Solutions
Deepfake social engineering attacks
Catch the deepfaked faces attackers use to manipulate employees into transfers, access, and approvals.
3,000%
growth in deepfake-based fraud attempts in a single yearSource: Onfido Identity Fraud Report
- Screens shared media for deepfakes
- In-meeting deepfake detection
- Flags impersonation before the ask lands
The threat
Modern social engineering wears a real face: a deepfaked executive on a video call, or an urgent message that looks like it came from someone you trust, pressuring an employee to move money or hand over access. In the 2024 Arup case, one such call moved $25M.
A verification layer across your riskiest requests
Social engineering converges on a few moments like a payment approval, a credential reset, or an access grant, so ScamAI deploys there: employees who handle them run Halo to verify faces in every meeting on-device. Any media used to build trust is scored through the REST API, and a flagged face or forged document pauses the request for verification through a known channel.
Awareness training assumed the fake would look fake
A decade of training taught employees to hunt for tells like bad grammar and video that looks off, but generative AI retired those tells (Onfido measured 3,000% single-year growth in deepfake fraud attempts). Training still matters for the instinct to slow down and verify, but the human eye can no longer be the detection layer: people own pausing and verifying out-of-band, software owns judging whether the face is real.
/ROI
What this is worth
- Loss avoidance: as an illustration, at 50,000 checks a month, catching just 0.2% more synthetic media is ~100 frauds stopped — at a $10k average loss, that's ~$1M a month that never walks out the door.
- Review time: evidence-backed results cut manual review from minutes to seconds, so analysts handle the small flagged fraction instead of screening everything.
- One integration: a single REST API covers faces, documents, and devices — no second vendor, no second review queue.
Common questions
What is deepfake social engineering?
Deepfake social engineering is manipulation that borrows a trusted face: an attacker appears on video as an executive, colleague, or vendor and uses that trust to push an employee into a transfer, a credential reset, or an access grant. It extends classic pretexting with synthetic media convincing enough to defeat visual judgment, stacking urgency and confidentiality to keep the target from verifying. Defenses combine process — out-of-band verification for sensitive requests — with in-meeting detection that flags the fake directly.
Can employees be trained to spot deepfakes?
Training helps with process but not with perception. Employees can reliably learn to pause on urgent requests, verify through separate channels, and escalate anomalies — behaviors that stop many attacks however good the fake. What they cannot learn is to see deepfakes: modern face swaps eliminate the glitches older awareness material taught people to find. Effective programs pair the trained behaviors with algorithmic detection, such as Halo running during meetings, so identifying the synthetic face is not a human responsibility.
How should a company verify an urgent request made over video?
Urgent video requests should be verified through a channel the requester did not control: a phone number from the directory, a message in the corporate chat thread, or an in-person check — never contact details provided during the call. The policy works best unconditional, applied to every payment or access request above a threshold, because attackers engineer exceptions to feel justified. In-meeting detection strengthens the policy by flagging synthetic faces during the call, giving employees grounds to invoke it.
See Halo flag a deepfake in a live meeting
15 minutes, on your own media. Pick a slot and leave with a result.