# CEO Impersonation and Deepfake Fraud: Assessing the Risk > Attackers impersonate executives — increasingly with AI voice and video deepfakes — to authorise fraudulent payments and access. How the attack works, who is exposed, and how to defend. Source: https://playciso.com/blog/ceo-impersonation-deepfake-risk · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- CEO impersonation fraud is a decades-old social-engineering play — pose as the boss, apply urgency and authority, get an employee to wire money or hand over access. What has changed is the fidelity: AI voice clones and video deepfakes now let an attacker be the executive on a call, defeating the "I recognise their voice" check that a lot of informal verification quietly depends on. ## How the attack works An attacker poses as a senior executive and pressures an employee into a harmful action — usually a fraudulent payment, sometimes a data or access request. Urgency ("I need this done now, discreetly") plus authority short-circuits scrutiny. With a cloned voice or deepfaked video, the impersonation extends from email to phone and video calls that _feel_ like proof of identity. ## Why deepfakes change the calculus Employees are trained to distrust emailed payment requests — but a call in the executive's voice, or a video with their face, feels verified. Voice and video can no longer be treated as authentication, which is exactly what many payment-approval processes implicitly assume. ## Who is exposed Anyone who can move money or grant access: finance/AP, executive assistants, HR, IT admins — especially where one person can act on an apparent executive request without independent verification. ## The defence: process, not detection Do not try to spot the deepfake in the moment. Require **out-of-band verification** for high-risk actions — payments over a threshold, bank-detail changes, sensitive data/access — via a pre-agreed channel and known contact, never the channel the request arrived on. Add a mandatory second approver and a callback to a known number, and make verifying an executive request expected, not insubordinate. Assess and rehearse with the [deepfake awareness tools →](/deepfake), and quantify identity exposure with the [Identity Risk tool](/tools/identity-risk). ## Frequently asked questions **What is it?** A BEC attack impersonating an executive to authorise fraudulent payments, data sharing or access — now aided by AI voice/video deepfakes. **Why do deepfakes make it worse?** They defeat voice/face recognition, so a call or video feels like proof of identity. **How to defend?** Out-of-band verification and dual approval for high-risk actions — assume voice and video can be faked. **Who is exposed?** Anyone who can move money or grant access, especially without mandatory verification.