Payload Logo

Deepfakes and Social Engineering: Why You Can't Trust Your Inbox Anymore

Date Published

You get an email from your boss. The tone is right. The signature is right. There's a link to a shared file, and a note asking you to "take a look before the 3 PM call." Nothing feels off. So you click.

That single click is how most modern attacks begin. And here's the scary part: the email might not have come from your boss at all. It might have been written by a machine, sent by a stranger, and designed to look so real that even careful people fall for it.

Welcome to the new world of online scams, where fake voices, fake faces, and fake messages are cheap to make and hard to spot. In this guide, we'll break down what's happening, why it works so well, and what you can actually do about it — all in plain language.

First, what is a "deepfake"?

A deepfake is fake audio, video, or images made by artificial intelligence (AI) that looks or sounds like a real person. Think of it like a very advanced impression. But instead of a comedian imitating a celebrity, a computer copies someone so well that your eyes and ears believe it.

A few years ago, making a convincing deepfake needed expensive computers and technical skill. Not anymore. Today, cheap or free tools can do the job, and the results keep getting better.

Here's a number that should make you pause: it now takes just <cite index="2-1">3 seconds of audio to clone a voice with 85% accuracy.</cite> Three seconds. That's shorter than the average voicemail greeting. Anyone who has posted a video online, spoken on a podcast, or left a voice note has given away enough for a scammer to copy them.

And these aren't rare experiments anymore. <cite index="2-1">Around 500,000 deepfakes existed online in 2023. By 2025, that number reached 8 million.</cite> That's a massive jump in a very short time.

What is "social engineering"?

If deepfakes are the fake face, social engineering is the game plan behind it.

Social engineering is a fancy term for a simple, old trick: instead of breaking through a company's security systems, attackers just trick a human into opening the door for them. They don't hack the computer. They hack the person.

They do this by playing on normal human feelings — trust, fear, urgency, and the desire to be helpful. A message that says "Please help me, I need this done right now" is far more powerful than any piece of malicious software, because it targets how our brains work under pressure.

Security experts put it clearly: <cite index="1-1">the most significant threat to your organization in 2025 isn't a zero-day exploit or a complex piece of malware. It's a well-crafted email, a convincing phone call, or a deepfake video.</cite>

When you combine social engineering (the trick) with deepfakes (the fake face and voice), you get a scam that is incredibly hard to catch.

Why your inbox is now the danger zone

For years, we were told how to spot a fake email. Look for bad spelling. Watch for weird grammar. Be suspicious of strange greetings like "Dear Valued Customer." If the message looked messy, it was probably a scam.

That advice is now useless.

AI can write a perfect email in seconds — no typos, no awkward phrasing, and written in a tone that matches your company or your friend. Worse, it can make these emails personal. It can mention your actual projects, your real coworkers, and details that make the message feel trustworthy.

The results speak for themselves. Research shows that <cite index="1-1">phishing emails generated entirely by AI can achieve a 42% higher click-through rate than those written by humans.</cite> In plain terms: AI-written scam emails work far better than the old ones, because they don't look like scams.

This is why the classic advice has quietly expired. As one report bluntly states, <cite index="1-1">the age-old advice to "look for spelling and grammar mistakes" is now dangerously obsolete.</cite>

Your inbox used to be a place where sloppy scams gave themselves away. Now it's a place where a flawless, personalized, machine-made message can land at any moment — and look exactly like the real thing.

A real example: the $25 million video call

If this all sounds theoretical, let me tell you about a case that shook the business world.

A finance worker at a large engineering firm received a message about a "secret transaction." It felt suspicious at first. So the company did the smart thing — or so it seemed. They set up a video call with several senior colleagues, including the chief financial officer (CFO), to confirm everything.

The worker joined the call. The people on screen looked and sounded exactly like the real executives. Reassured that everything was legitimate, the worker followed instructions and sent the money.

Every single person on that video call was fake. All of them were deepfakes. The company lost around <cite index="1-1">$25 million</cite> in what became one of the most famous deepfake scams ever recorded.

Read that again. The victim did try to verify. They asked for a video call — normally a sensible step. But the attackers had already thought of that and faked the entire meeting.

The lesson here is uncomfortable: <cite index="3-1">the $25 million fraud was not a failure of an employee's detection skills; it was a failure of organizational process.</cite> The worker wasn't foolish. The verification method they trusted had simply been beaten by better technology.

How these attacks actually work, step by step

Modern deepfake scams usually follow a clear pattern. Understanding it makes them easier to spot.

Step 1: Research. Attackers study their target. They look at your company website, LinkedIn, social media, and public videos. They figure out who the boss is, who handles money, and how people talk to each other. This is where they collect that 3-second voice sample and the details that make a message feel real.

Step 2: Prepare the fake. Using the collected material, they build the deepfake — a cloned voice, a fake video face, or a perfectly written email. Thanks to AI, this step is fast and cheap.

Step 3: Make contact and apply pressure. They reach out pretending to be someone you trust. There is almost always a sense of urgency: a deadline, a secret deal, an emergency payment. Urgency is the key ingredient because it stops you from thinking carefully.

Step 4: Extract the money or data. Once you believe the message, you do what's asked — send a payment, share a password, or approve access. By the time anyone realizes the truth, the money or data is gone.

Notice how attacks now jump across different platforms to seem more believable. <cite index="5-1">Attackers are coordinating deepfake video, voice cloning, and social engineering across multiple platforms in a single operation. Campaigns often move from messaging apps to video calls and email, which increases credibility and reduces the chance of detection.</cite>

That's why an email might be followed by a "confirmation" phone call, and then a video meeting. Each step is designed to melt away your doubt.

This isn't rare — it's an everyday flood

It would be comforting to think these attacks only hit giant corporations. They don't.

The scale is genuinely huge. <cite index="3-1">CEO fraud now targets at least 400 companies per day.</cite> Voice scams have reached ordinary people too — <cite index="3-1">a 2024 McAfee study found that 1 in 4 adults have experienced an AI voice scam, with 1 in 10 having been personally targeted by one.</cite>

The financial damage is climbing fast. <cite index="1-1">Business Email Compromise caused $2.77 billion in losses in 2024,</cite> and that figure keeps rising as AI makes attacks easier to run.

Perhaps most worrying, these attacks are now common across the business world. A recent survey found that <cite index="4-1">62% of organizations experienced a deepfake incident in the prior 12 months.</cite> Nearly two out of three. This is no longer a "someday" problem — it's a "this year" problem.

Why you can't just "spot the fake"

A natural reaction is to say: "I'll just look harder. I'll train myself to notice fakes."

Unfortunately, that plan doesn't hold up. Humans are simply not built to detect high-quality fakes, especially when we're stressed, busy, or being pressured — which is exactly the state attackers try to create.

Security researchers make this point strongly. They argue that <cite index="3-1">humans are not, and will not become, reliable forensic analysts, especially when under the pressure of a sophisticated social engineering attack.</cite>

In other words, trying to catch every fake with your own eyes and ears is a losing battle. The technology is too good, and it improves every month. So instead of relying on detection, we need to rely on process — simple habits and rules that protect you no matter how convincing the fake is.

How to actually protect yourself

Here's the good news. You don't need to become a tech expert to stay safe. You just need a few strong habits. These work whether you're protecting a business or your own family.

1. Verify on a second channel. This is the single most important rule. If you get an urgent request for money, passwords, or sensitive information, confirm it using a different method than the one it came in on. Got an email from your boss? Call them on their known phone number. Got a voice message? Send a text to confirm. Never verify a suspicious request using the same channel it arrived on — that channel might be controlled by the attacker.

2. Treat urgency as a warning sign, not a reason to hurry. Scammers rely on panic. When a message screams "Do this now or something bad happens," that's your cue to slow down, not speed up. Real emergencies can survive a two-minute verification call. Fake ones usually can't.

3. Set up a family or team "safe word." Agree on a private code word with your family or close coworkers. If someone calls sounding exactly like your daughter or your CEO asking for money, you ask for the safe word. A cloned voice won't know it. This simple trick defeats even a perfect voice fake.

4. Be careful what you share publicly. Every public video, voice note, and photo is raw material for a deepfake. You don't need to go silent online, but be mindful. The less voice and video of you floating around freely, the harder you are to copy.

5. Build verification into your rules — especially for money. For businesses, this is critical. Require that any large payment or account change be confirmed by two people through a trusted, offline method. Don't leave it up to one employee's judgment during a stressful call. The Arup company learned this the hard way: process protects you when detection fails.

6. Assume voice and video can be faked. This is a mindset shift. In the past, hearing someone's voice or seeing their face was proof. Not anymore. As experts now advise, everyone should know that <cite index="4-1">live audio and video can be faked, that urgency is part of the attack, and that verification must happen on a second trusted channel.</cite>

The bottom line

The uncomfortable truth is this: we've entered an age where seeing and hearing are no longer believing. A voice on the phone, a face on a video call, a perfectly written email — none of these are proof of identity on their own anymore.

But this isn't a reason to panic. It's a reason to change one habit: verify before you trust.

The scammers are betting on speed, fear, and our instinct to be helpful. You beat them by slowing down, confirming through a second channel, and refusing to act on urgency alone. Technology may keep making fakes better, but a two-minute phone call to the real person defeats even the most convincing fake.

Your inbox, your phone, and your video calls are no longer safe by default. That's the new reality. The people and companies who accept it — and build simple verification habits around it — are the ones who stay safe. The ones who keep trusting their eyes and ears are the ones who end up in the next headline.

Trust, but verify. And in this new world, verify a little harder than you used to.