Deepfakes are no longer a novelty. Convincing voice clones can be produced from a few seconds of public audio, real-time video impersonation tools are widely available, and AI-generated images have already been used to deceive employees, customers, and partners. For small and mid-sized businesses, the most pressing question is not whether deepfakes are real — they are — but how to recognize and respond to them before they cause harm.
Why are SMBs being targeted?
Attackers know that small and mid-sized businesses often have less mature fraud prevention than large enterprises, but still handle meaningful sums of money. A convincing deepfake of a CEO calling the finance team late on a Friday afternoon to request an urgent wire transfer can succeed in environments where verification habits are not yet second nature.
What does a deepfake attack look like in practice?
The most common scenarios share a familiar pattern: a request that creates urgency, an unusual channel of communication, and pressure to act before there is time to verify. The signal is rarely the audio or video quality; it is the situation itself, which is why process-based defenses tend to outperform technical detection.
What practical steps can businesses take?
- Require out-of-band verification: Confirm unusual financial or sensitive requests using a separate, known channel — never the channel the request arrived on.
- Use pre-arranged code words: Establish simple verification phrases for executive and finance teams, refreshed periodically, so identity can be confirmed quickly in a tense moment.
- Train the front line: Provide scenario-based training for receptionists, executive assistants, and finance staff, who are the most common first points of contact for deepfake attempts.
- Strengthen approval workflows: Require multi-person approval for high-value transactions, regardless of who appears to be asking, so a single deceived employee cannot complete the transaction alone.
- Limit public audio and video exposure: Be thoughtful about how much executive audio and video is publicly available, since this is the raw material attackers use to build convincing clones.
How should businesses respond after a suspected deepfake attempt?
Treat suspected deepfake attempts the way you would treat any other fraud attempt: preserve evidence, alert the relevant internal team, and report to appropriate authorities. Just as importantly, share the experience internally so others learn from it. Deepfake awareness compounds quickly when employees hear real, anonymized examples from their own organization.
Email noelga@vastmanagementcorp.com
Phone +1-516-449-7411