For as long as any of us can remember, seeing someone has been proof of who they are. A phone call could be faked, an email could be spoofed, but if you got on a video call and saw a familiar face and heard a familiar voice, you knew who you were talking to. That last, most trusted form of proof is now failing, and every business owner should understand why. Criminals can now put a convincing fake face on a video call, impersonating an executive, a colleague, or a client, in real time. The person you are looking at on the screen might not be a person at all.
We have written about criminals cloning a voice for a phone call. This is the next, more alarming step: deepfake video, where the impersonation happens live on a video meeting. It sounds like science fiction, but it has already cost a business a fortune. In one widely reported case, a finance employee at a firm in Hong Kong was tricked into transferring around twenty-five million dollars after joining a video call in which the company's chief financial officer and several colleagues were all convincing deepfakes. The employee saw familiar faces, heard familiar voices, followed their instructions, and sent the money to criminals. Let me explain how this works, why it defeats our instincts, and the one approach that actually stops it, an approach that scales all the way down to the smallest business.
What deepfake video fraud is
A deepfake is media, audio or video, generated or manipulated by artificial intelligence to convincingly imitate a real person. We covered the audio version in our piece on voice cloning scams, where a criminal fakes someone's voice for a phone call. Deepfake video takes this further, creating a fake visual likeness of a person, which can now be used live on a video meeting so that the impersonated individual appears to be on the call, speaking and moving, when they are not there at all.
Put that capability together with a classic scam, and you get the video version of business email compromise. A criminal sets up or joins a video call posing as a trusted authority, an executive, the boss, a senior colleague, sometimes several fake participants at once to make it more convincing, and uses the trust and urgency of that "face-to-face" meeting to instruct an employee to transfer money or take some sensitive action. Because the employee is looking right at what appears to be their leadership team, they do not doubt it. That is exactly what happened in the Hong Kong case, and it is the template criminals will reuse.
Why this defeats our instincts
This threat is uniquely unsettling because it attacks the very thing we fall back on to be sure. When something feels off about an email or a call, our instinct is to seek stronger proof, and a video call has long been the gold standard: "I saw them, it was really them." Deepfake video turns that last line of defense into a liability, because now the strongest-feeling proof can be the fake.
And it is only getting better. As we discuss in how AI changed the threat landscape, these tools are improving rapidly, becoming more convincing and more accessible. Which leads to a hard but important truth: you cannot reliably beat this by trying to spot the fake. People instinctively want a checklist of glitches to watch for, unnatural blinking, odd lighting, a lag in the lips. Some current deepfakes do have tells, and it does not hurt to stay alert to obvious ones. But betting your business on your ability to visually detect a fake is a losing strategy, because the technology is racing to eliminate those tells, and it is winning. Detection is a treadmill you cannot stay ahead of. The real defense has to be something else.
The defense that actually works: verification, not detection
Here is the key insight, and it is genuinely empowering because it does not depend on catching a flawless fake. The way to defeat deepfake fraud is a verification culture, not a detection skill. Instead of trying to determine whether the face on the call is real, you adopt a simple, ironclad rule: no request to move money or take a sensitive action is authorized based on a call alone, whether that call is by phone or video, no matter how real the person looks or sounds. Such requests are always confirmed through a separate, trusted channel before anyone acts.
This is the same out-of-band verification that defeats voice cloning and business email compromise, extended to cover video too, because the principle is channel-independent. If someone on a video call, even one who looks exactly like your CFO or your boss, asks you to wire money or change payment details, you do not act on the strength of the video. You verify the request another way: a call back to the person on a number you already have, a confirmation in person, a check through an established process. A genuine executive making a legitimate request will not mind a quick verification. A deepfake cannot survive one, because the real person, reached independently, will say "I never asked for that."
Notice how freeing this is. You do not have to become a deepfake expert. You do not have to win a technological arms race against increasingly perfect fakes. You just have to make verification a firm habit for anything that matters, so that no single call, of any kind, can move money on its own. The deepfake can be flawless and it still fails, because it never had the power to authorize the action by itself. That is why verification culture beats detection: it takes the fake's convincingness out of the equation entirely.
This same principle is exactly what we recommend in our 3-step payment verification rule, and it applies just as powerfully here. If you ever do face a situation where money has already moved, our wire fraud recovery playbook covers the urgent first steps.
Yes, this matters for small businesses too
You might think a twenty-five-million-dollar video deepfake scam is a big-company problem. It is not only that. The same playbook scales down, and simpler versions are well within reach for attacks on small businesses. A criminal does not need a whole fake boardroom to target a small team; a single convincing deepfake of the owner or a manager on a quick video call, combined with an urgent payment request, is enough. As the tools get cheaper and easier, expect these attacks to reach further down to smaller businesses, exactly as voice cloning and phishing already have.
The reassuring part is that the defense is the same regardless of your size, and it costs nothing: the verification rule, applied to everyone who can move money or take sensitive actions. A small business can adopt that habit as easily as a large one, arguably more easily, and be just as protected against this. You do not need enterprise technology to defeat a deepfake. You need a rule and the discipline to follow it.
How we think about it
Preparing businesses for exactly this kind of evolving threat is central to how we think at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, with protections like multi-factor authentication and controls on how money moves, so a single deception cannot cause a catastrophe. Inspect what is coming in, with the monitoring and awareness that keep your team alert to how threats are changing. And trust through validation, which is the entire answer to deepfake fraud: you do not trust a face or a voice on a screen, you verify important requests through a channel you control, every time, regardless of how convincing the call was. We help businesses build that verify-first culture and the protections around it, so that even as fakes become perfect, your defenses do not depend on spotting them.
What ready looks like
Picture a video call where your "CFO" or your "boss" appears, urgently instructing a payment. And instead of complying because the face looks right, your employee follows the rule: they pause, they verify the request through a separate known channel, they reach the real person who says "that was not me," and the deepfake collapses with nothing to show for it. Your team does not have to be fooled or not fooled by the video, because the video was never enough to move the money in the first place. The most convincing fake in the world meets a habit it cannot beat.
That is what ready feels like against deepfake video. Not straining to detect a perfect fake, but having a verification culture that makes the fake powerless no matter how real it looks.
The face on the video call might not be real, and soon there may be no reliable way to tell just by looking. That sounds frightening, but the defense is simple and entirely within your control: verify money and sensitive requests through a trusted channel, always, no matter how convincing the call. Build that habit into your team, and deepfake video loses its power over your business. If you want help building a verify-first culture and the protections that back it up, our free Business Security Assessment is the place to start, and it is a conversation worth having today.
Not sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

