Your Brand Has No Defense Against Deepfakes. That's a Strategy Problem, Not a PR Problem.
Why denial isn't a defense, and what actually is
· 4 min read
The call looked legitimate. The face on screen was the CFO. The voice matched. The employee did what was asked and transferred the money: $25 million, wired to accounts she’d never seen before. When the real CFO showed up in the Hong Kong office the next morning, the wire had been gone for twelve hours.
A few months later, someone tried the same move at Ferrari. They cloned the CEO Benedetto Vigna’s voice and called an executive, asking him to authorize an unusual financial transaction. The executive was suspicious. He asked a question about a book Vigna had recommended to him in a private meeting a few days earlier.
The caller couldn’t answer. The deepfake failed.
The difference between $25 million lost and $25 million saved wasn’t better deepfake detection. It wasn’t a faster crisis response. It was a book recommendation from a private conversation that existed nowhere in any public dataset.
Wrong frame
When a deepfake surfaces, every company’s first call is to legal, then comms. Issue a denial. Get ahead of the story. Control the news cycle.
I understand the impulse. It’s how we’ve always responded to reputational attacks. But a denial only works as well as the trust architecture underneath it. If the only thing standing between your brand and a convincing synthetic impersonation is your ability to say “that wasn’t us,” you don’t have a defense. You have a press release.
The deeper problem isn’t the deepfake. It’s that most organizations have never built the kind of authentic, verifiable behavioral record that would make a synthetic impersonation feel wrong rather than just deniable.
The math is bad and it’s not getting better
The economics of synthetic impersonation are grotesquely asymmetric. The robocall deepfake that flooded New Hampshire before the 2024 primary cost roughly $500 to produce. The FCC fine alone was $6 million. The Arup loss came from a single video call. The attacker’s investment (some time and a GPU) was trivial.
You cannot win the detection arms race. Every improvement in detection automatically provides a training signal for better fakes. The better detectors get, the better the fakes become. That equilibrium never favors the defender.
But the Ferrari executive didn’t need a detector. He had something better: he knew what the real Vigna actually knew.
How banks figured this out first
Financial services got here ahead of everyone else, because the stakes forced it.
For years, fraud worked the same way these deepfakes do: steal a credential, impersonate the account holder, extract the money. The industry’s first instinct was checkpoint defense: stronger passwords, better verification at the point of entry. It didn’t work, because sophisticated attackers just got better at the checkpoint.
What actually worked was a different frame entirely. Instead of trying to catch fakes at the gate, banks started building systems that track behavior continuously throughout every session. Not what you know, but how you act. Your typing cadence, your navigation patterns, the specific rhythm of how you move through an interface. BioCatch runs this kind of behavioral analysis for 34 of the top 100 global banks, covering more than 500 million customers. Their core insight: credentials can be stolen, but behavior can’t be replicated at scale. “Mules can change accounts, but they can’t change how they act.”
The authentication question shifted from “is this the right person?” to “does this behavior match everything we know about this person?”
That’s not a product feature. It’s an architectural choice about where trust lives.
What actually stopped the attacks
Every executive deepfake that was caught in the last few years was caught the same way: not by technology, but by behavioral knowledge the attacker couldn’t extract from public data.
WPP CEO Mark Read was deepfaked in a WhatsApp video call. Someone cloned his voice and image and tried to get an executive to set up a new business entity and wire money. The attempt was stopped not because anyone ran it through a detector, but because the request violated procedural norms: legitimate requests from the actual CEO don’t arrive via WhatsApp, and they don’t ask you to do things outside your normal authorization. The employee had internalized what normal looked like. This wasn’t it.
LastPass got the same playbook. A deepfake call impersonating the CEO failed because the channel was wrong and the employee had been trained to treat channel anomalies as authentication failures.
Ferrari’s defense came from something even further from public reach: private intellectual history. A book recommendation from a meeting that existed nowhere in the company’s materials, nowhere in the CEO’s public archive, nowhere a dataset could find it.
The pattern is the same across every stopped attack: behavioral and relational knowledge that exists only inside the actual relationship. The attacks that succeeded (Arup’s $25 million, the Binance cases) all involved people who had no prior personal relationship with the deepfaked individual. They had nothing to compare the fake against except the public footage that built it.
The question this raises
The strategic implication is harder than it looks.
If a deepfake of your CEO dropped tomorrow, what would your employees use to know it was fake, beyond the denial your communications team would issue? Do your people know what normal authorization looks and feels like, in enough operational detail that an anomaly would register? Do your most important stakeholders have the relational depth with your organization that would make a synthetic impersonation feel behaviorally wrong, not just logically suspicious?
That’s not a crisis comms question. It’s a question about what you’ve actually built.
The organizations that will hold up against synthetic impersonation aren’t the ones with the fastest response protocols. They’re the ones that already have what the Ferrari executive had: a dense, specific, private record of authentic interaction that no public data can replicate.
You can’t build that after the call comes in.
More on Trust as Infrastructure
Testimonials Are Dead. You Just Haven't Noticed Yet.
Social proof broke when the proof got cheap to fake.
Reviews and case studies can be faked for free now, and your best buyers know it. The proof that still works is vouched, with a real reputation on the line.
The Rebrand is the Tell
Every rebrand quietly admits the last version wasn't real.
Every rebrand quietly admits the last version wasn't real. In the synthetic era, a slow, traceable identity is the one signal you can't fake.
Behind-the-Scenes Content Is the New Greenwashing
Performed authenticity works, until someone audits it.
Behind-the-scenes content is a genre: produced rawness performing as candor. It works, until the gap gets seen. The transparency that survives an audit.
Have a project in mind?
I help purpose-driven organizations build the technology they need to tell their stories. If that sounds like you, let's talk.
Get in touch with Five59 Labs →