Seeing and hearing are no longer enough to establish that digital media is authentic. Generative systems have reduced the cost of creating convincing images, voices and video, so “it looked real” is no longer a reliable test.
The operational lesson
A striking example came from engineering firm Arup. In 2024, an employee in Hong Kong was deceived into transferring about US$25 million after joining a video call in which people who appeared to be the company’s CFO and other colleagues were deepfake recreations. The attack succeeded because the people looked and sounded familiar. CNN — Arup deepfake scam case.
Why a detector is not enough
Detection tools are useful, but their performance can fall when media is compressed, resized, edited or generated by systems the detector has not seen before. Recent research has found substantial gaps between benchmark performance and difficult real-world synthetic imagery. Bhattacharjee et al. and Karageorgiou et al..
The more durable direction: provenance
Provenance shifts the question from “can I spot the fake?” to “can this content prove where it came from?” The C2PA standard supports cryptographically signed Content Credentials that can record origin and editing history. C2PA.
Provenance is not complete proof either: missing credentials do not prove something is fake. But it gives you another independent signal that does not depend only on visual judgement.
What to do with this
- Verify identity through a separate channel.
- Use known phone numbers rather than numbers supplied in suspicious messages.
- Use dual authorisation for important payments or transfers.
- Treat a familiar face or voice as a claim, not proof.
- Check Content Credentials and provenance where available.
- Use detectors as supporting evidence, not a verdict.
For practical workflows, see How to Verify an Image, How to Verify a Video and C2PA & Content Credentials.




