**How to Protect Your Company from AI-Generated Deepfake Scams**
In January 2024, something shocking happened at professional services firm Arup. During a video call, employees believed they were speaking with the company’s CFO, but every participant on the other side was an AI-generated clone. The result? 15 wire transfers to third-party accounts totaling around $25 million. This incident highlights a frightening new reality: **Deepfakes and AI clones are getting more sophisticated and harder to detect**, and traditional security measures are struggling to keep up.
According to experts like Deepak Gupta from GrackerAI and James Scobey from S2i2, the solution might be simpler than you think—relying on low-tech security protocols that offer better defenses against these advanced threats.
## There Are No Obvious Tells
For most of corporate history, live voice and video calls have been the gold standard for verifying identity. These methods were central to authenticating high-value transactions, sharing sensitive medical data, and discussing legal matters. However, in the last five years, deepfake technology has quietly eroded this standard.
Deepfakes have improved to the point where they can mimic human behavior convincingly. There used to be tells—background noises, synthetic voice modulation, lack of breathing sounds—but those signs are disappearing. A University College London study found that listeners could accurately identify deepfakes only about 73% of the time, and even with training, accuracy improved by just 3.84%. Researchers from the University of Duisburg-Essen and Indiana University later aggregated results from 56 similar studies, finding that human detection rates were closer to chance.
As James Scobey of S2i2 explained, “Tells still have marginal value as a supporting signal,” but relying on them as an effective control is no longer an option. These scammers target the very sense employees rely on during attacks—perception.
What’s more concerning is that attacks are evolving from one-off financial scams to long-term infiltration of company systems. In a 2024 incident involving security training firm KnowBe4, attackers posed as employees during interviews and even received company workstations before being identified as North Korean operatives using the devices to upload malware.
## Old-Fashioned Is Best
Where advanced detection models and standard security measures fail, analog solutions that rely on a single controlled point of entry prove much more effective.
“The defense against the most advanced AI attack is often deliberately low-tech,” said Gupta. While deepfake technology is excellent at replicating publicly accessible appearances and voices, it’s useless against anything outside observable channels that can’t be spied on remotely.
Rather than relying on automated detection that looks for evidence of manipulation in voice or video (which may no longer be reliable), security experts now recommend hardware-based security keys and verbal passphrases. CISA, under the US Department of Homeland Security, now recommends FIDO2 and PIV hardware credentials as the new gold standard for multi-factor authentication (MFA). Secret verbal passphrases shared between workplace members are also frequently recommended by the FBI.
A verbal passphrase is a secret word or phrase shared during a call. Employees can verify the person on the other end by asking them to say the passphrase. However, these are only effective if used consistently by everyone in the organization. Gupta noted that employees often skip security checks when feeling intimidated, especially when the person on the other end presents as a superior.
To be effective, low-tech solutions need to be scalable for larger organizations. Here are best practices for verbal passphrases:
– Don’t create them manually; use a random password generator
– Use unrelated words separated by random numbers and symbols (e.g., “harley9jedi@buddies.sinclair”)
– Maintain separate passphrases for different roles and transactions
– Reset passphrases periodically, but not on a fixed schedule
– Combine passphrase authentication with other security protocols (hardware keys, out-of-band callbacks, dual authentication)
It’s better to use a random password generator since human minds have subconscious biases that make passphrases easier to guess. “The strength comes from the randomness of the selection,” Scobey added, “not from how meaningful the words are.”
Larger organizations should implement role- and relationship-based passphrases specific to certain transactions and employee roles. If one passphrase is compromised, it can be reset while others stay intact. Passphrases should be rotated frequently but not according to a fixed calendar. NIST guidelines now suggest overturning the 90-day password reset rule because it creates predictability. Instead, replace passphrases when there’s evidence of compromise, role change, or employee offboarding.
For high-value transactions in large enterprises, a verbal passphrase alone isn’t enough. It must be combined with other protocols like out-of-band callbacks and dual authorization—authenticating requests through more than one official communication channel and requiring a second authorized employee to validate the request.
While companies may resist adding more hurdles to their security systems, the goal isn’t to add friction everywhere but to confine it only to high-risk exposure workflows. “When people experience security as targeted rather than blanket, they stop trying to bypass it,” Gupta said.
—
## FAQ
**Q: What is a deepfake, and why is it dangerous for businesses?**
A deepfake is AI-generated content that mimics a person’s appearance, voice, or behavior. In business, deepfakes can be used to impersonate executives during video calls, leading to financial fraud, data breaches, or long-term system infiltration.
**Q: Why are traditional security measures failing against deepfakes?**
Traditional automated detection protocols that look for manipulation evidence in voice or video are becoming ineffective. Deepfake technology has advanced to the point where detectable traces are rare or nonexistent, and human detection rates have dropped to near-chance levels.
**Q: What are verbal passphrases, and how do they work?**
Verbal passphrases are secret words or phrases shared between participants during a call. Employees authenticate the person on the other end by asking them to repeat the passphrase. They must be used consistently across the organization and combined with other security measures for high-value transactions.
**Q: How can my organization create strong verbal passphrases?**
Use a random password generator to create unrelated words combined with random numbers and symbols. Avoid manually created phrases since human biases make them easier to guess. Maintain separate passphrases for different roles and transactions.
**Q: Are hardware security keys necessary if we use verbal passphrases?**
For high-value transactions, yes. Experts recommend combining verbal passphrases with hardware-based security measures like FIDO2 keys and out-of-band callbacks for layered security. Low-tech solutions work best when used together as part of a comprehensive strategy.
—
## Conclusion
The Arup incident serves as a wake-up call that AI-powered cyber fraud is no longer a future threat—it’s a present reality. As deepfake technology continues to evolve, traditional security measures based on visual and audio verification are becoming obsolete.
The good news is that effective defenses exist. By returning to low-tech, analog security protocols like hardware-based authentication and randomly generated verbal passphrases, organizations can build robust defenses against even the most sophisticated AI attacks.
The key is to implement these measures strategically—focusing on high-risk workflows rather than creating blanket security that slows down operations. In a world where seeing and hearing are no longer proof of reality, sometimes the simplest solutions are the most powerful defenses against an increasingly digital threat landscape.



