Category: Synthetic Media & Impersonation

Evidence-led analysis of voice cloning, deepfakes, identity impersonation and manipulated media.

  • Can a Deepfake Detector Prove a Recording Is Fake?

    Can a Deepfake Detector Prove a Recording Is Fake?

    A detector can produce a score. A score is not a verdict.

    CLAIM

    Uploading a recording or image to an automated deepfake detector can establish whether it is genuine.

    EVIDENCE

    NIST treats synthetic-content detection as one part of a wider authenticity problem. Its guidance also identifies provenance information—such as authenticated content credentials—and contextual evidence as relevant. Operational performance can deteriorate when detectors encounter unfamiliar generators, compression, editing or material outside their test conditions.

    A detector may therefore contribute evidence, but both false positives and false negatives remain possible.

    TEST

    Before accepting a detector result, ask:

    • What media type and manipulation was the system trained to detect?
    • Has the file been compressed, edited or re-recorded?
    • Is the result reproducible?
    • Does the provider disclose validation data and error rates?
    • Is the submitted material retained or used for training?
    • What independent evidence supports or contradicts the result?

    VERDICT

    A deepfake detector cannot, by itself, prove authenticity or fabrication. It can support an assessment when its scope, reliability and limitations are understood.

    ACTION — A BETTER AUTHENTICITY TEST

    1. Preserve the original. Do not begin with a social-media download if a higher-quality source exists.
    2. Trace provenance. Identify the earliest available source, acquisition route and any content credentials or metadata.
    3. Check context. Does the claimed event appear in reliable independent reporting, official records or other contemporaneous material?
    4. Verify the person independently. For a live payment or instruction, contact the supposed sender through an established channel.
    5. Use technical tools cautiously. Record the tool, version, settings, result and file tested.
    6. Seek specialist examination where stakes are high. A consumer web detector is not a substitute for a competent forensic process.

    WHAT A DETECTOR RESULT CAN SAY

    At most: “This system assessed this submitted file, under these conditions, and returned this result.” It cannot automatically establish the identity of the creator, intent, chain of custody or the truth of the underlying event.

    Primary sources


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Can You Trust This Voice Note?

    Can You Trust This Voice Note?

    What a business can and cannot prove from executive audio

    A voice message arrives from a senior executive.

    It sounds right.

    The cadence is familiar. The accent is right. The phrasing feels plausible.

    The instruction is urgent: process a payment, change a bank detail, send credentials, call a new number.

    The natural reaction is to ask:

    Does this sound like them?

    That is now the wrong question.

    The better question is:

    What independent evidence proves that this message actually came from them?

    That distinction matters because synthetic voice technology has moved the problem from “spot the fake” to verify the identity.

    The FBI now explicitly warns that AI-generated voice messages are being used to impersonate trusted people, including senior officials, and says recipients should not assume a message is authentic simply because the voice appears familiar.

    The FTC gives similar advice to consumers: if a caller sounds like someone you know but asks for urgent money, do not trust the voice alone. Independently contact the person using a number you already know.

    This investigation asks a narrower professional question:

    Can a business reliably authenticate an executive voice note from the audio itself?

    CLAIM

    The claim under examination is simple:

    “This voice message was recorded by the executive whose voice it resembles.”

    That claim may feel persuasive.

    But resemblance is not authentication.

    A convincing recording tells us that the audio sounds like a person. It does not, by itself, establish who created it, when it was created, whether it was manipulated, or whether the message was sent by the person being imitated.

    EVIDENCE

    A typical suspicious voice message may provide several forms of evidence:

    • the audio itself;
    • the phone number or messaging account that delivered it;
    • file metadata;
    • the wording of the request;
    • timing and context;
    • previous communications;
    • the recipient’s familiarity with the speaker;
    • any related emails, invoices or approval messages.

    The mistake is to treat all of these as equal.

    They are not.

    The strongest evidence is usually independent provenance: a known communications channel, independently confirmed sender identity, authenticated account history, or a separate confirmation from the purported speaker.

    The weakest evidence is often the thing people instinctively trust most: the sound of the voice.

    That is no longer enough.

    TEST 1 — “It sounds exactly like them”

    The FBI says AI-generated content has advanced to the point that it can be difficult to identify and that cloned voices can sound nearly identical to the real person.

    The FTC has also warned that voice cloning can be created from short audio samples obtained from public material and used in fraud against families and small businesses.

    Voice similarity is an indicator of resemblance, not proof of identity.

    A familiar voice may increase plausibility.

    It does not independently authenticate the sender.

    Verification finding
    Verification grade: V4 — Inconclusive

    TEST 2 — Listen for glitches

    Public guidance often suggests listening for:

    • unnatural pauses;
    • odd rhythm;
    • robotic delivery;
    • pronunciation errors;
    • strange breathing;
    • latency;
    • unusual word choice.

    Those indicators may still be useful.

    But they are weak negative evidence.

    An obvious defect can increase suspicion.

    The absence of a defect does not establish authenticity.

    The FBI itself cautions that cloned voices may sound almost indistinguishable from legitimate speech.

    Detecting an artefact may help identify a suspicious recording. Failing to detect one does not prove the recording is genuine.

    Verification finding
    Verification grade: V3 — Indicative only

    TEST 3 — Check the phone number or messaging account

    This is stronger than listening to the voice, but still not decisive.

    Ask:

    • Is this the executive’s normal number?
    • Is the message from their established account?
    • Has the number changed recently?
    • Did the conversation begin through an unexpected channel?
    • Does the account history look normal?
    • Is there a sudden move from email to WhatsApp, Signal or another service?

    The FBI specifically recommends independently researching the originating number and then contacting the purported sender through a separately established channel.

    Even a familiar number is not absolute proof. Accounts can be compromised and caller identity can be spoofed.

    A recognised channel increases confidence but should not override unusual payment or access instructions.

    Verification finding
    Verification grade: V2–V3 depending on corroboration

    TEST 4 — Examine context

    Context is often more useful than audio analysis.

    Questions include:

    • Is the request normal for this executive?
    • Is the amount unusual?
    • Is there pressure to act immediately?
    • Is normal approval being bypassed?
    • Has confidentiality suddenly been requested?
    • Are bank details changing?
    • Is the sender discouraging independent confirmation?
    • Does the request fall outside normal hours or normal process?

    Fraudsters regularly use urgency, authority and secrecy because these reduce the chance that a recipient will independently verify the request.

    FTC guidance repeatedly highlights urgency and secrecy as warning signs in impersonation fraud.

    Context can materially increase or reduce risk, but still does not independently establish authorship.

    Verification finding
    Verification grade: V3 — Indicative

    TEST 5 — Independently contact the executive

    This is the decisive control.

    Do not reply using contact information supplied in the suspicious message.

    Do not call a number introduced in the same conversation.

    Instead:

    1. use a known internal directory;
    2. call an established number;
    3. contact an executive assistant;
    4. use an authenticated corporate messaging account;
    5. require a second authorised approver where money or sensitive access is involved.

    This is essentially the verification method recommended by both the FBI and FTC.

    Independent confirmation through a known channel can move the assessment from suspicion to reliable authentication.

    Verification finding
    Verification grade: V1 — Verified, if the confirmation process itself is robust.

    VERDICT

    Can you trust a voice note?

    Not on the basis of the voice alone.

    The audio may be genuine.

    It may be synthetic.

    It may be edited.

    It may be genuine audio delivered through a compromised account.

    Without independent corroboration, the recording should be treated as unverified.

    Our conclusion is therefore:

    A voice that sounds authentic should be treated as an identity claim, not as identity proof.

    That principle matters because the scale of AI-enabled fraud is no longer theoretical.

    The FBI’s 2025 Internet Crime Report recorded 22,364 complaints involving AI-related information and more than $893 million in adjusted losses. It specifically identified voice cloning as a tool used in business email compromise and distress scams.

    The FTC separately reported $3.5 billion in losses to impersonation scams in 2025, with business and government impersonation among the largest categories.

    Not all of those losses involved cloned audio.

    But they show why identity verification cannot depend on familiarity alone.

    ACTION

    The Verification Desk Executive Voice Protocol

    For any unexpected voice instruction involving money, credentials, bank details or sensitive information:

    1. Stop the transaction. Do not let urgency override verification.
    2. Preserve the message. Retain the original audio, sender details, timestamps and associated messages.
    3. Do not authenticate from voice similarity. “Sounds like them” is not sufficient.
    4. Examine the channel. Check whether the number or account is established and expected.
    5. Examine the request. Flag urgency, secrecy, unusual amounts, changed payment instructions or process bypass.
    6. Verify out-of-band. Contact the executive through an independently known corporate channel.
    7. Require dual approval for high-risk changes. Especially for bank-detail changes, new beneficiaries and high-value payments.
    8. Record the verification step. Document who confirmed, when, by which channel and what was confirmed.
    9. Escalate unresolved cases. If identity cannot be independently confirmed, the correct finding is: Inconclusive — do not act.

    Verification Desk finding

    Claim: The voice note came from the executive.
    Evidence: Voice similarity, sender channel and contextual indicators.
    Test: Provenance, channel history, contextual consistency and independent out-of-band confirmation.
    Verdict: V4 — Inconclusive until independently verified.
    Action: Do not authorise consequential action on voice evidence alone.


    Evidence before certainty

    The most important lesson is not that every suspicious recording is fake.

    It is that modern synthetic media has made familiarity a poor substitute for authentication.

    The correct professional response is not:

    “Can I hear anything wrong?”

    It is:

    “What evidence independently proves who sent this?”

    That is the standard The Verification Desk will apply.