schedule
calendar_month
cloud Loading weather…
| location_on
cloud_off Weather unavailable
Deepfake Featured Image

Deepfake CEOs, fake bankers, fake friends: Inside the new face of cybercrime

100%
hourglass_top 6 min left

Deepfake scams are changing one of the most basic assumptions of digital life: that seeing or hearing someone is enough to know who they are.

A video call from your chief executive. A voice message from your father. A call that sounds like a bank representative. A video of a public official supposedly endorsing an investment.

Deepfake

Until recently, each carried some level of built-in credibility. Generative artificial intelligence is making that increasingly dangerous.

Cybercriminals are combining voice cloning, manipulated video, stolen photos, compromised accounts, and traditional social engineering to impersonate people their targets already trust. The result is a form of fraud that does not necessarily require hacking into a bank account or corporate network first.

Sometimes, the attacker only needs to convince the right person to move the money voluntarily.

When the CEO on the video call is not the CEO

One of the clearest examples came from engineering consultancy Arup.

In 2024, an employee in Hong Kong was tricked into joining a video conference in which people appearing to be the company’s chief financial officer and other colleagues were actually digitally impersonated. The employee ultimately made 15 transfers to five Hong Kong bank accounts, with the fraud costing Arup about US$25 million.

The company’s internal systems had not been compromised. The attackers instead went after something harder for cybersecurity software to protect: an employee’s trust in the people appearing on screen.

Screenshot 2026 08 10 at 11.17.13 AM

Mark Read, CEO of WPP, the largest global advertising and public relations agency. (IMAGE CREDIT: Toby Melville/Reuters)

Advertising giant WPP was also targeted in an attempted executive impersonation attack. Fraudsters reportedly used a fake WhatsApp account, publicly available video footage and an AI-generated voice in an effort to impersonate senior executives during a Microsoft Teams meeting.

The attempt failed, but it demonstrated how ordinary corporate communication tools can be used to make an impersonation convincing.

For businesses, that changes the threat model. An email asking for an unusual payment may raise suspicion, but a request delivered by what appears to be the CEO’s own face and voice can feel much more difficult to question.

In the Philippines, a fake endorsement helped sell a real scam

The same technology is already appearing in Philippine financial scams.

In October 2025, authorities arrested two suspects allegedly connected to an investment scheme that used a manipulated video of President Ferdinand Marcos Jr. A doctor who fell victim to the scheme said she had transferred ₱93 million over about a year.

The deepfake was only one part of a larger confidence-building operation. The victim was also reportedly given expensive gifts that the suspects claimed came from the President, while the supposed investment promised substantial returns.

AI technologies like deepfakes can replicate a person's facial features almost perfectly. Image Credit: Magnific
IMAGE CREDIT: Magnific

Months earlier, the Cybercrime Investigation and Coordinating Center had already warned Filipinos about a fake AI-manipulated video of Marcos being used to promote an investment scheme.

That distinction is important. Deepfakes do not have to carry an entire scam by themselves.

Instead, they can serve as manufactured proof. A fake video can make an investment platform appear legitimate, reinforce a fabricated story or give a scammer the perceived endorsement of someone the victim recognizes.

A familiar voice is no longer proof

The technology becomes even more personal when scammers impersonate relatives and friends.

In August 2026, reports emerged of a Hong Kong man who lost HK$10 million, or roughly US$1.27 million, after receiving WhatsApp messages from scammers allegedly using AI to imitate his father’s voice.

The victim reportedly believed the messages because the voice and manner of speaking resembled his father’s. After an initial urgent request for money, he continued sending funds until his savings were depleted.

The incident shows why voice cloning could become particularly effective in countries such as the Philippines, where messaging applications, voice notes, social media and digital transfers are embedded in everyday communication.

A criminal does not necessarily need a cinematic-quality fake. If the message arrives from a believable account, sounds like the right person and describes an urgent situation, familiarity can do much of the work.

Fake bank calls are becoming harder to judge by voice

Financial institutions are another natural target for impersonation.

In April 2026, the National Privacy Commission warned Filipinos about automated scam calls that can use recorded or AI-generated voices and even imitate real people through voice cloning. The calls may pretend to come from banks, delivery companies or government agencies.

That makes old advice such as listening for an unusual accent or robotic voice less reliable.

A scammer pretending to be from a bank could potentially combine information from previous data leaks, a spoofed phone number, personal account details and a convincing synthetic voice. Each element can make the next one appear more legitimate.

The fundamental problem is that a familiar voice is becoming an increasingly weak form of authentication.

Cybersecurity is shifting from recognition to verification

Deepfakes create a difficult problem because people have spent years learning to trust audiovisual evidence.

For businesses, the response cannot simply be teaching employees to look for strange blinking, unnatural facial movements or robotic speech. As synthetic media improves, those clues can disappear.

iProov study shows deepfakes shatter online confidence, 74% to switch banks for deepfake protection
IMAGE CREDIT: auto.mail.ru

A stronger defense is procedural.

Payment requests, changes to beneficiary accounts and requests for confidential information should be independently verified through a previously established channel. A video call from a senior executive should not be enough to override normal approval procedures, particularly when large transfers or unusual transactions are involved.

Dual authorization, transaction limits and callbacks using verified contact information can provide protection even when the person requesting the transaction appears completely genuine.

Families can apply the same principle. Unexpected requests for emergency money should be verified by calling the person through a known number rather than replying to the same account that initiated the request. Families may also establish a private question or codeword for emergencies.

Banks, meanwhile, will increasingly need authentication methods that do not depend primarily on whether a customer’s voice or face appears familiar. OpenAI CEO Sam Altman warned financial institutions in 2025 that AI had effectively defeated voiceprint authentication as a reliable standalone security measure.

The lesson is increasingly simple: recognition and verification are no longer the same thing.

For years, cybersecurity advice taught people not to trust unfamiliar links, strangers or suspicious emails. Deepfake fraud adds a more uncomfortable rule.

The next scam might look and sound exactly like someone you trust.