A Real-Time Deepfake Call Targeted Veriff's Own Staff, and an Accent Gave It Away
What happened
Veriff is in the business of verifying that people are who they claim to be. In early 2025, someone turned that premise against the company itself. A colleague of CEO Kaarel Kotkas received a WhatsApp call that appeared to show Kotkas on video, delivering an urgent request. The call was not Kotkas. According to the company's own account, it was a real-time deepfake, a live video clone of the CEO's face assembled and transmitted in the moment.
The mechanics of the attack are worth pausing on. This was not a pre-recorded clip edited to look authentic. The scammers ran a live synthesis of Kotkas's face in real time, plausible enough for a video call on a mobile messaging platform. The WhatsApp medium was deliberate: it is informal, widely used for quick business conversations, and carries an implicit trust that a formal meeting link does not. An urgent request over a familiar channel is the fastest path past a person's skepticism, and the technology to deliver that request wearing a CEO's face is now within reach of fraud operations that are not nation-state actors.
What stopped the fraud was not a technical detection system. It was an accent. Andrea Rozenberg noticed that the voice on the call lacked Kotkas's Estonian inflection. She sent a Slack message to the real Kotkas directly, confirmed the call was not from him, and the fraud attempt collapsed. No money moved. The social engineering failed at the last inch because something in the performance did not match what the target already knew about the person being impersonated.
The fact that this happened to an identity verification company is not incidental. Veriff's entire product is built on the problem of confirming that a face and an identity are genuine. Its staff encounters forged documents, injection attacks on camera feeds, and spoofed credentials routinely. A real-time deepfake sophisticated enough to target a company like this suggests the technology has reached the point where fraud operations can assemble a convincing live face clone without the resources that would once have made it prohibitively expensive. If the defense for a firm that specializes in detecting exactly this kind of manipulation is an employee noticing a missing accent, organizations with no such background are in a worse position still.
The incident resolved without financial loss, which means it will likely stay in the category of near misses rather than prompting a formal investigation or disclosure beyond the company's own statements. But that outcome does not close the gap the attack reveals. The scammers who built and deployed that deepfake left no forensic trail that any external party can inspect. There is no provable record of what the system produced, when it ran, or who directed it. Until that kind of record is routine, every organization with a recognizable executive is relying on the assumption that a human moment of doubt will always be the last line of defense.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.