Verify the request, not the voice: why spotting the deepfake is the wrong defence
Overview
A finance worker at the engineering firm Arup joined a routine video call. The company’s chief financial officer was on it, along with several colleagues he recognised — the right faces, the right voices. Over the call he was asked to move money for a confidential deal, and afterwards he did: about US$25.6 million (HK$200 million) across 15 transfers. Every other person on that call was a synthetic fake. He was the only real human in the room.
Why this is a 2026 lesson and not a 2024 curiosity: on 6 April 2026 the FBI released its 2025 Internet Crime Report, logging US$20.9 billion in reported losses — up 26% on the year — with business email compromise the second-biggest source of cyber-enabled fraud losses at US$3.05 billion, and more than 22,000 complaints flagged as AI-related. Four months earlier, in December, the Bureau issued a fresh alert on impersonators using “AI-generated voice messages” and deepfakes to reach people through the channels they trust.
The reflex this module retires is the one that feels most natural: getting better at spotting the fake.
The content
The obvious defence is detection. Listen for the flat note in the voice, watch for the eyes that don’t quite track, learn the tells. The overturn is that this is a treadmill you lose. The Arup worker had doubts — his first thought was that the email smelled like phishing — and the call talked him out of them, because the faces and voices were good enough. Detection asks you to out-perceive a system built specifically to beat perception, at the very moment it has engineered the pressure to act. The tells will only get rarer from here.
So stop authenticating the person and authenticate the request. Call it verify the request, not the voice: you are not trying to prove who is on the call, you are confirming that the thing being asked for is real, through a channel the person contacting you does not control. A genuine CFO asking for a genuine transfer survives a call back to the number in your directory. A fake does not. You never have to win the argument about whether the voice was real — you route around it.
That is exactly what the FBI now recommends, in plain terms. Don’t respond on the channel that reached you: “independently identify a phone number for the person and call to verify.” If someone you know surfaces on a new number or app, “verify the new contact information through a previously confirmed platform.” Agree “a secret word or phrase” in advance with the people you’d actually move money or data for. And before sending anything, “independently confirm their contact information prior to taking action.” None of it depends on catching a glitch. All of it depends on refusing to treat an inbound call as proof of anything.
The signature to train yourself on is not visual, it’s structural: urgency, secrecy, and a request for money, credentials or access, arriving through a channel you didn’t initiate. That combination is the alarm — the confidential deal that can’t wait and mustn’t be discussed. The pressure isn’t incidental. It is the attack, purpose-built to stop you doing the one boring thing that defeats it: hanging up and dialling back on a number you already trusted.
Try it
No prompt to memorise — a standing rule to write once and keep.
Pick the one inbound request you actually receive and act on:
a payment or bank-detail change, a password or MFA reset, an
"urgent, confidential" ask from someone senior, an invoice redirect.
Write your two lines for it:
TRIGGER — the request type, plus the tell: urgency + secrecy +
money/credentials/access, arriving on a channel I didn't start.
VERIFY — the exact second channel I will ALWAYS use before acting:
the number in our directory (not the one that called), a message
on our known work app, a code word, or a second person's sign-off.
Then say it out loud to the people it protects — so when the real
call comes, dialling back is the expected move, not the awkward one.
Where it breaks, deliberately: notice that everything above is designed to be overridden in the moment. “This is strictly confidential — don’t loop anyone in.” “The deal falls over if we don’t move now.” That script exists precisely because the callback is the defence, so the attack’s whole job is to make the callback feel rude, paranoid, or career-limiting. Decide now that you’ll wear the two minutes of awkwardness every time. The one call where it matters will not announce itself as the one that matters.
Additional reading
- Impersonation Campaign Alert (PSA I-121925-PSA) — FBI IC3 (2025-12-19) — the Bureau’s most recent alert on AI-voice and deepfake impersonation, and the source of the verbatim verification steps above: independently find the number and call back, confirm a new channel through an old one, agree a secret phrase.
- 2025 Internet Crime Report — FBI IC3 (2026-04-06) — the US$20.9 billion total, business email compromise at US$3.05 billion (second by loss among cyber-enabled fraud), and 22,364 complaints flagged as AI-related.
- Arup revealed as victim of $25 million deepfake scam — CNN Business (2024-05-16) — the Hong Kong video-call case: familiar faces and voices, all synthetic, and a loss discovered only after the worker checked with the real head office.
Editor’s note
I heard a story last week, retold to me after travelling through a number of people, about a deepfake scam that a distant acquaintance encountered. It was sophisticated to the point where I, as a hyper-aware internet-era millennial, considered whether or not I would fall for it. We all have different instincts for detecting fraud, but we really are entering a new era and it’s important to define your rules while they are still abstract, because you don’t know what it might feel like the moment a good fake is rushing you while you work.
// three assertions against what you just read · results stay in this browser
The module argues that learning to spot the tells of a fake voice or video is a losing defence. What does it say to do instead?
Your CFO video-calls you on WhatsApp — the face and voice check out, and two colleagues you recognise are on the call — asking for an urgent, confidential payment to close a deal today. What should you do?
You've written your two-line trigger-and-verify rule and shared it with your team. Where does the module warn this defence is still most likely to break?
Was this useful for your daily work?