Deepfake Attacks Keep Working Because We Keep Detecting Instead of Proving
Detection is a classification problem, and its error rate grows as the adversary improves. Cryptographic identity proof doesn't care how realistic the fake is, because it never relies on what someone looks or sounds like.
In 2025 the FBI’s Internet Crime Complaint Center logged 24,768 complaints of business email compromise, with $3.05 billion in reported losses out of $20.9 billion in total cybercrime losses, and its definition of the crime is explicit that fraudsters carry it out “by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications” (FBI IC3 2025 Annual Report). The security industry’s main answer has been better detection: train models to spot synthesized video, listen for artifacts in cloned audio, layer on liveness checks.
The problem is that detection is a classification problem, and classification error grows as the adversary improves. A detector is a model trained on yesterday’s fakes. A human is a colleague who trusts a familiar face. Both lose ground to the attacker every year. On episode 92, Jasson Casey, CEO and co-founder of Beyond Identity, framed the issue structurally: detection is reactive, always responding to the latest generation technique. Cryptographic identity proof is deterministic. It doesn’t care how realistic the fake is, because it never relies on what someone looks or sounds like.
This post is the deepfake half of that conversation: why “is this a deepfake?” is the wrong question, what a proof step actually proves, the three technologies that make it practical, and what a startup should change this quarter. The credentials half, how device-bound keys work and how to roll out passkeys without a company-wide password-reset day, is in Why Passwords Still Get Stolen: The Case for Device-Bound Credentials.
What happened on the $25 million Arup video call?
In early 2024, a finance employee in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House, received a message that appeared to come from the company’s UK-based CFO asking for an urgent, confidential transfer. He was suspicious, and rightly so. Then came a video call. The CFO was on it, and so were colleagues he recognized. He set his doubts aside and, over the following week, made 15 transfers to five local bank accounts totalling HK$200 million, about US$25.6 million (Fortune, reporting Arup’s confirmation in May 2024). Hong Kong police believe the fraudsters downloaded footage of real, earlier online meetings and used AI to add fake voices (The Register). The fraud surfaced only when the employee contacted head office in the UK.
Two details matter more than the number. First, nothing was hacked. Arup’s statement was precise: “fake voices and images were used,” and “none of our internal systems were compromised.” Rob Greig, Arup’s CIO, called it “an industry, business and social issue.” Second, the human check worked exactly once, at the message, and then the verification step, the video call, was the thing being faked. Detection did its job at the stage the attackers had already stopped relying on, and failed at the stage they had invested in.
That is a story about a control, not about a careless employee. A meta-analysis of 56 studies published in December 2024 found that people correctly identify deepfakes 55.5% of the time overall, with a confidence interval that crosses 50%; for video specifically, 57.3% (Diel et al., Computers in Human Behavior Reports). A coin is a competitive deepfake detector. The Arup employee was not unusually bad at spotting fakes. He was average, and average is the problem.
Why is deepfake detection the wrong question?
Casey’s objection is structural rather than technical:
“The industry jumped on ‘is this a deepfake?’ as a problem. But that’s the wrong question.”
Jasson Casey, CEO and co-founder of Beyond Identity, on episode 92
Detection, whether by a model or a person, looks at an artifact and decides whether it is real. That framing loses for three reasons, and none of them is fixable with a better model.
The classifier learns yesterday’s fakes. Australia’s national science agency, CSIRO, tested 16 leading deepfake detectors in 2025 and found that “many current detectors struggle when faced with deepfakes that fall outside their training data”; a detector trained on celebrity faces was significantly less effective on ordinary people (CSIRO). Every new generator resets the training set. The defender retrains and redeploys. The attacker downloads the next model.
The economics run the wrong way. Casey again: “You can generate a voice in seconds. Proving it’s real is the hard part.” Generation gets cheaper with every release, while the cost of verifying a face or a voice stays flat. When one side’s cost drops every quarter, the other side does not win by trying harder.
Detection assumes you are already in the meeting. By the time a control asks “is this real?”, the attacker has chosen the channel, the moment, and the pretext. You are grading their work on their terms. Casey’s one-line version of the whole problem: “The real problem isn’t deepfakes, it’s proving what’s real.”
The alternative asks a different question, one with a checkable answer. Detection asks “is this real?”, and that gets harder every year. Proof asks “can this device produce a valid signature over this action?”, and that has a mathematically verifiable answer that does not degrade as AI improves.
What does “prove, don’t detect” actually prove?
Casey’s shorthand for the alternative:
“Trust isn’t about detection. It’s about verification.”
Jasson Casey, Beyond Identity, episode 92
A proof step has three parts, and it pays to be concrete about them, because “we have MFA” or “we use Face ID” usually means only the first.
Prove the person. A private key is generated inside the secure hardware of a device (a TPM on a PC, the Secure Enclave on Apple hardware) and registered to one employee. When that person approves something, the device signs a challenge and the server checks the signature against the public key it already holds. NIST’s Digital Identity Guidelines, finalized in July 2025, spell out the assurance ladder: at AAL2, verifiers “SHALL offer at least one phishing-resistant authentication option,” and at AAL3 the authenticator “SHALL have a non-exportable private key and SHALL provide phishing resistance” (NIST SP 800-63B-4). The same document rules that biometrics “SHALL only be used as part of multi-factor authentication with a physical authenticator.” The face was never supposed to be the proof; the thing you hold is. How those keys work, and why device-bound beats synced for workforce access, is covered in the device-bound credentials post.
Prove the device. The hardware can attest that the key was born inside it and never left, and the endpoint can report its posture: disk encrypted, EDR running, OS patched. That turns “someone with the CFO’s credentials” into “the CFO’s managed laptop, in a healthy state, right now.”
Prove the action. This is the part most companies skip. An identity check at login says nothing about what happens twenty minutes later on a video call. Casey’s point on the episode is that identity is a property of the action, not only of the session: sending an email and committing code are different risks for the same person on the same day, and most systems treat them identically because both sit behind the same login. Approving a wire belongs in the high-risk column. A signed approval binds the person and the device to this amount, this destination, this moment. Replay it tomorrow against a different account and the signature fails.
Put the three together and the attacker’s job changes shape. To move HK$200 million out of Arup they would have needed the CFO’s own unlocked laptop, not the CFO’s face. That is the kind of contest Casey says you should design for: “You want unfair fights. You only want to show up where it’s almost impossible for you not to win.” His preference for prevention over post-mortems comes from the same place: “Instead of doing the root cause analysis of the event, we much rather prevent the event from happening in the first place.”
Which three technologies make identity proof practical?
None of this is speculative. Three technologies, each mature on its own, converge to make “prove, don’t detect” something a sixty-person company can deploy.
Device-bound keys (FIDO2 passkeys and PKI). The private key lives in the TPM or Secure Enclave and never transmits; only signatures leave. Because the browser presents a passkey only to the site it was registered for, a look-alike domain gets nothing. Had each participant in the Arup call been required to approve the transfer through a challenge signed by their own registered device, the deepfake video would have been irrelevant; the attacker would have needed physical possession of each person’s device. This is the same architecture that removes credential theft, and the rollout and recovery details live in the device-bound credentials post.
Verified device posture (continuous device trust). Attestation at registration, posture at each sensitive action, so the healthy device that signed in this morning is the one signing the wire this afternoon. Casey describes on the episode an AI agent that was reaching services it had no business touching, where nobody could answer the basics: which user, which device, what posture, what permissions, for how long. If your agents have started initiating or approving things, the same proof applies to them, which is where least privilege for agents and an AI access-control audit come in.
Signed actions and signed media (transaction signing and C2PA). The approval carries a signature over its own contents. On the media side, the Coalition for Content Provenance and Authenticity publishes an open standard (currently version 2.3) for Content Credentials, signed provenance attached to an image or video at capture and through each edit, which it describes as “a nutrition label for digital content”; the steering committee includes Adobe, Google, Microsoft, OpenAI, the BBC and Sony (C2PA). Detection inspects pixels after the fact; provenance signs them up front. Adoption is uneven and unsigned content will be around for years, so treat C2PA as a tool for decisions that depend on a specific piece of media, and sign the approval itself for everything else.
Casey’s test for any control is whether it holds up when someone serious pushes on it, and he offered one data point from his own company: “We’ve had a couple of run-ins with state actors and our product performed.”
Where does deepfake detection still belong?
Everywhere except the gate. Detection is a useful signal: a liveness score that flags a call for review, a mail filter that notices the CFO’s “confidential and urgent” phrasing, an anomaly model that sees five new beneficiary accounts in a week. Signals should reach people who can act on them, which is why we pair identity work with 24/7 monitoring and response instead of letting alerts age in a dashboard. What a signal should never do is carry the decision alone, because the moment a signal is the last line, the attacker only has to beat the signal.
The attackers, meanwhile, are automating. Reconnaissance, pretext, voice, video and the follow-up email can now come from agents that run the attack end to end, and we wrote about the week the hypothetical era of AI attacks ended in AI Agents Are Now on Both Sides of the Breach. Casey is unbothered by the novelty:
“We now have AI in our bread, we have AI in our toothpaste. It’s a new game but all the same injuries.”
Jasson Casey, CEO and co-founder of Beyond Identity, episode 92
The injuries are the same because the weakness is the same: a decision that rests on recognizing a face, a voice or a password. Move the decision onto a signature and the new game stops mattering. As he put it, “In a world of AI, ‘who am I talking to?’ becomes the hardest question,” and a proof step is how you make it the easiest one instead.
One more place the proof has to live: the browser tab where the approval happens. Or Eshed’s argument in Enterprise Browser Security, that the browser rather than the network is where the last mile of control now sits, applies directly. The wire approval is a web form, and that form should know which device it is running on.
What should a startup do about deepfake fraud this quarter?
You do not need Arup’s budget, and you should not start with a deepfake-detection vendor. Start with the decisions.
- List every decision your company makes on a face or a voice. Wire approvals and vendor bank-detail changes. Payroll changes. Password and MFA resets at the help desk. Production access granted because “the CTO asked on Slack.” Contracts signed after a video call. The list is usually longer than expected, and most of it lives in finance and IT.
- Move the money decisions behind a signed approval first. Any payment above a threshold, and any change to where money goes, requires an approval signed from a registered, managed device by a named approver, with a second approver above the threshold. If your banking or payments platform supports step-up authentication and dual control, turn both on; if it doesn’t, that is a vendor conversation worth having this quarter.
- Make finance, admins and founders phishing-resistant now. FIDO2 security keys or device-bound passkeys for every account that can move money or grant access, with SMS codes retired for those accounts. This is step two of the four-step rollout, and it is the fastest of the four.
- Rewrite the callback rule. A callback is still a voice check, but it is a voice check on a channel the attacker did not choose. Call a number from your own records, never one in the message, and treat “I’m in a meeting, just send it” as a no. Then put a date on retiring the callback in favor of a signature.
- Rehearse with the deepfake in the room. Run a tabletop where the “CFO” on the call is a clone and the finance lead has to decide. The purpose is to find which approvals still route through recognition, not to test whether people can spot the fake. They can’t, and neither can you.
- Decide who owns it. Identity work spans IT, finance and engineering, which is exactly why it stalls. Whether that owner is in-house, on-demand, or nobody yet is a real decision; make it on purpose.
Casey’s framing for the budget conversation is blunt: “If security doesn’t protect revenue, it won’t get prioritized.” A wire that never leaves is revenue protected in the most literal sense, and the same controls shorten your buyers’ security reviews, since account takeover and payment fraud show up in most enterprise questionnaires.
The decision: stop grading fakes, start signing approvals
The Arup employee did everything a detection strategy asks of a person: notice, hesitate, verify, then act once the verification looked right. The verification was the attack. A company that proves the person, the device and the action stops asking its people to outperform a model that improves every quarter, and starts asking the attacker to steal a laptop. That is an unfair fight, and you get to choose it.
If you want a second pair of hands on the design, which approvals move first, which identity-provider settings to change, how to make the signature invisible to the people who have to use it, our product security team builds exactly this alongside your engineers, and treats executive impersonation as the counter-espionage problem it is. If you would rather hear the argument from the person who built a company on it, Jasson Casey makes it in 39 minutes on episode 92.
Deepfake detection vs. identity proof frequently asked questions
- Can deepfake detection tools reliably stop fraud?
- Not on their own. Detection is a classification problem, and the classifier is trained on fakes that already exist, so every new generator erodes it. When CSIRO tested 16 leading detectors in 2025, many struggled with deepfakes outside their training data, and a 2024 meta-analysis of 56 studies put human accuracy at about 55%, close to a coin flip. Use detection as a signal that flags a request for review, and put a cryptographic proof step in front of the decision itself.
- How did the Arup deepfake scam work?
- In early 2024 a finance employee in Arup's Hong Kong office received a message appearing to come from the company's UK-based CFO requesting an urgent, confidential transfer. He was suspicious until a video call in which the CFO and colleagues appeared; police say those participants were deepfakes built from footage of real past meetings. He then made 15 transfers to five local accounts totalling HK$200 million, about US$25.6 million. Arup confirmed no internal systems were compromised.
- What does 'prove, don't detect' mean for deepfakes?
- It means changing the question from 'does this face or voice look real?' to 'did the right person, on the right device, sign this specific action?' The second question is answered with a cryptographic signature checked against a key you already hold, so the answer is deterministic and does not degrade as fakes improve. A perfect deepfake of the CFO is irrelevant if the wire requires a signature from the CFO's own registered device.
- Does a passkey or biometric login protect against a deepfake video call?
- A biometric on its own does not. NIST's 2025 Digital Identity Guidelines say biometrics shall only be used as part of multi-factor authentication with a physical authenticator, something you have. A passkey stops credential theft and phishing, but a video call is not an authentication event, so the approval itself has to become one: a signed approval from a registered device, bound to the amount and destination, rather than a decision made on recognizing a colleague.
- What is C2PA, and does it help against deepfakes?
- C2PA is the Coalition for Content Provenance and Authenticity, which publishes an open standard for Content Credentials: cryptographically signed provenance attached to an image or video at capture and through each edit. It is the media-side version of prove-don't-detect, signing origin up front instead of inspecting pixels afterwards. Adoption is still uneven, so it helps most for decisions that depend on a specific piece of media; for payment approvals, sign the approval itself.
- What is phishing-resistant authentication, and why does it matter here?
- Phishing-resistant authentication uses a cryptographic key bound to the real site, so a look-alike page or a relayed one-time code gets nothing usable. NIST SP 800-63B-4 requires verifiers to offer at least one phishing-resistant option at AAL2 and requires a non-exportable private key at AAL3. It matters for deepfake fraud because most impersonation attacks end in a request to log in, reset a password, or approve something; a device-bound key removes the first two and makes the third signable.
- What should a startup do first about deepfake fraud?
- List every decision your company makes on a face or a voice: wire approvals, vendor bank-detail changes, payroll changes, help-desk password and MFA resets, production access granted over chat. Move the money decisions behind signed approvals from registered devices with a second approver above a threshold, give finance, admins and founders phishing-resistant MFA now, and rewrite the callback rule so the number comes from your records, never from the message. Then rehearse it once with a fake CFO on the call.