Realtime deepfakes enter video calls and change the fraud risk
A 404 Media investigation showed software that can turn an operator's face into someone else's during Teams, Zoom, and WhatsApp calls. For companies, a video call is no longer enough to prove identity.
Summary
404 Media investigated a Chinese tool called Haotian AI, described as realtime deepfake software used by fraud operators. According to the investigation, the tool can transform one person's face into another's during calls on platforms such as Microsoft Teams, Zoom, WhatsApp, TikTok, and YouTube.
Reporter Joseph Cox obtained and tested the software, watching an operator turn into his own face during a Microsoft Teams call. The investigation connects this class of tool to scams such as romance fraud, business compromise, virtual kidnapping, and other operations that depend on identity manipulation.
In practice
The major shift is that deepfakes are no longer only fake videos published after the fact. With realtime tools, fraud can happen during a live conversation, with facial expressions and movements preserved well enough to persuade the other person.
That creates a direct problem for companies. Processes that rely on a video call to confirm identity, approve payments, validate urgent requests, or unlock access become weaker. Visual presence should no longer be treated as sufficient proof.
Context
In recent years, most discussions about deepfakes have focused on political disinformation, viral videos, and manipulated images. 404 Media's investigation points to a more operational risk surface: realtime fraud inside normal workplace tools.
The answer is not just automatic detection. The investigation itself suggests these systems can fool detection tools. More robust mitigation will need to combine human processes, confirmation through secondary channels, authorization limits, and practical training on AI-enabled social engineering.
Why it matters
- Video calls are no longer enough as a strong identity verification mechanism.
- Finance, legal, sales, and executive teams are natural targets for this type of fraud.
- Enterprise security needs simple protocols to confirm sensitive requests outside the call.
- AI training should include concrete examples of multimodal fraud, not only text and phishing.
The message for organizations is clear: if a decision has financial, legal, or operational impact, it should not depend only on who appeared in a video call. AI has made visual presence easier to fake, and internal processes need to catch up.