The chief financial officer appears on screen. He knows the business, speaks confidently and requests an urgent transaction. Everything seems normal, except for one crucial detail: it is not him. Executive deepfakes confront companies with an attack on their system of trust. Looking ahead to September 2026, the priority is not simply to spot a manipulated image. It is to prepare the organisation to verify a credible-sounding statement, then respond without amplifying the deception.
Fraud that mimics corporate conventions
In 2024, engineering group Arup confirmed that it had fallen victim to fraud involving deepfakes in Hong Kong. According to publicly available information, an employee had joined a video conference in which several participants, including a fake chief financial officer, were impersonated. Transfers totalling approximately $25 million followed. The decisive factor was not technical quality alone: the meeting made an unusual request look like a collective instruction.
That same year, an attempt targeting WPP used the identity of its chief executive, Mark Read, including a cloned voice and a staged virtual meeting. It failed. At Ferrari, an executive also reportedly thwarted an attempt to impersonate the company’s leader by voice, asking a personal question that the caller could not answer, according to an account published by Bloomberg in 2024.
These incidents shed light on a trend, without providing a straightforward basis for predicting its frequency in 2026. Attackers do not always seek to create a perfect illusion: they seek to prompt action before verification. Urgency, confidentiality, hierarchical authority and a familiar context can sometimes compensate for flaws in the fake.
The risk extends beyond fraudulent transfers
For a communications department, the scenario does not stop at the treasury function. A fake video could announce a factory closure, attribute discriminatory remarks to a chairperson or promise a non-existent product. A voice message could pressure an agency into issuing a press release. A manipulated clip could reach employees, journalists and customers simultaneously.
The damage can begin before any authentication takes place: screenshots, calls to managers, requests for comment. At a listed company, a fake message can also cause market disruption. The response must therefore bring together cybersecurity, communications, legal and investor relations teams, with an assessment of applicable obligations.
The most concerning future scenario is therefore not necessarily a spectacular video going viral. It is a succession of small, consistent signals: a credible invitation, a familiar voice, a well-presented document. Each element reinforces the others until verification seems unnecessary.
Establish authoritative channels before they are needed
The first task is to define where official statements carry authority. The corporate website should have a clearly identifiable section for sensitive information and clarifications. Employees should know the designated internal channel. Journalists, partners and strategically important customers should have contact details that have already been verified, rather than a number found in the suspicious message.
An account displaying a platform badge is not enough: it can be compromised, imitated or misinterpreted. Nor is a website post a magic solution if access controls are weak. Authentication rests on a chain of trust, not a logo. Accounts protected by strong authentication, restricted permissions and two-person approval for sensitive announcements are all part of the framework.
Organisations must also plan for the main channel becoming unavailable. If the website is compromised, where should information be published? If the messaging system is suspect, how should the crisis team convene? A backup contact directory stored outside the usual tools and a tested alternative channel prevent improvisation at the worst possible moment.
Verify the request, not just the face
Visual checks quickly become outdated. Looking for strange blinking or out-of-sync lip movements may help, but it is not a reliable procedure. Compression, poor connections and generative tools blur these clues. Automated detectors can contribute to the analysis; their findings should not be treated as a verdict.
The operational rule is simpler: an unusual instruction requires independent confirmation. Call the executive or their assistant back on a known number. Use a separate approval process. Do not simply reply in the suspicious thread, and do not call the number it provides.
- Money: no changes to bank details or exceptional transfers based solely on a call or video.
- Publication: every sensitive announcement requires dual approval, even if it appears to come from the top.
- Data: no confidential information should be shared without verifying identity and genuine need.
- Urgency: pressure to bypass the rules becomes a reason to escalate, never permission to proceed.
A personal question or shared password may offer protection in a particular situation, but should not be the only safeguard: such secrets can circulate or be discovered. Above all, executives must publicly authorise their teams to verify their identity. Without that permission, even the best procedure may give way to the fear of disobeying.
Prepare a public response that does not fuel the fake
The crisis team must know who makes decisions, who investigates and who speaks. Security preserves evidence and examines accounts; communications tracks the spread of the content; legal assesses the necessary steps. A shared incident log distinguishes established facts, hypotheses and decisions. This shared record limits contradictory accounts.
Even before the full technical assessment is complete, a holding statement can explain that content attributed to the executive is circulating, that its authenticity is being checked and that no action should be taken on that basis. It directs audiences to the official channel and announces a further update, without promising a deadline that cannot be met.
Once the manipulation has been established, the denial must be explicit, dated and easy to find. It corrects the central claim rather than unnecessarily reposting the entire video. Platforms receive reports, journalists receive verified information and managers receive clear instructions. Evidence must be preserved before takedown requests are submitted.
Not every fake warrants a press conference. Limited circulation may call for a targeted response; a widely repeated rumour requires greater visibility. The decision depends on the audiences affected and the potential consequences, not just the number of views.
Rehearse the crisis without setting traps for employees
A useful exercise starts with a concrete scenario: a fake voice message sent to an agency, a video received by a journalist, a video conference requesting an exception to the rules. Measure the time needed to report the incident, call back, suspend the action and produce an initial coherent message. The aim is not to ridicule those who believed the fake, but to identify procedural weaknesses.
What next? For September 2026 and beyond, the reasonable assumption is that impersonation will become more accessible and better integrated into everyday interactions, not that deception will become infallible. The best-prepared companies will not be those promising to detect everything. They will be those where everyone knows how to put a request on hold, verify it outside the suspicious channel and quickly find a reliable official statement.


