Managing AI-powered impersonation is becoming harder and harder. Generative AI can produce convincing text, images, video and cloned voices. Attackers can use these tools to make impersonation more personal and remove many of the spelling or grammar mistakes that once made phishing easier to spot.
Today, an attacker’s voice note can sound exactly like the managing director, a video can appear to show a trusted colleague, and an email can use the right tone, names and project details. The request feels genuine – but the person behind it may not be.
Sounding right is no longer proof of being right. For high-risk requests, an independent check is stronger than visual or audio familiarity.
Deepfake-enabled fraud is already causing measurable financial harm. Research identified 41 publicly reported corporate deepfake fraud incidents in 2025, with $74.9 million in verified losses – even though 71% disclosed no financial impact. (Resemble AI Annual Threat Intelligence: The 2025 Deepfake Threat Report)
How AI changes social engineering
Deepfakes are manipulated, or synthetic media that make it appear a real person said or did something they didn’t.
Voice cloning can turn a short public audio sample into a persuasive phone call or message, and public information from websites, interviews and social profiles can make the request feel even more credible.
This means organisations need to move away from tests based only on appearance. A familiar face, voice, name or writing style should never be enough to authorise a payment, disclose sensitive information or change access rights.
Warning signs still matter
None of these signs proves that a deepfake is present. Equally, their absence does not prove that the request is genuine. Verification should therefore be designed into the process.
Verify the person through an independent route
Do not overlook how employees use generative AI
AI risk isn’t limited to external attacks. Employees may enter client information, personal data, source code or confidential documents into public tools without understanding how prompts and outputs are stored, retained or used.
Organisations should define which tools are approved, what information may be entered and when human review is required. AI-generated output should be checked before it is relied upon or shared because it may be inaccurate, incomplete or disclose inappropriate information.
How do ISO standards help protect businesses?
ISO 27001 helps organisations manage information security risks and embed controls around access, communication, suppliers and incident response.
ISO 42001 provides a management-system framework for responsible AI governance, including clear accountability, risk assessment and continual improvement.
Used together, these two frameworks bring cyber security and AI governance under one roof, covering how AI is selected, deployed and overseen, including the risks posed by deepfakes and synthetic media.
Organisations wanting to test how their people would actually respond to an impersonation attempt can also use our sister company WorkNest, for social engineering penetration testing, which simulates deceptive calls, messages and physical-access attempts to reveal vulnerabilities.
Neither framework can stop that content from being created, but together they can strengthen the processes that stop an unusual request from turning into an avoidable loss.
Help your people turn four simple habits into everyday action: spot the pressure, verify the person, protect accounts and data, and report concerns early.

