Imagine your CEO calls the accounts department on a Friday afternoon. An acquisition is about to close, they say, and a deposit must be transferred before the end of the day. The matter is strictly confidential. Or perhaps they ask for access to sensitive customer data during a video conference. Everything seems genuine: the voice, the face, even the familiar gestures. But it is not your CEO. It is a deepfake. Fraudsters have used freely available AI software to replicate their voice and appearance, drawing on material such as interviews or corporate videos found online.
The case of engineering firm Arup shows that this is more than a theoretical threat. In 2024, an employee in Hong Kong transferred around US$25 million following a video conference with what appeared to be the company’s chief financial officer and several colleagues. Every familiar face on the call was a deepfake.
The problem is growing in Germany, too. According to Bitkom’s 2026 study on business security, the proportion of companies that suffered losses due to deepfakes doubled within a year, from 4% to 8%. This matches our own experience: over the past few weeks, we have seen a significant increase in enquiries about deepfakes.
Why a closer look is not enough
Deepfake attacks tend to follow the same pattern: an unusual communication channel, time pressure, secrecy and a request to bypass standard procedures “just this once”. When you recognise this pattern, you do not need to spot the deepfake itself. You simply need to question the request at the right moment.
So, how should you respond?
- Call back through a trusted channel. Hang up and call back using a number you already know, or contact the person through a different communication platform.
- Require two-person approval, without exception. No one should approve payments, changes to bank details or access to sensitive data on their own—not even when instructed to do so by senior management.
- Use a code word or a verification question. Ask for a pre-agreed code word or ask a question that only the real person would be able to answer.
- Make it safe to ask questions. Management should make it clear in advance that questions are welcome, even when an instruction ultimately turns out to be genuine. Employees must never face negative consequences for being cautious.
How we can help
Our experience with penetration testing and social engineering projects shows that procedures only work when people know and practise them before the first suspicious call comes in. We offer three ways to help your business prepare:
- Team training. Using real-world cases, we teach your employees to recognise the attack pattern and ask questions politely but firmly. This is particularly important for staff in accounting, administrative support and HR, as well as managers.
- A review of your approval processes. We identify where attackers could exploit weaknesses in payment processes, master data changes and access permissions—and show you how to address them.
- Testing under real-world conditions. On request, we carry out a simulated social engineering attack to assess whether your procedures hold up in day-to-day operations.
Often, a single follow-up question is all it takes. We prepare your team to ask it at the right moment.
Book a no-obligation initial consultation
Together, we will identify which processes in your business are most at risk and which of our services best meet your needs.