Skip to main content

Deepfake video call simulations

A deepfake video call simulation tests one thing that no email exercise can reach: whether an employee does what they are told by a face and a voice they recognise.

An operator on your team joins a real meeting wearing a real-time face and voice swap. They appear and sound like a colleague the target trusts, usually one with authority over them, and they make a request that should not survive contact with your controls: approve this payment, reset this password, grant this access, send me that file. What the target does next is the result.

What this costs you

A person, for the length of the call. This is the trade. An automated voice call runs itself and scales; a deepfake video call does not, because someone has to hold a conversation. In exchange you get the exercise that lands hardest in a debrief, because the target watched it happen to them.

Budget roughly: ten minutes to build the campaign, up to ten minutes waiting for the session, two or three minutes to set the voice and face, then the call itself.

One session at a time per workspace, shared with voice impersonation campaigns.

Choose the platform the target already trusts

The channel is not a detail. A finance controller who takes wire approvals over Zoom will find a Zoom call ordinary and a Signal call alarming, and the reverse is true of an executive who does deals over WhatsApp. Run the exercise where the real attack would happen.

PlatformYou needWhere it fits
ZoomThe meeting's ID and passcodeScheduled internal meetings, the default for most finance and operations teams
Google MeetThe meeting code, and someone to admit a guestWorkspace organisations, where a calendar invite is the normal way in
SlackAn account in the target's workspaceThe unscheduled call, the one that arrives without an invite
WhatsAppAn account, and a phone in the roomExecutives and field staff who do business on a personal number
TelegramAn account, and a phone in the roomOrganisations where Telegram is a real work channel, and crypto adjacent targets
SignalAn account, and a phone in the roomSecurity conscious targets, where the channel itself signals legitimacy

Microsoft Teams, Webex and GoTo Meetings are supported too and behave like Zoom. They do not yet have a page here; the reference page covers all nine.

Start here

How a deepfake video call runs is the whole procedure, and it is the same on every platform: building the campaign, the wait, setting the voice and the face, the controls you have during the call, and recording what happened.

Read it once. Then read your channel's page for the part that differs, which is getting into the call and what goes wrong when you do.

Before you run one on real people

  • Get the exercise authorised in writing, by someone who can authorise it. This is a simulation of a serious crime against a named employee.
  • Know your disclosure obligations before you launch, not after. In several jurisdictions, telling the target they were talking to a synthetic face is a legal requirement rather than a courtesy. See AI Act compliance.
  • Plan the debrief with the same care as the pretext. The value of this exercise is almost entirely in what happens after the call.