Deepfake Executive Impersonation on Earnings Calls: A Regulatory Response Playbook for Public Companies and Their IR Teams

The voice on the earnings call sounds exactly like your CFO. The cadence, the vocabulary, the slight pause before discussing guidance — all unmistakably familiar. But it isn't her. It's a deepfake, and by the time your investor relations team realizes what's happened, the market has already moved.
This is no longer a hypothetical. Deepfake executive impersonation is an emerging and rapidly escalating threat vector for public companies. In 2024, a multinational firm lost over $25 million after a finance employee was deceived by a deepfake video call impersonating the company's CFO. As generative AI tools become cheaper, more accessible, and more convincing, the attack surface for publicly traded companies — where executives regularly appear in recorded, streamed, and broadcast communications — grows exponentially.
For investor relations (IR) teams, legal counsel, and boards of directors, the question is no longer if this will happen — it's when, and whether you'll be ready when it does.
Understanding the Threat Landscape
Deepfake impersonation in the context of earnings calls represents a convergence of several risk categories: cybersecurity, securities law, market manipulation, and reputational damage. Threat actors — whether financially motivated, nation-state affiliated, or activist in nature — can synthesize convincing audio or video of a CEO or CFO making false statements about earnings, guidance, M&A activity, or regulatory matters.
The downstream consequences are severe. False statements made under the guise of an executive can trigger SEC disclosure obligations, investor litigation, stock price volatility, and regulatory investigations — even when the company is the victim, not the perpetrator. The SEC's enhanced focus on material cybersecurity incident disclosure under its 2023 rules adds another layer of urgency: a deepfake attack that influences market behavior may itself constitute a reportable event.
Step 1: Conduct a Pre-Incident Risk Assessment
Before building a response playbook, IR teams must first understand their exposure. This means auditing how much publicly available audio and video exists of your key executives — earnings calls, conference presentations, media interviews, and investor day footage. Every clip is potential training data for a voice or face clone.
Engage your CISO and a third-party threat intelligence provider to assess your organization's deepfake risk profile. Identify which executives are most exposed, which communication channels are most vulnerable, and whether any threat actor has already begun collecting or weaponizing executive media assets. This assessment should feed directly into your incident response plan.
Step 2: Establish Authentication Protocols for Live Executive Communications
Authentication is your first line of defense. Public companies should implement layered verification procedures for any live or pre-recorded executive communication that reaches investors or media.
For earnings calls specifically, consider working with your IR platform providers to introduce multi-factor authentication for dial-in hosts, real-time watermarking of audio streams, and cryptographic verification of pre-recorded segments. IR teams should develop internal challenge-response protocols — known only to a small circle — that can be used to verify executive identity before a live session begins. Some organizations are beginning to explore blockchain-anchored content provenance tools that can verify the authenticity of recorded media at the point of distribution.
Step 3: Build a Cross-Functional Incident Response Team
When a deepfake attack occurs, the clock starts immediately. You need a pre-designated, cross-functional response team that includes your General Counsel, CISO, Head of IR, Chief Communications Officer, and an external securities law firm with crisis experience. Each member must know their role before an incident happens.
The response team's first priority is containment and verification — confirming the attack is real, identifying the scope of distribution, and determining whether any material false statements were disseminated to investors. This assessment will drive every subsequent decision, from whether to issue a corrective public statement to whether SEC disclosure is required under Item 1.05 of Form 8-K.
Step 4: Navigate SEC Disclosure Obligations with Precision
This is where many public companies will find themselves in uncharted territory. The SEC's 2023 cybersecurity disclosure rules require registrants to disclose material cybersecurity incidents within four business days of determining materiality. A deepfake attack that causes market disruption, investor confusion, or requires a corrective statement may well meet that threshold.
Work closely with your securities counsel to evaluate materiality in real time. Consider proactive communication with your SEC Enforcement liaison if there is any risk of market manipulation allegations. Document everything — your timeline, your verification steps, your response decisions, and your communications. This documentation will be critical if the incident results in an SEC inquiry, shareholder litigation, or FINRA review.
Step 5: Prepare a Rapid Public Communications Strategy
Silence is not a strategy. If a deepfake of your CEO circulates before or during an earnings call, your IR team must be prepared to issue a rapid, clear, and factual public statement that: (1) confirms the communication was fraudulent, (2) clarifies what was and was not actually stated by company leadership, (3) directs investors to official company channels, and (4) signals that law enforcement and regulators have been engaged.
Pre-draft template statements now, while there is no crisis. Identify your approved spokespersons and ensure your IR team, PR agency, and legal counsel are aligned on approval workflows that can be executed in under two hours.
Step 6: Engage Law Enforcement and Preserve Digital Evidence
File a report with the FBI's Internet Crime Complaint Center (IC3) and notify the Secret Service if market manipulation is suspected. Simultaneously, engage your digital forensics team to preserve all evidence of the deepfake — source files, metadata, distribution pathways, and any associated social engineering attempts. This evidence chain will be essential for both criminal prosecution and civil litigation.
Building a Culture of Deepfake Vigilance
Beyond incident response, public companies must invest in ongoing education. Your IR team, executive assistants, board members, and communications staff should be trained to recognize the signs of synthetic media — unnatural blinking patterns, audio latency, inconsistent lip sync, and contextually unusual statements. Annual tabletop exercises that simulate a deepfake earnings call attack will harden your team's muscle memory before it's needed.
The Regulatory Horizon
Regulators are beginning to catch up. The SEC has signaled interest in AI-generated misinformation as a market integrity issue, and legislative proposals at both federal and state levels are targeting malicious deepfake use in financial contexts. Public companies that demonstrate proactive governance — documented policies, trained teams, and tested response plans — will be better positioned with regulators and institutional investors alike.
Deepfake executive impersonation is not just a cybersecurity problem. It is a governance problem, a securities law problem, and a trust problem. The companies that treat it as such — and build response capabilities today — will be the ones that protect their investors, their reputations, and their regulatory standing when the threat arrives.
More scenarios

Living Document or Liability: How to Build a Policy Versioning System That Proves Employees Were Trained on the Right Version at the Right Time
Your security policies are only as strong as your ability to prove who was trained on what and when. Learn how to build a policy versioning system that transforms compliance from a checkbox into a defensible audit trail.
6 min read
Audit-Ready Chain of Custody: How to Document Content Approval Workflows Before Regulators Ask Who Approved What and When
When regulators come knocking, "we have a process" isn't enough. Learn how to build an airtight, audit-ready chain of custody for content approval workflows that answers every question before it's asked.
5 min read
Tiered Compliance Retainer Packaging: Structuring Bronze, Silver, and Gold Tiers That Map Deliverables to Regulatory Risk Levels
Discover how to design Bronze, Silver, and Gold compliance retainer packages that align cybersecurity deliverables to real regulatory risk levels — and make premium pricing an easy sell to security-conscious buyers.
6 min read
Retainer-Based Content Compliance Audits: How Agencies Are Pricing, Scoping, and Delivering Ongoing Regulatory Review as a Standalone Service Line in 2025
As regulatory frameworks grow more complex and dynamic, forward-thinking cybersecurity firms are packaging content compliance audits as recurring retainer services — and the market is responding. Here's how leading agencies are structuring, pricing, and delivering this emerging service line in 2025.
5 min read
The Citation Mirage: Why RAG-Powered Compliance Tools Surface Plausible-Sounding Sources That Don't Actually Support the Claims They're Attached To
RAG-powered compliance tools promise accuracy through citation, but a dangerous gap exists between plausible-sounding references and sources that actually support the claims they're attached to. Here's what compliance and security leaders need to know.
5 min read
Pre-Audit Content Inventory Playbook: How to Map, Tag, and Freeze Regulated Records Before Examiners Request Them
Waiting for examiners to request records is a reactive strategy that costs organizations time, credibility, and compliance standing. This playbook shows you how to proactively map, tag, and freeze regulated content before audit season begins.
5 min read
False Confidence in AI Detection Scores: Why Probability Outputs Are Not Compliance Evidence in Regulated Industries
AI detection scores feel authoritative — but in regulated industries, a probability output is not proof of compliance. Here's why organizations must rethink how they interpret and document AI-driven security decisions.
6 min read
Phantom Disclosures and Missing Material Terms: How AI-Generated Social Posts Are Triggering FTC Endorsement Guide Violations in Financial and Health Sectors
AI-generated marketing content is quietly creating serious FTC compliance gaps in the financial and health sectors. Here's what compliance and security leaders need to know before regulators come knocking.
5 min read
AI-Flagged vs. Human-Reviewed: A Decision Matrix for Triaging High-Stakes Security Incident Claims in 2025
As AI-driven detection tools become standard in security operations, knowing when to trust the machine — and when to escalate to a human analyst — can mean the difference between rapid containment and catastrophic breach. Here's the decision matrix your SOC needs in 2025.
5 min read
Substantiation Files for AI Wellness Apps: How to Build an FTC-Defensible Evidence Dossier Before Your Next Product Launch
As AI-powered wellness apps face intensifying FTC scrutiny, building a robust substantiation dossier before launch isn't optional—it's your first line of legal and reputational defense. Here's how to do it right.
5 min read
Content Provenance in Practice: The Seven Fields Every Verifiable Record Must Include to Satisfy AI Transparency Mandates in 2025
As AI transparency regulations tighten globally, organizations must embed verifiable provenance records into every piece of AI-generated or AI-assisted content. Here are the seven essential fields your records cannot afford to omit.
5 min read
What Patients Actually Have the Right to Know: Building a Compliant Breach Notification Program That Meets Modern Disclosure Expectations
Healthcare organizations face mounting pressure to get breach notifications right — legally, ethically, and operationally. Here's how to build a program that meets modern disclosure expectations and protects patient trust.
5 min read
When AI Detection Gets It Wrong: Building a Human-in-the-Loop Escalation Protocol for Regulated Content Failures
AI-powered threat detection is powerful — but it's not infallible. Learn how to design a human-in-the-loop escalation protocol that keeps your regulated environment resilient when automated systems miss the mark.
5 min read
Beyond the Black Box: Why AI Content Moderation Tools Fail Compliance Audits and What Regulated Industries Must Do Instead
AI content moderation tools promise efficiency, but their opaque decision-making processes are creating serious compliance blind spots for regulated industries. Here's what security and compliance leaders need to know.
5 min read
The Audit-Ready Gap: Why Your Security Documentation Passes Review but Fails Under Cross-Examination
Your security documentation may look flawless on paper, but when auditors dig deeper, the cracks appear. Here's why the gap between audit-ready and audit-proof is costing organizations more than they realize.
5 min read
How to Cite NIST CSF 2.0 as Regulatory Evidence: A Practitioner's Guide to Source-Grounded Security Claims
Learn how to properly cite NIST CSF 2.0 as credible regulatory evidence in audits, risk assessments, and compliance documentation — with actionable guidance for security practitioners.
5 min read
When a Critical CVE Drops at 9am, Your Clients Hear From You by Noon
A KEV-listed flaw lands on a Tuesday morning. Walk the minute-by-minute flow from detection to a sourced, client-branded, human-approved advisory — published across every channel before lunch.
5 min read
Security Awareness Training for 30 Clients, Without Producing It 30 Times
One CVE becomes a 60–90 second branded micro-lesson per client — one green-screen recording or an AI presenter, delivered where people actually are, with an audit trail on every lesson.
5 min read
Riding a Trending Study Without Making a Disease Claim
A supplement brand wants to ride a trending sleep study — but the draft says “helps treat insomnia.” How a compliance gate, claim-level citations, and one human approval let regulated brands publish fast, with receipts.
6 min read