Cybersecurity · Artificial Intelligence

Defending against AI-powered deepfake impersonation

Written by the Mono training team · · 16 min read Share
Executive summary Deepfake technology — synthetic media that uses AI to convincingly alter video, audio, or images — now fuels some of the sharpest social engineering threats organisations face. Criminals clone executive voices and faces to issue urgent requests over video calls, phone, or email, leading to fraud and data loss at scale. This article looks at the evidence, the regulatory landscape, and the defences that actually work — centred on people, not just technology.
Data sources
Resemble AI, Deepfake Incident Reports (2025)·Surfshark Research (2025)·Gartner AI Risk Management Survey (2025)·Deloitte Center for Financial Services·South Australian Attorney-General's Department; Senator David Pocock's office
Figures reflect publicly reported research as of mid-2026. Findings evolve — verify current studies before citing externally.
01It has already arrived

The scale of the threat, by the numbers

The deepfake threat is no longer emerging — it has arrived. The data from 2025 is unambiguous about both scale and acceleration.

2,031

verified deepfake incidents in Q3 2025 alone — the highest ever recorded in a single quarter.

Resemble AI
$1.1B

in deepfake-related fraud losses in 2025, roughly tripling from ~$360M in 2024.

Surfshark Research
312%

year-on-year increase in deepfake incidents, Q2 2024 to Q2 2025.

Surfshark Research

In Australia, ASD's ACSC confirms AI is supercharging attacks: phishing laced with deepfakes featured in a majority of cyber incidents responded to in 2025, and large Australian businesses saw average cyber costs rise sharply, with AI-driven impersonation topping the list of new threats. These threats extend beyond financial loss — they erode trust in digital communication and can manipulate markets or sabotage supply chains through fake executive announcements or vendor impersonation.

02Not hypothetical

Real-world case studies — what has already happened

These are not hypothetical scenarios. The incident below is one of the most thoroughly documented cases of 2024–2025, illustrating the tangible impact of deepfake impersonation on an organisation that believed its controls were sufficient.

Arup — $25.6 million, January 2024

A finance employee at the UK engineering and design firm Arup authorised 15 wire transfers — around HK$200 million — after joining a video call populated entirely by AI-generated colleagues, including a deepfake of the CFO. The voice and likeness were indistinguishable from the real executives. Standard verification procedures were bypassed through urgency and authority cues. Hong Kong Police confirmed the attack; the funds were never recovered.

This is not an isolated pattern. Gartner's 2025 AI Risk Management Survey found that 62% of organisations reported a deepfake incident in the prior 12 months, and separate executive-protection research puts the share of organisations reporting deepfake incidents specifically targeting executives at 41% — up from 34% just two years earlier. Common tactics include impersonation of a trusted contact with an urgent demand for payment or information.

In Australia, while individual corporate cases are less publicised, the ACSC reports rising AI-enhanced phishing in finance and government sectors, where deepfakes have increasingly facilitated credential theft and payment fraud.

03The rules are catching up

The regulatory landscape — Australia and global

Regulatory responses to deepfake misuse are accelerating, but enforcement still lags the threat. Organisations should align with these frameworks now, rather than waiting for mandatory requirements to crystallise.

Australia · StateSouth Australia

Laws effective November 2025 criminalise AI-generated violent or sexually degrading deepfakes, with penalties up to $20,000 or four years' imprisonment.

Australia · FederalMy Face, My Rights Bill

Introduced by Senator David Pocock in November 2025, proposing amendments to the Online Safety Act and Privacy Act requiring consent for using a person's face or voice in AI content, with new powers for the eSafety Commissioner.

Australia · FederalCriminal Code Amendment

The Criminal Code Amendment (Deepfake Sexual Material) Act 2024 already criminalises sharing non-consensual sexually explicit deepfakes, with penalties up to six years' imprisonment.

GlobalEU AI Act & US TAKE IT DOWN Act

Both address non-consensual deepfakes at a regulatory level, though enforcement currently lags. Organisations with EU exposure or global operations should build these into their compliance strategy now.

Regulatory alignment is a floor, not a ceiling. Organisations that treat compliance as the target are already behind the threat — the evidence calls for a proactive, people-first approach that goes well beyond minimum obligations.

04Where defence actually starts

Building a robust culture — the four pillars

The foundation of deepfake defence lies in people. Technology helps, but organisations with proactive, people-first programs cut successful breaches significantly more than those relying on tools alone. Effective defence rests on four interlocking pillars.

01

Interactive simulations

Fake executive calls, glitched deepfake video, voice-cloned vishing. Employees learn to spot lip-sync drift and audio mismatch through live drills, not slides.

02

Monitoring & detection

AI-based anomaly detection, liveness checks that verify real-time human presence, and behavioural biometrics that flag mismatched typing or voice patterns.

03

Human-centric zero trust

No one is trusted by default for unusual requests — even from senior leadership. Code phrases for high-stakes communications, plus biometric MFA.

04

Incident response, phased

Assess, train, test, review. A dedicated response plan for detection, communication, and legal action — prepared before it's needed, not during.

05The human firewall

What good deepfake awareness training looks like

Generic cybersecurity training does not prepare people for deepfake threats. Programs that actually work share specific traits: deepfake-specific indicators (unnatural facial movement, audio glitches, lip-sync drift), scenario-based simulations across email, calls, and video, executive-focused content for the people disproportionately targeted, clear second-channel verification protocols, and ongoing reinforcement — quarterly, not annual.

Effective defence turns employees into a human firewall — not through fear, but through genuine competence built over time.

That competence only develops through repeated, realistic practice — the same principle that runs through every Mono course.

06Where this is heading

Looking ahead — the deepfake threat, 2025 to 2028

Forecasts from research firms are unambiguous: deepfake-related threats will keep accelerating over the next two years. Organisations that build their defences now will be substantially better positioned than those who wait.

2025

Deepfake fraud losses reach roughly $1.1 billion — tripling from 2024. Executive impersonation via voice and video becomes a standard attack vector, and cheap AI tools lower the skill barrier for attackers.

2026

Detection spending projected to surge as deepfakes go mainstream across industries (Forrester). Deepfake-driven employment fraud escalates, with AI-generated interviews and résumés.

2027

Generative AI fraud losses in the US alone projected to reach $40 billion, up from $12.3 billion in 2023 — a 32% compound annual growth rate (Deloitte Center for Financial Services).

2028

Up to 80% of social engineering attacks could feature deepfakes without global standards on AI misuse (WEF). Organisations with people-first programs will be measurably more resilient than those without.

The threat is accelerating. But so is the shield — if you build it now.

Key takeaways

What this means for your organisation

01

The threat is real and accelerating

2,031 verified incidents in Q3 2025 alone, $1.1 billion in losses, 62% of organisations already affected. This is a present risk, not a future one.

02

Technology alone is insufficient

Deepfakes exploit human trust, not software vulnerabilities. Detection tools help — but trained, vigilant people are the primary defence.

03

Verification protocols are essential

Code phrases, second-channel verification, and zero-trust habits need to become embedded behaviour — not procedures only remembered under pressure.

04

Proactive programs outperform reactive ones

Organisations that build people-first simulation programs now will be measurably more resilient than those waiting for a breach to act.

Enjoyed this article?

Build the human firewall before the attack arrives.

Click or Flick Corporate delivers deepfake-aware training, realistic simulations, and the behavioural reinforcement that turns awareness into instinct. If the evidence here concerns you, the program page is the right next step.