In our July newsletter, we shared ideas for building a deepfake detection and response toolkit. This month, we’re adding a simple checklist you can use or adapt.
If you receive suspicious audio, video, images or messages:
- Pause. Don’t share or respond.
Do not forward, repost, download or act on the content—even if it appears urgent or comes from a familiar person. - Check the source.
Look closely at the sender’s email address, phone number, account name and profile. Be alert for slight misspellings, unfamiliar domains or newly created accounts. - Consider the context.
Ask whether the message, request or behavior is unusual. Treat requests involving money, credentials, confidential information or urgent action as high risk. - Look and listen for inconsistencies.
Watch for unnatural facial movement, mismatched lip synchronization, odd blinking, distorted backgrounds, robotic speech or changes in tone and pacing. Remember: sophisticated deepfakes may show no obvious defects. - Verify independently.
Contact the apparent sender through a trusted phone number or communication channel—not by replying or using contact information provided in the suspicious message. Use a prearranged verification question or code when available. - Preserve the evidence.
Save the original message, link, file and related details. Take screenshots showing the sender, date, time and platform. Do not alter the content. - Report immediately.
Notify [IT/Security Contact] and [Communications Contact] through [approved reporting channel]. If money, legal issues, employee safety or sensitive data are involved, also alert [Finance/Legal/HR]. - Wait for clearance.
Do not publicly deny, confirm or discuss the content until Communications, Security and other appropriate leaders have assessed it and provided direction.
If you are in doubt, report it. Employees are not expected to prove something is fake. They just need to spot the warning signs, pause and escalate.
