How to do it
Deepfakes strike in two ways: in one-to-one calls (someone pretends to be a person you know) and in widely shared videos (a well-known figure saying things they never said). The defenses apply to both.
- For suspicious video calls, ask for a real-time action. A live deepfake struggles with sudden movements: ask the person to turn their head to the side, pass a hand in front of their face, stand up. Live reconstructions often warp or glitch on unexpected movements.
- Verify through another channel. No time for visual tricks? Hang up and re-contact the person via a different, reliable medium: call them at the number you have, message them on the app you usually use, send them an agreed message. The fake lives on a single channel.
- For shared videos, hold back the urge to share. Before believing or forwarding a sensational video of a public figure, check whether reliable and independent sources are reporting it. A genuine statement by a well-known person leaves a trail across multiple outlets; a deepfake often lives only on accounts that re-share it.
- Mind the visual warning bells, but don't make them proof. Off lip-sync, eyes that blink strangely or never, edges of the face that flicker, light on the face inconsistent with the background, neck and hair that blur together. These are clues to make you suspicious, not to certify.
Check: you've handled the situation well if, before acting (sending money, giving data, sharing), you obtained confirmation independent of the video or call itself. If you can't verify, behave as if it were fake.
A concrete example
At a company, an employee in the administration department receives a video call: on the screen is the chief financial officer, right voice and right face, ordering a confidential and urgent transfer to a new supplier. Everything looks authentic. But the internal procedure requires confirmation through a second channel for every non-standard payment. The employee says he'll proceed and, once the call is over, writes to the officer on the internal company channel: "Do you confirm the transfer requested on the video call?". Reply: "What video call?". It was a deepfake built from the executive's public material. The second-channel rule blocked the fraud before it went through.
When it does NOT work (and how to fix it)
If the deepfake is too realistic for visual checks
The best reconstructions of 2026 pass almost any examination by eye. When you can't find the flaw in the image, stop looking for it: the defense isn't visual but procedural. Always verify through a separate channel and treat any sensitive request made over video as one to confirm elsewhere.
If it's a work video call asking for payments or data
Corporate fraud using deepfakes of executives is among the most costly. The remedy is a fixed rule, not instinct: no payment or confidential data is authorized on the basis of a call or email alone, even if the person "is visible." A confirmation through a second, pre-agreed channel is always needed. If your organization doesn't have one, propose it.
If you've already acted and then discover the fake
Move fast. For a payment, contact the bank immediately to try to block it. For data or credentials handed over, change the passwords and enable two-step verification where it wasn't on. Report what happened to the relevant parties (your company, the authorities) and keep every piece of evidence: recordings, times, contacts. Speed is what makes the difference.
A tip from someone who actually uses it
Set the second-channel rule before you need it, both at home and at work. The rule is simple to state: no decision that costs money or data is ever made on the basis of a single call or a single video. A confirmation over a different medium is always needed. A shared rule works better than any individual ability to "recognize the fake," because it doesn't depend on how good the attacker is.
Frequently asked questions
Can I trust it if I see the person on video and they move normally?
No, and it's the most dangerous false security. Seeing a face move is no longer a guarantee: live deepfakes exist. Trust isn't based on what you see on the screen, but on a confirmation obtained through a channel the attacker doesn't control.
Do deepfake detection tools solve the problem?
They help, but they're not a magic wand: they give a probability, they make mistakes, and they chase generators that keep improving. Use them as an additional technical opinion in important cases. The everyday defense remains verification through a second channel, which works today and will keep working tomorrow.