Published on

Deepfakes and AI scams: how to spot them and protect yourself in 2026

Blog
  • Photo of Henrico Piubello
    Henrico Piubello
    Henrico Piubello
    IT Specialist - Grupo Voitto

    IT Specialist - Grupo Voitto

Cloning a convincing voice today takes a few seconds of public audio and no technical knowledge. The scam has not changed — it is still urgency, authority and secrecy — but the evidence that used to expose it, recognizing the voice of the caller, has stopped working.

What is a deepfake and why did it stop being a lab problem?

A deepfake is synthetic media generated by deep learning models to reproduce the image, voice or gestures of a real person. The technique is not new — it emerged in the late 2010s from generative adversarial networks — but it was expensive: it required hours of source material, powerful hardware and specialized knowledge.

Three changes brought that barrier down in just a few years:

  1. Less source material. Current voice-cloning models produce credible results from a handful of seconds of audio — an amount anyone with a story, a video or a recorded voice message has already made public.
  2. Real time. Face and voice replacement moved from post-processing to live video calls, which made meeting-based fraud viable.
  3. Interfaces for non-experts. What once required a command line became an app with a button. The bottleneck stopped being technical and became merely intent.

The result is a dangerous inversion of premise: for decades, hearing someone's voice worked as proof of identity. That premise is gone, and most verification processes — in families and in companies — have not been updated.

Practical example: a business owner received audio from his "son" asking for an urgent transfer after an accident. The voice was exact, with the right pauses and accent. The source material was thirty seconds of a public Instagram video.

What are the most common AI scams in Brazil?

Four formats account for most reported cases:

  1. Cloned relative's voice. A call or voice message simulating an emergency — accident, kidnapping, arrest — with a request for an immediate instant transfer. It exploits affection and haste; the typical victim is an older relative.
  2. Fake executive fraud. A video call where a "director" authorizes an urgent, confidential payment. The confidentiality is functional: it exists to stop the employee from confirming with someone else.
  3. Investment pitches with public figures. Videos of TV hosts, journalists and well-known entrepreneurs promoting investment platforms with guaranteed returns. They circulate as paid ads on social media and borrow credibility from the familiar face.
  4. Extortion with synthetic intimate images. Manipulated photos used for blackmail. Technically simple and personally devastating — and the guidance is always the same: do not pay, preserve the evidence and file a police report.

All of them share the same old social engineering. AI did not invent the scam; it removed the main warning sign people used to detect it.

Practical example: the most cited corporate case worldwide happened in Hong Kong in 2024: an employee at a multinational transferred roughly 25 million dollars after a video conference in which the finance director and other colleagues were all AI-generated. No technical control failed — what failed was the process that allowed a payment to be authorized without a second confirmation.

How do you identify AI-generated content?

There are useful hints, as long as you understand their limits:

SignWhat to look forReliability
Lip syncMouth out of time, especially on fast syllablesMedium, declining each generation
Face edgesShimmer or blur when the head turnsMedium
LightingFace shadows that do not match the sceneMedium
Blinking and micro-expressionsMechanical rhythm, no natural asymmetryLow today
AudioNo ambient noise, no breathing, flat intonationMedium
Hands and accessoriesFingers, glasses and earrings deforming in motionMedium in video
OriginWho published it, when, and what the official source saysHigh

That last row is the only one that does not age. Perceptual analysis is a losing race: each new generation of models eliminates the artifacts last year's guides taught you to spot — and the side effect is serious, because it creates false confidence in people who "know how to spot them".

Verifying origin always works. If a video shows a public figure announcing something extraordinary, does their official channel show it too? Did the press cover it? Does the posting account have any history? None of those questions depends on the quality of the model used.

Practical example: faced with a video of a well-known TV host promoting an investment platform, the check took twenty seconds: no mention on the official channel, no press coverage, account created two weeks earlier. Not a single pixel needed analysis.

How to protect yourself in practice — individuals and companies

Effective defense is procedural, because process does not depend on anyone noticing anything.

For individuals:

  1. Agree on a family code word. A word only the family knows, never published, required for any request for money by phone. It is the cheapest and most effective defense there is.
  2. Hang up and call back. Never continue on the incoming call. Call back on the number you have saved — the cloned voice does not control the other handset.
  3. Distrust urgency. Haste and secrecy are the signature of social engineering. There is no legitimate scam; a legitimate request tolerates five minutes of verification.
  4. Reduce the surface. Public profiles with a lot of audio and video make cloning easier. You do not have to disappear from the internet, but it is worth considering what stays open.
  5. Turn on two-factor authentication everywhere. Many AI scams are the second step after unauthorized access — multi-factor authentication cuts a good part of the chain.

For companies:

  1. Dual approval above a threshold. No single person authorizes a significant payment, regardless of the requester's title.
  2. Mandatory second channel. A request by video or audio is confirmed by another means, using a contact from the internal directory — never the one provided in the request itself.
  3. An explicit policy about urgency and secrecy. Put it in writing that no executive will ever request an urgent, confidential payment outside the standard workflow. That protects the employee from feeling awkward about verifying.
  4. Training with simulations. The same reasoning as a penetration test applies: a controlled exercise teaches more than a handbook.
  5. Treat voice and video as weak identifiers. In service desk systems, voice biometrics has stopped being a sufficient factor and needs a second one.

It is worth remembering that exposed personal data fuels these scams: the more information about relationships, routines and contacts circulates, the more convincing the approach — which is why the LGPD obligations on data minimization and retention have a direct security effect, not just a compliance one.

Practical example: a company that began requiring confirmation by registered phone number for any change to a supplier's bank details blocked an attempt in which the "supplier's finance team" called with a cloned voice asking to switch accounts. The process worked because it did not depend on anyone getting suspicious.

What does Brazilian law say about deepfakes?

There is no single deepfake law, but the set of applicable rules is already substantial:

  • Fraud (art. 171 of the Penal Code), including the electronic fraud modality, covers most financial scams using synthetic voice or video.
  • Crimes against honor — slander, defamation and insult — apply to false content that damages reputation.
  • Image and voice rights are protected by the Civil Code and the Constitution, allowing damages claims regardless of any criminal case.
  • Law 14.811/2024 toughened the treatment of crimes involving children and adolescents, including manipulated content.
  • Electoral law: the Electoral Court rules for the 2026 elections — art. 9-B of Resolution 23.610/2019, as amended by Resolution 23.755 of March 2026 — ban deepfakes in campaign propaganda, whether flattering or critical, authorized or not by the person portrayed. Any synthetic content used in a campaign requires explicit, prominent labeling of the manipulation and the technology employed. Non-compliance leads to immediate removal and a fine of R5,000toR 5,000 to R 30,000 under art. 57-D of Law 9.504/1997, plus the risk of losing candidacy registration or an elected mandate.

For citizens, the practical guidance if victimized is direct: preserve the evidence (original files, links, phone numbers, receipts), file a police report — cybercrime units exist in most states —, notify the bank immediately in case of a transfer and report the content on the platform where it is circulating.

Practical example: fake videos of public figures promoting investments are usually removed on the basis of unauthorized use of image — but the fastest route has been direct notification by the person portrayed or their representatives, since generic reports enter a moderation queue.

Conclusion

Deepfakes did not create a new category of crime: they eroded a verification signal society was using without noticing, the recognition of a voice and a face. That is why the correct response is not training people to spot odd pixels — that contest is lost with every new model version — but redesigning processes so that important decisions never depend on a single perception. A family code word, calling back on a known channel, dual approval for payments and an explicit ban on urgent, secret authorizations cover the overwhelming majority of cases, and none of them requires technology. In the public sphere, Brazil reaches the 2026 elections with clear rules — deepfakes banned in campaign propaganda and mandatory labeling of synthetic content — which helps, but does not replace the habit of checking the origin before sharing. Faced with any content that provokes urgency or immediate outrage, the useful question is no longer "does this look real?" but "where did this come from?".

## faq

Frequently asked questions

What is a deepfake?

It is synthetic audiovisual content created by artificial intelligence to reproduce the appearance, voice or gestures of a real person, making them appear to say or do something that never happened. The term combines deep learning and fake, and today it spans everything from elaborate videos to short voice-cloning clips generated in seconds.

How can you identify a deepfake video?

Possible signs include irregular blinking, face edges that shimmer during sharp movements, inconsistent lighting between face and scene, imperfect lip sync and audio with no ambient noise. But treat these as hints, not proof: model quality improves fast and the absence of artifacts does not mean authenticity. Reliable verification is about origin — who published it, where, and what the official source says.

How does the voice cloning scam work?

The criminal collects public audio of the victim — a story, a video, a podcast, a leaked voice message — and uses AI to generate new speech in that same voice. Then they call or send audio to a relative simulating an emergency and urgency, requesting an immediate transfer. The rush is part of the scam: it exists to prevent verification.

What is fake executive fraud with deepfakes?

It is the modern version of CEO fraud: instead of an email, the employee gets a video call with the image and voice of a superior authorizing an urgent, confidential payment. In 2024, a multinational in Hong Kong lost roughly 25 million dollars in a case where several meeting participants were synthetic.

Are deepfakes a crime in Brazil?

It depends on the use, and several legal frameworks already apply: fraud when there is financial deception, defamation and slander when reputation is attacked, violation of image and voice rights, and offenses under electoral law. Law 14.811/2024 increased penalties in cases involving children and adolescents, and the Electoral Court resolution bans deepfakes in campaign propaganda, with fines from R$ 5,000 to R$ 30,000 and risk of losing candidacy registration or an elected mandate.

How do I protect my company against AI fraud?

With process, not perception. Require dual approval for any payment above a threshold; adopt second-channel verification — hang up and call back on a registered number, never the one given in the call; forbid financial authorizations based on audio or video alone; and train the team with simulations. Workflows that depend on one person recognizing a voice are fragile by construction.

Topics in this article

## continue lendo

Keep browsing

About the author

Photo of Henrico Piubello

Henrico Piubello

IT Specialist - Grupo Voitto · Grupo Voitto

See profile and all articles