{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
        "slug": "do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action",
        "url": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/"
        },
        "title": "Do not let a familiar voice or face authorize a sensitive action",
        "summary": "Synthetic voice and video can make an impostor look familiar. Remove media familiarity from help-desk resets, executive requests, and payment approvals; verify through independent identity and workflow controls.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "A sensitive-action approval path resisting synthetic voice and face impersonation through independent verification.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action-card.webp?v=1.8.2",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action-hero.webp?v=1.8.2",
            "social_url": "https://update.dsesecurity.com/assets/editorial/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action-social.jpg?v=1.8.2",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-04T22:53:02+00:00",
        "modified_at": "2026-08-04T22:53:02+00:00",
        "reviewed_on": "2026-08-04",
        "reading_minutes": 4,
        "word_count": 702,
        "potentially_affected": "Help desks, identity administrators, executives and assistants, finance and payment teams, procurement, human resources, communications, and fraud or incident response teams.",
        "dse_recommendation": "Identify sensitive workflows, stop treating voice or video as identity proof, require independent callbacks and in-system approvals, and use detection tools only as supporting evidence.",
        "primary_source": {
            "name": "NIST AI 100-4, Reducing Risks Posed by Synthetic Content",
            "url": "https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content",
            "published_on": "2024-11-20",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: realistic media does not establish identity</h2>\r\n<p>The FBI has described attackers who impersonate employees to persuade help desks to reset credentials and attackers who use synthetic voice or video to impersonate executives. In an <a href=\"https://www.fbi.gov/video-repository/ahead-of-the-threat-podcast-s1-e6-charles-carmakal/view\">FBI Ahead of the Threat discussion</a>, investigators explain that personal knowledge questions may be answered from information attackers obtain elsewhere. A familiar face, voice, supervisor name, or biographical detail can make a request persuasive without making it authentic.</p>\r\n<p>The FBI&#8217;s <a href=\"https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-continue-to-be-impersonated-in-malicious-messaging-campaign\">2025 impersonation alert</a> reports malicious text and AI-generated voice messages impersonating senior officials and advises recipients to independently verify identity rather than assume a message is authentic. The FTC&#8217;s <a href=\"https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/04/approaches-address-ai-enabled-voice-cloning\">review of approaches to AI-enabled voice cloning</a> says no single intervention solves the problem and discusses limitations and false results across detection and other technical approaches.</p>\r\n<h2>DSE recommendation: make the workflow the authority</h2>\r\n<p><strong>DSE recommendation:</strong> classify live and recorded audio or video as untrusted presentation, not identity proof. A detector may add a signal, but a sensitive action should be authorized by an independently authenticated person using an approved system of record. This article differs from DSE&#8217;s existing business-email-compromise guidance: it focuses on identity proof and action authorization when an attacker can convincingly reproduce a person&#8217;s voice or image.</p>\r\n<h2>Apply the control where impersonation changes access or money</h2>\r\n<ul>\r\n<li><strong>Help-desk and identity actions:</strong> password and multifactor resets, new authenticator enrollment, recovery-contact changes, account unlocks, privilege changes, and device registration.</li>\r\n<li><strong>Executive and administrative requests:</strong> release of confidential information, creation of accounts, changes to access, urgent travel or personnel requests, and instructions to bypass a normal control.</li>\r\n<li><strong>Finance and commercial actions:</strong> new or changed payment instructions, bank-detail changes, refunds, gift-card or cryptocurrency purchases, new suppliers, and release of a held payment.</li>\r\n</ul>\r\n<p>Map each action to an authoritative request channel, required authentication, approver, separation of duties, evidence retained, and an alternate process for genuine emergencies. The requester must not be allowed to choose a new phone number, email address, messaging account, or colleague as the only verification route.</p>\r\n<h2>Checklist for help desks</h2>\r\n<ol>\r\n<li>Locate the user in an existing trusted directory; do not rely on contact details provided in the inbound request.</li>\r\n<li>Use an established authenticated channel or call a previously recorded number. If that path is unavailable, use the documented recovery process and its additional approval rather than improvising.</li>\r\n<li>Verify the requested action and its business reason. Treat urgency, secrecy, and pressure to avoid a callback as risk signals, not proof of fraud.</li>\r\n<li>Require independent approval for high-impact resets or privilege changes according to local policy. The same person should not both override identity proof and execute an irreversible action without review.</li>\r\n<li>Notify the account owner through a separate established channel and preserve the request, verification steps, decision, operator, and resulting account changes.</li>\r\n</ol>\r\n<h2>Checklist for executives and payment teams</h2>\r\n<p>Route instructions into the normal approval system and require the same authorization steps regardless of whether the request arrived by video conference, phone, text, or email. For a material change, call back through a known directory or confirm in an existing authenticated workflow. Verify the transaction details as well as the person: payee, account, amount, purpose, contract or invoice, and approving authority. An executive&#8217;s presence on video should not cancel dual approval or supplier bank-change validation.</p>\r\n<h2>Use detection as supporting evidence</h2>\r\n<p><a href=\"https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content\">NIST AI 100-4</a> surveys provenance and authentication, watermarking, detection, testing, and auditing for synthetic content. These techniques can contribute evidence, but coverage varies by content, generator, transformation, and operating condition. Validate any tool on the media and decisions where it will be used; document false-positive and false-negative consequences. Do not let a detector&#8217;s clean result authorize a reset or payment.</p>\r\n<p>When impersonation is suspected, stop the action, preserve the original message and metadata, contact the real person through a known route, notify fraud or incident response, and follow reporting obligations. Avoid repeatedly forwarding sensitive media through consumer tools, which can lose metadata and expose information. The durable defense is a workflow that remains valid even when the voice and face are perfect.</p>\r\n<h2>Official sources</h2>\r\n<ul>\r\n<li><a href=\"https://www.fbi.gov/video-repository/ahead-of-the-threat-podcast-s1-e6-charles-carmakal/view\">FBI: Ahead of the Threat, identity impersonation and synthetic media discussion</a></li>\r\n<li><a href=\"https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-continue-to-be-impersonated-in-malicious-messaging-campaign\">FBI: Senior Officials Continue to Be Impersonated in Malicious Messaging Campaign</a></li>\r\n<li><a href=\"https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/04/approaches-address-ai-enabled-voice-cloning\">FTC: Approaches to Address AI-Enabled Voice Cloning</a></li>\r\n<li><a href=\"https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content\">NIST: AI 100-4, Reducing Risks Posed by Synthetic Content</a></li>\r\n</ul>",
        "content_text": "Source fact: realistic media does not establish identity\r\nThe FBI has described attackers who impersonate employees to persuade help desks to reset credentials and attackers who use synthetic voice or video to impersonate executives. In an FBI Ahead of the Threat discussion, investigators explain that personal knowledge questions may be answered from information attackers obtain elsewhere. A familiar face, voice, supervisor name, or biographical detail can make a request persuasive without making it authentic.\r\nThe FBI’s 2025 impersonation alert reports malicious text and AI-generated voice messages impersonating senior officials and advises recipients to independently verify identity rather than assume a message is authentic. The FTC’s review of approaches to AI-enabled voice cloning says no single intervention solves the problem and discusses limitations and false results across detection and other technical approaches.\r\nDSE recommendation: make the workflow the authority\r\nDSE recommendation: classify live and recorded audio or video as untrusted presentation, not identity proof. A detector may add a signal, but a sensitive action should be authorized by an independently authenticated person using an approved system of record. This article differs from DSE’s existing business-email-compromise guidance: it focuses on identity proof and action authorization when an attacker can convincingly reproduce a person’s voice or image.\r\nApply the control where impersonation changes access or money\r\n\r\nHelp-desk and identity actions: password and multifactor resets, new authenticator enrollment, recovery-contact changes, account unlocks, privilege changes, and device registration.\r\nExecutive and administrative requests: release of confidential information, creation of accounts, changes to access, urgent travel or personnel requests, and instructions to bypass a normal control.\r\nFinance and commercial actions: new or changed payment instructions, bank-detail changes, refunds, gift-card or cryptocurrency purchases, new suppliers, and release of a held payment.\r\n\r\nMap each action to an authoritative request channel, required authentication, approver, separation of duties, evidence retained, and an alternate process for genuine emergencies. The requester must not be allowed to choose a new phone number, email address, messaging account, or colleague as the only verification route.\r\nChecklist for help desks\r\n\r\nLocate the user in an existing trusted directory; do not rely on contact details provided in the inbound request.\r\nUse an established authenticated channel or call a previously recorded number. If that path is unavailable, use the documented recovery process and its additional approval rather than improvising.\r\nVerify the requested action and its business reason. Treat urgency, secrecy, and pressure to avoid a callback as risk signals, not proof of fraud.\r\nRequire independent approval for high-impact resets or privilege changes according to local policy. The same person should not both override identity proof and execute an irreversible action without review.\r\nNotify the account owner through a separate established channel and preserve the request, verification steps, decision, operator, and resulting account changes.\r\n\r\nChecklist for executives and payment teams\r\nRoute instructions into the normal approval system and require the same authorization steps regardless of whether the request arrived by video conference, phone, text, or email. For a material change, call back through a known directory or confirm in an existing authenticated workflow. Verify the transaction details as well as the person: payee, account, amount, purpose, contract or invoice, and approving authority. An executive’s presence on video should not cancel dual approval or supplier bank-change validation.\r\nUse detection as supporting evidence\r\nNIST AI 100-4 surveys provenance and authentication, watermarking, detection, testing, and auditing for synthetic content. These techniques can contribute evidence, but coverage varies by content, generator, transformation, and operating condition. Validate any tool on the media and decisions where it will be used; document false-positive and false-negative consequences. Do not let a detector’s clean result authorize a reset or payment.\r\nWhen impersonation is suspected, stop the action, preserve the original message and metadata, contact the real person through a known route, notify fraud or incident response, and follow reporting obligations. Avoid repeatedly forwarding sensitive media through consumer tools, which can lose metadata and expose information. The durable defense is a workflow that remains valid even when the voice and face are perfect.\r\nOfficial sources\r\n\r\nFBI: Ahead of the Threat, identity impersonation and synthetic media discussion\r\nFBI: Senior Officials Continue to Be Impersonated in Malicious Messaging Campaign\r\nFTC: Approaches to Address AI-Enabled Voice Cloning\r\nNIST: AI 100-4, Reducing Risks Posed by Synthetic Content",
        "content_markdown": "## Source fact: realistic media does not establish identity\n\nThe FBI has described attackers who impersonate employees to persuade help desks to reset credentials and attackers who use synthetic voice or video to impersonate executives. In an [FBI Ahead of the Threat discussion](https://www.fbi.gov/video-repository/ahead-of-the-threat-podcast-s1-e6-charles-carmakal/view), investigators explain that personal knowledge questions may be answered from information attackers obtain elsewhere. A familiar face, voice, supervisor name, or biographical detail can make a request persuasive without making it authentic.\n\nThe FBI’s [2025 impersonation alert](https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-continue-to-be-impersonated-in-malicious-messaging-campaign) reports malicious text and AI-generated voice messages impersonating senior officials and advises recipients to independently verify identity rather than assume a message is authentic. The FTC’s [review of approaches to AI-enabled voice cloning](https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/04/approaches-address-ai-enabled-voice-cloning) says no single intervention solves the problem and discusses limitations and false results across detection and other technical approaches.\n\n## DSE recommendation: make the workflow the authority\n\nDSE recommendation: classify live and recorded audio or video as untrusted presentation, not identity proof. A detector may add a signal, but a sensitive action should be authorized by an independently authenticated person using an approved system of record. This article differs from DSE’s existing business-email-compromise guidance: it focuses on identity proof and action authorization when an attacker can convincingly reproduce a person’s voice or image.\n\n## Apply the control where impersonation changes access or money\n\n- Help-desk and identity actions: password and multifactor resets, new authenticator enrollment, recovery-contact changes, account unlocks, privilege changes, and device registration.\n\n- Executive and administrative requests: release of confidential information, creation of accounts, changes to access, urgent travel or personnel requests, and instructions to bypass a normal control.\n\n- Finance and commercial actions: new or changed payment instructions, bank-detail changes, refunds, gift-card or cryptocurrency purchases, new suppliers, and release of a held payment.\n\nMap each action to an authoritative request channel, required authentication, approver, separation of duties, evidence retained, and an alternate process for genuine emergencies. The requester must not be allowed to choose a new phone number, email address, messaging account, or colleague as the only verification route.\n\n## Checklist for help desks\n\n- Locate the user in an existing trusted directory; do not rely on contact details provided in the inbound request.\n\n- Use an established authenticated channel or call a previously recorded number. If that path is unavailable, use the documented recovery process and its additional approval rather than improvising.\n\n- Verify the requested action and its business reason. Treat urgency, secrecy, and pressure to avoid a callback as risk signals, not proof of fraud.\n\n- Require independent approval for high-impact resets or privilege changes according to local policy. The same person should not both override identity proof and execute an irreversible action without review.\n\n- Notify the account owner through a separate established channel and preserve the request, verification steps, decision, operator, and resulting account changes.\n\n## Checklist for executives and payment teams\n\nRoute instructions into the normal approval system and require the same authorization steps regardless of whether the request arrived by video conference, phone, text, or email. For a material change, call back through a known directory or confirm in an existing authenticated workflow. Verify the transaction details as well as the person: payee, account, amount, purpose, contract or invoice, and approving authority. An executive’s presence on video should not cancel dual approval or supplier bank-change validation.\n\n## Use detection as supporting evidence\n\n[NIST AI 100-4](https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content) surveys provenance and authentication, watermarking, detection, testing, and auditing for synthetic content. These techniques can contribute evidence, but coverage varies by content, generator, transformation, and operating condition. Validate any tool on the media and decisions where it will be used; document false-positive and false-negative consequences. Do not let a detector’s clean result authorize a reset or payment.\n\nWhen impersonation is suspected, stop the action, preserve the original message and metadata, contact the real person through a known route, notify fraud or incident response, and follow reporting obligations. Avoid repeatedly forwarding sensitive media through consumer tools, which can lose metadata and expose information. The durable defense is a workflow that remains valid even when the voice and face are perfect.\n\n## Official sources\n\n- [FBI: Ahead of the Threat, identity impersonation and synthetic media discussion](https://www.fbi.gov/video-repository/ahead-of-the-threat-podcast-s1-e6-charles-carmakal/view)\n\n- [FBI: Senior Officials Continue to Be Impersonated in Malicious Messaging Campaign](https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-continue-to-be-impersonated-in-malicious-messaging-campaign)\n\n- [FTC: Approaches to Address AI-Enabled Voice Cloning](https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/04/approaches-address-ai-enabled-voice-cloning)\n\n- [NIST: AI 100-4, Reducing Risks Posed by Synthetic Content](https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content)"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
                "url": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-04"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not let a familiar voice or face authorize a sensitive action",
                        "item": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/#article",
                "identifier": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
                "url": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/",
                "headline": "Do not let a familiar voice or face authorize a sensitive action",
                "description": "Synthetic voice and video can make an impostor look familiar. Remove media familiarity from help-desk resets, executive requests, and payment…",
                "abstract": "Synthetic voice and video can make an impostor look familiar. Remove media familiarity from help-desk resets, executive requests, and payment approvals; verify through independent identity and workflow controls.",
                "articleBody": "Source fact: realistic media does not establish identity\r\nThe FBI has described attackers who impersonate employees to persuade help desks to reset credentials and attackers who use synthetic voice or video to impersonate executives. In an FBI Ahead of the Threat discussion, investigators explain that personal knowledge questions may be answered from information attackers obtain elsewhere. A familiar face, voice, supervisor name, or biographical detail can make a request persuasive without making it authentic.\r\nThe FBI’s 2025 impersonation alert reports malicious text and AI-generated voice messages impersonating senior officials and advises recipients to independently verify identity rather than assume a message is authentic. The FTC’s review of approaches to AI-enabled voice cloning says no single intervention solves the problem and discusses limitations and false results across detection and other technical approaches.\r\nDSE recommendation: make the workflow the authority\r\nDSE recommendation: classify live and recorded audio or video as untrusted presentation, not identity proof. A detector may add a signal, but a sensitive action should be authorized by an independently authenticated person using an approved system of record. This article differs from DSE’s existing business-email-compromise guidance: it focuses on identity proof and action authorization when an attacker can convincingly reproduce a person’s voice or image.\r\nApply the control where impersonation changes access or money\r\n\r\nHelp-desk and identity actions: password and multifactor resets, new authenticator enrollment, recovery-contact changes, account unlocks, privilege changes, and device registration.\r\nExecutive and administrative requests: release of confidential information, creation of accounts, changes to access, urgent travel or personnel requests, and instructions to bypass a normal control.\r\nFinance and commercial actions: new or changed payment instructions, bank-detail changes, refunds, gift-card or cryptocurrency purchases, new suppliers, and release of a held payment.\r\n\r\nMap each action to an authoritative request channel, required authentication, approver, separation of duties, evidence retained, and an alternate process for genuine emergencies. The requester must not be allowed to choose a new phone number, email address, messaging account, or colleague as the only verification route.\r\nChecklist for help desks\r\n\r\nLocate the user in an existing trusted directory; do not rely on contact details provided in the inbound request.\r\nUse an established authenticated channel or call a previously recorded number. If that path is unavailable, use the documented recovery process and its additional approval rather than improvising.\r\nVerify the requested action and its business reason. Treat urgency, secrecy, and pressure to avoid a callback as risk signals, not proof of fraud.\r\nRequire independent approval for high-impact resets or privilege changes according to local policy. The same person should not both override identity proof and execute an irreversible action without review.\r\nNotify the account owner through a separate established channel and preserve the request, verification steps, decision, operator, and resulting account changes.\r\n\r\nChecklist for executives and payment teams\r\nRoute instructions into the normal approval system and require the same authorization steps regardless of whether the request arrived by video conference, phone, text, or email. For a material change, call back through a known directory or confirm in an existing authenticated workflow. Verify the transaction details as well as the person: payee, account, amount, purpose, contract or invoice, and approving authority. An executive’s presence on video should not cancel dual approval or supplier bank-change validation.\r\nUse detection as supporting evidence\r\nNIST AI 100-4 surveys provenance and authentication, watermarking, detection, testing, and auditing for synthetic content. These techniques can contribute evidence, but coverage varies by content, generator, transformation, and operating condition. Validate any tool on the media and decisions where it will be used; document false-positive and false-negative consequences. Do not let a detector’s clean result authorize a reset or payment.\r\nWhen impersonation is suspected, stop the action, preserve the original message and metadata, contact the real person through a known route, notify fraud or incident response, and follow reporting obligations. Avoid repeatedly forwarding sensitive media through consumer tools, which can lose metadata and expose information. The durable defense is a workflow that remains valid even when the voice and face are perfect.\r\nOfficial sources\r\n\r\nFBI: Ahead of the Threat, identity impersonation and synthetic media discussion\r\nFBI: Senior Officials Continue to Be Impersonated in Malicious Messaging Campaign\r\nFTC: Approaches to Address AI-Enabled Voice Cloning\r\nNIST: AI 100-4, Reducing Risks Posed by Synthetic Content",
                "datePublished": "2026-08-04T22:53:02+00:00",
                "dateModified": "2026-08-04T22:53:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action-social.jpg?v=1.8.2",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/posts/do-not-let-a-familiar-voice-or-face-authorize-a-sensitive-action-social.jpg?v=1.8.2",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not let a familiar voice or face authorize a sensitive action"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 702,
                "timeRequired": "PT4M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST AI 100-4, Reducing Risks Posed by Synthetic Content",
                    "url": "https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content",
                    "datePublished": "2024-11-20"
                }
            }
        ]
    }
}