Back to the glossary
    Social engineering & phishingCybersecurity glossary

    Deepfake

    Synthetic audio or video that imitates a real person. Applied to fraud, it turns a video call or voice note into an impersonation tool.

    Full definition

    A deepfake is AI-generated audio or video content that convincingly imitates the voice or image of a real person. Applied to corporate fraud, it lets an attacker appear on a video call or send a voice note with an executive's face and voice.

    The typical criminal use case complements BEC and vishing: the victim doubts the email requesting a transfer, and the fake call or video call from the boss dissolves that doubt. A few seconds of public audio are enough to clone a voice well enough for phone fraud.

    Defense cannot rely on spotting the fake by eye. It relies on process: alternate verification channels, agreed code words, and the rule that no payment instruction is executed just because a familiar face or voice requested it.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.