Deepfakes: Cyber Risks and Practical Controls
An analysis of the key cyber risks associated with deepfakes across biometric authentication, social engineering, and disinformation, along with practical mitigation controls.
Contents
Category
Article
Tags
Contents
Deepfakes use artificial intelligence to create fake audio, video, images, documents, and text. They mimic real people or real events to deceive others.
This is now a business risk, not just a media risk.
As deepfake tools become cheaper and easier to use, attackers can use them to bypass security checks, steal funds, impersonate executives, manipulate customers, damage reputations, or support corporate espionage.
The key point is simple: deepfakes attack trust.
They exploit the trust we place in faces, voices, documents, video calls, public statements, and digital onboarding processes.
According to the Monetary Authority of Singapore’s September 2025 information paper, deepfakes create risks across biometric authentication, social engineering, impersonation scams, misinformation, disinformation, fraud, market integrity, regulatory exposure, and reputation.
Three Main Deepfake Threats
MAS highlights three main deepfake risk areas:
Biometric bypass
What attackers do: Use fake faces, videos, or documents to pass onboarding or login checks.
Main controls: Liveness detection, document verification, injection protection.
Impersonation scams
What attackers do: Use fake voice or video to trick staff or customers.
Main controls: Out-of-band verification, dual approval, separation of duties.
Misinformation and disinformation
What attackers do: Use fake public content to damage trust or manipulate decisions.
Main controls: Media monitoring, takedown process, crisis playbooks.
1. Defeating Biometric Authentication
Many organizations use biometric checks during customer onboarding, login, and identity verification.
Deepfakes can weaken these controls.
Attackers can use synthetic faces, altered selfies, forged documents, stolen images, or pre-recorded videos. They can also use virtual camera software to feed fake video into a verification process.
This creates several risks:
- Fake account creation
- Identity theft
- Unauthorized transactions
- Money laundering
- Account takeover
- Fraudulent loan applications
MAS cites cases where attackers used AI-generated photos, malware-stolen customer images, and doctored documents to bypass or attack digital KYC and facial recognition processes.
Defeating biometric authentication
Attackers inject synthetic or stolen identity material to bypass verification controls and open the door to downstream fraud.
Deepfake identity input
Synthetic face · forged document · stolen image · virtual camera injection
Biometric verification
Customer onboarding · login · digital KYC
Document checks · liveness detection · injection detection
Fraudulent identity accepted
Controls are defeated. Attacker is treated as a legitimate user.
Identity fraud
Fake accounts · account takeover · transaction fraud · money laundering
Practical controls
Use stronger document checks.
Do not rely only on uploaded images. Check document security features, metadata, lighting, reflections, and inconsistencies across submitted documents.
Use liveness detection.
Ask users to perform random actions. Examples include blinking, turning their head, or responding to a prompt. Stronger systems should also check motion, texture, depth, and behavioural signals.
Detect injection attacks.
Attackers may use virtual cameras or browser manipulation to inject fake media into a live verification session. Use secure SDKs, runtime protection, device integrity checks, and anti-tampering controls.
Protect biometric data.
Use strong encryption in transit and at rest. Apply strict access control and secure key management. Where possible, use cancellable biometrics so stolen templates cannot be reused across systems.
Test the biometric process.
Run security testing against realistic deepfake samples. Test against different tools and techniques, not only one known attack method.
2. Social Engineering and Impersonation Scams
This is the most practical deepfake risk for many organizations.
Attackers do not need to break the system. They only need to convince one person to act.
- A fake CEO can request a fund transfer.
- A fake customer can request an account change.
- A fake employee can ask IT to reset access.
- A fake vendor can request a bank account update.
- A fake job candidate can pass interviews using a synthetic identity.
MAS cites several incidents. These include a Hong Kong case where an employee was tricked into transferring US$25 million after joining a video call with deepfakes of the company’s CFO and colleagues. It also cites a Singapore case where a finance director transferred US$499,000 after a fake Zoom call involving impersonation of the company’s CEO and colleagues.
Social engineering and impersonation scams
The diagram centers the decision point. The attacker tries to trigger a high-risk action, and independent verification determines whether the action moves forward.
Request
Deepfake or impersonated request
CEO payment request · customer account change · helpdesk reset · vendor bank change · synthetic job candidate
Action
High-risk business action
Payment, access, or account change is about to happen.
Decision
Independent verification performed?
Out-of-band verification · dual approval · separation of duties · privileged-user controls
Yes
Trusted channel verification
Second approval follows and fraud is prevented.
No
Employee complies
Financial loss or access loss follows.
Practical controls
Do not trust a single channel.
A video call is not enough. A voice call is not enough. An email is not enough. For high-risk requests, verify through a separate trusted channel.
Use out-of-band verification.
If the request comes by video call, confirm it using a known phone number, secure workflow, or internal approval system. Do not use contact details provided inside the suspicious request.
Use dual approval for sensitive actions.
Large transfers, payment changes, privileged access, and password resets should need more than one approver.
Enforce separation of duties.
No single person should be able to initiate, approve, and execute a critical transaction alone.
Use stronger controls for privileged users.
Apply MFA, role-based access control, and tighter monitoring for administrators, finance users, executives, and helpdesk staff.
Train staff on realistic scenarios.
Training should not only say “deepfakes exist.” It should cover common business scenarios, such as fake CEO calls, vendor payment changes, fake customer recovery requests, and fake IT access requests.
3. Misinformation and Disinformation
Deepfakes can also damage trust at scale.
- A fake executive statement can harm a company’s reputation.
- A fake investment endorsement can deceive customers.
- A fake crisis video can create public panic.
- A fake announcement can influence markets.
MAS notes that deepfakes can distort news, corporate announcements, and public confidence. They can also affect market integrity and investor confidence.
Misinformation and disinformation
Propagation and response sit on the same page: fake content spreads through amplification, reaches audiences, and produces impact, then the response lifecycle begins.
Source
Fake content
Deepfake video · audio · images · text
Spread
Amplification
Social media · news · video platforms · messaging · fake websites · paid ads · lookalikes
Audience
Customers, employees, investors, media, public
People encounter and share the claim.
Impact
Reputation, trust, market, confidence
The effect is organizational, not just technical.
Brand and executive monitoring · executive protection · takedown procedures · crisis communication templates · intelligence sharing
Practical controls
Monitor for brand and executive abuse.
Track social media, news sites, video platforms, fake websites, paid ads, and lookalike domains.
Protect senior executives.
Executives are high-value targets because their public images and speeches can be reused to create fake content.
Prepare takedown procedures.
Know who will contact platforms, legal teams, law enforcement, regulators, and external partners.
Create crisis communication templates.
Prepare statements for customers, employees, regulators, media, and the public before an incident happens.
Share intelligence.
Work with industry peers, regulators, and information-sharing groups. Deepfake campaigns often target more than one organization.
The 3A Approach
A simple way to handle suspicious content or requests is the 3A approach.
Assess
Ask:
- Is the request expected?
- Is the timing unusual?
- Is the person asking for something sensitive?
- Is there pressure to act fast?
- Is there a request to bypass normal process?
Analyse
Examples:
- Unnatural blinking
- Poor lip sync
- Mismatched lighting
- Blurred face edges
- Robotic voice
Warning: Quality is improving
Authenticate
Examples:
- Known phone number
- Secure internal workflow
- MFA challenge
- Dual approval
The goal is not to spot every deepfake. That is unrealistic.
The goal is to prevent a deepfake from becoming an approved action.
What Organizations Should Do Now
Start with the highest-risk business processes.
Focus on:
- Customer onboarding
- Account recovery
- Payment approval
- Vendor bank detail changes
- Privileged access requests
- Executive instructions
- Recruitment
- Public communications
- Crisis response
For each process, define what must happen before action is taken.
A practical standard should be:
- High-risk requests must not rely on one channel.
- Sensitive transactions need independent approval.
- Staff must know how to challenge unusual requests.
- Deepfake incidents must be part of incident response.
- Brand and executive impersonation must be monitored.
- Controls must be tested through simulations.
Key Takeaways
Deepfakes are attacks against digital trust.
The highest-risk areas are biometric onboarding, payment approval, privileged access, customer servicing, recruitment, and public communications.
Detection tools help, but they are not enough. Deepfake detection will never be perfect.
The stronger approach is layered defense:
- Verify high-risk requests through a separate trusted channel.
- Strengthen biometric and document checks.
- Protect against media injection attacks.
- Require dual approval for sensitive actions.
- Train staff using realistic scenarios.
- Monitor for brand and executive impersonation.
- Include deepfakes in incident response plans.
Deepfake defense is not about distrusting everyone. It is about making trust verifiable.
References
- Primary Source: Monetary Authority of Singapore (MAS) Information Paper: Cyber Risks Associated with Deepfakes (September 2025). MAS Official Site.
- Biometric Bypass Incidents & Research:
- Group-IB: Deepfake Fraud Analysis & GoldFactory iOS Trojan.
- South China Morning Post: Hong Kong Police Arrest 6 in Deepfake Loan Scam.
- ArXiv Research: Deepfake Detection Modalities Paper.
- 404 Media: Underground AI Face Generation Services.
- Impersonation Scams & Hiring Risks:
- BleepingComputer: AI-Powered Investment Scams Defraud $20M.
- Channel NewsAsia: CEO Impersonation Scam Targeting Finance Director.
- CNN: Hong Kong Deepfake Romance Scam Arrests.
- The Cyber Express: North Korean Hacker Posing as Employee.
- The Pragmatic Engineer: AI Fakers and Deepfake Avatars.
- CBS News: Fake Job Seekers Flooding Market.
- Straits Times: Hong Kong Firm Scammed of $25M in CFO Video Call.
- Misinformation, Disinformation & Response Guidelines:
- Straits Times: PM Wong Warns Against Deepfake Investment Scams and PM Lee Promoted Scams Warnings.
- Hong Kong Securities and Futures Commission: Quantum AI Warning Alert.
- NY Post: Pentagon Fake Explosion Image Stock Market Impact.
- Cyber Security Agency of Singapore (CSA): Advisory on Deepfake Tactics.
- ISC2: Deepfake Concerns in the C-Suite.
- OWASP: Guide for Preparing and Responding to Deepfake Events.