— Blog

Field notes

Dispatches on synthetic media, manipulation, and AI governance.

The 20-minute deepfake: when the wire request is your CFO

The most expensive deepfakes are not the viral ones. They are the quiet calls to a finance clerk, in a voice that sounds exactly like the CFO, asking for an urgent transfer before a deal closes. The clones are cheap to make, they are improving monthly, and they target precisely the people authorized to act on them.

Authority is the exploit

These attacks rarely break a technical control. They borrow legitimate authority and wrap it in urgency, which is the oldest social-engineering recipe there is — only now the voice and face are convincing enough to skip the doubt. Awareness training helps at the margins, but you cannot train your way out of a perfect impersonation under time pressure.

Detection where executives actually meet

Defog Shield's deepfake defense runs on the surfaces leadership uses: Zoom, Teams, and Meet, plus email attachments and recorded training. Voice and video are scored for synthesis in near real time, and the C-suite is treated as a first-class protected class rather than an afterthought. Pair that with the PII firewall and the agentic trust layer, and the same control surface that watches prompts also watches the calls where the biggest single-transaction losses happen.

None of this requires ripping anything out. It ships as a managed extension and agent through the same channel as your EDR, federates to your existing identity provider, and forwards to the SIEM you already run. The point of Shield is not to add another console nobody checks. It is to make the invisible layer — the one between your people and the models and media they cannot verify — finally visible.

← All posts