The cybercrime deepfake playbook
To understand the full scope of these attacks, let's break down the specific tactics cybercriminals are using to exploit deepfakes in real-world scenarios.
Voice cloning for vishing attacks
Attackers can now clone someone's voice and use it to impersonate your CEO, IT director, or a trusted vendor. In the first publicly known case of AI voice fraud, the CEO of a British energy company wired €220,000 (approximately $243,000) after receiving a phone call from what he thought was his superior at the group's German parent company. The deepfake was so convincing that the CEO even noted his boss's light German accent.
But it's not just business leaders being targeted. In July 2025, an unknown individual used an AI-synthesized voice to mimic US Secretary of State Marco Rubio. The impersonator was able to reach three foreign ministers and two US officials over Signal messaging until security teams discovered the deception.
Workday, the HR software giant, confirmed in August 2025 that hackers impersonated their own IT and HR officials to trick employees into resetting passwords, giving attackers access to sensitive customer data from a third-party platform.
So what makes these attacks so dangerous? They combine urgency with the trust of a familiar voice.
Video deepfakes for business email compromise (BEC)
Imagine joining a Zoom call with your CFO, only it's not your CFO at all, but a video deepfake. Attackers typically aim to persuade finance teams to initiate wire transfers or employees to give up their login credentials.
"Phishing isn't just about mass email blasts anymore. Attackers are leveraging breached data, open-source intelligence, and AI-generated deepfakes to craft highly personalized lures. We're seeing convincing deepfake audio used in wire fraud, generative AI powering phishing emails that evade detection, and attackers social engineering their way past identity verification."
—Prakash Ramamurthy Huntress Chief Product Officer