Know
What is Deepfake Impersonation?
Deepfake impersonation uses synthetic media to strengthen social engineering. Attackers may clone an executive’s voice, alter live video, fabricate identity documents, produce convincing profile images, or generate fake authority figures. The media is most dangerous when organizations treat appearance or voice as sufficient proof of identity.
Why it matters
In 2026 the FBI warned that scammers were using AI-generated videos to impersonate FBI personnel and described real-time video and voice-cloning tactics. Microsoft also documented threat actors using voice modulation, deepfake overlays, synthetic identities, and executive voice cloning as operational tradecraft.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
FBI warned that scammers were using AI-generated videos and voice cloning to impersonate trusted authorities
The FBI warned of ongoing schemes impersonating IC3 and FBI personnel using AI-generated videos, spoofed websites, social media personas, and voice cloning. The advisory notes scammers can use synthetic media in real-time video chats and private communications to make fraudulent identities appear authentic.
This is direct government validation that synthetic media is being used operationally for impersonation and fraud, reinforcing the need for independent identity verification rather than trusting voice or video appearance.
Understand the mechanics
How it works
- 1
Collect samples of the target’s voice, image, role, or public information.
- 2
Generate or manipulate audio, video, images, or identity artifacts.
- 3
Create a believable business or authority pretext.
- 4
Pressure the victim to transfer money, disclose data, change access, or bypass a process.
- 5
Use additional spoofing and contextual details to reduce suspicion.
Practice
What to watch for
- Urgent request that bypasses normal process
- Unexpected communication channel
- Request for secrecy
- Subtle audio/video inconsistencies
- Identity request cannot be confirmed through an independent channel
- Caller rejects established verification
Perform
What to do
- 1
Pause the requested action.
- 2
Verify the person through a known independent channel and established process.
- 3
Preserve the media and communication metadata.
- 4
Report suspected impersonation and investigate any account or payment changes already made.
How to reduce the risk
- Independent verification for high-impact actions
- Dual approval
- Known-channel call-back
- Help-desk identity proofing
- Executive and finance simulations
- Treat biometric resemblance as a signal, not sole authentication
Business impact
- Wire fraud
- Account recovery abuse
- Sensitive-data disclosure
- Reputational harm
- Executive impersonation
What different roles should do
Finance
- Never override payment controls because a voice or video looks authentic
IT / Help Desk
- Do not accept voice or video likeness as sufficient identity proof
Framework & standards context
- MITRE ATT&CK Phishing / Impersonation-related social engineering
Source transparency
Authoritative sources
- FBI / IC3: FBI Warns of Scammers Impersonating the IC3 ↗
- Microsoft Security: AI as tradecraft: How threat actors operationalize AI ↗
Last reviewed: 2026-09-02