Talk to us
Whether you're buying, selling, partnering, or investing — pick what fits and our team will get back to you within one business day.
A real human, fast
Someone on our team replies within one business day — no bots, no ticket queue.
Routed to the right team
Buying, selling, partnering, or investing — you reach the people who can actually help.
Independent & unbiased
No pushy sales. Just honest guidance grounded in the ecosystem.
Tailored to your context
Tell us what you need and we shape the next steps around it.
Who are you? Pick the option that fits best.
For decades, a familiar voice or face was proof enough. AI just quietly deleted that assumption — and most companies haven't updated their controls to match.
The short version: Deepfakes have turned "I recognized their voice" into a security liability. AI can now clone a voice from seconds of audio and fake an executive on a live video call — and criminals are already using it to authorize fraudulent payments, most infamously a roughly US$25 million transfer at engineering firm Arup. Detection is an arms race you can't win on its own. The 1% defend with process: never move money or data on a voice or face alone, and verify high-value requests out-of-band, every time.
For decades, a familiar voice on the phone or a face on a video call was proof enough. AI just quietly deleted that assumption — and most companies haven't updated their controls to match. Deepfake fraud is the social-engineering threat of the AI era, and it's already cost real companies real money.
A deepfake is AI-generated audio, video, or imagery that convincingly imitates a real person. Deepfake fraud weaponizes it: a cloned executive voice authorizing a wire, a faked face on a video call instructing a payment, a synthetic voice impersonating a customer or colleague. It's business email compromise with a human face bolted on — and the face is convincing.
Fact, widely reported. In 2024, an employee at the global engineering firm Arup was tricked into transferring around US$25 million after joining a video conference in which deepfaked versions of the company's CFO and other colleagues appeared and told him to make the payments. Everyone "on the call" was fake except the victim. It is the highest-profile case of a pattern that is now spreading down-market to ordinary criminals — because the tools got cheap.
The instinct is to buy a deepfake detector. Useful, but not a safeguard. Detection is an arms race: every improvement in detection is met by an improvement in generation, so a tool that catches today's fakes may miss tomorrow's. Betting your payment controls on detection is betting you'll always be ahead in a race designed to stay close. The durable defense doesn't try to spot the fake — it refuses to trust a voice or face in the first place.
The fix is procedural, and it's cheaper than any detector.
Deepfakes are the human layer of AI risk. Where prompt injection manipulates AI systems and non-human identities expose machine access, deepfakes manipulate people — and they make every other attack more convincing. A complete posture, of the kind our AI governance and vendor security guides describe, has to cover human verification, not just technical controls.
Opinion, clearly labeled. Companies will spend the next few years buying deepfake detectors and running awareness webinars, and most will still get hit — because they'll keep letting a convincing voice authorize a payment. The 1% skip the arms race and change the rule: identity is never established by how someone looks or sounds, only by a verification step that a deepfake can't pass. It costs a few seconds of friction on high-value requests. The alternative costs $25 million. Assume the voice is fake, and build the process that makes it not matter.
A deepfake is synthetic audio, video, or images generated by AI to convincingly imitate a real person. In fraud, criminals use deepfake voice or video of an executive to authorize fake payments, or cloned voices to trick employees, customers, or family members. It supercharges classic social-engineering scams like business email compromise by adding a convincing human face or voice to the request.
Yes. In an incident widely reported in 2024, an employee at the engineering firm Arup was tricked into transferring about US$25 million after joining a video call in which deepfaked versions of the company's CFO and colleagues appeared and instructed the payment. It's the highest-profile example of a fast-growing pattern: AI-generated voices and video used to make fraudulent requests look and sound real.
Because the technology got cheap, fast, and good. Convincing voice cloning now needs only seconds of sample audio, and real-time video deepfakes are increasingly plausible on an ordinary call. What used to require a skilled team is now available to ordinary criminals, so the volume and quality of AI-enabled fraud is rising sharply — while most companies' verification habits still assume a familiar voice or face is proof of identity.
The core defense is process, not detection: never authorize money or sensitive actions on the strength of a voice or video alone. Require out-of-band verification through a separate trusted channel, use pre-agreed verification steps or code words for high-value requests, enforce multi-person approval for large payments, and train staff that urgency plus a familiar-sounding voice is a red flag, not a reason to comply. Assume audio and video can be faked.
Not reliably enough to depend on. Deepfake-detection tools exist and are improving, but it's an arms race — as detectors improve, so do the fakes, so detection alone is not a safe control. The durable defense is procedural: verification steps and approval controls that don't trust a voice or face in the first place. Treat detection as a helpful layer, not the safeguard.
They target different things. Phishing and prompt injection manipulate systems and inboxes; deepfake fraud manipulates people by faking a trusted human. Deepfakes are the social-engineering layer of the AI threat landscape — and they pair with the others, since a convincing fake voice makes every other attack more effective. A complete security posture has to cover human verification, not just technical controls.
Tags
The 1% Stack
Saaskart's media & intelligence series for software buyers, founders, and operators — opinionated takes on SaaS, AI agents, and the stacks that separate the 1% from everyone else.
Explore thousands of vetted tools, AI agents, and service providers on Saaskart — compare features, pricing, and real buyer reviews in one place.