Financial Crime · Strategic Guide

Deepfake and Voice-Clone Fraud: Legal and Investigative Response

A familiar face on a video call and a recognised voice on the telephone can now be manufactured. Craig MacKenzie explains how organisations should respond when synthetic media may have been used to procure a payment, obtain information or manipulate a decision, and why the investigation must authenticate the decision rather than simply debate whether the recording “looks real”.

Author
Craig MacKenzie
Role
Partner and Solicitor Advocate
Published
27 July 2026
Reading time
22 minutes

Recognition is no longer verification

Deepfake fraud succeeds by exploiting a control which was never formally written down: the human instinct to trust a familiar face or voice.

An employee receives an urgent call from the chief executive. The voice is right. The mannerisms are familiar. A video conference appears to include colleagues whom the employee recognises. The instruction also fits an existing transaction. Only later does the organisation discover that the call may have been generated, altered or assembled from stolen material.

The immediate question is usually:

Was it a deepfake?

That matters, but it is not the first strategic question. The first question is:

What decision was made, what caused it to be made, and which independent control was supposed to authenticate it?

A technical opinion about whether media was synthetic may become important evidence. It does not, by itself, explain why money was transferred, credentials were disclosed or a safeguard was bypassed. Nor does it identify the person who acted dishonestly.

The machine did not commit the fraud. A person may have used it to make a false representation, conceal an identity, impersonate authority or defeat a verification process. The legal and investigative response must keep the human conduct, the organisational decision and the technological instrument separate.

The central principle is:

Authenticate the decision, not the face.

That principle governs prevention, incident response and proof.

What deepfake and voice-clone fraud means

“Deepfake” is a useful description, not a single legal category. It can include:

  • synthetically generated audio, video or images;
  • cloned speech created from recordings of a real person;
  • face replacement or facial animation;
  • lip-synchronised or translated video;
  • fabricated participants in a live or recorded call;
  • genuine footage edited or placed in a false context;
  • manipulated screen shares, documents or chat messages;
  • synthetic identities assembled from real and invented attributes; and
  • a mixture of genuine and generated material used to make an instruction credible.

The distinction between fully generated and partly manipulated content may matter to a forensic examiner. From the victim organisation’s perspective, however, the practical risk is broader: a communication has been presented as reliable evidence of identity, authority or fact when it may not be.

Fraudsters do not need cinematic perfection. They need material which survives the short period in which a pressured person decides whether to act. Poor audio, limited bandwidth, a brief call, an urgent deadline and a plausible commercial context can all reduce the need for technical sophistication.

The deception may also be distributed across several channels. An email creates the narrative. A messaging account supplies a document. A cloned voice confirms urgency. A video call supplies apparent authority. A compromised mailbox then suppresses the warning or alters the payment details.

An investigation which examines only the suspicious recording may therefore miss the fraud.

The law addresses the deception, not the label

There is no need for a prosecutor to prove an offence called “deepfake fraud”. Existing offences can apply to the conduct for which synthetic media was used.

Fraud by false representation

Section 2 of the Fraud Act 2006 is likely to be central in many cases. A person commits the offence if they dishonestly make a false representation, intending to make a gain or cause loss, or expose another to a risk of loss.

A representation may be express or implied. It may concern fact, law or state of mind. It may be communicated through a system without a human recipient.

A fabricated call may therefore contain several representations at once:

  • “I am this identified person.”
  • “I have authority to give this instruction.”
  • “This transaction is genuine.”
  • “The account details are legitimate.”
  • “The people visible or audible on this call approve the decision.”
  • “The urgency and confidentiality are real.”

The prosecution would still have to prove dishonesty and the required intent. Technical manipulation does not relieve it of that burden. Conversely, the absence of a perfectly generated artefact does not prevent proof of a false representation.

Fraud by failing to disclose information

Section 3 can apply where a person dishonestly fails to disclose information which they are under a legal duty to disclose, intending the relevant gain or loss. It will be less common in a straightforward impersonation, but may be relevant where a person participates in a transaction while concealing a material conflict, false identity or other fact which the law requires them to reveal.

Fraud by abuse of position

Section 4 may apply where a person occupies a position in which they are expected to safeguard, or not act against, another’s financial interests and dishonestly abuses that position.

This can matter when deepfake material is only part of the story. An insider may supply source recordings, approve a fraudulent payment, weaken controls or give an external actor the contextual information needed to make an impersonation convincing.

The deepfake may be the visible instrument. The underlying case may be an abuse of trusted access.

Conspiracy, attempts and assistance

Liability is not confined to the person who presses “generate” or speaks to the victim. Depending on the evidence, those who plan the fraud, acquire personal data, compromise accounts, create the synthetic media, provide mule accounts or launder the proceeds may face liability for conspiracy, attempts, assisting or encouraging offences, money laundering or related crimes.

The evidential question for each person remains individual:

  • What did they do?
  • What did they know or believe?
  • What dishonest agreement or assistance can be proved?
  • What was their intended gain or intended loss?

The sophistication of the technology must not substitute for proof of the defendant’s role and state of mind.

Computer misuse and stolen access

Where the fraud involves compromised email, unauthorised access, stolen credentials, malicious software or interference with systems, offences under the Computer Misuse Act 1990 may also arise.

This is important operationally. What first appears to be an external impersonation may be supported by an internal account compromise. A threat actor who can read a mailbox can learn transaction values, writing style, reporting lines, travel plans and the precise moment at which an instruction will appear plausible.

Proceeds of crime

Once property represents the benefit from criminal conduct, offences and investigative powers under the Proceeds of Crime Act 2002 may become relevant. Speed matters. Funds may pass through multiple accounts or be converted into other assets before the victim has settled the terminology of the incident.

The legal team should therefore avoid allowing a debate about whether the media meets a technical definition of “deepfake” to delay banking notifications, tracing, preservation or reporting decisions.

A deepfake does not prove fraud

Synthetic or manipulated media can be used lawfully. It may be created for entertainment, accessibility, localisation, training, security testing or authorised corporate communication.

Its presence does not establish:

  • dishonesty;
  • who created it;
  • who deployed it;
  • an intention to gain or cause loss;
  • that the recipient relied on it;
  • that any payment or disclosure resulted from it; or
  • that a particular suspect knew it was false.

Equally, a failure to prove technical manipulation does not mean there was no fraud. The offender may have used a real recording out of context, a human impersonator, a compromised account or a genuine call combined with false documents.

Investigators should resist two opposite errors:

  1. treating “deepfake” as a complete theory of guilt; and
  2. treating an inconclusive detector result as a complete answer to the allegation.

The proper case theory must connect human conduct to a false representation, dishonest intent, causation where relevant, and the movement or risk of property.

The first response: contain loss without contaminating proof

A suspected deepfake incident can create simultaneous pressures. The organisation may need to stop a payment, preserve evidence, protect accounts, notify insurers, consider regulatory duties, manage employees and communicate with law enforcement.

Those tasks should be coordinated, but not collapsed into one indiscriminate internal inquiry.

1. Stop or trace the transaction

Contact the relevant bank or payment provider immediately through a verified channel. Ask what recall, hold, tracing and beneficiary-bank measures are available. Record:

  • when the transaction was initiated;
  • who authorised it;
  • the accounts and payment rails involved;
  • when suspicion arose;
  • when each institution was contacted;
  • what action was requested; and
  • the response received.

Do not wait for a final technical conclusion about the audio or video.

2. Move communication to trusted channels

Assume that the channel used for the fraudulent instruction may be compromised. Verify key individuals through contact details already held in trusted systems. Do not use a telephone number, meeting link or email address supplied in the suspicious communication.

Consider resetting or suspending affected credentials, but coordinate this with evidence preservation. Deleting an account, wiping a device or rebuilding a mailbox too early may destroy material needed to understand the intrusion.

3. Preserve the original material

Retain the original audio, video, message, email, meeting invitation, attachment and associated metadata where available. A screen recording or forwarded copy may omit information. Preserve:

  • original files and container formats;
  • message headers;
  • meeting identifiers and participant logs;
  • account and device logs;
  • access and authentication records;
  • payment instructions and approval records;
  • telephone records;
  • chat exports;
  • versions of altered documents;
  • relevant CCTV or access-control data; and
  • the devices on which the communication was received.

Guide 4 in this series addresses the full preservation protocol for an AI-enabled fraud investigation. At this stage, the rule is simple: preserve first, transform later.

4. Capture the decision trail

The most valuable evidence may not be the synthetic file. It may be the record of how the organisation responded to it.

Capture:

  • what the recipient believed;
  • which features appeared authentic;
  • what urgency or secrecy was asserted;
  • what independent checks were attempted;
  • whether controls generated warnings;
  • who approved any exception;
  • whether the instruction matched a real transaction;
  • what was said immediately before and after the decision; and
  • when the recipient first became suspicious.

Obtain factual accounts promptly, but do not conduct accusatory or leading interviews without a proper investigation plan. Memory is vulnerable to hindsight. Once an employee learns that the call was probably false, their recollection of what originally persuaded them can change.

5. Establish governance

Appoint a response lead. Define who is responsible for:

  • loss containment;
  • technical investigation;
  • legal advice and privilege;
  • employee and witness interviews;
  • communications;
  • regulatory analysis;
  • insurer engagement;
  • law-enforcement contact; and
  • board reporting.

Separate operational recovery from fact-finding where necessary. The person restoring the system should not decide alone what evidence can be discarded.

Investigate the whole decision, not merely the media

A sound investigation should work across four connected layers.

Layer 1: the media

Questions include:

  • Is the file original, transcoded, compressed or screen-recorded?
  • What metadata remains?
  • Are there discontinuities, artefacts or signs of generation?
  • Can the source or editing history be identified?
  • Is there a genuine reference recording for comparison?
  • Could ordinary compression, lighting or network conditions explain the apparent anomaly?
  • Was the content live, prerecorded or replayed?

Automated deepfake detectors may assist triage. Their output should not be treated as a verdict. Performance can vary by model, language, compression, recording conditions and the type of manipulation. The detector’s version, settings, inputs and output should themselves be preserved.

Layer 2: the channel

Questions include:

  • How was the call, message or meeting initiated?
  • Was an account compromised, cloned or newly created?
  • Were multifactor-authentication events recorded?
  • Were forwarding rules or recovery details changed?
  • Which IP addresses, devices or session tokens were used?
  • Did the attacker have access to calendars, emails or documents?
  • Were domains, caller IDs or display names spoofed?

The channel may explain how the offender acquired credibility and how the organisation’s warnings were neutralised.

Layer 3: the transaction or disclosure

Questions include:

  • What precisely was authorised?
  • Which approval workflow applied?
  • Were payment details new or recently changed?
  • Did system controls flag the transaction?
  • Was segregation of duties preserved?
  • Who could override the control?
  • What reason was recorded for any exception?
  • Where did the funds or information go?

This layer connects the deception to the practical outcome.

Layer 4: the human and organisational context

Questions include:

  • Why was the instruction plausible to this recipient?
  • What public or stolen information could have been used?
  • Was the recipient selected because of role, workload or authority?
  • Did organisational culture reward speed or discourage challenge?
  • Was seniority used to suppress verification?
  • Had similar requests become normal?
  • Did the attacker exploit a live transaction, acquisition, travel plan or crisis?
  • Was an insider involved?

This is where the investigation moves from “how convincing was the fake?” to “why did the control environment permit the decision?”

Attribution requires discipline

Deepfake investigations can produce a persuasive narrative before they produce reliable attribution.

A cloned voice may identify the person impersonated, not the offender. An IP address may identify infrastructure, not the user. A beneficiary account may belong to a mule, not the organiser. A device may contain generated material without proving who created or deployed it.

Investigators should distinguish:

PropositionEvidence that may support it
The media was manipulatedOriginal file analysis, metadata, expert comparison, generation artefacts
A particular account delivered itPlatform records, headers, session logs, provider evidence
A person controlled that accountDevice evidence, credentials, IP history, admissions, surrounding communications
The person knew the representation was falsePlanning messages, source material, instructions, concealment, repeated conduct
The person acted dishonestly for gain or lossTransaction design, beneficiary links, division of proceeds, communications, conduct
The victim acted because of the deceptioncontemporaneous messages, approval records, witness evidence, timing

Each proposition needs its own proof. The word “deepfake” should not be used to bridge an evidential gap.

Evidence integrity and the generation trail

Traditional authenticity questions remain important: provenance, continuity, alteration and reliability. Generative systems add another category of evidence, the generation trail.

Depending on the case, relevant material may include:

  • prompts and prompt history;
  • source recordings or images;
  • uploaded reference files;
  • model and service used;
  • account records;
  • generation timestamps;
  • seed or configuration information;
  • edit and export history;
  • intermediate outputs;
  • moderation or safety records;
  • payment and subscription records;
  • API logs; and
  • communications between participants about selection and deployment.

The final audio or video may show what the recipient encountered. The generation trail may show how it was built, who was involved and what they intended.

Preservation requests to service providers may need to be made quickly and precisely. Data availability, jurisdiction, retention and lawful-access routes will vary. Organisations should obtain specialist advice before assuming that a platform will retain, locate or disclose the material later.

Interviewing the recipient

The recipient of a deceptive call is both a potential witness and an employee who may be distressed, embarrassed or concerned about blame. Poor handling can damage welfare, candour and evidence.

An initial factual account should distinguish:

  • what the witness remembers independently;
  • what the witness has since been told;
  • what records they have reviewed;
  • what appeared authentic at the time;
  • what appeared unusual at the time;
  • the sequence of communications and decisions;
  • the checks undertaken;
  • the reasons for acting; and
  • any contact with colleagues after suspicion arose.

Avoid showing the witness repeated commentary about common “deepfake signs” before obtaining their account. That can encourage reconstruction. Avoid asking them simply to confirm the organisation’s preferred explanation.

The interview should not become a disguised disciplinary process. If employee culpability, insider involvement or regulatory responsibility is in issue, the organisation should decide the interview’s purpose, status and safeguards before proceeding.

Voice and video must not be single-factor authority

The preventive lesson is not that employees must learn to spot every synthetic artefact. Detection literacy can help, but the technology will continue to change and genuine communications can exhibit the same supposed warning signs.

The durable control is independent verification.

High-risk decisions should require a process which cannot be satisfied merely by looking or sounding familiar. Depending on risk, that may include:

  • callback using a trusted directory;
  • approval through an authenticated internal system;
  • dual authorisation by independently verified persons;
  • confirmation of changed payment details through a separate channel;
  • transaction limits and cooling-off periods;
  • a pre-agreed escalation route for urgent exceptions;
  • cryptographic or platform-based authentication;
  • verified meeting invitations and participant controls;
  • alerts for unusual beneficiary, device or location data; and
  • a culture in which staff can pause a senior instruction without penalty.

A secret word is not a universal solution. It can be overheard, phished, shared or discovered in compromised communications. The control should authenticate the transaction and the authority to approve it, using context-independent information or a trusted system.

Build controls around the attack sequence

Organisations should test the complete path by which a synthetic-media fraud could succeed:

  1. Reconnaissance: public speeches, podcasts, social media, corporate filings, calendars or compromised mail reveal voices, faces, roles and transactions.
  2. Access: the offender spoofs or compromises a channel.
  3. Pretext: a plausible commercial or personal narrative is created.
  4. Synthetic confirmation: voice, video or imagery supplies apparent identity and urgency.
  5. Control pressure: secrecy, hierarchy or time pressure discourages checking.
  6. Execution: money, data, credentials or access are released.
  7. Concealment: messages are deleted, mail rules changed or the victim is kept engaged while funds move.
  8. Extraction: proceeds are dispersed or information is exploited.

A control mapped only to step 4 is fragile. Effective prevention interrupts several stages.

Board and senior-leadership questions

Boards should ask:

Exposure

  • Which decisions currently depend on recognising a voice, face, number or display name?
  • Which employees can release significant value or sensitive information?
  • What public audio and video exists for senior leaders?
  • Which current transactions would provide a convincing pretext?

Controls

  • Can a senior person bypass payment or disclosure controls through urgency?
  • Are changed bank details independently verified?
  • Does a high-risk instruction require confirmation through a trusted system?
  • Are exceptions recorded and reviewed?
  • Can staff challenge an instruction without reputational cost?

Detection

  • Are unusual login, device, beneficiary and payment events connected?
  • Can the organisation preserve meeting, telephony and messaging records?
  • Are fraud alerts tested against current synthetic-media scenarios?

Response

  • Who can contact banks and providers immediately?
  • Who controls evidence preservation?
  • Is there a legal and regulatory decision structure?
  • Has the response plan been exercised using a realistic scenario?

Assurance

  • Have controls been tested under time pressure and seniority pressure?
  • Did the test assess behaviour rather than merely staff knowledge?
  • Were lessons translated into system or process changes?

The strongest assurance does not ask whether staff attended deepfake training. It asks whether an apparently authentic instruction could still move money without independent authentication.

Failure to prevent fraud

For organisations within section 199 of the Economic Crime and Corporate Transparency Act 2023, a deepfake-enabled fraud may also expose weaknesses relevant to the corporate failure-to-prevent offence.

The analysis is not triggered merely because the organisation was deceived. The prosecution must prove the statutory elements, including fraud by an associated person intending to benefit the organisation or a person to whom services were provided on its behalf, subject to the statutory victim exception.

However, synthetic media can also be used by an employee, agent or other associated person to mislead customers, counterparties or regulators for commercial benefit. Examples could include fabricated customer communications, false executive approval, manipulated evidence of performance or synthetic endorsements.

The organisation’s reasonable-procedures analysis should therefore examine fraud committed both against it and for its intended benefit. Guide 2, Failure to Prevent Fraud: A Strategic Guide for Organisations and Senior Leaders, addresses the full section 199 framework.

Regulatory and reporting considerations

A single incident may engage several regimes. The correct response depends on the organisation, sector, data affected, transaction, systems involved and evidence available.

Potential issues can include:

  • reports to the organisation’s bank or payment provider;
  • notification to insurers;
  • reporting through the applicable national fraud-reporting service;
  • police or specialist law-enforcement engagement;
  • suspicious activity reporting where the statutory conditions are met;
  • FCA notification obligations for regulated firms;
  • personal-data-breach assessment and possible notification to the Information Commissioner;
  • contractual notification obligations;
  • disclosure to auditors, lenders or transaction counterparties; and
  • preservation or disclosure duties arising in later proceedings.

Reporting should be accurate about what is known and unknown. “Deepfake confirmed” should not appear in an external notification merely because a recipient believes the call looked unnatural. Conversely, an organisation should not minimise a credible compromise while waiting for certainty which may never be available.

Use disciplined language:

  • confirmed fact;
  • contemporaneous report;
  • preliminary technical indication;
  • working hypothesis;
  • unresolved issue; and
  • inference.

That vocabulary protects credibility and helps prevent an early assumption from becoming institutional fact.

Communications and reputation

Deepfake incidents create an unusual communications problem. Public denial by the impersonated executive may help prevent further loss, but premature detail can alert offenders, prejudice recovery, contaminate witnesses or create inconsistent accounts.

The organisation should decide:

  • whether other employees or counterparties are at immediate risk;
  • what minimum warning will help them authenticate future contact;
  • whether the impersonated person’s genuine channels remain trusted;
  • whether public material is feeding repeat attacks;
  • who approves external statements; and
  • how communications will distinguish confirmed facts from suspicion.

The response should not blame the recipient before the control failure is understood. A fraud which relies on hierarchy and urgency may reveal an organisational weakness, even where one employee made the final decision.

Common investigative failures

1. Focusing only on visual or audio artefacts

This neglects the compromised mailbox, payment trail, contextual intelligence and approval process.

2. Treating a detector score as expert proof

A percentage output is meaningless without the tool, version, validation, input quality and limitations.

3. Forwarding or converting the only copy

Transformation can strip metadata and alter the characteristics later examined.

4. Interviewing collectively

Group discussions contaminate recollection and can create a shared narrative.

5. Assuming the impersonated executive was the only target

The fraud may depend on compromised assistants, finance staff, suppliers or transaction advisers.

6. Resetting everything without preservation

Containment is necessary, but indiscriminate deletion can destroy access logs, messages, tokens and configuration evidence.

7. Announcing attribution too early

Infrastructure, accounts and beneficiary details do not automatically identify the controlling person.

8. Treating the employee as the control

“Be more vigilant” is not an adequate response where the process allows a recognised voice to override independent authorisation.

9. Looking only at fraud against the organisation

The same technology may have been used by an associated person to obtain business or advantage for it.

10. Letting the label drive the law

The investigation must prove the statutory offence, not the fashionable description.

A response framework

Control

  • Stop or trace the payment.
  • Secure affected accounts and channels.
  • Warn those at immediate risk through verified communications.
  • Establish decision ownership.

Preserve

  • Retain original media, messages and metadata.
  • Preserve access, meeting, telephony and payment logs.
  • Record the decision trail.
  • Identify provider-held evidence and retention risks.

Separate

  • Distinguish fact from hypothesis.
  • Separate recovery from investigation where needed.
  • Separate witness accounts.
  • Separate media authenticity from offender attribution.

Reconstruct

  • Map the attack sequence.
  • Identify the representations made.
  • Determine why they were believed.
  • Trace the transaction, disclosure or system action.
  • Test insider and account-compromise possibilities.

Assess

  • Identify possible criminal offences.
  • Consider corporate, regulatory, data and contractual exposure.
  • Decide the scope and status of the internal investigation.
  • Review privilege and reporting strategy.

Strengthen

  • Replace recognition-based approval with independent authentication.
  • Test urgent and senior instructions.
  • review exception and override data;
  • update training using the real control pathway; and
  • preserve evidence of the remedial decisions made.

Frequently asked questions

Is it a criminal offence simply to create a deepfake?

Not in every circumstance. Liability depends on what was created, why, how it was used and the applicable offence. Where synthetic media is used dishonestly to make a false representation with the intent required by the Fraud Act 2006, fraud may be committed. Other content and conduct may engage separate offences.

Must the prosecution prove exactly which AI model was used?

Not necessarily. The required proof depends on the offence and case theory. It may be possible to prove a dishonest false representation and the defendant’s participation without identifying the precise model. The model and generation records may nevertheless be important to provenance, attribution and intent.

Is a deepfake-detector result enough to prove that media is false?

It should not be treated as conclusive in isolation. Its reliability depends on the tool, version, validation, media quality and manipulation type. Expert analysis and the wider evidence may be required.

What should an organisation do first after a suspicious payment instruction?

Contact the relevant bank or provider through a verified channel, seek recall or tracing, secure affected communications, preserve the original material and establish a coordinated response. Do not wait for final media analysis before attempting to contain the loss.

Should the recipient be interviewed immediately?

A prompt, uncontaminated factual account can be valuable. The interview’s purpose and method should be planned, particularly if employee culpability, disciplinary action, privilege or regulatory exposure may arise.

Is calling the executive back sufficient verification?

Only if the callback uses independently held, trusted contact information and the wider approval process is appropriate to the risk. Calling a number supplied in the suspicious communication proves little.

Can an organisation prevent the risk by training staff to spot deepfakes?

Training helps, but visual and auditory detection is not a durable primary control. High-risk decisions should require independent authentication and appropriate authorisation.

Could a victim organisation face failure-to-prevent-fraud liability?

Being the victim of an external fraud does not itself establish the section 199 offence. A separate analysis is required of the associated person, intended benefit, underlying fraud and victim exception. Different facts may arise if an associated person used synthetic media intending to benefit the organisation.

Should the organisation make a public statement?

That depends on continuing risk, legal and regulatory duties, recovery strategy and the evidence. Any statement should distinguish confirmed fact from preliminary assessment and avoid prejudicing the investigation.

Final perspective

Deepfake fraud is often described as a detection problem. That description is incomplete.

It is a decision-authentication problem, an evidence problem and, sometimes, a governance problem. The synthetic voice or image supplies credibility. The fraud succeeds when credibility is allowed to become authority without an independent control.

The legal response should identify the human dishonesty. The investigation should reconstruct the entire pathway from pretext to payment. The organisation should preserve the original media and the decision trail. The remedial response should make the next high-risk decision depend on authenticated authority, not recognition.

Voice and video may support a decision. They should no longer authenticate it.

Voice and video may support a decision. They should no longer authenticate it.

Craig MacKenzie provides strategic advice through Forbes Solicitors to organisations and senior leaders dealing with suspected fraud, internal investigations, criminal and regulatory exposure, evidence preservation and engagement with investigators.

Request a confidential consultation

Do You Require Advice About Your Circumstances?

This material provides general information and is not a substitute for advice about a specific investigation or case.

Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:

craig.mackenzie@forbessolicitors.co.uk

07976 258 258

An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.

Related Guidance