Zog Blog | Information Technology, Cybersecurity, Non-Profit IT, & More

The Hall of Mirrors: Can You Trust Who You're Talking To?

Written by Preston Miller | Oct 6, 2026, 5:59:21 PM

Your CFO joins a video call.

You can see him. You can hear him. And he tells you he’s working on something confidential and needs a document sent immediately.

Would you send it?

Most people would.

And that's what makes the next generation of impersonation attacks so concerning.

AI is making it increasingly possible to imitate voices, faces, writing styles and other characteristics we’ve traditionally used to decide whether someone is who they claim to be.

Welcome to Week 5 of Zog’s 8 Weeks of Cyber Horrors and The Hall of Mirrors—where seeing and hearing aren’t necessarily believing.

Identity Is Becoming Harder to Prove

For years, one of the most common pieces of cybersecurity advice has been:

“If you're unsure, call the person.”

That's still good advice.

But the bigger lesson is that businesses need trusted methods of verification that don't rely entirely on whether someone looks or sounds familiar.

Imagine receiving a voicemail from your CEO asking you to handle an urgent payment.

You recognize the voice.

Or you're invited to a video meeting with someone who appears to be a company executive.

You recognize the face.

Or a vendor sends a message that sounds exactly like the person you've worked with for years.

All of those signals can influence our decision to trust the request.

And attackers understand that.

AI Changes the Impersonation Game

Impersonation isn't new.

Cybercriminals have been pretending to be executives, vendors and employees for years.

What's changing is the technology available to make those impersonations more convincing.

AI tools can help attackers create polished emails, imitate communication styles, generate realistic images and potentially clone voices or manipulate video.

And they don't necessarily need an enormous amount of information to get started.

Executives speak at conferences.

Employees appear in webinars.

Companies post videos to LinkedIn and YouTube.

Podcasts contain hours of someone's voice.

Social media provides names, titles, relationships and details about what people are working on.

None of those activities are inherently dangerous.

But together, publicly available information can help an attacker build a much more convincing story.

The Attack Still Needs a Story

Technology alone doesn't make an impersonation attack successful.

The attacker also needs a reason for you to act.

That's where social engineering comes in.

“I'm traveling and can't access the system.”

“This acquisition is confidential, so don't involve anyone else.”

“I need this payment completed before the meeting.”

“Send me the employee file. I'll explain later.”

Notice what these requests have in common.

Urgency.

Authority.

Secrecy.

Attackers don't simply want you to believe the person is real.

They want to create a situation where verifying the request feels inconvenient, inappropriate or unnecessary.

That's when impersonation becomes especially dangerous.

The Target Isn't Always IT

When businesses think about cyberattacks, they often think about the IT department.

But impersonation attacks can target anyone with something valuable.

Finance may be targeted for wire transfers, banking information or payments.

HR may be targeted for employee records, payroll changes or sensitive personal information.

Executives may be targeted for credentials, confidential documents or strategic information.

Sales may encounter fake prospects or customers designed to get employees to open files, visit websites or disclose information.

Administrative employees may receive requests that appear to come directly from company leadership.

The attacker doesn't necessarily need access to your network.

Sometimes they simply need to convince the right employee to do something for them.

Familiar Doesn't Mean Verified

This creates a challenge for businesses.

Humans naturally use familiarity as a shortcut for trust.

I recognize the email address.

I recognize the voice.

I recognize the face.

I know this person.

Those signals still matter, but they shouldn't be the only things standing between an unusual request and a high-risk action.

The more sensitive the request, the stronger the verification should be.

Sending a routine document may require one level of confidence.

Changing banking information, transferring a large amount of money or sending confidential employee data should require another.

Verification should match the potential consequence of getting it wrong.

Deepfakes Don't Have to Be Perfect

It's tempting to think you'd immediately recognize a fake.

Maybe the video would look strange. Maybe the voice wouldn't sound quite right. Maybe something would give it away.

Sometimes it might.

But an impersonation doesn't need to withstand hours of forensic analysis.

It only needs to be convincing long enough for someone to act.

Add urgency, a believable business situation and the authority of an executive or trusted partner, and even an imperfect fake can become persuasive.

That's why the solution can't simply be:

“We'll know a deepfake when we see one.”

A Business Leader's Question - This week, ask your leadership team:

“If someone convincingly impersonated one of us tomorrow, what would stop an employee from acting on the request?”

There should be an answer beyond:

“They'd recognize that it wasn't me.”

Think about financial approvals.

Sensitive documents.

Payroll changes.

Password resets.

Banking changes.

Confidential information.

What independent verification happens before those actions are completed?

Because we're entering a world where proving identity may require more than recognizing a familiar face or voice.

The question businesses need to start asking isn't:

“Does this look and sound like the person?”

It's:

“How do we verify that it really is the person?”

Welcome to The Hall of Mirrors.

Can You Survive the Scare?

On Thursday, we'll look at practical ways businesses can escape The Hall of Mirrors by creating verification processes that don't depend solely on what employees see, hear or read.

Because when anyone can potentially wear a familiar face, trust needs a second look.