Share This:

Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone.

According to the 2026 HYPR State of Passwordless Identity Authentication Report, 87percent of organizations have already encountered audio or video deepfakes in identity-based attacks. The barrier to creating them has fallen so dramatically that a non-technical individual can clone an executive’s voice in under 60 seconds and map a face onto a video template in three to five minutes. For MSPs, this is no longer a concern limited to large enterprises. It’s a threat their SMB clients face every day.

Why deepfakes are becoming harder to spot

“Deepfakes are now one of the most effective, scalable, and rapidly deployable weapons available to cybercriminals and nation-state actors alike,” says Bojan Simic, CEO of HYPR and a member of the FIDO Alliance. “The question is no longer whether deepfakes can be created convincingly, but how easily and cheaply they can be deployed at scale.”

The targets aren’t random. Mary Ann Miller, VP and Fraud Executive Advisor at Prove, is clear about who’s in the crosshairs: “Finance teams, executives, and help desk staff are often common targets because they can authorize payments or reset accounts.”

The attack surface is expanding rapidly. Simic notes that visual cues, once a reliable way to spot suspicious activity, are no longer trustworthy. “Techniques that once exposed fake identities, such as asking someone to move their hand in front of their face during a video interview, are no longer effective against today’s more sophisticated deepfakes.”

Trust but verify

Udaya Bhaskar Vemuri, a Senior Application Security Analyst, explains the impact on everyday business interactions. In many cases, in-person verification is back in style.

“Never approve sensitive requests such as money transfers, password resets, or sharing confidential information based only on a phone call, voice message, or video. Always verify the request through a second trusted method, such as calling a known phone number or confirming it through an internal messaging system,” Bhaskar says.

Or simply poke your head into the boss’s office and verify.

That habit is only part of the solution. All three experts say layered identity verification is the long-term fix. No single signal—whether a face, voice, or password—should authorize a high-risk action.

“The goal is to validate multiple factors within the same session, rather than just one signal,” Simic says. “While an attacker may manipulate one element, it’s much harder to compromise a trusted device, a biometric factor, and another independent verification mechanism at the same time.”

Building stronger identity defenses

Miller believes organizations must move from one-time authentication events to continuous identity signals. “Organizations need to trust signals across the customer journey rather than relying on a single authentication event,” she says. “Non-human identities, AI agents, and automated interactions are introducing new risks that many businesses are still unprepared for.” MSPs should also take her warning about the deepfake arms race seriously. “Expect these deepfakes to learn and get better, and if they do, it could affect some of your security routines. Make sure there are multiple layers and signals, continuous trust, and identity.”

For MSPs building defenses for clients, the most effective steps fall into three areas:

First, technology. Organizations need strong identity verification, multi-factor authentication, approval workflows, and activity monitoring. Vemuri notes that even if a deepfake convinces someone, layered controls “can help stop an attacker from completing their objective.” Miller also recommends evaluating whether security vendors and identity platforms include deepfake detection capabilities and asking vendors how they’re keeping pace with emerging threats.

Second, process. Any request involving money movement, credential changes, or sensitive data should require verification through a separate communication channel. “One convincing voice or video should never be enough to authorize a high-risk action,” Vemuri says.

Third, people. Miller emphasizes training. “Ensure your security teams and your executives are educated about the sophistication of deepfakes. Don’t be naive about how sophisticated they are. Deepfakes can be very dangerous, and we can’t underestimate that.”

Preparing clients for what’s next

Miller also recommends that MSPs proactively test client defenses through fraud red-team exercises focused on AI-generated attack scenarios. “It’s important to recognize AI-generated attack patterns earlier so businesses can rethink identity in a world where both humans and machines participate in digital interactions.”

Vemuri offers a useful message for every client conversation: “The goal is not to teach people to distrust every call or meeting. It is to build simple verification habits so that one convincing voice or video is never enough to authorize a high-risk action.”

In a world where seeing and hearing can no longer be trusted, the habits and security architecture behind an interaction matter more than the interaction itself.

Photo: New Africa / Shutterstock


Share This:
Kevin Williams

Posted by Kevin Williams

Kevin Williams is a journalist based in Ohio. Williams has written for a variety of publications including the Washington Post, New York Times, USA Today, Wall Street Journal, National Geographic and others. He first wrote about the online world in its nascent stages for the now defunct “Online Access” Magazine in the mid-90s.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.