witness
← All posts
deepfake-scams·Sep 15, 2026·9 min read

Messenger Fake Video Call Scams: How They Work and How to Protect Yourself

Scammers use deepfake video on Facebook Messenger calls to impersonate people you trust. How these scams work and what to do about them.

WT
Witness Team
Editorial
𝕏in
Messenger Fake Video Call Scams: How They Work and How to Protect Yourself

In February 2024, a finance worker at a multinational firm in Hong Kong joined a video call with his chief financial officer and several colleagues. Everyone looked and sounded exactly as expected. He followed their instructions and transferred $25 million across multiple accounts. Every person on that call was a deepfake [1].

That case made headlines because of the amount. But the same technology is now being used against ordinary people on Facebook Messenger, WhatsApp, FaceTime, and other video calling platforms. The targets are not corporate treasury departments. They are parents, grandparents, friends, and romantic interests. And the amounts stolen, while smaller per victim, add up. The FBI's Internet Crime Complaint Center received over 880,000 complaints in 2023, with losses exceeding $12.5 billion, and deepfake-enabled fraud is among the fastest-growing categories [2].

This guide explains how fake video call scams work, what the technology behind them actually does, what red flags to look for during a call, and what to do if you think you have been targeted.

Key Takeaways

  • Real-time deepfake software can replace a caller's face and voice during a live video call, making them appear to be someone you know.
  • These scams most commonly target family members (fake emergency calls), romantic interests (catfishing), and business contacts (CEO fraud).
  • Current deepfake video has telltale artifacts around hair edges, accessories, lighting, and facial expressions that you can learn to spot.
  • If a video call involves any request for money, passwords, or personal information, verify the caller's identity through a separate channel before acting.
  • Screenshots or recordings from suspicious calls can be analyzed with AI detection tools to check for manipulation.

How Deepfake Video Calls Actually Work

The core technology is called real-time face swapping. Software captures the scammer's face through their webcam, processes it frame by frame, and replaces it with a target face. The output is streamed directly into the video call application as if it were a normal camera feed.

Here is the pipeline in simplified terms:

  1. Source material. The scammer needs reference images or video of the person they want to impersonate. Social media profiles, YouTube videos, news appearances, or even a few photos are often enough.
  1. Face model training. The software builds a model of the target face: its geometry, skin texture, expressions, and how it moves. Some tools can do this with as few as one clear photo, though quality improves with more data.
  1. Real-time rendering. During the call, the software maps the scammer's facial movements onto the target face model. When the scammer smiles, the deepfake smiles. When they talk, the deepfake's lips move in sync.
  1. Voice cloning (optional but increasingly common). A separate system can clone the target's voice from audio samples. Some tools need only 3 to 10 seconds of reference audio to produce a passable clone [3]. The cloned voice runs in parallel with the video, creating a complete audiovisual impersonation.
  1. Virtual camera output. The processed video feeds into a virtual camera driver that applications like Messenger, WhatsApp, or Zoom read as if it were a physical webcam. To the receiving end, it looks like a normal video call.

The entire setup can run on consumer hardware. A modern gaming laptop with a mid-range GPU is sufficient. Commercial deepfake tools marketed for "entertainment" or "content creation" cost between $20 and $200. Open-source alternatives are free.

The Three Main Scam Scenarios

The family emergency

A parent or grandparent receives a video call from what appears to be their child or grandchild. The person on screen looks right and sounds right. They say they have been arrested, are in the hospital, or are stranded somewhere. They need money immediately. Sometimes a "lawyer" or "police officer" takes over the call to add authority.

The AARP reported that grandparent scams cost older Americans an estimated $1.5 billion in a single year, and deepfake audio and video are making these scams dramatically more convincing [4].

The romantic catfish

Someone you have been talking to on a dating app or social media agrees to a video call. They look exactly like their photos. The conversation flows naturally. Over weeks or months, trust builds. Eventually, a financial request arrives. The mechanics are identical to traditional romance scams, but the video call component eliminates the biggest red flag victims used to rely on: "We've never actually video chatted."

The business impersonation

An employee receives a call from someone who appears to be their manager, CEO, or business partner. They are instructed to transfer funds, share credentials, or approve a transaction. Deloitte's Center for Financial Services projected that AI-generated deepfake fraud could reach $40 billion in losses by 2027 [5]. The Hong Kong case was not an isolated event. It was an early signal.

Red Flags During a Video Call

Deepfake video in 2026 is good. It is not perfect. Knowing where the technology still struggles gives you a practical edge.

Visual artifacts

What to Watch ForWhy It Happens
Hair edges that shimmer, blur, or flickerFace-swap models have difficulty with fine hair strands at the boundary between face and background
Accessories that glitch (glasses, earrings, hats)Objects near the face boundary are inconsistently rendered as the model tracks facial movement
Skin tone that shifts subtly between framesLighting estimation on the generated face does not perfectly match the real environment
Background warping near the face outlineThe model can distort nearby background pixels when adjusting the face overlay
Teeth that look blurred or unnaturally uniformTooth rendering remains a weak point for most real-time models
Flat or delayed micro-expressionsEmotion transfer between the source face and the generated face still lags behind natural timing

Audio tells

  • Lip-sync drift. Audio and video run on separate processing pipelines. Over time, they can fall slightly out of sync.
  • Vocal quality that sounds slightly compressed or metallic, especially on consonants.
  • Background sounds that disappear entirely. Voice cloning systems sometimes strip ambient audio in ways that make the call sound unnaturally clean.

Behavioral tells

These are often more reliable than technical artifacts:

  • The caller controls the terms. They call you; you cannot call them back successfully. If you suggest hanging up and calling their known number, they resist.
  • They avoid unscripted physical actions. Ask them to turn their head fully to the side, touch their ear, or hold up a specific object. Real-time face swaps degrade significantly during profile views and occlusion.
  • The request always involves urgency. "I need this now." "Don't tell anyone." "There's no time to explain." Urgency is the mechanism that prevents you from verifying.
  • They deflect verification attempts. If you suggest confirming through another channel (texting their known number, calling another family member), they have a reason why that will not work right now.

What to Do If You Suspect a Call Is Fake

During the call

  1. Stay calm and do not send money. No legitimate emergency requires an immediate wire transfer during a phone call.
  2. Ask a verification question. Choose something only the real person would know: a shared memory, an inside joke, the name of a pet. Avoid questions whose answers exist online.
  3. Request an unscripted action. "Hold up three fingers." "Show me the room you're in by panning the camera." "Pick up the nearest object and show it to me." Deepfakes struggle with rapid changes in angle and occlusion.
  4. Say you will call them back on their known phone number or through a separate platform. If they resist strongly, that is a significant signal.

After the call

  1. Contact the person directly. Call their known phone number or message them through a platform the scammer does not control. Verify whether they actually called you.
  2. Save evidence. If you recorded the call or took screenshots, save everything. Do not delete the conversation history.
  3. Check recordings or screenshots. If you captured any portion of the video call, upload screenshots or frames to Witness to check for signs of AI manipulation. Detection tools can identify artifacts that are invisible during a live conversation.
  4. Report it. If money was sent, contact your bank immediately. File a report with the FBI's IC3 at ic3.gov. Report the account on the platform where the call took place.

How to Protect Yourself Before It Happens

Establish a family verification code

Choose a word or phrase that only your family knows. If anyone calls in an emergency, they must use the code before any action is taken. This is simple, effective, and defeats deepfakes entirely because the scammer does not have access to information that was never shared digitally.

Limit your digital footprint

Every public photo and video of you is potential training data for a face-swap model. Every public voice recording can feed a voice clone. You do not need to disappear from the internet, but consider:

  • Setting social media profiles to private
  • Removing or restricting access to videos where you speak at length
  • Being cautious about voice recordings in public settings

Enable platform protections

Most messaging platforms now offer some form of verified contact or encrypted communication. Use them:

  • WhatsApp's end-to-end encryption and security code verification
  • Messenger's encrypted chat mode
  • FaceTime's built-in identity verification through Apple ID

These do not prevent deepfakes directly, but they make it harder for a scammer to spoof the identity of an existing contact.

Verify before you trust video

The era of "I saw them on video, so they must be real" is over. Video calls are now in the same category as photos and text messages: useful, but not sufficient proof of identity on their own.

If a video call leads to a request for money, credentials, or sensitive information, verify the person's identity through a completely separate channel before you act. Always.

Why This Problem Is Growing

The tools for creating deepfake video calls are getting cheaper, faster, and easier to use. In 2023, they required technical skill and powerful hardware. In 2026, they are available as consumer apps with one-click setup. The barrier to entry has dropped from "machine learning expertise" to "download and run."

Meanwhile, awareness has not kept pace. A 2024 survey by iProov found that 43% of people said they could not tell the difference between a real video and a deepfake [6]. Among those who said they could, testing showed their confidence far exceeded their accuracy.

The gap between the technology and public awareness is where scammers operate. Closing that gap requires exactly two things: knowing that fake video calls exist, and knowing what to do when you encounter one.

What Witness Does

Witness is a free tool at witness.vision/scan that analyzes images and video for signs of AI generation or manipulation. If you have screenshots from a suspicious video call, a recording of the conversation, or images sent by someone whose identity you want to verify, upload them for analysis.

The Witness Chrome extension also lets you check profile photos and media directly in your browser without downloading files.

Detection is not a guarantee of catching every deepfake. But it catches patterns that human eyes miss, and it adds a verification layer that did not exist for most people until recently.

◆◆◆
  1. [1]CNN, "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'," February 2024, https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html
  2. [2]FBI Internet Crime Complaint Center, "2023 Internet Crime Report," https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf
  3. [3]Dan Goodin, Ars Technica, "AI voice cloning is getting dangerously good," https://arstechnica.com/security/2024/02/ai-voice-cloning/
  4. [4]AARP, "Grandparent Scams: What You Need to Know," https://www.aarp.org/money/scams-fraud/grandparent-scam/
  5. [5]Deloitte Center for Financial Services, "Generative AI deepfakes and the future of financial fraud," May 2024, https://www2.deloitte.com/us/en/insights/industry/financial-services/financial-services-industry-predictions/2024/deepfake-banking-fraud-risk-on-the-rise.html
  6. [6]iProov, "The Threat of Deepfakes," 2024, https://www.iproov.com/reports/the-threat-of-deepfakes
WT
Witness Team
Editorial at Witness. Building a second pair of eyes for everything you see online.
Try Witness →