The first time you deal with a convincing fake of your own executive, you learn something uncomfortable: the question isn’t whether it’s real. You know it isn’t real.
The question is how you prove that to eleven thousand people who already shared it, a reporter who’s on deadline in forty minutes, and a board member who’s calling because his neighbor sent him the clip.
That gap between knowing and proving is where most crisis plans fall apart. They were written for a world where the facts, once established internally, could be communicated outward and generally believed.
Synthetic media broke that assumption. So did the volume of leaked data now sitting in places you’ll never fully map.

What follows isn’t a survey of the threat landscape. It’s what tends to matter when the thing actually happens, and what you can put in place beforehand so you’re not improvising at 11pm on a Friday.
The Fake Doesn’t Have to Be Good
There’s a persistent assumption that the dangerous fakes are the technically impressive ones. The photorealistic video. The voice clone is indistinguishable from the source.
Wrong problem.
The Pelosi video in 2019 was slowed down. That’s it. No model, no training data, no GPU cluster. It moved anyway, because it confirmed something people were already inclined to believe and because slowing footage is cheap enough that nobody had to be committed to the project. The bar for causing damage is not “fools a forensic analyst.” The bar “survives eight seconds of scrolling.”
Which means your monitoring can’t be tuned only for AI artifacts. A screenshot of an email that never existed, a quote card attributed to your CEO with a plausible-looking outlet logo, a product photo with one detail altered. Those don’t trip detection tools. They trip your customers.
Design for the sloppy version. The sophisticated version is rarer and, oddly, easier to disprove.
Deepfakes Hit Finance Before They Hit Comms
In February 2024, Hong Kong police described a case that should be printed and stuck to the wall of every treasury department. An employee at a multinational joined a video call with what appeared to be the CFO and several colleagues.
Everyone on the call was synthetic. The employee, who had been suspicious of an earlier email, was reassured by seeing familiar faces and approved transfers totaling roughly 25 million US dollars.
Notice the sequence.
The written phishing attempt failed. The video succeeded. The fake worked precisely because the company had trained people to verify suspicious requests, and the verification step was the thing that got compromised.
Gregor Emmian, Deputy Chief Digital Growth Officer at Rise, works across fintech and SaaS growth where transaction authorization and customer trust sit on the same infrastructure.
He says, “The uncomfortable part for financial services is that our fraud controls were built around verifying identity through channels we assumed were hard to fake. Voice and video were the fallback when something looked wrong on email.
That fallback is gone, and most authorization workflows have not caught up. If your escalation path ends with someone saying they recognized the person on the call, you do not have control, you have a habit.”
The story your audience hears is that your company wired money to criminals. Pre-draft for the second version.
Leaked Data Is Raw Material Now
Old model of a breach: attacker takes data, sells it or dumps it, you notify affected parties, you absorb the regulatory and reputational hit, it winds down.

New model: the leak is an ingredient.
Internal emails give an adversary tone, names, project code words, the way your VP of Ops signs off, the fact that a particular product line had a quality escalation in March. Feed that into fabricated content, and you get something that doesn’t just look real, it corroborates.
Someone builds a fake audio clip of your operations lead discussing that March escalation, using details only an insider would plausibly know, and now your denial has to fight actual leaked material that supports the frame.
MOVEit demonstrated the reach problem in 2023, where organizations with no direct relationship to the software found themselves exposed through the supply chain.
23andMe demonstrated the compounding problem, where credential reuse and scraping turned a partial compromise into something much wider, involving deeply personal information.
The practical implication for a comms team is that your breach response window doesn’t close when the vulnerability is patched. Keep monitoring for derivative content for months. Keep the incident’s factual record accessible internally, because in eight months when a fabricated clip references it, you’ll need to know exactly what was and wasn’t in the exposed set, and the person who knew that will have left.
Consumer Brands Get a Different Version of This
Nobody makes a deepfake of a mid-market supplement brand’s CEO. That’s not the threat.
The threat is a thousand small fabrications. AI-generated review text that reads like a real customer. Product photos with your packaging and someone else’s contents.
A fake endorsement video where a fitness creator who has never used your product appears to recommend it, and the creator’s audience trusts them, and the traffic goes to a counterfeit storefront.
Ryan Beattie, Director of Business Development at UK SARMs, works in a category where product authenticity and counterfeit listings are an ongoing operational reality rather than a hypothetical risk.
He says, “In our sector, the fabrication is rarely aimed at the brand’s leadership, it is aimed at the buyer. Someone clones the storefront, generates fake reviews and fake endorsement clips, and sells something that has nothing to do with what we actually produce. The reputational damage lands on us regardless.
What has worked is making verification boringly easy for the customer, clear batch records, third-party testing they can check themselves, and a single authoritative place to confirm a seller is legitimate. You cannot argue people out of a convincing fake, but you can give them a faster way to check.”
That last point generalizes further than the category. Argument is slow. Verification infrastructure is fast.
Provenance Is a Filing System, Not a Shield
Content Credentials and C2PA get discussed as if they solve authenticity. They don’t. Nothing stops a bad actor from publishing unsigned content, and most platforms strip or ignore metadata anyway.
What provenance actually gives you is a defensible archive of your own material, signed at creation, so that when you need to publish the original footage of the product test, you’re not asking people to trust a file you uploaded at 2 am.
Sign everything brand-owned. Require it from agencies and production partners in the contract, not in the kickoff call. Store originals somewhere your comms lead can retrieve without filing a ticket.

It’s unglamorous. It matters mostly on one bad day, which is the definition of most insurance.
Write the Runbook Someone Will Actually Open
Most crisis documents fail because they’re written to be reviewed by legal, not used under pressure. Forty pages, thematic sections, no phone numbers.
Three pre-approved statement templates. Suspected synthetic content, still verifying. Confirmed synthetic content, here’s our evidence. Data exposure with active downstream manipulation, which is the ugly one because you’re simultaneously admitting something real and denying something fake.
A roster with mobile numbers. Detection lead. Legal. Named spokesperson and named backup. Platform contacts, actual humans where you have them, escalation forms where you don’t. Executive approver, plus who decides if that person is unreachable, which happens more than the plan assumes.
A decision threshold, agreed in advance with legal and security, for what “confirmed” means. Not a philosophical standard. A specific one. Two independent detection signals plus source analysis, or whatever your team can defend. Deciding this during an incident guarantees a meeting instead of a response.
And a rule about the first hour: what you’re permitted to say before confirmation. Silence reads as confirmation. “We’re aware and investigating” costs almost nothing and buys real time.
Drills That Are Allowed to Go Badly
Quarterly. Partial information. No warning to the participants.
The point of a drill is not to demonstrate that the plan works. The point is to find the four things that break. Someone can’t reach legal. The spokesperson is on a plane.
Nobody has admin access to publish on the corporate account outside business hours. The detection tool returns a confidence score of 61 percent, and no one knows what to do with that.
Run scenarios with teeth:
- Fake CEO audio instructing a wire transfer, and the finance lead has to decide whether to freeze outbound payments company-wide, which has its own consequences.
- Manipulated footage of your product failing, and you have to find and publish the original within ninety minutes.
- Vendor breach where genuine internal emails are stitched into fabricated video, and you have to explain publicly which parts are real, in a way that doesn’t sound like partial denial.
Invite security to sit in the room. Not to present. To participate, and to see how fast comms is expected to move, which usually surprises them.
The Part That Gets Left Out
Every organization deploying detection tooling should be able to answer who is accountable when the tool is wrong.
False positives have victims. If your monitoring flags an employee’s genuine video as synthetic, or your vendor’s model misclassifies a legitimate customer complaint as a coordinated campaign, someone bears the consequence of that error. Write down how you handle it before you need to.
Same with the tools you use offensively. If you’re cloning a voice for localization, get explicit consent, in writing, with scope limits. If you’re monitoring employee communications as part of insider risk, disclose it. The organizations that will struggle most in the next few years aren’t the ones that got deepfaked.
They’re the ones whose response to being deepfaked involved surveillance practices they hadn’t told anyone about.
What You’re Building Toward
A colleague once described her team’s readiness standard as: could a mid-level person, alone, on a Sunday, take the right first three actions without calling anyone?
That’s the bar. Not a strategy document. Three actions, executable by whoever happens to be there.
Most teams aren’t close to it, and the gap is rarely knowledge. It’s that nobody has phone numbers, nobody has publishing access, and nobody has permission to speak before the lawyers wake up.
Build your crisis response plan before you need it. See how Agility PR helps comms teams monitor, verify, and respond to synthetic media threats in real time.



