Deepfakes undermine trust. In today’s digital ecosystem, trust is not a soft value; it is functions as our operational infrastructure. When people can no longer trust what they see or hear, the foundations of commerce, governance, national security, and personal relationships start to erode. Generative AI has made that risk a reality.

AI is reshaping privacy and security. One of the most obvious and immediate effects is the weaponization of synthetic media. Hackers are now using generative AI to simulate voices and videos, resulting in deepfakes that can convincingly impersonate anyone. What used to require specialized skills, significant data, and time can now be done quickly and cheaply using publicly available tools. As a result, the threat landscape is asymmetrical, with attackers only needing to succeed once and defenders having to get it right every time.

Deepfakes have grown rapidly, transitioning from niche experiments to mainstream threats. In 2026, an estimated 900,000+ deepfakes are generated per month, up from approximately 140,000 in 2023, reflecting a massive increase in both quantity and quality of synthetic media.

The Expanded Attack Surface

Deepfakes are large-scale versions of traditional social engineering techniques. Voice clones trained on seconds of public audio can impersonate executives, family members, or officials during phone calls or live video broadcasts. Face-swap and lip-sync technologies allow for real-time video calls in which all participants except the victim can be synthetic. Documented cases already include multi-million-dollar wire transfers authorized after employees participated in video conferences with a deepfake “CFO” and colleagues. Phishing, business email compromise, romance scams, and political influence operations all use similar tactics.

This year, the Singapore Police Force (SPF) confirmed a case in which scammers used deepfake AI to impersonate senior government officials in a Zoom conference, defrauding one victim of at least S$4.9 million.

Deepfake AI created realistic video and audio of PM Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, MAS representatives, foreign officials (Canada’s Foreign Minister, UAE’s senior diplomatic adviser), and private-sector entities like BlackRock and the Dubai International Financial Center in the Zoom call. After the call, a lawyer-scammer requested funds from the victim.

The problem extends beyond finance. Non-consensual intimate imagery, fabricated political statements, and fake news disinformation content jeopardize democratic debate and personal safety. Because so much of our professional and personal interactions now take place via video platforms, accelerated by the pandemic-era shift to remote work, the attack surface has grown dramatically. Adversaries can obtain training data from public LinkedIn posts, conference talks, podcasts, and social media platforms. The dark web accelerates the spread of tools and techniques.

At the same time, artificial intelligence is a double-edged sword. Defenders can and must use it to detect anomalies, conduct behavioral analytics, authenticate in real-time, and respond automatically. The challenge is governance: without transparency, ethics, and controls, the technology that protects us can turn into a liability.

Why Detection Is Insufficient.

Current deepfakes frequently reveal subtle tells, such as stiff mannerisms, unnatural eye contact or blinking, flat or overly linear voice prosody, imperfect lip synchronization, inconsistent lighting or reflections, or delayed responses to unexpected prompts. These cues are helpful today, but the window is closing. Models are rapidly improving, and real-time systems are becoming increasingly difficult to distinguish with the naked eye and ear.

Watermarking, cryptographic provenance, commercial detection tools, and AI-versus-AI analysis are all effective technical countermeasures. None provide a 100 percent guaranty, especially given the volume of content circulating across platforms. Steganography and other embedding techniques increase the level of complexity.

While quantum computing is not an immediate threat to most organizations, it will eventually put a strain on existing cryptographic protections; post-quantum migration planning must begin now to ensure that data stolen today cannot be decrypted later.

Trust but verify: A practical cybersecurity framework.

The fundamental principle is timeless: trust but verify. Use it rigorously on people, processes, and technology.

• Establish your identity first. Before any high-stakes interaction, particularly one involving money, credentials, or sensitive decisions, confirm the person using an out-of-band channel you already trust (a known phone number, mutual connection, or previously established process). Do not rely entirely on a single video call or voice message.

• Conduct behavioral and contextual checks. Keep an eye out for natural reactions, hand gestures, eye contact, and unexpected responses to questions. Validate LinkedIn or other profiles over time by checking posting history, mutual connections, claimed employment, and consistency.

• Maintaining technical hygiene. Implement multi-factor authentication, strong unique passwords or passkeys, network segmentation, encrypted channels, and regular backups. Until proven otherwise, treat all new digital relationships as potentially synthetic.

• Organizational resilience. Extend Zero Trust principles beyond networks to include human interactions and supply chains. Train employees on deepfake risks in the same way that we teach them about phishing. Create clear escalation pathways for suspicious requests. Establish responsible AI governance to ensure that defensive tools are transparent and auditable.

• Strategic vision. Cybersecurity is no longer solely a technical or back-office function. It is a board-level business risk, a fiduciary concern, and a national security requirement. Organizations that treat trust as infrastructure, investing in both technology and human factors, will be better positioned to operate in an era of ubiquitous synthetic media.

Deepfakes are more than just a technological novelty or a future issue. They pose an active threat, capitalizing on the human tendency to believe what we see and hear. With the rapid advancement of generative AI, the quality and accessibility of these tools will only improve. The response cannot be entirely reactive. We require continuous adaptation, including better detection, stronger verification practices, resilient architectures, workforce awareness, and public-private collaboration on norms and standards.

We now live in the acceleration era, in which the convergence of AI with other emerging technologies will continue to transform privacy and security. Deepfakes demonstrate both the power and the peril. Organizations and societies that treat digital trust as the critical asset it has become will thrive, protecting it with the same rigor as they do financial controls, intellectual property, and critical infrastructure.

Seeing is no longer believing. Verification is the new standard for operating safely in the digital cyberspace.