A finance employee joins a routine video call. The CFO is there, along with someone from legal and a VP she recognizes. For eighteen minutes, it feels like a completely normal meeting. Then, near the end, the CFO asks for a time-sensitive vendor payment. She sends it. None of the people on that call were real. This is deepfake video call fraud, and it has moved from theoretical risk to documented, costly reality faster than most security awareness training in Dubai has been able to keep up with.
How deepfake video call fraud actually works:
Deepfake video call fraud is a form of business email compromise where an attacker uses real-time, AI-generated audio and video to impersonate a trusted executive on a live meeting, then uses that manufactured trust to authorize a payment or extract access. Attackers build these impersonations from public material: earnings calls, LinkedIn videos, leaked recordings, or conference footage, then wrap the resulting deepfake inside a fake Zoom invite, a phishing email, or a hiring process. The result looks and sounds like someone employees already trust, which is exactly what makes it effective.
The threat is no longer hypothetical:
A Hong Kong case made this risk concrete when an employee transferred roughly 25 million US dollars after a video call with what appeared to be several senior staff members, including the company’s CFO. That case also demonstrated a more advanced version of the attack: multiple participants on a single call were deepfaked simultaneously, not just one executive. Broader data confirms this is not an isolated incident. Gartner’s research found that over a third of organizations have already been hit by a deepfake incident during an online meeting, yet only a small fraction of security leaders currently prioritize deepfake recognition within their training programs, a gap that most security awareness training in Dubai still needs to close.
Why this breaks the usual defenses:
Traditional phishing training teaches employees to look for red flags: odd email addresses, spelling errors, urgent language. Deepfake video calls remove almost all of those signals. The face on screen is familiar, the voice sounds right, and the meeting itself feels procedurally normal, since video calls are simply how business gets done. The psychological trigger attackers rely on is urgency: the fake CFO doesn’t want the employee to pause, verify, or call back on a known number, because that single habit defeats the entire attack regardless of how convincing the deepfake looks.
The out-of-band callback: the single most effective defense:
Every major analysis of this threat converges on the same core control. If an unexpected, high-stakes request comes through a video call, the employee should end the call and dial the person back on a number already stored in the company directory, never a number supplied during the call itself. No deepfake, however advanced, can intercept a call the employee initiates independently to a number they already have. This is the foundation any serious security awareness training in Dubai should be building around, since it is a simple, low-tech habit rather than a piece of detection software employees have to trust blindly.
Beyond the callback, a few additional protocols strengthen this further: requiring dual approval for financial requests above a set threshold, using rotating verbal passphrases for executive and finance teams, and never treating a single video call as sufficient authorization for a wire transfer, no matter who appears to be asking.
Building this into organizational training:
Awareness training that only covers email-based phishing leaves a significant gap, since voice and video deepfakes require a different kind of preparation. Employees benefit from actually encountering a synthetic voice or face in a training scenario before they meet one in a real attack, since recognizing the pattern in a low-stakes setting builds the instinct to pause under real pressure. Regulation is also starting to catch up. The EU AI Act’s deepfake transparency provisions became enforceable in August 2026, requiring disclosure of AI-generated content, though this addresses labeling rather than real-time detection, which is exactly why procedural defenses like the callback remain essential regardless of what regulation eventually requires.

How Imperium builds deepfake awareness into training:
At Imperium Middle East, our security awareness training in Dubai is built around the threats organizations are actually facing today, including deepfake video and voice impersonation, not just legacy email phishing scenarios. We work with finance and executive teams specifically, since they remain the highest-value targets for this kind of fraud, to build callback verification habits and escalation protocols that hold up even when the person on screen looks exactly right.
Frequently asked questions
1. Can deepfake video calls really fool experienced employees?
2. Is there software that can detect deepfakes in real time?
3. Who is most at risk from this type of fraud?
4. How often should employees receive deepfake-specific training?
Getting started
Deepfake video call fraud has already cost organizations tens of millions of dollars, and the technology behind it is only becoming more accessible. A single verification habit, calling back on a known number, remains the most reliable defense available, but it only works if employees have actually practiced it before facing the real thing.
Get in touch with Imperium Middle East to build security awareness training in Dubai that prepares your team for deepfake and video-based fraud, not just email phishing.