S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T12.9
CATEGORY Deception
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Deepfakes

Synthetic Media · AI Impersonation · Emerging → High
Critical
How It WorksSEC 01

Deepfakes are AI-generated audio, video, or images that convincingly impersonate a real person or event. They weaponize trust transfer: a familiar face or voice carries authority and intimacy that we normally treat as strong evidence of identity. When that signal can be synthesized from a handful of public samples, “seeing is believing” and “I’d recognize that voice” stop being reliable — which is what makes the technique so corrosive, and why it now underwrites CEO-voice fraud, relative-in-distress scams, disinformation, and non-consensual imagery.

Detection tips help but degrade fast, and this dossier stays strictly at recognition altitude: no creation guidance. Visible or audible artifacts — unnatural blinking, lip-sync drift, edge blur, flat audio, mismatched lighting — can betray a fake, but generation quality is improving and absence of artifacts is not proof of authenticity. The more durable signals sit outside the media itself: a context that doesn’t fit, an out-of-character or urgent ask, and resistance to verifying through a second channel. Legitimate synthetic media exists too — consented dubbing, clearly labeled satire — and it announces itself rather than hiding.

Because the pixels and waveform can no longer be trusted on their own, the defense moves to provenance and out-of-band verification. Confirm the person through a channel you control, agree on a shared code phrase for urgent requests, check content-provenance signals and corroborating official channels, and put a deliberate pause between a shocking clip and any wire, credential, or reshare. The synthetic media may be flawless; the scenario around it — urgency, secrecy, an unverifiable path — is where the deception still shows.

Warning SignsSEC 02
  • Audiovisual artifacts. What you see or hear can carry tells — odd blinking or lip-sync, edge blur around the face, flat or slightly off-cadence audio, lighting that doesn't match. Absence of tells is not proof of authenticity.
  • Context mismatch. The person says or does something out of character, or the clip surfaces through a channel or at a time that doesn't fit.
  • Urgent, unusual ask. A senior figure or relative suddenly requests a wire, gift cards, credentials, or secrecy — the pressure pattern matters more than the pixels.
  • Resists a second channel. The caller discourages hanging up and calling back, or can't appear live on a channel you control.
  • No verifiable provenance. The media lacks a traceable origin, and reverse search / official channels don't corroborate it.
Frequently Paired WithSEC 03
  • Impersonation · T12.12
    Deepfakes are impersonation given a synthetic face and voice
  • Manipulated Images · T12.20
    Edited (vs. wholly generated) visual deception
  • Business Email Compromise · T14.10
    Voice/video clone escalates the payment-redirect play
  • Synthetic Media (general) · T12.21
    Broader AI-generated content family
How the Fake LandsSEC 04
  • Stage 01 · Clone
    A target's likeness or voice is synthesized from publicly available samples, producing audio, video, or images that read as the real person.
  • Stage 02 · Stage the Context
    The synthetic media is delivered inside a plausible scenario — an urgent call from the "CEO," a "relative" in distress, a leaked "clip" — that supplies a reason to act now.
  • Stage 03 · Convert
    Borrowed identity plus urgency drives the payoff: a wire transfer, credentials, a damaged reputation, or a believed falsehood — before out-of-band verification happens.
Counter-ProtocolSEC 05
Defense: Treat audio and video as claims, not proof — verify the person through a channel you control.
  • Verify out-of-band. For any consequential ask, hang up and reach the real person via a known, independent contact — a saved number, an official line — never the channel that delivered the media.
  • Use a shared verification cue. Agree in advance on a family or team code phrase for urgent money or access requests; a real caller can supply it, a clone typically cannot.
  • Check provenance. Look for content credentials / provenance signals (e.g., C2PA-style metadata), reverse-image search stills, and corroboration from the person's official channels before believing or resharing.
  • Slow the money and the share. Route urgent payments through a second-approver step and don't amplify a shocking clip until it's confirmed — urgency is the lever the fake depends on.