Deepfakes are targeting your executives. Here’s what…
A CFO avoided a seven-figure wire fraud attempt after identifying a deepfake video call through a subtle hesitation during a verification question
- Incident date
- Aug 2026
- Target
- unnamed CFO
A chief financial officer recently thwarted a seven-figure fraudulent transfer after recognizing that a video call featuring his CEO and board members was a sophisticated deepfake. While the impersonators used realistic audio and video, the CFO’s insistence on verifying information only the real CEO would know exposed the deception.
What happened
The incident involved a forty-minute video call where the CFO believed he was authorizing a legitimate acquisition payment. The attackers utilized voice cloning derived from earnings call recordings and video imagery synthesized from public YouTube conference footage. The deepfakes were convincing enough to include familiar voices and unscripted social commentary, making the interaction feel authentic.
The attempt failed when the CFO tested the participants by asking about a specific side conversation that had occurred the previous week. The voice on the other end hesitated for half a second too long before attempting an answer, a delay that alerted the CFO to the fraud. This hesitation served as the primary indicator of the attack, as the synthetic media tools failed to replicate the nuanced, real-time knowledge and spontaneity of the actual executives. This case highlights that while detection technology exists, it is often ineffective during live, time-sensitive calls. Consequently, security experts emphasize that established human verification protocols, such as pre-agreed authentication phrases and out-of-band confirmation, remain the most reliable defenses against executive impersonation.