Deepfake-as-a-Service Is Fueling More “Fake Boss” Scams — What to Know

Deepfake-as-a-Service Is Fueling More “Fake Boss” Scams — What to Know

You are currently viewing Deepfake-as-a-Service Is Fueling More “Fake Boss” Scams — What to Know
Criminals can use AI-generated voices and videos to impersonate bosses, relatives, or other trusted contacts and make urgent requests appear real.

Criminals are buying deepfake tools on the dark web to create fake voices and videos. Here’s what this trend means, why it could affect you, and how to protect yourself.  

What Happened?

According to TechRadar, cybersecurity researchers at NordStellar have found a sharp increase in discussions about Deepfake-as-a-Service (DFaaS) on dark web forums.

The dark web means hidden parts of the internet where criminals often buy, sell, or discuss illegal services.

Between January and May 2026, researchers identified 924 posts advertising or discussing these services. That is a 39% increase compared with the same period in 2025.

Deepfake-as-a-Service allows criminals to pay for realistic AI-generated voices, images, or videos without needing advanced technical skills. 

Researchers believe improvements in generative AI are making these services easier to use and much more convincing.

Who Could Be Affected?

The report highlights a growing criminal trend that could impact businesses of every size and, in some cases, ordinary consumers.

Researchers did not identify individual victims or leaked personal data in this report.

However, successful deepfake attacks often become much more convincing when criminals already have access to personal information gathered from previous data breaches, data leaks, or public online sources.

Information such as your name, job title, workplace, phone number, or email address can help criminals create messages, phone calls, or videos that seem trustworthy.

Many people also do not realize their personal information may already be leaked in earlier incidents involving schools, employers, healthcare providers, retailers, or online services.

If you are not sure whether your information was leaked somewhere, automatic monitoring can help you spot problems earlier. 

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

How Do These Deepfake Attacks Work?

Deepfakes are AI-generated videos, photos, or voices that closely imitate a real person.

Criminals can use them in many ways. They may create a fake video of your boss asking you to transfer money, a fake phone call from a family member asking for emergency help, or a fake voice message that sounds like your bank or another company you trust.

They may also use deepfake videos, photos, or voices to impersonate celebrities, government officials, or customer support representatives in phishing scams.

These attacks are becoming more convincing because AI can now copy voices and facial expressions with much greater accuracy than before.

Scammers also use AI-generated photos and videos to create fake online personalities that look completely real. In one recent case, AI-generated influencer accounts posed as military members and healthcare workers to gain trust, attract millions of followers, and make money.

Researchers also warn that criminals often combine deepfakes with stolen personal information to make their impersonation even more believable.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

Why This Trend Should Matter to You

Deepfake technology is no longer limited to large criminal groups or highly skilled hackers.

As these services become cheaper and easier to buy, more criminals can use them to impersonate trusted people.

Sumsub’s 2025 Identity Fraud Report found a 180% increase in sophisticated fraud compared with the previous year. The report says attackers are increasingly using AI-generated identities and deepfake-enabled schemes rather than simple scams.

Seeing a familiar face or hearing a familiar voice should no longer be treated as proof that a request is real.

A person reviews multiple email alerts on a laptop, illustrating how criminals may use stolen personal information to create convincing phishing and impersonation messages.
Deepfake scams are often combined with phishing emails and leaked personal details to make urgent requests from a supposed boss, company, or trusted contact appear legitimate.

3 Simple Ways to Reduce Your Risk

These simple habits can help you stay safer from AI-powered impersonation attacks:

1. Verify urgent requests another way

A phone call, video message, or voice recording can be faked. 

If someone asks you to send money or share sensitive information, contact them using a phone number or email address you already know. Never rely only on the message you received.

2. Protect your email account

Because your email account can be used to reset passwords for many other services, protecting it with more than just a password is important. 

Start by creating a unique password and turning on two-step verification (an extra security step that requires a second code). For most email providers, you can find this option in Account Settings → Security.

If you are not sure how to set up extra protection, the Futureproof Email Protection tool guides you through creating a strong password and enabling two-step verification step by step.

3. Share less personal information publicly

The more information criminals can collect from social media and previous data breaches, the easier it becomes to create convincing deepfake attacks.

Review your social media privacy settings and avoid sharing details such as your workplace, travel plans, or personal contact information unless necessary.

As AI Gets Smarter, Your Security Habits Matter Even More

Artificial intelligence is making impersonation attacks more convincing, but a realistic voice or video should never replace verification.

Whenever someone asks you for money, passwords, or sensitive information, pause and confirm the request through another trusted method.

Simple habits, together with tools like Futureproof that monitor for leaked information, can help you spot risks earlier and stay one step ahead of increasingly convincing scams.