Face-swapping apps seem harmless. Upload a photo, see yourself as a different age or character, share it with friends. But when your employees use these apps, they’re handing over something that can’t be changed: their face. And that creates real problems for your business.
In February 2024, a finance worker in Hong Kong transferred $25 million after a video call with what appeared to be the CFO and other colleagues. Every person on the call was fake. The attack worked because the employee saw and heard people who looked and sounded exactly like senior leadership.
This isn’t a one-time incident. Here’s what you need to know.
The Numbers Tell the Story
- 3,000% increase in deepfake fraud attempts in 2024
- $500,000 average loss per deepfake fraud incident
- 1,740% rise in deepfake fraud in North America (2022-2023)
- 24.5% human accuracy in detecting high-quality deepfakes
- 400 companies targeted per day with CEO impersonation attacks
- 0.1% of people can correctly identify all fake content when shown both real and deepfake media
Why Face Data Is Different
Your face isn’t like a password. You can’t reset it if it’s compromised. Once someone has photos of your face, they have permanent access to your biometric identity.
When employees upload photos to these apps:
- The data gets stored permanently. Even if they delete the app, the company still has their facial data. Many apps retain the right to use uploaded photos to train their models.
- It can be sold or acquired. When small AI companies get bought or go bankrupt, user data often becomes part of the deal.
- Attackers can access it. Data breaches at these companies happen regularly and often go unreported.
- The AI learns from it. Once facial data trains a model, it’s embedded in that system forever.
How This Threatens Your Business
1. Executive Impersonation
Voice cloning now requires only 20-30 seconds of audio. Attackers pull this from public interviews, earnings calls, or social media videos. Combined with face-swapping technology, they create video calls that pass visual inspection.
In 2019, thieves used a deepfaked voice of a UK energy firm CEO to transfer €220,000. By 2024, the attacks had become more sophisticated. The Hong Kong case involved multiple people on a video conference call, all deepfaked.
2. Identity Verification Bypass
Deepfakes account for 40% of all biometric fraud attempts. In 2025, one in 20 identity verification failures linked to deepfake usage. Attackers use this technology to open fraudulent accounts, bypass security checks, and gain access to systems.
3. Employee Vulnerability
According to recent surveys, one in four business leaders has little familiarity with deepfake technology. Over half report their employees have received no training on identifying these attacks. Meanwhile, 32% of leaders have no confidence their employees could recognize deepfake fraud.
4. Financial Impact
Businesses faced average losses of nearly $500,000 from deepfake-related fraud in 2024. Large enterprises saw losses up to $680,000. Financial losses from deepfake fraud exceeded $200 million in Q1 2025 alone.
How to Protect Your Business
Implement Verification Procedures
Create mandatory out-of-band verification for financial transactions and sensitive requests. This means using a different communication channel than the one that initiated the request.
Example: If a request comes via email or video call, verify through a phone call to a known number. If it comes via phone, confirm through email or in-person.
Set Clear Financial Controls
- No wire transfers above a certain threshold without in-person or verified video approval
- Mandatory waiting periods for urgent requests, regardless of who makes them
- Dual approval for account changes, payroll modifications, or vendor updates
- Pre-established security questions that only real executives would know
Train Your Team on Real Threats
Traditional awareness training doesn’t work. Employees need exposure to actual deepfake examples and practice with realistic scenarios.
Research shows that after about 12 simulation rounds, employee detection rates increase from 34% to 74%. Regular training further improves these rates.
Control Digital Footprints
- Limit public-facing video and audio of executives
- Review what content appears on company websites, social media, and conference recordings
- Educate employees about the risks of uploading photos to AI apps
- Prohibit face-swapping applications on company devices
- Monitor for unauthorized use of executive images or voices online
Deploy Detection Technology (But Don’t Rely on It Alone)
Detection tools add a layer of defense but aren’t perfect. Some systems claim 90%+ accuracy in controlled settings, but performance drops when facing new or sophisticated deepfakes. Use detection as one component of a broader strategy.
Start This Week
- Review current financial authorization procedures
- Brief executive team on voice and face cloning capabilities
- Identify gaps where deepfake fraud could succeed
Start This Month
- Implement out-of-band verification for financial transactions
- Conduct initial awareness training for finance, HR, and IT teams
- Audit public-facing content to understand your exposure
What Employees Should Know
Share these guidelines with your team:
- Don’t upload personal photos to AI face-swapping apps. Once uploaded, you lose control over that data.
- Review privacy settings on social media. Limit who can see and download your photos.
- Remove location data from photos before posting online.
- Be cautious about platforms offering free AI services. Free often means you’re paying with your data.
- Ask family members and colleagues to respect your privacy by not posting identifiable photos without permission.
The Bottom Line
Deepfake attacks increased 3,000% in 2024. The average loss per incident is $500,000. Human detection rates remain at 24.5% for high-quality fakes.
The organizations that will be protected are those with strong verification processes, not just detection technology. Process discipline is what matters.
This isn’t a problem you solve once. Deepfake capabilities improve continuously. Your defenses must improve with them.
Need Help Protecting Your Organization?
Holocron Cyber helps businesses build defenses against AI-powered threats. We provide security assessments, verification procedures, employee training with realistic simulations, and incident response planning.
We work with small and medium-sized businesses to build practical, cost-effective defenses. Our approach focuses on what works: verified processes, trained teams, and layered security.
Contact us to discuss how we can help protect your organization.
