What a deepfake scam looks like inside a larger fraud campaign

bs-single-container

What a deepfake scam looks like inside a larger fraud campaign

When a deepfake report reaches your desk, everyone wants to talk about the video. Was it convincing, and can we buy something that catches the next one?

Those are the wrong first questions. The synthetic call is one step in an operation that started weeks earlier and will outlive your incident review by months. By the time anyone on your side is looking at a clip, the domain has been registered, the account built, the story told, and the money moved in pieces small enough to clear.

The clone did one job. It closed the distance between a request that felt odd and a request that felt approved.

A deepfake scam is a campaign, not a clip

Most coverage treats a deepfake as an object: a video, a voice note, a file you could hand to a lab. That framing is why teams reach for a detector first, and why it disappoints them.

In early 2024, an employee in a multinational’s Hong Kong office joined a video call with people he took to be his CFO and several colleagues, then sent HK$200 million, about $25.6 million, out of the company. Hong Kong police later told reporters that every other participant on that call had been generated. After the call came 15 transfers to five bank accounts over a week.

What the clone adds is confirmation, and only confirmation.

So the useful question isn’t whether the video was real. It’s how much of the operation is still running, which is why Bolster AI opens a deepfake report as a campaign investigation instead of a media question.

How the campaign actually runs

The steps on either side of the clone are ordinary fraud mechanics that worked for years before anyone could synthesize a face. The FBI’s Internet Crime Complaint Center put reported losses from business email compromise, fraud that talks a company into wiring money on false instructions, at $3.05 billion in 2025, up from $2.77 billion the year before. Almost none of that needed a synthetic anything.

The harvest

Every clone starts from a sample, and for an executive the sample is already published: earnings calls, keynotes, webinars, podcasts. A public company cannot unpublish its CFO, so this stage is not one you prevent.

The infrastructure

A cloned voice on its own is a prank call. What turns it into fraud is something the target has reason to trust: a domain a character or two off the real one, an account carrying the executive’s name and photo, or an ad that looks like a real outlet ran it. All of it gets built before the call. In the failed attempt against WPP, the operators created a WhatsApp account using a publicly available image of the chief executive and used it to schedule the meeting. That account existed before anyone was invited to anything.

The approach

The first message asks for nothing. It supplies a pretext, the story that gives the request a reason to exist, usually a confidential deal the recipient has been specially trusted with. It is a phishing message in every sense that matters, and it often points at a page built to look like yours.

The call

The shortest stage. The clone appears, the doubt resolves, and a suspicious instruction becomes a legitimate one in the approver’s head.

The cash-out

The money leaves in a shape designed to clear controls one transfer at a time. Then the operation moves on, because the domain, the accounts, the ad creative, and the contact list can all be aimed elsewhere.

That reuse is why the forecasts are steep. Deloitte’s Center for Financial Services projects generative AI could enable US fraud losses to reach $40 billion by 2027, up from $12.3 billion in 2023. The “could” is load-bearing.

The evidence sits on somebody else’s platform

Line those five stages up and the visibility problem is plain.

Two of them, the harvest and the call, leave almost nothing an outsider can detect. Downloading a keynote looks like watching one, and the meeting happened inside a room nobody else recorded.

The other three are different, because they force the campaign to publish something. A domain has to work when somebody types it. An account has to be reachable. An ad has to be served.

Here is the awkward part. Every one of those assets lives on infrastructure somebody else operates. The registrar holds the domain, the platform holds the account, the ad network holds the placement. The levers that would remove them are not in your console and never will be.

Your own tooling records your side of the exchange. Your mail gateway, your meeting logs, your payment approvals. It can tell you exactly what your people did. It cannot tell you whether the thing that fooled them is still live.

That distance is the whole problem. Your logs close the case, and the campaign keeps running.

What actually covering deepfake scams requires

A program that covers this does five things. Each one is a claim you can put to a vendor, not a principle you can nod along to.

1. Find the exposure before anyone builds a clone. You cannot stop the harvest, so the useful move is knowing which accounts, profiles, and pages already trade on your executives’ names and faces, and catching new ones as they appear rather than when somebody complains. Bolster AI runs this as executive impersonation coverage, and it is usually the part of the problem the brand team notices before security does.

2. Catch the lookalike domain in the window before it gets used. The domain that sends the first message exists days or weeks before the message goes out, and that gap is the only period where you’re ahead of the campaign. Anything that waits for traffic, a customer complaint, or a mail filter hit has given the window away, because all three need somebody targeted first. Bolster AI’s domain monitoring works off new-registration records instead, and the domain surfaces already joined to whatever accounts and ads share its fingerprints. A domain-only tool can tell you the name exists. It cannot tell you what got built alongside it.

3. Cover the surfaces that carry the story, not just the inbox. The account that schedules the meeting and the ad that lends the story credibility never touch your email, so an email-shaped program cannot see either one, and neither can a tool that only watches domains. Covering them means impersonation accounts on the platforms your executives use and fraudulent ads and the fabricated articles they point at, found by the same system that found the domain instead of matched up by hand afterward.

4. Put the media verdict inside the same investigation. This is the criterion most tools fail, because a verdict delivered as its own alert in its own console tells an analyst that the call happened and nothing else. Bolster AI’s deepfake detection is built to run inside an impersonation investigation, so the clip arrives attached to the domain and the accounts around it instead of being filed on its own.

5. Link the assets, then enforce against the set. Discovery that produces 40 separate alerts has moved the work, not done it. Campaigns leave shared fingerprints: registration batches, reused hosting, repeated creative. Bolster AI uses Signals to pull those into one case and automated takedowns to file against the whole group with the evidence attached. A detection tool and a takedown service bought separately cannot reproduce that, because neither one is holding the other’s evidence.

Removing the reported asset closes one route in. Removing the set shortens the campaign.

Where the usual response to a deepfake scam stops short

A standalone deepfake detector. It grades the clip and returns a verdict. That confirms the call happened, which the transfer already confirmed, and says nothing about where the domain is, who else got the message, or which accounts are live.

Callback and approval policy. Necessary, and genuinely the control that would have stopped Hong Kong. It is also internal; it engages only once the request has reached somebody, and multi-party approval quietly assumes the other faces on the call are real. Fix it anyway. It will not remove a thing.

Defensive domain registration. You buy the variants you thought of. The operators register the ones you didn’t, in batches, and point them at a phishing page the month after your renewal. Buying permutations does not shrink the set.

Customer and employee reports. These arrive after somebody has been convinced, and each names one asset out of a group that is still working.

Each of these is a partial view of one campaign. None of them holds the domain, the accounts, the ads, and the media verdict in the same place, and that particular combination is what Bolster AI is built to run.

How Bolster AI handles deepfake scams

Bolster AI detects external threats including phishing sites, lookalike domains, fraudulent social accounts, fake mobile apps, fraudulent ads, marketplace abuse, and synthetic media used for impersonation, connects related infrastructure into a single campaign, and removes them. Detection and takedown run as one workflow rather than as two separate promises.

Exposure found before the report arrives. Bolster AI looks for the accounts, profiles, and pages already carrying your executives’ names and faces, and flags new ones as they show up. That running picture is what makes a later report legible, because you can tell at a glance which assets are new and which have been sitting there for months.

Discovery at registration speed. Bolster AI reports tracking 11.9 million malicious domains across 2025, with a peak daily average above 378,000. Volume at that level is the argument for watching registrations, since a domain sitting quiet for three weeks before its first message is invisible to anything waiting for a victim.

A verdict that lands inside the case. Bolster AI reports returning a verdict on a submitted asset in 100 milliseconds, and the point here is not the millisecond. It is that the media assessment happens in the same workflow already holding the domain and the accounts, so an analyst reads one story instead of stitching two consoles together at 2 am.

Enforcement against the whole set. Bolster AI reports a 98% takedown success rate and direct API partnerships with more than 1,500 registries and hosting providers, which is the machinery behind filing against a group of assets at once. SoFi is the published example: analyst workload cut by 20%, and an international phishing campaign shut down in 24 hours.

What Bolster AI does not do. Bolster AI is not inside your video call. There is no product here that tells an employee mid-meeting that the face on screen is generated, and the callback path that would have caught the request, along with the approval logic that let 15 transfers clear in a week, is internal work that stays yours. Bolster AI works on what the campaign had to publish, which is everything except the call itself.

The point isn’t that Bolster AI replaces your payment controls, your identity checks, or your training. Those govern the request once it has arrived. They have no view of the domain that sent it, the account that scheduled the meeting, or the ad that made the story plausible, and that external half is the half still running after your incident closes.

Treat the campaign as live until you’ve removed it

The transfer gets reversed or it doesn’t, and either way that part of this has an ending. The infrastructure doesn’t. The domain, the accounts, the ad creative, and the contact list the operators assembled along the way are all still there the week your incident review wraps up, and all of it works just as well on the next target.

So deepfake scams are not a case you close. They’re a surface you keep watching. See what’s still live around your executives once the incident is closed, and keep it in view.

TL;DR: Deepfake scams run as campaigns, and the synthetic call is one stage inside them. The stages around it are ordinary fraud mechanics: a harvest of published audio and video, a lookalike domain or impersonation account that lends the story credibility, a first message that asks for nothing, and a cash-out split across several transfers. The harvest and the call leave almost nothing an outsider can find. The domain, the accounts, and the ads do, and they sit on infrastructure you do not control. Opening a deepfake report as a campaign investigation, not a media verdict, is what turns it into something you can act on.

Frequently asked questions

Are deepfake scams just business email compromise with better production values?

Largely, yes, and that is the useful way to think about them. The pretext, meaning the story that gives the request a reason to exist, plus the target selection and the payment mechanics, are the same as wire fraud that has worked for years. The synthetic voice or video is added at the confirmation step, where a human approver wants reassurance from someone they recognize. Treating it as an exotic new category tends to send teams shopping for a detector instead of fixing the approval path and removing the infrastructure.

Can anything detect a deepfake during a live video call?

Bolster AI doesn’t do this and doesn’t take a position on the tools that claim to. What is worth saying is that your controls shouldn’t depend on catching it in the moment, because the defenses that work during a call are procedural: end it and call back on a number you looked up yourself, and treat agreement on a call as worth nothing, since every other face can be generated as easily as one. Bolster AI works on the assets around the call rather than inside it, because those are the ones that stay findable afterward.

What should a security team do in the first hour after a deepfake report?

Scope it as a campaign, not an incident. Enumerate the three asset types the public cases always show: the domain behind the first contact and anything registered alongside it, any account carrying the executive’s name or photo, and any ad or fabricated article pushing the story. Then act against all of them at once, which is the step most teams cannot finish in-house, because filing across registrars, platforms, and ad networks together is what Bolster AI’s takedown workflow exists to do.

Can Bolster AI remove the deepfake video itself?

Sometimes, and not always, which is worth being clear about. When the video sits on a surface Bolster AI covers, such as a social account, an ad placement, or a page on a lookalike domain, it can be submitted and removed like any other impersonation asset. When the clone only ever existed inside a private video call, there is no hosted copy to take down. In that case, the removable evidence is the infrastructure around it, which is where the campaign’s reusable value sits anyway.

Does defensive domain registration help?

It helps a little, and it is not a program. Registering the obvious variants takes the cheapest options off the menu, but operators buy in bulk and generate permutations faster than any budget covers. Monitoring new registrations and taking down the ones being used against you covers the set you did not think of, which is the set that gets used.

How does Bolster AI connect a deepfake to the rest of the campaign?

Through shared infrastructure rather than through the media itself. Campaigns reuse hosting, registration patterns, contact details, and creative, and Bolster AI groups assets sharing those fingerprints into a single case so a takedown can be filed against the group. That is the difference between closing one report and shortening the operation behind it.