Picture a finance manager who gets a message from the CFO about a confidential transaction. It feels a little off, so the manager asks for a video call. On the call, the CFO is there, along with several familiar colleagues. They look right and sound right, and they all agree the payment needs to go out today.
That is close to what happened to a finance employee at the engineering firm Arup. Hong Kong police said the employee was pulled into a video call with people he believed were the chief financial officer and other staff, and all of them turned out to be deepfake re-creations. He later sent about $25.6 million across 15 transactions.
The lesson for business owners is simple. Seeing someone on a screen is no longer proof that the person is real. For businesses in El Paso, TX and Las Cruces, NM, that changes how payments, account changes, and sensitive requests should be handled.
What Is a Deepfake?
A deepfake is a video, image, or other piece of media that has been created or altered with artificial intelligence to make it look like a real person did or said something they did not.
Older digital fakes, like a clumsy Photoshop job, were easy to spot. Deepfakes are different because AI software studies real footage of a person, such as their face, expressions, and movements, and then generates new footage that looks like them. The source material often comes from places businesses already publish: a company website, a LinkedIn profile, a conference recording, a promotional video.
Deepfakes can involve audio too, and we cover that separately in our post on voice cloning scams. This article is about the visual side: fake video, manipulated images, and impersonation that relies on what you can see.
Why Deepfake Scams Are Becoming a Business Problem
Fraud has always depended on trust. Criminals pretend to be a boss, a vendor, or a bank because people tend to act on requests from someone they recognize. Deepfakes make that pretense more convincing.
The concern is also showing up in official warnings. In November 2024, the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an alert about deepfake fraud. FinCEN said it had observed an increase in suspicious activity reports describing the suspected use of deepfake media in fraud schemes, starting in 2023 and continuing into 2024. The alert focused mainly on banks and identity verification, but it also noted that deepfake media may be used in phishing attacks and scams to defraud businesses and consumers by impersonating trusted individuals.
Arup’s own technology chief described the trend this way: the number and sophistication of attacks the company faces had been rising sharply in recent months.
None of this means every small business is about to be hit by a Hollywood-grade fake. Most fraud attempts are still simple, like a spoofed email asking for a gift card purchase. The point is that the tools for more convincing impersonation are now cheaper and easier to use, and attackers go where the money is. Any business that moves funds, pays vendors, or manages sensitive accounts is a potential target, regardless of size.
How Scammers Can Use Deepfakes Against Businesses
Deepfakes rarely work alone. They are usually one piece of a larger social engineering scheme, where the goal is to pressure someone into doing something they would not normally do. A few realistic scenarios:
A fake executive video call. An employee is invited to a meeting where a “leader” appears on camera and asks for an urgent transfer or a change to payment details. The Arup case followed this pattern, and it also shows why a call with several familiar faces can feel more trustworthy than a single email.
Fraudulent payment requests with visual “proof.” A scammer might send a short video message from a supposed owner or controller, saying a wire needs to go out before the end of the day. The video exists to shut down the employee’s doubts.
Fake vendor or employee verification. Attackers can pose as a new hire during a remote interview, or as a vendor representative confirming new banking information on camera. FinCEN’s alert describes criminals using altered or generated photos and videos to get past identity checks, which is the same idea applied to a business setting.
Impersonating company leadership to staff. A fake video of an owner announcing a “new software tool” or asking employees to log in to a portal can be a way to steal credentials.
Reputation attacks. A fabricated video of an executive saying something damaging can spread quickly on social media before anyone can respond.
A local example makes it concrete. Imagine an accounting manager at a family-owned company in El Paso who gets a video message from the owner, who is traveling, asking for an emergency payment to a “new supplier.” The owner looks and sounds right, and the manager does not want to be the person who delayed something important. That pressure is exactly what the attacker is counting on.
Why Deepfakes Are Harder to Identify
For years, advice about fake media focused on spotting flaws: odd blinking, blurry edges, lips that do not match the words. Those clues can still appear, but relying on them is a losing strategy.
The technology keeps improving, and attackers can pick their moment. A short, slightly grainy video call on a bad connection hides many imperfections, and the grainy picture feels normal because everyone has seen choppy video calls. In the Arup case, the employee reportedly had doubts at first, but put them aside after the call because the other attendees looked and sounded like colleagues he recognized.
There is also a human factor. When a request appears to come from the CEO, most employees are not thinking about forensic analysis. They are thinking about being responsive. Scammers deliberately create urgency, secrecy, and authority to keep people from slowing down.
That is why businesses should not ask employees to be human deepfake detectors. A better approach is to build processes that work even when the fake is flawless.
Warning Signs Employees Should Watch For
Visual clues can still help, as long as they are treated as extra signals and never as proof that something is real or fake. If a video seems off, it is worth pausing. Things to notice:
- Facial movement that looks slightly stiff, or lip movement that lags behind speech
- Odd lighting, shadows, or edges around the face and hair
- A person who avoids turning their head, or whose image glitches when they move
- Unexpected technical excuses, like a camera that “can’t be turned on” or a request to switch to a different app
The behavior around the video is often more revealing than the video itself. Be cautious when a request:
- Involves money, credentials, or sensitive data
- Comes with unusual urgency or a demand for secrecy
- Bypasses normal approval steps (“don’t loop in accounting”)
- Changes bank details or payment methods
- Arrives through an unusual channel or from an unfamiliar account
A request that checks every box above deserves verification, no matter how real the person looks.
How Businesses Can Protect Themselves From Deepfake Scams
The most effective way to prevent deepfake scams is to make sure no single phone call, message, or video can authorize something risky on its own. A few practices do most of the work.
Set a clear verification procedure. For payments, banking changes, and sensitive data requests, require confirmation through a separate channel. That means calling back on a number already on file, not one provided in the request. Make this a written policy so employees do not have to improvise.
Require dual approval for wire transfers and large payments. Two people signing off makes it much harder for one convincing impersonation to succeed. Set thresholds that fit your business.
Give employees permission to say no. Staff need to know they will never be penalized for verifying a request, even one that appears to come from the owner. Many successful frauds depend on people being afraid to question authority.
Use multi-factor authentication (MFA) everywhere. If a deepfake convinces someone to share a password or approve a login prompt, MFA adds a barrier. Pair it with access controls so employees only have access to what their role requires. That limits the damage when one account is compromised.
Train regularly and use real examples. Short, practical sessions that walk through scenarios work better than an annual slideshow. Include finance, HR, and executive assistants, since those roles are frequent targets.
Reduce what attackers can learn about you. Not everything needs to be public. Consider what executive video, org charts, and travel schedules are posted online, since those details help attackers craft believable requests.
Keep your technical defenses current. Email filtering, endpoint protection, and monitoring do not detect a deepfake directly, but they help catch the phishing emails, malicious links, and suspicious logins that usually come with these schemes. Reliable backups matter too, in case an attack leads to something worse than a bad payment.
What To Do If You Suspect a Deepfake Scam
Speed matters, but so does staying calm. If something feels wrong, employees should know the steps in advance:
- Pause. Do not complete the request, even if the person is pressuring you.
- Verify through a separate channel. Contact the person using a known phone number or in person.
- Report it internally. Tell a manager or your IT provider right away, even if you are not sure.
- Preserve the evidence. Save emails, chat messages, meeting links, and recordings if available.
- Contact your bank immediately if money moved. The sooner a bank is notified, the better the chance of recovering funds.
- Report the incident. Businesses in the U.S. can file a report with the FBI’s Internet Crime Complaint Center (IC3.gov).
How Excellent Networks Can Help
Deepfake scams are partly a technology problem and partly a people-and-process problem, so there is no single product that solves them. This is where an IT partner makes a difference.
At Excellent Networks, we work with businesses in El Paso and Las Cruces on the layers that reduce exposure to deepfake attacks. Our cybersecurity services cover email protection, endpoint security, MFA, and access controls. Our managed IT services keep systems patched and configured properly, and 24/7 monitoring helps flag unusual logins or account activity that could signal a compromised account. Through IT consulting, we also help businesses write verification and approval procedures that fit how they actually operate, and we support employee security awareness so teams know what to do when something looks wrong.
You should involve your IT or cybersecurity provider when a request involves money or credentials and something feels off, when you want to review your payment approval process, or after any suspected incident. Do not wait for a loss to bring them in.