Deepfake impersonation of executives moved from an edge-case warning to a documented Singapore problem faster than most corporate security policies have adapted. The cases on record are specific enough to be worth knowing in detail.
What's actually happened
In one documented case, a company finance director was tricked into transferring over S$499,000 after joining a fake Zoom conference featuring deepfake impersonation of the company's CEO and colleagues. In a separate, more striking incident, a fabricated video conference purported to include Singapore's President, Prime Minister, a government minister and MAS representatives, alongside international figures — a fabrication sophisticated enough to warrant a formal police statement.
MAS has separately flagged deepfake risk directly to financial institutions, and the joint advisory from MAS, the Singapore Police Force and the Cyber Security Agency addresses this category of scam specifically, not as a hypothetical.
The regulatory response, current as of this writing
- Enhanced banking safeguards took effect from October 2025, contributing to a measurable reduction in impersonation scam losses since introduction.
- The Online Safety (Relief and Accountability) Bill, passed by Parliament in November 2025, established an Online Safety Commission with powers to direct takedowns, restrict perpetrator accounts, and assist victims identifying anonymous actors.
- A "multi-layered approach" has been the explicit government framing — government agencies, banks, platforms and individuals all carrying part of the defence, not any single safeguard being treated as sufficient alone.
Why detection tools aren't the full answer
Deepfake detection technology exists and continues to improve, but documented losses have occurred despite its availability — sophisticated fabrications, delivered under time pressure in a live call, don't always trigger the doubt a viewer would apply with time to scrutinise. The more reliable defence is procedural rather than technical.
The defence that actually holds up isn't spotting the fake in the moment. It's a verification step that doesn't depend on trusting what's seen or heard at all.
What actually works procedurally
Out-of-band verification for any high-value or unusual request, even one that appears to come from a live video call with a recognisable executive — a callback to a known number, not a number provided on the call itself.
A standing rule that no financial transfer is authorised solely through a video or voice call, regardless of how convincing it appears, without a separate confirmation channel.
Executive-level awareness that their own likeness is a target, independent of whether they've personally been impersonated yet — the exposure exists the moment enough public video and audio of someone exists to train a convincing model, which for most senior executives is already true.
If it happens to you
The response sequence — platform reporting, police report, a clear public statement, direct notification to likely targets — is covered in full in our guide to investment-scam impersonation, which applies directly to deepfake-specific incidents as well.