Practical guide
Deepfakes and voice cloning: verify before you act
A convincing voice or video no longer proves identity. The right method is to end the exchange and verify the request through an independent channel.

In this article
Someone close to you calls from an unfamiliar number. The voice is recognisable, the story sounds coherent, and there is an urgent transfer to make. The first reflex is usually to listen to the voice and decide whether it is "real". That is no longer a sufficient method.
Voice cloning and synthetic video do not make every fraud perfect. What they mainly do is make the first few seconds more credible. That buys the fraudster the time needed to establish urgency, prevent verification, and obtain an action that is hard to undo.
The deepfake is only part of the scenario
A successful fraud does not rest on the quality of a voice or a video alone. It usually combines several elements:
- public information gathered from social networks;
- a plausible context, such as a trip, an accident or a banking problem;
- a voice, a photo or a video that resembles the person;
- time pressure;
- a request for secrecy;
- a payment, a code or remote access.
The imitation serves as emotional proof. It creates the impression that ending the conversation would be rude or dangerous. Yet hanging up in order to verify is precisely the right move.
Looking for visual flaws is not enough
A mismatch between lips and voice, inconsistent lighting or an unstable background can signal manipulated content. Those clues remain useful, but they do not constitute a test.
A poor connection also produces frozen images and delayed sound. Conversely, well-made synthetic content may show no obvious flaw at all on a small screen. More importantly, a fraudulent call does not need to be technically perfect if the person on the other end is rushed and worried.
The right question is therefore not: "Does this voice sound artificial?" The right question is: "Can I confirm this request by another route?"
The independent channel protocol
When someone you know asks for money, a document, a code or an unusual action, end the conversation. Get back in touch using a number already saved, a familiar application, or another relative in that person's circle.
Do not call back the number given during the exchange. Do not click a link sent to "confirm the identity". The verification channel must be chosen independently of the suspicious message.
A simple check can take this form:
1. end the call without lengthy discussion;
2. call the person on their usual number;
3. if there is no answer, contact another relative;
4. verify the announced event before taking any financial action;
5. alert the bank if a transaction has already been started.
A family question can supplement that check, but it should not be the only protection. Answers to personal questions are sometimes visible online, or may have been obtained during an earlier conversation.
In a company, the procedure must withstand a convincing voice
A fake call from an executive or a supplier may request a change of bank account, a confidential payment, or that a document be sent. A sound procedure must never depend on the judgement of the person taking the call alone.
For sensitive transactions, provide for:
- confirmation through a known channel;
- a second approval by another person;
- a check of the bank account on file;
- a clear ban on "urgent" exceptions;
- a way to report a doubt without fear of sanction.
The sentence "it really is my voice" must not be enough to bypass those steps. A useful procedure is one that not even the director can waive over the phone.
Fake advertising and fake experts
Deepfakes are not used solely to imitate a relative. They also appear in fake advertising where a public figure, a doctor, a journalist or a political official appears to recommend an investment.
The familiar face lends an appearance of legitimacy to an unknown platform. The victim is then directed to a form, called back by an "adviser", and guided all the way to a first payment.
Do not verify the advertisement inside the advertisement itself. Look for the announcement on the official channels of the person or organisation, check the FSMA warnings, and refuse any remote-access software.
You have sent money or a code
Act without delay:
- contact your bank on its official number;
- ask whether the transaction can still be blocked or recalled;
- change any passwords you disclosed or reused;
- revoke open sessions;
- keep the numbers, messages, recordings and payment references;
- report the facts to the police and to the platforms concerned.
Do not pay a second party who promises to recover the funds in exchange for an advance. Victims of a first fraud are frequently targeted again.
Preparing the family before the first call
A ten-minute conversation greatly reduces confusion on the day an alarming call comes in. Agree together on the usual channels, the relatives to contact, and this rule: any urgent request for money automatically entitles the person called to hang up and verify.
That rule also protects the relationship. It prevents verification from being read as a lack of trust. It is not the person being doubted, it is the channel.
Official sources
- Safeonweb - Deepfakes: how to recognise them and protect yourself
- FSMA - Warnings about fraudulent offers
- Safeonweb - Report a suspicious message
Editorial information
- Written by
- Jeremy Kraft
- Last reviewed
- Method
- Public sources, editorial review and proportionate guidance.