DeepFake: Is it really you?

أغسطس 26, 2026

DeepFake: Is it really you?

When a face and a voice on a video call can no longer be trusted, verification becomes a business critical control, not an IT afterthought.

In May 2026, a Singapore business professional joined what looked like a legitimate Zoom call with Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, and other senior officials, discussing urgent funding tied to the Strait of Hormuz crisis. Every person on that call was fake. The Singapore Police Force confirmed the meeting was fabricated using deepfake AI, built from stitched-together footage of real officials. The victim wired at least S$4.9 million (roughly US$3.8 million) before realizing the deception. Deepfake fraud is no longer a novelty. It is a working attack method, already landing in Gulf and Asian markets alike.

A Threat That Has Moved From Novelty to Routine

This was not an isolated case. The scam began with a WhatsApp message from someone posing as a trusted official,followed by forged documents and a fabricated video call built to manufacture urgency and legitimacy. Days later, Singapore police disclosed a related case in which a company transferred US$36.3 million after an executive received a deepfake assisted impersonation call. In 2024, engineering firm Arup lost US$25.6 million in Hong Kong the same way:a video call populated entirely by deepfaked colleagues.
The data confirms this is accelerating. Gartner’s 2025 survey found 62% of organizations had experienced a deepfake attack in the prior 12 months, and a separate Gartner survey found 41% had encountered a deepfake combined with social engineering on an audio call. Pindrop recorded a rise of over 1,300% in deepfake fraud attempts across contact centers year over year. Entrust’s 2026 Identity Fraud Report found deepfakes now account for roughly one in five biometric fraud attempts.

Why Human Judgment and Detection Tools Both Fall Short

People are not equipped to catch this on sight. A 2025 iProov study found only 0.1% of participants could correctly distinguish every real and fake sample shown to them, and high-quality video deepfakes are correctly identified by human viewers only around a quarter of the time.Automated detection helps but isn’t a complete answer either. AI detection tools report accuracy up to 90 to 96% under lab conditions, but real-world performance drops substantially against novel generation techniques and compressed call footage. Gartner projects that by 2026, 30% of enterprises will no longer treat identity verification alone as a reliable fraud control. This is precisely the kind of judgment call GRC and identity risk assessments exist to make explicit, and it is where firms like Cybrt work with organizations across the Gulf to reassess what their verification processes actually depend on.

Rebuilding Verification Around the Assumption That Screens Can Lie

If a convincing face or voice can now be fabricated in real time, the fix isn’t a better filter on the call. It’s redesigning the process around it so no single call, message, or video is ever sufficient on its own to move money or grant access:
• Out-of-band verification for high-value requests: calling back through an independently known number, never one supplied by the requester.
• Multi-person approval for wire transfers above a set threshold, so no single employee can authorize a transfer alone.
• Scheduled deepfake simulations, run at least quarterly, testing staff against realistic impersonation rather than generic phishing.
• Building an awareness culture through ongoing training, not a once-a-year module, so recognizing urgency, secrecy, and authority pressure becomes second nature at every level of the organization, not just in finance and IT.
• Monitoring of payment and account-change workflows for the urgency and secrecy patterns that precede fraud,the kind a managed CSOC can flag before funds leave the organization.
• Incident response playbooks written specifically for executive impersonation, since standard phishing runbooks rarely account for a fabricated video call from a “known” face.

None of this requires abandoning video conferencing or voice authentication. It requires accepting that neither can carry the full weight of a financial decision alone, and building the process controls, GRC documentation, and monitoring, the areas Cybrt works in across NCA ECC and SAMA-aligned environments, to compensate for a channel that can no longer be taken at face value

The Takeaway

Deepfake fraud has moved past headline grabbing curiosity into a routine line item on fraud reports, and the organizations getting hit aren’t careless ones. They’re businesses that still trust a familiar face and an urgent request on a video call. The defense isn’t sharper eyesight. It’s a verification process that assumes, correctly, that the screen can lie.

هل أنت مستعد لحماية أعمالك التجارية؟

احجز استشارتك الأمنية المجانية اليوم