Deepfake video call simulations
A deepfake video call simulation tests one thing that no email exercise can reach: whether an employee does what they are told by a face and a voice they recognise.
An operator on your team joins a real meeting wearing a real-time face and voice swap. They appear and sound like a colleague the target trusts, usually one with authority over them, and they make a request that should not survive contact with your controls: approve this payment, reset this password, grant this access, send me that file. What the target does next is the result.
What this costs you
A person, for the length of the call. This is the trade. An automated voice call runs itself and scales; a deepfake video call does not, because someone has to hold a conversation. In exchange you get the exercise that lands hardest in a debrief, because the target watched it happen to them.
Budget roughly: ten minutes to build the campaign, up to ten minutes waiting for the session, two or three minutes to set the voice and face, then the call itself.
One session at a time per workspace, shared with voice impersonation campaigns.
Choose the platform the target already trusts
The channel is not a detail. A finance controller who takes wire approvals over Zoom will find a Zoom call ordinary and a Signal call alarming, and the reverse is true of an executive who does deals over WhatsApp. Run the exercise where the real attack would happen.
| Platform | You need | Where it fits |
|---|---|---|
| Zoom | The meeting's ID and passcode | Scheduled internal meetings, the default for most finance and operations teams |
| Google Meet | The meeting code, and someone to admit a guest | Workspace organisations, where a calendar invite is the normal way in |
| Slack | An account in the target's workspace | The unscheduled call, the one that arrives without an invite |
| An account, and a phone in the room | Executives and field staff who do business on a personal number | |
| Telegram | An account, and a phone in the room | Organisations where Telegram is a real work channel, and crypto adjacent targets |
| Signal | An account, and a phone in the room | Security conscious targets, where the channel itself signals legitimacy |
Microsoft Teams, Webex and GoTo Meetings are supported too and behave like Zoom. They do not yet have a page here; the reference page covers all nine.
Start here
How a deepfake video call runs is the whole procedure, and it is the same on every platform: building the campaign, the wait, setting the voice and the face, the controls you have during the call, and recording what happened.
Read it once. Then read your channel's page for the part that differs, which is getting into the call and what goes wrong when you do.
Before you run one on real people
- Get the exercise authorised in writing, by someone who can authorise it. This is a simulation of a serious crime against a named employee.
- Know your disclosure obligations before you launch, not after. In several jurisdictions, telling the target they were talking to a synthetic face is a legal requirement rather than a courtesy. See AI Act compliance.
- Plan the debrief with the same care as the pretext. The value of this exercise is almost entirely in what happens after the call.