How to Spot Deepfake Video Call Scams?
Scammers can now fake a live video call of your CEO or your child. The good news: even the best deepfakes still fail simple physical tests you can run mid-call. Here's exactly how to catch them.
A deepfake video call scam puts an AI-generated face and voice of someone you trust on your screen, usually a boss or relative, asking you to wire money or share passwords. Catch it live by forcing the fake to do things it renders badly: ask them to turn fully sideways, wave a hand across their face, or answer an unpredictable personal question on the spot.
The $25 Million Call That Looked Completely Real
In early 2024, a finance worker at engineering firm Arup in Hong Kong joined what looked like a routine video conference. The company's UK chief financial officer was on screen. So were several colleagues the employee recognized. Everyone spoke, looked, and moved normally.
Every single person on that call except the victim was a deepfake.
The scammers had scraped real video and audio of the executives from public sources, generated live avatars, and ran a scripted meeting. The employee, reassured by seeing familiar faces, approved 15 transfers totaling about 200 million Hong Kong dollars, roughly 25.6 million US dollars. Police confirmed the entire meeting was synthetic.
What matters here: the victim wasn't careless. They saw multiple trusted faces confirming each other. That social proof, several people agreeing, is exactly the pressure that shuts down suspicion. A single fake face is easier to doubt. A whole room of them feels safe. That was the trap.
How Criminals Build a Live Fake of Your Boss
The attack has four moving parts, and each one is now cheap.
1. **Harvest.** Scammers collect footage and voice from LinkedIn videos, conference recordings, earnings calls, YouTube, and Instagram. Sixty seconds of clear audio and a few minutes of face video is plenty.
2. **Train.** Tools like DeepFaceLive and open-source face-swap models generate a real-time avatar that maps onto the scammer's own head movements as they sit at a webcam.
3. **Clone the voice.** Services like ElevenLabs turn a short sample into speech the scammer types or speaks through in real time.
4. **Stage the call.** A virtual webcam driver pushes the fake face directly into Zoom, Teams, or Google Meet as if it's a normal camera.
The processing runs on a decent gaming GPU. No secret lab required. Anyone following a tutorial can assemble the whole setup, which is why these attacks are climbing fast instead of staying rare.
The weak spot is real-time generation costs serious computing power, so the model cuts corners on anything unusual. That's where you attack back.
The 10-Second Tests That Break a Deepfake
Live deepfakes are trained on front-facing, well-lit faces doing normal things. Push them off that path and the illusion cracks. Try any of these mid-call:
- **Ask them to turn their head fully sideways.** Most real-time models fall apart at a 90-degree profile. Ears smear, the face wobbles, the jaw detaches for a frame. - **Have them wave a hand slowly in front of their face.** The model struggles to redraw the face behind a moving object. You'll see flicker or the hand vanishing into the cheek. - **Ask them to press a finger against their nose or cheek.** Skin doesn't deform correctly. - **Say something genuinely unexpected.** Ask about a specific private memory only the real person knows. Cloned voices stall on unscripted, personal answers.
Most guides tell you to look for unnatural blinking. That advice is mostly outdated now. Newer models blink fine. Motion and occlusion tests work far better than staring at eyes.
Here's the genuine hard part: the failure often lasts a single frame, so watch for a quick glitch rather than a long obvious melt. If someone refuses a simple motion request or gets irritated by it, treat that resistance itself as a red flag.
Why Smart People Approve the Wire Anyway
Detection tests only help if you use them, and the scam is built to stop you from thinking clearly. Every operation runs on three levers: authority, urgency, and isolation.
Authority means the 'boss' outranks you, so questioning them feels rude and risky. Urgency is 'the deal closes in an hour, wire it now.' Isolation is 'keep this confidential, don't loop in the team.' When those three combine, critical thinking drops off a cliff.
If you're relying on 'I'd just know if it was fake,' save that confidence for something else. The Arup employee knew those colleagues personally.
The real defense is procedural, not visual. Any payment or credential request that arrives by video call gets verified through a second channel you initiate yourself. Hang up and call the person on their known number. A real boss will never punish you for confirming a large transfer. A fake one can't survive the callback.
Key Takeaways
FAQ
Q: Can a deepfake video call happen on Zoom or Microsoft Teams?
A: Yes. Scammers use virtual webcam software that feeds the fake face into any platform as if it were a real camera, so Zoom, Teams, and Google Meet are all vulnerable. The platform can't tell the difference because it just sees a camera input.
Q: Do these physical tests actually work, or is that wishful thinking?
A: They work well against current consumer and criminal-grade real-time tools, which still smear on profile turns and hand occlusion. Be honest that top-tier research models are improving, so treat the tests as a strong warning sign, not a certificate, and always confirm with a callback.
Q: What should I do the moment I suspect a call is fake?
A: Stop, invent a reason to end the call ('my connection's dropping, I'll call you right back'), then dial the person directly on their saved number. Never approve any payment or send credentials until that separate call confirms it's really them.
Conclusion
Deepfake video calls succeed because they hijack the one thing you trusted most: a familiar face agreeing with you. Pick one rule and adopt it today. Any request for money, gift cards, or passwords that comes over video gets verified by a call you place yourself to a known number, no exceptions. That single habit defeats a $25 million-caliber attack for free.
Related Posts
- How Are AI Deepfakes Used in Romance Scams?
Romance scammers are now using real-time AI deepfake video and cloned voices to impersonate attractive strangers — and sometimes even your own family members. The technology costs less than $20/month and is shockingly convincing. Here's what the attack looks like and how to protect yourself today. - How Are AI Deepfakes Targeting Your College?
AI voice clones and deepfake video calls now impersonate students and university leaders to steal financial aid, redirect tuition, and crack into campus accounts. A 15-second voicemail of you is enough. Here's how the scam runs and how to shut it down. - How Are AI Deepfakes Stealing Billions From You?
A CFO in Hong Kong wired $25 million after a video call with people who didn't exist. AI deepfakes now clone voices from 3 seconds of audio and generate real-time video of anyone. This is happening to ordinary people right now — not just executives.