
Picture this: your finance manager gets a video call from the CEO. Same face. Same voice. Same way he always clears his throat before saying something important. He needs an urgent wire transfer approved, a big one, before the market closes. So she approves it.
Except the CEO was never on that call. It was AI.
This isn’t a hypothetical. It’s already happened, more than once, and for a lot more money than you’d think. In 2024, a finance worker at a multinational firm in Hong Kong was tricked into wiring $25 million after joining a video call where every single person on screen, including the company’s CFO, was a deepfake. No one on that call was real except her.
Deepfake scams have moved from “creepy internet trick” to one of the fastest-growing ways criminals are draining bank accounts, personal and corporate. Here’s what’s actually happening, and how to spot it before it happens to you.
What Exactly Is a Deepfake Scam?
A deepfake is AI-generated audio, video, or images built to look and sound like a real person. Scammers feed the AI a few minutes of someone’s voice, pulled from a YouTube video, a podcast appearance, even a voicemail greeting, and it can clone that voice well enough to fool a spouse, a colleague, or a bank’s phone verification system.
The video version is even more unsettling. With enough footage of someone’s face, AI tools can now generate a live, moving, talking version of them in real time, which is exactly what happened on that Hong Kong video call.
Real Cases That Actually Happened
- The $25 million video call. A Hong Kong employee joined what looked like a normal company video conference with senior leadership. Every participant was an AI-generated deepfake. She transferred the money across 15 transactions before anyone realized something was wrong.
- The “kidnapped daughter” voice clone. An Arizona mother received a call from a voice that sounded exactly like her teenage daughter, sobbing and saying she’d been kidnapped. A man’s voice then demanded ransom money. Her daughter was safe the entire time, the voice was AI-cloned from social media clips.
- The fake CEO voicemail. A UK energy firm’s CEO was impersonated by an AI-cloned voice on a phone call, convincing a senior executive to wire €220,000 to a “Hungarian supplier.” The voice reportedly even carried the CEO’s slight German accent and speech rhythm.

These aren’t isolated incidents anymore, they’re becoming a pattern, and the technology behind them keeps getting cheaper and easier to access.
Why This Is Getting Worse, Not Better
- Voice cloning now takes seconds, not hours. Some tools only need 3–10 seconds of someone’s voice to generate a convincing clone.
- Everyone has a voice sample online. Instagram Reels, TikToks, podcast clips, even voicemail greetings, scammers don’t need much to work with anymore.
- Real-time video deepfakes are here. What used to require hours of rendering can now run live during an actual video call.
- Urgency still works. Deepfakes don’t need to be perfect, they just need to create enough panic that you act before you think.
7 Warning Signs You Might Be Talking to a Deepfake
1. The Request Feels Urgent and Secretive
Scammers lean hard on urgency, “don’t tell anyone,” “this needs to happen right now,” “I can’t explain, just do it.” Real financial requests, especially large ones, rarely come with that kind of pressure.
2. The Audio or Video Has Small Glitches
Look for unnatural blinking (or no blinking at all), lighting that doesn’t quite match the face, lips slightly out of sync with the words, or audio that sounds a little too clean and flat.
3. The Person Avoids Video or Refuses to Answer Direct Questions
If someone insists on staying audio-only, or a video call has a suspiciously bad connection right when you ask something specific, that’s worth pausing on.
4. Emotional Manipulation Is Front and Center
Fear, panic, and love are the three easiest emotions to weaponize. A crying “family member,” a furious “boss,” or a desperate “friend”, deepfake scams are built to bypass logic entirely.
5. The Request Involves Money, Gift Cards, or Wire Transfers
This is almost always the actual goal. If the ask eventually comes down to moving money fast, treat it as a red flag no matter how convincing the voice or face is.
6. Something Feels “Almost Right” but Off
Many people who’ve been targeted describe a strange, hard-to-explain feeling that something was slightly wrong, a pause that lasted too long, a phrase that didn’t sound like “them.” Trust that instinct.
7. They Won’t Verify Through a Second Channel
A real person will have no problem if you hang up and call them back on a known number, or confirm through a separate app or in person. A scammer will push back hard on this.

How to Protect Yourself and Your Business
Set up a verification code word. Agree on a private phrase with close family members or your executive team, something only you’d know, to use during any unusual or urgent request.
Always verify through a second channel. If you get a suspicious call, video, or message, hang up and call the person back using a number you already have saved, never one given to you during the call.
Slow down on urgency. Scammers are betting you won’t stop to think. Give yourself permission to pause, even for five minutes, before acting on any financial request.
Limit what you post publicly. The more voice and video content of you that’s public, the easier you are to clone. This doesn’t mean going dark online, just be mindful of long, clear voice clips.
Train your team. If you run a business, make deepfake awareness part of onboarding and regular security training, especially for anyone with wire transfer or payment approval access.
Use multi-person approval for large transactions. No single employee, no matter how senior the “requester” seems, should be able to approve major transfers alone.
Frequently Asked Question
How much footage does someone need to clone my voice? Some AI tools can generate a usable voice clone from as little as 3–10 seconds of clear audio, a voicemail greeting is often enough.
Can deepfake video calls really happen in real time? Yes. What once required pre-rendering now runs live during actual video calls, as seen in the $25 million Hong Kong case.
What should I do if I think I’ve already sent money to a scammer? Contact your bank immediately to attempt a transfer recall, report it to your local cybercrime authority, and document everything, the call, the messages, and any account details involved.
Are deepfake scams only targeting businesses? No. Individuals are increasingly targeted too, especially through fake “family emergency” calls using cloned voices of loved ones.
Deepfakes are only going to get more convincing. The best defense isn’t spotting perfect fakes, it’s building habits that don’t depend on trusting your eyes and ears in the moment.