Now imagine receiving a video call from that same person. You can see their face, hear their voice and watch them speak.
Would you automatically believe them?
That is the problem we are beginning to face with AI-generated voice and video deepfakes.
Artificial intelligence has made it easier to create convincing synthetic voices, images and videos. The technology itself is not necessarily bad. It has legitimate uses in entertainment, accessibility, education and content creation. However, criminals can also use it to impersonate real people and make fraudulent requests appear genuine.

The Federal Trade Commission warns that scammers can use voice cloning to make requests for money or information more believable. The FBI has also warned that criminals are using AI-generated voices, videos and fake profiles as part of fraud schemes.
That means the old rule of “I know the person’s voice, so it must be them” is no longer enough.
In this guide, I want to look at a better approach: identity-first security.
Instead of asking only, “Does this voice or video look real?”, you should ask a more important question:
“How can I independently verify that the person communicating with me is actually who they claim to be?”
What Are AI Voice and Video Deepfakes?
An AI deepfake is synthetic or manipulated media designed to make someone appear or sound different from reality.
A voice deepfake can imitate a person’s speech patterns and create audio that sounds like them. A video deepfake can manipulate a person’s face, expressions or speech so that the resulting video appears authentic.
The important thing to understand is that deepfakes are not always obvious.
Some older AI-generated videos contained strange facial movements, unnatural expressions or obvious visual errors. Modern AI tools can produce much more convincing results.
The FBI’s guidance on artificial intelligence notes that synthetic media can sometimes contain clues such as unnatural movement, unusual pauses, distorted facial features, awkward positioning or audio inconsistencies. However, you should not depend on spotting these clues alone.
Why?
Because the technology keeps improving.
A safer strategy is to make verification more important than visual or audio appearance.
Why Voice Alone Is No Longer Proof of Identity
For many years, a person’s voice was a useful informal form of identification.
If your mother called you, you probably knew it was her immediately. If your business partner called you, you recognised their voice.
AI changes that assumption.
The FTC has specifically highlighted scenarios where scammers can clone a loved one’s voice and use it to make an emergency request. A similar technique can target businesses by impersonating an executive or another trusted person.
This is why you should be particularly careful when someone contacts you unexpectedly and combines three things:
- A familiar voice or face
- An urgent request
- A demand for money, sensitive information or immediate action
That combination should make you slow down rather than act faster.
The Identity-First Security Rule
My preferred way to think about deepfake protection is simple:
Never make an important decision based on a single identity signal.
A voice is one signal.
A video is one signal.
A phone number is one signal.
A social media profile is one signal.
Even a familiar WhatsApp profile picture is only one signal.
When the consequences are serious, combine multiple independent signals.
For example, if someone calls asking you to transfer money, do not verify them only by continuing the call. End the call and contact the person using a phone number you already had before the suspicious conversation.
This approach is much stronger because the person trying to deceive you does not control the second communication channel.
1. Create a Family Verification Phrase
This is one of the simplest defensive measures you can introduce with people you trust.
Choose a private phrase or question that only your family knows.
You do not need to make it complicated. The purpose is simply to create an additional identity check during an unusual situation.
For example, your family could agree that an unexpected emergency request should trigger a private question that is not publicly posted online.
However, remember that a verification phrase should not replace independent contact. If something feels suspicious, contact the person through another known channel anyway.
2. Never Let Urgency Make the Decision for You
Scammers understand human psychology.
If you have time to think carefully, you are more likely to notice inconsistencies. Therefore, fraudulent messages often try to create pressure.
You may hear:
- “I need the money immediately.”
- “Don’t tell anyone.”
- “You have to do this right now.”
- “My phone is damaged, so use this new number.”
- “I’m in trouble. Please don’t call anyone else.”
Those statements do not prove that something is fraudulent. However, they are strong reasons to pause.
Urgency should increase your verification, not reduce it.
If you receive an unexpected financial request, take a few minutes to verify the identity independently.
3. Call Back Using a Known Number
This is one of the most useful habits for protecting yourself against voice deepfakes.
Suppose someone calls from a number you do not recognise and claims to be your friend. They sound exactly like your friend and tell you they have lost their phone.
Do not use the number they just gave you as your only verification method.
Instead, find the person’s existing number from your contacts and call it yourself.
You can also contact them through another established communication channel.
The important part is that you initiate the second communication.
The same principle works for businesses. If someone claiming to be a manager requests a payment, confirm the request through the company’s normal communication process.
4. Protect Your Main Email Account
Your email account can be more important than you realise.
If someone gains access to your email, they may be able to reset passwords for other services connected to it.
That is why deepfake protection should not stop at recognising fake voices and videos. You also need to protect the accounts that control your digital identity.
Use a strong, unique password and enable two-step verification wherever possible.
Google also supports passkeys, which can use your device’s screen lock, fingerprint or face authentication instead of relying entirely on a traditional password. Google says passkeys are designed to provide stronger protection against phishing.
You can review Google’s official recommendations in its account security guidance.
If you use your phone for work, banking, content creation or online business, account security becomes even more important.
For example, protecting your device and accounts should be part of the same strategy as protecting your personal files. You can also see our guide on how to password-protect files and folders on a Windows laptop.
5. Be Careful About What You Publish Online
Many people share large amounts of personal information publicly without thinking about how that information could be used.
Photos, videos, voice recordings and public social media posts can reveal information about you.
You do not have to disappear from the internet. However, you should think carefully about the information you make publicly available.
Ask yourself:
- Does this post reveal my full name and workplace?
- Have I shared my phone number publicly?
- Have I posted lots of clear videos of myself speaking?
- Have I revealed the names of my family members?
- Have I shared information about where I live?
- Have I posted details about my daily routine?
This does not mean that every public photo or video is dangerous. It simply means you should understand that information published online can be copied and reused.
If you create content online, this is especially important. Our guide to content creation in Nigeria discusses the opportunities available to creators, but creators should also think about privacy and digital identity as their online presence grows.
6. Do Not Trust Caller ID Alone
Seeing a familiar name or number on your phone can make a call feel legitimate.
But caller ID should not be treated as absolute proof of identity.
The same principle applies to social media accounts.
A familiar profile picture does not prove that the person controlling the account is actually the person in the picture.
That is why identity-first security focuses on independent verification rather than appearance.
7. Treat Video Calls the Same Way
Video can feel more convincing than audio because you can see the person’s face.
However, seeing someone’s face on a screen still does not automatically prove their identity.
If a video call involves an unusual financial request, sensitive information or an urgent decision, verify the request through another channel.
For example, if someone supposedly from your company asks you to change payment details during a video call, follow the company’s normal verification procedure instead of acting because the person appeared on camera.
This is particularly important for online businesses and remote teams. Our guide on managing remote teams with Trello and Slack covers some of the tools people use to work remotely. Those systems should also have clear procedures for approving important financial or administrative changes.
8. Create a Rule for Financial Requests
If you run a business, create a simple rule:
No important payment changes based solely on a call, voice note or video message.
For example, if someone requests that a supplier’s bank details be changed, require confirmation through an established process.
The same applies to personal transactions.
If someone suddenly asks you to send money, stop and verify.
This matters because AI does not need to create a perfect deepfake to cause harm. It only needs to make a fraudulent request believable enough for someone to act before thinking.
9. Secure Your Social Media Accounts
Your social media accounts are part of your digital identity.
If someone takes control of your account, they can potentially impersonate you to people who already trust you.
Enable two-factor authentication or passkeys where the platform supports them. Use a unique password and review logged-in devices regularly.
Also be careful with unexpected links and login pages.
Deepfake scams and traditional phishing can work together. A scammer may first impersonate someone you know and then send you a malicious link.
That is why basic cybersecurity knowledge remains important. You can read our guide to staying safe online in Nigeria for more practical digital-security habits.
10. Learn to Spot Suspicious AI Media—but Don’t Depend on It
It is still useful to know some common signs of synthetic media.
For video, you may notice:
- Unnatural facial movement
- Odd blinking
- Unusual lip synchronization
- Strange lighting or shadows
- Facial details that change between frames
- Awkward head or body movement
For audio, you may notice:
- Unnatural pauses
- Odd pronunciation
- Unusual changes in tone
- Robotic or inconsistent speech
- Background noise that does not match the environment
The FBI has identified several of these kinds of inconsistencies as possible clues when examining AI-generated media. However, these signs are not a reliable authentication system.
A sophisticated fake may not contain obvious errors.
Therefore, think of deepfake detection as one layer of protection—not your entire security strategy.
11. Verify Important Information Through a Second Source
Imagine receiving a video from a supposed company executive saying that the company’s payment account has changed.
Do not immediately transfer money.
Instead, verify the change through an established company channel.
The same principle works for personal situations.
If a friend sends an unusual request through social media, contact them through their normal phone number.
If a family member suddenly asks for money from an unfamiliar account, contact them separately.
If a supposed bank representative contacts you, use the bank’s official contact method rather than relying on the details provided in the unexpected message.
This is the heart of identity-first security:
Verify the person independently, not just the message they sent.
12. Don’t Overshare Personal Information With AI or Unknown Apps
Deepfake protection also requires thinking about where you upload your information.
Before uploading photographs, recordings or personal documents to an unfamiliar website or application, understand what the service does with that information.
Ask:
- Who operates the service?
- Why does it need my information?
- What does its privacy policy say?
- Can I delete my information later?
- Is the service reputable?
This is particularly important when an app requests access to your microphone, camera, contacts or large collections of personal files.
Convenience should not automatically win over privacy.
What Should You Do If You Suspect a Deepfake Scam?
First, stop the conversation.
Do not send money. Do not provide passwords. Do not reveal verification codes. Do not share sensitive personal information simply because the person sounds or looks familiar.
Next, independently contact the person or organisation being impersonated.
If money has already been sent, contact your financial institution as quickly as possible and explain that you suspect fraud.
Preserve relevant evidence such as messages, usernames, phone numbers and transaction information. Do not rely on the suspicious caller or account to provide the correct reporting channel.
You can also report relevant fraud through appropriate authorities and platforms.
The FBI’s scams and safety resources provide general information about recognising and reporting fraud, while the FTC also provides consumer guidance about impersonation and voice-cloning scams.
A Simple Deepfake Protection Checklist
You don’t need to become a cybersecurity expert to improve your protection.
Start with these habits:
- Pause: Don’t act immediately because someone creates urgency.
- Verify: Contact the person through an independent channel.
- Protect: Use strong passwords, two-step verification and passkeys where available.
- Limit: Avoid unnecessarily publishing sensitive personal information.
- Question: Treat unexpected financial or sensitive requests carefully.
- Check: Look for inconsistencies in suspicious audio or video.
- Confirm: Follow established procedures for business payments and account changes.
- Report: If you encounter fraud, preserve evidence and report it through the appropriate channel.
Deepfakes Are Changing What “Proof” Means Online
One of the biggest lessons from AI-generated media is that familiar appearance and familiar sound are no longer enough to establish identity.
That does not mean we should stop trusting everyone.
It means we should become smarter about how trust is established.
A convincing voice should not automatically authorize a payment.
A familiar face on a video call should not automatically authorize a password reset.
A social media profile should not automatically prove who is behind the account.
Instead, important decisions should rely on independent verification, secure accounts and established communication procedures.
This approach is useful whether you are a student, employee, freelancer, content creator, business owner or ordinary social media user.
Technology will continue to improve, and deepfake detection tools will continue to develop. The Federal Trade Commission has noted that there is no single solution that solves the problem of AI voice cloning. Prevention, authentication and detection can all play a role.
For everyday users, however, one of the most practical defenses is surprisingly simple:
Don’t let a familiar voice or face make the decision for you.
Verify the identity independently, especially when money, passwords, private information or important decisions are involved.
And as you continue improving your digital skills, you can explore more practical technology and cybersecurity guides here on Infolandia. If you’re interested in useful digital resources and books, you can also visit the Infolandia Bookstore.
Final Thought
AI is making digital communication more powerful, but it is also forcing us to rethink digital trust.
In the past, hearing someone’s voice might have been enough. Seeing their face might have been enough. Today, neither should automatically be treated as proof when something important is at stake.
The best defense is not paranoia. It is a simple habit of verification.
Pause. Verify. Then act.