verifylabs logo
About Us FAQs Pricing Blog Sign up or Login Detected a Deepfake?
About Us Use cases by sector Pricing Blog
Sign up or Login Detected a Deepfake?

There was a time, not so long ago, when a familiar voice on the phone settled the matter. You knew your finance director’s laugh, your mortgage broker’s slightly weary “right then”, the particular way your chief executive clears her throat before saying something expensive. Recognition was a kind of security system, which served us well since the invention of the telephone.

That system has quietly been switched off. Most businesses simply haven’t noticed yet.

The voice you trust, annexed by someone else

Consider a couple in West Michigan. This month, Brian and Wendy VanDoeselaar lost their entire closing fund to scammers who combined AI voice cloning, spoofed email and spoofed caller ID to impersonate the mortgage professional they had been working with for weeks. The sum was $66,000. What undid them wasn’t carelessness. He heard a familiar voice, on a number that matched his lender’s, confirming wiring instructions that arrived in an email that looked right; three layers of fakery reinforced one another before any single one raised a flag. 

If you’re tempted to think this only happens to ordinary people buying ordinary houses, look at who was targeted in August. A coordinated voice-phishing campaign went after several of Wall Street’s largest asset managers, using cloned voices to mimic the tone and phrasing of executives and colleagues in order to coax staff into surrendering credentials or granting system access. Two Sigma, Citadel, Point72 and Millennium Management all faced attempted breaches; Two Sigma confirmed it stopped the attack with no data compromised. These are firms with security budgets most of us can only dream of. The criminals clearly thought the clones were good enough to be worth the effort. 

Where the money goes afterwards

Fraud is only half the story. Stolen money has to be washed, and deepfakes are increasingly how criminals get through the front door of the financial system in the first place. In February, a Ukrainian national pleaded guilty in the US to running OnlyFake, a site that generated and sold digital fake ID documents; prosecutors said it produced more than 10,000 fraudulent IDs, helping customers slip past Know Your Customer checks at banks and crypto exchanges. In the Netherlands, a case running through the Amsterdam courts involved a man who opened 47 fraudulent bank accounts by defeating a bank’s selfie-versus-ID onboarding check with deepfake and face-swap imagery. 

The scale of what sits behind all this is sobering. INTERPOL’s Operation First Light, which ran from January to April this year, targeted social engineering scams and the money laundering around them, leading to 5,811 arrests and the interception of $293 million across 97 countries. In Thailand, investigators found the digital wallet of one suspect, aged just 20, had processed more than $122.5 million in ten months. In Eswatini, police uncovered a gang that had built a realistic replica of a Brazilian police station, complete with fake uniforms and signage, then posed as Brazil’s Federal Police on video calls to talk victims into moving money for “safekeeping”. 

The carpentry involved sounds almost whimsical, until you realise that the most convincing deepfake scams merge real and synthetic content. AI bad actors are increasingly blending real and fake to make their “kills”.

Why “we’ll train our people to spot it” isn’t enough

The instinct of most organisations is to run an awareness session and hope for the best. The evidence is not kind to that plan. Veriff’s 2026 research, based on a survey of 3,000 people across the US, UK and Brazil, found that people are barely better than a coin toss at telling a real video or image from a fabricated one, with video the hardest format of all. In Britain specifically, 22% of people say they never verify suspicious content, the highest rate of any country surveyed. 

Meanwhile the machinery of fraud is being industrialised. Entrust’s 2026 Identity Fraud Report, drawn from more than a billion identity-verification events, found that deepfakes now account for one in five biometric fraud attempts. Here at home, UK Finance reported payment fraud losses of £1.28 billion in 2025, with authorised push payment fraud up 19% to £576.4 million, and said organised criminal groups are increasingly using deepfakes, cloned voices and synthetic identities to impersonate trusted people and bypass identity checks. 

The law has noticed, even if the boardroom hasn’t

This is where “optional extra” finally stops being a defensible position. In the UK, the failure to prevent fraud offence came into force on 1 September 2025 for large organisations, and a company can now be criminally liable for fraud committed for its benefit, including deepfake-enabled fraud, unless it can show reasonable prevention procedures were in place. Across the Channel, Article 50 of the EU AI Act has applied since 2 August 2026, and UK businesses serving EU customers fall within its scope. 

Put plainly: when a deepfake gets through, the question will no longer be “how were you to know?” It will be “what did you have in place?”

What changes when you can check

None of this means abandoning a good process. Call-backs on known numbers, second sign-offs and a healthy scepticism about urgency all still matter. But process relies on someone deciding to be suspicious, and the whole art of a good deepfake is that it gives them no reason to be.

That is the gap a detector fills. VerifyLabs.AI was independently benchmarked in 2026 at 98% accuracy, runs without any API integration, and works across iOS, Android, desktop and Chrome, so the check can happen on the call, in the inbox or at onboarding, wherever the doubt arises. It won’t replace judgement. It gives judgement something solid to stand on again.

The familiar voice used to be the proof. Now it’s the question.

Sources

  1. Resemble AI, “The Deepfake Watchlist: Week of September 11–17, 2026” (17 Sep 2026), summarising CNN, “How two homebuyers in Michigan lost $66,000 in a suspected voice-cloning scam” (15 Sep 2026). resemble.ai/resources/the-deepfake-watchlist-week-of-september-11-17-2026
  2. Resemble AI, “The Deepfake Watchlist: Week of July 31 – August 6, 2026” (7 Aug 2026), summarising Investing.com/Bloomberg, “Wall Street hit by wave of AI-powered ‘vishing’ cyberattacks”. resemble.ai/resources/the-deepfake-watchlist-week-of-july-31—august-6-2026
  3. INTERPOL, “Over 5,800 arrests, USD 293 million intercepted in global fraud bust” (9 Jul 2026). interpol.int
  4. Adaptive Security, “11 Deepfake Attack Examples: Real-World AI Fraud Cases” (26 Jun 2026), citing a February 2026 US Department of Justice announcement. adaptivesecurity.com/blog/11-deepfake-attack-examples-2026
  5. Brightside AI, “Deepfake Fraud in 2026: The $3.7B Problem and How to Defend” (19 Jul 2026). brside.com/blog/deepfake-fraud-losses-2026
  6. Veriff, “What deepfake fraud actually costs businesses in 2025–2026” (17 Jul 2026). veriff.com/fraud/deepfake-fraud-cost-2026
  7. Veriff, “Deepfakes Report 2026 UK” (May 2026). veriff.com/resources/ebooks/deepfakes-report-2026-uk
  8. DeepStrike, “Deepfake Statistics 2026” (Aug 2026), citing the Entrust 2026 Identity Fraud Report. deepstrike.io/blog/deepfake-statistics-2025
  9. IBTimes UK, “UK Fraud Losses Hit £1.28B as Banks Warn AI Makes Scams Harder to Spot” (12 Jul 2026), reporting UK Finance’s Fraud Report 2026. ibtimes.co.uk/ai-driven-fraud-costs-uk-1-28-billion-1808188
  10. Internet Safety Statistics, “Deepfake Technology Threats: A 2026 UK Business Guide” (Sep 2026). internetsafetystatistics.com/deepfake-technology-threats

 

verifylabs logo
© VerifyLabs.AI 2026. All rights reserved.