Deepfakes: How They Work, How They’re Used, and How to Spot Them

Authors: prof. Dr. Dimitar Bogatinov, prof. Dr. Ljupco Shosholovski,
Military Academy “General Mihailo Apostolski“- Skopje, an associate member to the University “Goce Delcev“ - Stip

Artificial intelligence can now put words in anyone's mouth — literally. A deepfake is a synthetic video, or audio clip generated or altered by AI to make a real person appear to say or do something they never did. What began as a novelty tied to face-swap apps has become one of the fastest-growing tools for scams, political disinformation, and identity fraud. [1][2]

Why this matters?

Deepfake fraud attempts have surged roughly 2,137% since 2022, now making up about 6.5% of all fraud attempts detected globally. [1] In 2026, one survey of 302 organizations found that 62% had already experienced a deepfake-related security incident, split between audio (41%) and video (35%) attacks. [2] The FBI's Internet Crime Complaint Center introduced a dedicated AI-fraud category, logging about $893.3 million in adjusted 2025 losses tied to AI-enabled fraud, with investment scams alone accounting for roughly 71% of that total and adults over 60 bearing nearly 39% of the losses. [3]

Voice-cloning tools such as Microsoft's VALL-E can replicate a person's voice from as little as three seconds of reference audio, while commercial platforms like ElevenLabs typically need around 10 seconds to a few minutes of sample audio to produce a convincing clone. [4][5] This technology has already fueled real-world scams, including a 2019 case where fraudsters cloned a CEO's voice to steal $243,000 from a UK energy firm, plus later cases in which synthetic executive voices and deepfake video meetings were used to authorize multi-million-dollar wire transfers. [6]

Illustration: AI voice-cloning scam call with robots around a smartphone screen

Deepfake fraud attempts have surged roughly 2,137% since 2022, now making up about 6.5% of all fraud attempts detected globally. [1] In 2026, one survey of 302 organizations found that 62% had already experienced a deepfake-related security incident, split between audio (41%) and video (35%) attacks. [2] The FBI's Internet Crime Complaint Center introduced a dedicated AI-fraud category, logging about $893.3 million in adjusted 2025 losses tied to AI-enabled fraud, with investment scams alone accounting for roughly 71% of that total and adults over 60 bearing nearly 39% of the losses. [3]

Voice-cloning tools such as Microsoft's VALL-E can replicate a person's voice from as little as three seconds of reference audio, while commercial platforms like ElevenLabs typically need around 10 seconds to a few minutes of sample audio to produce a convincing clone. [4][5] This technology has already fueled real-world scams, including a 2019 case where fraudsters cloned a CEO's voice to steal $243,000 from a UK energy firm, plus later cases in which synthetic executive voices and deepfake video meetings were used to authorize multi-million-dollar wire transfers. [6]

Illustration: AI face-swap example showing original and swapped faces side by side.

How Deepfakes Are Actually Used

Deepfakes fall into several categories, each with distinct techniques and risks. [10]

  • Video face-swaps and lip-sync manipulation — placing a real person's face or mouth movements onto fabricated speech, often fake political statements or celebrity endorsements.

  • Voice cloning — generating synthetic speech in a real person's voice for scam calls, fraudulent authorizations, or fake testimonials (for example, fake CEO or grandchild-in-trouble calls).

Red Flags You Can Spot Without Any Tool

  • Unnatural or absent eye blinking, since earlier deepfake models historically under-represent blink rate.

  • Lip movements slightly out of sync with the audio, especially on closed-mouth sounds paired with open vowels.

  • Blurring or a "halo" effect around the hairline, ears, or chin where a face overlay meets the original footage.

  • Flat, overly even speech rhythm with no natural breathing or hesitation sounds.

  • Inconsistent lighting direction between a face and its background, or warped background elements near the subject.

  • Teeth that look uniformly blurry or morph between frames.

Verification Tools to Help Confirm a Deepfake

Beyond visual inspection, a structured workflow combines several free and enterprise tools. Below are key platforms with short explanations and links you can click to test them.

‍ ‍

1. AI Aware Deepfake Detector (link): https://aiaware.io/deepfake-detector

‍ Multimodal detector that analyzes video, audio, images, and text for generative AI signatures, returning confidence scores and highlighting suspicious regions or segments.

‍2. Hive Detect (link): https://hivedetect.ai

‍Cloud-based API that analyzes video and images to identify AI‑generated and deepfake faces, returning per‑face classifications and confidence scores for synthetic media detection.

‍3. FotoForensics (ELA) (link): https://fotoforensics.com/

Forensics site that offers Error Level Analysis (ELA), highlighting regions with different compression levels that can reveal copy-paste edits or added objects in manipulated photos.

‍ 4. Forensically (link): https://29a.ch/photo-forensics/

‍ Browser-based forensic toolkit that provides clone detection, noise analysis, and JPEG ghost/ELA filters to spot duplicated regions and inconsistent noise patterns in images.

‍ ‍5.  InVID WeVerify Plugin (link): https://www.invid-project.eu/tools-and-services/invid-plugin/

‍Browser extension that extracts keyframes from online video, runs multi-engine reverse image searches, and offers basic forensic filters and metadata checks for social-media content.

‍ 6. C2PA Content Credentials Viewer (link): https://c2paviewer.com/

‍Tool that allow inspection of embedded Content Credentials metadata in media files, helping verify provenance and authenticated origin when available.

‍ 7.    AI or Not (link): https://www.aiornot.com/

‍ Browser-based app that lets users quickly check whether images or videos shared from other apps are likely AI-generated, returning instant AI/non-AI assessments on the device.

‍A Simple Deepfake Verification Workflow Anyone Can Follow

For deepfakes, the VERITAS Universal Verification Cycle becomes a focused, media‑forensics workflow:

‍ Identify → Gather Evidence → Technical Analysis → Cross‑Verification

1.       Identify the alleged event and medium

Clearly state what the deepfake is claiming (who is speaking, what they say or do, when and where it supposedly happens) and note whether you are dealing with video, audio‑only.

2.       Do a rapid SIFT pass on the clip

Before touching any detector, pause and run SIFT:

  • Stop and note emotional hooks (outrage, fear, “miracle” promises).

  • Investigate the source (who posted the media, how old the account is, whether it is verified).

  • Find better coverage by checking out reputable outlets for the same event.

  • Trace claims back to an original upload or official channel.

3.       Run targeted deepfake analysis with the right tools

Video deepfakes (face‑swap or lip‑sync):

  • Use the InVID WeVerify plugin to extract clear keyframes and run multi‑engine reverse‑image searches (Google, Yandex, etc.) to find the original footage.

  • Upload the full clip to AI Aware Deepfake Detector to get a deepfake probability score, focusing on face boundaries, blinking, and lip‑sync consistency.

  • For advanced cases, use the Hive Detect to classify each detected face as real or deepfake.

Audio deepfakes (voice cloning):

  • Submit the file to AI or Not to check whether the waveform looks AI‑generated, then compare the result against known genuine recordings of the speaker (interviews, podcasts, speeches).

  • Listen at normal and reduced speed for flat prosody, lack of breathing sounds, and unnatural phoneme transitions — all common voice‑clone artefacts.

Provenance for files that should be authentic:

  • Where available, inspect C2PA Content Credentials using a compatible viewer to check whether the file carries authenticated origin and edit history (e.g. newsroom or camera pipeline).

4.       Cross‑verify the scenario

A video or audio can be technically “real” but contextually fake. Check if the supposed event (speech, endorsement, incident) appears in trusted news archives or official channels; absence of any corroboration for a high‑impact claim is itself a strong red flag.

Practical Takeaways

Anyone confronted with a striking video or voice clip of a public figure should assume, by default, that deepfake manipulation is possible and pause before reacting or forwarding, especially when the content is emotionally charged or politically sensitive.

For everyday users and educators, a minimal deepfake check can be:

  • Video: InVID keyframes, then AI Aware or Hive for deepfake scoring.

  • Audio: AI or Not for synthetic‑audio likelihood plus listening for prosody and breathing anomalies.

For high‑impact material — claims that could affect elections, markets, security, or reputations — do not rely on any single detector or single source. Instead, require:

  • At least two independent deepfake tools (e.g. AI Aware + Hive, or AI or Not + a second audio detector).

  • Provenance checks via C2PA where technically feasible.

  • Independent confirmation of the underlying event from reputable newsrooms or official channels.

If this multi‑tool, multi‑source process leaves any major component classified as synthetic or uncertain, treat the entire deepfake clip as high‑risk content and avoid amplifying it in teaching, media, or social platforms.

References

  1. Zerothreat.ai. (2025, June 26). Deepfake attacks & AI-generated phishing: 2026 statistics. Zerothreat.ai. https://zerothreat.ai/blog/deepfake-and-ai-phishing-statistics

  2. Keepnet Labs. (2026, June 1). Deepfake statistics 2026: Verified benchmarks & risks. Keepnet Labs. https://keepnetlabs.com/blog/deepfake-statistics-and-trends

  3. DigitalApplied. (2026, July 3). Deepfake statistics 2026: Fraud and detection data. DigitalApplied. https://www.digitalapplied.com/blog/deepfake-statistics-2026-fraud-detection-data

  4. CompaniesHistory. (2026, January 16). Voice cloning security risk: Microsoft VALL-E and synthetic audio fraud. https://www.companieshistory.com/vall-e-statistics/

  5. ElevenLabs. (2026). Instant voice cloning (Documentation). ElevenLabs. https://elevenlabs.io/docs/eleven-creative/voices/voice-cloning/instant-voice-cloning

  6. Damiani, J. (2019, September 3). A voice deepfake was used to scam a CEO out of $243,000. Forbes. https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/