SardineCon SF/2026

Learn More

O que é Executive deepfake video-call scam?

Assine a newsletter

An executive deepfake video-call scam uses a live or recorded deepfake of a senior executive on a video call to authorize urgent payments or the release of sensitive data. It takes the old fake-CEO email and gives it a face and a voice, so the request is far harder for an employee to doubt.

What is this scam?

This is business email compromise upgraded with synthetic video. Instead of an email that claims to be from the chief executive, an employee is invited to a video call where a convincing deepfake of a senior leader, sometimes several fake colleagues at once, instructs them to make an urgent wire transfer or hand over sensitive data. The face moves, the voice matches, and the request comes with authority and time pressure.

The attackers build the fakes from public material: conference talks, earnings calls, interviews, and social video that show the executive's face and voice. Layered with a plausible story, a confidential acquisition, an urgent supplier payment, a regulator deadline, the call is engineered to make the employee feel that questioning it would be insubordinate or would blow a secret deal.

For fraud teams, the key point is that seeing and hearing a person is no longer proof the request is genuine. The control that matters is not the call; it is the out-of-band verification and the payment approval process that sits behind it.

How the scam unfolds

The attack blends reconnaissance, a staged call, and a rushed payment:

  1. ReconStudy the target Attackers map who can move money, and gather public video and audio of the executives to clone.
  2. StageSet up the call An employee is invited to an urgent, confidential video meeting with a deepfaked leader or team.
  3. InstructGive the order The fake executive authorizes an urgent transfer or data release and stresses secrecy and speed.
  4. MovePush funds out fast The employee sends the payment, often split across accounts, before anyone can verify off the call.

Who is involved?

Who

Their role

The attacker

Builds and drives the deepfakes, runs the call, and controls the destination accounts.

The impersonated executive

A real senior leader whose public face and voice are cloned without their knowledge.

The employee target

A finance or operations staffer with authority to move funds or release data, pressured to act fast.

The receiving accounts

Mule or shell accounts, often overseas, that absorb the transfer and layer it onward quickly.

What it looks like in practice

A finance analyst is pulled into a last-minute video call about a confidential acquisition. On screen, the chief financial officer and two colleagues appear and sound exactly as expected. The executive explains that a deposit must be wired to the seller's counsel within the hour to keep the deal alive, and that only the people on this call can know.

The analyst, wanting to be helpful and not derail a major deal, initiates the wire and a follow-up transfer to the accounts provided. Later, a routine check with the real executive reveals no such meeting and no such deal. The people on the call were synthetic, and the funds had already been moved on through several accounts.

Why it matters for operators

Video used to be the reassurance that ended doubt. Executive deepfakes remove that reassurance, and they do it against the highest-value target in a company: the people who can authorize large payments. A single successful call can move far more than a typical consumer scam, and the funds are usually gone before verification happens.

The defense cannot live inside the call, because everything on the call can be faked. It has to live in process: mandatory out-of-band callback to a known number for large or unusual payments, dual authorization, and a culture where verifying an executive request is expected, not insubordinate. On the payment side, banks can help by flagging urgent, first-time, high-value wires to new overseas beneficiaries that break a customer's normal pattern.

What to watch in the data

  • Urgent first-time wire. A large payment to a brand new beneficiary, often overseas, initiated under time pressure and outside the usual approval chain.
  • Secrecy and bypass. Instructions to keep the payment confidential or to skip normal dual-control and verification steps.
  • Pattern break for the payer. A finance user or company moving funds in a size, destination, or speed that does not match their history.
  • Rapid onward layering. Funds that arrive and are quickly split and forwarded across multiple accounts.
  • No out-of-band confirmation. A high-value request that was never verified through an independent, known channel before release.

Quick questions

Do the attackers need a lot of source material?

Less than you might think. Executives are heavily recorded through talks, interviews, and earnings calls, giving attackers ample face and voice data to build a convincing clone.

Can the deepfake really be live?

Increasingly yes. Real-time face and voice synthesis can sustain a short, high-pressure call, and attackers keep it brief and urgent to limit the chance of the employee noticing artifacts.

How is this different from classic business email compromise?

The goal is identical, an urgent unauthorized payment, but the channel is a live video call rather than email. The added realism of a familiar face and voice makes the request much harder to challenge.

What is the single most effective control?

Out-of-band verification. For any large or unusual payment, confirm the request through a separate, known channel such as calling the executive back on a trusted number, never using contact details supplied during the call.

Why does secrecy feature so heavily?

Secrecy isolates the target from the very colleagues who would spot the fraud. A confidential deal is the perfect cover to justify skipping normal checks and moving fast.

Where can a bank add friction?

On urgent, first-time, high-value wires to new beneficiaries. Prompting the payer to confirm they verified the request independently, and holding for review, gives a window to catch it.

O que saber junto com Executive deepfake video-call scam

Relatório

Relatório de Fraude e AML 2026

Esqueça as previsões. Este relatório detalha com o que as equipes de fraude e AML estão realmente lidando, e como responder.

Baixar relatório