AI Face Cloning: Why Video Calls No Longer Prove Identity

Profile of persons face transitions into virtual deep fake counterpart.

Image: Lazy_Bear/Adobe Stock

Written By
eWEEK Staff
eWEEK Staff
Aug 5, 2026
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In January 2024, a Hong Kong finance employee authorized transfers totaling HK$200 million, about US$25 million, after joining what appeared to be a video conference with senior executives.

Hong Kong police later said the conference was prerecorded and assembled from publicly available video clips and voices.

The case involved a financial transfer, but the risk reaches far beyond finance. Organizations use video calls to interview candidates, verify customers, approve account changes, discuss confidential work, and respond to requests from executives and vendors.

As face and voice cloning improve, seeing a familiar person on screen is no longer enough to confirm that the person is genuine, authorized, or participating live.

Deepfakes can enter routine business interactions

Hong Kong authorities said the employee first received a phishing email from someone posing as the company’s chief financial officer. The employee then joined a prerecorded meeting that appeared to include company executives and continued receiving payment instructions through instant messaging.

Deepfake technology can manipulate both audio and video, allowing impersonation attempts to appear in calls, recordings, remote meetings, and other digital interactions. Attackers can also use voice-cloning scams to imitate executives and relatives, making an urgent request sound as though it came from someone the recipient already trusts.

Hiring presents another opening. Fake job applicants using synthetic faces, voices, and credentials may attempt to pass remote interviews and gain access to corporate systems, customer information, financial data, or proprietary material.

The same problem affects customer support, account recovery, vendor relationships, and confidential meetings. A cloned face or voice can create the appearance of familiarity, but it does not establish authority. Someone may look and sound like a customer, employee, executive, or business partner without controlling the identity being presented.

Content-provenance tools address a related but different issue. C2PA Content Credentials can record information about a file’s source and editing history. That information can help people examine a recording or image, but it does not authenticate the person making a request during a live call.

Advertisement

Video calls need a second layer of identity verification

Organizations should separate communication from authorization. A video call can explain a request, but payments, account changes, access approvals, and other sensitive actions should require confirmation through another trusted channel.

Finance teams should require a callback to a number already stored in an internal directory before approving a transfer or changing vendor banking details. A second employee should confirm high-value or unusual transactions. Contact information supplied during the call, email, or message should not be used for verification.

Help desks should require an established second factor, such as a hardware token, internal approval workflow, or previously configured authentication method, before completing password resets, account recovery, or privileged-access changes.

HR teams should apply similar controls during remote hiring and onboarding. Identity documents, employment records, and system-access requests should be verified independently rather than accepted solely because a candidate appeared convincingly on camera.

Customer-facing teams may also need additional checks before changing contact details, payment methods, or account permissions. The verification method should rely on information or systems the caller cannot control during the conversation.

The FBI recommends secondary channels or two-factor authentication for requests involving account changes. If a fraudulent transfer occurs, the organization should contact its financial institution immediately, request a recall, and report the incident to the Internet Crime Complaint Center.

Organizations should review every process in which a video or voice call can establish identity or authorize an action. A familiar face may support a conversation, but it should no longer serve as proof on its own.

Also read: Google’s Android fake call detection uses device verification to flag suspected AI voice scams.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.