A familiar face is not proof. A familiar voice is not proof. A message from a familiar account is not proof.
That does not mean everything online should be treated as fake. It means the evidence required for a high-impact decision has to become stronger as synthetic media and account impersonation become easier to produce.
The new rule is simple:
Verification comes before trust when the consequence is high.
The problem is bigger than deepfakes
Deepfakes receive attention because they are visually dramatic, but many successful scams do not require sophisticated synthetic media at all.
An attacker may use a spoofed phone number, a compromised email account, a stolen social profile, a copied writing style, a cloned voice, or an urgent message that includes information gathered from public sources.
The common weakness is not always the fake itself. It is the process that allows one convincing message to trigger an irreversible action.
That is why The Deepfake Test Is the Wrong Test argues for a verification system instead of relying only on detection.
Separate identity from the request
When someone asks for something important, two questions should be answered independently:
- Who is making the request?
- Is the requested action legitimate?
A real employee can have a compromised account. A real customer can misunderstand a process. A real executive can send an unusual instruction. Confirming the person does not automatically prove the transaction or change is appropriate.
Likewise, a convincing voice clone does not prove the caller has authority.
Use a second channel for high-impact changes
The strongest simple rule is to verify through a channel the requester did not control in the original interaction.
If the request arrives by email, call a known number. If it arrives by phone, confirm inside a trusted system or with another authorized person. If it arrives in a messaging app, use a pre-existing contact route rather than a link or number supplied in the message.
This matters most for:
- banking or payment-instruction changes;
- wire transfers or urgent purchases;
- password or MFA resets;
- remote-access requests;
- domain, storefront, or advertising-account changes;
- release of private records;
- legal or contractual approvals;
- changes to account ownership or administrator roles.
Urgency should increase verification, not reduce it
Many scams work by compressing the victim's decision window.
The request may say the account will be closed, the payment is late, a family member is in danger, an executive is waiting, a customer will be lost, or the opportunity disappears unless action happens immediately.
A strong process treats urgency as a reason to use more verification.
The Imposter Scam Defense framework focuses on exactly this pressure point: when urgency replaces verification, the attacker gains control of the decision process.
Create a pre-agreed verification path
Verification is easier under pressure when the process was defined in advance.
Families can agree on a callback rule or a private confirmation question. Small businesses can require two-person approval for banking changes. Creators can document who has authority to approve sponsorship, licensing, or account changes. Teams can define which requests can never be completed from email alone.
The method does not need to be elaborate. It needs to be independent and known before the incident.
Do not let public information become a secret
A verification question is weak if the answer can be found on social media, public records, a company website, or a data-broker profile.
Birthdays, pet names, family relationships, addresses, employers, travel plans, and recent events are useful context for social engineering because people often assume only a real acquaintance would know them.
Reducing exposed personal data therefore strengthens verification.
See Your Personal Data Keeps Regrowing for the privacy side of that problem.
For businesses, protect process changes as carefully as passwords
A company can have strong account security and still lose money if its payment-change process is weak.
The attacker may never need the bank password. They only need to convince the right employee to send money somewhere new.
That is why payment instructions, vendor banking changes, payroll changes, refund destinations, and executive requests need a confirmation process that exists outside the incoming message.
The Five-Minute Rule provides a practical version of this idea for small businesses.
Creators need verification around likeness and rights too
AI impersonation is not limited to fraud against consumers. A creator's face, voice, style, and identity can also be used in synthetic endorsements, fake advertisements, unauthorized replicas, and licensing disputes.
Creators benefit from maintaining records of authorized campaigns, usage periods, approved partners, licensing terms, and whether digital replicas or synthetic edits were permitted.
For that side of the system, read Your Voice and Face Are Licensable Assets.
Content provenance can help, but it does not replace judgment
Content Credentials and provenance systems can provide useful information about the origin and editing history of media when those signals are available. They are an additional source of evidence—not a universal guarantee that every authentic item will carry credentials or every misleading item will be easy to identify.
For creators and publishers, the practical goal is to preserve trustworthy production records and use provenance information as one layer of the verification process.
See AI Content Provenance for Creators for a deeper explanation.
A verification system turns uncertainty into a process
The point is not to become suspicious of every interaction.
The point is to know which actions deserve independent evidence before they happen.
That keeps the rule simple:
low consequence → ordinary trust;
high consequence → independent verification.
Build that logic into your wider Digital Safety & Technology system before the next urgent request arrives.
Related resources