Artificial intelligence continues to progress at a rapid pace. It's helping businesses write documents, analyse data, automate routine tasks and improve productivity.
Unfortunately, the same technology is also being used by cyber criminals.
One of the fastest-growing concerns is the rise of deepfakes. AI-generated audio, video and images that convincingly imitate real people. While deepfakes first gained attention because of fake celebrity videos shared online, they're now being used in much more practical ways to deceive businesses.
The challenge is no longer simply recognising a suspicious email. Businesses must now consider a future where voices, faces and even live video calls can be manipulated by AI.
The good news is that protecting your organisation isn't about becoming suspicious of everyone. It's about strengthening the business processes that already keep your organisation safe.
What is a deepfake?
A deepfake is content created or altered using artificial intelligence to make someone appear to say or do something they never actually said or did.
This can include:
Videos
Voice recordings
Images
Live video impersonation during online meetings
Modern AI systems can learn someone's voice from surprisingly little publicly available audio. They can also generate realistic facial movements and expressions that make fake videos difficult to distinguish from genuine ones.
While some deepfakes are created for entertainment, others are designed to commit fraud.
See the Technology for Yourself
Before we talk about the risks, it's worth seeing what modern AI can already achieve.
Watch this deepfake demonstration on YouTube
Why businesses should be CONCERNED
Many cyber attacks rely on creating trust. For years, criminals impersonated banks, suppliers and colleagues using email. Now AI allows them to go much further.
Imagine receiving:
a Microsoft Teams call from someone who appears to be your Managing Director
a voicemail from your finance director requesting an urgent transfer
a WhatsApp voice message from a supplier explaining that their bank account has changed
a Zoom meeting where everyone appears genuine
If your normal process relies on recognising a familiar face or voice, AI is beginning to challenge that assumption.
A real-world example
Earlier this year, a finance employee at the Hong Kong office of a multinational company joined what appeared to be a routine video conference.
Everyone on the call looked genuine, including senior colleagues.
During the meeting, the employee was instructed to authorise a series of payments.
Only later did they discover that every other participant on the video call had been created using AI-generated deepfake technology.
The business reportedly lost around US$25 million before the fraud was discovered. Read the full article here
This isn't just a problem for large organisations
It's easy to assume criminals only target multinational companies.
In reality, smaller businesses often have:
fewer approval processes
smaller finance teams
less formal verification procedures
limited security awareness training
These characteristics can make smaller organisations attractive targets.
AI tools have also become significantly cheaper and more accessible. Criminals no longer need specialist skills to create convincing impersonations.
How attackers build convincing deepfakes
Most people already share a surprising amount of information publicly.
LinkedIn profiles identify job roles.Company websites often include leadership biographies and videos.Podcasts, webinars and conference presentations provide clear voice recordings.
Social media offers photographs from multiple angles.Individually these pieces of information appear harmless.
Combined together, they provide AI systems with enough material to imitate someone remarkably well.
It's not about spotting the fake
One common misconception is that employees simply need better training to recognise deepfakes.
While awareness is important, even experts can struggle to distinguish sophisticated AI-generated content.
The better approach is to ensure important decisions never rely on one communication alone.
Whether a request arrives by email, telephone, Microsoft Teams or WhatsApp shouldn't matter if your approval process requires independent verification.
Good business processes remain effective regardless of how realistic the technology becomes.
Practical steps every business can take
Verify financial requests
Any request to:
transfer money
change bank details
purchase gift cards
send confidential information
should be independently verified using a trusted contact method.
Don't reply directly to the message.
Use a known telephone number or previously established contact details.
Introduce dual approval
High-value payments should never rely on one person's decision.
Requiring a second authorised approver significantly reduces the risk of fraud.
Slow down urgent requests
Many scams rely on creating pressure.
Phrases like:
"I need this done in the next ten minutes."
or
"Don't tell anyone yet."
should immediately encourage additional verification.
Can technology help?
Security platforms can reduce many of the risks surrounding phishing, account compromise and malicious websites.
Identity management, Multi-Factor Authentication (MFA), email security and endpoint protection all remain essential.
However, technology alone cannot determine whether someone genuinely intended to authorise a payment during a conversation.
Combine good technology with sensible operational procedures and ongoing staff awareness.
WE’RE HERE TO HELP
At Roadmap IT, we help businesses combine practical security advice with modern technology to reduce cyber risk without making everyday work more complicated. If you'd like to review your current security processes or understand how AI is changing the threat landscape, we’re here to help.
