What Are Deepfakes? Voice Cloning & Scams Explained | AP Cybersecurity

AP Cybersecurity Topics › Deepfakes & Voice Cloning
Unit 1 • Topic 1.4 • AI-Based Cybersecurity Attacks

What Are Deepfakes? Voice Cloning, Scam Examples & How to Spot Them

Deepfakes and voice cloning are AI-generated audio and video used to impersonate trusted people. They are a powerful form of AI-augmented attack because they defeat the human instinct to trust a familiar face or voice.

Impersonatetrusted people
Defeats'I recognized the voice'
Verifythrough a second channel
Cloned voice/videoUrgent requestVerify on 2nd channelBlocked
Out-of-band verification stops a convincing deepfake request.

How deepfakes augment attacks

A deepfake clones a person's voice or appearance from samples, then uses it to make a fake request seem real (EK 1.4.A). An attacker can call sounding exactly like a manager, or send a video that looks like a known executive, to authorize a payment or extract information.

This raises the stakes of social engineering: the usual defense of 'I recognized their voice' no longer works, because the voice itself can be faked.

Scenario

An employee gets a call that sounds exactly like the CEO, urgently asking to wire funds. What makes this dangerous?

Reveal answer

Voice cloning defeats voice-based trust. The familiar voice feels like proof of identity, but it can be AI-generated. The urgency adds pressure to skip verification.

Exam tip

A deepfake is an AI-augmented impersonation. The tell is not the voice or face quality; it is the unverified, often urgent, request behind it.

How to defend

Because the media can be faked, defense shifts to the process: verify the request through a separate, known channel (call back on a saved number, confirm in person), and use agreed-upon verification steps for sensitive actions like payments.

Treat any urgent, high-stakes request as suspicious until verified independently, no matter how convincing the voice or video appears (EK 1.4.B).

Scenario

A 'manager' video-calls asking you to buy gift cards immediately. How should you verify?

Reveal answer

Confirm through a separate known channel, such as calling the manager's saved number or checking in person, before acting. Do not rely on the video alone.

Real-world example

The 2024 Hong Kong deepfake heist

A finance employee at an engineering firm wired about 25 million US dollars after joining a video call where deepfakes impersonated the CFO and colleagues. Every person on the call was AI-generated.

Verify high-stakes requests on a separate, known channel.

Key Terms

Deepfake AI-generated audio or video that impersonates a real person.
Voice cloning Recreating a person's voice from samples to fake a call.
Impersonation Pretending to be a trusted person to gain compliance.
Out-of-band verification Confirming a request through a separate, known channel.

Match It Up

Tap a term, then tap its definition. Correct pairs lock in green.
Term
Definition
All matched. Nice work.

Common Mistakes

!

Trusting a familiar voice as proof

Voice cloning can fake a known voice. A familiar voice is no longer identity verification.

!

Judging by media quality

Deepfakes can be highly convincing. The request, not the realism, is what to scrutinize.

!

Acting on urgency without verification

High-stakes urgent requests are exactly where deepfakes are used. Verify first.

!

Assuming video is harder to fake than audio

Both can be faked. Verify through a second channel regardless of medium.

Check for Understanding

Predict your answer before you tap. Click a choice to check it and read why.
Question 1
What is a deepfake in the context of cyberattacks?
C. A deepfake is AI-generated media that impersonates a real person to make a fake request seem legitimate.
Question 2 Predict first
Why does voice cloning defeat a common verification habit?
A. If the voice itself can be faked, recognizing a familiar voice no longer proves identity.
Question 3
Which statements are true? I. A deepfake is an AI-augmented impersonation. II. Media quality is the best tell. III. Verification should use a separate channel.
B. I and III are true. II is false because convincing realism is exactly the danger; the request is what to scrutinize.
Question 4 Predict first
An urgent call sounds exactly like your manager and asks you to wire money now. The BEST action is:
B. Verify independently through a known channel; a familiar voice can be cloned.
Question 5
Deepfakes are best classified under which Unit 1 topic?
C. Deepfakes are an AI-augmented attack technique covered under AI-based cybersecurity attacks (Topic 1.4).
Question 6
What is the most reliable defense against a deepfake request?
D. Process-based verification works even when the audio or video looks and sounds real.

Frequently Asked Questions

A deepfake is AI-generated audio or video that impersonates a real person, used to make a fraudulent request seem legitimate.
They defeat the instinct to trust a familiar face or voice, since the media itself can be faked, often paired with urgency to pressure quick action.
Verify high-stakes requests through a separate, known channel, use agreed verification steps for payments, and treat urgent requests as suspicious until confirmed.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]