TL;DR
- Deepfakes are AI-generated audio, video, or images that imitate a real person. The cost has dropped from "Hollywood studio" to "free phone app" in two years. Your ear and eye are no longer enough — the defence is a small habit, not better detection.
- The most damaging deepfake today is a 20-second voice clone of a relative or your boss, used over the phone to ask for money or a code. "Mum, I crashed the car, I need cash right now."
- Two habits beat almost every consumer-grade deepfake: a family code-word to verify any urgent voice or video request, and a slow callback through the phone number you already had — never a number on the screen.
- Children of public figures, victims of past data breaches, and people with a lot of public audio or video — podcasters, executives, influencers, public officials — are at highest risk. So are their families.
- Image-based abuse — non-consensual intimate deepfakes — is a separate category that needs its own response. Global services (StopNCII.org, Take It Down) can remove these without you uploading the image anywhere.
- "I won't be fooled" is what every fooled person believed.
What it is
A deepfake is any synthetic media — audio, image, or video — that imitates a real person convincingly enough to be used as if it were real. Three current categories:
- Voice clones. Built from as little as 5–10 seconds of someone's voice — a podcast clip, a TikTok, a voicemail, a YouTube interview, a Zoom recording. The clone can read any new text in the person's voice, with inflection.
- Face swap and lip-sync video. A short reference video of the target's face mapped onto another person's body, or an existing video of the target re-spoken with new audio. Quality varies but is getting cheaper monthly.
- AI-generated still images. A photo of a real person placed in a setting they were never in — sometimes intimate, sometimes politically compromising, sometimes for romance or identity fraud.
These are used in five main ways:
- "Family emergency" voice calls — the grandparent scam, evolved.
- Fake-CEO or finance-officer requests to staff — business-email-compromise, evolved.
- Romance fraud with video "proof" — the scammer appears on a brief call to prove they're real.
- Political disinformation — coordinated audio or video clips released ahead of elections.
- Image-based abuse — intimate deepfakes targeting women and minors disproportionately.
The underlying technology is not exotic anymore. The tools are publicly available, mostly legal to use, and rapidly improving. Treating this as something that happens "to other people" is the same mistake people made about phishing in 2015.
How to spot it
The old advice — "look for blurring at the jaw, count the fingers" — is now mostly obsolete. Recent generations of deepfake tools no longer leave those tells. The reliable signals have moved from the artefact to the context.
On a phone call:
- The voice is right but the conversation is shallow. The caller doesn't reference shared memories, can't answer "what did we talk about last weekend," can't be drawn into specifics only the real person would know.
- Urgency is high. Always urgency. "Don't tell anyone — I'm in trouble."
- The payment method is unusual. Gift cards. Crypto. Wire to an unfamiliar account. Real family members borrowing money do not, normally, ask you to send Apple gift cards.
- The caller wants the conversation off the original channel — "call me back on this WhatsApp number, my phone broke."
In a video call:
- The face moves slightly less than real faces do — micro-expressions look subtly off.
- The eyes don't follow naturally when you ask the person to look around the room.
- Lighting on the face doesn't quite match lighting in the background.
- One thing worth trying: ask them to turn sideways and slowly move a hand in front of their face. Some real-time deepfakes still break on this — the hand disappears, the face glitches, the lip-sync slips — but the tools improve every month, so treat a clean "pass" as one weak signal, not proof. The reliable move is still to verify through a separate channel.
In a still image:
- Reverse-image-search the photo. AI-generated faces typically have no other appearances online; real people do.
- Hands and ears are still the most error-prone areas in still images.
- The background is too clean or oddly inconsistent — a window with no view, a wall with no shadow, a logo that is almost a real logo.
Most reliable: ignore the artefacts. Verify through a different channel. Always.
What to do
If a suspicious voice or video has just contacted you:
- Stop the conversation. Politely or not. "Let me call you back." Hang up. Close the chat.
- Verify through a known channel. Call the person on the number you've had for them for years. If they don't answer, call a family member who would know where they are. Do not call back the number that just contacted you.
- Use the family code-word. Discussed below. If you don't have one yet, this is the moment to invent one.
- If money was asked for, do not send it — even if you're 90% sure it was them. The 10% case can be catastrophic; the wait is recoverable.
- If they showed urgency about secrecy — "don't tell your mum" — that confirms it. Real emergencies are not secret.
If you discover the deepfake after the fact (money sent, message believed, image shared):
- Call your bank immediately. International transfers can sometimes be recalled within 24 hours; after that, much harder.
- Save everything. Screenshots, voicemails, call logs, message threads, transaction confirmations. The case file matters even if you never recover the money, because it helps the next victim.
- Report to police. Your country's cybercrime unit, and the platform the contact came through. In the EU, also notify your national data-protection authority if your likeness or voice was used — that is a personal-data violation in itself.
- Tell your circle. The same operation likely targets your family and contacts next, using the credibility you just unwittingly lent them.
- If intimate imagery was involved, use a takedown service immediately — see below.
Set up a family code-word now, while everyone is calm.
- A short word or phrase only your household knows. Not a birthday, not a pet name (those are on social media).
- "Pumpkin sunset," "blue crayfish," "Tuesday Yvonne." Anything memorable but un-Googleable.
- Anyone calling with urgency must produce the word. No exceptions.
- Tell elderly relatives in writing. Some won't remember the rule under pressure; a fridge magnet helps.
What NOT to do
- Don't rely on "I'd recognise their voice" or "they look just like them." That recognition is exactly what the technology is built to exploit.
- Don't argue with the deepfake. Engaging only confirms your details and gives more voice for training.
- Don't post videos of children with their full name and school. Voice and face — the two ingredients for a clone — get harvested from public posts.
- Don't pay an extortion fee for a "deepfake nude" of yourself or your child. Paying confirms a paying target; the demand returns. Save evidence, report, and use takedown services.
- Don't try to outsmart the caller with trick questions. Sophisticated operations are scripted with prepared answers. Code-words work better than puzzles.
- Don't trust biometric authentication — face or voice — for anything important unless paired with a second factor. A voice clone can defeat voice-authentication on some banks; some face-recognition systems are fooled by a high-quality video.
- Don't blame yourself. Smart people are fooled by this every day. The technology is engineered to exploit normal trust.
Use AI to help you
Two prompts you can copy and adapt. Paste the situation in the brackets. Don't paste passwords or two-factor codes.
Analyse a suspicious clip:
"I received this audio (or video / image) clip and I'm not sure if it is genuine or a deepfake. Below is the context — who sent it, what they're claiming, and what was asked of me. Please analyse: (a) what red flags you see in the situation (not the artefact — assume the media itself is convincing), (b) what verification I could do in the next ten minutes to confirm or refute, (c) what specifically I should NOT do until I've verified, and (d) on a 1–10 scale, how likely this is to be a deepfake attack, with your reasoning.
Context: [paste]"
Plan a family verification routine:
"I want to protect my family — including [list ages and tech-comfort, e.g., teenage kids, my elderly parents] — from voice-clone and video-deepfake attacks. Please give me (a) a one-page family verification routine including a code-word system that even an 80-year-old can follow under stress, (b) the specific scenarios I should walk each family member through tonight (the 'mum I crashed the car' call, the 'CEO needs an emergency transfer' call to my partner at work, the 'I have your nude and I'll send it to everyone' email to a teenager), and (c) what I should change in our social-media posting habits to reduce future risk."
A reminder: AI can be confidently wrong about specific country laws on synthetic media, on whether to involve police, and on what reporting routes work. Use it to plan; verify with your bank, your local police, and your country's data-protection authority for the formal steps.
Who to call
The order: the platform the deepfake appeared on, your bank if money has moved, takedown services if intimate imagery is involved, police for criminal use.
Find the latest contacts for your country with AI:
"I'm in [your country]. List the official channels I should contact about a deepfake incident — the national cybercrime reporting body, the data-protection authority (for unauthorised use of likeness or voice), the financial fraud line if money has moved, and any government or NGO service specifically handling synthetic-media abuse (especially intimate-image abuse). For each, give the official website and public phone number, and tell me which to contact first depending on whether (a) money has moved, (b) my likeness was used to defraud others, (c) intimate imagery of me or my child was made or shared, or (d) the deepfake is political or election-related. Cite the official source page for each. Flag anything that might be outdated."
A short curated list (for the very latest, prefer the AI prompt above):
- Image-based abuse — global takedown services (do not upload the image):
- StopNCII.org — generates a hash on your device; participating platforms (Meta, TikTok, Snap, Reddit, Bumble, OnlyFans, Pornhub, Microsoft, and more) block matching uploads without ever receiving the image itself.
- Take It Down (operated by NCMEC, US) — same approach, specifically for under-18s; also accepts adults concerned about historical images.
- English: UK — National Crime Agency cybercrime; Revenge Porn Helpline (revengepornhelpline.org.uk, 0345 6000 459). US — FBI IC3 (ic3.gov); Cyber Civil Rights Initiative (cybercivilrights.org). Australia — eSafety Commissioner (esafety.gov.au) for image-based abuse.
- German: Germany — local Polizei online, BSI für Bürger. Austria — Watchlist Internet. Switzerland — NCSC (ncsc.admin.ch); cybercrimepolice.ch.
- French: France — Pharos (internet-signalement.gouv.fr); arretonslesviolences.gouv.fr. Belgium — safeonweb.be.
- Italian: Italy — Polizia Postale (commissariatodips.it).
- Spanish: Spain — INCIBE (017); Mexico — Policía Cibernética.
- Portuguese: Portugal — CNCS / Linha Internet Segura 1407; Brazil — SaferNet (safernet.org.br).
- Polish: Poland — CERT Polska (cert.pl); dyzurnet.pl.
When to escalate beyond chat
- Money has been sent and the conversation is ongoing — call the bank's fraud line in the next minute, not the next hour. International recall windows are short.
- An intimate deepfake of you or a child has been made or threatened — use StopNCII or Take It Down today; police report in parallel. Do not pay extortion.
- A deepfake is being used to defraud people in your network — your face or voice on a fake-CEO call to your staff, for instance — alert HR, IT, or a lawyer immediately. There may be a corporate liability dimension.
- A political deepfake of you is circulating — verify with your communications team or a lawyer before responding publicly; uncoordinated denials can amplify the original.
- A teenager in your family is being sextorted with an AI-generated nude image — this is a criminal matter in most countries even if the image was generated rather than real. NCMEC's Take It Down, plus police, plus the school if peers are involved.
- You're in mental distress — fraud, image-based abuse, and identity loss can each push people into crisis. Switzerland: 143. UK: 116 123 (Samaritans). US: 988. EU: 116 111 (children) / 116 123 (adults).
Sources & further reading
- Stanford Internet Observatory — ongoing public research on synthetic media
- Witness.org — global civil-society organisation on deepfake response and field training
- Cyber Civil Rights Initiative — research on image-based abuse and survivor support
- StopNCII.org / NCMEC Take It Down — public takedown infrastructure
- EU AI Act — provisions on synthetic media disclosure
- US Federal Trade Commission — ongoing rulemaking on deepfake fraud