Playbook ID: PB-DEEPFAKE | Default severity: SEV-3 (SEV-2 once a payment has been sent or a credential, MFA re-enrolment or access grant has been given up; SEV-1 if the target held a privileged role or synthetic media of a named executive is circulating outside the company) | Owner: Incident Commander
Open this playbook on: an employee reporting a call, voicemail, video meeting or voice note from an "executive" pressing for a payment, a credential, a gift-card purchase or an urgent exception; a service-desk contact requesting a password reset or MFA re-enrolment where the caller's identity rests on their voice, or a request deliberately split across two contacts — the CISA AA23-320A pattern; an approach that arrives on a channel the real person never uses (personal WhatsApp, a new mobile number, a meeting invite from outside the tenant); a participant on a video call whose audio, lip sync or lighting is wrong, or who will only appear on camera and never type; a synthetic audio or video clip of a named executive circulating externally; or a phishing wave with unusually fluent, well-targeted copy at volume and almost no shared indicators.
Not this playbook: a compromised mailbox sending real mail from a real account (14.2 PB-BEC — and if the deepfake succeeded and money left, run 14.2's money track in parallel from minute one); a completed identity-provider or privileged-credential compromise (14.4 PB-IDP); an attack against your own AI systems, agents or model supply chain (14.11 PB-AISYS); a genuine employee abusing genuine access (14.6 PB-INSIDER). The design of help-desk identity verification, and the phishing-resistant MFA program that makes a stolen reset worthless, belong to Chapter 4. Executive media exposure and workforce training sit in Chapter 19.
Someone will call your accounts payable clerk in your CFO's voice. Not a robotic approximation — the voice, with the pauses and the regional vowels, on a Tuesday afternoon, about an invoice that genuinely exists. The technology is a commodity; the target is not the technology, it is the moment where one junior person weighs their own doubt against apparent authority and picks authority.
The reference case is Arup's Hong Kong office: an employee received a phishing email impersonating the UK-based CFO, was sceptical, and had that scepticism dismantled by a multi-person video conference in which every other participant was AI-generated. About US$25.6 million left across 15 wire transfers in a single day (CNN). Three other named attempts failed, and how they failed is the whole of this playbook. WPP's CEO was impersonated through a WhatsApp account, a Teams meeting, a voice clone and stitched YouTube footage — stopped by an employee who did not buy it (OECD AI Incidents). A Ferrari executive challenged a voice clone of the CEO with a shared-secret question — a book the real CEO had recently recommended — that the clone could not answer (AI Incident Database). A LastPass employee flagged a voice clone of their CEO because the channel was wrong — WhatsApp, outside normal business communication — not because the audio sounded off (LastPass). Zero of those three were stopped by detection technology. Three of three were stopped by a human process check.
This is not a niche. Voice phishing was the #2 initial infection vector in 2025, at 11% of all Mandiant investigations (M-Trends 2026), and DBIR 2026 finds voice and text phishing convert better than email (Help Net Security). IC3 added "AI-related" as a formal crime descriptor for the first time in its 2025 report: 22,000+ complaints and roughly $900 million in losses (FBI). The written variant scaled too — Hoxhunt found AI-generated spear phishing went from 31% less effective than elite human red-teamers in 2023 to 24% more effective by March 2025 (Hoxhunt), and Microsoft assesses AI can make some phishing operations up to 50× more profitable (MDDR 2025). Keep the calibration honest, though, because it changes what you fund: Mandiant's conclusion from over 500,000 hours of 2025 response work is that 2025 was not the year breaches directly resulted from AI — most intrusions still stem from human and systemic failures, and Anthropic's mapping of banned malicious accounts found AI-assisted phishing actually fell 8.6% while post-compromise use rose (Anthropic). AI is a force multiplier on social engineering you already faced, not a new kill chain.
Which brings us to the mistake teams make, and it arrives as a purchase order. The instinct is to buy a synthetic-media detector and declare the problem handled. But that enters your people into a perception contest against a generator that improves monthly, with a stressed clerk as the classifier. Do not enter that contest. Actionable takeaway: stop trying to detect the fake and start verifying the request — a callback on a number from your own directory, a shared-secret challenge, dual authorization. The control is procedural, it is nearly free, and it works against a perfect fake.
| Role | Responsibility in this scenario |
|---|---|
| Incident Commander | Owns the "is this real?" determination and the tip-off timing; decides workforce broadcast; runs no queries. |
| Operations Lead | Preserves the media and platform records; runs the identity and campaign scoping; executes any revocation. |
| Communications Lead | Stands up the out-of-band channel; runs the workforce warning and, if media is public, the external statement. |
| Finance Lead (Controller/Treasury) | Payment freeze, beneficiary screening, bank recall — the money track in 14.2 Phase 2A. |
| Legal Liaison | Attaches privilege; approves law-enforcement filing and any external statement; owns the notification determination. |
| Impersonated Party (the executive or employee whose likeness was used) | Gives ground truth on the alleged request; approves use of their name in the warning; is a witness, never a suspect. |
| Scribe | Minute-by-minute timeline, including the moment the request was received and the moment it was doubted. |
| Executive Sponsor | Loss disclosure, insurer notification, materiality escalation, and the authority behind the refusal rule. |
The first fifteen minutes answer one question — did the request succeed — and preserve one artefact that has a short and unforgiving life. Voicemail boxes overwrite. Meeting chats fall off retention. People delete embarrassing messages.
| # | Action | Who | Done when | Evidence to capture |
|---|---|---|---|---|
| 1.1 | Declare; open the timeline; Legal attaches privilege before the first substantive assessment | IC / Legal | Incident ID issued | Declaration time (UTC, ISO 8601), declarer, reporter |
| 1.2 | Ask the recipient, by voice, exactly four things: did money move or get queued; did you give a credential, code or approval; did you grant access to anything; did you install anything | Ops Lead | All four answered yes/no/unsure | Verbatim answers, time asked, who asked |
| 1.3 | Tell the recipient: do not delete anything, do not reply, do not call the number back. Their instinct will be to clean up | Ops Lead | Instruction acknowledged | Instruction time and acknowledgement |
| 1.4 | Preserve the media in its original form — the voicemail audio file, the video recording, the chat export. Copy the file; do not forward it through a channel that re-encodes it | Ops Lead | Original file in the evidence store with a hash | SHA-256, file name, source path, collector, collection time |
| 1.5 | Preserve the platform record separately from the media: meeting attendance report, join and leave times, participant identifiers, tenant of origin, chat transcript, call detail records | Ops Lead | Records exported for every session in the window | Meeting/call IDs, participant list, join IPs where available, export query and time |
| 1.6 | Place a Purview eDiscovery hold on the recipient, the impersonated party and any finance approver — this covers the mailboxes and sites backing Teams and M365 Groups | Ops Lead | Hold active on all custodians | Case ID, hold policy ID, custodian list, timestamp |
| 1.7 | Record every attacker-controlled identifier: calling number and display name, WhatsApp/Signal handle, sender address and full headers, meeting organiser identity, external tenant ID, any URL or attachment | Ops Lead | Identifier list complete | Identifiers, where each was observed, screenshots with visible timestamps |
| 1.8 | Run the verification callback. Reach the impersonated party on the number in the corporate directory of record — never a number supplied in the approach — and ask whether they made the request | Ops Lead | Impersonated party confirms or denies, by voice | Number called and its source, time, who answered, exact words of the denial |
| 1.9 | Ask the impersonated party's assistant and direct reports whether they received the same approach; check whether the lure went to anyone else | Ops Lead | Second-target list produced or ruled out | Names contacted, responses, times |
| 1.10 | If a service-desk contact is involved, pull the ticket, the call recording and the agent's notes before the agent goes off shift | Ops Lead | Ticket and recording preserved | Ticket ID, agent, verification steps the agent performed, recording hash |
| 1.11 | Set severity and confirm which parallel playbook is now running: 14.2 for money, 14.4 for a granted reset | IC | Severity recorded, parallel playbook declared | Severity, rationale, time, named leads for each track |
# Pull the audit record around the approach for the targeted account and the impersonated party.
# Search broadly first, then filter the returned records - but the search is only broad if
# -SessionCommand ReturnLargeSet is set. Without it the cmdlet returns at most 100 records
# however high you set -ResultSize, and filtering a truncated set is how you conclude that
# nothing happened. ReturnLargeSet comes back unsorted; re-run it with the SAME -SessionId
# until it returns zero rows, then sort what you have. Operation strings vary by tenant and by
# how the action was performed - read them out of your own results, do not assume them.
Search-UnifiedAuditLog -StartDate <MM/DD/YYYY> -EndDate <MM/DD/YYYY> `
-UserIds <target-upn>,<impersonated-upn> `
-SessionCommand ReturnLargeSet -SessionId <id> -ResultSize 1000
# Risk state on both accounts, in case the social engineering rode on an existing compromise.
Connect-MgGraph -Scopes "IdentityRiskEvent.Read.All","IdentityRiskyUser.ReadWrite.All"
Get-MgRiskDetection -Filter "RiskType eq 'anonymizedIPAddress'" |
Format-Table UserDisplayName, RiskType, RiskLevel, DetectedDateTimeSearch-UnifiedAuditLog syntax · ID Protection via Graph · eDiscovery holds
Containment here is unusual: there may be no malware, no beachhead and nothing to isolate. What you are containing is an instruction in flight and an adversary's ability to place the next call.
| # | Action | Who | Done when | Evidence to capture |
|---|---|---|---|---|
| 2.1 | If funds moved or are queued, launch 14.2 Phase 2A now, in parallel — bank fraud desk by voice, recall request, IC3 filing. Do not wait for this playbook to finish | Finance Lead | Bank case reference and IC3 complaint number issued | Call time, bank contact, case reference, complaint number |
| 2.2 | Freeze the specific instruction: hold the payment, the vendor-master change, the payroll bank-detail change or the account modification that was requested | Finance Lead / Ops Lead | Hold confirmed by the system owner | Hold ticket, systems affected, approver, time |
| 2.3 | If a credential, MFA re-enrolment or access grant was given up: revoke sessions and reset in the same action, then hand to 14.4 | Ops Lead | Revoke-MgUserSignInSession succeeds for the account | Cmdlet output, timestamp, operator |
| 2.4 | Freeze service-desk-initiated password resets and MFA re-enrolment for the privileged cohort tenant-wide until verification is upgraded to a scripted out-of-band check | IC | Freeze in force, service desk briefed by voice | Freeze scope, start time, authorizing role, exception path |
| 2.5 | Brief the service desk on the specific pretext, the caller identifiers, and the split-request pattern — the same account approached twice, by two agents | Ops Lead | Every agent on shift briefed and the briefing left for the next shift | Briefing content, time, agents briefed |
| 2.6 | Warn the workforce through a channel the impersonated party is confirmed to control, naming the pretext and the channel — this tips off the adversary and is worth it | Comms Lead | Broadcast sent, read receipts or acknowledgement tracked | Message text, channel, send time, approver |
| 2.7 | Block the calling number, handle and sender domain at the telephony, messaging and mail gateway. Expect low yield; do it anyway and do not call it containment | Ops Lead | Blocks applied and confirmed active | Indicators blocked, systems, time |
| 2.8 | For an AI-generated phishing wave, quarantine by campaign shape — same landing infrastructure, same send window, same targeted role — not by literal indicator match | Ops Lead | Campaign clustered and quarantined | Cluster criteria, message count, recipients, quarantine action |
| 2.9 | Preserve copies of every lure before purging it from mailboxes. Purging first destroys the evidence counsel and your insurer will ask for | Ops Lead | Export complete and hashed, then purge executed | Export manifest, hashes, purge command and time |
| 2.10 | Notify the cyber insurer; social-engineering-fraud cover is commonly conditioned on prompt notice | Exec Sponsor | Claim reference issued | Notification time, policy and claim reference |
There is often no implant to remove. What you eradicate is the adversary's information advantage and the process gap that let a voice function as an authorization.
| # | Action | Who | Done when | Evidence to capture |
|---|---|---|---|---|
| 3.1 | Establish what source material the impersonation used: earnings calls, conference video, podcast appearances, published org charts, the executive's public social profiles | Comms Lead | Exposure inventory produced for the impersonated party | Source list with URLs, dates, retrieval time |
| 3.2 | Pivot on every attacker identifier from 1.7 across mail, telephony, messaging and sign-in logs, tenant-wide | Ops Lead | Full target list produced or the single-target finding evidenced | Query, time range, matches, accounts touched |
| 3.3 | Review every vendor-master, payroll and beneficiary change made in the approach window, whoever approved it | Finance Lead | Every change in window reviewed and attributed | Change records, approvers, verification evidence per change |
| 3.4 | Review every service-desk password reset and MFA re-enrolment in the same window for the split-request pattern | Ops Lead | All tickets in window reviewed | Ticket IDs, requester, agent, verification performed |
| 3.5 | If any access was granted, enumerate OAuth consents and remove unexpected grants — a reset does not revoke a consented app | Ops Lead | No unexpected grants remain | App name, OAuthAppId, consent type, scopes removed |
| 3.6 | Search the audit log for Consent to application carrying IsAdminConsent: True. Latency runs 30 minutes to 24 hours — run it twice, an hour apart | Ops Lead | Two runs, second returning nothing new | Search parameters, both run times, results |
| 3.7 | Remove remaining lure copies from mailboxes and shared channels, after the 2.9 export | Ops Lead | Search returns no remaining copies | Search query, items removed, count |
| 3.8 | Close the gap that let the request through: the missing callback, the single-approver threshold, the service-desk script that accepted a voice as identity proof | IC | Named owner and date on each gap | Gap register, owner, target date |
# Tenant-wide consent inventory - Microsoft's documented method.
.\Get-AzureADPSPermissions.ps1 | Export-csv -Path "Permissions.csv" -NoTypeInformation
# Revoke what the inventory turns up - Microsoft's two documented revocation cmdlets.
Remove-MgOauth2PermissionGrant # revokes a delegated consent grant
Remove-MgServicePrincipalAppRoleAssignment # revokes an application-permission role assignmentDetect and remediate illicit consent grants
Blocklisting is close to worthless against a caller who buys a new number for nine dollars, and indicator-matching is close to worthless against generated phishing text that is unique per recipient. Takeaway: hunt on the campaign's shape — the targeted role, the send window, the landing infrastructure, the pretext — and put the caller identifiers in the hunt query, not just the block list.
| # | Action | Who | Done when | Evidence to capture |
|---|---|---|---|---|
| 4.1 | Release the payment hold under joint Incident Commander and Finance Lead approval; retain the beneficiary hold | IC / Finance | Payments resumed, beneficiary hold retained | Release approval, retained holds, time |
| 4.2 | Restore any account access that was suspended; confirm the real user has service, by voice | Ops Lead | User confirms access out of band | Restore time, first successful sign-in, confirmation call |
| 4.3 | Publish or re-publish the verification protocol: callback to a directory-of-record number, on every payment, banking, credential or access request arriving by voice, video or message | Finance / Ops | Protocol issued, acknowledged by finance, AP, treasury, HR and the service desk | Signed procedure, distribution list, acknowledgement date |
| 4.4 | Issue a shared-secret challenge to executives and their frequent counterparts — a phrase or fact not present in any public source, rotated on a stated schedule, never sent by email | Comms Lead | Challenge distributed out of band and rehearsed once | Distribution method, rotation schedule, rehearsal record |
| 4.5 | Set dual authorization above a stated threshold and a cooling-off period on beneficiary bank changes | Finance Lead | Control live in the AP system | Threshold, approver roles, system configuration record |
| 4.6 | Upgrade the service-desk identity-verification runbook: out-of-band callback, a challenge not derivable from public sources, and a mandatory second-agent check on any privileged-account reset | Ops Lead | Runbook published, agents trained, one live test passed | Runbook version, training record, test result |
| 4.7 | Move the impersonated party, the target, and the whole finance and privileged cohort to phishing-resistant MFA (FIDO2/WebAuthn or PKI) | Ops Lead | Cohort enrolled, legacy methods removed for those accounts | Enrolment report, date legacy methods disabled |
| 4.8 | Tell the workforce, by name and with credit, that the report was correct behavior — including when the report turned out to be a false alarm | Comms Lead | Message sent | Message text, send date |
Phishing-resistant MFA blocks over 99% of identity-based attacks even when the attacker already holds a valid username and password (MDDR 2025). It does not stop a deepfake call, but it makes the credential the caller is fishing for far less useful. Number matching is a push-fatigue mitigation and CISA is explicit that it is not phishing-resistant MFA (CISA). Actionable takeaway: step 4.8 is not sentiment. If reporting a suspected fake costs an employee an awkward conversation with an executive, the next one will not report. Make the report cost nothing, publicly, once.
| # | Action | Who | Done when | Evidence to capture |
|---|---|---|---|---|
| 5.1 | Blameless review within 10 business days with the recipient, the service-desk agent and the impersonated party present. The person who was targeted is a witness, not a defendant | IC | Findings logged with owners and dates | Findings register |
| 5.2 | Close the notification determination with Legal, including a documented "no notification required" | Legal Liaison | Determination signed and filed | Memo, decision date, reasoning |
| 5.3 | Assess executive media exposure and agree what the impersonated party will and will not publish going forward | Comms Lead | Exposure decision recorded with the executive's agreement | Decision memo, review date |
| 5.4 | Ship detections for the campaign shape: new external tenant meeting invites to finance roles, first-contact-from-unknown-number to payment approvers, bulk send patterns with unique bodies | Detection engineering | Rules in production with a passing validation test | Rule IDs, ATT&CK mapping, last validated date |
| 5.5 | Add this scenario to the exercise calendar as a tabletop card, including the version where the callback reaches an executive who is genuinely unreachable | IC | Exercise scheduled with a date and a facilitator | Exercise card, date, participants |
| 5.6 | Record in the playbook header: the directory of record used for callbacks, who owns it, and when its numbers were last verified | Ops Lead | All three recorded and dated | Contact source, owner, verification date |
The deepfake itself almost never starts a regulatory clock. What starts one is what the social engineering obtained. If the approach yielded access to personal data, GDPR Article 33's 72 hours from awareness is running, and the Scribe's timeline is your only evidence of when awareness arose. If it yielded a credential into a regulated service, the NIS2 and DORA clocks may run on the downstream compromise rather than on the call. If the loss could be material to a public filer, the Executive Sponsor opens the SEC materiality assessment on day one. The full matrix is Chapter 15 — do not reconstruct it under pressure.
Two things belong here rather than in Chapter 15. File with IC3 regardless of loss amount when funds moved — it is the entry point to the Recovery Asset Team, not a regulatory notification, and 14.2 Phase 2A owns the mechanics. And notify counterparties by telephone on numbers you already held, never by replying to any thread the approach touched.
Automate the preservation, never the determination. The moment a suspected-impersonation report opens, a playbook can safely and reversibly: pull the meeting and call records for the window, snapshot the voicemail or recording and hash it, place the eDiscovery hold, export sign-in and audit logs for both the target and the impersonated party, extract the caller identifiers, search for the same identifiers across mail and telephony, and attach the lot to the ticket. All read-only, all racing a seven-day Entra Free retention, all faster than a human opening a console.
Gate everything else. The verification callback is the one step that must never be automated — its entire value is a human hearing a human on a number the attacker did not supply, and a system that auto-approves on a matched voiceprint has recreated the vulnerability in software. The rule that holds up: automation may gather, enrich, correlate and recommend without approval; it may act only where the action is reversible, scoped and rate-limited; irreversible or organization-wide actions require a named human approver. The tenant-wide reset freeze (2.4), the workforce broadcast (2.6) and the payment release (4.1) are all named-approver actions. And resist wiring an AI triage agent to auto-close these reports: the documented failure modes are overconfident closure on weak proof and hallucinated detail in the investigation narrative (Panther), and a report that reads like "employee thought a call sounded strange" is precisely where both bite.