Writing / Article

Deepfakes: Cyber Risks and Practical Controls

An analysis of the key cyber risks associated with deepfakes across biometric authentication, social engineering, and disinformation, along with practical mitigation controls.

Contents

Deepfakes use artificial intelligence to create fake audio, video, images, documents, and text. They mimic real people or real events to deceive others.

This is now a business risk, not just a media risk.

As deepfake tools become cheaper and easier to use, attackers can use them to bypass security checks, steal funds, impersonate executives, manipulate customers, damage reputations, or support corporate espionage.

The key point is simple: deepfakes attack trust.

They exploit the trust we place in faces, voices, documents, video calls, public statements, and digital onboarding processes.

According to the Monetary Authority of Singapore’s September 2025 information paper, deepfakes create risks across biometric authentication, social engineering, impersonation scams, misinformation, disinformation, fraud, market integrity, regulatory exposure, and reputation.


Three Main Deepfake Threats

MAS highlights three main deepfake risk areas:

Biometric bypass

What attackers do: Use fake faces, videos, or documents to pass onboarding or login checks.
Main controls: Liveness detection, document verification, injection protection.

Impersonation scams

What attackers do: Use fake voice or video to trick staff or customers.
Main controls: Out-of-band verification, dual approval, separation of duties.

Misinformation and disinformation

What attackers do: Use fake public content to damage trust or manipulate decisions.
Main controls: Media monitoring, takedown process, crisis playbooks.


1. Defeating Biometric Authentication

Many organizations use biometric checks during customer onboarding, login, and identity verification.

Deepfakes can weaken these controls.

Attackers can use synthetic faces, altered selfies, forged documents, stolen images, or pre-recorded videos. They can also use virtual camera software to feed fake video into a verification process.

This creates several risks:

  • Fake account creation
  • Identity theft
  • Unauthorized transactions
  • Money laundering
  • Account takeover
  • Fraudulent loan applications

MAS cites cases where attackers used AI-generated photos, malware-stolen customer images, and doctored documents to bypass or attack digital KYC and facial recognition processes.

Defeating biometric authentication

Attackers inject synthetic or stolen identity material to bypass verification controls and open the door to downstream fraud.

Deepfake identity input

Synthetic face · forged document · stolen image · virtual camera injection

Biometric verification

Customer onboarding · login · digital KYC

Document checks · liveness detection · injection detection

Fraudulent identity accepted

Controls are defeated. Attacker is treated as a legitimate user.

Identity fraud

Fake accounts · account takeover · transaction fraud · money laundering

Practical controls

Use stronger document checks.
Do not rely only on uploaded images. Check document security features, metadata, lighting, reflections, and inconsistencies across submitted documents.

Use liveness detection.
Ask users to perform random actions. Examples include blinking, turning their head, or responding to a prompt. Stronger systems should also check motion, texture, depth, and behavioural signals.

Detect injection attacks.
Attackers may use virtual cameras or browser manipulation to inject fake media into a live verification session. Use secure SDKs, runtime protection, device integrity checks, and anti-tampering controls.

Protect biometric data.
Use strong encryption in transit and at rest. Apply strict access control and secure key management. Where possible, use cancellable biometrics so stolen templates cannot be reused across systems.

Test the biometric process.
Run security testing against realistic deepfake samples. Test against different tools and techniques, not only one known attack method.


2. Social Engineering and Impersonation Scams

This is the most practical deepfake risk for many organizations.

Attackers do not need to break the system. They only need to convince one person to act.

  • A fake CEO can request a fund transfer.
  • A fake customer can request an account change.
  • A fake employee can ask IT to reset access.
  • A fake vendor can request a bank account update.
  • A fake job candidate can pass interviews using a synthetic identity.

MAS cites several incidents. These include a Hong Kong case where an employee was tricked into transferring US$25 million after joining a video call with deepfakes of the company’s CFO and colleagues. It also cites a Singapore case where a finance director transferred US$499,000 after a fake Zoom call involving impersonation of the company’s CEO and colleagues.

Social engineering and impersonation scams

The diagram centers the decision point. The attacker tries to trigger a high-risk action, and independent verification determines whether the action moves forward.

Request

Deepfake or impersonated request

CEO payment request · customer account change · helpdesk reset · vendor bank change · synthetic job candidate

Action

High-risk business action

Payment, access, or account change is about to happen.

Decision

Independent verification performed?

Out-of-band verification · dual approval · separation of duties · privileged-user controls

Yes

Trusted channel verification

Second approval follows and fraud is prevented.

No

Employee complies

Financial loss or access loss follows.

Practical controls

Do not trust a single channel.
A video call is not enough. A voice call is not enough. An email is not enough. For high-risk requests, verify through a separate trusted channel.

Use out-of-band verification.
If the request comes by video call, confirm it using a known phone number, secure workflow, or internal approval system. Do not use contact details provided inside the suspicious request.

Use dual approval for sensitive actions.
Large transfers, payment changes, privileged access, and password resets should need more than one approver.

Enforce separation of duties.
No single person should be able to initiate, approve, and execute a critical transaction alone.

Use stronger controls for privileged users.
Apply MFA, role-based access control, and tighter monitoring for administrators, finance users, executives, and helpdesk staff.

Train staff on realistic scenarios.
Training should not only say “deepfakes exist.” It should cover common business scenarios, such as fake CEO calls, vendor payment changes, fake customer recovery requests, and fake IT access requests.


3. Misinformation and Disinformation

Deepfakes can also damage trust at scale.

  • A fake executive statement can harm a company’s reputation.
  • A fake investment endorsement can deceive customers.
  • A fake crisis video can create public panic.
  • A fake announcement can influence markets.

MAS notes that deepfakes can distort news, corporate announcements, and public confidence. They can also affect market integrity and investor confidence.

Misinformation and disinformation

Propagation and response sit on the same page: fake content spreads through amplification, reaches audiences, and produces impact, then the response lifecycle begins.

Source

Fake content

Deepfake video · audio · images · text

Spread

Amplification

Social media · news · video platforms · messaging · fake websites · paid ads · lookalikes

Audience

Customers, employees, investors, media, public

People encounter and share the claim.

Impact

Reputation, trust, market, confidence

The effect is organizational, not just technical.

Monitor Verify Assess Respond Communicate Recover

Brand and executive monitoring · executive protection · takedown procedures · crisis communication templates · intelligence sharing

Practical controls

Monitor for brand and executive abuse.
Track social media, news sites, video platforms, fake websites, paid ads, and lookalike domains.

Protect senior executives.
Executives are high-value targets because their public images and speeches can be reused to create fake content.

Prepare takedown procedures.
Know who will contact platforms, legal teams, law enforcement, regulators, and external partners.

Create crisis communication templates.
Prepare statements for customers, employees, regulators, media, and the public before an incident happens.

Share intelligence.
Work with industry peers, regulators, and information-sharing groups. Deepfake campaigns often target more than one organization.


The 3A Approach

A simple way to handle suspicious content or requests is the 3A approach.

Assess

Check the source, context, and intent.
Ask:
  • Is the request expected?
  • Is the timing unusual?
  • Is the person asking for something sensitive?
  • Is there pressure to act fast?
  • Is there a request to bypass normal process?

Analyse

Look for technical and behavioural signs.
Examples:
  • Unnatural blinking
  • Poor lip sync
  • Mismatched lighting
  • Blurred face edges
  • Robotic voice

Warning: Quality is improving

Authenticate

Verify through trusted controls.
Examples:
  • Known phone number
  • Secure internal workflow
  • MFA challenge
  • Dual approval

The goal is not to spot every deepfake. That is unrealistic.

The goal is to prevent a deepfake from becoming an approved action.


What Organizations Should Do Now

Start with the highest-risk business processes.

Focus on:

  • Customer onboarding
  • Account recovery
  • Payment approval
  • Vendor bank detail changes
  • Privileged access requests
  • Executive instructions
  • Recruitment
  • Public communications
  • Crisis response

For each process, define what must happen before action is taken.

A practical standard should be:

  • High-risk requests must not rely on one channel.
  • Sensitive transactions need independent approval.
  • Staff must know how to challenge unusual requests.
  • Deepfake incidents must be part of incident response.
  • Brand and executive impersonation must be monitored.
  • Controls must be tested through simulations.

Key Takeaways

Deepfakes are attacks against digital trust.

The highest-risk areas are biometric onboarding, payment approval, privileged access, customer servicing, recruitment, and public communications.

Detection tools help, but they are not enough. Deepfake detection will never be perfect.

The stronger approach is layered defense:

  • Verify high-risk requests through a separate trusted channel.
  • Strengthen biometric and document checks.
  • Protect against media injection attacks.
  • Require dual approval for sensitive actions.
  • Train staff using realistic scenarios.
  • Monitor for brand and executive impersonation.
  • Include deepfakes in incident response plans.

Deepfake defense is not about distrusting everyone. It is about making trust verifiable.


References