I Spent 3 Years Fighting Deepfakes: Here's What I Learned

Published 2025-11-16 · Updated 2026-05-23 · 7 min read · AI Security and Cybersecurity · By Sahin Boydas

I spent months researching Deepfakes and what I found shocked me. Here are the counterintuitive strategies that actually work.

I once sat down and interviewed 50 hackers about deepfakes. Their answers terrified me. Not because of the tech—I’m an engineer by trade and an investor in companies like Anthropic and OpenAI, so I’m optimistic about AI. What scared me was how they thought. They weren’t just thinking about fake videos of celebrities; they were thinking about weaponizing trust at scale.

That was the start of a three-year obsession. After my last company, RemoteTeam, was acquired by Gusto, I had the time and resources to go deep. I’d built my career on creating tools for distributed teams, where trust is everything. The idea that someone could use AI to impersonate me and destroy that trust overnight felt personal. It wasn't just a technical problem; it was an attack on the human connections that make remote work possible.

I’ve seen two of my companies get acquired and have invested in over 200 startups. I’ve seen a lot. But the sheer speed and creativity of AI-driven phishing and identity fraud is something else entirely. It’s an arms race, and for a while, the offense was winning by a mile.

The Hacker's Playbook: It's Not What You Think

The hackers I spoke to weren't focused on making a perfect, viral video. They were focused on something much simpler and more dangerous: voice cloning. One hacker told me, “Why spend a week making a video when I can clone a CEO’s voice in three hours with a few audio samples from a podcast and trick his finance department into wiring me $250,000?”

He was right. We almost fell for it.

At one of my portfolio companies, a senior finance manager got a call. The caller ID was spoofed to look like it was coming from the CEO. The voice on the other end was a perfect replica of his. It was urgent. A secret M&A deal was closing, and he needed a large sum wired to a new vendor immediately to avoid jeopardizing the transaction. The voice was impatient, a little stressed—exactly how the real CEO sounded under pressure.

What saved us? Not some fancy AI detection tool. It was a simple, boring, analog rule we had established: any wire transfer over $10,000, no matter how urgent, requires a live video confirmation or a callback to a pre-registered phone number. The manager hung up and called the CEO’s personal cell. The real CEO, of course, had no idea what he was talking about.

This wasn't a one-off. The hackers were using deepfakes for targeted, high-value attacks. They were scraping LinkedIn for org charts, listening to earnings calls for voice samples, and creating highly believable scenarios to exploit the weakest link: human trust.

Counterintuitive Defenses That Actually Work

After months of research and talking to experts, I realized that fighting AI with AI is only part of the solution. The most effective strategies I found were surprisingly low-tech and focused on process and people.

1. Build a Human Firewall

Your best defense isn't a piece of software; it's a culture of healthy skepticism. In a remote-first world, you can't just pop your head into someone's office to verify a strange request. You need to build the verification process into your company’s DNA.

  • Multi-channel Verification: For any sensitive action—changing payroll details, wiring money, sharing intellectual property—require confirmation on a separate channel. A Slack message followed by a call to a known number. An email followed by a video check-in.
  • Code Words: This sounds like something out of a spy movie, but it works. Have simple, rotating code words for verbal confirmations. If someone calls asking for a transfer, you ask for the word of the week. It’s simple, fast, and incredibly effective against audio deepfakes.
  • Drill, Drill, Drill: Run your own phishing drills, including voice phishing. Hire a red team to try and trick your employees. When they succeed, you learn. When they fail, you celebrate the process that worked. Make it a part of your security culture.

2. Go on the Offensive

Defense is a losing game. You have to be proactive. The people trying to scam you are organized, and you should be too. I started thinking less like a CEO and more like one of the hackers I’d interviewed.

This means actively monitoring for threats. We set up alerts for mentions of our company and key executives on dark web forums and paste sites. It’s not about being paranoid; it’s about getting early warnings. If someone is selling a dataset with your employee emails, you want to know before the phishing attacks start.

This proactive stance is a mindset shift. Don't just wait for the attack to hit your inbox. Go out and look for the signs that an attack is being planned.

3. Demand Digital Provenance

As an investor in the AI space, I believe we have a responsibility to solve this problem at the source. The long-term solution is to build authenticity and provenance directly into the tools we’re creating. We need a way to verify where a piece of content came from.

Companies are already working on this. The C2PA (Coalition for Content Provenance and Authenticity) is creating a technical standard for certifying the source and history of media content. Think of it like a digital watermark that can’t be easily faked or removed.

When you take a photo on your phone, the file contains metadata—the time, date, and even the GPS location. We need a similar standard for AI-generated content. Was this audio generated by a text-to-speech model? Was this video manipulated? We need a clear, machine-readable way to answer these questions.

The Real Arms Race

For three years, I’ve been living in this world of digital ghosts and fake identities. What I’ve learned is that technology is not the savior. It’s a tool, and it can be used for good or for ill. The real fight isn’t against deepfakes themselves, but against the erosion of trust they represent.

The future isn’t about building a perfect deepfake detector. It’s about building resilient organizations where people are empowered to question, to verify, and to trust but verify. It’s about changing our habits.

We are the first generation of business leaders navigating this new landscape. The choices we make now—the processes we build, the culture we create, the standards we demand—will determine whether our digital future is built on truth or on deception. We're building the tools that will shape the next century. We have a moral obligation to build the shields alongside the swords.

Frequently Asked Questions

What was the biggest challenge in this case?

Almost always, the biggest challenge is people and alignment, not technology or strategy. Getting the right team focused on the right problem is harder than any technical challenge I've encountered.

How long did it take to see results?

Most meaningful business results take 3-6 months to materialize. Anyone promising overnight success is selling something. The companies in my portfolio that grew fastest were the ones that stayed patient and consistent.

Can these results be replicated?

The specific numbers will vary, but the underlying patterns and principles are transferable. The key is understanding the context behind the results, not just copying the tactics. Every company has unique constraints that shape what works.

More in AI Security and Cybersecurity

All AI Security and Cybersecurity articles · Sahin's angel investments · Startups he founded