Deepfake Scams: How AI Impersonation Works and How to Stop It
A deepfake scam uses AI to fake a boss, relative or celebrity on a call, video or ad and ask for money. Learn the common forms, how to verify through a known channel and what to do.
A deepfake scam uses AI-generated or altered voice, video or images to impersonate someone you trust, such as your boss, a family member or a celebrity, and then asks for money, a payment, login details or an investment. You can’t rely on spotting the fake by eye or ear, so the defense is process: hang up and contact the person through a number or channel you already know, use a family code word, and never send money because of an urgent call, video or message alone. If you’ve already paid, contact your bank immediately and report it at ReportFraud.ftc.gov and ic3.gov. For every reporting option in one place, including outside the US, see how to report a scammer.
This guide covers the forms deepfake scams take, how to set up simple checks at home and at work, and what to do if you’re targeted or impersonated. Our separate guide to deepfake detection covers how to examine a suspicious video or image in detail.
The main types of deepfake scam
The fake executive
An employee gets a call, voice note or video meeting invitation from someone who looks or sounds like a senior leader. The “executive” asks for an urgent, confidential payment, a change to a supplier’s bank details, or gift cards for a client. This is a newer form of business email compromise, and the fake is often backed up by emails from a lookalike address. In one widely reported 2024 case in Hong Kong, an employee made transfers after a video call in which the other participants, including a senior finance executive, were deepfakes.
The relative in trouble
A parent or grandparent gets a call from what sounds like their child or grandchild saying they’ve been arrested, in an accident or stranded, and need money now. The voice may be cloned from short clips posted online. Sometimes a second person comes on the line as a “lawyer” or “police officer”. Our guides to AI voice cloning scams and grandparent scams go deeper on this version.
The celebrity endorsement
A video ad or social post shows a well-known entrepreneur, TV host or actor apparently recommending an investment platform, a crypto giveaway or a miracle product. The clip is generated or edited. The link leads to a site that takes deposits and shows fake profits. Our guide to crypto scams covers the investment side.
The fake romantic partner
Scammers running fake relationships can now use face-swapping on video calls, removing one of the old warning signs, that they would never turn on their camera. A video call is no longer proof that someone is who they claim to be.
The fake explicit image
Scammers generate explicit images of a real person from ordinary photos and threaten to share them unless paid. This is sextortion using fake images, and the same advice applies as for real ones: don’t pay. See our sextortion help guide and the help resources page for support.
Deepfake scam warning signs
These signs are about the request, not the quality of the fake, because a good fake can look and sound right.
- Urgency. The money has to move today, within the hour, before a deadline.
- Secrecy. Don’t tell anyone, don’t call the office, don’t tell mom.
- An unusual channel. A new number, a personal messaging app, or a meeting link from an unfamiliar address.
- An unusual payment method. Gift cards, crypto, wire transfer, cash handed to a courier, or a new bank account.
- A reason you can’t call back. Their phone is broken, they’re in a meeting, the police won’t let them talk.
- Emotional pressure. Fear, panic, flattery or authority used to stop you thinking it through.
- A celebrity promising returns. Real public figures don’t personally invite strangers into investment schemes through ads.
Glitches such as odd blinking, blurry edges or robotic pauses can be clues, but their absence proves nothing.
How to protect your family
- Agree a family code word or question that only your household would know and that isn’t posted anywhere online. Anyone calling in an “emergency” should be able to give it.
- Agree a callback rule. If anyone calls asking for money, the rule is to hang up and call the person back on their usual number, or call another family member.
- Talk to older relatives about these calls before they happen. Knowing the pattern in advance makes it much easier to pause.
- Limit public voice and video where it’s easy to. Public videos of you speaking can be used as source material, so consider who can see them.
- Be wary of unknown callers who ask you to say “yes” or talk at length. Let unknown numbers go to voicemail if you prefer.
How to protect a business
- Make verification a rule, not a judgement call. Any payment request, bank detail change or gift card request that arrives by call, video or message is confirmed through a known number or in person.
- Require two people to approve unusual or large payments, so one convincing call isn’t enough.
- Tell staff it’s fine to check. Leaders should say openly that they’ll never be annoyed by a callback, so employees don’t feel they’re defying the boss.
- Use internal channels for sensitive requests, and treat requests from personal accounts or new numbers with extra suspicion.
- Train with realistic examples. Walk teams through a fake executive call so they recognize the pressure when it comes.
- Watch for impersonation of your brand, including fake ads using your executives’ faces or voices, and report them to the platform quickly.
Executives with a public profile are more likely to be impersonated. Our guide to executive privacy protection covers reducing what’s available about them.
What to do if you think you’ve been targeted
- Stop the conversation and don’t send money, gift card numbers, crypto or codes.
- Verify by contacting the real person through a known channel.
- If you’ve paid, contact your bank immediately using the number on your card or statement. For wire transfers, speed matters. For gift cards, contact the issuing company. For crypto, contact the exchange you used.
- Save evidence: phone numbers, call logs, voicemails, meeting links, emails, usernames and payment details.
- Report it at ReportFraud.ftc.gov and to the FBI at ic3.gov. Businesses should also tell their bank’s fraud team and review whether any accounts were accessed.
- Report fake ads or videos to the platform they appeared on, as impersonation or scam content.
A worked example
This is an illustrative scenario, not a real client. The office manager at a small engineering firm gets a voice note on a messaging app from what sounds exactly like the owner. He says he’s closing a deal while traveling, needs a deposit wired to a new supplier today, and can’t take calls because he’s in meetings. An email follows from an address that is one letter off the company domain.
- The firm has a rule that any new payee or urgent transfer is confirmed by phone. She calls the owner on the number saved in her phone.
- He answers from his hotel and says he sent nothing.
- She saves the voice note and email, reports the account on the messaging app, and forwards the details to the company’s bank.
- The owner reports it at ic3.gov and ReportFraud.ftc.gov, and reminds staff that he’ll never ask for a payment that skips the callback rule.
The fake was convincing. The process, not her ear, is what stopped it.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditIf someone uses a deepfake of you
If your face or voice is used in a scam, people may think you were involved. Move quickly.
- Report every copy to the platform as impersonation or synthetic media. Our guide on online impersonation covers the routes.
- Post a clear statement on your real accounts saying the video or ad is fake and you’ll never ask for money.
- Tell your employer or clients if the fake uses your professional identity.
- Keep records of where the fake appears, with links and dates, and talk to a lawyer if it’s damaging your business or career.
If fake content about you is appearing in search results, our personal reputation management service can help assess what can be removed or pushed down.
Common mistakes to avoid
- Trusting a video call as proof of identity. Faces can now be swapped live.
- Calling back the number that called you, or one given in the message, instead of a number you already had.
- Relying on spotting glitches. Good fakes don’t have obvious ones.
- Keeping it secret because you were told to. Secrecy protects the scammer, not the person asking.
- Paying someone to recover the money. Follow-up “recovery” offers are usually another scam. See our guide to recovery scams.
Frequently asked questions
Can a deepfake scammer really copy someone's voice?
Yes. Voice-cloning tools can produce a convincing imitation from recordings of someone speaking, which is why many public videos and voice notes are enough source material. That’s why a callback to a known number or a family code word is more reliable than trusting the voice.
How do I know if a video call is a deepfake?
Sometimes you’ll notice odd lighting, blurring around the face or lip movements out of sync with speech, but convincing fakes may show none of these. If the call involves money or sensitive information, end it and verify through a channel you already know.
Is a celebrity investment video real?
Treat any ad or post in which a celebrity personally recommends an investment, crypto platform or giveaway as a likely scam. Check the person’s verified official accounts and reputable news sources, and never deposit money through a link in the ad.
Where do I report a deepfake scam?
Report to your bank first if you’ve paid, then to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov. Report the fake video, ad or account to the platform it appeared on.