Skip to main content

Street Safe Self Defence

Digital Safety, Digital Self Defense, Online Scams, Scams

One in Four Face Deepfake Scams: Use Two Step Verification

Person reviewing a suspicious video call

A deepfake scam uses AI-generated audio, video, or images to impersonate someone you trust and pressure you into sending money or sharing sensitive data. The moment a call, video, or message pushes you toward an urgent, secretive action, stop and verify through a separate channel you control before doing anything else. If something feels off, report it to your bank, the platform involved, or the Canadian Anti-Fraud Centre.


TL;DR:

  • Verify any urgent financial request through a separate trusted channel before acting, especially if it involves gift cards, cryptocurrencies, or wire transfers.
  • Observe media clues such as inconsistent blinking, mismatched lighting, or unnatural lip movements to identify potential deepfake videos or audio.
  • Use behavioral questions or physical gestures like asking the caller to turn their head or cover their face to spot real-time deepfake manipulation.
  • Report suspected scams to authorities and preserve original files, timestamps, and transaction details early to aid investigation.
  • Practice and establish verification routines in low-pressure situations to build automatic habits that prevent trust in deepfake scams.

Table of Contents

What are deepfake scams? Types and common targets

Deepfake scams take several forms, and most people encounter more than one variant without realizing it. Voice cloning recreates someone’s speech patterns from a short audio sample. Synthetic video deepfakes swap faces or generate entirely fabricated footage. Manipulated still images get paired with fake captions or fabricated endorsements. All three tactics usually show up wrapped in classic social-engineering pressure: urgency, secrecy, and a request that bypasses your normal habits.

Certain scam templates repeat because they work:

  • Grandparent or family emergency scams: a cloned voice claims to be a relative in trouble, needing cash wired immediately.
  • CEO or payment fraud: an employee gets a deepfaked voice or video call from a “boss” authorizing an urgent wire transfer.
  • Romance and catfish scams: a fabricated video call builds trust before the request for money arrives.
  • Fake celebrity or political endorsements: manipulated clips show public figures promoting investments or products they never touched.

These succeed because familiarity with a voice or face short-circuits your usual scepticism, and scammers pair that familiarity with time pressure so you act before you think to check.

How deepfakes are made and what clues they leave behind

Voice cloning tools train a model on sample audio, sometimes just a few seconds pulled from a social media video, then generate new speech in that person’s cadence and tone. Video deepfakes often rely on generative adversarial networks or diffusion models that learn a face’s movement and lighting patterns well enough to paste it convincingly onto new footage. Neither process is flawless, and the seams still show if you know where to look.

Watch for these observable clues:

  • Blinking that looks too frequent, too rare, or oddly timed.
  • Lip movements that lag slightly behind or don’t quite match the audio.
  • Lighting or shadows on the face that don’t match the background.
  • Skin texture that looks unnaturally smooth or waxy in patches.
  • Audio with an unnatural cadence, odd pauses, or abrupt edits mid-sentence.

No single tell is reliable on its own. MIT Media Lab’s Detect Fakes project found that accuracy improves substantially when people check multiple artifacts together, rather than fixating on one detail like blinking. A slightly odd blink rate on a bad webcam feed doesn’t mean much by itself; a bad blink rate combined with mismatched lighting and a garbled audio edit tells a much clearer story.

What real deepfake fraud cases reveal about the risk

What real deepfake fraud cases reveal about the risk — overview diagram

The scale of this problem is already measurable, not theoretical. McAfee’s global survey of 7,000 people found one in four had direct or indirect experience with a voice-cloning scam, and 70% said they weren’t confident they could distinguish a cloned voice from the real thing. That uncertainty has a price tag: among victims who recognized the voice being cloned, 77% reported losing money.

The pattern behind most losses follows a similar arc:

  1. Reconnaissance: scammers pull a voice or video sample from a public post, an old interview, or a data breach.
  2. Fabrication: they generate a cloned voice or synthetic clip, sometimes needing only a few seconds of source audio.
  3. Contact: the fake reaches out through a call, video message, or social post, usually with urgency baked in.
  4. Conversion: the victim is steered toward gift cards, wire transfers, or cryptocurrency, all payment methods that are hard to trace or reverse.
  5. Disappearance: by the time anyone questions the story, the funds are gone and the trail goes cold.

Political impersonation and fake celebrity investment pitches follow the same conversion logic, just aimed at a wider audience instead of one targeted family member. Government of Canada guidance specifically warns that AI-generated clips can show public officials urging Canadians toward products, giveaways, or investments they never endorsed. Gift cards and crypto stay the preferred payout method precisely because they’re nearly impossible to claw back once sent.

How can you tell if a video or call is a deepfake?

Spotting a deepfake in real time comes down to layering media clues on top of behavioural ones, since either alone leaves too much room for doubt.

On the media side, look for:

  • Lip-sync that drifts out of alignment during longer sentences.
  • Blinking patterns that feel mechanical or absent altogether.
  • Lighting that shifts inconsistently across the face compared to the room.
  • Compression artifacts or blurring concentrated around the jawline and hairline.
  • Audio stutters, robotic cadence, or oddly placed pauses.

On the behavioural side, treat these as red flags regardless of how convincing the media looks:

  • A request to keep the conversation secret from other family members or coworkers.
  • Urgent payment demands with no room to “think it over.”
  • A push toward gift cards, cryptocurrency, or wire transfers instead of normal payment channels.
  • Pressure to skip standard verification steps “because there’s no time.”

Pro Tip: If you’re on a video call and suspect a deepfake, ask the person to turn their head sideways or place a hand fully over half their face. Many real-time face-swap tools still struggle with extreme angles and occlusion, and the glitch often shows up instantly.

A simpler trick works for calls: ask a specific question only the real person would know, one that isn’t posted anywhere online, and listen for hesitation or a scripted-sounding non-answer.

How to protect yourself from deepfake scams

The most effective defence against deepfake fraud isn’t sharper eyesight. It’s a rule you follow every time, regardless of how convincing the voice or face seems.

  1. Make out-of-band verification mandatory. Any request involving money, passwords, or sensitive data gets confirmed through a separate channel, such as calling back a known number, before you act.
  2. Refuse gift-card requests outright. No legitimate employer, government agency, or family emergency is ever resolved with a gift-card PIN read over the phone.
  3. Treat crypto and wire-transfer requests as red flags when they arrive alongside urgency or secrecy, especially from someone claiming to be a relative or executive.
  4. Contact your bank directly the moment something feels wrong, rather than using any number or link provided in the suspicious message itself.
  5. Limit how much voice and video content you share publicly. A few seconds of clear audio is often enough to build a convincing clone, so a private social account matters more than people assume.
  6. Turn on multi-factor authentication everywhere it’s offered, and review your privacy settings on social platforms at least twice a year.

Pro Tip: Set a household or team rule that no financial request is ever approved on the first call, no matter who it appears to be from. A 15-minute callback delay costs you nothing and defeats almost every urgency-based scam script.

What to do if you’re targeted by a deepfake scam

Report suspected government impersonation or investment fraud to the Competition Bureau or the Canadian Anti-Fraud Centre, and flag the content directly through the social platform or payment app where it appeared.

Before you close any tab or delete anything, preserve what you can:

  • Save original files rather than just screenshots, since metadata matters to investigators.
  • Record exact timestamps, phone numbers, and transaction IDs.
  • Copy message headers or call logs if your phone or app allows it.

Then move fast on recovery: call your bank or payment provider directly, change any passwords involved, enable multi-factor authentication if you haven’t already, and consider an identity-theft remediation service if personal data was exposed.

A two-step verification system that actually holds up

Individually spotting every artifact in a deepfake is unreliable. What works consistently is a two-gate system that doesn’t depend on anyone’s ability to notice a bad blink rate under pressure.

Gate one: the red-flag filter. Run through the media and behavioural checks covered above. Does the audio stutter? Is there a secrecy request? Is the payment method unusual? Any single flag should slow you down.

Gate two: mandatory out-of-band verification. Regardless of how gate one goes, no money moves and no credentials get shared until you’ve confirmed the request through a channel the scammer doesn’t control. That means calling a known number back, not the one they gave you.

Family and workplace code words work best when they’re paired with something that changes, not just a static shared secret. A codeword that never changes can leak once and stay compromised indefinitely. Pairing it with a current, non-public detail, like a shared plan only your household knows about this week, makes replay attacks far harder.

Short, scenario-based digital risk and fraud awareness training helps these habits stick because rehearsed behaviour under mild stress transfers better to real pressure than reading a checklist once ever did.

SituationGate one checkGate two action
Unexpected call asking for moneyListen for urgency, secrecy, odd cadenceHang up, call back on a known number
Video call requesting sensitive dataCheck lip-sync, lighting, blinkingAsk a private, unposted verification question
Social post with a celebrity endorsementCheck for compression artifacts, odd audioVerify through the person’s or brand’s official channel
Workplace payment request from “executive”Note bypassed normal approval processConfirm via internal phone directory, not the message

Why verification routines beat trying to spot AI

Chasing perfect deepfake detection skills is a losing race. The technology improves every few months, and expecting anyone, including trained professionals, to reliably eyeball a synthetic voice under real-world pressure sets people up to fail. What holds up over time isn’t sharper senses. It’s a behavioural gate that doesn’t care how good the fake is.

Why verification routines beat trying to spot AI — overview diagram

Simple verification rules stop most scams regardless of how convincing the AI gets, because the scam depends on you skipping the callback, not on you failing to notice a lighting glitch. Short drills, run occasionally with family or coworkers, build the reflex to pause before the reflex to trust kicks in. Organizations that fold a five-minute scenario drill into onboarding see that habit spread faster than any written policy ever manages on its own.

Communities and workplaces that practise this together, rather than leaving each person to figure it out alone, close the gap that individual vigilance can’t.

— Rob

Build verification habits before you need them

You’ve now got the red-flag filter and the verification gate. Turning that knowledge into a reflex, one that holds up when a call sounds exactly like your dad or a video looks exactly like your boss, takes practice under mild pressure, not just reading about it. That’s the gap Streetsafeselfdefence’s digital risk and fraud awareness sessions are built to close: hands-on, mobile workshops that walk families, corporate teams, educators, and real estate professionals through the same scenario drills covered here.

Streetsafeselfdefence

Sessions cover verification routines, code-word design, and live scenario drills, delivered onsite so your household or team practises the exact moment of hesitation that stops a scam cold. It’s a fit for families wanting a shared protocol, HR teams building onboarding content, and offices that handle wire transfers or client payments regularly. Book a mobile training session and give your group a rehearsed response before a scammer ever tests it for real.

Sources

For government guidance on AI impersonation and where to report it, see the Competition Bureau’s warning on AI-generated impersonators. The Canadian Anti-Fraud Centre’s deepfake bulletin covers rising impersonation reports and how to file one. McAfee’s voice-cloning research breaks down survey figures on incidence and loss. MIT Media Lab’s Detect Fakes project explains the multi-artifact detection approach referenced throughout this guide. For a behavioural look at how scammers exploit urgency, see this piece on rising online scams.

TESTIMONIALS

Word on the street

Check out what some of our past clients have said about our programs!

“Rob provides reality-based training that is informative, creates awareness and could save your life someday! The hands-on training is both fun and effective! Thanks Rob and Beth!!".
“This course is taught with the perfect balance of realism, respect, and compassion. Rob and Beth, you’re a power team and you do what you do extremely well! Thank you for everything".
“I learned so much today that I hope never to use, but if the time comes I feel much better prepared to defend myself. Thank you for making a difference in so many people’s lives".
“Top quality instruction from some of the most honest and straight forward folks around".
Excellent for people of all ages! Practical tips and tactics to help keep you safe & deal with "situations" both that are happening & ones that mght happen if you do not take the sensible advice they offer. HIGHLY RECOMMENDED!