epfake is defined as a video, audio, or image created or manipulated through AI technology to give a genuine individual the appearance of saying or doing things they did not really say or do at all. The combination of “deep learning,” which is the machine learning technology used for making such content, and “fake” makes up the word.
The number of deepfakes available online has increased from around 500,000 in 2023 to about 8 million in 2025, according to reports by Cybersecurity Drive.
What Will I Learn?
What Does “Deepfake” Mean?
A deepfake is different from typical photo and video editing because the machine learning models generate the content instead of humans manually editing the pixels. Editing applications like Adobe Photoshop rely on humans selecting, cutting, and mixing image pieces together. The process of deepfake generation involves the training model learning patterns from the training data and then producing the frames, audio waves, or images without human intervention at the pixel level.
Deepfake content comes in various types. Video deepfakes involve replacing one person’s face with the other’s face in the video or changing the original video of the targeted individual. Audio deepfakes use voice cloning techniques to replicate someone else’s voice based on a recorded sample. Image deepfakes involve generating a still photo of the targeted person in a scenario which didn’t happen.
Deepfake vs. Synthetic Media vs. Shallowfake
The main idea: deepfake, synthetic media, and shallowfake represent three distinct types of manipulated or generated content, varying by the way of creation and the technology used in doing so.
Synthetic media is the overarching term for all content created or manipulated by artificial intelligence and including text, images, audio, and video. A deepfake represents a specific kind of synthetic media that is created using technology to represent a real-life individual in an artificial context. Shallowfake refers to an artificially modified video or other media made without the use of complex algorithms but simple editing tricks like changing the speed of a video or deleting words from audio.
| Term | Production Method | Requires AI Training | Example |
|---|---|---|---|
| Deepfake | Neural network trained on target’s likeness | Yes | AI-generated video of an executive giving false instructions |
| Synthetic media | Any AI-generated or AI-altered content | Yes (broad category) | An AI-written article, an AI-generated image, or a deepfake video |
| Shallowfake | Basic editing software, no AI training | No | A video slowed down to make a speaker sound impaired |
| Cheapfake | Low-effort manual edit or mislabeling | No | An old photo captioned with a false, unrelated event date |
How Deepfakes Are Made?
The creation of a deepfake involves three key ingredients: a dataset for the target individual, a training algorithm, and computing power to perform the training.
The Generative Adversarial Network (GAN) Process
A GAN is basically a method used to create the bulk of deepfake videos and images. GAN was invented by Ian Goodfellow, who works as a researcher at the University of Montreal in 2014.
GAN uses two neural networks that essentially go against each other. One neural network known as the generator creates new images or videos based on patterns it identifies from the training dataset. The second neural network is called the discriminator; it checks the generator’s output against actual samples and detects any differences. The generator improves on its output each time while the discriminator becomes better at spotting any errors. This process is repeated until the discriminator is unable to tell the difference between the generated data and real images or videos.
Autoencoders and Face-Swapping
Autoencoders are neural network architectures used to encode an input image into a compressed format that represents only the important features of the input image. The deepfake autoencoder uses the features learned from a source video, like facial expressions, head movement, and lighting. Then these features are encoded on the target video.
Voice Cloning
Voice cloning software creates synthetic voices that mimic the tone, rhythm, and speech patterns of a particular individual’s voice. Contemporary voice cloning software can create a voice that is accurate enough to use after processing just three seconds of audio, as reported by Proofpoint in its threat intelligence research.
What Are Deepfakes Used For?
Deepfake technology has documented uses in both legitimate industries and criminal activity.
Legitimate and Creative Uses
Some of the known uses of deepfake technology by organizations include:
- Films and video games. Film and game producers utilize voice cloning and face replacement to finish the shots without making the actor go back on set.
- Video dubbing and localization. Streaming services use lip-sync technology to synchronize the voice-over with an actor’s mouth movement in another language.
- Education. AI-powered tutoring platforms leverage voice and avatar technology to offer personalized lessons.
- Recreation of historical images. The technology is used by museums and documentary filmmakers to create animations of historical images.
- Automated customer service. Companies use voice technology to route calls and provide information regarding the status of accounts.
Malicious and Criminal Uses
Deepfake techniques have been employed by criminals for the following known uses:
- Financial fraud: Attackers masquerade as executives or even family members to sign off on wire transfer requests for illegal gain.
- Explicit imagery without consent: Attackers create explicit imagery or videos of individuals without their permission, usually targeting public figures.
- Interference in elections: Attackers create fake videos or audios of political candidates to sway voters.
- Disinformation campaigns: Governments and other non-governmental actors use fake videos of public officials to spread disinformation.
- Identity theft: Attackers use synthetic voice or face media to evade identity verification systems.
Deepfakes in Cybercrime: How Enterprises Get Attacked
In 2025, the total financial damage from deepfake enabled fraud for businesses in the US exceeded $1.1 billion compared to $360 million recorded in 2024 based on threat research conducted by Proofpoint. Enterprise deepfakes can be classified into five groups.
Executive impersonation takes place when the attacker steals the voice of the CEO by creating a copy of the voice using recordings of public speeches like earning calls or presentations. This attack is used when the cloned voice is called to authorize the transfer. In an example of this attack, a finance employee transferred $25 million after a video call where all the participants were deepfakes.
Email compromise (BEC) amplification involves making an additional call on top of the scamming request by email, which increases credibility of the latter and allows bypassing verification checks specifically intended for BEC attacks via text only.
Account takeover is performed by the use of a face-swap technology in order to pass a liveness test in video-based authentication of an account, or by a cloned voice to pass phone-based authentication at a call center.
Identity verification and Know Your Customer (KYC) bypass occurs when an attacker submits an AI-generated fake identity document or a synthetic selfie to pass an automated verification check.One financial company had reported over 1,100 deepfake attacks against its biometric verification of loan applications in just one year.
Attacks through brands or reputation may arise where the attacker spreads false video or audio content of the statements made by the company’s executive, regarding the company, its products, and financial status that may impact the value of the publicly listed stock of the company before a correction is issued.
Artificial Intelligence (AI) Course
Average time: 4 month(s)
Skills you’ll build: Python for AI, Machine Learning, Neural Networks, NLP Basics, AI Tools (ChatGPT, Copilot)
Real-World Deepfake Examples
Deepfake cases range from political to celebrity to enterprise targets.
Political and celebrity cases. There was a deepfake video of Facebook CEO Mark Zuckerberg making an incorrect claim regarding the control of user data. There was a deepfake video released in 2022 where the President of Ukraine, Volodymyr Zelenskyy, was shown ordering troops to lay down their arms during the Russian invasion of Ukraine. There were also several deepfake videos of various political figures in the United States that came out between 2019 and 2023.
Cases of enterprise fraud. At the beginning of 2024, a finance staff member from the Hong Kong office of a multinational company transferred money worth $25 million based on a video call of deepfake video of the chief financial officer and other company employees. In March 2025, a finance director of a multinational company approved the transfer of $499,000 based on a Zoom call featuring a deepfake video of the company’s CFO and others.
Non-financial fraud incident. In July 2024, cybersecurity firm KnowBe4 found out that their newly recruited software engineer was an agent from North Korea who was posing as someone else by using stolen identity credentials, a deepfake picture generated by artificial intelligence, and deepfake video recorded during four rounds of interviews.
Attempted fraud halted via verification process. Ferrari executives were sent a message seeking their help for acquiring another firm due to the time sensitivity of the issue, followed by a phone call in which the voice of the company’s CEO was being mimicked. The attempt failed because an executive posed a verification question that only the true CEO could answer.
How to Spot a Deepfake
Deepfake content shows detectable inconsistencies in visual, audio, and behavioral signals.
Visual Signs
The reviewer must look out for:
- Abnormal eye blinking. Deepfake generation technologies usually create abnormally fast or slow blink rates compared to the natural human blinking cycle.
- Unnatural skin color or texture. Deepfake created skin normally fails to reproduce natural human skin with the presence of pores, acne, and shading.
- Mismatching lighting or shadows. The deepfake face might be inconsistent with lighting or shadow direction of the background video.
- Edges of the inserted face. The edges of the inserted face are often blurred or distorted against the background of hair or neck.
- Mismatched reflections. Reflections on eyeglasses or eyes might not match the environment of the person.
Audio Signs
The following audio discrepancies need to be considered by reviewers:
- A flat or inconsistent emotional tone. Voices that are cloned often have trouble with reflecting the right emotional tone in their statements.
- A wrong pacing or pause. The synthetic speech often includes some pauses that don’t fit the natural breathing process.
- An audio background that is inconsistent with the supposed setting of the recording.
Behavioral and Contextual Signs on Live Calls
These behaviors should be seen as red flags by reviewers when there is a live video or telephone call:
- A demand for an urgent transfer of money or for a change of credentials.
- A demand made at unusual hours or through an unexpected communication medium.
- Refusal to make a callback on an independently verified telephone line.
- A caller that refuses to answer a pre-arranged question.
How to Protect Yourself From Deepfakes
For Individuals and Families
- Choose a phrase for verification. Choose a specific word or phrase from your family members that must be said before you perform any task based on an emergency message.
- Confirm the message through another medium. Confirm the message via phone after receiving a suspicious video call or voice call message.
- Do not post many high-resolution photos or videos. The more public material available, the better the quality of a deepfake generated from the individual’s image.
- Report the non-consent immediately. All major sites have a way to report any non-consensual AI-generated images.
For Businesses and Employees
- Implement out-of-band validation for finance transactions. Any request to move money or to update financial information should be validated using another previously arranged channel of communication.
- Use MFA that is resistant to phishing attempts. Traditional phone or video authentication is not enough to protect against deepfake attacks.
- Conduct social engineering training specific to deepfakes. Add deepfake-related training modules to your security awareness training programs.
- Set up an escalation process. The procedure should allow employees to safely pause and validate any suspicious activity without repercussions.
Artificial Intelligence (AI) Course
Average time: 4 month(s)
Skills you’ll build: Python for AI, Machine Learning, Neural Networks, NLP Basics, AI Tools (ChatGPT, Copilot)
Are Deepfakes Illegal?
However, legality of deepfakes in the United States varies depending on how the technology is used for certain purposes. There is no blanket prohibition of the technology under any existing law at the federal level.
U.S. Federal Law
In May 2025, the Take It Down Act was enacted. The act punishes the distribution of non-consensual intimate images, including those generated using AI, and mandates removal of such images by specified platforms within 48 hours of reporting.
The NO FAKES Act introduced in September 2024 addresses the unauthorized creation of artificial voice or visual representation and allows suing the creators of unauthorized digital representations.
With the passing of the DEFIANCE Act, victims of nonconsensual deepfakes can hold perpetrators of deepfakes accountable through a lawsuit where the perpetrator is aware that there was no consent.
Apart from these special pieces of legislation, the general provisions of state law relating to fraud, wire fraud, defamation, and identity theft come into play.
State Law
Up to the end of 2025, Proofpoint has reported 47 states having enacted certain deepfake legislation. This type of legislation relates to the issues of election-related deepfakes, nonconsensual intimate images, and impersonation. The standards related to notification, removal, and liability vary by state.
International Law: The EU AI Act
The European Union’s AI Act requires disclosure when content qualifies as an AI-generated deepfake, placing a labeling obligation on both developers and deployers of qualifying systems.
What to Do If You’re a Victim of a Deepfake
For a person whose deepfake is discovered without their consent, the following are the actions to take in order:
- Collect evidence. This includes saving any screenshots and the original file or link prior to making a complaint, as there is a chance that the content will be taken down during the process.
- Complaint about the content on the hosting platform. Most major platforms have a category for AI-generated content or nonconsensual content.
- File a takedown request under the Take It Down Act, where applicable. The act stipulates that covered platforms are mandated to remove nonconsensual intimate imagery within a certain period upon receiving a complaint.
- Reach out to local law enforcement. Make a report in case of fraud, extortion, or credible threat made via the content.
- Consult an attorney. An attorney can advise on available civil claims under state deepfake or right-of-publicity laws.
Deepfake Detection Technology and Content Provenance
Deepfake detection tools use four signal types to detect deepfaked material. These include media signal, behavioral signal, context signal, and identity signal.
There are many companies that provide deepfake detection tools. Intel FakeCatcher uses the signal of physiological behavior, which means that it detects blood flow patterns visible in videos. Microsoft also offers a detection tool that calculates the probability of manipulation by assigning confidence scores. Sensity AI uses the detection system based on pattern matching from the database of deepfakes.
The Coalition for Content Provenance and Authenticity (C2PA) is an industry standard which involves attaching Content Credentials, which are verifiable metadata, to media at the time of capture or creation. The Content Credentials indicate whether AI has created or modified a content item, thus providing an independent verification process without relying on any visual or audio detection method. Google’s SynthID also provides a similar kind of service by embedding a digital watermark in AI-generated content.
Detection accuracy is dynamic. As deepfake generation techniques evolve, detection tools become better, implying that detection outcomes cannot be used as a sole verification method for important decisions.
| Detection Approach | What It Analyzes | Best Suited For |
|---|---|---|
| Media signal analysis | Pixel, audio waveform, and compression artifacts | Post-incident review of recorded content |
| Behavioral signal analysis | Request patterns, urgency, timing | Real-time fraud prevention during live calls |
| Content provenance (C2PA) | Cryptographic metadata attached at capture | Verifying content origin before it spreads |
| Identity signal analysis | Device fingerprint, session history, account activity | Account takeover and KYC bypass detection |
Emerging Trends in Deepfake Threats
New deepfake attack vectors have emerged as follows:
- Synthetic video calls in real-time. Modern live face-swap software is implemented during an active video session and thus skips post-production stages which previous attack detection mechanisms used to depend on.
- Multilingual voice synthesis. Modern voice generation systems produce multilingual clones with corresponding intonations, thus letting one voice generation model be employed for victim targeting in different geographic locations.
- Deepfake-as-a-service. Commercialized services let attackers with little to no technical skills create cloned voices, videos and fake profiles whenever needed.
- AI-driven impersonation by autonomous agents. Autonomous agents have been developed to conduct multi-stage impersonation campaigns independently without a person’s continuous input.
- Impersonation via multiple channels. It has become common practice for attackers to combine fake voice calls, AI-created emails and chat platform messages in one impersonation attack, thus requiring organizations to analyze signals across channels rather than in isolation from each other.
The History of Deepfake Technology
Deepfake technology originated from previous studies conducted by academics in the field of image processing and machine learning.
Academic researchers started investigating artificial intelligence technologies capable of manipulating images in the 1990s. Generative adversarial networks were invented by Ian Goodfellow in 2014 while he was working at the University of Montreal, laying down the groundwork for modern deepfake technologies. The term was used publicly for the first time in 2017 when an anonymous Reddit user posted face-swapped videos under the username “deepfakes.” There was an increased development of commercial and open-source deepfake tools starting from 2017. In 2025, deepfakes technology was capable of synthesizing fake images in real time, giving hackers the opportunity to create synthesized audio or video in the course of a phone conversation.
FAQs
Q1. Is it illegal to make a deepfake of yourself?
Ans. No law makes it illegal to create a deepfake of yourself for personal or private use.
Q2. How much footage does someone need to deepfake a person?
Ans. A voice clone takes only 3 seconds of the source audio, whereas a video deepfake takes several minutes of footage from different angles of the target individual.
Q3. What is the difference between a deepfake and a regular AI-generated image?
Ans. Deepfake shows a real-life identifiable person in an imaginary scenario, whereas regular images, for example, from Midjourney, may not depict any real-life person.
Q4. Can deepfakes bypass biometric security systems?
Ans. Yes, face swap tools in real-time can beat liveness tests in video identity verification, and voice clones can fool voice authentication systems on phones not designed to recognize fake audio.
Q5. Are deepfakes illegal in the United States?
Ans. Although there is no federal law that bans deepfakes, the Take It Down Act, together with the existing laws on fraud, defamation, and identity theft, can be applied to certain malicious uses, and there are laws about deepfakes in 47 states as of late 2025.
Q6. What should you do if someone sends you a deepfake of yourself?
Ans. Preserve the content as evidence, report it to the hosting platform’s nonconsensual content process, and file a request under the Take It Down Act if the content is intimate imagery.