Live video is evidence of a conversation, not proof of identity

The FBI’s 20 July 2026 IC3 warning says scammers are using AI-generated video for real-time chats with alleged company executives, law-enforcement officers and other authority figures. The same alert describes fear, urgency, caller-ID spoofing and private video as tools used to make an approach feel legitimate. The operational lesson is simple: seeing and hearing a known person cannot be the only control for releasing money or changing payment details.

This is not a reason to assume every unusual call is synthetic. Accounts can be compromised, an authentic executive can be pressured, and an ordinary business-email-compromise attack may contain no generated media at all. Finance teams should verify the identity, channel and transaction separately rather than trying to diagnose the production technique during a pressured call.

The FBI’s 2025 Internet Crime Report, released in April 2026, recorded 22,364 complaints involving artificial intelligence and nearly $893 million in reported losses. Those figures cover multiple AI-enabled tactics, not only video-call impersonation, but they show why a written control is more useful than relying on an employee to notice visual glitches.

Use a ten-minute stop-and-verify protocol

The first objective is to interrupt the pressure without accusing the caller. A finance employee can say that company policy requires an independent check for every urgent payment, beneficiary change or release of credentials. The rule should apply to everyone, including the chief executive, so following it does not feel like a personal judgment.

Leave the incoming channel. Do not call a number supplied in the message, meeting invitation or chat. Use a phone number already held in the company directory, an authenticated internal account or a known assistant. If the request involves a supplier, call a previously verified contact from the vendor master record, not the new details on the invoice.

Require a second authorized person to confirm both the requester and the transaction in a separate channel. For high-risk payments, the second approver should see the beneficiary, amount, purpose, supporting contract or invoice and any recent change. A detector may be used while this happens, but the payment remains paused until the business verification is complete.

  • Pause the transfer, credential release or bank-detail change
  • Record the time, channel, claimed requester and requested action
  • End or leave the incoming conversation
  • Contact the person through a pre-existing trusted route
  • Verify the beneficiary and business purpose independently
  • Obtain the required second approval in a different channel
  • Escalate unresolved identity or media questions to security
  • Document the final decision before releasing or rejecting payment

Verify the transaction as carefully as the person

A perfect callback does not make an unusual transaction safe. The requester’s real account may be compromised, or a fraudster may have changed supplier data earlier in the process. Check purchase orders, contracts, delivery evidence, invoice history and the approved vendor record. Treat a first payment, new country, new currency, new wallet, split transfer or changed beneficiary as a separate risk event.

Bank-detail changes should have their own control: confirmation with a known supplier contact, dual approval, a recorded effective date and a cooling-off period where business needs allow. Prevent a user who edits beneficiary data from being the only person who releases the next payment. Alert on attempts to bypass the usual enterprise resource planning or treasury workflow.

Code words can help with an unexpected family or executive impersonation, and the FBI recommends pre-agreed secret phrases in its public guidance. In a company, however, a phrase should supplement - not replace - a trusted callback and transaction review. It can be overheard, phished or exposed in a compromised message history.

Watch the request pattern, not only the face

Visual artifacts such as inconsistent lighting, lip-sync errors or unnatural movement can justify a closer look, but high-quality synthetic media may not display an obvious flaw. Compression, poor bandwidth and accessibility tools can also create benign anomalies. Behavioural and transaction context is often the more stable warning signal.

Escalate when a senior person appears through an unfamiliar account, moves the discussion to a private or encrypted channel, demands secrecy, invokes an emergency, discourages a callback or asks staff to ignore ordinary approvals. A last-minute beneficiary change, cryptocurrency request or insistence that a transfer be split can increase concern even if the call looks ordinary.

Do not turn these indicators into an automatic allegation. Record them as reasons to pause and verify. The aim is to make the safe path faster and routine, not to teach employees that every delayed video frame is a crime.

  • Unfamiliar meeting account, number, domain or messaging profile
  • Urgency, fear, secrecy or claimed legal consequences
  • Request to bypass dual approval, procurement or treasury controls
  • New beneficiary, wallet, country, currency or payment method
  • Refusal to accept a callback through the company directory
  • Pressure to keep the conversation away from colleagues or security

Use detection as triage, not payment authorisation

A detector can add useful information when the team has a recording, voice note, image or exported video. It may identify provenance data, file metadata, media anomalies or model signals that support escalation. It cannot confirm that the apparent executive controls the calling account, that the invoice is genuine or that the bank details belong to the intended supplier.

Analyse a working copy and preserve the received file or message in its original form. Record the service and model version, analysis time, score, threshold and limitations. If only a screen recording is available, label it as a derived capture; conferencing software, screen capture and re-encoding may have removed metadata and changed the signals a model sees.

Do not release a payment because one tool returned ‘likely authentic’, and do not accuse an employee or supplier solely because a detector returned ‘likely synthetic’. Route uncertain or high-impact cases to a trained reviewer and keep the independent identity and transaction checks in place.

If money moved, switch immediately to incident response

Contact the sending bank or payment provider at once through its official fraud channel and ask whether the transaction can be recalled, frozen or traced. Time matters, so this step should not wait for a completed media analysis. Preserve the payment confirmation, beneficiary information, invoices, meeting invite, chat history, email headers, phone numbers, account handles and the original media available to the team.

Notify the organization’s security, legal, fraud and leadership contacts according to the incident plan. Secure affected accounts, revoke exposed sessions or credentials and look for earlier changes to mail forwarding, vendor records or approval rules. Avoid deleting the suspicious account or conversation before relevant records have been preserved.

The FBI asks US victims to report through IC3 and include contact methods, transaction details and a description of the interaction. Other jurisdictions have their own police, cybercrime and financial-intelligence reporting routes. Regulatory or suspicious-activity reporting obligations depend on the organization and jurisdiction, so involve qualified compliance or legal staff rather than relying on a general web guide.

Controls to put in place before the next request

Build the protocol into treasury and accounts-payable policy, then rehearse it. Give staff a short phrase they can use to pause a senior caller, and make leaders publicly support the rule. Test the trusted directory, after-hours escalation and supplier callback path so that verification does not fail when the request arrives outside normal hours.

Run exercises that mix deepfake, account-compromise and ordinary-error scenarios. The correct response should not depend on guessing which technique is present. Measure whether staff pause, use the approved callback, inspect the transaction, preserve evidence and report quickly - not whether they can identify a synthetic face by sight.

Review exceptions after each incident or exercise. If legitimate teams routinely bypass the process because it is too slow, attackers will use the same gap. The control works when independent verification is the easiest recognized path for both the employee and the real executive.

  • Trusted executive, security and supplier contact directory
  • Dual approval for high-risk payments and beneficiary changes
  • Separation between vendor-data editing and payment release
  • Clear limits for cryptocurrency and unusual payment methods
  • Documented after-hours escalation and payment-recall contacts
  • Evidence preservation and detector-review procedure
  • Regular exercises with leadership participation
Automated results require source and context review.

Continue with independent verification.

Build a team verification workflow
Sources

Primary reading

We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 23 August 2026.