Deepfakes 101: Examples and deepfake fraud prevention tips
Far from a distant threat or centerpiece of science-fiction literature, modern deepfakes have become incredibly advanced, posing serious threats to consumers and organizations alike. As of the end of 2024, deepfake fraud costs U.S. businesses more than $1 billion annually. Complex deepfake scams have tricked many people into forfeiting thousands, even millions, of dollars.
Deepfakes pose an extreme threat to society. And they’re just getting started: deepfake instances are projected to increase by 495% before the end of 2026. It’s imperative that consumers and business leaders alike equip themselves with the knowledge to thwart deepfakes — if not by eye, then with the aid of AI tools.
In this post, we’ll cover everything you need to know about deepfakes, including how the technology works well enough to fool a live video call, what documented incidents have cost businesses as of 2026, and the prevention steps that reduce exposure right now.
What are deepfakes?
A deepfake is synthetic or manipulated media, typically video, audio, or images, generated by AI models trained to convincingly replace or fabricate a person's likeness or voice.
Early deepfakes were uncanny but usually included artifacts that indicated fabrication. For example, in a deepfake video of someone speaking, the mouth might not match the audio exactly. Or, in a more famous example, the person employing a deepfake mask might be unable to successfully hold up three fingers.
But these deepfake “tells” are starting to fade as AI technologies improve rapidly. Now, fraudsters can successfully generate a convincing deepfake for a fraction of the cost just two years ago. It’s easier than ever for fraudsters to impersonate a specific executive, employee, or customer well enough to defeat a phone call, a video meeting, or a remote verification check.
How deepfakes work
Deepfake technology ranges from convincing voice clones to fully fabricated, lifelike video, most of it built on generative adversarial networks (GANs) or autoencoders that substitute or superimpose one person's facial features and expressions over someone else's. These can be pre-recorded or generated in real time through a manipulated webcam feed, which is how fraudsters run live impersonation calls rather than just sending a pre-made clip.
The part that should concern any finance or security leader is cost and speed. Voice cloning tools now need only a few seconds of sample audio, often pulled from a public earnings call, interview, or LinkedIn video, to produce a convincing match. That's why voice-based impersonation scams targeting finance teams have scaled so quickly: the barrier to running one dropped from specialized skill to a few minutes of setup.
Types of deepfakes
Not all deepfakes work the same way, and the type matters for how you defend against it.
1. Face swap deepfakes
These deepfakes superimpose one person's face onto another's body or existing footage. This is the category behind most celebrity examples and a lot of video-call impersonation fraud.
2. Voice cloning deepfakes
Voice clone deepfakes recreate a specific person's voice from a short audio sample, commonly used in phone-based executive impersonation scams.
3. Full-body or synthetic avatar deepfakes
Full-body or synthetic avatar deepfakes generate an entire person, including movement and expression, rather than swapping features onto existing footage. This is the category behind the most convincing live video-call fraud, including the Arup case below.
4. Text-to-video and lip-sync deepfakes
These deepfakes sync fabricated speech to a real or synthetic face, commonly used for fabricated statements and misinformation.
Notable deepfake examples
The most useful deepfake examples fall into two very different buckets: demonstrations built to show what the technology can do, and incidents built to extract money or access. Business leaders should understand both, because the same underlying tools power each.
Public figures and celebrities
Oprah Winfrey has become a recurring target for deepfake supplement scams, with the Better Business Bureau logging over 150 reports tied to a single fake-endorsement campaign in recent months, including victims who lost hundreds of dollars each.
Elon Musk remains one of the most commonly deepfaked public figures in investment and cryptocurrency scam videos, with fabricated endorsement clips convincing victims to send money directly to fraudsters.
Business fraud and identity theft
In 2024, employees at engineering firm Arup joined what appeared to be a routine video call with company executives, all of whom were deepfakes, and authorized transfers totaling $25.6 million before the fraud was caught. That incident is now a standard reference point for why voice and video can no longer be treated as sufficient proof of identity in a high-stakes approval process.
More recently, in January 2026, a business owner in Switzerland was contacted over a series of calls using AI-manipulated audio impersonating a trusted business partner, and transferred several million Swiss francs before the deception was discovered. Voice and video impersonation fraud is still active years after the first cases made headlines.
The evolution of deepfake technology
What matters for a business decision isn't the technology's history so much as its trajectory. The tools have gone from expensive and rare to cheap and accessible in under a decade, which is exactly why deepfake fraud has moved from novelty to mainstream attack vector.
Early instances and key developments
Deepfakes as a recognizable category date to the mid-2010s. Early attempts, including Lucasfilm's 2016 use of the technology to superimpose Carrie Fisher and Peter Cushing's likenesses onto other actors, were resource-intensive and only moderately convincing. That's no longer the constraint. The same generation of tooling that once required specialized skill and significant compute now runs on consumer hardware, which is the main reason attack volume has grown so fast.
The role of AI and machine learning
Most deepfakes today are produced with GANs. A generative algorithm produces the fake while a discriminative algorithm tries to catch it, and the generator improves until the discriminator can no longer reliably tell the difference. Combined with autoencoders and natural language processing (NLP), this is what makes real-time voice cloning and lip-syncing accessible to an attacker with no specialized background.
Why deepfakes are so dangerous
For a business, the risk breaks down into two categories: reputational and informational harm on one side, and direct financial exposure on the other. The second is where the numbers are largest and growing fastest.
Misinformation and fake news
Fabricated statements, manipulated executive commentary, and impersonated public communications can cause real reputational and market damage even when no money changes hands directly, particularly for public companies and regulated industries where a fabricated statement can move a stock price before it's debunked.
Identity theft and financial fraud
This is the category with the clearest deepfake statistics available. Entrust's 2026 Identity Fraud Report, drawing on more than a billion identity verifications across 195 countries, found that deepfakes now drive roughly 1 in 5 biometric fraud attempts globally, with deepfaked selfie attempts up 58% year over year. A 2025 Gartner survey found 62% of organizations had experienced at least one deepfake attack in the prior 12 months. Attacks in this category span account takeover, blackmail, stock manipulation, and the executive-impersonation wire fraud covered above.
How to identify deepfakes
Detection splits into two layers: what a trained employee can catch by eye, and what requires purpose-built technology. Relying on the first alone is no longer a defensible position for any high-value process.
Visual and audio cues
Awareness training still has value, and the tell-tale signs of a deepfake are worth knowing:
- Inconsistent audio or poor lip-syncing
- Unnatural coloring, reflections, or shadows
- Little to no blinking, or unnatural eye movement
- Stiff or unnatural facial and body movement
- Visual artifacts that appear when footage is zoomed in
- Small details (jewelry, hair, buttons) that look off, blurred, or misaligned
However, our senses are no longer reliable when it comes to deepfakes. Research shows that fewer than 0.1% of people can reliably detect deepfake videos. As the technology further improves, this gap will widen.
Technological solutions for detection
As deepfakes improve, the most reliable method of detection and prevention, particularly for businesses, has become AI-based identity verification (IDV).
Advanced IDV detects deepfakes with far greater accuracy than the human eye. And the right system relies on machine learning (ML) to keep pace with emerging deepfake technologies, improving in minutes, not months.
Solutions like Incode Deepsight spot deepfakes using multi-layered analysis:
- Perception Layer: Using a world-class, multi-modal AI that examines thousands of data points across multiple frames, motion, and depth data, Deepsight detects deepfakes and physical spoofs in captured selfies. It also protects ID captures from AI-generated content by running its own proprietary ML model that was trained on thousands of AI-generated ID cards. As a result, Deepsight is able to accurately detect >99.99% of deepfakes and synthetic ID images.
- Behavioral Layer: Deepsight monitors user behavior to identify fraudulent patterns and ensure authentic interactions. This includes analyzing motion dynamics, detecting suspicious bot-like behavior, and verifying natural user activity.
- Integrity Layer (Device): Deepsight detects fraudulent attempts by analyzing device signals. This includes identifying suspicious devices, virtual emulators, and fingerprint anomalies.
- Integrity Layer (Camera): Deepsight safeguards camera integrity by identifying fraudulent attempts through analysis of camera interactions. This includes detecting virtual cameras and tampering to ensure live, unaltered video feeds and authenticity.
How to prevent deepfake fraud
For businesses, a few concrete steps reduce exposure to deepfake fraud meaningfully:
- Never rely on voice or video alone for high-value approvals: Require a second, independent verification channel for any wire transfer, credential change, or access request initiated over a call or video meeting.
- Layer automated detection into onboarding and verification flows, rather than depending on a human reviewer to catch manipulated media: Combine liveness detection with deepfake-specific signals to catch both presentation attacks and injection attacks.
- Watch for injection-style attacks specifically: These bypass a physical camera entirely by feeding fabricated video straight into a verification system, and they've grown significantly faster than camera-based deepfakes over the past year.
- Build a response plan before an attack happens: A large share of companies still have no defined process for a suspected deepfake incident, which turns a containable event into a scramble.
- Apply the same scrutiny to hiring and workforce verification: Deepfakes are increasingly used to fabricate candidate identities during remote interviews, which makes candidate verification as important as customer-facing checks.
- Extend verification thinking to agentic and automated workflows: As more transactions are initiated or approved by AI agents rather than people directly, verifying the identity behind an agentic request matters as much as verifying a human one.
Strategies to combat deepfake fraud
Beyond individual best practices, the broader fight against deepfakes plays out on two fronts: regulation and technology.
Legal and regulatory approaches
Regulation is catching up, if unevenly. Dozens of U.S. states have enacted some form of deepfake-related legislation in recent years, and the EU AI Act now requires labeling or disclosure of AI-generated content in many contexts. Even so, legal recourse remains slower than the pace of the technology, which is why technological and procedural defenses still carry most of the weight today.
Technological defenses
Beyond detection software, digital signatures can help authenticate content at the point of creation. Growing databases of known deepfakes allow new content to be checked against existing "digital fingerprints," and detection platforms increasingly rely on deep learning to flag manipulated media the way security software flags malware.
Where is deepfake technology heading next?
A single deepfake is becoming one component in a larger, autonomous attack rather than the whole event. Incode's agentic fraud research documents AI agents that now run an entire fraud workflow end to end, generating synthetic media, submitting it, reading why an attempt was rejected, and adjusting automatically across hundreds of parallel sessions at once. Digital injection attacks, which bypass a physical camera entirely, have grown 55% year over year as a result.
For businesses, this means today's prevention steps are necessary but no longer sufficient on their own. Verification increasingly needs to defend against adaptive, machine-driven attacks that test and retry automatically, which is exactly what Incode's agentic identity solution is built for: confirming there's a real, authorized person behind a given interaction, whether an AI agent is involved or not.
Want to see how Incode's fraud detection and deepfake detection technology can protect your business? Request a demo today.