Deepfake video calls and the case for continuous identity verification
Pindrop · Katelyn Halbert · source ↗
Business email compromise used to be a text problem. Pindrop’s latest article argues it has “evolved from text to voice to live video”: the spoofed-email attacker now joins the video call wearing a synthetic face and voice and makes the wire request in person. Its anchor case is the 2024 Arup loss — a Hong Kong finance employee sent $25.6 million after a meeting in which every participant but the victim was AI-generated, still the largest publicly reported deepfake-call loss.
The problem the piece frames is a gap in how deepfakes are caught. Most detection acts as a one-time checkpoint — it scans the feed when a call starts, makes a real-or-synthetic call, and stops watching. That, Pindrop argues, is exactly the seam the attack is built around: join clean, spend the meeting building trust, and swap in the synthetic executive only when the payment ask lands, after the check has already passed. Their proposed answer is “continuous identity verification” — zero trust applied to the meeting — confirming that each participant is a real human, the right human, and in the right location for the full duration of the call rather than only at login, packaged as Pulse for Meetings on Zoom, Teams, and Webex. The piece also notes the EU AI Act’s Article 50 transparency rules going enforceable August 2 — the provision Telnyx flagged earlier — while conceding that labeling requirements bind cooperative content and do nothing about an attacker who won’t self-label.
It’s a vendor making the case for its own category, so weigh the prescription accordingly. The framing worth keeping is the shift from a single gate to a continuous one; the question it leaves open is whether the durable control is detecting the synthetic at all, or verifying that whoever’s behind it is authorized to make the ask.