๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

CEO Impersonation and Deepfake Fraud: Assessing the Risk

September 26, 2026 ยท PlayCISO
TL;DR

CEO impersonation โ€” a form of business email compromise (BEC) โ€” is when an attacker poses as a senior executive to pressure an employee into authorising a fraudulent payment, sharing data, or granting access. The tactic is old, but AI has sharpened it: convincing voice clones and video deepfakes now let attackers impersonate a known executive on a call, not just in email, defeating the "I recognise their voice" check people rely on. Assessing your exposure means looking at who can move money or grant access, what verification those actions require, and whether your controls assume voice or video is proof of identity. The defence is process, not detection: out-of-band verification for high-risk actions, so no single channel โ€” email, voice or video โ€” is sufficient to authorise them.

CEO impersonation fraud is a decades-old social-engineering play โ€” pose as the boss, apply urgency and authority, get an employee to wire money or hand over access. What has changed is the fidelity: AI voice clones and video deepfakes now let an attacker be the executive on a call, defeating the "I recognise their voice" check that a lot of informal verification quietly depends on.

How the attack works

An attacker poses as a senior executive and pressures an employee into a harmful action โ€” usually a fraudulent payment, sometimes a data or access request. Urgency ("I need this done now, discreetly") plus authority short-circuits scrutiny. With a cloned voice or deepfaked video, the impersonation extends from email to phone and video calls that feel like proof of identity.

Why deepfakes change the calculus

Employees are trained to distrust emailed payment requests โ€” but a call in the executive's voice, or a video with their face, feels verified. Voice and video can no longer be treated as authentication, which is exactly what many payment-approval processes implicitly assume.

Who is exposed

Anyone who can move money or grant access: finance/AP, executive assistants, HR, IT admins โ€” especially where one person can act on an apparent executive request without independent verification.

The defence: process, not detection

Do not try to spot the deepfake in the moment. Require out-of-band verification for high-risk actions โ€” payments over a threshold, bank-detail changes, sensitive data/access โ€” via a pre-agreed channel and known contact, never the channel the request arrived on. Add a mandatory second approver and a callback to a known number, and make verifying an executive request expected, not insubordinate.

Assess and rehearse with the deepfake awareness tools โ†’, and quantify identity exposure with the Identity Risk tool.

Frequently asked questions

What is it? A BEC attack impersonating an executive to authorise fraudulent payments, data sharing or access โ€” now aided by AI voice/video deepfakes.

Why do deepfakes make it worse? They defeat voice/face recognition, so a call or video feels like proof of identity.

How to defend? Out-of-band verification and dual approval for high-risk actions โ€” assume voice and video can be faked.

Who is exposed? Anyone who can move money or grant access, especially without mandatory verification.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’
CEO Impersonation and Deepfake Fraud: Assessing the Risk | PlayCISO Blog ยท PlayCISO