Blindfy — Digital Protection

42.5% of scams in Brazil already use AI — Federal Police 2026 report

Fraud became a production line: synthetic videos, cloned voices, flawless emails and identities fabricated in an industrial pipeline.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

A video of the CEO on a Microsoft Teams call approves an urgent R$ 800k transfer to a "new strategic supplier". The audio matches, the lips sync, the background is his office in São Paulo, the company context is correct. The CFO executes. Thirty minutes later he discovers the CEO was on an international flight and never joined the call. It was a deepfake combined with virtual camera injection — produced in 15 minutes from the executive's public LinkedIn videos.

How the scam works

Operators combine four vectors: (a) scraping the target's public audio and video from social networks and events, (b) generation via open-source deepfake models (HeyGen, Sora clones), (c) injection into video calls via virtual camera during live meetings, (d) LLM-orchestrated scripts that answer unexpected questions in real time.

Common mistake

Trusting visual recognition and the "familiar voice". The attack is designed precisely to exploit that recognition — the more charismatic and exposed the executive, the more training material is available.

Impact

The Federal Police reports that 42.5% of frauds recorded in 2025 had some AI component. R$ 1.2 billion attributed to deepfakes in 2025, with 70% of online fraud projected to use AI in 2026. Averages per incident: R$ 80k to R$ 5M, depending on the operation's size.

What works

An alternative-channel validation protocol for any movement above R$ 50k: call the executive's known number (not the one from the call) and wait for a reply through an official channel. Define an internal verbal code for "urgent" situations and share it only among approvers. Continuous finance training against fabricated urgency.

Protection checklist

  • Define a financial threshold that requires alternative-channel validation
  • Establish an internal verbal code for urgency approvals
  • Train the finance team monthly against "urgency pressure"
  • Validate the requester's identity by phone call (not through the video call)
  • Keep an approver registry with documented alternative channels
  • Require two approvers above the threshold
  • Audit C-level public audio/video exposure quarterly

Editorial sources

It is no longer "if it happens". It is "when". Whoever lacks an out-of-band validation protocol in 2026 is open to the first deepfake that comes along.

← All risk analyses · Blindfy initial assessment