What is a deepfake?
A deepfake is audio, an image or a video created or manipulated with artificial intelligence to suggest something happened when it did not. It can imitate a face or voice and make it seem that someone said or did something. The US Government Accountability Office (GAO) describes how this content can appear convincing to the eye and ear. GAO.
How it exploits our trust
Recognising a voice can lead us to trust a request. The US Federal Trade Commission (FTC) warns about scams using cloned voices to fake family emergencies. Surrey Police explains that pressure to act quickly aims to prevent us from consulting other people or checking the request. FTC Surrey Police.
Looking for flaws in an image or sound may raise a suspicion, but it does not provide definitive proof. The FBI warns that AI-generated content can be difficult to identify. The practical response is to check the identity and the request even when the audio or video seems normal. FBI/IC3.
A fake meeting and losses of approximately US$25.6 million
On 26 June 2024, the Hong Kong Government described a fraud reported in late January: a prerecorded video conference impersonated a chief financial officer. Transfers were then authorised and about HK$200 million was lost. According to the investigation described at the time, public videos and recordings of the executive’s voice had been used. The meeting involved no real interaction with him. This is a documented case from 2024. Hong Kong Government.
The US dollar amount is an indicative equivalent: HK$200 million ÷ 7.80 ≈ US$25.6 million. It uses the central reference of the exchange rate system described by the Hong Kong Monetary Authority in 2005, rather than the exact exchange rate of the transfers. HKMA.
Agree a code word before an urgent request arrives
The FBI recommends establishing a private word or phrase with your family. To put this into practice, agree something memorable that does not appear on your social profiles. Avoid names, birthdays and account passwords. Ask for it without saying it first: “What word did we agree?”. If someone outside the agreement learns it, change it. FBI/IC3.
Ask about a shared memory without giving hints
Surrey Police suggests asking for details of a shared experience and avoiding revealing information to the caller. Its usefulness depends on the answer being private. A name or date anyone can find on social media adds little to the check. Surrey Police.
An illustrative example to adapt: “What did we burn the last time we cooked together?”. Do not suggest “Was it the pizza?” or complete the answer. Avoid account recovery questions. These examples are editorial suggestions; they do not describe a test carried out with readers.
What an answer can and cannot confirm
A code word or memory might have reached someone else. A genuine caller might also forget a detail or become confused under pressure. A correct answer therefore does not guarantee identity, and a wrong answer does not prove fraud. Use the reply as a reason to keep checking, without making accusations or treating the request as resolved.
Have a call and a backup contact ready
The FTC recommends contacting the person on a number you already know and trying another relative or friend if you cannot reach them. Agree beforehand who that backup contact will be. You can say: “I’ll hang up and call you on the number I have saved”. Avoid relying on a number supplied during the suspicious request. FTC.
Check before sending money or information. The FBI warns against giving authentication codes to anyone else. If there are signs of real danger, contact your local emergency services; a wrong answer to the code word does not rule out an emergency. FBI/IC3.
A check you can practise today
Rehearse how you will ask for the code word, whom you will call and what you will do if they do not answer. Keep the word and personal answers private. Having this agreement ready means you have already thought through how to check an urgent request.
Sources
- GAO · Combating Deepfakes · 11 March 2024
- FTC · Family emergency schemes and voice cloning · March 2023
- Hong Kong Government · LCQ9: Combating frauds involving deepfake · 26 June 2024
- HKMA · Linked exchange rate reference · 18 May 2005
- FBI/IC3 · Generative AI and financial fraud · 3 December 2024
- FBI/IC3 · Impersonation campaign · 19 December 2025
- Surrey Police · AI and deepfakes · November 2025