TL;DR

What it is

A deepfake is any synthetic media — audio, image, or video — that imitates a real person convincingly enough to be used as if it were real. Three current categories:

  1. Voice clones. Built from as little as 5–10 seconds of someone's voice — a podcast clip, a TikTok, a voicemail, a YouTube interview, a Zoom recording. The clone can read any new text in the person's voice, with inflection.
  2. Face swap and lip-sync video. A short reference video of the target's face mapped onto another person's body, or an existing video of the target re-spoken with new audio. Quality varies but is getting cheaper monthly.
  3. AI-generated still images. A photo of a real person placed in a setting they were never in — sometimes intimate, sometimes politically compromising, sometimes for romance or identity fraud.

These are used in five main ways:

The underlying technology is not exotic anymore. The tools are publicly available, mostly legal to use, and rapidly improving. Treating this as something that happens "to other people" is the same mistake people made about phishing in 2015.

How to spot it

The old advice — "look for blurring at the jaw, count the fingers" — is now mostly obsolete. Recent generations of deepfake tools no longer leave those tells. The reliable signals have moved from the artefact to the context.

On a phone call:

In a video call:

In a still image:

Most reliable: ignore the artefacts. Verify through a different channel. Always.

What to do

If a suspicious voice or video has just contacted you:

  1. Stop the conversation. Politely or not. "Let me call you back." Hang up. Close the chat.
  2. Verify through a known channel. Call the person on the number you've had for them for years. If they don't answer, call a family member who would know where they are. Do not call back the number that just contacted you.
  3. Use the family code-word. Discussed below. If you don't have one yet, this is the moment to invent one.
  4. If money was asked for, do not send it — even if you're 90% sure it was them. The 10% case can be catastrophic; the wait is recoverable.
  5. If they showed urgency about secrecy"don't tell your mum" — that confirms it. Real emergencies are not secret.

If you discover the deepfake after the fact (money sent, message believed, image shared):

  1. Call your bank immediately. International transfers can sometimes be recalled within 24 hours; after that, much harder.
  2. Save everything. Screenshots, voicemails, call logs, message threads, transaction confirmations. The case file matters even if you never recover the money, because it helps the next victim.
  3. Report to police. Your country's cybercrime unit, and the platform the contact came through. In the EU, also notify your national data-protection authority if your likeness or voice was used — that is a personal-data violation in itself.
  4. Tell your circle. The same operation likely targets your family and contacts next, using the credibility you just unwittingly lent them.
  5. If intimate imagery was involved, use a takedown service immediately — see below.

Set up a family code-word now, while everyone is calm.

What NOT to do

Use AI to help you

Two prompts you can copy and adapt. Paste the situation in the brackets. Don't paste passwords or two-factor codes.

Analyse a suspicious clip:

"I received this audio (or video / image) clip and I'm not sure if it is genuine or a deepfake. Below is the context — who sent it, what they're claiming, and what was asked of me. Please analyse: (a) what red flags you see in the situation (not the artefact — assume the media itself is convincing), (b) what verification I could do in the next ten minutes to confirm or refute, (c) what specifically I should NOT do until I've verified, and (d) on a 1–10 scale, how likely this is to be a deepfake attack, with your reasoning.

Context: [paste]"

Plan a family verification routine:

"I want to protect my family — including [list ages and tech-comfort, e.g., teenage kids, my elderly parents] — from voice-clone and video-deepfake attacks. Please give me (a) a one-page family verification routine including a code-word system that even an 80-year-old can follow under stress, (b) the specific scenarios I should walk each family member through tonight (the 'mum I crashed the car' call, the 'CEO needs an emergency transfer' call to my partner at work, the 'I have your nude and I'll send it to everyone' email to a teenager), and (c) what I should change in our social-media posting habits to reduce future risk."

A reminder: AI can be confidently wrong about specific country laws on synthetic media, on whether to involve police, and on what reporting routes work. Use it to plan; verify with your bank, your local police, and your country's data-protection authority for the formal steps.

Who to call

The order: the platform the deepfake appeared on, your bank if money has moved, takedown services if intimate imagery is involved, police for criminal use.

Find the latest contacts for your country with AI:

"I'm in [your country]. List the official channels I should contact about a deepfake incident — the national cybercrime reporting body, the data-protection authority (for unauthorised use of likeness or voice), the financial fraud line if money has moved, and any government or NGO service specifically handling synthetic-media abuse (especially intimate-image abuse). For each, give the official website and public phone number, and tell me which to contact first depending on whether (a) money has moved, (b) my likeness was used to defraud others, (c) intimate imagery of me or my child was made or shared, or (d) the deepfake is political or election-related. Cite the official source page for each. Flag anything that might be outdated."

A short curated list (for the very latest, prefer the AI prompt above):

When to escalate beyond chat

Sources & further reading