suspicion.

Combined, they can create a convincing story.

That's what stood out to me about the FOX 11 report. The alleged deception wasn't dependent on one thing. Multiple pieces appeared to reinforce the same identity.

That's exactly how sophisticated social engineering works.

Your Executives Are Easier to Impersonate Than You Think

Consider how much information about your leadership team is publicly available.

LinkedIn provides names, titles, employment history, connections, and sometimes current projects.

Your company website provides headshots and biographies.

Webinars, podcasts, conference appearances, and YouTube videos provide hours of voice and video.

Social media provides additional context about relationships, travel, events, and activities.

None of those things are inherently dangerous.

But together, they can give someone an enormous amount of material to build a believable impersonation.

This is why deepfake risk isn't just a technology problem.

It's an identity and verification problem.

Businesses Need a New Rule: Verify the Person, Not Just the Request

If seeing someone's face and hearing someone's voice are no longer enough to establish identity, businesses need another layer of verification.

I recommend creating specific verification procedures for high-risk requests.

If a request involves:

Money. Credentials. Sensitive information. Access. Banking changes.

Require independent verification.

For example, if your CFO appears on a video call asking for an urgent wire transfer, don't verify the request using the phone number or link provided during that conversation.

Call the CFO using the number already stored in your corporate directory.

If a vendor requests a banking change, contact a known representative through an established channel before changing anything.

If an executive asks IT for a password reset or MFA change, follow the established identity verification process regardless of how convincing the person sounds.

The point isn't to distrust everyone.

It's to make sure trust has a verification step.

Update Your Security Awareness Training

This story also highlights why cybersecurity awareness training has to evolve.

If your training program still revolves primarily around spotting bad grammar and suspicious email links, you're preparing employees for yesterday's attacks.

Show employees what modern impersonation looks like.

Talk about deepfake video.

Demonstrate voice cloning.

Walk through fake vendor scenarios.

Practice executive impersonation scenarios.

Teach employees that urgency, authority, and familiarity are psychological tools attackers use to bypass good judgment.

And most importantly, create a culture where an employee feels comfortable telling the CEO:

"I need to verify this before I proceed."

That's not insubordination.

That's good cybersecurity.

Build Verification Into the Process

One lesson I've learned through years of working in cybersecurity is that you can't rely on people to recognize every attack.

The better approach is to design business processes that make successful fraud harder.

Consider controls such as:

  • Dual approval for large financial transactions
  • Independent verification of banking changes
  • Defined procedures for credential and MFA resets
  • Call-back requirements for unusual requests
  • Role-based access controls
  • Limits on who can authorize sensitive transactions
  • Clear escalation procedures when something doesn't feel right

Those controls may add an extra minute or two to a transaction.

Compare that inconvenience with the cost of sending money, credentials, or confidential information to an attacker.

The Bigger Lesson

What happened to this family is upsetting, and according to FOX 11, they chose to tell their story because they hoped it would prevent someone else from falling victim to something similar.

Businesses should pay attention to that warning.

We're entering an environment where a professional-looking profile can be manufactured.

Documents can be fabricated.

Voices can be cloned.

Video can be manipulated or generated.

And an interaction that feels very human may not be what it appears to be.

That doesn't mean we should become afraid of AI.

It means our verification habits need to catch up with what AI can now do.

At Netready, we talk frequently about people, process, and technology because cybersecurity requires all three. Deepfakes are a perfect example. Technology can help identify suspicious activity, but your processes and your people still matter enormously.

The next social engineering attempt targeting your organization may not look like a scam.

It may look like your CEO.

It may sound like your CFO.

It may appear to be your attorney, banker, client, or trusted vendor.

Seeing and hearing someone is no longer enough to prove identity. In the age of AI, trust needs a second step: verification.