Deepfakes and the ‘New’ Phishing: Is That Actually Your Client on the Phone?
2026 is a turning point. You can no longer assume a familiar voice or face is real.
Your team has finally gotten good at spotting phishing emails. Great. Attackers move to channels you still trust.
Now the scam hits your phone, your Zoom calls, and your FaceTime requests.
1) Voice Cloning Is Here (Vishing)
Voice cloning can copy someone from seconds of audio. A voicemail greeting. A webinar clip. A past call.
That’s vishing (voice phishing). Plain language: they sound like your client or coworker and pressure you to act fast.
2) Real-Time Video Deepfakes Are Next
Real-time video deepfakes can impersonate someone on a live Zoom or FaceTime call.
If the request is “send money” or “share data,” your eyes and ears are not proof.
3) Stop Trying to “Spot the Fake.” Verify Instead.
Deepfakes keep improving. “Look for glitches” doesn’t scale.
Shift to verification-based protocols. Assume the channel could be compromised and prove the requester is real.
Practical Advice: The Frankel Protocol for High-Stakes Verification
In 2026, you can no longer afford to “trust your senses” during sensitive requests: voices, faces, and even live video can be spoofed. Your turning point is operational, not technical: standardize verification before incidents escalate.
Here’s the gold standard we recommend for any high-stakes request (money movement, banking changes, privileged access, sensitive data release):
- Pause. Treat urgency as a risk signal, not a reason to move faster.
- Hang up / end the call. Do not “verify” inside the same channel: not the same email thread, not the same phone call, not the same Zoom.
- Call back on a KNOWN, trusted number. Dial the requester’s direct office line or a saved mobile number you already have on file (or pulled from a trusted internal directory/CRM): never a number they provide in the moment.
- Confirm the specific action. State the exact request and require a clear “yes” (and, for your highest-risk actions, a second approval).
Why this works: while voices and faces are easy to fake, telephony routing to a specific, known number is much harder to manipulate at the scale most attackers operate. No system is 100% breach-proof, but this single habit reduces the risk of deepfake-enabled fraud more than any “spot the glitches” advice ever will.
Professional services firms have always been targets because of the sensitive information they handle and the trust their clients place in them. As cybersecurity services constantly evolve to address new threats, your internal protocols need to evolve too.
The firms that will weather this transition successfully are the ones that implement this Frankel Protocol now: before deepfake phishing becomes as common as the email scams your team has already learned to spot.
Where Frankel Technology Services Fits In
We help professional services firms think through exactly these kinds of emerging risks. From evaluating your current security posture to implementing security awareness training programs that address modern threats, we can help you build the policies and habits that protect your firm and your clients.
If you're wondering whether your team is ready for the next wave of social engineering: or if you just want to talk through what "out-of-band verification" looks like in practice: let's have a conversation. We're here to help you stay ahead of what's coming.