Skip to main content
Video call face showing subtle deepfake distortion, representing how to spot deepfakes targeting a business

Beware of Deepfakes: How to Spot the Different Types Targeting Your Business

Updated August 22, 2026

In July 2024, KnowBe4, a company that literally sells security awareness training, hired a remote software engineer who turned out to be a North Korean operative using a stolen American identity. The applicant’s photo was an AI-altered stock image, good enough to pass HR and four separate video interviews with someone who matched it closely enough that nobody blinked. The new hire cleared a background check built on the stolen identity, received a company laptop, and within hours of logging in, the device started loading malware.

Nobody caught this by staring hard at a video call and noticing something was off. KnowBe4 caught it because its endpoint detection software flagged the malware and its security team moved fast once the alert fired. That’s an uncomfortable lesson for any business that assumes a bad actor would look, sound, or act obviously wrong on camera.

This Isn’t a 2024 Story Anymore

It would be easy to file the KnowBe4 case away as an isolated, embarrassing one-off. It isn’t. On July 31, 2026, the FBI and State Department, alongside allied governments in the UK, Canada, Australia, Japan, and South Korea, issued a joint alert warning that operatives are still landing remote IT jobs at Western companies using falsified documents, laptop farms, and, increasingly, AI to polish fake profiles and generate convincing communications. Eight people have already been sentenced in 2026 alone for helping run these schemes.

The financial numbers tell a similar story. Deloitte’s Center for Financial Services projects that generative AI-enabled fraud could cost US businesses $40 billion by 2027, up from $12.3 billion in 2023. The report’s go-to example is the finance employee at a Hong Kong firm who joined a video call with what looked and sounded like his company’s CFO and several colleagues. Every person on that call was a deepfake, and the employee wired $25 million before anyone realized it.

The 4 Types of Deepfakes Businesses Run Into

“Deepfake” covers more than the face-swapped celebrity videos that made the term famous. Here’s what’s showing up in inboxes, interviews, and phone calls right now.

Video Deepfakes

This is the classic type: someone’s face and voice, mapped in real time onto a video call or pre-recorded clip, well enough to hold a conversation. The Hong Kong case above is the extreme version, a whole conference room of fabricated executives. Most attempts aren’t nearly that polished. Watch for lighting that doesn’t quite match between someone’s face and the rest of the frame, a mouth that lags slightly behind the words, or a person who avoids turning their head or reacting to interruptions.

Voice Cloning

Modern voice-cloning tools need only a few seconds of someone’s real voice, pulled from a company video, a podcast appearance, or even a voicemail greeting, to generate convincing fake audio. The most common version is an urgent call or voicemail from “the CEO” demanding a wire transfer: essentially business email compromise, except the message arrives in a voice the target actually recognizes. A cloned voice can still sound flat or slightly off in its pacing, but that’s not something to bet on catching mid-call.

Synthetic Identity Deepfakes

This is what caught KnowBe4: an AI-manipulated photo, a fabricated resume, and a stolen or invented identity, built to survive a hiring process rather than fool one person for five minutes. It’s built for volume, not perfection, since a hiring pipeline usually has multiple people reviewing an application quickly rather than one person studying it closely. That’s exactly why it works.

AI-Generated Text and Phishing Content

AI-written phishing emails, fake reviews, and impersonated social media posts don’t fit the strict definition of a deepfake, but they come from the same toolset and the same goal: content convincing enough that a person acts on it without checking. The grammar mistakes and awkward phrasing that used to be a phishing tell are mostly gone. What’s left to check is the actual request: is this something the sender would normally ask for, through this channel, right now?

Why “Just Look Closely” Isn’t a Real Defense

Here’s the uncomfortable part. A 2024 meta-analysis of 56 separate studies, published in Computers in Human Behavior Reports, found that people correctly identify deepfakes only 55.54% of the time on average, a number statistically indistinguishable from a coin flip. People did slightly better with audio (62%) and worse with still images (53%). Specific training and detection tools helped, pushing accuracy up to around 65%, but even that leaves plenty of room for something to slip through.

That’s the real argument for building verification into your process instead of trusting your gut on a call. The next section is what that looks like in practice.

What Actually Works Against Deepfakes

Verify Through a Second Channel Before Acting

Any request involving money, credentials, or sensitive data, especially one that feels urgent, gets confirmed through a channel other than the one it arrived on. If “the CFO” calls asking for a wire transfer, hang up and call the CFO back on a number you already have on file, not one provided in the same call or email. This is the same principle behind multi-factor authentication: one channel alone, whether it’s a password or a familiar-sounding voice, isn’t enough proof on its own anymore.

Tighten Identity Verification for Remote Hires

A photo and a video interview aren’t independent checks if the photo was used to coach what the interviewer expects to see. Verify government ID against a live selfie or video using a proper identity verification service, confirm previous employment by calling the company directly rather than emailing an address on the resume, and be skeptical of a candidate who refuses a camera-on interview or insists on unusual payment arrangements.

Train Your Team on What’s Changed

Most phishing and deepfake awareness training still teaches people to look for typos and robotic voices. That advice is aging out fast. Update what your team is watching for: an unusual request delivered through an unusual channel, urgency that discourages a second check, and a willingness to verify out loud instead of assuming a familiar voice or face is enough.

Assume Some Will Get Through, and Watch for What Happens Next

KnowBe4 didn’t stop its fake hire during the interview. It caught the damage starting to happen and shut it down fast, because endpoint monitoring was watching for unusual activity regardless of who was behind the keyboard. That’s worth building into your own security posture: assume a well-made deepfake might get past a person, and make sure something is still watching for what a bad actor does once they’re in.

The Bottom Line

A company that trains other businesses on security awareness still got fooled by an AI-altered photo and four ordinary-looking video calls. That’s not a knock on KnowBe4, it’s the whole point: deepfakes aren’t getting caught because someone stared hard enough at a screen. They’re getting caught by verification habits and monitoring that don’t depend on a person’s judgment in the moment. Know the four types you’re likely to run into, verify anything involving money or access through a second channel, tighten how you vet remote hires, and keep watching for what happens after the trick works, not just during it.

Book a Free Consultation

Not sure how exposed your business is to deepfake-driven fraud or hiring scams? Let’s talk. Book a time on my calendar and we’ll walk through your current verification habits and what a practical defense looks like, as part of a broader cybersecurity program built for your business.

Frequently Asked Questions

A deepfake is synthetic audio, video, or imagery generated or altered by AI to convincingly show someone doing or saying something they didn’t. The term covers everything from face-swapped video calls to cloned voices to AI-manipulated photos used in identity fraud.

In July 2024, the security awareness training company KnowBe4 unknowingly hired a North Korean operative posing as a remote software engineer, using a stolen identity and an AI-altered stock photo that passed four video interviews. The device issued to the new hire started loading malware within hours, and KnowBe4’s endpoint monitoring caught it.

Yes. The FBI and State Department, along with several allied governments, issued a joint alert on July 31, 2026 confirming that North Korean IT worker schemes are ongoing and increasingly use AI to build convincing fake profiles. Eight people were sentenced in connection with these schemes in 2026 alone.

Not reliably. A 2024 meta-analysis of 56 studies found that people correctly spot deepfakes only about 55% of the time on average, close to a coin flip. That’s why verification procedures, not visual judgment, are the more dependable defense.

Verifying any request involving money, credentials, or sensitive data through a second channel you already trust, such as calling someone back on a known phone number, rather than acting on a single call, video, or message no matter how convincing it seems.

Deloitte’s Center for Financial Services projects generative AI-enabled fraud could cost US businesses $40 billion by 2027, up from $12.3 billion in 2023.