
When a voice, video or image is used to demand money, access or sensitive information, verify the request through an independent channel before acting. You do not need to prove that a recording is a deepfake to refuse an unsafe request.
Deepfake scams use generated or manipulated media to support impersonation. The most useful response combines source checking, normal approval procedures and careful handling of payments or credentials. This guide explains those steps and the limits of visual clues and Content Credentials.
How an impersonation request reaches you
A synthetic voice can make an emergency story sound familiar. The FTC describes family-emergency scams in which a caller imitates a loved one and presses for money. It recommends contacting the person using a number already known to you instead of trusting the voice alone. FTC guidance on voice-cloned emergency scams.
Other requests can claim to come from a colleague, official, investment promoter or online acquaintance. Whether the media is synthetic or simply misleading, treat an unexpected demand for a transfer, sign-in code or confidential file as a request that needs verification.
Check the request, not just the recording
| Scenario | Useful check | Unsafe shortcut |
|---|---|---|
| Family emergency | Contact the person or another trusted contact using established details | Calling only the number supplied by the caller |
| Workplace payment | Follow the normal approval and recipient-verification process | Bypassing approvals because a video looks convincing |
| Investment endorsement | Check the offer and operator independently | Treating a familiar face as proof of a legitimate investment |
| Account-security warning | Open the service independently and inspect its alerts | Sharing a verification code with the person making the claim |
Urgency, secrecy, a new payment destination or pressure to skip an established process should slow your decision. These clues do not prove a deepfake; they identify a request that has not earned trust. A normal-sounding call can still contain a fraudulent request.
Use an independent verification process
- Pause: do not transfer money, share credentials or open an unexpected attachment while the caller pressures you.
- Choose the destination yourself: use a contact detail or service you trusted before the message arrived.
- Verify the actual instruction: ask whether the person made the request and confirm the recipient, amount or document involved.
- Keep normal approvals: a claimed emergency does not authorize bypassing a workplace payment or access-control process.
- Escalate uncertainty: if you cannot verify, involve an appropriate trusted person or your organization’s established support team.
A family verification phrase can be an additional check, but should not be the only one. Keep it private, and do not publish examples containing your real answers. A voice, face or secret that has already been exposed cannot serve as reliable proof on its own.
What Content Credentials can tell you
C2PA Content Credentials record provenance using cryptographically signed, tamper-evident structures associated with an asset. Provenance can supply information about the file’s recorded origin and changes. The C2PA explainer explicitly separates validation of that information from judging whether the depicted content is true. C2PA architecture and limits.
A credential is therefore one piece of context, not authorization to pay someone or a guarantee that an event happened. Inspect what it actually asserts and which signer is trusted. The C2PA FAQ explains the standard and trust mechanisms in more detail.
Do not turn an absent credential into a verdict that a file is fake. Nor should a visible icon replace verification of the person and transaction. Media provenance and identity or payment approval answer different questions.
How to use detection clues cautiously
Unusual lip movement, audio pacing or a strange background may justify closer inspection. They are not a dependable pass-or-fail test: ordinary compression, connection problems and editing can also make media look unusual.
If you use a detection tool, read its intended use and limitations. Record the tool, version, input and result. Treat the output as an assessment requiring context rather than a final accusation. Avoid uploading private voice recordings, identity documents or intimate material to an unfamiliar service.
Detection accuracy must be assessed for a particular tool, input type and evaluation method. Results from one dataset should not be treated as a guarantee about a recording received in a real conversation.
If money or account access was already shared
Contact the affected bank, payment service or account provider promptly through its established channel. Describe the transaction or access involved and ask what protection or recovery options are available. Outcomes depend on the provider and circumstances; a request to recall a payment is not a promise of recovery.
If a password or session was exposed, follow the service’s account-recovery guidance and review access and recovery settings. Our OTP scam guide covers verification-code risks. For deposit-based messaging jobs, see our task-scam guide.
Preserve the original message, relevant timestamps, account identifiers, receipts and incident references privately. Report through the platform and appropriate authorities in your location. Reporting routes and legal obligations vary; this guide does not present one country’s helpline or deadline as a universal procedure.
A verification worksheet for families and teams
- Who is authorized to request money, access or confidential information?
- Which established contact route will you use to verify?
- Who gives a second approval when the request is unusual?
- What recipient details must be checked independently?
- Where will incident evidence be stored privately?
- Who is the verified support contact if information has already been shared?
Glossary
- Deepfake: synthetic or manipulated media used to represent a person or event.
- Provenance: information about content’s recorded origin and history.
- Independent channel: a contact route chosen separately from the suspicious request.
- Impersonation: falsely presenting oneself as another person or organization.
Sources and editorial review
Updated 1 October 2026. This guide draws on the linked FTC warning and C2PA documentation. The verification worksheet is practical editorial guidance; no forensic examination or detection-tool test is claimed. Send corrections through our contact page.
Written and prepared by Kshitij Gupta.



