Spot Deepfake Video Call Scams (2026)

Train staff to spot deepfake video call scams in 2026: a verify-out-of-band rule, three drills, and a 30-day plan that stops emergency wire requests.

Deepfake video call scams press staff into moving money or secrets while they believe a real executive is on screen. This guide shows how to train staff to spot deepfake video call scams in 2026 — with one verify rule, three drills, and a 30-day plan you can measure.

TL;DR

Why this matters

In 2026 a cloned CEO face and voice can land in a Teams or Zoom invite in minutes. Staff who would never wire money from a random email will still obey a face they recognise under time pressure. Filters do not join the call for them.

IBM’s 2025 Cost of a Data Breach report put attacker AI in roughly 16% of breaches, with deepfake impersonation a large share of those cases. The FBI IC3 logged US$893 million in AI-related losses in 2025 across 22,364 complaints. Verizon’s 2026 DBIR still puts the human element in 62% of breaches. That is why phishing simulations and process beats another annual video about “AI bad.”

What you'll need

The steps

1. Publish the verify-out-of-band rule before any drill

State one non-negotiable rule for every staffer who can move money or data: any urgent request that arrives on a live video or voice call must be confirmed on a second channel already on file — a known desk number, a standard ticket, or an approved chat to a person who was not on the call. Never confirm using a number or link the caller provides.

Put the rule in the intranet, finance SOP, and onboarding the same week.

Expected outcome: staff can quote the rule without a slide deck.

Common mistake: treating deepfakes as an IT gadget problem instead of a payment process problem.

2. Map who can still move money under pressure

List roles that approve wires, payroll changes, vendor banks, VPN access, or customer data exports. Include executive assistants and backup approvers. Tag high-pressure windows: month-end, board week, product launch.

Expected outcome: a one-page heat map of who faces fake-exec pressure first.

Common mistake: training only the security team while finance and EAs stay untested.

3. Build three deepfake-flavoured templates

Use synthetic detail only — never a real bank account or private diary.

  1. Emergency board wire — “I’m in a meeting, cannot talk, approve the transfer now.”
  2. IT identity check on video — “Share screen and enter your password so I can unlock payroll.”
  3. Vendor re-sign on a hurried call — “New bank details, legal already approved, need you live.”

Pair each with a 3–5 minute lesson that shows freeze-frames, audio glitches, and refusal scripts staff can say without freezing.

Expected outcome: three staged cadences ready by day seven.

Common mistake: only email sims with “AI” in the subject line and no call-path rehearsal.

4. Baseline, then run three sends over 30 days

Week 1: soft baseline to the high-risk cohort. Weeks 2–4: send the three templates 7–10 days apart. Auto-enrol fails into the matching lesson the same day. Celebrate anyone who hangs up and verifies.

Expected outcome: report rate above 20% by week 4; zero real funds moved off policy.

Common mistake: full-company blast on day one without a cohort baseline.

5. Add a live call-check to the release form

On payment and access forms add: Second-channel verification completed — channel used, person reached, time. No field, no release. Spot-check 10% weekly.

Expected outcome: dual-channel checks become as normal as attaching an invoice.

Common mistake: allowing “they looked and sounded right on Zoom” as enough.

6. Score behaviour in human risk reporting

Fold video-scam fails, late lessons, and missed second-channel checks into human risk reporting. Review Fridays for 30 days, then keep a monthly deepfake variant for finance and exec support.

Expected outcome: scorecard with click %, report %, verified call-backs %, blocked payments.

Common mistake: 100% LMS completion with near-zero challenge rate on live pressure.

7. Brief real executives so they stop bypassing you

Tell executives the programme exists. Ask them never to demand off-policy money on a rushed video call, and to expect a second-channel check every time — including when they are travelling.

Expected outcome: executives reinforce the rule instead of punching holes in it.

Common mistake: hiding drills from the people attackers will deepfake.

Troubleshooting

Staff say the deepfake clips look fake. That is fine for lesson one. Raise difficulty with better audio and a familiar backdrop once the rule sticks.

Legal blocks any fake video of executives. Use synthetic faces styled as generic senior leaders and label every drill clearly in the debrief, not in the mid-call wow moment.

Click rate near zero. Whitelist simulation domains; check that invites are not auto-declined by calendar policy.

Report rate under 10%. Teach the exact report button and the hang-up-and-call script in the fail lesson.

Remote-only workforce skips phone call-backs. Allow approved authenticator push or IT ticket as the second channel — still never the contact path inside the lure.

Simulations fade after the pilot. Keep one deepfake-themed slice each month for high-risk roles through the rest of 2026.

Tools and resources

What to do next

Lock the verify-out-of-band rule this week, stage the three templates, and book the 30-day window. If you need a side-by-side on automation and reporting, use the MSP-focused compare page before renewing tools.

FAQ

How do you train staff to spot deepfake video call scams in 2026?

Write a second-channel verify rule for any money or access ask on a live call, run three deepfake-themed drills over 30 days, auto-enrol fails into short lessons, and score report rate and blocked payments.

What is a deepfake video call scam?

Attackers clone a leader’s face and voice on a live or near-live call to pressure staff into wires, gift cards, password shares, or data exports without a normal approval path.

How much did AI-related cybercrime cost in 2025?

FBI IC3 reported US$893 million in AI-related losses across 22,364 complaints in 2025. IBM also found attackers used AI in about 16% of breaches studied.

Can filters alone stop deepfake CEO calls?

No. Filters may catch some spoofed emails, but they do not sit on the video call when a staffer is pressured live. Process plus rehearsal closes that gap.

Should only executives get deepfake training?

No. Train anyone who can move money, reset access, or export data — especially EAs, payroll, AP, and help desk.

How often should deepfake drills run after month one?

Monthly for finance and exec support; quarterly awareness for broader staff is a workable 2026 baseline.

Is hanging up on a real executive allowed?

Yes under the written rule. Real executives should expect a second-channel check and never punish staff for following it.

What report rate should teams aim for?

Push above 20% reporting on current templates while click and compliance-fail rates trend down across the 30-day window.

One last thing

The quiet failure mode is a polished AI-awareness module and a Tuesday afternoon when someone still wires funds because the face on the call blinked like the boss. If your 2026 pack cannot show second-channel logs next to the phishing trend, you are measuring course seats, not payment risk. Put the rule, the drill, and the scorecard on one page.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.