Detect Deepfakesby Resemble AI
Deepfake case study · Video

Would your team pass a security test if you didn't tell…

An internal security test using a deepfake video to impersonate a colleague successfully tricked team members into sharing sensitive information

Incident date
Jul 2026
Target
Anonymous corporate team members
Updated Jul 29, 2026 · 1 min read

A security professional recently conducted an unauthorized internal test to evaluate their team's resilience against deepfake-based social engineering. By utilizing a deepfake video of a consenting colleague during a video call, the tester impersonated the employee to request sensitive personal information intended for a Google Sheet. All three targeted team members complied with the request without questioning the authenticity of the call or the nature of the information being shared.

What happened

The tester leveraged a deepfake of a colleague to initiate a video call under the guise of an internal business request. The target employees were asked to provide specific personal details, which they surrendered immediately. To conclude the test, the organizer contacted one of the participants to reveal the deception and observe the reaction. The test highlights a significant vulnerability in organizational security awareness, as the participants failed to verify the identity of the person on the call despite the potential for deepfake manipulation. While the tester accepted responsibility for the lack of prior training, the incident sparked broader professional discussions regarding the effectiveness of such drills. Security experts note that relying on human detection for deepfakes is increasingly unreliable as technology evolves to patch previous physical tells, such as lip sync lag or occlusion issues. Industry guidance suggests that rather than relying on employees to spot visual glitches, organizations should implement robust verification processes—such as mandatory multi-channel confirmation for sensitive requests—to mitigate the risks posed by identity-based social engineering.

Sources