The Old Scams Feel Almost Quaint
We all learned the rules of the road for spotting online scams. For years, cybersecurity training has drilled employees to look for the classic red flags: phishing emails riddled with typos, generic greetings like “Dear Valued Customer,” and suspicious
links from unknown senders. These were the obvious, low-effort attacks. The core message from security teams was simple: be vigilant, don't click strange links, and use common sense. The annual reminders during Cybersecurity Awareness Month, led by the Cybersecurity and Infrastructure Security Agency (CISA), focused on foundational practices like using strong passwords and enabling multi-factor authentication (MFA). These are still crucial habits, but they were designed for a threat landscape that is rapidly becoming a relic of the past. The attackers have evolved, and their new tools are dismantling the old defenses one convincing fake at a time.
Enter the Hyper-Realistic Impersonator
The new problem isn’t an email from a Nigerian prince; it’s a video call that appears to be from your own CEO. Generative AI has made it frighteningly easy for criminals to create “deepfakes”—hyper-realistic audio, image, or video forgeries of real people. Modern AI models can clone a voice from just a few seconds of audio, perhaps lifted from a podcast or a company-wide video message. These cloned voices are then used in “vishing” (voice phishing) attacks, where an employee receives an urgent call from what sounds exactly like their boss instructing them to transfer money or share sensitive data. In one now-infamous case, a finance worker in Hong Kong was duped into transferring $25 million after attending a video conference where every single participant, including the CFO, was a deepfake. The scam isn’t just a fake email anymore; it’s a full-sensory assault on an employee’s trust, complete with familiar faces and voices that are nearly impossible to distinguish from reality.
Why Your Brain Is Wired to Fall for It
Traditional phishing attacks preyed on carelessness. Deepfake scams prey on human nature. When you receive an urgent request from someone who looks and sounds like your boss, your brain’s natural instinct is to comply, not to question their authenticity. These attacks exploit authority and urgency, but with a powerful layer of fake sensory “proof” that bypasses our usual skepticism. Scammers know this and combine the deepfake with high-pressure tactics. The request is always urgent, confidential, and critical to the business. The pressure to act quickly prevents the target from pausing to think critically. While early deepfakes had tells—like unnatural blinking or a robotic tone—the technology is improving at an exponential rate. Attackers no longer need significant technical skill, making these sophisticated attacks scalable and widespread.
Rethinking 'Awareness' in the AI Era
If seeing and hearing is no longer believing, then cybersecurity awareness can no longer be a passive exercise. This year, experts and security firms are shifting the focus from just “awareness” to active “verification.” The new guidance acknowledges that even savvy employees can be fooled by a convincing deepfake. The solution isn't just to spot the fake; it's to build processes that don't rely on a single channel of communication for sensitive actions. Instead of simply training employees to look for red flags, companies must create a culture of healthy skepticism where questioning an unusual request is standard procedure. This marks a fundamental shift from spotting bad grammar to questioning a seemingly legitimate video call from a senior executive.
What Companies and Employees Must Do Now
The defense against AI-driven scams is both technological and human. For companies, the first step is updating training to include examples of deepfake audio and video. The next is to establish strict, multi-channel verification protocols. For any financial transfer or data request that is unusual or urgent, employees must be required to verify it through a separate, trusted channel. For example, if a request comes via email, the employee should call the person back on a known phone number from the company directory to confirm. Some organizations are even implementing verbal “code words” for highly sensitive transactions. For employees, the rule is simple: stop, think, and verify. Never trust a single point of contact for an urgent, high-stakes request, no matter how convincing it seems. If you receive a strange call, hang up and call back using an official number. The most important security tool in the age of AI isn't an app; it's the institutional habit of pausing to ask, “How can I be absolutely sure this is real?”













