Your company hierarchy could be enabling deepfake fraud

Deepfake CEO fraud works because employees rarely question senior leaders. Verification built into processes, a culture that permits challenge and real-time detection close that gap.

4 min read
Read with AI

Open in

ChatGPT Claude Perplexity

This page

Copied to clipboard
Your company hierarchy could be enabling deepfake fraud

An urgent video call comes in from your CFO – they need a payment approved immediately. The transaction is sensitive, there is little time to discuss it and the person on screen looks and sounds exactly as they should. What would you do?

In February 2026, BBC Business Daily examined the case of British engineering firm Arup, where a finance employee in Hong Kong was deceived by a video call featuring deepfake versions of the company’s CFO and other colleagues. The employee went on to make 15 transfers worth around $25 million before the fraud was uncovered.

It is tempting to think we would have recognised the warning signs. But most employees have been trained to only look for suspicious links and unusual email addresses as obvious signs of phishing. Far fewer have been trained to question a senior executive speaking directly to them.

Gallagher’s 2026 research suggests the tactic is widespread. Half of UK organisations surveyed experienced at least one attempt to impersonate or deceive a senior executive in the previous year, often using the authority of CEOs, CFOs and other senior colleagues to pressure employees into authorising payments or bypassing controls.

Deepfake technology makes impersonation increasingly convincing, but it’s not the only thing that helps fraudsters. They are also taking advantage of the way people behave around authority.

Why authority changes how we respond

Psychologists have studied our relationship with authority for decades. Stanley Milgram’s well-known obedience experiments in the 1960s demonstrated how easily people could be persuaded to follow instructions when they believed those instructions came from someone in a position of power.

In his best-known study, participants were instructed by a researcher to administer increasingly severe electric shocks to another person. Some 65% continued to the maximum 450-volt setting when told to do so. The shocks were simulated, although participants believed they were real.

The experiment exposes the same instinct that helps deepfake fraud succeed. People appear to be less likely to challenge a request when it comes from someone they see as senior to them.

In a corporate setting, hierarchy still exists. Regardless of how flat the structure may appear, the CEO, chair or another C-suite leader remains an authority figure. When that person gives an instruction, particularly an urgent one, employees may focus on completing it quickly rather than questioning why they are being asked. That creates a vulnerability deepfake scams are designed to exploit: the more credible the authority figure appears, the less scrutiny the request receives.

Urgency makes authority harder to challenge

Authority becomes even more effective when combined with pressure. An instruction to ‘do this now’, ‘keep this confidential’ or ‘not involve anyone else’ reduces the time and permission an employee feels they have to question what is happening.

That’s where workplace culture becomes a security issue. Employees need to know that checking an unusual instruction from a senior leader is expected behaviour, even when the request appears urgent. If questioning the CEO feels professionally risky, fraudsters gain an advantage.

Senior executives should make it clear that sensitive requests can be challenged and independently verified, without employees fearing they will be criticised for doing so.

Build checks into the process

Individual awareness is critical, but businesses should avoid making employees solely responsible for spotting increasingly sophisticated deepfakes. Safeguards need to be built into normal processes.

For high-risk requests, organisations can require employees to confirm the instruction through another trusted channel or obtain a secondary approval before releasing funds or sensitive information.

Employees can then use a simple mental checklist before acting. Does the executive usually contact you directly? Is the request consistent with their role? Is the tone or phrasing unusual? Today’s deepfake technology can produce highly realistic voice and video, meaning distorted faces or other obvious flaws are appearing far less frequently. Mannerisms, language and context offer better clues.

Technology as another layer of defence

There is an obvious limitation to relying on human judgement alone. Even well-trained employees become distracted, rushed or intimidated, and deepfake technology will continue to become more convincing.

Technology provides another layer of protection.

You put on a seatbelt before you drive because you know the risk exists. It is a deliberate decision made in advance, so that when the moment of impact comes, protection is already in place. Deepfake detection must work in much the same way.

On-device, real-time detection can work during the conversation itself, providing another source of scrutiny when the person on the other end may not be who they claim to be. It does not hesitate or feel the weight of hierarchy.

Deploying those tools also sends a useful message internally. It shows employees that identifying fraud is a shared organisational responsibility, rather than a test they are expected to pass alone.

Deepfake technology will continue to improve, but fraudsters won’t need better tools if workplace behaviour is already doing part of the job for them. Businesses will be better protected when employees feel able to question senior requests and are equipped with the processes and technology to back them up.