Skip to content
Annuaire
Sections
Soft Skills

Deepfakes in the workplace: learning to verify without accusing

Deepfakes in the workplace: learning to verify without accusing
L’essentiel

Faced with cloned voices and doctored videos, seeking independent confirmation is becoming as much an interpersonal skill as a security reflex. The challenge: being able to verify an instruction, even from a senior executive, without turning caution into personal suspicion.

À retenir

Faced with cloned voices and doctored videos, seeking independent confirmation is becoming as much an interpersonal skill as a security reflex. The challenge: being able to verify an instruction, even from a senior executive, without turning caution into personal suspicion.

The voice is familiar, and so is the face. On screen, your chief financial officer requests an urgent, confidential, exceptional transfer. Everything seems credible, except for that quiet internal alarm: why bypass the procedure? When faced with deepfakes, the right response is not necessarily to expose a manipulated image. It is knowing how to say: “I’ll take care of it as soon as we’ve confirmed the request through our usual channel.” A simple sentence, but one that can be hard to say when hierarchy, urgency and the fear of disappointing someone enter the conversation.

When trust gives attackers a foothold

The risk is far from fictional. In 2024, Hong Kong police described a fraud in which an employee had made several transfers after a video conference featuring fake colleagues, including a fake chief financial officer. Engineering group Arup subsequently confirmed that it had fallen victim to the scam. The case showed how an apparently collective discussion could lend formidable credibility to a fraudulent instruction.

That does not mean every video meeting is suspicious, or that deepfakes dominate corporate fraud. Compromised email accounts, fake suppliers and conventional manipulation remain major threats. But voice and visual impersonation expand the attackers’ arsenal by exploiting a powerful human shortcut: equating recognition of a person with the authenticity of their request.

Looking ahead to September 2026, the reasonable outlook is therefore not a workplace where nobody believes anyone anymore. It is one in which organizations are forced to draw a clearer distinction between a relationship of trust and proof of authorization. This forward-looking analysis builds on documented incidents and the growing accessibility of synthetic media tools, without making quantitative assumptions about how widespread these attacks will become.

The real obstacle: daring to interrupt a superior

On paper, the instruction seems obvious: call back to verify. In practice, an employee may fear appearing slow, incompetent or insolent. The fake executive exploits precisely that discomfort: “I’m traveling,” “We don’t have time,” “Keep this between us.” These arguments also arise in legitimate situations, making the judgment call uncomfortable.

Assertiveness here means maintaining a boundary without attacking the person. It is not about saying: “Prove you really are who you say you are.” It is about invoking a rule tied to the transaction: “For any change to bank details, I need independent confirmation.” That shift is crucial: the request is being checked, not the other person’s loyalty.

Yet this skill cannot rest on individual courage alone. If a manager routinely penalizes delays, a reminder during cybersecurity training will carry little weight. For verification to work, it must be permitted in practice, including when it delays a genuine request from an influential person.

Another channel, yes. But a truly independent one

Switching from video to a written message is not automatically enough. If the message arrives in the same compromised account, the confirmation remains potentially under the attacker’s control. Similarly, calling a number supplied during the suspicious exchange amounts to asking the requester to arrange their own verification.

The useful principle is more demanding: reestablish contact using a known, trusted reference. This could mean a number listed in an internal directory, an established approval process or in-person confirmation where possible. Depending on the sensitivity of the action, a second approval can supplement this check. Since no channel is infallible, the aim is to avoid relying on a single piece of evidence.

Three ways to avoid sounding accusatory

  • When faced with urgency: “I understand the deadline. I’m starting the required verification before executing the transfer.”
  • When dealing with an executive: “This rule also applies to requests from senior management. I’ll call you back on the number in the directory.”
  • When confidentiality is requested: “I can maintain confidentiality while still going through the authorized approver.”

These phrases acknowledge the need while maintaining the rules. They work best when adapted to the team’s vocabulary and then practiced aloud. The aim is not to recite a mechanical script, but to have a ready response when stress reduces the ability to improvise.

Verify the action rather than scrutinizing the pixels

A slightly frozen face, unusual intonation or a mismatch between sound and image may draw attention. But these do not constitute a reliable test: a poor connection also produces anomalies, while a convincing imitation may leave no obvious signs. Training employees solely to “spot the fake” therefore risks giving them false confidence.

It is better to examine what is being requested. Does it involve transferring money, sending a sensitive file, changing a recipient’s bank account, sharing an authentication secret or bypassing an approval? The more sensitive or difficult to reverse the action, the more robust its validation must be, even if the conversation seems entirely natural.

This approach has another advantage: it avoids treating an accent, a speech disorder or a faulty camera as suspicious. Caution focuses on observable operational conditions, not on a person’s appearance or ease of communication. Detection tools can contribute to the defense, but should not serve as the sole arbiters of trust.

Making verification a collective practice

The first step lies with leaders: explicitly state that they accept being called back and having their requests checked. Then demonstrate it, without sarcasm or reproach, when it happens. Saying “You were right to check” after a legitimate request teaches more than a poster urging everyone to remain vigilant.

Exercises must also address the interpersonal dimension. A short simulation can confront an employee with a pressing request, then have them practice restating it, temporarily declining it and escalating it. The debrief should focus as much on the resources available as on emotions: at what point were they afraid of being a nuisance? Did they know whom to contact?

Finally, the company must plan for exceptions before a crisis hits. If the person in charge cannot be reached, who can approve? What can be put on hold? Where can an attempted attack be reported without unnecessarily sharing personal data? A procedure without a fallback encourages workarounds. A workable procedure also protects the employee who decides to suspend a transaction.

What now? If impersonations become more accessible and convincing, defenses will need to rely less on individual skill at recognizing a voice. They will depend more on independent validation and a culture in which asking for confirmation is not an offense. The sign of maturity will be simple: being able to tell a senior executive “I’ll verify first,” then return to work without an awkward explanation. Trust does not disappear; it learns to accept verification.

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi