A deepfake call is no longer easy to spot
Faces and voices are synthesised live from material already public. The visual tells are disappearing — the behavioural ones are not, and neither is calling back on a number you already had.

Short answer
A deepfake call is a live video or voice call where the face, the voice or both are generated rather than captured. Voice cloning needs only a short public recording and face synthesis now runs in real time, so seeing and hearing someone is no longer verification. Hang up and call back on a number you already had — that is the one defence that does not weaken as the technology improves.
On this page
For most of the time video calling has existed, seeing someone settled the question of who they were. That assumption is now unsafe. Synthesised faces and cloned voices run in real time on ordinary hardware, and the recognisable version of this is no longer a laboratory demonstration — it is a finance employee approving a transfer after a call with people who looked and sounded like colleagues.
A deepfake call is a live video or voice call in which the face, the voice, or both are generated rather than captured. The technique is not new; what changed is that it now runs live, cheaply, and needs only a small sample of the person being imitated.
Why seeing is no longer sufficient
A deepfake call became practical because three developments happened at once, and the combination is what matters.
- Voice cloning needs very little audio. A short recording — a voicemail greeting, a conference talk, a story posted publicly — is enough for a usable clone. Anyone who has spoken in public has provided the sample.
- Face synthesis runs in real time. It no longer requires rendering in advance, so it works in a live conversation and responds while you watch.
- The material is public. Photos, videos and recordings of most professionals are online, posted by them or by their employer, and there is nothing to be done about that retrospectively.
The face and the voice are no longer credentials. They are content, and content can be produced.
Two consequences follow. Verification has to move to something that cannot be synthesised from public material, and it has to happen outside the call itself — because anything performed inside a channel the attacker controls proves nothing about the channel.
What these calls are used for
A deepfake call is nearly always used to make an ordinary process happen faster than its checks allow.
| Scenario | What is requested |
|---|---|
| Executive impersonation | An urgent payment outside normal process |
| Family emergency | Money sent immediately, quietly |
| IT support | Credentials, or a code read aloud |
| Investment or partnership | A transfer to a new account |
| Recruitment | Documents and identity details |
The family emergency version is the one that reaches individuals rather than companies, and it is built on distress rather than authority. A voice that sounds like your child or your parent, in trouble, asking you not to tell anyone else — the secrecy request is functional, because a second person would break it in one phone call.
The tells, and why not to rely on them
A deepfake call leaves artefacts. They are real, and they are also disappearing, which is why the advice built on them ages badly.
In the picture: a face that does not turn fully to profile, hair and glasses that flicker at the edges, lighting on the face that does not match the room, a hand passing in front of the face producing distortion, and blinking that is either too regular or absent.
In the audio: flat prosody across a long sentence, absent breath, background noise that stays constant regardless of movement, and slight timing mismatches with the lips.
In the behaviour: reluctance to switch to a different channel, deflection of specific personal questions, and pressure that increases when you hesitate.
The third group is the durable one. The visual and audio artefacts are being engineered away release by release, and a system that fails those tests today may pass them next year. The behavioural signals are structural: whatever the fidelity, the caller still needs you to act now and to avoid verification.
There is one active test still worth attempting, on the understanding that it is weakening: ask the person to turn fully sideways, or to pass a hand slowly across their face. Many live systems still degrade visibly. Treat a pass as inconclusive rather than as proof.
What if you are the one being impersonated?
The other half of this is being the face someone else uses, and it is more common than people expect for anyone with a public role — an employer, a landlord, a treasurer of a club.
Three things you can do in advance:
- Tell people how you will and will not contact them. A stated policy — "I will never ask you to move money by message or on a call" — is what a colleague or a family member measures the impersonation against. It costs one sentence in an onboarding document.
- Publish a verification route. A number people can call back on, listed somewhere they can reach independently, converts an awkward request into a normal one.
- Do not treat it as embarrassing. Being impersonated says nothing about you except that your material is public. Teams that treat it as a failure of the victim get told about it later, which is precisely when it is too late to intervene.
And if it has happened, act on distribution rather than on the artefact: tell the people likely to be contacted, directly and quickly, because a warning that reaches someone before the call is worth more than any subsequent explanation. Report it to the platform where it circulated, and if money was involved, to the police fraud line — but the warning to your own contacts is the part that actually prevents the next loss.
Verification that actually holds
Everything reliable shares one property: it happens outside the call.
- Hang up and call back on a number you already had. Not a number given on the call, not a callback offered — one from your own contacts or the organisation's published listing. This single step defeats nearly every version, and it is the only advice here that does not weaken as the technology improves.
- Use a second channel. Message the person on a platform you have used with them before and ask whether they are on a call with you right now.
- Ask about something shared and unrecorded. Not a fact — facts are researchable. Something the two of you experienced, from a context that was never posted anywhere.
- Follow the process, especially under pressure. Payment approvals exist to be slow. An instruction to bypass them is the signal itself, regardless of who appears to be giving it.
- Agree a family code word. One word, agreed in advance, never written down anywhere digital. For the emergency version this is the whole defence and it takes a minute to arrange.
Point one is worth stating plainly because people find it socially awkward. "I'm going to call you back on the number I have" is a normal thing to say, and anyone genuine will understand it — while anyone who objects has told you what you needed to know.
Reducing your own exposure
You cannot remove what is already public, but you can make a deepfake call of you harder to produce and less useful when it happens.
Recorded audio is a resource. This is not an argument for silence — it is an argument for knowing that voice notes, talks and podcast appearances are training material, and that anyone with public recordings should assume a clone is feasible. Local, on-device recording tools such as TapMemo at least keep the audio you produce privately from being uploaded anywhere in the first place, which is a small but real reduction.
Two people for anything that moves money. The most effective organisational control by a wide margin, because it does not depend on anyone detecting anything.
Never approve a payment on a call alone, whatever the seniority of the person appearing on it.
Talk about it before it happens. Households and teams that have discussed this once respond far better, because the first time is when the pressure works.
More on impersonation patterns in impersonation, the messaging equivalents in messaging scams, and account protection in digital safety. The NCSC on generative AI and integrity covers the organisational side in more depth.
The short version
A deepfake call means a video or voice call is no longer evidence of who is speaking. Faces and voices are synthesised live from publicly available material, and the artefacts that give it away are shrinking with each release.
Verify outside the call: hang up and dial a number you already had, message on a channel you have used before, and agree a code word with your family. Never approve a payment or release a credential on a call alone — and treat urgency plus a request to skip the usual process as the signal, because that part does not improve with the technology.
Frequently asked questions
- How much audio does a voice clone need?
- Very little — a voicemail greeting, a conference talk or a posted video is generally enough. Anyone who has spoken publicly has already provided the sample.
- Can I spot a deepfake call by looking carefully?
- Sometimes today, less so each year. Artefacts around hair, profile turns and a hand crossing the face still appear, but they are being engineered away. The behavioural signals — urgency, secrecy, resistance to switching channels — are the durable ones.
- What is the single best verification step?
- Hang up and call back on a number you already had, from your own contacts or an official listing — never a number offered during the call. It defeats nearly every version and does not depend on detecting anything.
- How do I protect my family from the emergency version?
- Agree a code word in advance, never written down digitally, and talk about the scenario once before it happens. The request not to tell anyone else is functional, because a second person would end it with one phone call.
Sources
- Preserving integrity in the age of generative AI — UK National Cyber Security Centre
- Imposter scams — US Federal Trade Commission
- TapMemo: AI Voice Recorder — Tecno Blocks
Scamiro
Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.
About the publication