Skip to content
isthisaigenerated.appsignals behind the content
Image detectorText detectorDocument detectorCheckersAppsHow it works ▾TeamsFor developersDocsPricingAccuracyTrustBlogContactNLSign in

Impersonation fraud

How to spot a deepfake on a video call: why a face on screen is no longer proof

A video call used to be the strongest check available at a distance: you see the person, so you know who you are talking to. That assumption no longer holds. In Hong Kong a finance worker paid out about 25 million dollars after a multi-person video conference with what he believed were his chief financial officer and colleagues. Hong Kong police said everyone he saw on screen was a deepfake recreation, and his doubts only surfaced when he checked with the company's head office (CNN, February 2024).

The pattern is broader than one case. The FBI warns that scammers use AI-generated videos in which FBI personnel promote a spoofed complaint website to revictimise earlier fraud victims, and advises extra caution with online content that elicits strong emotion (FBI IC3, July 2026). In Indonesia the communication ministry links a 550 percent rise in deepfake content over five years to digital fraud, and describes why detection is getting harder: face, expression and voice are imitated with a high degree of similarity (Komdigi, September 2025; Telkom, July 2026).

That is what this guide is built on: the call is not the verification, and the check moves to a channel the attacker does not control.

Direct answer: five checks before you trust someone on screen

  1. End the call and call back on a number you already had. The safest response to a suspicious call is to end it and verify the request independently through a trusted contact (Kaspersky). Use the number in your own contacts, not the number or account you were given during the conversation. In the Hong Kong case that second channel is what broke the scam open: head office knew nothing about the transaction.
  2. Treat urgency and secrecy as the mechanism, not as a detail. Deepfake fraud deliberately uses an emotional or urgent situation so that you do not take the time to verify (Telkom). The FBI says the same: be wary of online content that elicits strong emotion such as anger, fear or disbelief (FBI IC3). A request that can only be done now and must stay secret is a reason to involve someone else, not to hurry.
  3. Read the payment route, not the face. If the conversation turns into a transfer to a new or foreign account number, crypto, gift cards or a payment link to a private individual, the destination is the decisive signal — however convincing the video was. A genuinely urgent situation also allows a payment that can be checked and recalled.
  4. Agree a code word or fixed question, and use it consistently. A shared word or question only works if it cannot be found in the conversation itself and is not posted anywhere online. Exchange it at a moment that has nothing to do with money, and treat the answer as one signal: a code word that turns out to be known is not permission to pay.
  5. Get a second person to look before anything moves. Deepfake fraud counts on speed and on the fear of seeming paranoid. Having someone else look at the same request — a family member, a colleague, or your bank — usually breaks that pattern immediately. For a business instruction, confirmation belongs with a second person inside the organisation; the FBI advises using the organisation's official channel rather than the contacts given in the call (FBI IC3).

Why a video call no longer works as a check

The technique is no longer visible in the conversation itself: face, expression and voice are imitated with high similarity, and the output keeps getting harder to tell apart from the real thing (Telkom). What you are watching is a production: existing footage combined with a model that turns it into a talking head. That also means you will not win by looking harder. Someone who watches only for lip-sync, edges or strange hands loses to the next generation of models — and spends the time they should have spent on one phone call to a number they already had.

One thing to be clear about: interactivity is not proof either. With cloned voices, researchers and vendors describe callers who respond live and follow the tone of the conversation (Kaspersky). A conversation that feels normal is exactly what this kind of fraud is built to produce.

What a detector does and does not see

A live video call cannot be uploaded, and it does not need to be: the decision does not depend on a score. The traces around it can be checked. If you receive a clip, a screen recording or a screenshot, you can run the image through the image detector and the accompanying text through the text detector. That is triage: it helps you decide which material to verify first. It says nothing about the sender. A deepfake is also an edit of existing footage, so individual frames need not look suspicious — and our checkers assess sampled frames, not continuous live analysis. A high score does not prove fraud and a low score does not prove authenticity.

What a video call cannot tell you

  • whether the person really is who they claim to be, even when face, voice and surroundings match;
  • whether the account or number belongs to that person — a hijacked account looks exactly the same;
  • whether the crisis, instruction or problem actually exists; only the person themselves, or someone who can reach them, knows that;
  • whether it is fraud; only a bank or an investigating authority can establish that.

If you already paid or shared information

  • Contact your bank the same day and ask about a block or a recall; speed determines the outcome.
  • Keep everything: the request, the names and numbers used, the recording or screenshots, the payment details and the timestamp.
  • Report it to your national fraud reporting body and, where there is loss, file a police report. For a business payment, alert your organisation's security or fraud function immediately.
  • Shared login details? Change them right away and check whether they have been used elsewhere.
  • Warn the person whose face or voice was used: they can report it themselves and warn others.

More checks are in the guides on an AI voice clone scam, deepfake ads with celebrities and a fake bank call. To check a file or a message on its own, use the free checker.

Frequently asked questions

Does a video call prove I am really talking to the right person?

No. Face and voice can be imitated in real time, and in the Hong Kong case everyone who appeared on screen was a deepfake. A call can confirm a suspicion you already had, but it cannot establish identity. Verify through a channel you already had.

Can I run a recording of the call through a detector?

A still image or screenshot can go through the image detector as triage. A live conversation cannot be uploaded, and sampled frames are not continuous deepfake analysis. The result says nothing about the identity of the speaker and is never proof of fraud.

The person answered my questions live. Does that make it real?

No. Cloned-voice callers also respond live and adjust their tone. Interactivity is not evidence. Use a second channel — the number you already have, an agreed code word, or another person who knows the individual.

isthisaigenerated.appWhat’s real? What’s fake?

Signals support human judgement. They do not prove origin.

ProductCheck mediaCheckersBlogAppsHow it worksPricing
BuildFor developersDocsDetection APIAccuracyBenchmarks
CompanyTrustTeamsPilotContact
LegalPrivacyTermsProvenanceC2PA

© 2026 isthisaigenerated.app · Open beta · No detector output is standalone proof.