In January 2024, a finance employee at Arup, the London engineering firm behind the Sydney Opera House, joined a video call with his CFO and several familiar colleagues. Every one of them was fake. By the time he called headquarters to double-check, he’d already completed 15 wire transfers totaling $25.6 million to accounts in Hong Kong. Nobody on that call was real — every face and voice had been built from public video and audio, the kind anyone can scrape off LinkedIn or a recorded earnings call.
That case is now the industry’s go-to example for a reason: deepfake fraud is genuinely surging, though it’s worth being skeptical of any single headline number — vendor reports each measure something slightly different, and figures ranging from “1,300% up” to “2,137% up” to “4x year-over-year” are all circulating simultaneously, often describing different metrics entirely (contact-center call attempts versus overall fraud-attempt share versus platform-specific incidents). What’s consistent across every major fraud-tracking firm — Sumsub, Pindrop, Keepnet Labs — is the direction and scale: deepfake fraud attempts have gone from a rare curiosity to, by Sumsub’s tracking, 6.5% of all fraud attempts globally, up from just 0.1% a few years ago. Deloitte separately projects GenAI-enabled fraud losses in the U.S. will reach $40 billion by 2027, up from $12.3 billion in 2023. Whatever the precise multiplier, the old advice for spotting a fake — “check for weird teeth” or “look for bad lighting” — genuinely doesn’t work anymore against current-generation models. Here’s what actually still works, in order.

Step 1: Verify the context before you look at a single pixel
Before analyzing anything visual, ask where this actually came from. Reverse-search a still frame, look for the original upload, and check whether other trusted sources are reporting the same thing. A huge share of viral fake or misleading video isn’t even a technical deepfake — it’s real footage stripped of context, or several real clips edited together to tell a false story. This step alone catches more manipulated content than any visual trick on this list, and it costs you nothing but a few minutes.
Step 2: If it’s a live call, stress-test it in real time
This is the single most effective defense against the exact scenario that hit Arup, and it works because real-time deepfakes are still computationally expensive to render well under sudden, unscripted conditions.
- Ask the person to turn fully to the side. Real-time face-swap technology has very little reference data to work with at a full profile angle — rendering frequently breaks down, blurs, or glitches at exactly this moment.
- Ask them to wave a hand in front of their own face. The swap can smear, flicker, or let the hand pass through in a way a real face never would.
- Change the lighting, or ask them to move toward a window. Inconsistent shadows are a reliable tell — in one documented deepfake of a public official, his facial lighting stayed completely static even as he supposedly moved past a window, which isn’t how light behaves in the real world.
Step 3: Watch the edges of the face, not the center
Most deepfake models are trained overwhelmingly on front-facing data, which means the failure points show up at the margins: ears that blur or disappear, a jawline that seems to float apart from the neck, and glasses that visually melt into the skin rather than sitting on top of it. If a face rotates toward profile at any point in the video, pause exactly there.
Step 4: Listen as carefully as you watch
Audio is frequently the weaker half of a deepfake, even when the visuals are convincing. Human speech includes natural, irregular breathing — AI-generated audio often either omits it entirely or inserts breath sounds at moments that don’t syntactically make sense. Mismatched acoustics are another tell: if someone is supposedly speaking outdoors in visible wind, but the audio sounds studio-clean and controlled, that gap is your signal.
Step 5: Check the small physical details generative models still struggle with
Zoom in on the parts of the image doing the most complex physical work. Jewelry tends to morph or vanish entirely as a head moves. Hair often renders as a single solid mass rather than individual strands catching light differently. Teeth can appear as one undifferentiated white block instead of natural, separated teeth. Skin frequently looks waxy and overly smooth, missing the pores and texture real 4K footage naturally captures. None of these are guaranteed tells on the best current models, but they still fail more often than people expect.
Step 6: Know what real detection software is actually checking for — and which tools to actually use
If you want a second opinion beyond your own eyes, several tools are built specifically for this. Worth a quick honest note first: some of the “best deepfake detector” rankings circulating online are published by the tools themselves ranking their own product first — that doesn’t necessarily mean the tool is bad, but treat any single “best of” list with the same skepticism you’d apply to a company reviewing itself.
- Intel FakeCatcher — one of the more technically rigorous options, built around analyzing photoplethysmographic (rPPG) signals: the subtle, involuntary shifts in skin color caused by a real heartbeat pushing blood through capillaries. Generative AI builds images from visual patterns, not biological systems, so a synthetic face typically lacks this signal entirely — which makes this one of the harder checks for a deepfake to fake around.
- Reality Defender and McAfee’s Deepfake Detector — consistently show up across independent, third-party comparison lists (not just self-published ones), alongside Intel’s tool, as more established options for real-time or browser-based detection.
- DeepfakeDetector.ai — a self-serve consumer tool offering 50 free checks a month across image, video, and audio: upload a clip and get back a verdict (Authentic, Likely Synthetic, or Inconclusive) plus a confidence score, no account needed.
- Imagera’s AI Video Detector — scans a clip across multiple forensic signals (temporal consistency, lip-sync alignment, frame-level artifacts) and can be paired with its companion image and audio detectors for borderline cases.
Whatever tool you use, treat a confidence score as a starting point for further investigation, not a final verdict — a low-confidence result means “look closer,” not “definitely fake” or “definitely real.” And avoid feeding a tool a heavily compressed, re-downloaded, or re-uploaded copy of a video; a degraded file produces a weak, unreliable result that’s easy to mistake for a genuine “can’t tell” verdict. Always use the highest-quality version of the source you can find.
Step 7: For anything involving money or urgency, verify out-of-band — no exceptions
This is the step that would have stopped the Arup fraud entirely, and it’s the one the U.S. Federal Trade Commission explicitly recommends: if a call, message, or video asks you to move money or share sensitive information, hang up and call the person back on a number you already had saved — never one provided in the same message or call. For families specifically, the FTC recommends agreeing on a shared code word in advance, known only to your real family, specifically to defeat voice-cloning and video-impersonation scams targeting relatives.
The bottom line
No single trick on this list is foolproof anymore — a Reddit-viral 2024 test by Arup’s own CIO, done out of curiosity with free, publicly available tools, took him roughly 45 minutes to build a passable deepfake of himself. The technical floor for “good enough to fool somebody” keeps dropping. What still works is combining several of these checks rather than relying on any one, and treating urgency — a request to act fast, send money, or skip your normal verification process — as the loudest red flag of all, regardless of how convincing everything else about the video looks.
Compiled and cross-checked against CNN Business, CFO Dive, the World Economic Forum, Sumsub’s Identity Fraud Report, Pindrop’s Voice Intelligence + Security Report, Keepnet Labs, Deloitte’s fraud-loss projections, the FTC’s public consumer guidance, and current 2026 deepfake-detection research — including a security-industry critique of vendor stat-shopping, which is why growth figures above are presented as a range with named sources rather than a single headline multiplier. If you believe you’ve been targeted by a deepfake-enabled scam involving money or sensitive information, report it to your bank immediately and to the PNP Anti-Cybercrime Group if you’re in the Philippines.