The Twenty-Five Million Dollar Video Call
In early 2024, a finance employee at the global engineering firm Arup joined a video conference. On the screen were colleagues he recognised, including the company’s chief financial officer. Following their instructions, he processed 15 transfers totalling
approximately $25.6 million. The problem? Every single person on the call, aside from the employee himself, was a deepfake. This incident was not an isolated case but a dramatic example of a rapidly growing threat. Cybercriminals are now using artificial intelligence to create hyper-realistic video and audio simulations of senior executives to authorise fraudulent high-value transactions. This type of attack is particularly potent because it weaponises trust and authority. In India, the threat is escalating quickly. A 2025 report found that 47 percent of Indian adults have been a victim of, or know someone victimised by, an AI voice scam, a figure nearly double the global average. The Indian government has also issued advisories, highlighting the urgent need for stronger corporate defences.
A Framework, Not Just a Fix
In response to this sophisticated threat, leading corporate teams are moving away from single-point solutions. Instead, they are implementing comprehensive verification frameworks. This isn't about buying one piece of software; it's a strategic, multi-layered defense that integrates people, processes, and technology to create a resilient security culture. A framework acknowledges that technology alone cannot solve a problem that so effectively manipulates human psychology. The goal is to build a system where suspicious requests are not just identified but are structurally impossible to fulfil without triggering multiple, independent checks. This approach creates friction for fraudsters, making the company a much harder target and reducing the risk of a catastrophic breach born from a single moment of deception.
The Human Firewall: Training and Vigilance
The most critical component of any deepfake defense is the human element. Attackers rely on creating a sense of urgency, authority, or even panic to push employees to bypass normal procedures. Therefore, the primary line of defense is a well-trained and vigilant workforce. Companies are investing heavily in awareness training that goes beyond typical phishing emails. These programs teach employees to recognise the subtle and not-so-subtle red flags of a deepfake, such as unnatural facial movements, mismatched lip-syncing, or a flat, emotionless tone in an audio call. More advanced training involves running controlled simulations where employees are exposed to a fake deepfake call from their own CEO. This 'fire drill' approach builds muscle memory, training staff to pause, question unusual requests, and escalate concerns, even when the person making the request sounds exactly like their boss.
The Process Blueprint: Zero-Trust Verification
Robust processes form the backbone of a successful deepfake verification framework. The core principle is 'zero trust'—no urgent, high-stakes request made via a single channel like a phone call or video meeting is ever trusted outright. The most effective process control is known as out-of-band verification. If an employee receives a call, even a video call, from a supposed executive requesting a large fund transfer, the policy dictates that they must end the communication. Then, they must independently verify the request through a completely separate channel. This usually means calling the executive back on a pre-saved number from the official company directory or contacting them via a trusted internal messaging platform. Some organisations also implement verbal passphrases or code words shared only among senior leaders for use in unscheduled financial discussions, a simple but effective method to stop an impersonator cold.
The Technology Safety Net: AI vs. AI
While human vigilance and strong processes are paramount, technology plays a crucial supporting role in fighting fire with fire. A new generation of AI-powered deepfake detection tools is now being integrated into corporate communication systems. These platforms work in real-time to analyse audio and video streams for tell-tale signs of artificial generation that are often imperceptible to the human eye or ear. Tools from companies like Pindrop and Reality Defender can analyse vocal tract characteristics, background noise inconsistencies, and video artifacts to generate a risk score, alerting employees or security teams to a likely deepfake before a fraudulent transaction can be completed. By integrating this technology into virtual meeting platforms and call centre software, companies add a powerful layer of automated defense that complements and reinforces their human and process-based controls.












