The Video Call Was Fake and So Was Everyone On It
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Manipulated video was, for a while, mostly a curiosity — celebrity face swaps and political mischief. It has since become a practical instrument of fraud, and the most damaging cases have not targeted the public at all. They have targeted company finance departments.
The attack that actually works
The pattern is a variation of an old fraud with a new layer of proof.
Business email compromise has existed for years: an employee receives an instruction, apparently from a senior colleague, to make an urgent payment. Defences grew up around it, chiefly the habit of verifying unusual requests through another channel — typically a call or video meeting.
Synthetic video attacks that defence directly. If the verification step is a video call, and the video call can be faked, the control that made the old fraud manageable now confirms the fraud instead.
Reported cases have involved employees joining calls with what appeared to be several colleagues, all synthetic, and authorising very large transfers. The employee did not skip verification. They performed it, and it passed.
Why "look for the tells" is weak advice
Guidance about spotting fakes tends to list artefacts: unnatural blinking, odd edges around hair, mismatched lighting, lips slightly out of sync.
Two problems. Each generation of tools removes tells from the previous list, so advice dates quickly and confidently applying an outdated checklist is worse than having none. And these judgements are being made on a compressed video call on a laptop screen by someone with no reason for suspicion — conditions where subtle artefacts are invisible anyway.
Asking someone to turn their head sharply or wave a hand across their face is sometimes suggested, and does still disrupt some systems. Treat it as a weak signal that may stop working, not a test you can rely on.
What holds up: process, not perception
The controls that survive do not depend on anyone detecting anything.
Verify through a separate channel you initiate. Not the channel that contacted you. If a request arrives by video, confirm by calling the person on their known number. The attacker controls their channel, not yours.
Require a second authoriser for payments above a threshold. Two people, independently, through separate channels. This is standard financial control and it defeats the attack without anyone judging a video.
Make urgency a trigger, not an excuse. Every version of this fraud requires speed and discourages checking. A policy that unusual urgency mandates *more* verification inverts the attacker's main tool.
Never allow seniority to bypass the process. These attacks work because staff are reluctant to question an executive. That reluctance is the vulnerability, and only a policy explicitly protecting employees who verify can remove it.
For individuals
The consumer version is the voice call from a relative in trouble, and the fix is the same in miniature: a family safeword, and hanging up to call back on a known number.
Video adds a wrinkle for anyone using face recognition for identity verification — some financial services accept a video selfie to open accounts or reset access. That is a matter for the provider's liveness checks rather than something you can control, but it is a reason to prefer providers using stronger methods, and to keep your accounts protected by something other than your face alone.
Setting expectations honestly
There is no reliable consumer tool for detecting synthetic video, and detection is an arms race that defenders do not obviously win. Systems claiming high accuracy tend to perform far worse on real-world footage than on the datasets they were tested against.
Which is why the recommendation is deliberately unglamorous. Do not try to become a better judge of whether a face is real. Build a process where it does not matter — because the payment requires a second person, verified on a channel you dialled yourself.
That approach worked before synthetic video existed and it will keep working after the tells everyone is currently taught have stopped being true.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.