The Video Call Was Fake and So Was Everyone On It
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Manipulated video was, for a while, mostly a curiosity — celebrity face swaps and political mischief. It has since become a practical instrument of fraud, and the most damaging cases have not targeted the public at all. They have targeted company finance departments.
The attack that actually works
The pattern is a variation of an old fraud with a new layer of proof.
Business email compromise has existed for years: an employee receives an instruction, apparently from a senior colleague, to make an urgent payment. Defences grew up around it, chiefly the habit of verifying unusual requests through another channel — typically a call or video meeting.
Synthetic video attacks that defence directly. If the verification step is a video call, and the video call can be faked, the control that made the old fraud manageable now confirms the fraud instead.
Reported cases have involved employees joining calls with what appeared to be several colleagues, all synthetic, and authorising very large transfers. The employee did not skip verification. They performed it, and it passed.
Why "look for the tells" is weak advice
Guidance about spotting fakes tends to list artefacts: unnatural blinking, odd edges around hair, mismatched lighting, lips slightly out of sync.
Two problems. Each generation of tools removes tells from the previous list, so advice dates quickly and confidently applying an outdated checklist is worse than having none. And these judgements are being made on a compressed video call on a laptop screen by someone with no reason for suspicion — conditions where subtle artefacts are invisible anyway.
Asking someone to turn their head sharply or wave a hand across their face is sometimes suggested, and does still disrupt some systems. Treat it as a weak signal that may stop working, not a test you can rely on.
What holds up: process, not perception
The controls that survive do not depend on anyone detecting anything.
Verify through a separate channel you initiate. Not the channel that contacted you. If a request arrives by video, confirm by calling the person on their known number. The attacker controls their channel, not yours.
Require a second authoriser for payments above a threshold. Two people, independently, through separate channels. This is standard financial control and it defeats the attack without anyone judging a video.
Make urgency a trigger, not an excuse. Every version of this fraud requires speed and discourages checking. A policy that unusual urgency mandates more verification inverts the attacker's main tool.
Never allow seniority to bypass the process. These attacks work because staff are reluctant to question an executive. That reluctance is the vulnerability, and only a policy explicitly protecting employees who verify can remove it.
For individuals
The consumer version is the voice call from a relative in trouble, and the fix is the same in miniature: a family safeword, and hanging up to call back on a known number.
Video adds a wrinkle for anyone using face recognition for identity verification — some financial services accept a video selfie to open accounts or reset access. That is a matter for the provider's liveness checks rather than something you can control, but it is a reason to prefer providers using stronger methods, and to keep your accounts protected by something other than your face alone.
Setting expectations honestly
There is no reliable consumer tool for detecting synthetic video, and detection is an arms race that defenders do not obviously win. Systems claiming high accuracy tend to perform far worse on real-world footage than on the datasets they were tested against.
Which is why the recommendation is deliberately unglamorous. Do not try to become a better judge of whether a face is real. Build a process where it does not matter — because the payment requires a second person, verified on a channel you dialled yourself.
That approach worked before synthetic video existed and it will keep working after the tells everyone is currently taught have stopped being true.
A worked example of the meeting
An employee in a finance team receives an email from a senior executive about a confidential acquisition. It asks them to join a video call.
They join. Several colleagues are visible, including the executive and someone from legal. The faces are right, the voices are right, and the meeting behaves like a meeting — people speak, someone apologises for a poor connection, the executive does most of the talking.
The instruction is to make a series of transfers to complete a deal that must not be discussed internally until it is announced. The confidentiality requirement conveniently explains why the employee should not raise it with anyone, and the deal timetable explains the urgency.
The employee is not reckless. They know about payment fraud. So they verify — and the verification they were trained to perform was "confirm unusual requests by speaking to the person", which is exactly what the video call is.
The transfers go out.
Notice which control failed. Not the employee's diligence, which was present. Not the policy, which was followed. The policy assumed that seeing and hearing a colleague constituted proof of identity, and that assumption is what stopped being true. Any organisation whose verification step is "get them on a call" has the same gap, and it is worth checking whether yours does.
The policy wording that actually holds
If you are responsible for this somewhere, the difference between a control that works and one that does not comes down to a few specifics.
- Verification must use a channel the verifier initiates, from contact details held in the company's own directory — never a number, address or link supplied in the request itself.
- The second authoriser must be independent, not chosen by the requester, and must verify separately rather than accepting the first person's confirmation.
- The threshold must include new payees, not only large amounts. A first payment to an unknown account is the risky event, whatever its size.
- Confidentiality must never suspend the process. "Do not discuss this with anyone" is a hallmark of the fraud, and a policy that allows it to override verification has a hole shaped exactly like the attack.
- Staff who delay a payment to verify must be explicitly protected, in writing, including when the request appears to come from an executive. Without this the policy exists on paper and fails in practice.
- The process must be tested, ideally by someone attempting it, because a control nobody has tried is a control nobody knows works.
The consumer versions worth recognising
Synthetic media reaches individuals in a few recurring shapes, and knowing the shapes is more useful than trying to spot the fakery.
Investment promotions using a recognisable face. A well-known figure appearing to endorse a trading platform or cryptocurrency scheme, often in an advertisement on a mainstream platform. The tell is not the video; it is that a genuine endorsement of a guaranteed-return investment does not exist.
Romance and long-term deception, where video calls are used to establish that a person is real. A short, poor-quality call that always has a reason not to happen again is a signal in itself.
Fake support or authority figures, where a video or voice adds weight to an instruction to move money "for safekeeping". No legitimate bank, police force or tax authority does this, ever.
In every case the durable test is the same as the one for voice clone scams: judge the request and the payment method, not the media. Irreversible payment plus urgency plus a reason you must not check with anyone else is fraud, regardless of who appears on screen.
On detection tools and provenance
Two things are often offered as the answer, and both deserve a realistic appraisal.
Detection software tries to identify synthetic media from the media itself. It is an arms race in which the generator gets the last move, and accuracy measured on curated test sets tends to fall away on real footage that has been compressed, re-encoded and streamed. Treat any claim of reliable consumer-grade detection with scepticism.
Provenance and content-credential schemes work from the other direction: rather than detecting fakes, they attach signed information about how a piece of media was captured and edited, so that genuine material can prove its own origin. This is a more promising approach because it does not require winning an arms race. Its limitation is coverage — it only helps where the capture device, the editing software and the platform all support it and the signature survives the journey, and absence of a credential does not mean something is fake.
Neither changes the advice above. Both are reasons to expect the situation to improve slowly, and neither is something to rely on for a payment decision this week.
Where this fits
This is the organisational sibling of AI voice clone scams, and it shares its structure with ordinary phishing and scam text messages: manufacture urgency, supply the channel, discourage checking. The account security that stops the email side of business email compromise is covered in two-factor authentication and passkeys — a compromised mailbox is what makes these requests land in a real thread in the first place. Securing that mailbox is a tooling problem, and our shortlist of security tools covers what does it.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
The USB Stick That Types: BadUSB, Bad Cables and Juice Jacking
Why a computer cannot tell a keyboard from an impostor, what a malicious cable adds, and the honest state of the airport-charging warning.
privacy
Cheap Hacking Gadgets: What They Can Actually Do to You
The pocket-money hardware sold openly on every marketplace, sorted honestly into what works, what needs conditions you control, and what is pure theatre.
guides
The Password Rules the Standard Now Forbids: What NIST SP 800-63B-4 Actually Says in 2026
Forced 90-day changes and 'one capital, one number, one symbol' are not merely unfashionable — the current US federal standard says SHALL NOT. Here is the exact wording, with section numbers.
