The Cohort Room
Live
Providers

Training For The Deepfake Era: Why Verification Habits Beat Detection Skills

As deepfake technology advances, companies are struggling to keep up with the latest phishing tactics. A recent case highlights the need for verification habits over detection skills in corporate training.

Providers: As deepfake technology advances, companies are struggling to keep up with the latest phishing tactics

The rise of deepfake technology has left companies scrambling to keep up with the latest phishing tactics. A recent case in point is a finance employee at a multinational engineering firm in Hong Kong who was duped into approving transfers worth $25 million after being convinced by a group of deepfakes during a video call.

The trouble is that corporate training has not caught up with the new reality. We teach people to distrust text but leave voice and video as unquestioned tiebreakers. This approach is no longer effective, as detection training gives employees confidence that lasts only a few months, and nearly every visual glitch has since disappeared.

## Why "Spot The Fake" Training Expires So Fast

The instinctive response is to teach detection: odd blinking, hands with too many fingers, lighting that does not quite match the room. However, this approach has several problems. Firstly, each visual glitch is a bug report, and the next model version fixes it. Secondly, synthetic media is no longer only a fraud tool; marketing teams now put out synthetic influencers and deepfake spokespeople as ordinary brand assets.

### Teach Verification, Not Detection

What holds up is procedure. A deepfake literacy program should spend a small fraction of its time on how the technology works and most of it on what employees do when a request arrives by voice or video. The skills worth drilling are boring, which is exactly why they survive model upgrades.

### Confirm On A Second Channel

Any request involving money, credentials, or data access gets verified on a channel different from the one it arrived on. If the CFO asks during a video call, the employee calls back using the number in the company directory, not the number in the meeting invite. The rule matters more than the tool. Attackers control the channel they contacted you on; they rarely control the one you choose yourself.

### Put Authority In Writing

Half of these scams work because nobody is sure who can approve what. Publish the actual approval chain for payments, vendor changes, and access grants, and state plainly that no phone call or video call can override it. An employee who knows the CEO cannot authorize a wire by voice alone has a script for the scariest moment of the con.

### Treat Urgency As The Alarm

Manufactured time pressure is the one element the attacker cannot remove, because verification takes minutes and minutes are what kill the scheme. "This has to happen before end of day and you cannot tell anyone" should register as the red flag itself, whatever face is saying it.

### Give High-Exposure Teams A Shared Phrase

Finance, executive assistants, and IT support pick up the phone for a living. Families now use code words to defeat voice-clone scams aimed at relatives, and the same low-tech fix works for a leadership team. It costs nothing and no model can generate it.

### Drill It Like You Drill Phishing

Phishing simulations became standard because one experience of being fooled teaches more than an hour of video content. The same logic applies here, and the raw material is uncomfortably easy to produce. A short clip of clean audio from a town hall recording or a webinar is enough to clone a voice with a consumer tool.

### Let Peers Carry The Message

A mandated module tells employees the company is worried. A teammate who plays a clone of their own voice in a Monday meeting and says "this took me four minutes and a free trial" changes what people believe. That demonstration lands because of who is giving it, which is the same reason internal learning champions outperform top-down rollouts in AI adoption generally: people weigh who is talking before they weigh what is being said.

### Measure Behavior, Then Protect It

Completion rates tell you nothing about any of this. Track what people do. In drills, measure the share of targeted employees who actually made the callback, and how long reporting took. Outside drills, count near-miss reports, and treat a rising count as the program working rather than the sky falling. People reporting weird calls means people noticing weird calls.

Then protect the behavior. The employee who double-checks a genuine request from the CEO must come out of that exchange feeling smart, not insubordinate. One executive who snaps "why are you wasting my time" undoes a year of training, because everyone hears about it. Leadership has to say, out loud and more than once, that verification is never a career risk.

Topics

Related coverage

More from Providers