Skip to Content

The Rising Threat of Deepfakes: Why Organizations Must Rethink Trust

For decades, we believed that if could hear someone’s voice on a phone call or see them on a video call, they were who they said they were. What if that’s no longer true? 

Jake Dorval

This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats.

Organizations have operated on a simple assumption for decades: if you could hear someone’s voice or see their face on a video call, you could reasonably trust their identity. In the AI era, that assumption may no longer be true.

What makes incidents like this particularly concerning is that they exploit a resource that organizations depend on every day: trust.

Once viewed as a cool trick confined to social media use, deepfakes have evolved into a mainstream threat that organizations of all sizes must take seriously. They have become practical tools for cybercriminals who want to manipulate employees, bypass verification processes, and exploit the human trust that underpins everyday business operations.  

What once required significant computing power and technical expertise can now be generated in minutes using freely available tools and consumer-grade hardware. The challenge for security leaders is bigger than detecting fake videos; as AI-generated content becomes more accessible, organizations must move away from security programs that rely on human judgement and more toward systems that verify trust through multiple independent signals.

Detecting, validating, and responding to AI-enabled attacks increasingly requires visibility across identities, endpoints, communications, and security operations. Organizations that approach these threats through isolated tools and disconnected processes may struggle to keep pace.

The Current Prevalence of Deepfakes

The numbers surrounding deepfake proliferation are staggering and continue to climb year over year. According to Sumsub's Identity Fraud Report 2025-2026, the number of deepfake attacks globally have increased by 2,100%, highlighting that the rise of deepfakes is no longer a technology story; it’s a business risk story.

There have been an increasing number of organizations that are seeing AI-generated content used to facilitate fraud, impersonation, and social engineering attacks. In 2024, a finance employee at a multinational firm in Hong Kong was deceived into transferring approximately $25 million USD after participating in a video conference call in which every other participant was an AI-generated impersonation, including someone posing as the company's CFO.  

Beyond the immediate financial impact, organizations that fall victim to deepfake attacks face serious reputational damage. Customers, partners, and investors may lose confidence in a company's ability to protect its assets and communications. There are also growing legal and regulatory implications to consider, as data protection laws and emerging AI governance frameworks may hold organizations accountable for failing to implement reasonable safeguards against synthetic media threats.

The compounding nature of these risks means that a single successful deepfake attack can trigger a cascade of consequences that affects an organization for years after the initial incident.

How Deepfakes Are Being Used to Target Organizations

Many conversations about deepfakes focus on detection. Can employees spot a fake voice? Can they recognize manipulated video? Can they identify subtle artifacts that reveal synthetic content? However, deepfakes undermine those assumptions by making those signals increasingly easy to manipulate at scale.

Voice deepfakes, or "audio cloning," are being used to impersonate CEOs and senior executives in phone calls to finance and HR departments, instructing employees to transfer funds or share sensitive credentials. This tactic is often referred to as "vishing" or voice phishing.

Video deepfakes are being used to bypass identity verification processes, gain unauthorized access to secure systems, and manipulate employees during live video conferences.

Beyond financial fraud, deepfakes are also being used to fabricate compromising content involving executives or employees, creating opportunities for blackmail, reputational damage, and insider threat manipulation. The versatility of deepfake technology as an attack tool makes it particularly dangerous, as it can be adapted to target virtually business process that relies on human communication and trust.

The Real Problem Isn’t Deepfakes, It’s Identity Verification

One of the most significant and underappreciated risks organizations face is the assumption that trained employees can reliably identify deepfakes in real-time.

Even if individuals become better at recognizing suspicious content, the quality of AI-generated media continues to improve. Organizations cannot build long-term security strategies around the assumption that employees will consistently outperform increasingly sophisticated AI systems.

This challenge is particularly apparent in customer support and help desk environments. Frontline personnel are often expected to make rapid decisions while balancing customer experience, operational efficiency, and security requirements. Asking those employees to serve as the primary defense against AI-generated deception places an unrealistic burden on people who were never intended to function as deepfake detection systems.

That said, the lesson is not that employees should stop being vigilant. However, organizations that rely on human intuition as their primary line of defense against deepfakes are, in effect, leaving their front door unlocked and hoping that no one tries the handle.

How Organizations Can Build Resilience Against Deepfakes

Historically, organizations have built security programs around protecting systems, devices, applications, and data. Deepfakes expose a different challenge: protecting trust.

As AI capabilities continue to advance, organizations must assume that identity signals can be manipulated, which requires a shift from trust-by-observation to trust-by-verification.

There are concrete steps organizations can take to reduce their exposure to deepfake-related risks, including:

  • Implementing multi-factor authentication and out-of-band verification protocols (e.g., requiring a secondary confirmation through a separate, pre-established channel) before acting on any high-stakes request, which can significantly reduce the effectiveness of voice and video deepfake attacks. A request that appears legitimate should still be verified through established procedures before action is taken.
  • Investing in AI-powered deepfake detection tools, which analyze subtle artifacts in audio and video content that are invisible to the human eye, such as unnatural blinking patterns, inconsistent lighting, or audio frequency anomalies.
  • Establishing clear internal policies around the verification of executive communications, particularly those involving financial transactions or sensitive data.
  • Taking a layered security approach that combines technology, policy, and employee awareness training, without placing undue reliance on any single element.
  • Creating a culture in which verification is encouraged, rather than discouraged. Employees should feel empowered to pause, question, and validate unusual requests, regardless of who appears to be making them.

While these processes may introduce additional friction into certain workflows, it is significantly less disruptive than recovering from a successful fraud incident or compromise.

AI-Era Threats Require Connected Defenses

Deepfakes are often discussed as a standalone issue, but they are better understood as one component of a broader wave of AI-enabled threats.

An attack that begins with a synthetic voice may ultimately involve compromised identities, endpoint activity, cloud services, email systems, collaboration platforms, or sensitive business applications. Security teams need visibility across these environments to understand the full scope of an incident and respond effectively.

This is where security architectures become increasingly important.

Organizations need security controls that work together rather than operating as isolated point products. The ability to correlate signals across identities, endpoints, communications, and security operations helps defenders identify suspicious activity earlier and respond more effectively when incidents occur.

This need for connected defense is one of the reasons security strategies are evolving toward AI-native approaches. Sophos Fusion, the Sophos AI-Native Cybersecurity Defense System, is built on the premise that modern attacks cannot be understood through isolated security signals alone. Instead, organizations need the ability to connect insights across their entire environment, helping security teams detect, investigate, and respond to AI-enabled attacks with greater speed and context as part of a coordinated defense strategy.

The Future of Trust

The age of deepfakes is here, and it demands a fundamental rethinking of how organizations establish trust. The challenge facing organizations over the next several years will not simply be determining whether a video, voice, or image is authentic. It will be learning how to operate securely in a world where authenticity can no longer be assumed.

The organizations that thrive in this environment will be those that adapt their security strategies now. They will move beyond assumptions about trust and build resilient verification processes, layered defenses, and connected security operations designed for the realities of the AI era.

Because the question is no longer whether deepfakes will affect organizations; the question is whether organizations are prepared for a future in which trust itself has become a cybersecurity challenge.