Skip to main content
AEO/GEO

What to Do When Someone Fakes Your Brand

Short answer. The best-documented defence against a deepfaked executive is a process, not a product: a Ferrari executive defeated a CEO voice clone by asking a question only the real…

Mumu D. · September 2026 · 13 min read

Download PDF

Short answer. The best-documented defence against a deepfaked executive is a process, not a product: a Ferrari executive defeated a CEO voice clone by asking a question only the real person could answer. That matters because a CrowdStrike study found 65% of employees who received a cloned voice call from their "CEO" complied before seeking independent verification. Cyble reported AI deepfakes in over 30% of high-impact corporate impersonation attacks in 2025. Treat the loss totals in this field with suspicion — the reporting is inconsistent, and headline sums should not be converted into per-incident averages.

Brand?

The best deepfake defence I have come across was not a piece of software. It was a question about a book.

An executive at Ferrari received a call from someone who sounded exactly like the company's CEO, discussing a confidential acquisition and pushing for urgency. Rather than complying, the executive asked a question only the real person could answer: the title of a book the CEO had recommended to him days earlier. The caller could not answer. The call ended.

That story gets told as a curiosity. It should be told as policy, because it demonstrates the thing most organisations get wrong about this threat. The defence that worked was a process, not a detection tool. No software was involved.

Someone simply refused to act on an unusual request through an unusual channel without independent verification.

That is the argument of this piece, and the data supports it more strongly than most vendors would like.


What the threat actually looks like now

Two years ago this was a niche problem affecting a handful of public figures. It is now an industrialised attack vector, and the shape of it matters for how you defend.

Executive voice cloning for payment fraud is the most financially damaging vector. Attackers clone a voice from earnings calls, conference talks, podcast appearances or social video, then call a finance team member impersonating the CEO to authorise an urgent transfer. These calls tend to arrive late on Friday afternoons or during known travel, when independent verification is inconvenient.

The compliance rate is the uncomfortable part. A CrowdStrike study found that 65% of employees who received a cloned voice call from their "CEO" complied with the request before seeking independent verification.

Real-time video call impersonation has escalated the same technique. The largest single deepfake scam on record used live video impersonation of multiple colleagues simultaneously on the same call, which defeats the instinct that a face on a video call is verification.

Fake job candidates using real-time face-swapping in interviews, either to secure a role on false credentials or to gain access to internal systems. The FBI's Internet Crime Complaint Center flagged this in 2022; by 2025 it had become systematic.

Internal impersonation of IT staff, HR directors or team leads to extract credentials or authorise access changes. The internal trust that makes an organisation function is the attack surface.

Brand and advertising impersonation, where synthetic executives or spokespeople appear in fraudulent ads.

Researchers identified more than 100 deepfake video ads impersonating a single UK prime minister on one platform in a single month, which gives a sense of how cheaply this scales.

Cyble's Executive Threat Monitoring reporting found AI deepfakes involved in over 30% of high-impact corporate impersonation attacks in 2025, and CEO fraud using deepfakes now reportedly targets around 400 companies per day.


A word about the numbers, because this field is noisy

I want to flag something before going further, because the statistics in this area are unusually unreliable and I would rather you knew which ones I trust.

This topic is dominated by aggregator articles recycling the same figures, frequently without primary attribution, and often with headline numbers that do not survive scrutiny. I found one headline claiming a 3,892% fraud surge, which is the kind of figure that gets quoted for years without anyone checking what it measures.

Two sources in this space were notably honest about their own limitations, and their caution is worth adopting.

One noted that a full-year 2025 reported loss total exceeding $1.28 billion should not be converted into an average loss per incident, because most incidents had no disclosed financial figure, the largest public cases dominate the total, and media datasets are biased toward events that become visible.

Another stated plainly that the various available datasets cannot be combined into one global total, because each measures a different stage of the fraud process.

The figures I would put in front of a board are the ones with a named source and a defined measurement: the CrowdStrike compliance rate, the Cyble corporate impersonation share, and the detection accuracy figures below. The billion-dollar totals and percentage surges I would leave out.


Why detection is not the defence

This is the section that should change budget allocation, because the instinct when facing a deepfake threat is to buy a detector.

AI detection tools claim 90 to 96% accuracy in laboratory settings, with Intel's FakeCatcher reported at 96%. Realworld effectiveness drops 45 to 50%. Which means a tool achieving 96% in the lab may perform at roughly 48% in production. That is a coin flip, deployed as a control.

Humans are worse. iProov's research puts human detection of deepfakes at 0.1%. Separate work by Veriff and Kantar found people performing only slightly above chance when asked to identify manipulated visuals. So "train staff to spot deepfakes" is not a viable control either, and any awareness programme built on spotting visual artefacts is training people for a task they cannot perform.

And the asymmetry is widening. Detection improves incrementally; generation quality improves with every model release.

The conclusion practitioners have reached is that detection is a supporting control, not a primary one. The primary control is process: making the fraud fail even when the fake is convincing. The Ferrari executive did not detect anything. He simply required verification through a channel the attacker did not control.


The three layers that actually work

Layer one: process controls that make the fake irrelevant.

This is where most of the protective value sits and it costs almost nothing.

Out-of-band verification for every irreversible action. Wire transfers, payee changes, credential resets, access grants and contract signatures arriving through an unusual channel require call-back on a known number, not a number supplied in the request.

Pre-agreed passphrases or challenge questions for executive-level requests. This is the Ferrari method, formalised. It works because it requires knowledge the attacker cannot synthesise.

Remove urgency as an authorisation shortcut. The attack mechanics are consistent: establish authority, manufacture urgency, restrict independent verification, push toward an irreversible action. A policy that no genuine request is ever too urgent for verification removes the mechanism the attack depends on.

Rehearse it. Deepfake scenarios belong in tabletop exercises and red team engagements. Some security firms now include voice-clone and video-conference deepfake scenarios in social engineering testing, which tells you the threat has moved from theoretical to operational.

Layer two: provenance, so your genuine content is verifiable.

Rather than trying to prove a fake is fake, you make your real content provably real. The relevant standards are C2PA, Adobe Content Credentials and Google SynthID, which embed cryptographic provenance in generated and captured media.

Adoption has reached meaningful scale. Google reported in May 2026 that SynthID had watermarked more than 100 billion images and videos plus 60,000 years of audio, with verification used 50 million times globally.

The practical strategy is to tag all genuine corporate content, so that unlabelled media claiming to be from you becomes automatically suspect. That inverts the burden: instead of proving a fake is fake, you point to the absence of credentials.

Two honest caveats. Adoption is uneven, strongest in enterprise creative tools and weakest in open-source generation pipelines, so an attacker using open tooling produces unlabelled media without effort. And provenance is not a complete fraud defence: it strengthens evidence about origin, but capture integrity, identity verification, transaction monitoring and independent approval address the wider scam process.

Layer three: monitoring and response.

Content monitoring platforms scanning for media referencing your brand, executives or products, and liveness detection integrated into identity verification workflows for hiring and KYC.


What the law now gives you

The legal position has moved substantially and gives brands more leverage than most realise.

The TAKE IT DOWN Act was signed in May 2025. It criminalises certain publication of non-consensual intimate imagery including AI-generated material, and from 19 May 2026 covered platforms must provide a removal process and take down validly reported content and known identical copies within 48 hours. The FTC began enforcing the platform requirements and sent warning letters to a dozen websites on 20 May 2026.

The DEFIANCE Act creates a federal civil cause of action for deepfake victims, with damages up to $150,000 per violation or actual damages, whichever is greater, and holds platforms liable where they fail to act.

Both are aimed primarily at non-consensual intimate imagery rather than corporate impersonation, so a brand cannot rely on them directly for most commercial deepfakes. But they establish precedent, they create functioning notice-and-takedown infrastructure at platforms, and that infrastructure is what you use when reporting brand impersonation.

EU AI Act obligations phase in through 2027, adding transparency duties around synthetic content, and US state-level deepfake laws continue to expand.


The response playbook

When it happens, and increasingly it will, speed matters more than perfection.

Preserve evidence first. Screen recordings, URLs, timestamps, account details, and the content itself before it is deleted.

Reporting frequently removes the material you would need later.

Report through platform channels immediately. The notice-and-takedown infrastructure now exists and is subject to regulatory attention.

Notify internally before externally. Your own staff are a target audience for the fake. A message to employees saying what happened and reminding them of verification procedures prevents the secondary attack that often follows.

Communicate to customers with specifics. Not "beware of scams" but "a video circulating on this platform showing our CEO announcing an investment scheme is fabricated; we do not solicit investments by video message." Specificity is what makes the correction usable.

Point to your verified channels. This works only if you established them beforehand, which is the argument for provenance work in advance.

Involve legal early for preservation orders and platform escalation.

Debrief the process, not the technology. The useful question after an incident is not "how did we not spot it" but "which control should have made this fail, and did it exist?"


The gap almost nobody covers

Every framework I found in researching this is written in English, for English-speaking organisations, and assumes the target and the attacker share a language.

That assumption fails in exactly the environments most exposed. A multinational running finance operations across several countries has staff receiving instructions in a second or third language routinely. The subtle cues that might make a synthetic voice feel wrong, idiom, register, regional phrasing, hesitation patterns, are precisely the cues a non-native listener has least access to. A cloned voice speaking English to a team in Manila, Jakarta or Nairobi loses the anomalies a London colleague might half-notice.

Voice cloning quality also varies by language in ways that cut both ways. Cloning is generally strongest in high-resource languages with abundant training audio, so an executive with hours of public English speaking is more cloneable in English than in a language they rarely use publicly. That creates an underused control: verification in a language the attacker's model is less likely to handle well.

This is where our own work sits, so I will declare the interest. Lifewood operates across 50-plus languages with human-inthe-loop verification as the core discipline, and we build the multilingual speech and content data that underpins both generation and detection systems. Two practical points follow from that vantage.

First, verification procedures need writing in every operating language, not translated as an afterthought. A challengequestion protocol that exists only in the English employee handbook does not protect a finance team in another market.

Second, if you produce synthetic media legitimately, as many brands now do, provenance discipline on your own output is part of the defence. An organisation generating AI content without credentials is contributing to an environment where unlabelled synthetic media looks normal, which is the environment attackers depend on.


What to do this quarter

Write the out-of-band verification policy for wire transfers, payee changes, credential resets and access grants. One page.

Establish executive challenge questions and brief the people who would receive such a call.

Audit your executives' public audio footprint. Not to reduce it, that is impractical, but to know what an attacker has to work with.

Start tagging genuine content with C2PA or Content Credentials, beginning with executive video and official announcements.

Add a deepfake scenario to your next tabletop exercise.

Write the response playbook before you need it, including who preserves evidence and who authorises public statements.

Translate all of it into every operating language.

None of that requires a detection platform. All of it works whether the fake is convincing or not, which is the property that matters when the fakes keep getting better.


Key takeaways

  • The best documented defence was a process, not a tool: a Ferrari executive defeated a CEO voice clone by asking a question only the real person could answer.
  • A CrowdStrike study found 65% of employees who received a cloned voice call from their "CEO" complied before seeking independent verification.
  • Cyble reported AI deepfakes involved in over 30% of high-impact corporate impersonation attacks in 2025, with CEO fraud reportedly targeting around 400 companies per day.
  • The largest single deepfake scam used real-time video impersonation of multiple colleagues on the same call.
  • Statistics in this field are unreliable. One source cautioned that a $1.28 billion reported loss total should not be converted into an average per incident; another that available datasets cannot be combined into one global total.
  • Detection tools claim 90 to 96% laboratory accuracy but real-world effectiveness drops 45 to 50%, so a 96% tool may perform at roughly 48% in production. iProov puts human deepfake detection at 0.1%, and Veriff and Kantar found people performing only slightly above chance. Training staff to spot fakes is not a viable control.
  • Detection is a supporting control. The primary control is process that makes fraud fail even when the fake is convincing.
  • Layer one is out-of-band verification for irreversible actions, pre-agreed challenge questions, removing urgency as an authorisation shortcut, and rehearsing deepfake scenarios in tabletops.
  • Layer two is provenance: C2PA, Content Credentials and SynthID. Google reported in May 2026 that SynthID had watermarked over 100 billion images and videos and 60,000 years of audio, with verification used 50 million times.
  • Provenance adoption is uneven, strongest in enterprise creative tools and weakest in open-source pipelines, and it strengthens evidence about origin rather than defeating the wider scam process.
  • The TAKE IT DOWN Act, signed May 2025, requires covered platforms from 19 May 2026 to remove validly reported content within 48 hours. The FTC sent warning letters to a dozen websites on 20 May 2026.
  • The DEFIANCE Act creates a federal civil cause of action with damages up to $150,000 per violation.
  • Response priorities: preserve evidence first, report through platform channels, notify staff before customers, communicate with specifics, point to verified channels, involve legal early.
  • Deepfake guidance is written in English and assumes shared language. Non-native listeners have least access to the cues that make a synthetic voice feel wrong, and verification procedures need to exist in every operating language.

Sources and further reading

Frequently asked questions

Only partially. Tools claiming 90 to 96% laboratory accuracy show real-world effectiveness drops of 45 to 50%, meaning a 96% tool may operate near 48% in production.

Not reliably. iProov puts human detection at 0.1% and other research finds people performing only slightly above chance. Train them on verification procedures instead, which work regardless of how convincing the fake is.

Out-of-band verification for irreversible actions, combined with pre-agreed challenge questions for executive requests. This is what defeated the Ferrari attack, and it works because it requires knowledge the attacker cannot synthesise.

No, but it changes the burden. Tagging genuine content with C2PA or Content Credentials makes unlabelled media claiming to be from you automatically suspect. Adoption is uneven and it addresses origin rather than the wider fraud process.

The TAKE IT DOWN Act requires covered platforms to remove validly reported content within 48 hours from 19 May 2026, with FTC enforcement underway. The DEFIANCE Act allows damages up to $150,000 per violation. Both target non-consensual intimate imagery primarily, but the takedown infrastructure serves brand reporting too.

In some respects yes. Staff receiving instructions in a second language have least access to the idiom and register cues that make a synthetic voice feel wrong, and verification procedures that exist only in English do not protect teams in other markets.

Have an AI or visibility project in mind?

From AI evaluation and human-in-the-loop review to GEO and AEO strategy, our team can help you deploy with confidence and get found in the AI search era.

Talk to our team