🤖 AI SCAM DEFENSE · GUIDE 4 OF 10

AI Impersonation Scams Explained

Text, voice, and now a whole room of familiar faces on a video call — the format keeps changing, but the trick underneath doesn't.

By TechODash.com  ·  9–11 minute read  ·  Published 2026

We've covered fake emails, cloned voices, and fraudulent payment requests as separate guides in this category, and each one is a specific costume worn by the same underlying trick: convincing you that a fabricated identity is a real, trusted one. This guide steps back to look at that trick directly, including its most advanced version yet — an entire video call populated by people who don't actually exist, all agreeing with each other in real time.

Once you see the pattern clearly, it stops mattering whether the costume is a text, a phone call, or a full meeting.

Who This Guide Is For

Anyone who assumes a video call feels more trustworthy than an email or a text, and hasn't yet considered that the video itself can now be fabricated too.

One Trick, Many Costumes

Impersonation is impersonation whether it arrives as a written message, a cloned voice, or a fabricated video, and the goal is always the same: borrow someone else's trust to get you to do something you wouldn't do for a stranger. What's changed is how far the costume can go. Where this used to top out at a convincing email or a believable phone call, it's now possible to fabricate an entire video conference — every face on the screen generated from real footage of people who were never actually on the call at all.

The Call That Cost One Company $25 Million

The case that put this on everyone's radar involved a finance employee at a global engineering firm's Hong Kong office, invited to a video call with what appeared to be the company's CFO and several familiar colleagues. Every single participant was a deepfake, built from real footage the company itself had previously posted or recorded. Convinced by the meeting, the employee authorized fifteen separate wire transfers totaling $25.6 million, and the deception was only discovered afterward, once someone manually verified the request directly with corporate headquarters. The money was never recovered. It's worth being clear that quick verification and quick reporting genuinely can make a difference — a separate case involving a similarly staged fake video call, including a fabricated lawyer added specifically to boost credibility, saw funds successfully clawed back after police in two countries were alerted fast.

Why Seeing Several People Agree Doesn't Make It Real

There's a specific psychological lever both cases above lean on: when multiple people appear to independently confirm the same story, it feels far more credible than any one person making the same claim alone. A single suspicious email invites scrutiny. A room full of familiar faces, all behaving consistently with an urgent, confidential request, overwhelms that instinct — which is exactly why attackers now go to the trouble of fabricating an entire meeting rather than a single message. More apparent witnesses isn't more proof. In a world where every one of those witnesses can be generated from existing footage, it's not corroboration at all.

The Defense Doesn't Change With the Format

This is genuinely good news: the same verification habit from earlier guides in this category works here too, regardless of how sophisticated the impersonation gets. Any request involving money, credentials, or sensitive information — whether it arrived by email, phone, or a full video call — gets verified through a channel you established independently, before the request came in, not through anything the call or message itself offers. For a business, that means a standing rule that no high-value transfer gets authorized from a meeting alone, no matter how many familiar faces appeared on it, without a separate confirmation through an already-known contact method. That single rule would have stopped both cases above.

A Realistic Standard to Aim For

No high-stakes request — money, credentials, sensitive data — gets authorized based on a meeting, call, or message alone, regardless of how many people appeared to confirm it. Every one of those requests gets a separate, independent confirmation through a contact method you already trusted before the request arrived.

Where to Go From Here

Everything covered so far applies to anyone, but a business has more at stake and more structure to build around it — which is exactly what the next guide addresses.

→ How to Verify a Payment Request Is Legitimate → Protecting Your Business from AI-Powered Fraud Download Free Checklist →

Sources

  • Adaptive Security — the Arup $25.6 million deepfake video call case and how it was uncovered
  • Bitdefender — the Singapore fake-lawyer video call case and successful fund recovery
  • Doppel — organizational deepfake attack prevalence and defense strategy
GOING DEEPER

Scam defense is one layer. A well-built network is the rest.

The SOHO 2026 Guide covers the network foundation that keeps a home office or small business secure — the same structure and habits that back up everything in this category. Written in plain English. Built on 25+ years of real-world IT experience.

Explore SOHO 2026 →
TechODash.com

Calm, practical guides for remote workers, content creators, and small business owners who want networks that work reliably and safely — without the enterprise complexity. Built on 25+ years of hands-on IT experience.