In the most famous case so far, a finance employee in Hong Kong joined a video conference with his company's CFO and several colleagues — all of whom were deepfakes — and wired out roughly $25 million on their instructions. Seeing was believing. That's exactly what the attackers counted on.
Real-time face swapping has left the research lab: consumer tools can now puppet a stolen face over a live webcam feed. The targets are businesses (executive impersonation for wire fraud), individuals (romance scammers who can finally 'prove' they're real on video), and families (video versions of the emergency call).
How the scam works
1
Source material
Photos and video of the target — an executive's conference talks, a stolen dating profile's owner, anyone with a public face — train the model.
2
The live puppet
On the call, the attacker's face movements drive the victim's trusted face. Voice cloning covers the audio. Short, low-resolution, 'bad connection' calls hide the seams.
3
The ask
For businesses: an urgent, confidential wire or a change to payment details. For individuals: video 'proof' that dissolves your last doubt before the money request that follows.
4
The pressure
Deepfake calls are kept brief and one-directional. Long, interactive conversation is the enemy of the technology — so the script avoids it.
Red flags to watch for
!Video proof arriving exactly when you doubted
If someone dodged video for weeks and suddenly offers a short, blurry call right when you got suspicious, the call is the costume.
!Short calls, bad quality, excuses to end
Real-time deepfakes degrade with length, motion, and resolution. Chronically brief and blurry is a pattern, not bad luck.
!Faces that won't turn
Current face-swaps struggle with full profile views, hands passing over the face, and objects held near it. Evasion of simple requests like these is telling.
!Meeting requests from odd channels
A 'confidential' video meeting scheduled through personal email or WhatsApp rather than the company calendar is a setup, whatever the faces show.
!Instructions that bypass process
Any payment, credential, or data request whose justification is 'the person told me on video' should trigger process, not obedience.
What to do
✓Ask for movement
A slow head turn to full profile, a hand waved in front of the face, standing up. Refusal or a sudden 'frozen connection' after the request is your answer.
✓Verify through a second channel
Message the person on their known number or company chat while the call is live: 'Are you on this call with me?' Thirty seconds, scam over.
✓For companies: make out-of-band verification policy
No wire, vendor change, or credential reset on the strength of a call alone — voice or video — regardless of who appears to ask. Attackers exploit hierarchy; policy removes it.
✓If money moved
Call the bank immediately for a recall attempt, file with ic3.gov, and preserve the meeting invite, recording, and messages. Speed is the only real lever on wires.
Frequently asked questions
Can deepfakes really run live on a video call?
Yes. Real-time face swap tools run on ordinary gaming hardware. Quality varies — which is why attackers keep calls short and blame the connection — but 'good enough for a compressed webcam feed' was passed years ago.
How did the $25M Hong Kong scam work if the whole meeting was fake?
The attackers reconstructed multiple executives from public appearances and staged a group call where only the victim was real. Group settings actually help attackers: peer pressure plus authority, and the victim mostly listens.
Is there software that detects deepfake calls?
Detection tools exist but lag behind generation and aren't practical mid-call. Procedural defenses — movement requests, second-channel checks, payment policies that don't bend for urgency — are what actually hold.
Fight AI with AI.
Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.