Artificial intelligence (AI) is changing the way we create and consume digital content. One of the most concerning applications is deepfake technology, which can use AI and machine learning to create or manipulate realistic-looking images, videos and audio recordings. Deepfakes can have legitimate uses in entertainment, education and creative industries. However, criminals can also use synthetic media to impersonate trusted individuals, spread false information, steal personal information and commit financial fraud.
For consumers and businesses, the biggest lesson is simple: seeing or hearing someone is no longer enough to prove that a communication is authentic. Canadian cybersecurity and fraud authorities have warned that criminals are using AI-generated audio and video to impersonate trusted individuals and make requests for money or sensitive information appear legitimate. Understanding how deepfakes work and knowing how to respond to suspicious communications can help you protect your identity, information and money.
A deepfake is digitally manipulated or AI-generated media that makes it appear as though a person said or did something they did not actually say or do.
Deepfakes can involve:
The technology is becoming increasingly sophisticated, which can make fabricated content difficult to identify simply by looking or listening.
Deepfakes can make traditional scams more convincing. A criminal doesn't necessarily need to convince you that an entire story is true. They may only need to create enough trust to persuade you to click a link, share a verification code, disclose personal information or send money. AI can help criminals personalize these scams and make impersonations more convincing. Canada's National Cyber Threat Assessment notes that AI-generated audio and visual content can help threat actors impersonate trusted individuals and persuade targets to disclose sensitive information or authorize fraudulent transactions.
One of the most important risks for consumers is financial fraud through impersonation. Imagine receiving a video call that appears to come from a family member asking for an emergency transfer. Or imagine hearing a familiar voice telling you that a financial transaction needs to be completed immediately.
The voice or video may look and sound authentic, but that does not necessarily mean the request is legitimate. Deepfake technology can be combined with other forms of social engineering, phishing and impersonation to create highly convincing scams. Canadian authorities have specifically warned about AI-generated voice messages and impersonation campaigns involving urgent requests for money or information.
Deepfake-enabled scams may involve:
The Canadian Anti-Fraud Centre has also warned about deepfake videos impersonating politicians, celebrities and news anchors to promote fraudulent investments, merchandise and applications.
Deepfakes can also contribute to the spread of misinformation and disinformation. A fabricated video of a public figure can be shared thousands of times before people have an opportunity to verify whether it is authentic. This can damage reputations, influence public opinion and make it more difficult for people to distinguish reliable information from manipulated content.
The Canadian Centre for Cyber Security identifies AI-generated deepfakes as one of the technologies that can contribute to misinformation and disinformation campaigns. The challenge is not simply that fake content exists. It is that convincing fake content can cause people to question legitimate information as well.
Your face and voice are increasingly part of your digital identity. Photos, videos and recordings posted publicly online can provide criminals with material that may potentially be manipulated or used as part of an impersonation attempt.
Deepfake technology can therefore become one component of a broader identity-theft or social-engineering attack. The Canadian Centre for Cyber Security identifies synthetic media—including video, audio and photos—as a potential tool for impersonating individuals or organizations and stealing sensitive information. This is another reason to think carefully about what personal information and media you share publicly online.
Investment fraud is another area where deepfake technology can be particularly dangerous. A scammer may create a fake video showing a celebrity, business leader, financial professional or other trusted person appearing to recommend an investment opportunity. The goal is to make the investment appear legitimate.
The Canadian Anti-Fraud Centre has specifically reported deepfake videos being used to promote fraudulent investment platforms and other offers.
Never invest simply because a familiar face appears to recommend an opportunity.
Before investing, independently research the company, investment and individual involved. Verify that the opportunity is legitimate using trusted sources rather than relying on the video or message itself.
Deepfakes can be difficult to identify, and visual clues are not always reliable. As AI-generated content improves, simply looking for unusual facial movements or poor video quality may not be enough.
Still, some potential warning signs include:
Canadian cybersecurity officials recommend watching for signs such as unnatural movements, mismatched audio, inconsistent lighting, unusual background noise and choppy speech—but also emphasize the importance of independently verifying unexpected requests.
The most important warning sign may not be the deepfake itself. It may be what the person is asking you to do.
You don't need to become an expert in artificial intelligence to protect yourself. Good cybersecurity and fraud-prevention habits remain your best defence.
If someone sends you an urgent request involving money, personal information or account access, don't rely on the communication itself to verify their identity. Contact the person or organization using a trusted phone number, email address or other contact method that you already have.
For example, if someone appears to be calling from your financial institution, end the call and contact the institution using the phone number on the back of your debit or credit card or another trusted source. Canadian authorities specifically recommend independently verifying unexpected requests through an alternate, previously confirmed channel.
Scammers want you to act before you have time to think.
Be especially cautious when someone tells you:
Urgency is a common social-engineering tactic. Take a moment to stop and verify the request.
Your password, one-time verification code and other authentication information should be treated as confidential. A legitimate organization should not ask you to disclose your password or authentication code so that someone else can access your account. If you receive an unexpected request for a verification code, don't provide it. Instead, contact the organization directly using trusted contact information.
Enable multi-factor authentication (MFA) or two-factor authentication (2FA) wherever it is available, particularly for email, financial and social media accounts. MFA provides an additional layer of protection if someone obtains your password. For businesses, Canadian authorities also recommend using multi-factor authentication on business email accounts as part of protection against payment-redirection fraud.
Think carefully about what you share publicly online. Photos, videos, your full name, workplace, family relationships, travel plans and other personal information can give scammers material for highly personalized social-engineering attempts. You don't have to remove yourself from social media. Instead, review your privacy settings and consider limiting access to personal content.
Don't assume an investment is legitimate because a celebrity, financial professional or public figure appears to endorse it. Research the investment independently and use trusted sources to verify the company and people involved. If an investment promises unusually high returns with little or no risk, requires immediate action or pressures you to send money, treat those as significant warning signs.
Businesses should be particularly cautious about requests to change banking or payment information. If a supplier, contractor, lawyer, client or other business contact sends new payment instructions, verify the change through an independent communication channel before sending funds. The Canadian Anti-Fraud Centre recently highlighted payment-redirection fraud involving fraudulent instructions and emphasized independently verifying payment changes before sending funds.
Use current versions of your operating system, applications and security software. Download applications from reputable sources and avoid installing software from unknown websites or links. Keeping your devices updated helps protect against vulnerabilities that criminals may use alongside social-engineering attacks.
One of the biggest changes brought by deepfake technology is that audio and video are no longer proof of identity on their own. If a request seems unusual, verify it using another method. A familiar voice can be cloned. A familiar face can be manipulated. A familiar email address can be spoofed. Trust should be based on verification—not appearance alone.
If you receive a suspicious message, call or video, don't respond by providing information or sending money.
Instead:
If you believe you have been the victim of fraud, reporting quickly can be important. The Canadian Anti-Fraud Centre notes that prompt reporting can improve the chances of recovering funds in some circumstances.
Deepfake technology is likely to continue evolving. As AI-generated content becomes more realistic, individuals and organizations will need to adapt how they establish trust online. The answer isn't to assume that everything we see or hear is fake. Instead, we should develop better habits for verifying important information. When money, personal information or account security is involved, take a moment to stop, question the request and verify it independently.
Deepfake AI can be used for legitimate creative and technological purposes, but criminals can also use it to make scams, impersonation attacks, misinformation and financial fraud more convincing. The best defence is a combination of awareness, skepticism and verification.
Don't rely solely on a person's face, voice, caller ID, email address or video to determine whether a request is legitimate. Be especially cautious when someone creates urgency or asks for money, sensitive information or changes to payment instructions. When in doubt, stop and verify using a trusted source.
For more honest money talk tips, follow YNCU on Instagram, Facebook, and LinkedIn.