
By Milos Kral
PreClear Cybersecurity
For most of my life, there was a fairly reliable way to settle an argument about whether something really happened.
“Did you see it?”
If you saw it with your own eyes, that was pretty good evidence.
A photograph was even better.
Video? Case closed.
We even built the expression into our language:
Seeing is believing.
Artificial intelligence may be turning that phrase into an antique. And one finance employee learned that lesson in spectacular fashion.
In early 2024, an employee working in the Hong Kong office of a multinational company received a message that appeared to come from the company’s chief financial officer in the United Kingdom.
The message involved a confidential financial transaction. The employee was suspicious, which is important.
This wasn’t someone mindlessly clicking everything that appeared in an inbox. The employee reportedly suspected that the original message might be a phishing attempt.
That’s exactly what cybersecurity training tells us to do. Be skeptical, look for something unusual, don’t blindly trust an email.
Then came the video meeting.
And that’s where things became strange.
The employee joined a video conference with people who appeared to be company executives and colleagues. There was the CFO, there were familiar coworkers, there were recognizable faces, there were recognizable voices.
Imagine being in that position.
You receive a questionable email supposedly from your boss. You’re suspicious. Then you join a video conference and there is your boss, apparently sitting right there in front of you, other colleagues are there too.
At some point, most of us would probably think: Okay. Apparently, this is real.
The employee did, and ultimately authorized a series of transactions totaling approximately $25 million.
There was just one problem, the people in the meeting weren’t actually there, the employee was reportedly the only real participant.
The executives and colleagues appearing on screen had been digitally recreated using deepfake technology. Hong Kong authorities said the criminals apparently used publicly available video and audio of the people they were impersonating to construct the deception.
Think about that for a moment.
The employee apparently did something we tell people to do all the time.
Don’t simply trust the email. Verify.
So, the employee looked for stronger evidence, a face, a voice, a meeting, and the evidence was fake.
Welcome to the next trust problem
Deepfakes aren’t entirely new. We’ve seen fake celebrity videos, altered photographs and strange clips circulating online for years. Some were amusing. Some were obviously fake. Some were disturbing.
But this case represents something much more consequential. Artificial intelligence isn’t merely becoming capable of creating fake content, it’s becoming capable of creating fake trust.
That’s a very different problem.
Consider how many things you accept as real every day because you recognize the person involved; your daughter calls, you recognize her voice. Your boss appears on a video meeting; you recognize his face. Your accountant sends an email; it sounds exactly like something she would write. A friend sends you a photograph; there she is in the picture.
Historically, those have all been useful signals.
Now imagine that voice can be synthesized, the face can be recreated, the writing style can be imitated, the photograph can be generated. Suddenly, the question isn’t simply whether something looks authentic.
The question becomes: What actually proves that it is authentic?
That’s going to take some getting used to.
Your mother was right
Ironically, one of the best defenses against sophisticated artificial intelligence may be something your mother taught you when you were five: just because someone says something doesn’t mean it’s true.
We may simply have to expand that lesson.
Just because you read it doesn’t mean it’s true, just because you hear it doesn’t mean it’s true.
And increasingly: just because you see it doesn’t mean it’s true.
That doesn’t mean we should become paranoid.
I’m not suggesting that the next time Grandma calls, you demand a passport and two forms of identification before discussing Thanksgiving dinner. But when something unusual involves money, passwords, confidential information or access to an important account, we may need a second method of verification.
If your daughter calls saying she’s in trouble and desperately needs money, hang up and call her back using the number you already have.
If your bank contacts you about a problem, open the banking app yourself instead of using the link they sent.
If your boss suddenly asks you to transfer a large amount of money, follow the company’s established approval process—even if you’re looking at your boss on a computer screen.
In other words:
Don’t let the person asking for your trust also control the method you use to verify them.
The criminals don’t need perfection
There’s another important lesson buried in the $25 million story.
People sometimes imagine that a deepfake has to be absolutely flawless to be dangerous. It doesn’t. Neither does a phishing email. Neither does a telephone scam. The criminal doesn’t have to create something that would survive three weeks of forensic analysis. They only need to create something convincing enough for the few minutes in which you make a decision.
That’s an enormously lower bar.
And AI is getting very good at clearing it.
The Hong Kong case is especially revealing because authorities later said the fabricated conference appears to have been pre-recorded. There wasn’t even genuine interaction between the victim and the supposed executives. The meeting was convincing enough to establish credibility, and subsequent payment instructions continued through messaging.
That’s almost more unsettling than a Hollywood-quality live deepfake. The criminals didn’t need to perfectly recreate reality; they only needed to create enough reality to be trusted.
The five-second question
As artificial intelligence becomes more convincing, I think we’re all going to have to develop a slightly different relationship with trust.
Not distrust. Verification.
When something unusual happens, particularly when money or sensitive information is involved, give yourself five seconds.
Ask:
Was I expecting this?
Is this request normal?
Is someone trying to make me act quickly?
And most importantly:
Can I verify this another way?
Those questions won’t make deepfakes disappear.
But they move the decision away from: “It looked real.”
Toward: “I have a reason to know it’s real.”
That’s an important distinction.
Because we are entering a world our parents and grandparents never had to navigate, a photograph is no longer necessarily a photograph, a voice isn’t necessarily a person, a video meeting isn’t necessarily a meeting.
And the familiar old saying may finally need an update.
Seeing isn’t believing anymore.
Verifying is.
