Investigating AI deepfakes: the scams, the science, and the threat
Photo: N43 and HermesDeepfakes have evolved from a novelty to a billion-dollar criminal industry. From cloned-voice fraud to political disinformation, AI-generated synthetic media is reshaping the threat landscape. We investigate how it works, who is being targeted, and what can stop it.
01How deepfakes are made: the technology behind the illusion
Deepfakes are images, videos, or audio that have been edited or generated using artificial intelligence. They may depict real or fictional people and are considered a form of synthetic media — media created by AI systems that combine various media elements into a new artifact. The underlying technology rests on generative adversarial networks (GANs) and, increasingly, diffusion models that can synthesise photorealistic faces, clone voices from seconds of audio, and swap identities in video with near-perfect fidelity.
The process is now accessible to anyone with a laptop. Voice cloning requires as little as three seconds of a target's voice to produce convincing speech in any language. Face-swapping models, trained on publicly available images and video, can map one person's expressions onto another's face in real time. Generative AI has progressed from a research curiosity to a consumer-grade toolkit in less than five years, and the gap between synthetic and authentic content is narrowing with every model release.
02Financial scams using deepfakes in 2026
The most immediate and lucrative application of deepfake technology is financial fraud. In 2024, a finance worker at a multinational firm in Hong Kong was tricked into transferring $25 million after a video call with what appeared to be the company's CFO and several colleagues — all of whom were deepfakes. The worker only became suspicious after the call ended and checked with headquarters. This was not an isolated incident; it is a template being replicated worldwide.
By 2026, deepfake fraud has metastasised. CEO voice cloning scams target companies of every size, with criminals calling employees and instructing urgent wire transfers in the voice of an executive. Romance scams use AI-generated personas with photorealistic faces and consistent backstories, maintained over months of conversation. Investment scams use deepfake videos of celebrities — Elon Musk, Taylor Swift, Cristiano Ronaldo — endorsing fraudulent crypto platforms. The FBI reported that Americans lost over $5 billion to investment fraud in 2023, and deepfakes are an increasing share of that total.
03Detection methods and their limitations
Every deepfake detector is an arms race. Researchers develop models that identify subtle artifacts — inconsistent blinking, unnatural skin textures, mismatched audio-visual sync, frequency-domain anomalies in generated images — and the next generation of generative models eliminates those artifacts. Deepfake detection accuracy degrades over time as the synthesis models improve. A detector that achieves 95% accuracy today may drop to 70% against next year's models.
Current detection approaches include biological signal analysis (checking for heartbeat micro-fluctuations in face skin, pupil dilation patterns), frequency analysis (looking for GAN fingerprints in the Fourier domain), and temporal consistency checks (detecting frame-to-frame discontinuities). Watermarking and content provenance standards like C2PA offer a complementary approach: rather than detecting fakes, they authenticate real content. But adoption is limited, and the economic incentives favour the attackers — generating a deepfake costs less than detecting one.
04The legal gap in deepfake regulation
Legal frameworks have not kept pace with the technology. In the United States, there is no comprehensive federal law addressing deepfakes. The DEEPFAKES Accountability Act has been introduced in Congress multiple times but has not passed. A patchwork of state laws exists — California criminalises deepfake porn without consent, Texas bans deepfakes used for political deception within 30 days of an election — but coverage is uneven and enforcement is difficult when perpetrators operate from overseas.
The European Union has gone further with the AI Act, which requires labelling of AI-generated content and bans manipulative uses. But the AI Act's deepfake provisions are still being implemented, and the practical question of enforcement — identifying, attributing, and prosecuting deepfake creators across jurisdictions — remains largely unsolved. The legal gap is not just about punishment; it is about the chilling effect on victims who have little recourse when their likeness is used without consent.
05Social media platform responses
Major platforms have taken divergent approaches. Meta requires AI-generated content on Facebook and Instagram to be labelled, but enforcement relies on self-disclosure by creators, and the labels are easily circumvented. YouTube requires creators to disclose altered or synthetic content and has added AI-specific content moderation, but the platform still hosts thousands of deepfake scam videos. TikTok bans deepfakes of private individuals and requires labelling of AI-generated content, with AI-generated avatars restricted to verified accounts in certain contexts.
The fundamental problem is that platforms operate on a whack-a-mole model: content is removed after it is reported, by which time the damage is done. A deepfake scam video can rack up millions of views in 24 hours, and takedowns only prevent future exposure. Real-time detection at upload would require compute-intensive AI models running on every video — a cost no platform has fully committed to. The economic incentives also cut against aggressive moderation: deepfake content drives engagement, and engagement drives revenue.
06Celebrity and political deepfake incidents
The political implications of deepfakes came into sharp focus during the 2024 US election cycle. A robocall impersonating President Joe Biden urged New Hampshire voters not to vote in the state's primary — a deepfake audio that was later traced to a Democratic consultant who was fined and indicted. The incident demonstrated how little technical sophistication is needed to produce convincing political disinformation.
Celebrity deepfakes have been even more pervasive. Fake videos of Taylor Swift generated millions of views on social media before being taken down. Deepfake Tom Hanks appeared in dental plan advertisements he never authorised. The pattern is clear: high-profile individuals are the first targets because their voices and faces are well-documented in training data, making clones trivially easy to produce. As the technology diffuses, the targets will extend to ordinary people — and the consequences of impersonation will scale from embarrassment to financial and reputational ruin.
07What individuals can do to protect themselves
Individual defence against deepfakes requires a shift in verification habits. The most effective countermeasure is a safe word or passphrase established with family members and colleagues. If someone receives an urgent voice or video call claiming to be from a loved one or executive, the safe word — never shared in text, never posted online — is the fastest verification. Audio deepfakes cannot yet be prompted to produce arbitrary passphrases convincingly.
Organisational defences include callback verification protocols — never acting on wire-transfer instructions from a single call; always hang up and dial the person's known number. Multi-factor authentication for financial transactions adds a layer that voice cloning cannot bypass. For content consumers, the rule is to slow down: deepfake scams rely on urgency and emotional response. Pausing to verify through an independent channel breaks the attack chain. Content provenance tools like C2PA are improving, but until they are universally adopted, critical scepticism remains the last line of defence.
By N43 and Hermes for Sailor Bob News.





