Test your workforce againstAI-powered impersonation.
When seeing and hearing someone is no longer proof of identity, verification becomes critical. Don't train employees to spot a fake. Train them to verify before they trust.
Trust itself becomes the attack vector.
Deepfake attacks combine AI-generated voices, video, familiar identities, urgency and social engineering. The goal may not be to make an employee believe a video is fake, but to make them act before verifying the request.
An attacker may impersonate
- CEO or senior executive
- Finance or procurement leader
- IT or helpdesk personnel
- Customer or business partner
- Vendor or supplier
- Colleague or manager
PhishPrep turns that scenario into a safe, measurable simulation.
Realistic AI impersonation, safely simulated.
AI Voice Impersonation
Simulate realistic voice-based interactions where a trusted individual appears to make an urgent request.
Executive Impersonation
Test how employees respond when a simulated CEO, CFO, manager, or other senior leader requests an unusual action.
Deepfake Video Scenarios
Test whether employees rely on visual familiarity or follow established verification procedures.
Video Meeting Simulation
Test deepfake scenarios within familiar collaboration environments such as virtual meetings.
Urgency & Authority
Simulate requests involving payments, credentials, sensitive information, access, or approvals.
Multi-Channel Social Engineering
Combine deepfake interactions with supporting email, SMS or messaging to recreate a realistic attack sequence.
Behavioral Analytics
Measure employee responses, verification behavior, reporting, and repeat-risk patterns.
Targeted Awareness Training
Provide focused awareness intervention based on observed behavior rather than generic training alone.
Scenarios built around real business requests.
- Lure 01“A simulated CFO joins a video interaction and requests an urgent payment.”
Urgent Payment Process Execution
- Lure 02“A simulated IT executive or helpdesk representative requests an urgent credential reset.”
Account Reset
- Lure 03“A simulated senior executive requests an unusual action because they are supposedly unavailable through normal channels.”
I'm Travelling — I Need Your Help
- Lure 04“An employee receives a meeting invitation followed by a simulated deepfake interaction involving a familiar person.”
"Join This Meeting"
A continuous security-awareness cycle.
Deepfake simulation should be part of a continuous cycle, not a one-time exercise.
PhishPrep · Simulate
01 / 05Scenario: CFO urgent payment
ScheduledImpersonated identity
Mark Di, CFO
Channels
Targets
64
Finance & AP
Request
Payment
Urgency
High
Consent
Approved
Internal policy
Decision analysis
Sample data- Joined interaction84%
- Followed the request22%
- Paused & questioned41%
- Verified via trusted channel37%
- Reported29%
Targeted awareness
Sample dataInterventions
14
Only those who acted
Completed
93%
Focus
Verify
Lesson: Verify before you trust
- A familiar face or voice is not proof
- Call back on a known number
- Follow the payment approval process
- Report unusual requests
Verification habits
Sample dataCall-back verification
+46%
Process followed
+38%
By team
- Finance82%
- Accounts payable74%
- Procurement61%
- Executive assistants55%
Retest results
Sample dataFollowed the request
Verified (higher is better)
Audit evidence exported for the security review
Test the decision, not just the click.
Traditional phishing
Deepfake simulation
- Primarily tests email behaviorBehaviorTests identity and trust behavior
- Employee receives a phishing messageInteractionEmployee interacts with a simulated person
- Focuses on links and attachmentsFocusFocuses on requests and decisions
- Tests click/report behaviorMeasuresTests verification and process adherence
- Primarily text-basedMediumVoice, video and multi-channel
- Often stops at the clickDepthCan test the action that follows
Deepfake simulation covers all 6 areas.
Request a ConsultationQuestions about
deepfake simulation
Find quick answers, or talk to our team.
Request a ConsultationA deepfake simulation is an authorized security-awareness exercise that uses simulated AI-generated voice, video, or other impersonation techniques to test how employees respond to realistic social-engineering scenarios.
Traditional phishing simulations primarily test email behavior. Deepfake attacks can target employees through voice and video interactions, particularly where trust, urgency, and authority influence decisions.
Scenarios can include executive impersonation, finance requests, IT/helpdesk requests, sensitive information requests, vendor interactions, and video-meeting impersonation.
The simulation can measure identity verification, response to the request, process adherence, information sharing, reporting behavior, response time, and repeat behavior.
Yes. Deepfake scenarios can be incorporated into broader social-engineering campaigns involving email, SMS, Microsoft Teams, voice, QR codes, and other channels.
Yes. Repeated simulations allow organizations to measure whether verification behavior improves over time rather than treating deepfake awareness as a one-time training activity.
Don't wait for a real deepfake attack to test your defenses.
Build a workforce that verifies before it trusts. Simulate it. Measure it. Reinforce it. Retest it.

