Deepfake Workplace Fraud: A Verification Workflow
Treat the request as unverified until a second channel confirms it
An urgent call appears to come from an executive. A person on video asks finance to change payment details. A voice message tells HR to release employee information. The voice or face may look familiar, but familiarity does not establish identity. The FBI warns that criminals use generative AI to make fraud more believable and can use AI-generated audio to impersonate public figures or personal relations to elicit payments. It also describes AI-generated video used to create believable depictions of public figures in support of fraud.
That warning changes the starting assumption for a high-risk workplace request. The request remains unverified until the team confirms it through a channel that the requester did not provide or control. Do not ask an employee to decide whether a voice or face looks synthetic. Give them a short process they can follow while under pressure.
Separate the claimed identity from the requested action
Write down two things before responding: who the person claims to be, and what they want changed. A convincing identity claim does not make the requested action safe. The useful questions are concrete: Which payment, account, employee record, credential, or approval would change? Who receives the benefit? What deadline was given? Which normal control would the request bypass?
The FBI source supports scrutiny of AI-assisted fraud and impersonation. It does not publish a finance or HR approval standard. The workflow below is an operational recommendation for teams to adapt to their own policies, authorities, and reporting duties.
Run an independent verification path
Pause the transaction or disclosure. Keep the current payment details, access rights, and employee records unchanged while the request is checked. Urgency is information about the request, not permission to skip a control.
End the incoming interaction. Do not use a phone number, meeting link, email address, or chat account supplied during the suspicious contact. Open the company directory or another record your team already trusts.
Contact the claimed requester independently. Call a known number or start a new message in an established company channel. Ask them to restate the exact request. If they cannot be reached, route the case to the person already authorized by company policy rather than improvising approval.
Require the normal approvers. A video appearance or familiar voice should not replace the people and records already required for a payment, bank-detail change, payroll update, access reset, or release of personal information. Record who confirmed the request and through which independently opened channel.
Preserve the suspicious material. Keep the original voicemail, file, message, sender details, meeting invitation, and transaction information that are available. Do not edit the only copy. If the request may involve financial fraud, the FBI directs victims to report to the Internet Crime Complaint Center and include available details.
Use detection only when there is a file to inspect
A live call may leave no usable recording. When a voicemail, image, video, or saved clip exists, DeepFakeCheck can analyze the file and return a probabilistic risk signal. That signal may help the review, but it does not identify the caller, approve a payment, or establish that a request is legitimate.
Automated detectors have false positives and false negatives. A false positive can flag authentic material; a false negative can miss synthetic or manipulated material. A high score supports further review, while a low score cannot clear the request. Independent contact and the organization’s approval records remain necessary whichever score appears.
Keep the detector result beside the preserved file, the verification notes, and the final disposition. This makes clear which part came from a tool and which part came from people following the company’s process.
Decide before the next urgent request arrives
Finance and HR teams should define the independent channels and approvers for high-risk actions before a suspicious call arrives. The useful test is simple: can an employee stop the request, find a trusted contact path, and record the verification without relying on anything supplied in the incoming interaction?
If the answer is no, tighten that procedure before adding another detection tool. A fixed verification path protects the decision even when the media looks convincing and the detector result is uncertain.
Sources
- FBI Internet Crime Complaint Center, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud”: https://www.ic3.gov/PSA/2024/PSA241203
Suspect an image might be AI-generated?
Use our advanced deepfake detection tool to analyze images with high precision.
Analyze Image Now